Keeper¶
Keeper backs up Postgres and MySQL databases running in Kubernetes to any S3 bucket, streams every change, and restores any second of the retention window into a throwaway sandbox, a new database, or in place. Everything is a Kubernetes resource, every object is encrypted before it leaves the pod, and data moves only in short-lived Jobs.
-
Quickstart
Install the chart, point Keeper at a bucket, declare your first database and restore it, in about ten minutes.
-
Restore
Pick a time or a backup and a destination: a sandbox, a new database, a download, or in place.
-
Custom resources
Every field of
BackupStore,BackupPolicy,BackupTarget,Backup,RestoreandSandbox. -
REST API
The JSON API behind the console and the CLI, generated from its OpenAPI document.
-
CLI
keeper targets,diff,restore,sandbox connect,queryand the rest. -
On call
What each alert means and what to do about it, including restoring when Keeper itself is down.
At a glance¶
| Area | Details |
|---|---|
| Engines | Postgres 15, 16, 17 (incl. PostGIS): physical or logical backups plus WAL streaming. MySQL 8.4: logical backups plus binlog streaming. |
| Storage | Any S3-compatible bucket. zstd compression (on by default) and age encryption on the client, parallel multipart uploads, manifest written last. |
| Restore | Any second inside the point-in-time window, or any retained backup, into a sandbox, a new database, a download or in place. |
| Safety | Scheduled verification restores with your SQL checks, Prometheus alerts, a Grafana dashboard, and a chaos suite that kills Keeper mid-backup. |
| Footprint | One static binary for the controller, the API and console, the data movers and the CLI. Nothing heavy runs between backups. |
| Access | Console and CLI on one JSON API (OpenAPI), with roles from Cloudflare Access. Every write and query is audited. |