The following properties configure the Snapshot Transfer utility. The utility runs in a separate Kubernetes pod.
Setting snapshotTransfer.enabled to true starts the pod and — if the
cluster is already running — starts the utility. If the Snapshot Transfer utility is enabled in the same Helm
configuration that starts the cluster, the pod is created but the utility is not run since the cluster is not available yet.
To start the utility in this situation, you must cycle the snapshotTransfer.enabled property to
false and back to true.
Table B.8. Options Starting with snapshotTransfer...
| Parameter | Description | Default |
|---|---|---|
| .enabled | Deploy the snapshot-transfer Job or CronJob. Independent of cluster.enabled — the transfer may target a cluster this chart did not deploy, in which case config.servers is required. | false |
| .mode | job for a single one-shot transfer, cronjob to repeat on a schedule | job |
| .schedule | Cron expression for the transfer. Required when mode is cronjob; the chart fails to render without it | "" |
| .backoffLimit | Retries before the Job is marked failed. 0 is honoured and means do not retry. | 2 |
| .ttlSecondsAfterFinished | Seconds a finished Job is kept before Kubernetes deletes it. 0 is honoured and means delete as soon as it finishes; raise it to copy data out of a pod that wrote to a local destination. | 3600 |
| .successfulJobsHistoryLimit | Completed Jobs to retain (mode cronjob only). 0 is honoured and means keep none. | 3 |
| .failedJobsHistoryLimit | Failed Jobs to retain (mode cronjob only). 0 is honoured and means keep none. | 1 |
| .concurrencyPolicy | How overlapping runs are handled: Allow, Forbid or Replace (mode cronjob only) | Forbid |
| .image.registry | Image registry | Same as global.image.registry |
| .image.repository | Image repository | voltdb/snapshot-transfer |
| .image.tag | The snapshot-transfer version. Pinned by the chart release to a matching version; override to run a different one. Rendering fails with an actionable message if set empty. | latest |
| .image.pullPolicy | Image pull policy | Same as global.image.pullPolicy |
| .serviceAccountName | Service account for the pod; the identity used for GCS Workload Identity or AWS IRSA | "" |
| .config | Inline YAML written verbatim into a ConfigMap and mounted as config.yaml. Keys are snapshot-transfer CLI long options without the leading --, such as servers, destination and s3-region. Credential-bearing keys (password, s3-access-key-id, s3-secret-access-key) are refused: they would be stored in plain text — use the Secret-based values below instead. Paths to material you mount yourself are fine. | See file values.yaml |
| .config.format | Output format written to the destination | parquet |
| .config.new | Take a fresh snapshot before streaming, instead of streaming the latest existing one. Rarely wanted with mode: job, which fires once at install. | unset |
| .config.servers | VoltDB client address. Derived from this release's cluster when unset; set it only to reach a cluster this chart did not deploy. | <release>-cluster-client:21212 |
| .config.destination | Where the data goes: local path, gs:// or s3:// URI. Required when snapshotTransfer.enabled — no default, since the CLI would otherwise write into the pod's own filesystem and the Job would report success having produced nothing. | None |
| .additionalVolumes | Extra volumes for the transfer pod, same shape as cluster.clusterSpec.additionalVolumes. Mount a PVC and point config.destination at it to keep the data after the pod is cleaned up. | [ ] |
| .additionalVolumeMounts | Mount points for additionalVolumes. | [ ] |
| .auth.existingSecret | Pre-created secret holding VoltDB client credentials. Empty means no authentication is wired | "" |
| .auth.secretKey | Key within the auth secret holding the credentials file | credentials |
| .auth.mountPath | Mount point for the auth secret inside the container | /etc/voltdb-creds |
| .ssl.existingSecret | Pre-created secret holding the VoltDB client TLS properties and truststore. Empty means no TLS is wired — and is refused when the chart's cluster has TLS enabled for external connections, since the client port would then be TLS-only. | "" |
| .ssl.sslPropsKey | Key within the SSL secret holding the properties file | ssl.props |
| .ssl.mountPath | Mount point for the SSL secret inside the container | /etc/voltdb-ssl |
| .gcpCredentialsSecret.name | Pre-created secret holding a Google service-account JSON key. Empty means Workload Identity is used | "" |
| .gcpCredentialsSecret.key | Key within the GCP secret holding the JSON key | key.json |
| .gcpCredentialsSecret.mountPath | Mount point for the GCP secret inside the container | /etc/gcp-creds |
| .awsCredentialsSecret.name | Pre-created secret holding S3 credentials as a properties file. Empty means the default AWS credential chain (IRSA, environment, instance metadata) is used | "" |
| .awsCredentialsSecret.secretKey | Key within the AWS secret holding the properties file | credentials.properties |
| .awsCredentialsSecret.mountPath | Mount point for the AWS secret inside the container | /etc/aws-creds |
| .resources | CPU/Memory resource requests/limits | See file values.yaml |
| .securityContext | Container security context defined by Kubernetes. The chart always mounts an emptyDir on /tmp, so readOnlyRootFilesystem is safe to enable | { } |
| .nodeSelector | Node labels for pod assignment | { } |
| .tolerations | Pod tolerations for node assignment (see Kubernetes documentation) | [ ] |
| .affinity | Kubernetes node affinity | { } |
Documentation