- What's New
- Product Bulletin
- Service Overview
- Billing
- Getting Started
-
User Guide
-
UCS Clusters
- Overview
- Huawei Cloud Clusters
-
On-Premises Clusters
- Overview
- Service Planning for On-Premises Cluster Installation
- Registering an On-Premises Cluster
- Installing an On-Premises Cluster
- Managing an On-Premises Cluster
- Attached Clusters
- Multi-Cloud Clusters
- Single-Cluster Management
- Fleets
-
Cluster Federation
- Overview
- Enabling Cluster Federation
- Using kubectl to Connect to a Federation
- Upgrading a Federation
-
Workloads
- Workload Creation
-
Container Settings
- Setting Basic Container Information
- Setting Container Specifications
- Setting Container Lifecycle Parameters
- Setting Health Check for a Container
- Setting Environment Variables
- Configuring a Workload Upgrade Policy
- Configuring a Scheduling Policy (Affinity/Anti-affinity)
- Configuring Scheduling and Differentiation
- Managing a Workload
- ConfigMaps and Secrets
- Services and Ingresses
- MCI
- MCS
- DNS Policies
- Storage
- Namespaces
- Multi-Cluster Workload Scaling
- Adding Labels and Taints to a Cluster
- RBAC Authorization for Cluster Federations
- Image Repositories
- Permissions
-
Policy Center
- Overview
- Basic Concepts
- Enabling Policy Center
- Creating and Managing Policy Instances
- Example: Using Policy Center for Kubernetes Resource Compliance Governance
-
Policy Definition Library
- Overview
- k8spspvolumetypes
- k8spspallowedusers
- k8spspselinuxv2
- k8spspseccomp
- k8spspreadonlyrootfilesystem
- k8spspprocmount
- k8spspprivilegedcontainer
- k8spsphostnetworkingports
- k8spsphostnamespace
- k8spsphostfilesystem
- k8spspfsgroup
- k8spspforbiddensysctls
- k8spspflexvolumes
- k8spspcapabilities
- k8spspapparmor
- k8spspallowprivilegeescalationcontainer
- k8srequiredprobes
- k8srequiredlabels
- k8srequiredannotations
- k8sreplicalimits
- noupdateserviceaccount
- k8simagedigests
- k8sexternalips
- k8sdisallowedtags
- k8sdisallowanonymous
- k8srequiredresources
- k8scontainerratios
- k8scontainerrequests
- k8scontainerlimits
- k8sblockwildcardingress
- k8sblocknodeport
- k8sblockloadbalancer
- k8sblockendpointeditdefaultrole
- k8spspautomountserviceaccounttokenpod
- k8sallowedrepos
- Configuration Management
- Traffic Distribution
- Observability
- Container Migration
- Pipeline
- Error Codes
-
UCS Clusters
- Best Practices
-
API Reference
- Before You Start
- Calling APIs
-
API
- UCS Cluster
-
Fleet
- Adding a Cluster to a Fleet
- Removing a Cluster from a Fleet
- Registering a Fleet
- Deleting a Fleet
- Querying a Fleet
- Adding Clusters to a Fleet
- Updating Fleet Description
- Updating Permission Policies Associated with a Fleet
- Updating the Zone Associated with the Federation of a Fleet
- Obtaining the Fleet List
- Enabling Fleet Federation
- Disabling Cluster Federation
- Querying Federation Enabling Progress
- Creating a Federation Connection and Downloading kubeconfig
- Creating a Federation Connection
- Downloading Federation kubeconfig
- Permissions Management
- Using the Karmada API
- Appendix
-
FAQs
- About UCS
-
Billing
- How Is UCS Billed?
- What Status of a Cluster Will Incur UCS Charges?
- Why Am I Still Being Billed After I Purchase a Resource Package?
- How Do I Change the Billing Mode of a Cluster from Pay-per-Use to Yearly/Monthly?
- What Types of Invoices Are There?
- Can I Unsubscribe from or Modify a Resource Package?
-
Permissions
- How Do I Configure Access Permissions for Each Function of the UCS Console?
- What Can I Do If an IAM User Cannot Obtain Cluster or Fleet Information After Logging In to UCS?
- How Do I Restore ucs_admin_trust I Deleted or Modified?
- What Can I Do If I Cannot Associate the Permission Policy with a Fleet or Cluster?
- How Do I Clear RBAC Resources After a Cluster Is Unregistered?
- Policy Center
-
Fleets
- What Can I Do If Cluster Federation Verification Fails to Be Enabled for a Fleet?
- What Can I Do If an Abnormal, Federated Cluster Fails to Be Removed from the Fleet?
- What Can I Do If an Nginx Ingress Is in the Unready State After Being Deployed?
- What Can I Do If "Error from server (Forbidden)" Is Displayed When I Run the kubectl Command?
- Huawei Cloud Clusters
- Attached Clusters
-
On-Premises Clusters
- What Can I Do If an On-Premises Cluster Fails to Be Connected?
- How Do I Manually Clear Nodes of an On-Premises Cluster?
- How Do I Downgrade a cgroup?
- What Can I Do If the VM SSH Connection Times Out?
- How Do I Expand the Disk Capacity of the CIA Add-on in an On-Premises Cluster?
- What Can I Do If the Cluster Console Is Unavailable After the Master Node Is Shut Down?
- What Can I Do If a Node Is Not Ready After Its Scale-Out?
- How Do I Update the CA/TLS Certificate of an On-Premises Cluster?
- What Can I Do If an On-Premises Cluster Fails to Be Installed?
- Multi-Cloud Clusters
-
Cluster Federation
- What Can I Do If the Pre-upgrade Check of the Cluster Federation Fails?
- What Can I Do If a Cluster Fails to Be Added to a Federation?
- What Can I Do If Status Verification Fails When Clusters Are Added to a Federation?
- What Can I Do If an HPA Created on the Cluster Federation Management Plane Fails to Be Distributed to Member Clusters?
- What Can I Do If an MCI Object Fails to Be Created?
- What Can I Do If I Fail to Access a Service Through MCI?
- What Can I Do If an MCS Object Fails to Be Created?
- What Can I Do If an MCS or MCI Instance Fails to Be Deleted?
- Traffic Distribution
- Container Intelligent Analysis
- General Reference
Copied.
e-backup
Introduction
e-backup is a subsystem in Everest 2.0 (cloud native storage system) for protecting cloud native application data. With e-backup, you can back up application data (Kubernetes resources) and service data (data in PVs) to OBS and restore backup data to a specified cluster.
The backup and restoration functions of e-backup are available for:
- Single cluster DR
The data of applications in a cluster is periodically backed up. When the cluster or an application is damaged, you can redeploy the application to the cluster to take over services in disaster scenarios.
- Intra-cluster/Cross-cluster clone
If multiple applications need to be cloned across clusters, especially the applications that have been working in a cluster for a period of time, their data is backed up and then restored to different namespaces in the same cluster or other clusters.
- Cross-cluster/Cross-cloud migration
If applications need to be migrated from a cluster to another cluster across regions or from another cloud to CCE due to network, cost, or service location changes, their data is backed up and then restored to the destination cluster.
Constraints
- The cluster version must be 1.15 or later and have at least one available node.
- When e-backup is installed in a cluster, the cluster image can be pulled from SWR.
- To prevent failures or incomplete data, you cannot add, delete, or modify the cluster during the backup or restoration. If there are any changes to a cluster, you are advised to wait for 15 minutes until the cluster is stable and then perform the backup operation.
- e-backup integrates the PV data backup capability of restic. e-backup can create a snapshot for the data at the backup time point and upload the data, which does not affect subsequent data read and write. However, restic does not verify the file content and service consistency.
- The memory occupied by restic depends on the size of the PV data backed up for the first time. If there is more than 300 GB of data, use the data migration method provided by the cloud storage. If you use application data management to migrate a large amount of PV data, you can modify the resource levels of the restic instance. For details, see Modifying Add-on Settings.
- e-backup complies with velero and restic constraints. For example, during the restoration, the Service will clear the ClusterIP to better adapt to the differences between the source and target clusters.
- When restoring an application in a CCE cluster that uses a secret (cfe/secure-opaque) for data encryption to another cluster, you need to manually create a secret with the same name and type as the original cluster. This ensures that the restored application runs normally.
- e-backup cannot be installed in UCS on-premises clusters.
Installing e-backup
e-backup depends on the custom resource BackupStorageLocation and its secret to execute backup and restore tasks. However, the resource will change if it is uninstalled and reinstalled. As a result, if you uninstall e-backup, existing backups may not be restored.
- Access the cluster details page.
- In the navigation pane, choose Add-ons. In the Add-ons Available area, click Install of e-backup.
- Configure the parameters as described in Table 1.
Table 1 e-backup parameters Parameter
Description
Add-on Specifications
Select Standalone.
Containers
Configure resource levels for the add-on instance.
- velero: backup and restoration of Kubernetes metadata.
- restic: backup and restoration of application data storage volumes.
NOTE:
- To ensure the add-on instance can be scheduled, reserve sufficient resources in the cluster.
- To create an add-on instance, ensure the request is no more than the limit.
- To avoid add-on faults, adjust the resource limit based on the amount of data to be backed up or restored.
- Configure volumeWorkerNum.
volumeWorkerNum indicates the number of concurrent data volume backup tasks, which defaults to 3.
{ "volumeWorkerNum": 3 }
- Click Install and check the add-on status on the Add-ons page.
Running indicates the add-on has been installed in the cluster.
Modifying Add-on Settings
- Access the cluster details page.
- In the navigation pane, choose Add-ons. In the Add-ons Installed area, click Edit of e-backup.
- Modify the add-on settings. For details about related parameters, see Table 1.
- Click OK. The add-on is in the Upgrading state. After the upgrade is complete, new settings will be used.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot