Custom resources¶
Packages¶
keeper.republic.global/v1alpha1¶
Package v1alpha1 contains the Keeper custom resource types (API group keeper.republic.global).
Resource Types¶
Backup¶
Backup is one full backup run.
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string |
keeper.republic.global/v1alpha1 |
||
kind string |
Backup |
||
metadata ObjectMeta |
Refer to Kubernetes API documentation for fields of metadata. |
||
spec BackupSpec |
|||
status BackupStatus |
BackupPolicy¶
BackupPolicy holds schedules, retention and limits. Targets look a policy up in their own namespace first, then in Keeper's namespace (shared presets).
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string |
keeper.republic.global/v1alpha1 |
||
kind string |
BackupPolicy |
||
metadata ObjectMeta |
Refer to Kubernetes API documentation for fields of metadata. |
||
spec BackupPolicySpec |
|||
status BackupPolicyStatus |
BackupPolicySpec¶
BackupPolicySpec is shared configuration for many targets.
Appears in: - BackupPolicy
| Field | Description | Default | Validation |
|---|---|---|---|
store string |
BackupStore name. | ||
full FullSchedule |
|||
pitr PITRSpec |
Optional: {} |
||
retain RetainSpec |
Optional: {} |
||
limits LimitsSpec |
Optional: {} |
||
loadGuard LoadGuardSpec |
Optional: {} |
||
verify VerifySpec |
Optional: {} |
||
jobs JobSpec |
Optional: {} |
||
compression CompressionSpec |
Compression of backup data (on by default: zstd, level default). | Optional: {} |
|
sandbox SandboxPolicy |
Optional: {} |
||
keepBackupObjects integer |
How many Backup objects to keep per target in the API server (S3 keeps everything). Default 20. | Optional: {} |
BackupPolicyStatus¶
BackupPolicyStatus reports validation.
Appears in: - BackupPolicy
| Field | Description | Default | Validation |
|---|---|---|---|
phase string |
Optional: {} |
||
message string |
Optional: {} |
||
observedGeneration integer |
Optional: {} |
||
conditions Condition array |
Optional: {} |
BackupRef¶
BackupRef is a short reference to a backup.
Appears in: - BackupTargetStatus
| Field | Description | Default | Validation |
|---|---|---|---|
name string |
Optional: {} |
||
id string |
Optional: {} |
||
time Time |
Optional: {} |
||
phase string |
Optional: {} |
BackupSpec¶
BackupSpec requests one full backup run. Backups imported from S3 carry spec.backupID.
Appears in: - Backup
| Field | Description | Default | Validation |
|---|---|---|---|
target string |
BackupTarget name in the same namespace. | ||
reason string |
Optional: {} |
||
requestedBy string |
Optional: {} |
||
backupID string |
Set for backups that already exist in S3 (catalog import); the controller then only mirrors them. | Optional: {} |
|
pinned boolean |
Retention hold. | Optional: {} |
|
pinReason string |
Optional: {} |
||
pinExpires Time |
Optional: {} |
||
skipLoadGuard boolean |
Skip the load guard (manual runs may set it). | Optional: {} |
BackupStatus¶
BackupStatus reports a run.
