mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-10-05 09:23:17 +00:00
1 line
15 KiB
JavaScript
1 line
15 KiB
JavaScript
"use strict";(self.webpackChunkrancher_docs=self.webpackChunkrancher_docs||[]).push([[58941],{3905:(e,n,r)=>{r.d(n,{Zo:()=>u,kt:()=>m});var t=r(67294);function a(e,n,r){return n in e?Object.defineProperty(e,n,{value:r,enumerable:!0,configurable:!0,writable:!0}):e[n]=r,e}function c(e,n){var r=Object.keys(e);if(Object.getOwnPropertySymbols){var t=Object.getOwnPropertySymbols(e);n&&(t=t.filter((function(n){return Object.getOwnPropertyDescriptor(e,n).enumerable}))),r.push.apply(r,t)}return r}function o(e){for(var n=1;n<arguments.length;n++){var r=null!=arguments[n]?arguments[n]:{};n%2?c(Object(r),!0).forEach((function(n){a(e,n,r[n])})):Object.getOwnPropertyDescriptors?Object.defineProperties(e,Object.getOwnPropertyDescriptors(r)):c(Object(r)).forEach((function(n){Object.defineProperty(e,n,Object.getOwnPropertyDescriptor(r,n))}))}return e}function i(e,n){if(null==e)return{};var r,t,a=function(e,n){if(null==e)return{};var r,t,a={},c=Object.keys(e);for(t=0;t<c.length;t++)r=c[t],n.indexOf(r)>=0||(a[r]=e[r]);return a}(e,n);if(Object.getOwnPropertySymbols){var c=Object.getOwnPropertySymbols(e);for(t=0;t<c.length;t++)r=c[t],n.indexOf(r)>=0||Object.prototype.propertyIsEnumerable.call(e,r)&&(a[r]=e[r])}return a}var s=t.createContext({}),p=function(e){var n=t.useContext(s),r=n;return e&&(r="function"==typeof e?e(n):o(o({},n),e)),r},u=function(e){var n=p(e.components);return t.createElement(s.Provider,{value:n},e.children)},l={inlineCode:"code",wrapper:function(e){var n=e.children;return t.createElement(t.Fragment,{},n)}},d=t.forwardRef((function(e,n){var r=e.components,a=e.mdxType,c=e.originalType,s=e.parentName,u=i(e,["components","mdxType","originalType","parentName"]),d=p(r),m=a,k=d["".concat(s,".").concat(m)]||d[m]||l[m]||c;return r?t.createElement(k,o(o({ref:n},u),{},{components:r})):t.createElement(k,o({ref:n},u))}));function m(e,n){var r=arguments,a=n&&n.mdxType;if("string"==typeof e||a){var c=r.length,o=new Array(c);o[0]=d;var i={};for(var s in n)hasOwnProperty.call(n,s)&&(i[s]=n[s]);i.originalType=e,i.mdxType="string"==typeof e?e:a,o[1]=i;for(var p=2;p<c;p++)o[p]=r[p];return t.createElement.apply(null,o)}return t.createElement.apply(null,r)}d.displayName="MDXCreateElement"},85465:(e,n,r)=>{r.r(n),r.d(n,{assets:()=>s,contentTitle:()=>o,default:()=>l,frontMatter:()=>c,metadata:()=>i,toc:()=>p});var t=r(87462),a=(r(67294),r(3905));const c={title:"Examples"},o=void 0,i={unversionedId:"reference-guides/backup-restore-configuration/examples",id:"version-2.5/reference-guides/backup-restore-configuration/examples",title:"Examples",description:"This section contains examples of Backup and Restore custom resources.",source:"@site/versioned_docs/version-2.5/reference-guides/backup-restore-configuration/examples.md",sourceDirName:"reference-guides/backup-restore-configuration",slug:"/reference-guides/backup-restore-configuration/examples",permalink:"/v2.5/reference-guides/backup-restore-configuration/examples",draft:!1,editUrl:"https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.5/reference-guides/backup-restore-configuration/examples.md",tags:[],version:"2.5",lastUpdatedAt:1667002159,formattedLastUpdatedAt:"Oct 29, 2022",frontMatter:{title:"Examples"},sidebar:"tutorialSidebar",previous:{title:"Backup Storage Location Configuration",permalink:"/v2.5/reference-guides/backup-restore-configuration/storage-configuration"},next:{title:"Configuring OpenLDAP",permalink:"/v2.5/pages-for-subheaders/configure-openldap"}},s={},p=[{value:"Backup",id:"backup",level:2},{value:"Backup in the Default