Wire worker kubeconfig hostPath (no PATH override), enable daily-cnpg-option-a-backup for R01 targets, ESO already synced.
1.7 KiB
1.7 KiB
| id | name | enabled | owner | governance | status | trigger | context_sources | ||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| daily-cnpg-option-a-backup | Daily CNPG Option A Backup | true | custodian-agent | custodian | active |
|
|
Daily CNPG Option A Backup
Runs daily at 02:30 UTC (RPO 24h). Invokes
railiance-platform/tools/cmd/cnpg-option-a-backup on the railiance01
activity-core worker to age-encrypt logical dumps and upload to Nextcloud.
Workplan: RAILIANCE-WP-0016 (railiance-apps).
Enable checklist
- Vendor tools on railiance01 hostPath tree:
tools/cmd/install-cnpg-backup-vendor-tools(age + kubectl). - ExternalSecret
actcore-backup-offsitesynced intoactcore-runtime-secret(NC_WEBDAV_TOKEN,NC_WEBDAV_URL,AGE_PUBLIC_KEY). - Worker mounts:
/opt/railiance-platform,/kube(host kubeconfigs). - CoulombCore kubeconfig present at
/kube/configfor Core clusters; R01 at/kube/config-hosteurope. enabled: true+make sync/ schedule reconcile on railiance01.- Forced run succeeds;
make cnpg-backup-statusstays healthy.
Starts disabled until T02–T04 wiring is verified on railiance01.