Data Protection¶
Two mechanisms, protecting two different losses. Choosing between them is really choosing what you are afraid of.
| You are protecting against | Use | Runs in |
|---|---|---|
| Losing the data in a volume — a bad migration, a corrupted database, a deletion you regret | Volume Snapshots | Your cluster |
| Losing the cluster — a teardown, a botched upgrade, an Environment you have to rebuild | Cluster Backup & Restore | Your Environment |
They are not alternatives.
A ClusterBackup captures API objects and not bytes, so it rebuilds your workloads and hands them empty volumes unless the volumes were set to survive.
A VolumeSnapshot holds bytes and nothing else, so it cannot recreate a cluster to mount them.
A real recovery plan uses both.
Three things to settle before you need any of it¶
Retain on the volumes that matter.
The default is that your volume is deleted with the cluster that claimed it.
Retain is what carries a volume through a restore, it has to be set while the volume exists, and nothing sets it for you — see Volumes need Retain.
Enough quota to restore into. A restore is new storage, not reclaimed storage. Restoring a 20Gi snapshot needs 20Gi of headroom, and a restored cluster needs quota for a whole second set of volumes while the old ones still exist. A budget with no slack is a backup you cannot use.
Something off the platform.
Both mechanisms live on the platform you would be trying to survive: a snapshot sits on the same storage as its volume, and a ClusterBackup needs the platform to build a new cluster into.
For anything whose loss is not survivable, a dump to storage outside the platform is the unglamorous thing that actually works.
What you need from your platform team¶
Neither mechanism is entirely self-service.
| For | You need |
|---|---|
ClusterBackup |
Permission to create the object at all — it is not granted by default — plus a bucket, S3 credentials and an encryption key in your Environment. |
| A restore | The cluster to still be buildable: the tier enabled, a Kubernetes version inside the window, and free quota and addresses. |
Retain as a default |
A second StorageClass in your cluster. The default class cannot be changed. |
VolumeSnapshot |
Nothing. It is already there. |
If kubectl get clusterbackups -n <your-environment> is refused, that is the first conversation to have — see Cluster Backup & Restore.