Location with Encryption",id:"backup-in-the-default-location-with-encryption",level:3},{value:"Recurring Backup in the Default Location",id:"recurring-backup-in-the-default-location",level:3},{value:"Encrypted Recurring Backup in the Default Location",id:"encrypted-recurring-backup-in-the-default-location",level:3},{value:"Encrypted Backup in Minio",id:"encrypted-backup-in-minio",level:3},{value:"Backup in S3 Using AWS Credential Secret",id:"backup-in-s3-using-aws-credential-secret",level:3},{value:"Recurring Backup in S3 Using AWS Credential Secret",id:"recurring-backup-in-s3-using-aws-credential-secret",level:3},{value:"Backup from EC2 Nodes with IAM Permission to Access S3",id:"backup-from-ec2-nodes-with-iam-permission-to-access-s3",level:3},{value:"Restore",id:"restore",level:2},{value:"Restore Using the Default Backup File Location",id:"restore-using-the-default-backup-file-location",level:3},{value:"Restore for Rancher Migration",id:"restore-for-rancher-migration",level:3},{value:"Restore from Encrypted Backup",id:"restore-from-encrypted-backup",level:3},{value:"Restore an Encrypted Backup from Minio",id:"restore-an-encrypted-backup-from-minio",level:3},{value:"Restore from Backup Using an AWS Credential Secret to Access S3",id:"restore-from-backup-using-an-aws-credential-secret-to-access-s3",level:3},{value:"Restore from EC2 Nodes with IAM Permissions to Access S3",id:"restore-from-ec2-nodes-with-iam-permissions-to-access-s3",level:3},{value:"Example Credential Secret for Storing Backups in S3",id:"example-credential-secret-for-storing-backups-in-s3",level:2},{value:"Example EncryptionConfiguration",id:"example-encryptionconfiguration",level:2}],u={toc:p};function l(e){let{components:n,...r}=e;return(0,a.kt)("wrapper",(0,t.Z)({},u,r,{components:n,mdxType:"MDXLayout"}),(0,a.kt)("p",null,"This section contains examples of Backup and Restore custom resources."),(0,a.kt)("p",null,"The default backup storage location is configured when the ",(0,a.kt)("inlineCode",{parentName:"p"},"rancher-backup")," operator is installed or upgraded."),(0,a.kt)("p",null,"Encrypted backups can only be restored if the Restore custom resource uses the same encryption configuration secret that was used to create the backup."),(0,a.kt)("h2",{id:"backup"},"Backup"),(0,a.kt)("p",null,"This section contains example Backup custom resources."),(0,a.kt)("h3",{id:"backup-in-the-default-location-with-encryption"},"Backup in the Default Location with Encryption"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-yaml"},"apiVersion: resources.cattle.io/v1\nkind: Backup\nmetadata:\n name: default-location-encrypted-backup\nspec:\n resourceSetName: rancher-resource-set\n encryptionConfigSecretName: encryptionconfig\n")),(0,a.kt)("h3",{id:"recurring-backup-in-the-default-location"},"Recurring Backup in the Default Location"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-yaml"},'apiVersion: resources.cattle.io/v1\nkind: Backup\nmetadata:\n name: default-location-recurring-backup\nspec:\n resourceSetName: rancher-resource-set\n schedule: "@every 1h"\n retentionCount: 10\n')),(0,a.kt)("h3",{id:"encrypted-recurring-backup-in-the-default-location"},"Encrypted Recurring Backup in the Default Location"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-yaml"},'apiVersion: resources.cattle.io/v1\nkind: Backup\nmetadata:\n name: default-enc-recurring-backup\nspec:\n resourceSetName: rancher-resource-set\n encryptionConfigSecretName: encryptionconfig\n schedule: "@every 1h"\n retentionCount: 3\n')),(0,a.kt)("h3",{id:"encrypted-backup-in-minio"},"Encrypted Backup in Minio"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-yaml"},"apiVersion: resources.cattle.io/v1\nkind: Backup\nmetadata:\n name: minio-backup\nspec:\n storageLocation:\n s3:\n credentialSecretName: minio-creds\n credentialSecretNamespace: default\n bucketName: rancherbackups\n endpoint: minio.sslip.io\n endpointCA: LS0tLS1CRUdJTi3VUFNQkl5UUT.....pbEpWaVzNkRS0tLS0t\n resourceSetName: rancher-resource-set\n encryptionConfigSecretName: encryptionconfig\n")),(0,a.kt)("h3",{id:"backup-in-s3-using-aws-credential-secret"},"Backup in S3 Using AWS Credential Secret"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-yaml"},"apiVersion: resources.cattle.io/v1\nkind: Backup\nmetadata:\n name: s3-backup\nspec:\n storageLocation:\n s3:\n credentialSecretName: s3-creds\n credentialSecretNamespace: default\n bucketName: rancher-backups\n folder: ecm1\n region: us-west-2\n endpoint: s3.us-west-2.amazonaws.com\n resourceSetName: rancher-resource-set\n encryptionConfigSecretName: encryptionconfig\n")),(0,a.kt)("h3",{id:"recurring-backup-in-s3-using-aws-credential-secret"},"Recurring Backup in S3 Using AWS Credential Secret"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-yaml"},'apiVersion: resources.cattle.io/v1\nkind: Backup\nmetadata:\n name: s3-recurring-backup\nspec:\n storageLocation:\n s3:\n credentialSecretName: s3-creds\n credentialSecretNamespace: default\n bucketName: rancher-backups\n folder: ecm1\n region: us-west-2\n endpoint: s3.us-west-2.amazonaws.com\n resourceSetName: rancher-resource-set\n encryptionConfigSecretName: encryptionconfig\n schedule: "@every 1h"\n retentionCount: 10\n')),(0,a.kt)("h3",{id:"backup-from-ec2-nodes-with-iam-permission-to-access-s3"},"Backup from EC2 Nodes with IAM Permission to Access S3"),(0,a.kt)("p",null,"This example shows that the AWS credential secret does not have to be provided to create a backup if the nodes running ",(0,a.kt)("inlineCode",{parentName:"p"},"rancher-backup")," have ",(0,a.kt)("a",{parentName:"p",href:"/v2.5/reference-guides/backup-restore-configuration/backup-configuration#iam-permissions-for-ec2-nodes-to-access-s3"},"these permissions for access to S3.")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-yaml"},"apiVersion: resources.cattle.io/v1\nkind: Backup\nmetadata:\n name: s3-iam-backup\nspec:\n storageLocation:\n s3:\n bucketName: rancher-backups\n folder: ecm1\n region: us-west-2\n endpoint: s3.us-west-2.amazonaws.com\n resourceSetName: rancher-resource-set\n encryptionConfigSecretName: encryptionconfig\n")),(0,a.kt)("h2",{id:"restore"},"Restore"),(0,a.kt)("p",null,"This section contains example Restore custom resources."),(0,a.kt)("h3",{id:"restore-using-the-default-backup-file-location"},"Restore Using the Default Backup File Location"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-yaml"},"apiVersion: resources.cattle.io/v1\nkind: Restore\nmetadata:\n name: restore-default\nspec:\n backupFilename: default-location-recurring-backup-752ecd87-d958-4d20-8350-072f8d090045-2020-09-26T12-29-54-07-00.tar.gz\n# encryptionConfigSecretName: test-encryptionconfig\n")),(0,a.kt)("h3",{id:"restore-for-rancher-migration"},"Restore for Rancher Migration"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-yaml"},"apiVersion: resources.cattle.io/v1\nkind: Restore\nmetadata:\n name: restore-migration\nspec:\n backupFilename: backup-b0450532-cee1-4aa1-a881-f5f48a007b1c-2020-09-15T07-27-09Z.tar.gz\n prune: false\n storageLocation:\n s3:\n credentialSecretName: s3-creds\n credentialSecretNamespace: default\n bucketName: rancher-backups\n folder: ecm1\n region: us-west-2\n endpoint: s3.us-west-2.amazonaws.com\n")),(0,a.kt)("h3",{id:"restore-from-encrypted-backup"},"Restore from Encrypted