Sign inSign up

rimmon1971/backupper

By rimmon1971

•Updated over 1 year ago

Image
0

391

rimmon1971/backupper repository overview

⁠Velero installation on AKS

⁠Initial situation

⁠Resource groups
ferdi@DESKTOP-NL6I2OD:~/velero-test$ az group list -o table
Name                                            Location       Status
----------------------------------------------  -------------  ---------
cloud-shell-storage-westeurope                  westeurope     Succeeded
NetworkWatcherRG                                westus         Succeeded
DefaultResourceGroup-WEU                        westeurope     Succeeded
DefaultResourceGroup-PAR                        francecentral  Succeeded
MC_DefaultResourceGroup-PAR_test_francecentral  francecentral  Succeeded
⁠AKS clusters
ferdi@DESKTOP-NL6I2OD:~/velero-test$ az aks list -o table
Name    Location       ResourceGroup             KubernetesVersion    CurrentKubernetesVersion    ProvisioningState    Fqdn
------  -------------  ------------------------  -------------------  --------------------------  -------------------  -----------------------------------------------------------------
test    francecentral  DefaultResourceGroup-PAR  1.25.6               1.25.6                      Succeeded            test-defaultresourceg-f1fbee-wybl4aiy.hcp.francecentral.azmk8s.io]

⁠Resource Group

ferdi@DESKTOP-NL6I2OD:~/velero-test$ AZURE_BACKUP_RESOURCE_GROUP=Velero_Backups
az group create -n $AZURE_BACKUP_RESOURCE_GROUP --location francecentral
{
  "id": "/subscriptions/f1fbee51-bbe1-4a48-908f-aa600c39faa8/resourceGroups/Velero_Backups",
  "location": "francecentral",
  "managedBy": null,
  "name": "Velero_Backups",
  "properties": {
    "provisioningState": "Succeeded"
  },
  "tags": null,
  "type": "Microsoft.Resources/resourceGroups"
}

⁠Storage Account

ferdi@DESKTOP-NL6I2OD:~/velero-test$ AZURE_STORAGE_ACCOUNT_ID="velero$(uuidgen | cut -d '-' -f5 | tr '[A-Z]' '[a-z]')"
az storage account create \
    --name $AZURE_STORAGE_ACCOUNT_ID \
    --resource-group $AZURE_BACKUP_RESOURCE_GROUP \
    --sku Standard_GRS \
    --encryption-services blob \
    --https-only true \
    --kind BlobStorage \
    --access-tier Hot
The public access to all blobs or containers in the storage account will be disallowed by default in the future, which means default value for --allow-blob-public-access is still null but will be equivalent to false.
{
  "accessTier": "Hot",
  "allowBlobPublicAccess": true,
  "allowCrossTenantReplication": null,
  "allowSharedKeyAccess": null,
  "allowedCopyScope": null,
  "azureFilesIdentityBasedAuthentication": null,
  "blobRestoreStatus": null,
  "creationTime": "2023-05-22T07:15:51.853585+00:00",
  "customDomain": null,
  "defaultToOAuthAuthentication": null,
  "dnsEndpointType": null,
  "enableHttpsTrafficOnly": true,
  "enableNfsV3": null,
  "encryption": {
    "encryptionIdentity": null,
    "keySource": "Microsoft.Storage",
    "keyVaultProperties": null,
    "requireInfrastructureEncryption": null,
    "services": {
      "blob": {
        "enabled": true,
        "keyType": "Account",
        "lastEnabledTime": "2023-05-22T07:15:51.931693+00:00"
      },
      "file": {
        "enabled": true,
        "keyType": "Account",
        "lastEnabledTime": "2023-05-22T07:15:51.931693+00:00"
      },
      "queue": null,
      "table": null
    }
  },
  "extendedLocation": null,
  "failoverInProgress": null,
  "geoReplicationStats": null,
  "id": "/subscriptions/f1fbee51-bbe1-4a48-908f-aa600c39faa8/resourceGroups/Velero_Backups/providers/Microsoft.Storage/storageAccounts/velero5d14d4544585",
  "identity": null,
  "immutableStorageWithVersioning": null,
  "isHnsEnabled": null,
  "isLocalUserEnabled": null,
  "isSftpEnabled": null,
  "keyCreationTime": {
    "key1": "2023-05-22T07:15:51.931693+00:00",
    "key2": "2023-05-22T07:15:51.931693+00:00"
  },
  "keyPolicy": null,
  "kind": "BlobStorage",
  "largeFileSharesState": null,
  "lastGeoFailoverTime": null,
  "location": "francecentral",
  "minimumTlsVersion": "TLS1_0",
  "name": "velero5d14d4544585",
  "networkRuleSet": {
    "bypass": "AzureServices",
    "defaultAction": "Allow",
    "ipRules": [],
    "resourceAccessRules": null,
    "virtualNetworkRules": []
  },
  "primaryEndpoints": {
    "blob": "https://velero5d14d4544585.blob.core.windows.net/",
    "dfs": "https://velero5d14d4544585.dfs.core.windows.net/",
    "file": null,
    "internetEndpoints": null,
    "microsoftEndpoints": null,
    "queue": null,
    "table": "https://velero5d14d4544585.table.core.windows.net/",
    "web": null
  },
  "primaryLocation": "francecentral",
  "privateEndpointConnections": [],
  "provisioningState": "Succeeded",
  "publicNetworkAccess": null,
  "resourceGroup": "Velero_Backups",
  "routingPreference": null,
  "sasPolicy": null,
  "secondaryEndpoints": null,
  "secondaryLocation": "francesouth",
  "sku": {
    "name": "Standard_GRS",
    "tier": "Standard"
  },
  "statusOfPrimary": "available",
  "statusOfSecondary": "available",
  "storageAccountSkuConversionStatus": null,
  "tags": {},
  "type": "Microsoft.Storage/storageAccounts"
}

⁠BLOB Container

ferdi@DESKTOP-NL6I2OD:~/velero-test$ BLOB_CONTAINER=velerotest
ferdi@DESKTOP-NL6I2OD:~/velero-test$ az storage container create -n $BLOB_CONTAINER --public-access off --account-name $AZURE_STORAGE_ACCOUNT_ID

There are no credentials provided in your command and environment, we will query for account key for your storage account.
It is recommended to provide --connection-string, --account-key or --sas-token in your command as credentials.

You also can add `--auth-mode login` in your command to use Azure Active Directory (Azure AD) for authorization if your login account is assigned required RBAC roles.
For more information about RBAC roles in storage, visit https://docs.microsoft.com/azure/storage/common/storage-auth-aad-rbac-cli.

In addition, setting the corresponding environment variables can avoid inputting credentials in your command. Please use --help to get more information about environment variable usage.
{
  "created": true
}

⁠Get Resource Group for PV Snapshots

It's the autogenerated RG for the AKS cluster; in this case, it's MC_DefaultResourceGroup-PAR_test_francecentral

We're going to populate another env var

ferdi@DESKTOP-NL6I2OD:~/velero-test$ AZURE_RESOURCE_GROUP="MC_DefaultResourceGroup-PAR_test_francecentral"

⁠Create Service Principal

ferdi@DESKTOP-NL6I2OD:~/velero-test$ AZURE_SUBSCRIPTION_ID=`az account list --query '[?isDefault].id' -o tsv`
ferdi@DESKTOP-NL6I2OD:~/velero-test$ AZURE_TENANT_ID=`az account list --query '[?isDefault].tenantId' -o tsv`

ferdi@DESKTOP-NL6I2OD:~/velero-test$ AZURE_CLIENT_SECRET=`az ad sp create-for-rbac --name "velero" --role "Contributor" --scopes /subscriptions/${AZURE_SUBSCRIPTION_ID}/resourceGroups/${AZURE_RESOURCE_GROUP} /subscriptions/${AZURE_SUBSCRIPTION_ID}/resourceGroups/${AZURE_BACKUP_RESOURCE_GROUP} --query 'password' -o tsv`

ferdi@DESKTOP-NL6I2OD:~/velero-test$ AZURE_CLIENT_ID=`az ad sp list --display-name "velero" --query '[0].appId' -o tsv`
ferdi@DESKTOP-NL6I2OD:~/velero-test$ AZURE_SP_ID=`az ad sp list --display-name "velero" --query '[0].id' -o tsv`

