29_backup_k8s_etcd.yml - Usage Guide
Takes a snapshot of the etcd database (the heart of Kubernetes) and stores it safely.
Playbook: playbooks/29_backup_k8s_etcd.yml
What it does
- Detects whether the cluster uses
k3sorkubeadm(etcdctl). - Takes the snapshot and saves it under
/var/backups/etcdwith a timestamp. - Protects the backup directory with
0700and snapshot files with0600. - After a successful backup, removes snapshots older than the retention period.
- Runs only on the first server in the master nodes to avoid duplicate work.
Parameters (optional)
| Variable | Default | Description |
|---|---|---|
etcd_backup_retention_days | 30 | After a successful backup, deletes snapshots older than this many days. Must be a positive integer. |
ansible-playbook -i inventories/musteri_a/hosts.ini playbooks/29_backup_k8s_etcd.yml \
--extra-vars 'etcd_backup_retention_days=14'
An etcd snapshot also contains Kubernetes Secret data. Restrict access to the backup directory to authorized users and copy the backup to a separate, encrypted location.
Sample output
################################################################################
# HOST: master1
################################################################################
k3s detected. Running k3s etcd-snapshot...
Retention: snapshots older than 30 days were removed.
SUCCESS: k3s etcd snapshot saved to /var/backups/etcd