Backing up 3scale API Management by using OADP
Back up Red Hat 3scale API Management components, including the 3scale Operator, MySQL database, and Redis database, by using OpenShift API for Data Protection (OADP). This helps you protect your API management infrastructure and provides recovery in case of data loss.
For more information about installing and configuring Red Hat 3scale API Management, see Installing 3scale API Management on OpenShift and Red Hat 3scale API Management.
Creating the Data Protection Application
Create a Data Protection Application (DPA) custom resource (CR) to configure backup storage and Velero settings for Red Hat 3scale API Management. This helps you set up the backup infrastructure required for protecting your 3scale components.
Procedure
- Create a YAML file with the following configuration:yaml
apiVersion: oadp.openshift.io/v1alpha1 kind: DataProtectionApplication metadata: name: dpa-sample namespace: openshift-adp spec: configuration: velero: defaultPlugins: - openshift - aws - csi resourceTimeout: 10m nodeAgent: enable: true uploaderType: kopia backupLocations: - name: default velero: provider: aws default: true objectStorage: bucket: <bucket_name> prefix: <prefix> config: region: <region> profile: "default" s3ForcePathStyle: "true" s3Url: <s3_url> credential: key: cloud name: cloud-credentialswhere:
<bucket_name>Specifies a bucket as the backup storage location. If the bucket is not a dedicated bucket for Velero backups, you must specify a prefix.
<prefix>Specifies a prefix for Velero backups, for example,
velero, if the bucket is used for multiple purposes.<region>Specifies a region for backup storage location.
<s3_url>Specifies the URL of the object store that you are using to store backups.
- Create the DPA CR by running the following command:terminal
$ oc create -f dpa.yaml
Backing up the 3scale API Management operator, secret, and APIManager
Back up the Red Hat 3scale API Management operator resources, including the Secret and APIManager custom resources (CRs), by creating backup CRs. This helps you preserve your 3scale operator configuration for recovery scenarios.
Prerequisites
- You created the Data Protection Application (DPA).
Procedure
- Back up your 3scale operator CRs, such as
operatorgroup,namespaces, andsubscriptions, by creating a YAML file with the following configuration:yamlapiVersion: velero.io/v1 kind: Backup metadata: name: operator-install-backup namespace: openshift-adp spec: csiSnapshotTimeout: 10m0s defaultVolumesToFsBackup: false includedNamespaces: - threescale includedResources: - operatorgroups - subscriptions - namespaces itemOperationTimeout: 1h0m0s snapshotMoveData: false ttl: 720h0m0swhere:
operator-install-backupSpecifies the value of the
metadata.nameparameter in the backup. This is the same value used in themetadata.backupNameparameter used when restoring the 3scale operator.threescaleSpecifies the namespace where the 3scale operator is installed.
NoteYou can also back up and restore
ReplicationControllers,Deployment, andPodobjects to ensure that all manually set environments are backed up and restored. This does not affect the flow of restoration. - Create a backup CR by running the following command:terminal
$ oc create -f backup.yamlExample outputbackup.velero.io/operator-install-backup created - Back up the
SecretCR by creating a YAML file with the following configuration:yamlapiVersion: velero.io/v1 kind: Backup metadata: name: operator-resources-secrets namespace: openshift-adp spec: csiSnapshotTimeout: 10m0s defaultVolumesToFsBackup: false includedNamespaces: - threescale includedResources: - secrets itemOperationTimeout: 1h0m0s labelSelector: matchLabels: app: 3scale-api-management snapshotMoveData: false snapshotVolumes: false ttl: 720h0m0snameSpecifies the value of the
metadata.nameparameter in the backup. Use this value in themetadata.backupNameparameter when restoring theSecret.
- Create the
Secretbackup CR by running the following command:terminal$ oc create -f backup-secret.yamlExample outputbackup.velero.io/operator-resources-secrets created - Back up the APIManager CR by creating a YAML file with the following configuration:yaml
apiVersion: velero.io/v1 kind: Backup metadata: name: operator-resources-apim namespace: openshift-adp spec: csiSnapshotTimeout: 10m0s defaultVolumesToFsBackup: false includedNamespaces: - threescale includedResources: - apimanagers itemOperationTimeout: 1h0m0s snapshotMoveData: false snapshotVolumes: false storageLocation: ts-dpa-1 ttl: 720h0m0s volumeSnapshotLocations: - ts-dpa-1nameSpecifies the value of the
metadata.nameparameter in the backup. Use this value in themetadata.backupNameparameter when restoring the APIManager.
- Create the APIManager CR by running the following command:terminal
$ oc create -f backup-apimanager.yamlExample outputbackup.velero.io/operator-resources-apim created
Backing up a MySQL database
Back up a MySQL database by creating a persistent volume claim (PVC) to store the database dump. This helps you preserve your 3scale system database data for recovery scenarios.
