Sign inSign up

jonaseck/mongodb-gcs-backup

By jonaseck

•Updated over 7 years ago

Image
0

602

jonaseck/mongodb-gcs-backup repository overview

⁠mongodb-gcs-backup

This project aims to provide a simple way to perform a MongoDB server/db backup using mongo-tools and to upload it to Google Cloud Storage. It was greatly inspired from takemetour/docker-mongodb-gcs-backup⁠.

We provide a kubernetes support thanks to the helm chart located in the chart folder of this repository.

⁠Docker Image

You can pull the public image from Docker Hub:

docker pull jonaseck/mongodb-gcs-backup:latest
⁠Configuration

The following table lists the configurable parameters you can set up.

Environment VariableRequiredDefaultDescription
BACKUP_DIRNo/tmpThe path where the mongodump result will be temporarily stored.
BACKUP_PREFIXNobackupPrefix of the backup file name.
BOTO_CONFIG_PATHNo/root/.botoThe path where gsutil will search for the boto configuration file.
GCS_BUCKETYesThe bucket you want to upload the backup archive to.
GCS_KEY_FILE_PATHYesThe location where the GCS serviceaccount key file will be mounted.
MONGODB_HOSTNolocalhostThe MongoDB server host.
MONGODB_PORTNo27017The MongoDB port.
DATABASE_NAMENoThe database to backup. By default, a backup of all the databases will be performed.
MONGODB_USERNAMENoThe MongoDB user if any.
MONGODB_PASSWORDNoThe MongoDB password if any.
MONGODB_REPLICASETNoThe MongoDB replicaset if any. Adds --oplog to EXTRA_OPTS unless set.
EXTRA_OPTSNoAdditional backup flags.
SLACK_ALERTSNotrue if you want to send Slack alerts in case of failure.
SLACK_WEBHOOK_URLNoThe Incoming WebHook URL to use to send the alerts.
SLACK_CHANNELNoThe channel to send Slack messages to.
SLACK_USERNAMENoThe user to send Slack messages as.
SLACK_ICONNoThe Slack icon to associate to the user/message.

You can set all of these variables within your values.yaml file under the env dict key.

⁠Usage
⁠Run Locally

You can run the script locally:

cd /path/to/mongodb-gcs-backup
chmod +x backup.sh
GCS_BUCKET=<gs://bucket_name> \
./backup.sh

Please note that you can set any environment variable described in the previous section! As an example, to enable the Slack alerts on failure:

SLACK_ALERTS=true \
SLACK_WEBHOOK_URL=<webhook_url> \
SLACK_CHANNEL=<slack_channel> \
SLACK_USERNAME=<slack_username> \
SLACK_ICON=<slack_icon> \
GCS_BUCKET=<gs://bucket_name> \
./backup.sh
⁠Run within Kubernetes
⁠Installing the Chart

To install the chart with the release name my-release within you Kubernetes cluster:

helm install --name my-release chart/mongodb-gcs-backup

The command deploys the chart on the Kubernetes cluster in the default namespace. The configuration section lists the parameters that can be configured during installation.

⁠Uninstalling the Chart

To uninstall/delete the my-release deployment:

helm delete my-release --purge

The command removes all the Kubernetes components associated with the chart and deletes the release.

⁠Authenticate with GCS
⁠Using the gcloud CLI

If you are running the script locally, the easiest solution is to sign in to the google account associated with your Google Cloud Storage data:

gcloud init --console-only

More information on how to setup gsutil locally here⁠.

⁠Using a Service Account Within Kubernetes

You can create a service account⁠ by executing the example below. The service account is granted access to the specific bucket only and a lifecycle to delete backups after 28 days is added.

To use the resulting JSON key file within Kubernetes you can create a secret from it by running the following command:

GCLOUD_PROJECT=$(gcloud config get-value project 2>/dev/null)
BUCKET=gs://example-bucket
NAME=mongodb-gcs-backup
KEYNAME=credentials.json
SERVICE_ACCOUNT=${NAME}@${GCLOUD_PROJECT}.iam.gserviceaccount.com
gcloud iam service-accounts create ${NAME} --display-name "${NAME}" 2>/dev/null
gcloud iam service-accounts keys create ${KEYNAME} --iam-account=${SERVICE_ACCOUNT}
kubectl create secret generic ${NAME} --from-file ${KEYNAME}
rm -f ${KEYNAME}

gsutil mb -b off -c regional -l ${REGION} ${BUCKET}
gsutil defacl ch -u ${SERVICE_ACCOUNT}:O ${BUCKET}

cat << EOF > lifecycle.json
{
    "rule": [{
        "action": {
            "type": "Delete"
        },
        "condition": {
            "age": 28
        }
    }]
}
EOF
gsutil lifecycle set lifecycle.json ${BUCKET}
rm -f lifecycle.json

Then you will need to specify this secret name via the --set secretName=<your_secret_name> argument to the helm install command or by specifying it directly in your values.yaml file (by default, the secret name is set to mongodb-gcs-backup). The key file will be mounted by default under /secrets/gcp/credentials.json and the GCS_KEY_FILE_PATH variable should point to it.

Tag summary

Content type

Image

Digest

Size

67 MB

Last updated

over 7 years ago

docker pull jonaseck/mongodb-gcs-backup