From 48f2095dc9f704edf05d2798d34c743838e03402 Mon Sep 17 00:00:00 2001 From: Ralthos <161431341+Ralthos@users.noreply.github.com> Date: Tue, 11 Aug 2026 21:14:02 +0530 Subject: [PATCH] Site: document artifact download failures with an in-cluster s3Url (#10231) troubleshooting.md covers SignatureDoesNotMatch but not the other way a log or results download fails: the pre-signed URL carries the s3Url host, which for an in-cluster Service name does not resolve on the client. The backup or restore itself is unaffected, which makes the error easy to misread. The fix, publicUrl, is documented only under exposing Minio, so this links there instead of duplicating it. Signed-off-by: saral --- changelogs/unreleased/10231-Ralthos | 1 + site/content/docs/main/troubleshooting.md | 14 ++++++++++++++ 2 files changed, 15 insertions(+) create mode 100644 changelogs/unreleased/10231-Ralthos diff --git a/changelogs/unreleased/10231-Ralthos b/changelogs/unreleased/10231-Ralthos new file mode 100644 index 000000000..415cc3d27 --- /dev/null +++ b/changelogs/unreleased/10231-Ralthos @@ -0,0 +1 @@ +Add a troubleshooting entry for artifact downloads failing when the BackupStorageLocation s3Url is only resolvable inside the cluster diff --git a/site/content/docs/main/troubleshooting.md b/site/content/docs/main/troubleshooting.md index dc692771c..df5d71753 100644 --- a/site/content/docs/main/troubleshooting.md +++ b/site/content/docs/main/troubleshooting.md @@ -77,6 +77,19 @@ Here are some things to verify if you receive `SignatureDoesNotMatch` errors: * Make sure your S3-compatible layer is using [signature version 4][5] (such as Ceph RADOS v12.2.7) * For Ceph, try using a native Ceph account for credentials instead of external providers such as OpenStack Keystone +### `velero backup logs` or `velero describe` fails with `no such host` + +Downloading artifacts uses a pre-signed URL built from the `s3Url` in your `BackupStorageLocation`. If that address is only resolvable inside the cluster, such as a Kubernetes Service name, the Velero client cannot fetch the artifact even though the backup or restore itself succeeded: + +``` +Warnings: +``` + +The backup or restore is unaffected. Only the download of its log or results file fails. + +To fix this, give the location a `publicUrl` that your client can reach. See [Expose Minio outside your cluster][26] for the Minio case; the same applies to any object store addressed by an in-cluster name. + ## Velero (or a pod it was backing up) restarted during a backup and the backup is stuck InProgress Velero cannot resume backups that were interrupted. Backups stuck in the `InProgress` phase can be deleted with `kubectl delete backup -n `. @@ -250,3 +263,4 @@ Please refer to [Issue 9007](https://github.com/velero-io/velero/issues/9007) fo [11]: /plugins [12]: https://kubernetes.io/docs/concepts/configuration/secret/#editing-a-secret [25]: https://kubernetes.slack.com/messages/velero +[26]: contributions/minio.md