Prerequisites
- You have backed up the Red Hat 3scale API Management operator.
Procedure
- Create a YAML file with the following configuration for adding an additional PVC:yaml
kind: PersistentVolumeClaim apiVersion: v1 metadata: name: example-claim namespace: threescale spec: accessModes: - ReadWriteOnce resources: requests: storage: 1Gi storageClassName: gp3-csi volumeMode: Filesystem - Create the additional PVC by running the following command:terminal
$ oc create -f ts_pvc.yml - Attach the PVC to the system database pod by editing the
system-mysqldeployment to use the MySQL dump:terminal$ oc edit deployment system-mysql -n threescaleyamlvolumeMounts: - name: example-claim mountPath: /var/lib/mysqldump/data - name: mysql-storage mountPath: /var/lib/mysql/data - name: mysql-extra-conf mountPath: /etc/my-extra.d - name: mysql-main-conf mountPath: /etc/my-extra ... serviceAccount: amp volumes: - name: example-claim persistentVolumeClaim: claimName: example-claim ...claimNameSpecifies the PVC that contains the dumped data.
- Create a YAML file with following configuration to back up the MySQL database:yaml
apiVersion: velero.io/v1 kind: Backup metadata: name: mysql-backup namespace: openshift-adp spec: csiSnapshotTimeout: 10m0s defaultVolumesToFsBackup: true hooks: resources: - name: dumpdb pre: - exec: command: - /bin/sh - -c - mysqldump -u $MYSQL_USER --password=$MYSQL_PASSWORD system --no-tablespaces > /var/lib/mysqldump/data/dump.sql container: system-mysql onError: Fail timeout: 5m includedNamespaces: - threescale includedResources: - deployment - pods - replicationControllers - persistentvolumeclaims - persistentvolumes itemOperationTimeout: 1h0m0s labelSelector: matchLabels: app: 3scale-api-management threescale_component_element: mysql snapshotMoveData: false ttl: 720h0m0swhere:
mysql-backupSpecifies the value of the
metadata.nameparameter in the backup. Use this value in themetadata.backupNameparameter when restoring the MySQL database./var/lib/mysqldump/data/dump.sqlSpecifies the directory where the data is backed up.
includedResourcesSpecifies the resources to back up.
- Back up the MySQL database by running the following command:terminal
$ oc create -f mysql.yamlExample outputbackup.velero.io/mysql-backup created
Verification
- Verify that the MySQL backup is completed by running the following command:terminal
$ oc get backups.velero.io mysql-backup -o yamlExample outputstatus: completionTimestamp: "2025-04-17T13:25:19Z" errors: 1 expiration: "2025-05-17T13:25:16Z" formatVersion: 1.1.0 hookStatus: {} phase: Completed progress: {} startTimestamp: "2025-04-17T13:25:16Z" version: 1
Backing up the back-end Redis database
Back up the back-end Redis database by configuring Velero annotations and creating a backup CR with the required resources. This helps you preserve your 3scale back-end Redis data for recovery scenarios.
Prerequisites
- You backed up the Red Hat 3scale API Management operator.
- You backed up your MySQL database.
- The Redis queues have been drained before performing the backup.
Procedure
- Edit the annotations on the
backend-redisdeployment by running the following command:terminal$ oc edit deployment backend-redis -n threescaleyamlannotations: post.hook.backup.velero.io/command: >- ["/bin/bash", "-c", "redis-cli CONFIG SET auto-aof-rewrite-percentage 100"] pre.hook.backup.velero.io/command: >- ["/bin/bash", "-c", "redis-cli CONFIG SET auto-aof-rewrite-percentage 0"] - Create a YAML file with the following configuration to back up the Redis database:yaml
apiVersion: velero.io/v1 kind: Backup metadata: name: redis-backup namespace: openshift-adp spec: csiSnapshotTimeout: 10m0s defaultVolumesToFsBackup: true includedNamespaces: - threescale includedResources: - deployment - pods - replicationcontrollers - persistentvolumes - persistentvolumeclaims itemOperationTimeout: 1h0m0s labelSelector: matchLabels: app: 3scale-api-management threescale_component: backend threescale_component_element: redis snapshotMoveData: false snapshotVolumes: false ttl: 720h0m0snameSpecifies the value of the
metadata.nameparameter in the backup. Use this value in themetadata.backupNameparameter when restoring the Redis database.
- Back up the Redis database by running the following command:terminal
$ oc create -f redis-backup.yamlExample outputbackup.velero.io/redis-backup created
Verification
- Verify that the Redis backup is completed by running the following command:terminal
$ oc get backups.velero.io redis-backup -o yamlExample outputstatus: completionTimestamp: "2025-04-17T13:25:19Z" errors: 1 expiration: "2025-05-17T13:25:16Z" formatVersion: 1.1.0 hookStatus: {} phase: Completed progress: {} startTimestamp: "2025-04-17T13:25:16Z" version: 1