Velero
HashiCorp Velero install for cluster and persistent volume backup/restore, pre-wired for S3-compatible storage (default: MinIO).
Anchors the work in #111 (sharded Crossplane control planes) and #115 (restore hooks for provider readiness).
Prerequisites
- An S3-compatible bucket (MinIO, AWS S3, etc.) and credentials for it
- For ESO credential mode: External Secrets Operator installed and a
ClusterSecretStore(e.g. wired to Vaultsthings.lab)
Credential modes
The base layer creates the cloud-credentials Secret as a plain manifest (pre-release.yaml) from substitution variables. To read the pair from a ClusterSecretStore instead, a bundle cluster selects the velero-eso component in place of velero; other consumers enable the components/external-secret/ kustomize Component and delete the base Secret — see the README.
Trust bundle for self-signed S3 endpoints
The base mounts the trust-manager-published cluster-trust-bundle ConfigMap into the velero pod at /etc/ssl/custom with optional: true — harmless when no ConfigMap is published. To activate it, set VELERO_SSL_CERT_DIR=/etc/ssl/custom so Go's crypto/x509 reads the bundle instead of the system CA store. Empty default = system CAs. See the README for the trust-manager Bundle requirements.
ServiceMonitor prerequisite
VELERO_SERVICE_MONITOR_ENABLED=true requires the monitoring.coreos.com/v1 ServiceMonitor CRD — provided by kube-prometheus-stack or a standalone prometheus-operator install. The standalone prometheus Helm chart does not ship the CRD; enabling the toggle without the operator present causes the Helm install to fail with no matches for kind "ServiceMonitor". With no operator, leave the toggle off — the /metrics endpoint stays exposed on the velero Service and can be scraped via a static job.
Deployment
GitRepository
---
apiVersion: source.toolkit.fluxcd.io/v1
kind: GitRepository
metadata:
name: flux-apps
namespace: flux-system
spec:
interval: 1m0s
ref:
tag: <version>
url: https://github.com/stuttgart-things/flux.git
Kustomization (substitution mode)
---
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
name: velero
namespace: flux-system
spec:
interval: 1h
retryInterval: 1m
timeout: 10m
sourceRef:
kind: GitRepository
name: flux-apps
path: ./infra/velero
prune: true
wait: true
postBuild:
substitute:
VELERO_BUCKET: cluster-backups
VELERO_S3_ENDPOINT: https://minio.sthings.lab
VELERO_S3_REGION: minio
substituteFrom:
- kind: Secret
name: velero-s3-credentials # SOPS-encrypted, contains VELERO_S3_ACCESS_KEY / VELERO_S3_SECRET_KEY
Variables
| Variable | Default | Description |
|---|---|---|
VELERO_NAMESPACE |
velero |
Target namespace |
VELERO_VERSION |
9.0.0 |
velero Helm chart version |
VELERO_PLUGIN_AWS_VERSION |
v1.13.0 |
velero-plugin-for-aws image tag |
VELERO_BUCKET |
(required) | S3 bucket name |
VELERO_S3_ENDPOINT |
(required) | S3 endpoint URL |
VELERO_S3_REGION |
minio |
S3 region |
VELERO_S3_FORCE_PATH_STYLE |
true |
Path-style URLs (MinIO requirement) |
VELERO_S3_INSECURE_SKIP_TLS_VERIFY |
false |
Skip TLS verify on S3 endpoint |
VELERO_CREDENTIALS_SECRET_NAME |
cloud-credentials |
Secret consumed by Velero |
VELERO_S3_ACCESS_KEY |
(required, substitution mode) | MinIO access key |
VELERO_S3_SECRET_KEY |
(required, substitution mode) | MinIO secret key |
VELERO_SNAPSHOTS_ENABLED |
false |
Enable volume snapshots |
VELERO_DEPLOY_NODE_AGENT |
false |
Deploy node-agent for filesystem backup |
VELERO_METRICS_ENABLED |
true |
Expose Prometheus metrics |
VELERO_SERVICE_MONITOR_ENABLED |
false |
Create a Prometheus ServiceMonitor |
VELERO_ESO_SECRET_STORE_NAME |
vault-cluster |
ClusterSecretStore name (ESO mode) |
VELERO_ESO_SECRET_PATH |
velero |
KV entry name; the store supplies mount and version (ESO mode) |
See README for the full list, including all ESO mode variables.
Notes
- The Velero CRDs are installed by the chart;
cleanUpCRDs: falsekeeps them in place across uninstalls so that scheduled-backup metadata survives. velero-plugin-for-awsis used for all S3-compatible providers including MinIO — there is no separate MinIO plugin.- Scheduled backups are not defined in this base; create
Scheduleresources separately or extend the HelmReleasevalues.schedules.