mirror of
https://github.com/vmware-tanzu/velero.git
synced 2026-10-01 12:15:36 +00:00
Support setting a custom CA bundle to use with a BackupStorageLocation (#2353)
* Support setting a custom CA certificate for a BSL Signed-off-by: Sam Lucidi <slucidi@redhat.com> * update CRDS Signed-off-by: Sam Lucidi <slucidi@redhat.com> * Add changelog for #2353 Signed-off-by: Sam Lucidi <slucidi@redhat.com> * Clean up temp file from TestTempCACertFile Signed-off-by: Sam Lucidi <slucidi@redhat.com>
This commit is contained in:
@@ -212,21 +212,37 @@ func (c *podVolumeBackupController) processBackup(req *velerov1api.PodVolumeBack
|
||||
log.WithField("path", path).Debugf("Found path matching glob")
|
||||
|
||||
// temp creds
|
||||
file, err := restic.TempCredentialsFile(c.secretLister, req.Namespace, req.Spec.Pod.Namespace, c.fileSystem)
|
||||
credentialsFile, err := restic.TempCredentialsFile(c.secretLister, req.Namespace, req.Spec.Pod.Namespace, c.fileSystem)
|
||||
if err != nil {
|
||||
log.WithError(err).Error("Error creating temp restic credentials file")
|
||||
return c.fail(req, errors.Wrap(err, "error creating temp restic credentials file").Error(), log)
|
||||
}
|
||||
// ignore error since there's nothing we can do and it's a temp file.
|
||||
defer os.Remove(file)
|
||||
defer os.Remove(credentialsFile)
|
||||
|
||||
resticCmd := restic.BackupCommand(
|
||||
req.Spec.RepoIdentifier,
|
||||
file,
|
||||
credentialsFile,
|
||||
path,
|
||||
req.Spec.Tags,
|
||||
)
|
||||
|
||||
// if there's a caCert on the ObjectStorage, write it to disk so that it can be passed to restic
|
||||
caCert, err := restic.GetCACert(c.backupLocationLister, req.Namespace, req.Spec.BackupStorageLocation)
|
||||
if err != nil {
|
||||
log.WithError(err).Error("Error getting caCert")
|
||||
}
|
||||
var caCertFile string
|
||||
if caCert != nil {
|
||||
caCertFile, err = restic.TempCACertFile(caCert, req.Spec.BackupStorageLocation, c.fileSystem)
|
||||
if err != nil {
|
||||
log.WithError(err).Error("Error creating temp cacert file")
|
||||
}
|
||||
// ignore error since there's nothing we can do and it's a temp file.
|
||||
defer os.Remove(caCertFile)
|
||||
}
|
||||
resticCmd.CACertFile = caCertFile
|
||||
|
||||
// Running restic command might need additional provider specific environment variables. Based on the provider, we
|
||||
// set resticCmd.Env appropriately (currently for Azure and S3 based backuplocations)
|
||||
var env []string
|
||||
@@ -272,7 +288,7 @@ func (c *podVolumeBackupController) processBackup(req *velerov1api.PodVolumeBack
|
||||
|
||||
var snapshotID string
|
||||
if !emptySnapshot {
|
||||
snapshotID, err = restic.GetSnapshotID(req.Spec.RepoIdentifier, file, req.Spec.Tags, env)
|
||||
snapshotID, err = restic.GetSnapshotID(req.Spec.RepoIdentifier, credentialsFile, req.Spec.Tags, env, caCertFile)
|
||||
if err != nil {
|
||||
log.WithError(err).Error("Error getting SnapshotID")
|
||||
return c.fail(req, errors.Wrap(err, "error getting snapshot id").Error(), log)
|
||||
|
||||
@@ -293,8 +293,23 @@ func (c *podVolumeRestoreController) processRestore(req *velerov1api.PodVolumeRe
|
||||
// ignore error since there's nothing we can do and it's a temp file.
|
||||
defer os.Remove(credsFile)
|
||||
|
||||
// if there's a caCert on the ObjectStorage, write it to disk so that it can be passed to restic
|
||||
caCert, err := restic.GetCACert(c.backupLocationLister, req.Namespace, req.Spec.BackupStorageLocation)
|
||||
if err != nil {
|
||||
log.WithError(err).Error("Error getting caCert")
|
||||
}
|
||||
var caCertFile string
|
||||
if caCert != nil {
|
||||
caCertFile, err = restic.TempCACertFile(caCert, req.Spec.BackupStorageLocation, c.fileSystem)
|
||||
if err != nil {
|
||||
log.WithError(err).Error("Error creating temp cacert file")
|
||||
}
|
||||
// ignore error since there's nothing we can do and it's a temp file.
|
||||
defer os.Remove(caCertFile)
|
||||
}
|
||||
|
||||
// execute the restore process
|
||||
if err := c.restorePodVolume(req, credsFile, volumeDir, log); err != nil {
|
||||
if err := c.restorePodVolume(req, credsFile, caCertFile, volumeDir, log); err != nil {
|
||||
log.WithError(err).Error("Error restoring volume")
|
||||
return c.failRestore(req, errors.Wrap(err, "error restoring volume").Error(), log)
|
||||
}
|
||||
@@ -313,7 +328,7 @@ func (c *podVolumeRestoreController) processRestore(req *velerov1api.PodVolumeRe
|
||||
return nil
|
||||
}
|
||||
|
||||
func (c *podVolumeRestoreController) restorePodVolume(req *velerov1api.PodVolumeRestore, credsFile, volumeDir string, log logrus.FieldLogger) error {
|
||||
func (c *podVolumeRestoreController) restorePodVolume(req *velerov1api.PodVolumeRestore, credsFile, caCertFile, volumeDir string, log logrus.FieldLogger) error {
|
||||
// Get the full path of the new volume's directory as mounted in the daemonset pod, which
|
||||
// will look like: /host_pods/<new-pod-uid>/volumes/<volume-plugin-name>/<volume-dir>
|
||||
volumePath, err := singlePathMatch(fmt.Sprintf("/host_pods/%s/volumes/*/%s", string(req.Spec.Pod.UID), volumeDir))
|
||||
@@ -327,6 +342,7 @@ func (c *podVolumeRestoreController) restorePodVolume(req *velerov1api.PodVolume
|
||||
req.Spec.SnapshotID,
|
||||
volumePath,
|
||||
)
|
||||
resticCmd.CACertFile = caCertFile
|
||||
|
||||
// Running restic command might need additional provider specific environment variables. Based on the provider, we
|
||||
// set resticCmd.Env appropriately (currently for Azure and S3 based backuplocations)
|
||||
|
||||
Reference in New Issue
Block a user