None of the CNPG clusters had any backup configured, so a lost PVC or a bad
migration meant permanent data loss. This adds continuous WAL archiving plus a
nightly base backup to Ceph RGW for every cluster, with restore docs.
- Add spec.backup.barmanObjectStore (in-tree; operator is CNPG 1.28, Barman
Cloud Plugin not deployed) to each cnpg_cluster.yaml: WAL zstd, base bzip2,
30-day retention, endpointCA via the reflected vault-ca-cert.
- Add cnpg_backup.yaml per app: a cephrgw ObjectStoreUser + Bucket (one
dedicated s3://cnpg-<app> bucket and owner user per cluster, since cephrgw CRs
and the CNPG credential Secret are namespace-scoped) and a staggered nightly
ScheduledBackup. Credentials are minted by the operator; nothing is hardcoded.
- Add the three ceph.unkin.net CRD schemas so kubeconform can validate the CRs.
- Add docs/ (README index, cnpg-backups.md, cnpg-restore.md) covering config and
full/PITR restore procedures.
Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv