B.10. Snapshot Transfer Configuration Options

The following properties configure the Snapshot Transfer utility. The utility runs in a separate Kubernetes pod. Setting snapshotTransfer.enabled to true starts the pod and — if the cluster is already running — starts the utility. If the Snapshot Transfer utility is enabled in the same Helm configuration that starts the cluster, the pod is created but the utility is not run since the cluster is not available yet. To start the utility in this situation, you must cycle the snapshotTransfer.enabled property to false and back to true.

Table B.8. Options Starting with snapshotTransfer...

ParameterDescriptionDefault
.enabledDeploy the snapshot-transfer Job or CronJob. Independent of cluster.enabled — the transfer may target a cluster this chart did not deploy, in which case config.servers is required.false
.modejob for a single one-shot transfer, cronjob to repeat on a schedulejob
.scheduleCron expression for the transfer. Required when mode is cronjob; the chart fails to render without it""
.backoffLimitRetries before the Job is marked failed. 0 is honoured and means do not retry.2
.ttlSecondsAfterFinishedSeconds a finished Job is kept before Kubernetes deletes it. 0 is honoured and means delete as soon as it finishes; raise it to copy data out of a pod that wrote to a local destination.3600
​.successfulJobsHistoryLimitCompleted Jobs to retain (mode cronjob only). 0 is honoured and means keep none.3
.failedJobsHistoryLimitFailed Jobs to retain (mode cronjob only). 0 is honoured and means keep none.1
.concurrencyPolicyHow overlapping runs are handled: Allow, Forbid or Replace (mode cronjob only)Forbid
.image.registryImage registrySame as global.image.registry
.image.repositoryImage repositoryvoltdb/snapshot-transfer
.image.tagThe snapshot-transfer version. Pinned by the chart release to a matching version; override to run a different one. Rendering fails with an actionable message if set empty.latest
.image.pullPolicyImage pull policySame as global.image.pullPolicy
.serviceAccountNameService account for the pod; the identity used for GCS Workload Identity or AWS IRSA""
.configInline YAML written verbatim into a ConfigMap and mounted as config.yaml. Keys are snapshot-transfer CLI long options without the leading --, such as servers, destination and s3-region. Credential-bearing keys (password, s3-access-key-id, s3-secret-access-key) are refused: they would be stored in plain text — use the Secret-based values below instead. Paths to material you mount yourself are fine.See file values.yaml
.config.formatOutput format written to the destinationparquet
.config.newTake a fresh snapshot before streaming, instead of streaming the latest existing one. Rarely wanted with mode: job, which fires once at install.unset
.config.serversVoltDB client address. Derived from this release's cluster when unset; set it only to reach a cluster this chart did not deploy.<​release>​-cluster-client:21212
.config.destinationWhere the data goes: local path, gs:// or s3:// URI. Required when snapshotTransfer.enabled — no default, since the CLI would otherwise write into the pod's own filesystem and the Job would report success having produced nothing.None
.additionalVolumesExtra volumes for the transfer pod, same shape as cluster.clusterSpec.additionalVolumes. Mount a PVC and point config.destination at it to keep the data after the pod is cleaned up.[ ]
.additionalVolumeMountsMount points for additionalVolumes.[ ]
.auth.existingSecretPre-created secret holding VoltDB client credentials. Empty means no authentication is wired""
.auth.secretKeyKey within the auth secret holding the credentials filecredentials
.auth.mountPathMount point for the auth secret inside the container/etc/voltdb-creds
.ssl.existingSecretPre-created secret holding the VoltDB client TLS properties and truststore. Empty means no TLS is wired — and is refused when the chart's cluster has TLS enabled for external connections, since the client port would then be TLS-only.""
.ssl.sslPropsKeyKey within the SSL secret holding the properties filessl.props
.ssl.mountPathMount point for the SSL secret inside the container/etc/voltdb-ssl
​.gcpCredentialsSecret​.namePre-created secret holding a Google service-account JSON key. Empty means Workload Identity is used""
.gcpCredentialsSecret.keyKey within the GCP secret holding the JSON keykey.json
​.gcpCredentialsSecret​.mountPathMount point for the GCP secret inside the container/etc/gcp-creds
​.awsCredentialsSecret​.namePre-created secret holding S3 credentials as a properties file. Empty means the default AWS credential chain (IRSA, environment, instance metadata) is used""
​.awsCredentialsSecret​.secretKeyKey within the AWS secret holding the properties filecredentials.properties
​.awsCredentialsSecret​.mountPathMount point for the AWS secret inside the container/etc/aws-creds
.resourcesCPU/Memory resource requests/limitsSee file values.yaml
.securityContextContainer security context defined by Kubernetes. The chart always mounts an emptyDir on /tmp, so readOnlyRootFilesystem is safe to enable{ }
.nodeSelectorNode labels for pod assignment{ }
.tolerationsPod tolerations for node assignment (see Kubernetes documentation)[ ]
.affinityKubernetes node affinity{ }