Learn KOP - Part 2 - Create Backup Resources - Rafay Product Documentation

Part 2: Create Resources

This is Part 2 of a multi-part, self-paced quick start exercise.


What Will You Do

In part 2, you will setup the backup/restore resources in order to perform backup and restore operations. You will:


Step 1: Create IRSAs

In this step, we will create an IRSA for each cluster that will perform backup/restore operations in order to provide the backup/restore pods with the appropriate permissions needed to access the Amazon S3 bucket which will store the backup data.

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "ec2:DescribeVolumes",
                "ec2:DescribeSnapshots",
                "ec2:CreateTags",
                "ec2:CreateVolume",
                "ec2:CreateSnapshot",
                "ec2:DeleteSnapshot"
            ],
            "Resource": "*"
        },
        {
            "Effect": "Allow",
            "Action": [
                "s3:GetObject",
                "s3:DeleteObject",
                "s3:PutObject",
                "s3:AbortMultipartUpload",
                "s3:ListMultipartUploadParts"
            ],
            "Resource": [
                "arn:aws:s3:::<bucket_name>/*"
            ]
        },
        {
            "Effect": "Allow",
            "Action": [
                "s3:ListBucket"
            ],
            "Resource": [
                "arn:aws:s3:::<bucket_name>"
            ]
        }
    ]
}
    rctl create iam-service-account <cluster-name> --name velero-rafay --namespace rafay-system --policy-document backup-iam-policy.json --role-only
IAM role for serviceaccount "rafay-system/velero-rafay" [created and managed by Rafay]

Step 2: Create Backup Cloud Credential

In this step, you will create cloud credentials for each of the clusters that will perform backup or restore operations. You will need the IAM role ARNs from the previous step in order to create the cloud credentials for each cluster.

Perform the following steps for each cluster where backup or restore operations will be performed. Ensure to use the IAM Role ARN from the previous step for each cluster's cloud credential.

Alternatively, you can create the cloud credential using RCTL and build this into an automation pipeline. The following command could be used ensuring the credential name and role ARN are updated first.

rctl create credential aws <name> --cred-type data-backup --role-arn <role_arn>

Step 3: Create Backup Locations

In this step, we will create two backup locations which will store the control plane backup data and persistent volume data respectively. We will use an Amazon S3 bucket to store the data.

First, we will create the backup location for the Control Plane backups.

Alternatively, you can create the backup locations using RCTL and build this into an automation pipeline. The following commands could be used ensuring the location name, bucket region and bucket name are updated first.

rctl create dp-location <name> --backup-type controlplanebackup --target-type amazon --region <region> --bucket-name <bucketname>
rctl create dp-location <name> --backup-type volumebackup --target-type amazon --region <region> --bucket-name <bucketname>

Step 4: Create Data Agents

In this step, we will create a data agent on each cluster where a backup or restore operation will occur. The agent on each cluster will be used to perform the backup/restore operations.

Perform the following steps for each cluster where backup or restore operations will be performed.

We must now deploy the agent to a cluster.

Alternatively, you can create and deploy the data agents using RCTL and build this into an automation pipeline. The following commands could be used ensuring the data agent name, cloud credential name and cluster name are updated first.

rctl create dp-agent <name> --cloud-credentials <cloudcredentials>
rctl deploy dp-agent <agent-name> --cluster-name <cluster-name>

Step 5: Create Backup and Restore Policies

In this step, you will create both a backup and a restore policy.

First, you will create a backup policy.

Alternatively, you can create the backup policy using RCTL and build this into an automation pipeline. The following command could be used ensuring the policy name, control plane location and volume location are updated first.

rctl create dp-policy <name> --type backup --location <location> --snapshot-location <snapshot-location> --retention-period 720h

Now, you will create a restore policy.

Alternatively, you can create the restore policy using RCTL and build this into an automation pipeline. The following command could be used ensuring the policy name is updated first.

rctl create dp-policy <name> --type restore --restore-pvs

Recap

In this part, you have created the needed backup and restore resources in order to be able to initiate backup and restore jobs on your two clusters.