Backing up 3scale API Management by using OADP
Back up Red Hat 3scale API Management components, including the 3scale Operator, MySQL database, and Redis database, by using OpenShift API for Data Protection (OADP). This helps you protect your API management infrastructure and provides recovery in case of data loss.
For more information about installing and configuring Red Hat 3scale API Management, see Installing 3scale API Management on OpenShift and Red Hat 3scale API Management.
Creating the Data Protection Application
Create a Data Protection Application (DPA) custom resource (CR) to configure backup storage and Velero settings for Red Hat 3scale API Management. This helps you set up the backup infrastructure required for protecting your 3scale components.
Procedure
-
Create a YAML file with the following configuration:
apiVersion: oadp.openshift.io/v1alpha1kind: DataProtectionApplicationmetadata:name: dpa-samplenamespace: openshift-adpspec:configuration:velero:defaultPlugins:- openshift- aws- csiresourceTimeout: 10mnodeAgent:enable: trueuploaderType: kopiabackupLocations:- name: defaultvelero:provider: awsdefault: trueobjectStorage:bucket: <bucket_name>prefix: <prefix>config:region: <region>profile: "default"s3ForcePathStyle: "true"s3Url: <s3_url>credential:key: cloudname: cloud-credentialswhere:
<bucket_name>- Specifies a bucket as the backup storage location. If the bucket is not a dedicated bucket for Velero backups, you must specify a prefix.
<prefix>- Specifies a prefix for Velero backups, for example,
velero, if the bucket is used for multiple purposes. <region>- Specifies a region for backup storage location.
<s3_url>- Specifies the URL of the object store that you are using to store backups.
-
Create the DPA CR by running the following command:
$ oc create -f dpa.yaml
Backing up the 3scale API Management operator, secret, and APIManager
Back up the Red Hat 3scale API Management operator resources, including the Secret and APIManager custom resources (CRs), by creating backup CRs. This helps you preserve your 3scale operator configuration for recovery scenarios.
Prerequisites
- You created the Data Protection Application (DPA).
Procedure
-
Back up your 3scale operator CRs, such as
operatorgroup,namespaces, andsubscriptions, by creating a YAML file with the following configuration:apiVersion: velero.io/v1kind: Backupmetadata:name: operator-install-backupnamespace: openshift-adpspec:csiSnapshotTimeout: 10m0sdefaultVolumesToFsBackup: falseincludedNamespaces:- threescaleincludedResources:- operatorgroups- subscriptions- namespacesitemOperationTimeout: 1h0m0ssnapshotMoveData: falsettl: 720h0m0swhere:
operator-install-backup- Specifies the value of the
metadata.nameparameter in the backup. This is the same value used in themetadata.backupNameparameter used when restoring the 3scale operator. threescale- Specifies the namespace where the 3scale operator is installed.
noteYou can also back up and restore
ReplicationControllers,Deployment, andPodobjects to ensure that all manually set environments are backed up and restored. This does not affect the flow of restoration. -
Create a backup CR by running the following command:
$ oc create -f backup.yamlExample outputbackup.velero.io/operator-install-backup created -
Back up the
SecretCR by creating a YAML file with the following configuration:apiVersion: velero.io/v1kind: Backupmetadata:name: operator-resources-secretsnamespace: openshift-adpspec:csiSnapshotTimeout: 10m0sdefaultVolumesToFsBackup: falseincludedNamespaces:- threescaleincludedResources:- secretsitemOperationTimeout: 1h0m0slabelSelector:matchLabels:app: 3scale-api-managementsnapshotMoveData: falsesnapshotVolumes: falsettl: 720h0m0sname- Specifies the value of the
metadata.nameparameter in the backup. Use this value in themetadata.backupNameparameter when restoring theSecret.
-
Create the
Secretbackup CR by running the following command:$ oc create -f backup-secret.yamlExample outputbackup.velero.io/operator-resources-secrets created -
Back up the APIManager CR by creating a YAML file with the following configuration:
apiVersion: velero.io/v1kind: Backupmetadata:name: operator-resources-apimnamespace: openshift-adpspec:csiSnapshotTimeout: 10m0sdefaultVolumesToFsBackup: falseincludedNamespaces:- threescaleincludedResources:- apimanagersitemOperationTimeout: 1h0m0ssnapshotMoveData: falsesnapshotVolumes: falsestorageLocation: ts-dpa-1ttl: 720h0m0svolumeSnapshotLocations:- ts-dpa-1name- Specifies the value of the
metadata.nameparameter in the backup. Use this value in themetadata.backupNameparameter when restoring the APIManager.
-
Create the APIManager CR by running the following command:
$ oc create -f backup-apimanager.yamlExample outputbackup.velero.io/operator-resources-apim created
Backing up a MySQL database
Back up a MySQL database by creating a persistent volume claim (PVC) to store the database dump. This helps you preserve your 3scale system database data for recovery scenarios.
