mirror of
https://github.com/immich-app/yucca.git
synced 2026-10-04 23:32:45 +08:00
fix(cnpg): fix backup alerts (#522)
This commit is contained in:
@@ -55,10 +55,22 @@ radosgw-admin user create \
|
||||
| `svc-yucca-db-backup` | CNPG (yucca-database) WAL archiving + base backups via the Barman Cloud plugin | 1 | — |
|
||||
|
||||
All three are created by `rgw.yml` with predetermined, TF-minted keys (see
|
||||
[secrets.md](secrets.md)). `svc-yucca-db-backup` never needs a pre-created
|
||||
bucket: barman creates `yucca-db-backups` on first use, and `--max-buckets=1`
|
||||
caps the user there. The k8s side consumes the keys plus the RGW cert from the
|
||||
TF-provisioned `yucca-db-backup-s3` Secret.
|
||||
[secrets.md](secrets.md)). `svc-yucca-db-backup`'s bucket is NOT auto-created —
|
||||
barman-cloud fails with `NoSuchBucket` until it exists. Create it once per
|
||||
cluster with the user's own credentials (`--max-buckets=1` permits exactly this
|
||||
one bucket):
|
||||
|
||||
```bash
|
||||
AWS_ACCESS_KEY_ID=$(op read "op://<vault>/<CLUSTER>_CEPH_S3_SVC_YUCCA_DB_BACKUP_ACCESS_KEY/password") \
|
||||
AWS_SECRET_ACCESS_KEY=$(op read "op://<vault>/<CLUSTER>_CEPH_S3_SVC_YUCCA_DB_BACKUP_SECRET_KEY/password") \
|
||||
aws s3api create-bucket --bucket yucca-db-backups \
|
||||
--endpoint-url https://s3.<cluster domain> --no-verify-ssl
|
||||
```
|
||||
|
||||
(Or a named profile holding the same keys, per the AWS CLI section below.)
|
||||
|
||||
The k8s side consumes the keys plus the RGW cert from the TF-provisioned
|
||||
`yucca-db-backup-s3` Secret.
|
||||
|
||||
## Self-signed certificate handling
|
||||
|
||||
|
||||
@@ -904,8 +904,10 @@
|
||||
# A dedicated S3 user the yucca-database CNPG cluster (Barman Cloud plugin)
|
||||
# archives WALs and base backups with. Keys are TF-minted in 1P
|
||||
# (<CLUSTER>_CEPH_S3_SVC_YUCCA_DB_BACKUP_{ACCESS,SECRET}_KEY) and passed here so
|
||||
# the consumer is pre-configured with matching credentials. max-buckets=1: barman
|
||||
# creates its single bucket on first use; this user can never create another.
|
||||
# the consumer is pre-configured with matching credentials. max-buckets=1: the
|
||||
# yucca-db-backups bucket is created out-of-band with this user's own creds
|
||||
# (barman does NOT auto-create it — see docs/s3-integration.md), and the cap
|
||||
# means this user can never create another.
|
||||
|
||||
- name: Check if db-backup RGW user exists
|
||||
ansible.builtin.command: "radosgw-admin user info --uid={{ ceph_rgw_db_backup_user_uid }}"
|
||||
|
||||
Reference in New Issue
Block a user