OADP Operator issues
Resolve issues with the OpenShift API for Data Protection (OADP) Operator, such as silent failures that prevent proper operation. This helps you restore normal Operator functionality and ensure successful backup and restore operations.
Resolving silent failure of the OADP Operator
Resolve the silent failure issue where the OADP Operator reports a Running status but the AWS S3 buckets remain empty due to incorrect cloud credentials permissions. This helps you identify and fix credential permission problems in your backup storage locations.
To fix this issue, retrieve a list of backup storage locations (BSLs) and check the manifest of each BSL for credential issues.
Procedure
-
Retrieve a list of BSLs by using either the OpenShift CLI or the OADP CLI:
- Retrieve a list of BSLs by using the OpenShift CLI (
oc):$ oc get backupstoragelocations.velero.io -A - Retrieve a list of BSLs by using the OADP CLI:
$ oc oadp backup-location get -n <oadp_operator_namespace>
- Retrieve a list of BSLs by using the OpenShift CLI (
-
Use the list of BSLs from the previous step and run the following command to examine the manifest of each BSL for an error:
$ oc get backupstoragelocations.velero.io -n <namespace> -o yamlapiVersion: v1items:- apiVersion: velero.io/v1kind: BackupStorageLocationmetadata:creationTimestamp: "2023-11-03T19:49:04Z"generation: 9703name: example-dpa-1namespace: openshift-adp-operatorownerReferences:- apiVersion: oadp.openshift.io/v1alpha1blockOwnerDeletion: truecontroller: truekind: DataProtectionApplicationname: example-dpauid: 0beeeaff-0287-4f32-bcb1-2e3c921b6e82resourceVersion: "24273698"uid: ba37cd15-cf17-4f7d-bf03-8af8655cea83spec:config:enableSharedConfig: "true"region: us-west-2credential:key: credentialsname: cloud-credentialsdefault: trueobjectStorage:bucket: example-oadp-operatorprefix: exampleprovider: awsstatus:lastValidationTime: "2023-11-10T22:06:46Z"message: "BackupStorageLocation \"example-dpa-1\" is unavailable: rpcerror: code = Unknown desc = WebIdentityErr: failed to retrieve credentials\ncausedby: AccessDenied: Not authorized to perform sts:AssumeRoleWithWebIdentity\n\tstatuscode: 403, request id: d3f2e099-70a0-467b-997e-ff62345e3b54"phase: Unavailablekind: Listmetadata:resourceVersion: ""