Merge pull request #8759 from shubham-pampattiwar/add-vp-labels-docs
Run the E2E test on kind / build (push) Failing after 6m24s
Run the E2E test on kind / setup-test-matrix (push) Successful in 2s
Run the E2E test on kind / run-e2e-test (push) Has been skipped
Main CI / Build (push) Failing after 36s
Close stale issues and PRs / stale (push) Successful in 8s
Trivy Nightly Scan / Trivy nightly scan (velero, main) (push) Failing after 1m7s
Trivy Nightly Scan / Trivy nightly scan (velero-restore-helper, main) (push) Failing after 59s

Add docs for volume policy with labels as a criteria
This commit is contained in:
Tiger Kaovilai
2025-03-07 09:52:49 -06:00
committed by GitHub
2 changed files with 47 additions and 0 deletions
@@ -0,0 +1 @@
Add docs for volume policy with labels as a criteria
@@ -362,6 +362,52 @@ Velero supported conditions and format listed below:
```
Volume types could be found in [Persistent Volumes](https://kubernetes.io/docs/concepts/storage/persistent-volumes) and pod [Volume](https://kubernetes.io/docs/concepts/storage/volumes)
- pvc Labels
This condition filters volumes based on the labels on their associated PVCs. The condition is specified as a simple key/value mapping. The volume matches this condition if all the key/value pairs defined in the policy are present on the PVC.
```yaml
pvcLabels:
environment: production
```
Some examples:
- Environment specific labels: Snapshot volumes whose associated PVC has the label `environment: production`.
```yaml
volumePolicies:
- conditions:
pvcLabels:
environment: production
action:
type: snapshot
```
- Subset Matching: Even if the PVC contains extra labels, it will match as long as the required key/value pair is present. For example, if the PVC has:
```yaml
labels:
environment: production
team: backend
```
the following policy will match because it only requires `environment: production`:
```yaml
volumePolicies:
- conditions:
pvcLabels:
environment: production
action:
type: skip
```
- Mismatched PVC Labels: If the policy requires both `environment: production` and `app: frontend`, but the PVC only has `environment: production`, the volume will not match.
```yaml
volumePolicies:
- conditions:
pvcLabels:
environment: production
app: frontend
action:
type: skip
```
### Resource policies rules
- Velero already has lots of include or exclude filters. the resource policies are the final filters after others include or exclude filters in one backup processing workflow. So if use a defined similar filter like the opt-in approach to backup one pod volume but skip backup of the same pod volume in resource policies, as resource policies are the final filters that are applied, the volume will not be backed up.
- If volume resource policies conflict with themselves the first matched policy will be respected when many policies are defined.