fix(cnpg): fix backup alerts (#522)

This commit is contained in:
Antoine Lecompte
2026-08-21 13:17:57 +00:00
committed by GitHub
parent 13dc15e576
commit bbcfa7c295
4 changed files with 44 additions and 21 deletions
+16 -4
View File
@@ -55,10 +55,22 @@ radosgw-admin user create \
| `svc-yucca-db-backup` | CNPG (yucca-database) WAL archiving + base backups via the Barman Cloud plugin | 1 | — |
All three are created by `rgw.yml` with predetermined, TF-minted keys (see
[secrets.md](secrets.md)). `svc-yucca-db-backup` never needs a pre-created
bucket: barman creates `yucca-db-backups` on first use, and `--max-buckets=1`
caps the user there. The k8s side consumes the keys plus the RGW cert from the
TF-provisioned `yucca-db-backup-s3` Secret.
[secrets.md](secrets.md)). `svc-yucca-db-backup`'s bucket is NOT auto-created —
barman-cloud fails with `NoSuchBucket` until it exists. Create it once per
cluster with the user's own credentials (`--max-buckets=1` permits exactly this
one bucket):
```bash
AWS_ACCESS_KEY_ID=$(op read "op://<vault>/<CLUSTER>_CEPH_S3_SVC_YUCCA_DB_BACKUP_ACCESS_KEY/password") \
AWS_SECRET_ACCESS_KEY=$(op read "op://<vault>/<CLUSTER>_CEPH_S3_SVC_YUCCA_DB_BACKUP_SECRET_KEY/password") \
aws s3api create-bucket --bucket yucca-db-backups \
--endpoint-url https://s3.<cluster domain> --no-verify-ssl
```
(Or a named profile holding the same keys, per the AWS CLI section below.)
The k8s side consumes the keys plus the RGW cert from the TF-provisioned
`yucca-db-backup-s3` Secret.
## Self-signed certificate handling
+4 -2
View File
@@ -904,8 +904,10 @@
# A dedicated S3 user the yucca-database CNPG cluster (Barman Cloud plugin)
# archives WALs and base backups with. Keys are TF-minted in 1P
# (<CLUSTER>_CEPH_S3_SVC_YUCCA_DB_BACKUP_{ACCESS,SECRET}_KEY) and passed here so
# the consumer is pre-configured with matching credentials. max-buckets=1: barman
# creates its single bucket on first use; this user can never create another.
# the consumer is pre-configured with matching credentials. max-buckets=1: the
# yucca-db-backups bucket is created out-of-band with this user's own creds
# (barman does NOT auto-create it — see docs/s3-integration.md), and the cap
# means this user can never create another.
- name: Check if db-backup RGW user exists
ansible.builtin.command: "radosgw-admin user info --uid={{ ceph_rgw_db_backup_user_uid }}"