mirror of
https://github.com/vmware-tanzu/velero.git
synced 2026-09-29 11:16:08 +00:00
Merge pull request #9141 from kaovilai/9097
Run the E2E test on kind / get-go-version (push) Failing after 1m8s
Run the E2E test on kind / build (push) Has been skipped
Run the E2E test on kind / setup-test-matrix (push) Successful in 3s
Run the E2E test on kind / run-e2e-test (push) Has been skipped
Main CI / get-go-version (push) Successful in 16s
Main CI / Build (push) Failing after 45s
Run the E2E test on kind / get-go-version (push) Failing after 1m8s
Run the E2E test on kind / build (push) Has been skipped
Run the E2E test on kind / setup-test-matrix (push) Successful in 3s
Run the E2E test on kind / run-e2e-test (push) Has been skipped
Main CI / get-go-version (push) Successful in 16s
Main CI / Build (push) Failing after 45s
feat: Enhance BackupStorageLocation with Secret-based CA certificate support
This commit is contained in:
@@ -44,13 +44,47 @@ spec:
|
||||
provider: aws
|
||||
objectStorage:
|
||||
bucket: velero-backups
|
||||
# Base64 encoded CA certificate
|
||||
# Base64 encoded CA certificate (deprecated - use caCertRef instead)
|
||||
caCert: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUR1VENDQXFHZ0F3SUJBZ0lVTWRiWkNaYnBhcE9lYThDR0NMQnhhY3dVa213d0RRWUpLb1pJaHZjTkFRRUwKQlFBd2JERUxNQWtHQTFVRUJoTUNWVk14RXpBUkJnTlZCQWdNQ2tOaGJHbG1iM0p1YVdFeEZqQVVCZ05WQkFjTQpEVk5oYmlCR2NtRnVZMmx6WTI4eEdEQVdCZ05WQkFvTUQwVjRZVzF3YkdVZ1EyOXRjR0Z1ZVRFV01CUUdBMVVFCkF3d05aWGhoYlhCc1pTNXNiMk5oYkRBZUZ3MHlNekEzTVRBeE9UVXlNVGhhRncweU5EQTNNRGt4T1RVeU1UaGEKTUd3eEN6QUpCZ05WQkFZVEFsVlRNUk13RVFZRFZRUUNEQXBEWEJ4cG1iM0p1YVdFeEZqQVVCZ05WQkFjTURWTmgKYmlCR2NtRnVZMmx6WTI4eEdEQVdCZ05WQkFvTUQwVjRZVzF3YkdVZ1EyOXRjR0Z1ZVRFV01CUUdBMVVFQXd3TgpaWGhoYlhCc1pTNXNiMk5oYkRDQ0FTSXdEUVlKS29aSWh2Y05BUUVCQlFBRGdnRVBBRENDQVFvQ2dnRUJBS1dqCi0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0K
|
||||
config:
|
||||
region: us-east-1
|
||||
s3Url: https://minio.example.com
|
||||
```
|
||||
|
||||
#### Using a CA Certificate with Secret Reference (Recommended)
|
||||
|
||||
The recommended approach is to use `caCertRef` to reference a Secret containing the CA certificate:
|
||||
|
||||
```yaml
|
||||
# First, create a Secret containing the CA certificate
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: storage-ca-cert
|
||||
namespace: velero
|
||||
type: Opaque
|
||||
data:
|
||||
ca-bundle.crt: <base64-encoded-certificate>
|
||||
|
||||
---
|
||||
# Then reference it in the BackupStorageLocation
|
||||
apiVersion: velero.io/v1
|
||||
kind: BackupStorageLocation
|
||||
metadata:
|
||||
name: default
|
||||
namespace: velero
|
||||
spec:
|
||||
provider: aws
|
||||
objectStorage:
|
||||
bucket: myBucket
|
||||
caCertRef:
|
||||
name: storage-ca-cert
|
||||
key: ca-bundle.crt
|
||||
# ... other configuration
|
||||
```
|
||||
|
||||
**Note:** You cannot specify both `caCert` and `caCertRef` in the same BackupStorageLocation. The `caCert` field is deprecated and will be removed in a future version.