Appears in: - Backup
| Field | Description | Default | Validation |
|---|---|---|---|
phase string |
Optional: {} |
||
message string |
Optional: {} |
||
observedGeneration integer |
Optional: {} |
||
conditions Condition array |
Optional: {} |
||
backupID string |
Optional: {} |
||
manifestKey string |
Optional: {} |
||
queuedTime Time |
Optional: {} |
||
startTime Time |
Optional: {} |
||
completionTime Time |
Optional: {} |
||
bytes integer |
Optional: {} |
||
compressedBytes integer |
Optional: {} |
||
durationSeconds integer |
Optional: {} |
||
startLSN string |
Optional: {} |
||
endLSN string |
Optional: {} |
||
binlogFile string |
Optional: {} |
||
binlogPos integer |
Optional: {} |
||
gtidSet string |
Optional: {} |
||
inventorySummary InventorySummary |
Optional: {} |
||
tiers string array |
Optional: {} |
||
verified boolean |
Optional: {} |
||
verifiedTime Time |
Optional: {} |
||
postpones integer |
Optional: {} |
||
postponedUntil Time |
Optional: {} |
||
attempts integer |
Optional: {} |
||
jobName string |
Optional: {} |
||
warnings string array |
Optional: {} |
||
progress Progress |
Optional: {} |
||
priority integer |
Optional: {} |
||
serverKey string |
Optional: {} |
||
pinSynced boolean |
Optional: {} |
BackupStore¶
BackupStore is an S3 bucket plus encryption recipients.
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string |
keeper.republic.global/v1alpha1 |
||
kind string |
BackupStore |
||
metadata ObjectMeta |
Refer to Kubernetes API documentation for fields of metadata. |
||
spec BackupStoreSpec |
|||
status BackupStoreStatus |
BackupStoreSpec¶
BackupStoreSpec defines where backups go.
Appears in: - BackupStore
| Field | Description | Default | Validation |
|---|---|---|---|
s3 S3Spec |
|||
prefix string |
Key prefix inside the bucket, for example "cluster-a/". | Optional: {} |
|
encryption EncryptionSpec |
|||
upload UploadSpec |
Optional: {} |
||
readOnly boolean |
Read-only stores are browsed and restored from but never written or garbage collected (shared across clusters). |
Optional: {} |
BackupStoreStatus¶
BackupStoreStatus reports store reachability.
Appears in: - BackupStore
| Field | Description | Default | Validation |
|---|---|---|---|
phase string |
Optional: {} |
||
message string |
Optional: {} |
||
observedGeneration integer |
Optional: {} |
||
conditions Condition array |
Optional: {} |
||
lastCheckTime Time |
Optional: {} |
||
lastGCTime Time |
Optional: {} |
||
lastGCDeleted integer |
Optional: {} |
||
lastGCPlanKey string |
Optional: {} |
BackupTarget¶
BackupTarget is one database server to protect; it lives next to the database.
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string |
keeper.republic.global/v1alpha1 |
||
kind string |
BackupTarget |
||
metadata ObjectMeta |
Refer to Kubernetes API documentation for fields of metadata. |
||
spec BackupTargetSpec |
|||
status BackupTargetStatus |
BackupTargetSpec¶
BackupTargetSpec describes one database server (or a subset of its databases).
Appears in: - BackupTarget
| Field | Description | Default | Validation |
|---|---|---|---|
engine string |
Enum: [postgres mysql mongodb] |
||
endpoint Endpoint |
|||
databases string array |
Databases to back up; ["*"] (default) means all non-template databases. | Optional: {} |
|
credentials TargetCredentials |
|||
policy string |
BackupPolicy name. | ||
pitr PITRSpec |
Overrides the policy's PITR setting. | Optional: {} |
|
scope ScopeSpec |
Optional: {} |
||
checks TargetCheck array |
Optional: {} |
||
mask string array |
Column name regexes masked in previews and the table browser, for example [email, phone, "password.*"]. | Optional: {} |
|
previews PreviewSpec |
Optional: {} |
||
sandbox SandboxTemplate |
Optional: {} |
||
exactCounts ExactCountSpec |
Optional: {} |
||
suspend boolean |
Pause scheduled backups and streams. | Optional: {} |
BackupTargetStatus¶
BackupTargetStatus reports the target's backup state.
