Skip to content

Install

Keeper is one Helm chart and one image. The image holds the keeper binary plus the Postgres 15/16/17 and MySQL 8.4 client tools the data movers run; the same binary is the CLI.

Get the image and the chart

Releases are built from tags only: a tag v1.2.3 publishes the image <registry>/keeper/keeper:v1.2.3, the chart keeper:1.2.3 (OCI) and CLI binaries for Linux and macOS on the GitHub release. Nothing is published from main.

helm install keeper oci://registry.example.com/helm/keeper --version 1.2.3 -n keeper-system --create-namespace \
  -f values.yaml

From a checkout, helm install keeper charts/keeper … works the same way.

Minimal values

values.yaml
image:
  repository: registry.example.com/keeper/keeper
  tag: v1.2.3
  pullSecrets: [registry-pull]        # also copied into sandbox namespaces
targetNamespaces: [team-a, team-b]    # where BackupTargets and their keeper-* secrets live
examplePolicies:                      # prod, dev and critical presets in keeper-system
  enabled: true
  store: main
metrics:
  serviceMonitor: { enabled: true }
  prometheusRule: { enabled: true }
  grafanaDashboard: { enabled: true }

Keeper ships no organization-specific defaults: every endpoint, hostname and credential is yours to set (ADR 0002). All values: Helm values.

Authentication and exposure

Both are pluggable and off by default.

Setting Values What it does
auth.provider none (development) · cloudflare-access Verifies the Cloudflare Access JWT on every console and API request and maps users and groups to roles.
auth.roles viewer · operator · restorer · restorer-admin Who may look, back up and restore to a sandbox, restore to a new database or a download, and restore in place or pin.
expose.provider none · cloudflare Publishes sandboxes as Cloudflare Tunnel TCP routes behind Access, so keeper sandbox connect works from a laptop.
expose.cloudflared.enabled true / false Runs the cloudflared connector for the console route and the sandbox routes.

See Console, CLI and access for the details.

What gets installed

Object Purpose
6 CRDs BackupStore, BackupPolicy, BackupTarget, Backup, Restore, Sandbox (reference)
keeper-controller Deployment (2 replicas, leader election) schedules backups, runs streamers, restores, sandboxes, verification and garbage collection
keeper-api Deployment (2 replicas) and Service the console, the JSON API and server-sent events
RBAC cluster-wide read of Keeper resources; per target namespace, read of keeper-* secrets only
PrometheusRule, ServiceMonitor, Grafana dashboard optional, see Monitoring

Pods run as non-root with a read-only root filesystem, no privilege escalation and all capabilities dropped. Data moves only in Jobs (movers, restorers) and per-target streamer Deployments; the controller and the API never carry backup data.

Upgrades

helm upgrade replaces the CRDs (installCRDs: true) and rolls the controller and the API. Running backups finish or retry: every data path is crash-only, and a backup only exists once its manifest is written.