Prerequisites
- You have backed up the Red Hat 3scale API Management operator.
Procedure
-
Create a YAML file with the following configuration for adding an additional PVC:
kind: PersistentVolumeClaimapiVersion: v1metadata:name: example-claimnamespace: threescalespec:accessModes:- ReadWriteOnceresources:requests:storage: 1GistorageClassName: gp3-csivolumeMode: Filesystem -
Create the additional PVC by running the following command:
$ oc create -f ts_pvc.yml -
Attach the PVC to the system database pod by editing the
system-mysqldeployment to use the MySQL dump:$ oc edit deployment system-mysql -n threescalevolumeMounts:- name: example-claimmountPath: /var/lib/mysqldump/data- name: mysql-storagemountPath: /var/lib/mysql/data- name: mysql-extra-confmountPath: /etc/my-extra.d- name: mysql-main-confmountPath: /etc/my-extra...serviceAccount: ampvolumes:- name: example-claimpersistentVolumeClaim:claimName: example-claim...claimName- Specifies the PVC that contains the dumped data.
-
Create a YAML file with following configuration to back up the MySQL database:
apiVersion: velero.io/v1kind: Backupmetadata:name: mysql-backupnamespace: openshift-adpspec:csiSnapshotTimeout: 10m0sdefaultVolumesToFsBackup: truehooks:resources:- name: dumpdbpre:- exec:command:- /bin/sh- -c- mysqldump -u $MYSQL_USER --password=$MYSQL_PASSWORD system --no-tablespaces> /var/lib/mysqldump/data/dump.sqlcontainer: system-mysqlonError: Failtimeout: 5mincludedNamespaces:- threescaleincludedResources:- deployment- pods- replicationControllers- persistentvolumeclaims- persistentvolumesitemOperationTimeout: 1h0m0slabelSelector:matchLabels:app: 3scale-api-managementthreescale_component_element: mysqlsnapshotMoveData: falsettl: 720h0m0swhere:
mysql-backup- Specifies the value of the
metadata.nameparameter in the backup. Use this value in themetadata.backupNameparameter when restoring the MySQL database. /var/lib/mysqldump/data/dump.sql- Specifies the directory where the data is backed up.
includedResources- Specifies the resources to back up.
-
Back up the MySQL database by running the following command:
$ oc create -f mysql.yamlExample outputbackup.velero.io/mysql-backup created
Verification
-
Verify that the MySQL backup is completed by running the following command:
$ oc get backups.velero.io mysql-backup -o yamlExample outputstatus:completionTimestamp: "2025-04-17T13:25:19Z"errors: 1expiration: "2025-05-17T13:25:16Z"formatVersion: 1.1.0hookStatus: {}phase: Completedprogress: {}startTimestamp: "2025-04-17T13:25:16Z"version: 1
Backing up the back-end Redis database
Back up the back-end Redis database by configuring Velero annotations and creating a backup CR with the required resources. This helps you preserve your 3scale back-end Redis data for recovery scenarios.
Prerequisites
- You backed up the Red Hat 3scale API Management operator.
- You backed up your MySQL database.
- The Redis queues have been drained before performing the backup.
Procedure
-
Edit the annotations on the
backend-redisdeployment by running the following command:$ oc edit deployment backend-redis -n threescaleannotations:post.hook.backup.velero.io/command: >-["/bin/bash", "-c", "redis-cli CONFIG SET auto-aof-rewrite-percentage100"]pre.hook.backup.velero.io/command: >-["/bin/bash", "-c", "redis-cli CONFIG SET auto-aof-rewrite-percentage0"] -
Create a YAML file with the following configuration to back up the Redis database:
apiVersion: velero.io/v1kind: Backupmetadata:name: redis-backupnamespace: openshift-adpspec:csiSnapshotTimeout: 10m0sdefaultVolumesToFsBackup: trueincludedNamespaces:- threescaleincludedResources:- deployment- pods- replicationcontrollers- persistentvolumes- persistentvolumeclaimsitemOperationTimeout: 1h0m0slabelSelector:matchLabels:app: 3scale-api-managementthreescale_component: backendthreescale_component_element: redissnapshotMoveData: falsesnapshotVolumes: falsettl: 720h0m0sname- Specifies the value of the
metadata.nameparameter in the backup. Use this value in themetadata.backupNameparameter when restoring the Redis database.
-
Back up the Redis database by running the following command:
$ oc create -f redis-backup.yamlExample outputbackup.velero.io/redis-backup created
Verification
-
Verify that the Redis backup is completed by running the following command:
$ oc get backups.velero.io redis-backup -o yamlExample outputstatus:completionTimestamp: "2025-04-17T13:25:19Z"errors: 1expiration: "2025-05-17T13:25:16Z"formatVersion: 1.1.0hookStatus: {}phase: Completedprogress: {}startTimestamp: "2025-04-17T13:25:16Z"version: 1
Additional resources