Appears in: - BackupTarget
| Field | Description | Default | Validation |
|---|---|---|---|
phase string |
Optional: {} |
||
message string |
Optional: {} |
||
observedGeneration integer |
Optional: {} |
||
conditions Condition array |
Optional: {} |
||
lastBackup BackupRef |
Optional: {} |
||
lastSuccessTime Time |
Optional: {} |
||
lastScheduleTime Time |
Optional: {} |
||
nextRunTime Time |
Optional: {} |
||
lastVerification BackupRef |
Optional: {} |
||
lastVerifyScheduleTime Time |
Optional: {} |
||
pitr PITRStatus |
Optional: {} |
||
serverVersion string |
Optional: {} |
||
storeBytes integer |
Optional: {} |
||
handledBackupNow string |
Optional: {} |
||
handledVerifyNow string |
Optional: {} |
||
prefix string |
Key prefix of this target in the store. | Optional: {} |
CheckResult¶
CheckResult is the outcome of one check.
Appears in: - RestoreStatus
| Field | Description | Default | Validation |
|---|---|---|---|
name string |
|||
passed boolean |
|||
message string |
Optional: {} |
CommonStatus¶
CommonStatus is embedded in every status.
Appears in: - BackupPolicyStatus - BackupStatus - BackupStoreStatus - BackupTargetStatus - RestoreStatus - SandboxStatus
| Field | Description | Default | Validation |
|---|---|---|---|
phase string |
Optional: {} |
||
message string |
Optional: {} |
||
observedGeneration integer |
Optional: {} |
||
conditions Condition array |
Optional: {} |
CompressionSpec¶
CompressionSpec tunes how backup data is compressed before it is encrypted (ADR 0013).
Appears in: - BackupPolicySpec
| Field | Description | Default | Validation |
|---|---|---|---|
algorithm string |
Algorithm: zstd (default) or none. Use none only for data that is already compressed, or when the Job's CPU is the bottleneck and the network is not. |
Enum: [zstd none] Optional: {} |
|
level string |
Level: fastest, default (the default), better or best. Higher levels store less and use more CPU; restores decompress at the same speed whatever the level. |
Enum: [fastest default better best] Optional: {} |
|
threads integer |
Threads per mover (0: one per CPU of the Job's limit). Streamers use one thread unless this is set. | Maximum: 64 Minimum: 0 Optional: {} |
Duration¶
Underlying type: string
Duration is a duration string that also accepts days and weeks ("7d", "2w", "36h", "15m").
Validation:
- Pattern: ^([0-9]+(\.[0-9]+)?(ns|us|ms|s|m|h|d|w))+$
Appears in: - ExactCountSpec - FullSchedule - JobSpec - LoadGuardSpec - PITRSpec - SandboxDestination - SandboxPolicy - SandboxSpec
EncryptionSpec¶
EncryptionSpec configures client-side age encryption.
Appears in: - BackupStoreSpec
| Field | Description | Default | Validation |
|---|---|---|---|
ageRecipients string array |
age X25519 recipients (public keys). Every data object is encrypted to all of them. | MinItems: 1 |
|
identitySecret SecretKeyRef |
Secret holding the age identity (private key) under key "identity". Only restorer Jobs read it. | Optional: {} |
|
catalogRecipients string array |
Extra recipients for catalog objects only (inventories and masked previews, never dumps or WAL). The console decrypts them with catalogIdentitySecret (ADR 0009). |
Optional: {} |
|
catalogIdentitySecret SecretKeyRef |
Secret with the catalog identity under key "identity" (read by keeper-api). | Optional: {} |
Endpoint¶
Endpoint is a database network address.
Appears in: - BackupTargetSpec - NewDatabaseDestination
| Field | Description | Default | Validation |
|---|---|---|---|
host string |
|||
port integer |
Optional: {} |
ExactCountSpec¶
ExactCountSpec enables count(*) for small tables during inspection.
