Skip to content

0008: Policy lookup, endpoint names and credential secret names

Date: 2026-10-07 · Status: accepted

Context

The design says a BackupPolicy is "cluster or namespace" scoped, but a CRD has a single scope. Data-path pods run in Keeper's namespace while targets live next to their databases. The design limits Keeper to secrets named keeper-* in target namespaces.

Decision

  • BackupPolicy is namespaced. A target's policy is looked up in the target's namespace first, then in Keeper's namespace, where the shared presets (prod, dev, critical) live.
  • A bare endpoint host (postgres) is qualified with the target's namespace (postgres.<ns>.svc).
  • Target credential secrets must be named with the prefix from KEEPER_SECRET_PREFIX (Helm secretPrefix, default keeper-). Keeper refuses other names. RBAC grants get secrets in the listed target namespaces.

Consequences

Shared presets need no copies per namespace. Targets can use short host names. A mis-named credential secret shows up as a clear status error on the target.