Data placement and storage

Independent bundled or external placement for PostgreSQL, Kafka, ClickHouse, and Redis, including bundled-store limits.

Short glossary
  • Helm release: an installed and independently managed resource set from one chart.
  • Secret object: a Kubernetes resource referenced for sensitive values; the delivery charts do not own the values themselves.
  • PersistentVolumeClaim (PVC): a storage request used by a bundled data component.
  • NetworkPolicy: rules governing permitted network connections for application Pods.
  • Container Storage Interface (CSI) and Container Network Interface (CNI) capabilities are provided by the customer cluster.

Data-store placement

Select bundled or external placement independently for PostgreSQL, Kafka, ClickHouse, and Redis. All 16 combinations of the four independent settings are supported; there is no aggregate installation mode.

Store modeBoundary
bundledThe package installs the selected single-node store in massaccess-data with an RWO PVC.
externalThe package does not create this store and connects MassAccess to the company infrastructure endpoint and Secret.

Confirmed limits

  • Bundled data is single-node and non-HA; multi-node topology, drain, replication, failover, and PDB claims are not supported
  • The charts do not provision or harden Kubernetes, DNS, CNI, CSI, StorageClass, Ingress/Gateway controllers, TLS automation, monitoring, or backup infrastructure
  • Docker Desktop hostpath and local reference-CNI evidence does not prove customer CSI/CNI, HA, capacity, performance, disaster recovery, or production SLA
  • The release contract does not claim cryptographic signing or absence of vulnerabilities; use the documented checksum, SBOM, SLSA provenance, and policy verification boundary