Appears in: - BackupTargetSpec
| Field | Description | Default | Validation |
|---|---|---|---|
enabled boolean |
Optional: {} |
||
maxRows integer |
Only tables with an estimate below this. Default 100000. | Optional: {} |
|
timeout Duration |
Per-query timeout. Default 5s. | Pattern: ^([0-9]+(\.[0-9]+)?(ns\|us\|ms\|s\|m\|h\|d\|w))+$ Optional: {} |
ExportQuery¶
ExportQuery is a selective export stored as CSV next to the dump.
Appears in: - ScopeSpec
| Field | Description | Default | Validation |
|---|---|---|---|
name string |
|||
database string |
Optional: {} |
||
sql string |
FullSchedule¶
FullSchedule configures scheduled full backups.
Appears in: - BackupPolicySpec
| Field | Description | Default | Validation |
|---|---|---|---|
schedule string |
Cron expression (5 fields). | ||
timeZone string |
IANA time zone for the schedule and for tier assignment. Default UTC. | Optional: {} |
|
jitter Duration |
Maximum deterministic per-target offset added to the schedule, for example 20m. | Pattern: ^([0-9]+(\.[0-9]+)?(ns\|us\|ms\|s\|m\|h\|d\|w))+$ Optional: {} |
|
startingDeadline Duration |
A missed run is executed once on start if it is not older than this. Default 6h. | Pattern: ^([0-9]+(\.[0-9]+)?(ns\|us\|ms\|s\|m\|h\|d\|w))+$ Optional: {} |
InPlaceDestination¶
InPlaceDestination restores over the original target.
Appears in: - RestoreDestination
| Field | Description | Default | Validation |
|---|---|---|---|
confirm string |
Must equal the target name. | ||
credentialsSecretRef LocalSecretRef |
Admin user able to drop and recreate the databases, in the target's namespace. | ||
skipSafetyBackup boolean |
Skip the automatic safety backup (not recommended). | Optional: {} |
InventorySummary¶
InventorySummary is a short inventory.
Appears in: - BackupStatus
| Field | Description | Default | Validation |
|---|---|---|---|
databases integer |
Optional: {} |
||
tables integer |
Optional: {} |
||
rowsEstimate integer |
Optional: {} |
||
schemaHash string |
Optional: {} |
||
migrationVersion string |
Optional: {} |
JobSpec¶
JobSpec tunes mover/restorer Jobs.
Appears in: - BackupPolicySpec
| Field | Description | Default | Validation |
|---|---|---|---|
activeDeadline Duration |
Pattern: ^([0-9]+(\.[0-9]+)?(ns\|us\|ms\|s\|m\|h\|d\|w))+$ Optional: {} |
||
backoffLimit integer |
Optional: {} |
||
stallTimeout Duration |
Watchdog: abort when no bytes flow for this long. Default 60s. | Pattern: ^([0-9]+(\.[0-9]+)?(ns\|us\|ms\|s\|m\|h\|d\|w))+$ Optional: {} |
|
cpu string |
Optional: {} |
||
memory string |
Optional: {} |
LimitsSpec¶
LimitsSpec bounds concurrency and bandwidth.
Appears in: - BackupPolicySpec
| Field | Description | Default | Validation |
|---|---|---|---|
perHost integer |
Optional: {} |
||
perTarget integer |
Optional: {} |
||
global integer |
Optional: {} |
||
bandwidth string |
Upload rate limit per mover, for example 200Mi (bytes per second). | Optional: {} |
|
restoreBandwidth string |
Download rate limit per restorer. | Optional: {} |
|
priority integer |
Higher runs first. | Optional: {} |
LoadGuardSpec¶
LoadGuardSpec postpones backups when the server is busy.
Appears in: - BackupPolicySpec
| Field | Description | Default | Validation |
|---|---|---|---|
maxActiveConnections integer |
Optional: {} |
||
maxReplicationLagSeconds integer |
Optional: {} |
||
maxLongTransactionSeconds integer |
Optional: {} |
||
postponeFor Duration |
Pattern: ^([0-9]+(\.[0-9]+)?(ns\|us\|ms\|s\|m\|h\|d\|w))+$ Optional: {} |
||
maxPostpones integer |
Optional: {} |
LocalSecretRef¶
LocalSecretRef points at a Secret in the same namespace with configurable keys.
Appears in: - InPlaceDestination - NewDatabaseDestination - TargetCredentials
| Field | Description | Default | Validation |
|---|---|---|---|
name string |
|||
usernameKey string |
Key holding the user name. Default "username". | Optional: {} |
|
passwordKey string |
Key holding the password. Default "password". | Optional: {} |
NamespacedName¶
NamespacedName references a namespaced object.
Appears in: - SandboxSource
| Field | Description | Default | Validation |
|---|---|---|---|
namespace string |
|||
name string |
NewDatabaseDestination¶
NewDatabaseDestination writes into a new database on an existing server.
Appears in: - RestoreDestination
| Field | Description | Default | Validation |
|---|---|---|---|
endpoint Endpoint |
|||
database string |
Name of the database to create. With several source databases, " |
||
credentialsSecretRef LocalSecretRef |
Admin user able to create the database, in the Restore's namespace. |
PITRSpec¶
PITRSpec configures continuous change capture.
Appears in: - BackupPolicySpec - BackupTargetSpec
| Field | Description | Default | Validation |
|---|---|---|---|
enabled boolean |
Optional: {} |
||
window Duration |
How far back point-in-time restore must reach, for example 7d. | Pattern: ^([0-9]+(\.[0-9]+)?(ns\|us\|ms\|s\|m\|h\|d\|w))+$ Optional: {} |
|
partialInterval Duration |
How often the streamer uploads the segment that is still being written, so recent seconds are restorable. Default 60s. |
Pattern: ^([0-9]+(\.[0-9]+)?(ns\|us\|ms\|s\|m\|h\|d\|w))+$ Optional: {} |
PITRStatus¶
PITRStatus reports the change stream.
Appears in: - BackupTargetStatus
| Field | Description | Default | Validation |
|---|---|---|---|
enabled boolean |
Optional: {} |
||
chainBroken boolean |
Optional: {} |
||
brokenSince Time |
Optional: {} |
||
brokenReason string |
Optional: {} |
||
windowStart Time |
Optional: {} |
||
windowEnd Time |
Optional: {} |
||
lastSegment string |
Optional: {} |
||
lagSeconds integer |
Optional: {} |
||
streamerReady boolean |
Optional: {} |
PreviewSpec¶
PreviewSpec configures masked row previews in change summaries.
Appears in: - BackupTargetSpec
| Field | Description | Default | Validation |
|---|---|---|---|
enabled boolean |
Default true for MySQL; Postgres row previews need Logical. | Optional: {} |
|
rows integer |
Rows per table per segment. Default 5. | Optional: {} |
|
logical boolean |
Postgres only: stream a logical (pgoutput) slot for row previews. Retains extra WAL. Default false. | Optional: {} |
|
maxValueLength integer |
Maximum characters per value. Default 64. | Optional: {} |
Progress¶
Progress is reported by movers and restorers.
Appears in: - BackupStatus - RestoreStatus
| Field | Description | Default | Validation |
|---|---|---|---|
stage string |
Optional: {} |
||
bytes integer |
Optional: {} |
||
totalBytes integer |
Optional: {} |
||
updatedAt Time |
Optional: {} |
Restore¶
Restore is a restore request.
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string |
keeper.republic.global/v1alpha1 |
||
kind string |
Restore |
||
metadata ObjectMeta |
Refer to Kubernetes API documentation for fields of metadata. |
||
spec RestoreSpec |
|||
status RestoreStatus |
RestoreDestination¶
RestoreDestination selects the restore mode.
