Postgres backups (CNPG)
The k3s target runs Postgres via the CloudNativePG operator. HA (3 instances) is on by default in prod. Off-site backups are opt-in, so the default stack deploys without an object store configured.
Enable backups
Section titled “Enable backups”-
Credentials. Provide an S3-compatible access key as a
boringstack-backupSecret (keysACCESS_KEY_ID/ACCESS_SECRET_KEY). With Vault, uncommentvault-backup-secret.yamlinoverlays/prod/secrets/vault/kustomization.yamland seed:Terminal window vault kv put secret/boringstack-backup \AWS_ACCESS_KEY_ID=<key> AWS_SECRET_ACCESS_KEY=<secret> -
Store. Edit
overlays/prod/patches/postgres-backup.yaml: setdestinationPath(e.g.s3://my-bucket/boringstack) andendpointURL(e.g. your Cloudflare R2 endpoint). AdjustretentionPolicy. -
Wire it up. In
overlays/prod/kustomization.yaml, uncomment:- the
scheduled-backup.yamlresource (runs every 4h via CNPG’s 6-field cron) - the
patches/postgres-backup.yamlpatch (attaches the barman store and enables WAL archiving)
- the
Sync. CNPG starts archiving WAL and taking base backups on schedule.
Verify
Section titled “Verify”kubectl -n boringstack-prod get cluster boringstack-db -o jsonpath='{.status.conditions}'kubectl -n boringstack-prod get backupsRestore
Section titled “Restore”CloudNativePG restores by bootstrapping a new Cluster from the object store
(bootstrap.recovery); you don’t restore in place. See the
CNPG recovery docs,
then point a recovery externalCluster at the same barmanObjectStore and the
boringstack-backup credentials.
Related
Section titled “Related”- Provisioning with k3s
- Backups (Compose path), the single-host equivalent.