Support copying namespace-scoped secrets/configmaps for backup and restore PVC provisioning

Backport of #9920 to release-1.18.

Enables datamover backup/restore of CSI volumes that require
namespace-scoped secrets/configmaps for provisioning (e.g., ODF/ceph-csi
encrypted volumes with Vault KMS). Adds secretNames/configMapNames to the
backupPVC/restorePVC node-agent config; the CSI snapshot and generic
restore exposers copy the named resources from the source/target
namespace to the Velero namespace before creating the intermediate PVC,
and clean them up afterward (labeled with the owner UID). Adds the
corresponding RBAC for secrets/configmaps.

Signed-off-by: Shubham Pampattiwar <spampatt@redhat.com>
This commit is contained in:
Shubham Pampattiwar
2026-08-19 09:14:51 -07:00
parent ffe6cffe37
commit 7922bb33c2
11 changed files with 886 additions and 0 deletions
+25
View File
@@ -59,11 +59,36 @@ type BackupPVC struct {
// Annotations permits setting annotations for the backupPVC
Annotations map[string]string `json:"annotations,omitempty"`
// SecretNames is a list of secret names to copy from the source PVC namespace
// to the Velero namespace before creating the backupPVC. The secrets are deleted
// after the DataUpload completes. This is needed for CSI drivers that require
// namespace-scoped secrets for volume provisioning (e.g., encrypted volumes).
SecretNames []string `json:"secretNames,omitempty"`
// ConfigMapNames is a list of configmap names to copy from the source PVC namespace
// to the Velero namespace before creating the backupPVC. The configmaps are deleted
// after the DataUpload completes. This is needed for CSI drivers that require
// namespace-scoped configmaps for volume provisioning (e.g., tenant-specific
// Vault connection overrides for encrypted volumes).
ConfigMapNames []string `json:"configMapNames,omitempty"`
}
type RestorePVC struct {
// IgnoreDelayBinding indicates to ignore delay binding the restorePVC when it is in WaitForFirstConsumer mode
IgnoreDelayBinding bool `json:"ignoreDelayBinding,omitempty"`
// SecretNames is a list of secret names to copy from the target namespace to the
// Velero namespace before creating the restorePVC. The secrets are deleted after the
// DataDownload completes. This is needed for CSI drivers that require namespace-scoped
// secrets for volume provisioning (e.g., encrypted volumes).
SecretNames []string `json:"secretNames,omitempty"`
// ConfigMapNames is a list of configmap names to copy from the target namespace to the
// Velero namespace before creating the restorePVC. The configmaps are deleted after the
// DataDownload completes. This is needed for CSI drivers that require namespace-scoped
// configmaps for volume provisioning (e.g., tenant-specific Vault connection overrides).
ConfigMapNames []string `json:"configMapNames,omitempty"`
}
type CachePVC struct {