Appears in: - RestoreSpec
| Field | Description | Default | Validation |
|---|---|---|---|
mode string |
Enum: [sandbox new in-place download] |
||
sandbox SandboxDestination |
Optional: {} |
||
new NewDatabaseDestination |
Optional: {} |
||
inPlace InPlaceDestination |
Optional: {} |
||
tables string array |
Only these tables (table-level restore). | Optional: {} |
RestorePlanStatus¶
RestorePlanStatus summarizes the computed plan.
Appears in: - RestoreStatus
| Field | Description | Default | Validation |
|---|---|---|---|
baseBackupID string |
Optional: {} |
||
segments integer |
Optional: {} |
||
targetTime Time |
Optional: {} |
||
bytes integer |
Optional: {} |
||
message string |
Optional: {} |
RestoreSource¶
RestoreSource picks what to restore: a backup ID, a point in time, or the latest restorable state.
Appears in: - RestoreSpec
| Field | Description | Default | Validation |
|---|---|---|---|
backupID string |
Optional: {} |
||
time Time |
Optional: {} |
||
latest boolean |
Optional: {} |
||
targetNamespace string |
Restore from a target in another namespace (for example into a sandbox requested elsewhere). | Optional: {} |
RestoreSpec¶
RestoreSpec requests a restore.
Appears in: - Restore
| Field | Description | Default | Validation |
|---|---|---|---|
target string |
BackupTarget name (namespace: source.targetNamespace or the Restore's namespace). | ||
source RestoreSource |
|||
destination RestoreDestination |
|||
runChecks boolean |
Run inventory comparison and target checks after restore. Default true. | Optional: {} |
|
checks string array |
Built-in checks for verification restores. | Optional: {} |
|
reason string |
Optional: {} |
||
requestedBy string |
Optional: {} |
RestoreStatus¶
RestoreStatus reports progress.
Appears in: - Restore
| Field | Description | Default | Validation |
|---|---|---|---|
phase string |
Optional: {} |
||
message string |
Optional: {} |
||
observedGeneration integer |
Optional: {} |
||
conditions Condition array |
Optional: {} |
||
plan RestorePlanStatus |
Optional: {} |
||
sandboxName string |
Optional: {} |
||
safetyBackup string |
Optional: {} |
||
jobName string |
Optional: {} |
||
attempts integer |
Optional: {} |
||
startTime Time |
Optional: {} |
||
completionTime Time |
Optional: {} |
||
durationSeconds integer |
Optional: {} |
||
checks CheckResult array |
Optional: {} |
||
downloadURL string |
Optional: {} |
||
downloadExpires Time |
Optional: {} |
||
progress Progress |
Optional: {} |
RetainSpec¶
RetainSpec is the tiered retention.
Appears in: - BackupPolicySpec
| Field | Description | Default | Validation |
|---|---|---|---|
daily integer |
Optional: {} |
||
weekly integer |
Optional: {} |
||
monthly integer |
Optional: {} |
||
yearly integer |
Optional: {} |
S3CredentialsRef¶
S3CredentialsRef points at the S3 credentials secret.
Appears in: - S3Spec
| Field | Description | Default | Validation |
|---|---|---|---|
namespace string |
Optional: {} |
||
name string |
|||
accessKeyIdKey string |
Optional: {} |
||
secretAccessKeyKey string |
Optional: {} |
S3Spec¶
S3Spec configures an S3-compatible bucket. Endpoint and region are required: Keeper has no default provider.
Appears in: - BackupStoreSpec
| Field | Description | Default | Validation |
|---|---|---|---|
endpoint string |
Endpoint URL, for example https://s3.example.com. http:// is allowed for in-cluster test stores. | MinLength: 1 |
|
region string |
MinLength: 1 |
||
bucket string |
MinLength: 1 |
||
pathStyle boolean |
Path-style addressing (bucket in the path instead of the host name). | Optional: {} |
|
credentialsSecret S3CredentialsRef |
Secret with keys accessKeyId and secretAccessKey (names configurable). | ||
disableConditionalPut boolean |
Disable conditional PUT (If-None-Match) for manifests; Keeper then writes and reads back. | Optional: {} |
Sandbox¶
Sandbox is an isolated, expiring database restored from a backup.
