Skip to content

feat(cnpg): move shared-cluster backups off Linode to GCS - #225

Merged
themightychris merged 1 commit into
mainfrom
feat/cnpg-backups-gcs
Sep 28, 2026
Merged

themightychris merged 1 commit into
mainfrom
feat/cnpg-backups-gcs

Conversation

@themightychris

Copy link
Copy Markdown
Member

Supersedes the Linode destination from #223 before it ever took a backup. Deploy PR #224 should be left unmerged; this one's deploy PR replaces it. Mirrors the sandbox PR.

  • Bucket gs://cnpg-live in GCP project openphl-1177, us-east4, uniform access, public access prevented. Off Linode on purpose: the backup has to survive losing the Linode account or region, which a Linode bucket next to the cluster wouldn't.
  • Service account cnpg-backup-live@openphl-1177 with objectAdmin + legacyBucketReader on that one bucket only; JSON key sealed as cloudnative-pg.secrets/cnpg-backup-creds.yaml (key gcsCredentials).
  • ObjectStore/gcs-cnpg replaces linode-cnpg; the Cluster's plugin parameter follows. Compression, 30-day retention and the 04:00 UTC ScheduledBackup with immediate: true are unchanged from feat(cnpg): back up shared-cluster to Linode Object Storage #223. CLAUDE.md updated to match.

Projection QA

git diff --name-status origin/deploys/k8s-manifests <projection>: 4 files in cloudnative-pg: Cluster gains plugins, plus ObjectStore, ScheduledBackup and SealedSecret.

🤖 Generated with Claude Code

ObjectStore gcs-cnpg -> gs://cnpg-live/ in GCP project openphl-1177
(us-east4), replacing the Linode bucket from #223 before it ever took a
backup. Off-provider so backups survive losing the Linode account or
region. Sealed service-account key scoped to this one bucket.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@themightychris
themightychris requested a review from a team as a code owner September 28, 2026 19:35
@themightychris
themightychris merged commit 4c1912f into main Sep 28, 2026
@themightychris
themightychris deleted the feat/cnpg-backups-gcs branch September 28, 2026 19:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant