--- # Ceph RGW (S3) backup target for the woodpecker CNPG cluster, provisioned by the # in-estate cephrgw-operator. One dedicated bucket + owner user per cluster: # cephrgw CRs are namespace-scoped and CNPG reads its S3 credential Secret from # its own namespace, so backups are per-database rather than one shared bucket. apiVersion: ceph.unkin.net/v1alpha1 kind: ObjectStoreUser metadata: name: cnpg-woodpecker-backup namespace: woodpecker spec: displayName: "CNPG backup owner (woodpecker)" # RGW users are global; keep the uid namespace-qualified so it never collides. uid: cnpg-woodpecker-backup maxBuckets: 5 # Operator writes AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY (+ RGW_UID, # S3_ENDPOINT) into this Secret; the Cluster's barmanObjectStore consumes it. secretName: cnpg-woodpecker-backup-s3 # Keep the RGW user (and thus the keys) if this CR is ever deleted, so an # in-flight restore can still reach the archive. retainOnDelete: true --- apiVersion: ceph.unkin.net/v1alpha1 kind: Bucket metadata: name: cnpg-woodpecker namespace: woodpecker spec: bucketName: cnpg-woodpecker # The owner user has full control of its own bucket (read + write), which is # all the backup/restore identity needs — no extra BucketAccess grant. ownerRef: cnpg-woodpecker-backup versioning: false tags: app: woodpecker purpose: cnpg-backup # Never drop the backups if the CR is removed; retire buckets by hand. retainOnDelete: true --- # Nightly base backup. Continuous WAL archiving is always-on via the Cluster's # spec.backup.barmanObjectStore; this schedules the periodic full backup that # WAL is layered on top of. Schedules are staggered across clusters so the 8 # base backups do not hit RGW at once (CNPG cron is 6-field, seconds first). apiVersion: postgresql.cnpg.io/v1 kind: ScheduledBackup metadata: name: cnpg-woodpecker-nightly namespace: woodpecker spec: schedule: "0 0 2 * * *" immediate: false backupOwnerReference: self method: barmanObjectStore cluster: name: woodpecker-postgres