Research-2351: components of the cloud-native platform, their versions, licences and limits¶
Question¶
Which components can carry the cloud-native target of #2431 (state out of the processes, queue-driven scaling, artifacts in registries, events, generated surfaces, a standalone profile), at which current version, under which licence, and with which limits that change the design? Every row below was read from the upstream release, licence file or documentation on 2026-10-07, not from memory. Rows marked unverified could not be confirmed that day.
Sources¶
Release pages are https://github.com/<repository>/releases; the licence is the repository's licence file unless the row says otherwise.
| Component | Repository | Latest stable (date) | Licence |
|---|---|---|---|
| CloudNativePG operator | cloudnative-pg/cloudnative-pg | v1.30.1 (2026-09-23); chart cloudnative-pg 0.29.1 | Apache-2.0 |
| Barman Cloud plugin for CloudNativePG | cloudnative-pg/plugin-barman-cloud | v0.15.1 (2026-09-30) | Apache-2.0 |
| PostgreSQL | postgresql.org versions.json | 18.6 (2026-08-13); 14 is end of life on 2026-11-12 | PostgreSQL |
| TimescaleDB | timescale/timescaledb | 2.30.2 (2026-09-29), PostgreSQL 16 to 18 | Apache-2.0 outside tsl/, Timescale License (TSL) in tsl/ |
| River | riverqueue/river | v0.49.0 (2026-10-05) | MPL-2.0 |
| Valkey | valkey-io/valkey | 9.1.2 (2026-09-01); chart valkey-io/valkey-helm 0.12.0 | BSD-3-Clause |
| Dragonfly | dragonflydb/dragonfly | v2.0.0 (2026-09-16) | BUSL-1.1, change date 2030-11-01 to Apache-2.0 |
| Redis | redis/redis | 8.10.2 (2026-09-17) | RSALv2, SSPLv1 or AGPLv3 (8.x); BSD-3-Clause up to 7.2 |
| rueidis | redis/rueidis | v1.0.78 (2026-09-15) | Apache-2.0 |
| otter | maypok86/otter | v2.3.0 (2025-12-22) | Apache-2.0 |
| KEDA | kedacore/keda | v2.21.0 (2026-09-23) | Apache-2.0 |
| Kubernetes | kubernetes/kubernetes | 1.37 (1.37.0 on 2026-08-26); 1.34 is end of life on 2026-10-27 | Apache-2.0 |
| GPU DRA driver (NVIDIA GPUs) | kubernetes-sigs/dra-driver-nvidia-gpu | v0.5.0 (2026-08-19) | Apache-2.0 |
| GPU DRA driver (Intel GPUs) | intel/intel-resource-drivers-for-kubernetes | gpu-v0.12.1 (2026-09-29) | Apache-2.0 |
| GPU DRA driver (AMD GPUs) | ROCm/k8s-gpu-dra-driver | v1.0.1 (2026-07-22) | Apache-2.0 |
| GPU device plugins | NVIDIA/k8s-device-plugin, intel/intel-device-plugins-for-kubernetes, ROCm/k8s-device-plugin | v0.20.1, v0.37.1, v1.31.0.11 | Apache-2.0 |
| Node Feature Discovery | kubernetes-sigs/node-feature-discovery | v0.19.0 (2026-07-10) | Apache-2.0 |
| OCI image specification | opencontainers/image-spec | v1.1.1 (2025-03-03) | Apache-2.0 |
| oras-go, oras CLI | oras-project/oras-go, oras-project/oras | v2.6.2, v1.3.4 | Apache-2.0 |
| go-containerregistry | google/go-containerregistry | v0.22.1 (2026-09-04), the version golusoris container/registry pins | Apache-2.0 |
| cosign, sigstore-go | sigstore/cosign, sigstore/sigstore-go | v3.1.3, v1.3.0 | Apache-2.0 |
| ModelPack model specification | modelpack/model-spec | tag v0.0.7 | Apache-2.0 |
| cert-manager, trust-manager | cert-manager/cert-manager, cert-manager/trust-manager | v1.21.2, v0.25.0 | Apache-2.0 |
| External Secrets Operator | external-secrets/external-secrets | v2.12.0 (2026-10-06) | Apache-2.0 |
| NATS server, nats.go | nats-io/nats-server, nats-io/nats.go | v2.15.0, v1.54.0; chart nats 2.15.0 | Apache-2.0 |
| Apache Kafka, franz-go, Strimzi | downloads.apache.org, twmb/franz-go, strimzi/strimzi-kafka-operator | 4.3.1, v1.22.1, 1.2.0 | Apache-2.0, BSD-3-Clause, Apache-2.0 |
| CloudEvents | cloudevents/spec, cloudevents/sdk-go | spec 1.0.2, sdk-go v2.16.2 | Apache-2.0 |
| golang-migrate, sqlc, pgx | golang-migrate/migrate, sqlc-dev/sqlc, jackc/pgx | v4.20.1, v1.31.1, v5.11.0 | MIT |
| buf, connect-go, grpc-go | bufbuild/buf, connectrpc/connect-go, grpc/grpc-go | v1.73.0, v1.21.0, v1.84.0 | Apache-2.0 |
| controller-tools (controller-gen) | kubernetes-sigs/controller-tools | v0.22.0 (2026-09-02) | Apache-2.0 |
| Helm | helm/helm | 4.3.0 and 3.22.0 | Apache-2.0 |
| kind, kuttl | kubernetes-sigs/kind, kudobuilder/kuttl | v0.33.0, v0.27.0 | Apache-2.0 |
| S3-compatible test servers | seaweedfs/seaweedfs, versity/versitygw | 4.48, 1.8.0 | Apache-2.0 |
| MinIO | minio/minio | last release 2025-10-16; repository archived | AGPL-3.0 |
| tusd | tus/tusd | v2.10.1 | MIT |
| Harbor | goharbor/harbor | v2.15.3 (2026-10-06) | Apache-2.0 |
The golusoris modules were read at golusoris/golusoris origin/main 9dac7d0 (tag v0.12.0 is the version go.mod pins); River's behaviour was read in its v0.47.0 source, the version golusoris pins.
Findings¶
Licences that pass conditions on to every operator¶
- TimescaleDB. Hypertables,
drop_chunksandtime_bucketare Apache-2.0. Compression (the columnstore), continuous aggregates, retention policies (add_retention_policy) and background jobs are TSL. TSL section 2.2 forbids offering the TSL code to third parties "to provide time-series database functions or operations, other than as part of Your Value Added Products or Services", and a value-added service may not give its users direct database access (section 3.10). The extension image CloudNativePG publishes (cloudnative-pg/postgres-extensions-containers,timescaledb-oss) is the Apache-2.0 edition; a TSL build means thetimescale/timescaledb-haimage as a customimageName. golusorisdb/timescalecallsEnableCompression,AddCompressionPolicyandSetRetention, which are TSL functions. Managed PostgreSQL offerings differ in whether they offer the extension at all (not checked per provider). - Dragonfly. BUSL-1.1 until 2030-11-01. The additional use grant allows use "only as part of your own product or service, provided it is not an in-memory data store product or service" and not "as a Service".
- Redis 8. RSALv2, SSPLv1 or AGPLv3 at the user's choice; Valkey is the BSD-3-Clause line.
- MinIO. AGPL-3.0 and archived; not a test dependency to add. SeaweedFS and versitygw are Apache-2.0 S3-compatible servers.
- River Pro (workflows, sequences, concurrency limits, durable periodic jobs) is commercial; open-source River has unique jobs, periodic jobs, retries with backoff, leader election and resumable jobs.
Limits that change the design¶
- River runs a job only inside a River client.
JobCompleteTxrefuses to run outside a worker ("client not found in context, can only work within a River worker",job_complete_tx.goin v0.47.0), and the public client has no fetch-without-execute call (client.go:Insert*,Job{Get,List,Cancel, Retry,Update,Delete},Queue*). A process that is not a River client (a remote, tenant-bound node behind the gRPC node API) cannot take and complete a River job. - River on SQLite exists but is experimental (
riverdriver/riversqlite, since v0.23.0; v0.40.0 added a pseudo listen/notify table for SQLite). - GPU allocation through DRA is not production-ready for any vendor. The NVIDIA driver's README calls GPU allocation "not yet officially supported" (only ComputeDomains are); the Intel driver calls itself "beta / non-production"; the AMD driver is at v1.0.1. The Kubernetes side is stable (
DynamicResourceAllocationgate stable in 1.34,resource.k8s.io/v1; prioritized lists and admin access stable in 1.36). Device plugins are stable and published for all three vendors. - Support windows. CloudNativePG 1.30 supports Kubernetes 1.34 to 1.36 and is tested on 1.37; KEDA 2.21 is tested on 1.34 to 1.36 (N-2 policy); the repository's kind job pins kind v0.33.0 and kubectl v1.37.0 (
.github/workflows/e2e-k8s.yml). Kubernetes 1.34 reaches end of life on 2026-10-27. - CloudNativePG extensions from images (
.spec.postgresql.extensions) need PostgreSQL 18, Kubernetes 1.35 (image volumes on by default from 1.35) and containerd 2.1 or CRI-O 1.31. - CloudNativePG backups. The in-tree
barmanObjectStoreis deprecated since 1.26; the Barman Cloud plugin is the supported path and authenticates with IRSA, GKE Workload Identity or Azure managed identity. - CloudEvents for Kafka with franz-go. sdk-go has NATS, JetStream and two Kafka bindings (sarama, confluent), none for franz-go, which golusoris
pubsub/kafkauses. - Helm values schemas. Helm 3.22 and 4.3 both validate with
santhosh-tekuri/jsonschema/v6; keywords of JSON Schema draft-07 are read by both lines and by older Helm 3 releases. - Linkerd publishes no open-source stable releases since February 2024; mTLS from cert-manager certificates needs no mesh.
- Bitnami charts and images left the public catalogue on 2025-09-29 (old images moved to
bitnamilegacy); a chart dependency on them would stop receiving updates.
golusoris: what exists and what is missing¶
| Module | Has | Missing for #2431 |
|---|---|---|
jobs | River client over pgxpool, Register, 25 attempts and 30 s timeout by default, River UI | A driver choice (riversqlite) for the standalone profile; River is two minors behind (v0.47.0 against v0.49.0) |
outbox | Transactional Add(ctx, tx, …), leader-gated drainer into River jobs, golang-migrate files | SQLite; a CloudEvents envelope |
pubsub/nats, pubsub/kafka | JetStream and franz-go clients | CloudEvents binary and structured mode for both |
cache/twotier | L1 otter, L2 rueidis, singleflight, prefix invalidation | An L1-only mode (the constructor requires a rueidis.Client); invalidation of other replicas' L1 |
idempotency | HTTP middleware for Idempotency-Key, in-memory store | A shared store (Postgres or Redis protocol); a gRPC interceptor |
storage | Bucket interface, local and S3 (aws-sdk-go-v2 default credential chain, so IRSA and EKS Pod Identity), presigned GET | GCS and Azure Blob backends (GCS is marked planned), presigned PUT |
container/registry | go-containerregistry client: resolve, manifest, tags, copy; keychains are injectable | Pushing and pulling arbitrary OCI artifacts (artifact type, own layers), referrers |
grpc | Server TLS from a certificate file pair | Client-certificate verification (mTLS), certificate reload on rotation, configurable keepalive (open issue golusoris#589) |
db/timescale | Hypertable, compression and retention helpers | Edition detection, so TSL-only calls fail with a named error on the Apache edition |
db/migrate | golang-migrate on pgx v5 | A SQLite source for the standalone profile |
leader | Kubernetes Lease and Postgres advisory-lock electors | nothing |
secrets | Environment, file and static backends | nothing (External Secrets Operator writes Secrets that mount as files) |
k8s/operator | controller-runtime manager under fx | nothing |
Alternatives explored¶
- Temporal (golusoris
jobs/workflow): long activities on remote workers with heartbeats fit the node model, but it adds a server cluster with its own persistence next to PostgreSQL; ADR-2350 lists it as rejected. - oras-go next to go-containerregistry: both write OCI 1.1 artifacts; carrying two OCI clients in one fleet contradicts HISS-19.
- Service meshes for mTLS: Istio ambient (Apache-2.0, 1.31.1) works but adds a data plane; Linkerd has no open-source stable line.
Open questions¶
Not confirmed on 2026-10-07: River's minimum PostgreSQL version; Kafka 4.x being KRaft-only; which JSON Schema draft the Helm documentation states; referrers API support in Harbor, GHCR, ECR, GAR, Docker Hub and Zot (ACR supports it except for customer-managed-key registries); cosign sign on an arbitrary artifact by digest (documented, not run); Azure federated workload identity in the Barman Cloud plugin by that name; the default Kubernetes versions of the managed offerings; the AMD DRA driver's production status.