|
||||
|
||||
### Parameter Reference
|
||||
|
||||
The configurable parameters are as follows:
|
||||
@@ -64,7 +98,10 @@ The configurable parameters are as follows:
|
||||
| `objectStorage` | ObjectStorageLocation | Required Field | Specification of the object storage for the given provider. |
|
||||
| `objectStorage/bucket` | String | Required Field | The storage bucket where backups are to be uploaded. |
|
||||
| `objectStorage/prefix` | String | Optional Field | The directory inside a storage bucket where backups are to be uploaded. |
|
||||
| `objectStorage/caCert` | String | Optional Field | A base64 encoded CA bundle to be used when verifying TLS connections |
|
||||
| `objectStorage/caCert` | String | Optional Field | **Deprecated**: Use `caCertRef` instead. A base64 encoded CA bundle to be used when verifying TLS connections |
|
||||
| `objectStorage/caCertRef` | [corev1.SecretKeySelector](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#secretkeyselector-v1-core) | Optional Field | Reference to a Secret containing a CA bundle to be used when verifying TLS connections. The Secret must be in the same namespace as the BackupStorageLocation. |
|
||||
| `objectStorage/caCertRef/name` | String | Required Field (when using caCertRef) | The name of the Secret containing the CA certificate bundle |
|
||||
| `objectStorage/caCertRef/key` | String | Required Field (when using caCertRef) | The key within the Secret that contains the CA certificate bundle |
|
||||
| `config` | map[string]string | None (Optional) | Provider-specific configuration keys/values to be passed to the object store plugin. See [your object storage provider's plugin documentation](../supported-providers) for details. |
|
||||
| `accessMode` | String | `ReadWrite` | How Velero can access the backup storage location. Valid values are `ReadWrite`, `ReadOnly`. |
|
||||
| `backupSyncPeriod` | metav1.Duration | Optional Field | How frequently Velero should synchronize backups in object storage. Default is Velero's server backup sync period. Set this to `0s` to disable sync. |
|
||||
@@ -72,4 +109,4 @@ The configurable parameters are as follows:
|
||||
| `credential` | [corev1.SecretKeySelector](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#secretkeyselector-v1-core) | Optional Field | The credential information to be used with this location. |
|
||||
| `credential/name` | String | Optional Field | The name of the secret within the Velero namespace which contains the credential information. |
|
||||
| `credential/key` | String | Optional Field | The key to use within the secret. |
|
||||
{{< /table >}}
|
||||
{{< /table >}}
|
||||
@@ -31,34 +31,73 @@ Take the following as an example:
|
||||
```
|
||||
|
||||
## Set the proxy required certificates
|
||||
In some cases, the proxy requires certificate to connect. Set the certificate in the BSL's `Spec.ObjectStorage.CACert`.
|
||||
It's possible that the object storage also requires certificate, and it's also set in `Spec.ObjectStorage.CACert`, then set both certificates in `Spec.ObjectStorage.CACert` field.
|
||||
In some cases, the proxy requires certificate to connect. You can provide certificates in the BSL configuration.
|
||||
It's possible that the object storage also requires certificate, then include both certificates together.
|
||||
|
||||
The following is an example file contains two certificates, then encode its content with base64, and set the encode result in the BSL.
|
||||
### Method 1: Using Kubernetes Secrets (Recommended)
|
||||
|
||||
The recommended approach is to store certificates in a Kubernetes Secret and reference them using `caCertRef`:
|
||||
|
||||
1. Create a file containing all required certificates:
|
||||
|
||||
``` bash
|
||||
cat certs
|
||||
-----BEGIN CERTIFICATE-----
|
||||
certificates first content
|
||||
-----END CERTIFICATE-----
|
||||
|
||||
-----BEGIN CERTIFICATE-----
|
||||
certificates second content
|
||||
-----END CERTIFICATE-----
|
||||
```
|
||||
|
||||
2. Create a Secret from the certificate file:
|
||||
|
||||
``` bash
|
||||
kubectl create secret generic proxy-ca-certs \
|
||||
--from-file=ca-bundle.crt=certs \
|
||||
-n velero
|
||||
```
|
||||
|
||||
3. Reference the Secret in your BackupStorageLocation:
|
||||
|
||||
``` yaml
|
||||
apiVersion: velero.io/v1
|
||||
kind: BackupStorageLocation
|
||||
metadata:
|
||||
name: default
|
||||
namespace: velero
|
||||
spec:
|
||||
provider: <YOUR_PROVIDER>
|
||||
default: true
|
||||
objectStorage:
|
||||
bucket: velero
|
||||
caCertRef:
|
||||
name: proxy-ca-certs
|
||||
key: ca-bundle.crt
|
||||
# ... other configuration
|
||||
```
|
||||
|
||||
### Method 2: Using inline certificates (Deprecated)
|
||||
|
||||
**Note:** The `caCert` field is deprecated. Use `caCertRef` for better security and management.
|
||||
|
||||
If you must use the inline method, encode the certificate content with base64:
|
||||
|
||||
``` bash
|
||||
cat certs
|
||||
-----BEGIN CERTIFICATE-----
|
||||
certificates first content
|
||||
-----END CERTIFICATE-----
|
||||
|
||||
-----BEGIN CERTIFICATE-----
|
||||
certificates second content
|
||||
-----END CERTIFICATE-----
|
||||
|
||||
cat certs | base64
|
||||
LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCmNlcnRpZmljYXRlcyBmaXJzdCBjb250ZW50Ci0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0KCi0tLS0tQkVHSU4gQ0VSVElGSUNBVEUtLS0tLQpjZXJ0aWZpY2F0ZXMgc2Vjb25kIGNvbnRlbnQKLS0tLS1FTkQgQ0VSVElGSUNBVEUtLS0tLQo=
|
||||
```
|
||||
|
||||
``` yaml
|
||||
apiVersion: velero.io/v1
|
||||
kind: BackupStorageLocation
|
||||
...
|
||||
spec:
|
||||
...
|
||||
default: true
|
||||
objectStorage:
|
||||
bucket: velero
|
||||
caCert: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCmNlcnRpZmljYXRlcyBmaXJzdCBjb250ZW50Ci0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0KCi0tLS0tQkVHSU4gQ0VSVElGSUNBVEUtLS0tLQpjZXJ0aWZpY2F0ZXMgc2Vjb25kIGNvbnRlbnQKLS0tLS1FTkQgQ0VSVElGSUNBVEUtLS0tLQo=
|
||||
...
|
||||
apiVersion: velero.io/v1
|
||||
kind: BackupStorageLocation
|
||||
# ...
|
||||
spec:
|
||||
# ...
|
||||
default: true
|
||||
objectStorage:
|
||||
bucket: velero
|
||||
caCert: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCmNlcnRpZmljYXRlcyBmaXJzdCBjb250ZW50Ci0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0KCi0tLS0tQkVHSU4gQ0VSVElGSUNBVEUtLS0tLQpjZXJ0aWZpY2F0ZXMgc2Vjb25kIGNvbnRlbnQKLS0tLS1FTkQgQ0VSVElGSUNBVEUtLS0tLQo=
|
||||
# ...
|
||||
```
|
||||
|
||||
@@ -23,18 +23,91 @@ velero install \
|
||||
Velero will then automatically use the provided CA bundle to verify TLS connections to
|
||||
that storage provider when backing up and restoring.
