mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-09-30 15:05:50 +02:00
Support for GCS WAL-E backups (#620)
* Support for WAL_GS_BUCKET and GOOGLE_APPLICATION_CREDENTIALS environtment variables * Fixed merge issue but also removed all changes to support macos. * Updated test to new format * Missed macos specific changes * Added documentation and addressed comments * Update docs/administrator.md * Update docs/administrator.md * Update e2e/run.sh Co-authored-by: Felix Kunde <felix-kunde@gmx.de>
This commit is contained in:
@@ -518,6 +518,57 @@ A secret can be pre-provisioned in different ways:
|
||||
* Automatically provisioned via a custom K8s controller like
|
||||
[kube-aws-iam-controller](https://github.com/mikkeloscar/kube-aws-iam-controller)
|
||||
|
||||
## Google Cloud Platform setup
|
||||
|
||||
To configure the operator on GCP there are some prerequisites that are needed:
|
||||
|
||||
* A service account with the proper IAM setup to access the GCS bucket for the WAL-E logs
|
||||
* The credentials file for the service account.
|
||||
|
||||
The configuration paramaters that we will be using are:
|
||||
|
||||
* `additional_secret_mount`
|
||||
* `additional_secret_mount_path`
|
||||
* `gcp_credentials`
|
||||
* `wal_gs_bucket`
|
||||
|
||||
### Generate a K8 secret resource
|
||||
|
||||
Generate the K8 secret resource that will contain your service account's
|
||||
credentials. It's highly recommended to use a service account and limit its
|
||||
scope to just the WAL-E bucket.
|
||||
|
||||
```yaml
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: psql-wale-creds
|
||||
namespace: default
|
||||
type: Opaque
|
||||
stringData:
|
||||
key.json: |-
|
||||
<GCP .json credentials>
|
||||
```
|
||||
|
||||
### Setup your operator configuration values
|
||||
|
||||
With the `psql-wale-creds` resource applied to your cluster, ensure that
|
||||
the operator's configuration is set up like the following:
|
||||
|
||||
```yml
|
||||
...
|
||||
aws_or_gcp:
|
||||
additional_secret_mount: "pgsql-wale-creds"
|
||||
additional_secret_mount_path: "/var/secrets/google" # or where ever you want to mount the file
|
||||
# aws_region: eu-central-1
|
||||
# kube_iam_role: ""
|
||||
# log_s3_bucket: ""
|
||||
# wal_s3_bucket: ""
|
||||
wal_gs_bucket: "postgres-backups-bucket-28302F2" # name of bucket on where to save the WAL-E logs
|
||||
gcp_credentials: "/var/secrets/google/key.json" # combination of the mount path & key in the K8 resource. (i.e. key.json)
|
||||
...
|
||||
```
|
||||
|
||||
## Sidecars for Postgres clusters
|
||||
|
||||
A list of sidecars is added to each cluster created by the operator. The default
|
||||
|
||||
@@ -451,6 +451,20 @@ yet officially supported.
|
||||
present and accessible by Postgres pods. At the moment, supported services by
|
||||
Spilo are S3 and GCS. The default is empty.
|
||||
|
||||
* **wal_gs_bucket**
|
||||
GCS bucket to use for shipping WAL segments with WAL-E. A bucket has to be
|
||||
present and accessible by Postgres pods. Note, only the name of the bucket is
|
||||
required. At the moment, supported services by Spilo are S3 and GCS.
|
||||
The default is empty.
|
||||
|
||||
* **gcp_credentials**
|
||||
Used to set the GOOGLE_APPLICATION_CREDENTIALS environment variable for the pods.
|
||||
This is used in with conjunction with the `additional_secret_mount` and
|
||||
`additional_secret_mount_path` to properly set the credentials for the spilo
|
||||
containers. This will allow users to use specific
|
||||
[service accounts](https://cloud.google.com/kubernetes-engine/docs/tutorials/authenticating-to-cloud-platform).
|
||||
The default is empty
|
||||
|
||||
* **log_s3_bucket**
|
||||
S3 bucket to use for shipping Postgres daily logs. Works only with S3 on AWS.
|
||||
The bucket has to be present and accessible by Postgres pods. The default is
|
||||
|
||||
Reference in New Issue
Block a user