Files
auricom-home-cluster/kubernetes/apps/default/truenas
feisar-bot 5aa8638b96 ⬆️ Update chart app-template to 1.3.2
| datasource | package      | from  | to    |
| ---------- | ------------ | ----- | ----- |
| helm       | app-template | 1.3.1 | 1.3.2 |
2023-02-21 21:55:51 +01:00
..
2023-02-21 21:55:51 +01:00
2023-02-21 21:55:51 +01:00
2023-02-21 21:55:51 +01:00

truenas

truenas-backup S3 Configuration

  1. Create ~/.mc/config.json

    {
      "version": "10",
      "aliases": {
        "minio": {
          "url": "https://s3.<domain>",
          "accessKey": "<access-key>",
          "secretKey": "<secret-key>",
          "api": "S3v4",
          "path": "auto"
        }
      }
    }
    
  2. Create the truenas user and password

    mc admin user add minio truenas <super-secret-password>
    
  3. Create the truenas bucket

    mc mb minio/truenas
    
  4. Create truenas-user-policy.json

    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Action": [
            "s3:ListBucket",
            "s3:PutObject",
            "s3:GetObject",
            "s3:DeleteObject"
          ],
          "Effect": "Allow",
          "Resource": ["arn:aws:s3:::truenas/*", "arn:aws:s3:::truenas"],
          "Sid": ""
        }
      ]
    }
    
  5. Apply the bucket policies

    mc admin policy add minio truenas-private truenas-user-policy.json
    
  6. Associate private policy with the user

    mc admin policy set minio truenas-private user=truenas
    
  7. Create a retention policy

    mc ilm add minio/truenas --expire-days "90"
    

minio-rclone S3 Configuration

  1. Create ~/.mc/config.json

    {
      "version": "10",
      "aliases": {
        "minio": {
          "url": "https://s3.<domain>",
          "accessKey": "<access-key>",
          "secretKey": "<secret-key>",
          "api": "S3v4",
          "path": "auto"
        }
      }
    }
    
  2. Create the rclone user and password

    mc admin user add minio rclone <super-secret-password>
    
  3. Create rclone-user-policy.json

    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Action": [
            "s3:ListBucket",
            "s3:GetObject"
          ],
          "Effect": "Allow",
          "Resource": ["arn:aws:s3:::opnsense/*", "arn:aws:s3:::opnsense","arn:aws:s3:::truenas/*", "arn:aws:s3:::truenas"],
          "Sid": ""
        }
      ]
    }
    
  4. Apply the bucket policies

    mc admin policy add minio rclone-private rclone-user-policy.json
    
  5. Associate private policy with the user

    mc admin policy set minio rclone-private user=rclone