|
||||
|
||||
## Trusting a self-signed certificate using Kubernetes Secrets (Recommended)
|
||||
|
||||
The recommended approach for managing CA certificates is to store them in a Kubernetes Secret and reference them in the BackupStorageLocation using `caCertRef`. This provides better security and easier certificate management:
|
||||
|
||||
1. Create a Secret containing your CA certificate:
|
||||
|
||||
```bash
|
||||
kubectl create secret generic storage-ca-cert \
|
||||
--from-file=ca-bundle.crt=<PATH_TO_CA_BUNDLE> \
|
||||
-n velero
|
||||
```
|
||||
|
||||
2. Create or update your BackupStorageLocation to reference the Secret:
|
||||
|
||||
```yaml
|
||||
apiVersion: velero.io/v1
|
||||
kind: BackupStorageLocation
|
||||
metadata:
|
||||
name: default
|
||||
namespace: velero
|
||||
spec:
|
||||
provider: <YOUR_PROVIDER>
|
||||
objectStorage:
|
||||
bucket: <YOUR_BUCKET>
|
||||
caCertRef:
|
||||
name: storage-ca-cert
|
||||
key: ca-bundle.crt
|
||||
# ... other configuration
|
||||
```
|
||||
|
||||
### Benefits of using Secrets
|
||||
|
||||
- **Security**: Certificates are stored encrypted in etcd
|
||||
- **Certificate Rotation**: Update the Secret to rotate certificates without modifying the BackupStorageLocation
|
||||
- **RBAC**: Control access to certificates using Kubernetes RBAC
|
||||
- **Separation of Concerns**: Keep sensitive certificate data separate from configuration
|
||||
|
||||
## Trusting a self-signed certificate with the Velero client
|
||||
|
||||
When using Velero client commands like describe, download, or logs to access backups or restores
|
||||
in storage secured by a self-signed certificate, the CA certificate can be configured in two ways:
|
||||
**Note**: As of Velero v1.15, the CLI automatically discovers certificates configured in the BackupStorageLocation. If you have configured certificates using either `caCert` (deprecated) or `caCertRef` (recommended) in your BSL, you no longer need to specify the `--cacert` flag for backup describe, download, or logs commands.
|
||||
|
||||
1. **Using the `--cacert` flag** (legacy method):
|
||||
### Automatic Certificate Discovery
|
||||
|
||||
```bash
|
||||
velero backup describe my-backup --cacert <PATH_TO_CA_BUNDLE>
|
||||
The Velero CLI automatically discovers and uses CA certificates from the BackupStorageLocation configuration. The resolution order is:
|
||||
|
||||
1. **`--cacert` flag** (if provided) - Takes highest precedence
|
||||
2. **`caCertRef`** - References a Secret containing the certificate (recommended)
|
||||
3. **`caCert`** - Inline certificate in the BSL (deprecated)
|
||||
|
||||
Examples:
|
||||
|
||||
```bash
|
||||
# Automatic discovery (no flag needed if BSL has caCertRef or caCert configured)
|
||||
velero backup describe my-backup
|
||||
velero backup download my-backup
|
||||
velero backup logs my-backup
|
||||
|
||||
# Manual override (takes precedence over BSL configuration)
|
||||
velero backup describe my-backup --cacert <PATH_TO_CA_BUNDLE>
|
||||
```
|
||||
|
||||
### Configuring CA Certificates in BackupStorageLocation
|
||||
|
||||
You can configure CA certificates in the BackupStorageLocation using either method:
|
||||
|
||||
1. **Using `caCertRef` (Recommended)**:
|
||||
|
||||
```yaml
|
||||
apiVersion: velero.io/v1
|
||||
kind: BackupStorageLocation
|
||||
metadata:
|
||||
name: default
|
||||
namespace: velero
|
||||
spec:
|
||||
provider: aws
|
||||
objectStorage:
|
||||
bucket: velero-backups
|
||||
caCertRef:
|
||||
name: storage-ca-cert
|
||||
key: ca-bundle.crt
|
||||
config:
|
||||
region: us-east-1
|
||||
```
|
||||
|
||||
2. **Configuring the CA certificate in the BackupStorageLocation**:
|
||||
2. **Using inline `caCert` (Deprecated)**:
|
||||
|
||||
```yaml
|
||||
apiVersion: velero.io/v1
|
||||
@@ -51,7 +124,7 @@ in storage secured by a self-signed certificate, the CA certificate can be confi
|
||||
region: us-east-1
|
||||
```
|
||||
|
||||
When the CA certificate is configured in the BackupStorageLocation, Velero client commands will automatically use it without requiring the `--cacert` flag.
|
||||
When the CA certificate is configured in the BackupStorageLocation using either method, Velero client commands will automatically discover and use it without requiring the `--cacert` flag.
|
||||
|
||||
## Error with client certificate with custom S3 server
|
||||
|
||||
|
||||
Reference in New Issue
Block a user