Install¶
Keeper is one Helm chart and one image. The image holds the keeper binary plus the Postgres 15/16/17 and MySQL 8.4
client tools the data movers run; the same binary is the CLI.
Get the image and the chart¶
Releases are built from tags only: a tag v1.2.3 publishes the image <registry>/keeper/keeper:v1.2.3, the chart
keeper:1.2.3 (OCI) and CLI binaries for Linux and macOS on the GitHub release. Nothing is published from main.
helm install keeper oci://registry.example.com/helm/keeper --version 1.2.3 -n keeper-system --create-namespace \
-f values.yaml
From a checkout, helm install keeper charts/keeper … works the same way.
Minimal values¶
image:
repository: registry.example.com/keeper/keeper
tag: v1.2.3
pullSecrets: [registry-pull] # also copied into sandbox namespaces
targetNamespaces: [team-a, team-b] # where BackupTargets and their keeper-* secrets live
examplePolicies: # prod, dev and critical presets in keeper-system
enabled: true
store: main
metrics:
serviceMonitor: { enabled: true }
prometheusRule: { enabled: true }
grafanaDashboard: { enabled: true }
Keeper ships no organization-specific defaults: every endpoint, hostname and credential is yours to set (ADR 0002). All values: Helm values.
Authentication and exposure¶
Both are pluggable and off by default.
| Setting | Values | What it does |
|---|---|---|
auth.provider |
none (development) · cloudflare-access |
Verifies the Cloudflare Access JWT on every console and API request and maps users and groups to roles. |
auth.roles |
viewer · operator · restorer · restorer-admin |
Who may look, back up and restore to a sandbox, restore to a new database or a download, and restore in place or pin. |
expose.provider |
none · cloudflare |
Publishes sandboxes as Cloudflare Tunnel TCP routes behind Access, so keeper sandbox connect works from a laptop. |
expose.cloudflared.enabled |
true / false |
Runs the cloudflared connector for the console route and the sandbox routes. |
See Console, CLI and access for the details.
What gets installed¶
| Object | Purpose |
|---|---|
| 6 CRDs | BackupStore, BackupPolicy, BackupTarget, Backup, Restore, Sandbox (reference) |
keeper-controller Deployment (2 replicas, leader election) |
schedules backups, runs streamers, restores, sandboxes, verification and garbage collection |
keeper-api Deployment (2 replicas) and Service |
the console, the JSON API and server-sent events |
| RBAC | cluster-wide read of Keeper resources; per target namespace, read of keeper-* secrets only |
| PrometheusRule, ServiceMonitor, Grafana dashboard | optional, see Monitoring |
Pods run as non-root with a read-only root filesystem, no privilege escalation and all capabilities dropped. Data moves only in Jobs (movers, restorers) and per-target streamer Deployments; the controller and the API never carry backup data.
Upgrades¶
helm upgrade replaces the CRDs (installCRDs: true) and rolls the controller and the API. Running backups finish
or retry: every data path is crash-only, and a backup only exists once its manifest is written.