⁠Create install config file

ferdi@DESKTOP-NL6I2OD:~/velero-test$ cat << EOF  > ./credentials-velero
AZURE_SUBSCRIPTION_ID=${AZURE_SUBSCRIPTION_ID}
AZURE_TENANT_ID=${AZURE_TENANT_ID}
AZURE_CLIENT_ID=${AZURE_CLIENT_ID}
AZURE_CLIENT_SECRET=${AZURE_CLIENT_SECRET}
AZURE_RESOURCE_GROUP=${AZURE_RESOURCE_GROUP}
EOF
ferdi@DESKTOP-NL6I2OD:~/velero-test$ 

⁠Generate YAML for Velero installation

velero install \
    --provider azure \
    --plugins velero/velero-plugin-for-microsoft-azure:v1.6.0 \
    --bucket $BLOB_CONTAINER \
    --secret-file ./credentials-velero \
    --backup-location-config resourceGroup=$AZURE_BACKUP_RESOURCE_GROUP,storageAccount=$AZURE_STORAGE_ACCOUNT_ID[,subscriptionId=$AZURE_BACKUP_SUBSCRIPTION_ID] \
    --snapshot-location-config apiTimeout=<YOUR_TIMEOUT>[,resourceGroup=$AZURE_BACKUP_RESOURCE_GROUP,subscriptionId=$AZURE_BACKUP_SUBSCRIPTION_ID] \
    --dry-run -o yaml > velero-install.yml

⁠Create Service Principal 2

ferdi@DESKTOP-NL6I2OD:~/velero-test$ AZURE_SUBSCRIPTION_ID=`az account list --query '[?isDefault].id' -o tsv`
ferdi@DESKTOP-NL6I2OD:~/velero-test$ AZURE_TENANT_ID=`az account list --query '[?isDefault].tenantId' -o tsv`

ferdi@DESKTOP-NL6I2OD:~/velero-test$ AZURE_CLIENT_SECRET=`az ad sp create-for-rbac --name "velero2" --role "Contributor" --scopes /subscriptions/${AZURE_SUBSCRIPTION_ID}/resourceGroups/${AZURE_RESOURCE_GROUP} /subscriptions/${AZURE_SUBSCRIPTION_ID}/resourceGroups/${AZURE_BACKUP_RESOURCE_GROUP} --query 'password' -o tsv`

ferdi@DESKTOP-NL6I2OD:~/velero-test$ AZURE_CLIENT_ID=`az ad sp list --display-name "velero2" --query '[0].appId' -o tsv`
ferdi@DESKTOP-NL6I2OD:~/velero-test$ AZURE_SP_ID=`az ad sp list --display-name "velero2" --query '[0].id' -o tsv`

⁠Creazione Credentials file 2

ferdi@DESKTOP-NL6I2OD:~/velero-test$ cat << EOF  > ./credentials-velero2
AZURE_SUBSCRIPTION_ID=${AZURE_SUBSCRIPTION_ID}
AZURE_TENANT_ID=${AZURE_TENANT_ID}
AZURE_CLIENT_ID=${AZURE_CLIENT_ID}
AZURE_CLIENT_SECRET=${AZURE_CLIENT_SECRET}
AZURE_RESOURCE_GROUP=${AZURE_RESOURCE_GROUP}
EOF
ferdi@DESKTOP-NL6I2OD:~/velero-test$ 

⁠Generate YAML for Velero installation 2

velero install \
    --provider azure \
    --plugins velero/velero-plugin-for-microsoft-azure:v1.6.0 \
    --bucket $BLOB_CONTAINER \
    --secret-file ./credentials-velero2 \
    --backup-location-config resourceGroup=$AZURE_BACKUP_RESOURCE_GROUP,storageAccount=$AZURE_STORAGE_ACCOUNT_ID[,subscriptionId=$AZURE_BACKUP_SUBSCRIPTION_ID] \
    --snapshot-location-config apiTimeout=2m0s[,resourceGroup=$AZURE_BACKUP_RESOURCE_GROUP,subscriptionId=$AZURE_BACKUP_SUBSCRIPTION_ID] \
    --dry-run -o yaml > velero-install2.yml

Tag summary

Content type

Image

Digest

sha256:bb471db15…

Size

47.2 MB

Last updated

over 1 year ago

docker pull rimmon1971/backupper:15