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string |
keeper.republic.global/v1alpha1 |
||
kind string |
Sandbox |
||
metadata ObjectMeta |
Refer to Kubernetes API documentation for fields of metadata. |
||
spec SandboxSpec |
|||
status SandboxStatus |
SandboxDestination¶
SandboxDestination restores into a sandbox.
Appears in: - RestoreDestination
| Field | Description | Default | Validation |
|---|---|---|---|
name string |
Existing Sandbox name; empty creates one. | Optional: {} |
|
ttl Duration |
Pattern: ^([0-9]+(\.[0-9]+)?(ns\|us\|ms\|s\|m\|h\|d\|w))+$ Optional: {} |
||
expose boolean |
Expose through the configured exposure provider (Cloudflare Tunnel). | Optional: {} |
|
deleteAfter boolean |
Delete the sandbox when the restore finishes (verification). | Optional: {} |
SandboxPolicy¶
SandboxPolicy bounds sandboxes created from targets that use the policy.
Appears in: - BackupPolicySpec
| Field | Description | Default | Validation |
|---|---|---|---|
defaultTTL Duration |
Pattern: ^([0-9]+(\.[0-9]+)?(ns\|us\|ms\|s\|m\|h\|d\|w))+$ Optional: {} |
||
maxTTL Duration |
Pattern: ^([0-9]+(\.[0-9]+)?(ns\|us\|ms\|s\|m\|h\|d\|w))+$ Optional: {} |
SandboxSource¶
SandboxSource is where the sandbox's data comes from.
Appears in: - SandboxSpec
| Field | Description | Default | Validation |
|---|---|---|---|
targetNamespace string |
Optional: {} |
||
target string |
Optional: {} |
||
backupID string |
Optional: {} |
||
time Time |
Optional: {} |
||
restoreRef NamespacedName |
Restore that fills this sandbox (set when a Restore created it). | Optional: {} |
SandboxSpec¶
SandboxSpec describes an ephemeral database.
Appears in: - Sandbox
| Field | Description | Default | Validation |
|---|---|---|---|
engine string |
Enum: [postgres mysql mongodb] |
||
image string |
Optional: {} |
||
ttl Duration |
Pattern: ^([0-9]+(\.[0-9]+)?(ns\|us\|ms\|s\|m\|h\|d\|w))+$ Optional: {} |
||
owner string |
Optional: {} |
||
source SandboxSource |
Optional: {} |
||
sizeLimit string |
Optional: {} |
||
storageClass string |
Optional: {} |
||
cpu string |
Optional: {} |
||
memory string |
Optional: {} |
||
expose boolean |
Expose through the configured exposure provider. | Optional: {} |
|
physical boolean |
Physical (Postgres base backup + WAL) restores fill the data directory before the database starts. | Optional: {} |
|
major integer |
Postgres server major for physical restores. | Optional: {} |
|
extensions Duration array |
Extra time added to the TTL by "extend". | Pattern: ^([0-9]+(\.[0-9]+)?(ns\|us\|ms\|s\|m\|h\|d\|w))+$ Optional: {} |
|
resetGeneration integer |
Generation counter: bumping it recreates the database pod with an empty data directory. | Optional: {} |
SandboxStatus¶
SandboxStatus reports the sandbox lifecycle.