Backup"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-yaml"},"apiVersion: resources.cattle.io/v1\nkind: Restore\nmetadata:\n name: restore-encrypted\nspec:\n backupFilename: default-test-s3-def-backup-c583d8f2-6daf-4648-8ead-ed826c591471-2020-08-24T20-47-05Z.tar.gz\n encryptionConfigSecretName: encryptionconfig\n")),(0,a.kt)("h3",{id:"restore-an-encrypted-backup-from-minio"},"Restore an Encrypted Backup from Minio"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-yaml"},"apiVersion: resources.cattle.io/v1\nkind: Restore\nmetadata:\n name: restore-minio\nspec:\n backupFilename: default-minio-backup-demo-aa5c04b7-4dba-4c48-9ac4-ab7916812eaa-2020-08-30T13-18-17-07-00.tar.gz\n storageLocation:\n s3:\n credentialSecretName: minio-creds\n credentialSecretNamespace: default\n bucketName: rancherbackups\n endpoint: minio.sslip.io\n endpointCA: LS0tLS1CRUdJTi3VUFNQkl5UUT.....pbEpWaVzNkRS0tLS0t\n encryptionConfigSecretName: test-encryptionconfig\n")),(0,a.kt)("h3",{id:"restore-from-backup-using-an-aws-credential-secret-to-access-s3"},"Restore from Backup Using an AWS Credential Secret to Access S3"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-yaml"},"apiVersion: resources.cattle.io/v1\nkind: Restore\nmetadata:\n name: restore-s3-demo\nspec:\n backupFilename: test-s3-recurring-backup-752ecd87-d958-4d20-8350-072f8d090045-2020-09-26T12-49-34-07-00.tar.gz.enc\n storageLocation:\n s3:\n credentialSecretName: s3-creds\n credentialSecretNamespace: default\n bucketName: rancher-backups\n folder: ecm1\n region: us-west-2\n endpoint: s3.us-west-2.amazonaws.com\n encryptionConfigSecretName: test-encryptionconfig\n")),(0,a.kt)("h3",{id:"restore-from-ec2-nodes-with-iam-permissions-to-access-s3"},"Restore from EC2 Nodes with IAM Permissions to Access S3"),(0,a.kt)("p",null,"This example shows that the AWS credential secret does not have to be provided to restore from backup if the nodes running ",(0,a.kt)("inlineCode",{parentName:"p"},"rancher-backup")," have ",(0,a.kt)("a",{parentName:"p",href:"/v2.5/reference-guides/backup-restore-configuration/backup-configuration#iam-permissions-for-ec2-nodes-to-access-s3"},"these permissions for access to S3.")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-yaml"},"apiVersion: resources.cattle.io/v1\nkind: Restore\nmetadata:\n name: restore-s3-demo\nspec:\n backupFilename: default-test-s3-recurring-backup-84bf8dd8-0ef3-4240-8ad1-fc7ec308e216-2020-08-24T10#52#44-07#00.tar.gz\n storageLocation:\n s3:\n bucketName: rajashree-backup-test\n folder: ecm1\n region: us-west-2\n endpoint: s3.us-west-2.amazonaws.com\n encryptionConfigSecretName: test-encryptionconfig\n")),(0,a.kt)("h2",{id:"example-credential-secret-for-storing-backups-in-s3"},"Example Credential Secret for Storing Backups in S3"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-yaml"},"apiVersion: v1\nkind: Secret\nmetadata:\n name: creds\ntype: Opaque\ndata:\n accessKey: <Enter your base64-encoded access key>\n secretKey: <Enter your base64-encoded secret key>\n")),(0,a.kt)("h2",{id:"example-encryptionconfiguration"},"Example EncryptionConfiguration"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-yaml"},"apiVersion: apiserver.config.k8s.io/v1\nkind: EncryptionConfiguration\nresources:\n - resources:\n - secrets\n providers:\n - aesgcm:\n keys:\n - name: key1\n secret: c2VjcmV0IGlzIHNlY3VyZQ==\n - name: key2\n secret: dGhpcyBpcyBwYXNzd29yZA==\n - aescbc:\n keys:\n - name: key1\n secret: c2VjcmV0IGlzIHNlY3VyZQ==\n - name: key2\n secret: dGhpcyBpcyBwYXNzd29yZA==\n - secretbox:\n keys:\n - name: key1\n secret: YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXoxMjM0NTY=\n")))}l.isMDXComponent=!0}}]); |