Skip to content

Velero

HashiCorp Velero install for cluster and persistent volume backup/restore, pre-wired for S3-compatible storage (default: MinIO).

Anchors the work in #111 (sharded Crossplane control planes) and #115 (restore hooks for provider readiness).

Prerequisites

  • An S3-compatible bucket (MinIO, AWS S3, etc.) and credentials for it
  • For ESO credential mode: External Secrets Operator installed and a ClusterSecretStore (e.g. wired to Vault sthings.lab)

Credential modes

The base layer creates the cloud-credentials Secret as a plain manifest (pre-release.yaml) from substitution variables. To read the pair from a ClusterSecretStore instead, a bundle cluster selects the velero-eso component in place of velero; other consumers enable the components/external-secret/ kustomize Component and delete the base Secret — see the README.

Trust bundle for self-signed S3 endpoints

The base mounts the trust-manager-published cluster-trust-bundle ConfigMap into the velero pod at /etc/ssl/custom with optional: true — harmless when no ConfigMap is published. To activate it, set VELERO_SSL_CERT_DIR=/etc/ssl/custom so Go's crypto/x509 reads the bundle instead of the system CA store. Empty default = system CAs. See the README for the trust-manager Bundle requirements.

ServiceMonitor prerequisite

VELERO_SERVICE_MONITOR_ENABLED=true requires the monitoring.coreos.com/v1 ServiceMonitor CRD — provided by kube-prometheus-stack or a standalone prometheus-operator install. The standalone prometheus Helm chart does not ship the CRD; enabling the toggle without the operator present causes the Helm install to fail with no matches for kind "ServiceMonitor". With no operator, leave the toggle off — the /metrics endpoint stays exposed on the velero Service and can be scraped via a static job.

Deployment

GitRepository

---
apiVersion: source.toolkit.fluxcd.io/v1
kind: GitRepository
metadata:
  name: flux-apps
  namespace: flux-system
spec:
  interval: 1m0s
  ref:
    tag: <version>
  url: https://github.com/stuttgart-things/flux.git

Kustomization (substitution mode)

---
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
  name: velero
  namespace: flux-system
spec:
  interval: 1h
  retryInterval: 1m
  timeout: 10m
  sourceRef:
    kind: GitRepository
    name: flux-apps
  path: ./infra/velero
  prune: true
  wait: true
  postBuild:
    substitute:
      VELERO_BUCKET: cluster-backups
      VELERO_S3_ENDPOINT: https://minio.sthings.lab
      VELERO_S3_REGION: minio
    substituteFrom:
      - kind: Secret
        name: velero-s3-credentials   # SOPS-encrypted, contains VELERO_S3_ACCESS_KEY / VELERO_S3_SECRET_KEY

Variables

Variable Default Description
VELERO_NAMESPACE velero Target namespace
VELERO_VERSION 9.0.0 velero Helm chart version
VELERO_PLUGIN_AWS_VERSION v1.13.0 velero-plugin-for-aws image tag
VELERO_BUCKET (required) S3 bucket name
VELERO_S3_ENDPOINT (required) S3 endpoint URL
VELERO_S3_REGION minio S3 region
VELERO_S3_FORCE_PATH_STYLE true Path-style URLs (MinIO requirement)
VELERO_S3_INSECURE_SKIP_TLS_VERIFY false Skip TLS verify on S3 endpoint
VELERO_CREDENTIALS_SECRET_NAME cloud-credentials Secret consumed by Velero
VELERO_S3_ACCESS_KEY (required, substitution mode) MinIO access key
VELERO_S3_SECRET_KEY (required, substitution mode) MinIO secret key
VELERO_SNAPSHOTS_ENABLED false Enable volume snapshots
VELERO_DEPLOY_NODE_AGENT false Deploy node-agent for filesystem backup
VELERO_METRICS_ENABLED true Expose Prometheus metrics
VELERO_SERVICE_MONITOR_ENABLED false Create a Prometheus ServiceMonitor
VELERO_ESO_SECRET_STORE_NAME vault-cluster ClusterSecretStore name (ESO mode)
VELERO_ESO_SECRET_PATH velero KV entry name; the store supplies mount and version (ESO mode)

See README for the full list, including all ESO mode variables.

Notes

  • The Velero CRDs are installed by the chart; cleanUpCRDs: false keeps them in place across uninstalls so that scheduled-backup metadata survives.
  • velero-plugin-for-aws is used for all S3-compatible providers including MinIO — there is no separate MinIO plugin.
  • Scheduled backups are not defined in this base; create Schedule resources separately or extend the HelmRelease values.schedules.