Skip to content

backupTargets

This page is generated from the same Go declarations the loader enforces, so it cannot drift from what ob validate accepts.

accessKeyEntry · bucket · cold · credentials · encryption · endpoint · failureDomain · file · host · identity · kind · pitr · prefix · provider · region · secretKeyEntry · sessionTokenEntry · snapshot · tls

FieldTypeDefaultWhat it does
<name>.bucketstring—Existing destination bucket used by this target. Expects a lower-case S3-compatible bucket name between 3 and 63 characters.
<name>.credentialsobject—Trusted encrypted-file entries containing destination credentials; values never appear in the project.
<name>.credentials.accessKeyEntrystring—Variable name containing the destination access key. Expects a variable name of letters, digits and underscores, not starting with a digit.
<name>.credentials.filestring—Repository-relative encrypted credential file staged through the trusted secret flow. Expects a path inside the repository, with no control character or shell metacharacter.
<name>.credentials.providerSopsSopsTrusted secret provider. Only sops is currently executable.
<name>.credentials.secretKeyEntrystring—Variable name containing the destination secret key. Expects a variable name of letters, digits and underscores, not starting with a digit.
<name>.credentials.sessionTokenEntrystring—Optional variable name containing a temporary destination session token. Expects a variable name of letters, digits and underscores, not starting with a digit.
<name>.encryptionobject—Required encryption mode for each recovery kind this target may store.
<name>.encryption.coldClientSide · ServerSide—Encryption mode required for cold recovery: client-side or server-side.
<name>.encryption.pitrClientSide · ServerSide—Encryption mode required for point-in-time recovery: client-side or server-side.
<name>.encryption.snapshotClientSide · ServerSide—Encryption mode required for snapshot recovery: client-side or server-side.
<name>.endpointstring—Destination API endpoint. HTTPS is required unless tls is explicitly insecure. Expects an http or https URL.
<name>.failureDomainobject—Operator-declared identity used to prove the destination does not share the protected host.
<name>.failureDomain.hoststring—Destination host identity used to refuse a target on the protected host. Expects a stable identifier of letters, digits, dots, colons, slashes, underscores and hyphens.
<name>.failureDomain.identitystring—Stable operator-owned failure-domain identity, distinct from the protected host. Expects a stable identifier of letters, digits, dots, colons, slashes, underscores and hyphens.
<name>.kindS3Compatible—Destination kind. Only s3-compatible is supported.
<name>.prefixstring—Non-secret object prefix reserved for Onebox backup data. Expects a relative object prefix with no empty leading component or shell metacharacter.
<name>.regionstring—S3-compatible region when the endpoint requires one. Expects a lower-case S3-compatible region of letters, digits and hyphens.
<name>.tlsVerify · SkipVerifyVerifyTransport policy: verify, or skip-verify to accept a plaintext http endpoint.