# Clone with DSN credentials: the provider (RDS, Neon, ...) hands you a
# complete connection URI; store it in a Secret and reference it. TLS
# verification against a provider CA bundle is shown on the target side.
# The inline form is in 01-clone-minimal.yaml; the forms are mutually
# exclusive per endpoint.
apiVersion: pgcopydb-operator.io/v1beta1
kind: Migration
metadata:
  name: clone-dsn-secret
spec:
  source:
    # The Secret key holds the full libpq URI including credentials, e.g.
    # postgres://user:pass@db.eu-central-1.example.com/app?sslmode=require
    uriSecretRef: {name: rds-source, key: uri}
  target:
    host: app-pg-rw.app.svc
    database: app
    username: app
    passwordSecretRef: {name: app-pg-app, key: password}
    sslMode: verify-full
    tls:
      rootCA: {name: app-pg-ca, key: ca.crt}  # provider CA bundle
