--- # Ceph RGW (S3) backup target for the netbox CNPG cluster, provisioned by the # in-estate cephrgw-operator. One dedicated bucket + owner user per cluster: # cephrgw CRs are namespace-scoped and CNPG reads its S3 credential Secret from # its own namespace, so backups are per-database rather than one shared bucket. apiVersion: ceph.unkin.net/v1alpha1 kind: ObjectStoreUser metadata: name: cnpg-netbox-backup namespace: netbox spec: displayName: "CNPG backup owner (netbox)" # RGW users are global; keep the uid namespace-qualified so it never collides. uid: cnpg-netbox-backup maxBuckets: 5 # Operator writes AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY (+ RGW_UID, # S3_ENDPOINT) into this Secret; the Cluster's barmanObjectStore consumes it. secretName: cnpg-netbox-backup-s3 # Keep the RGW user (and thus the keys) if this CR is ever deleted. retainOnDelete: true --- apiVersion: ceph.unkin.net/v1alpha1 kind: Bucket metadata: name: cnpg-netbox namespace: netbox spec: placementTarget: ec bucketName: cnpg-netbox ownerRef: cnpg-netbox-backup versioning: false tags: app: netbox purpose: cnpg-backup retainOnDelete: true --- apiVersion: postgresql.cnpg.io/v1 kind: ScheduledBackup metadata: name: cnpg-netbox-nightly namespace: netbox spec: # 6-field CNPG cron (seconds first). 03:40 — next free slot after grafana # (03:20), keeping the estate's 20-minute stagger. schedule: "0 40 3 * * *" immediate: false backupOwnerReference: self method: barmanObjectStore cluster: name: netbox-postgres