Appears in: - Sandbox
| Field | Description | Default | Validation |
|---|---|---|---|
phase string |
Optional: {} |
||
message string |
Optional: {} |
||
observedGeneration integer |
Optional: {} |
||
conditions Condition array |
Optional: {} |
||
namespace string |
Optional: {} |
||
host string |
Optional: {} |
||
port integer |
Optional: {} |
||
database string |
Optional: {} |
||
credentialsSecret string |
Secret in the sandbox namespace holding username and password. | Optional: {} |
|
expireTime Time |
Optional: {} |
||
readyTime Time |
Optional: {} |
||
route string |
Optional: {} |
||
restoreName string |
Optional: {} |
||
expiringSince Time |
Optional: {} |
||
observedResetGeneration integer |
Optional: {} |
||
receiverPort integer |
Optional: {} |
SandboxTemplate¶
SandboxTemplate configures sandboxes restored from this target.
Appears in: - BackupTargetSpec
| Field | Description | Default | Validation |
|---|---|---|---|
image string |
Database image for sandboxes, for example postgis/postgis:16-3.4. Default: postgres: |
Optional: {} |
|
sizeLimit string |
emptyDir size limit. Default 2x the backup size, at least 1Gi. | Optional: {} |
|
storageClass string |
Use a PVC of this storage class instead of emptyDir. | Optional: {} |
|
cpu string |
Optional: {} |
||
memory string |
Optional: {} |
||
postRestoreSQL string array |
SQL run in the sandbox after restore, for example masking scripts. | Optional: {} |
ScopeSpec¶
ScopeSpec selects what a backup contains.
Appears in: - BackupTargetSpec
| Field | Description | Default | Validation |
|---|---|---|---|
mode string |
physical (default for Postgres: pg_basebackup) or logical (pg_dump / mysqldump). MySQL is always logical. | Enum: [physical logical ] Optional: {} |
|
excludeData string array |
Tables whose data is not dumped (schema is). Logical mode only. "table" or "schema.table". | Optional: {} |
|
excludeTables string array |
Tables left out entirely. Logical mode only. | Optional: {} |
|
queries ExportQuery array |
Optional: {} |
SecretKeyRef¶
SecretKeyRef points at a Secret, optionally in another namespace.
Appears in: - EncryptionSpec
| Field | Description | Default | Validation |
|---|---|---|---|
namespace string |
Namespace of the secret. Defaults to the namespace of the referencing object (or Keeper's namespace for cluster-scoped objects). |
Optional: {} |
|
name string |
|||
optional boolean |
Optional: {} |
TargetCheck¶
TargetCheck is a SQL check that must return a single true value after a restore.
Appears in: - BackupTargetSpec
| Field | Description | Default | Validation |
|---|---|---|---|
name string |
|||
database string |
Optional: {} |
||
sql string |
TargetCredentials¶
TargetCredentials references the database users Keeper uses.
Appears in: - BackupTargetSpec
| Field | Description | Default | Validation |
|---|---|---|---|
secretRef LocalSecretRef |
Read-only backup user (Postgres pg_read_all_data + pg_monitor; MySQL SELECT, SHOW VIEW, TRIGGER, EVENT, LOCK TABLES, PROCESS, RELOAD, REPLICATION CLIENT). |
||
replicationSecretRef LocalSecretRef |
Replication user for change streams and physical backups (Postgres REPLICATION; MySQL REPLICATION SLAVE, REPLICATION CLIENT). Defaults to secretRef. |
Optional: {} |
UploadSpec¶
UploadSpec tunes multipart uploads.
Appears in: - BackupStoreSpec
| Field | Description | Default | Validation |
|---|---|---|---|
partSize string |
Part size, default 16Mi. | Optional: {} |
|
concurrency integer |
Parallel parts, default 8. | Optional: {} |
VerifySpec¶
VerifySpec configures scheduled verification restores.
Appears in: - BackupPolicySpec
| Field | Description | Default | Validation |
|---|---|---|---|
schedule string |
Optional: {} |
||
timeZone string |
Optional: {} |
||
checks string array |
Built-in checks: inventory-matches, schema-matches, row-estimates-within-10pct (any NN), target-checks. | Optional: {} |
|
randomPointInTime boolean |
Also restore to a random point inside the PITR window when streams exist. Default true. | Optional: {} |