Kubernetes Backup Done Right, with Plakar — Transcript
Full transcript
- 0:00You are running Kubernetes in production
- 0:02and your team is shipping very fast.
- 0:04Then someone runs a wrong command or a
- 0:07node goes down or a bad deployment just
- 0:09corrupts your state. What happens next?
- 0:12If you don't have a proper backup
- 0:13strategy, well, you are in trouble. And
- 0:16if you think you have one, you want want
- 0:18to check whether it actually works or
- 0:20not. In this video, I'm going to show
- 0:22you how to back up a Kubernetes cluster
- 0:24by using Pluker, which is an open-source
- 0:27backup tool that covers everything
- 0:28including your state, your manifests,
- 0:31and even your persistent volume data. We
- 0:34will deploy a WordPress MySQL stack,
- 0:36create real content in this WordPress
- 0:38website, then we will take a full backup
- 0:41including the persistent volume data. Of
- 0:43course, we will delete everything and do
- 0:46a complete restore. If you're into
- 0:47DevOps, cloud-native tooling, and you're
- 0:50not losing your data, please hit
- 0:51subscribe. And hey, welcome to Usain
- 0:53Codes. Let's compile.
- 1:00Most people's Kubernetes backup strategy
- 1:02is, well, nothing. Or maybe etcd
- 1:05snapshots once a day or they rely on
- 1:07Velero, which is great but can be
- 1:09complex to set up and doesn't give you
- 1:11much visibility into what you have
- 1:13backed up. The real challenge is that a
- 1:15Kubernetes cluster has three layers of
- 1:17data you need to protect. The first one
- 1:19is etcd. This is the brain of your
- 1:21cluster. Every resource definition,
- 1:23every secret, every config map lives
- 1:24here. If etcd dies and you have no
- 1:27backup, your cluster is gone. The second
- 1:29one is the manifest. The YAML
- 1:31definitions of your deployments,
- 1:32services, ingresses, config maps,
- 1:35everything. You want these versioned and
- 1:37restorable individually, not just as a
- 1:39giant etcd blob. The third one is
- 1:42persistent volumes. Stateful apps like
- 1:44databases, message queues, anything
- 1:46writing to disk. These are often the
- 1:48most critical and the most forgotten
- 1:50ones. Most tools handle one or two of
- 1:52these. Pluker handles all three with a
- 1:55single consistent interface. Pluker is
- 1:57an open-source backup platform. Think of
- 1:59it as the Docker container model, but
- 2:01for your data. Instead of raw files,
- 2:03Pluker stores everything in something
- 2:05called a closet, a self-contained,
- 2:08immutable, encrypted data unit. Like a
- 2:10container that packages your data with
- 2:12all its context and metadata. A few
- 2:14things that make Pluker stand out: the
- 2:16client-side encryption. Your data is
- 2:18encrypted before it leaves your machine.
- 2:21The storage backend, whether it's S3,
- 2:23local disk, or SFTP, never sees your
- 2:26plain text. The second one,
- 2:27deduplication before encryption. Most
- 2:29tools can't deduplicate encrypted data.
- 2:31Pluker's closet engine does dedupe
- 2:33first, which means you get massive
- 2:35storage savings without sacrificing
- 2:37privacy. Third one, browsable snapshots.
- 2:40You don't have to restore a backup to
- 2:42see what's in it. You can mount it,
- 2:43browse it, and even diff two snapshots
- 2:46directly from the CLI or UI. And as of
- 2:49early 2026,
- 2:50Pluker joined the Linux Foundation and
- 2:52the CNCF. So, this is not a side
- 2:54project. It's production-grade,
- 2:56community-backed infrastructure. Oh, and
- 2:58it's free and open-source. Let's install
- 3:01it. For this demo, I am running a GKE
- 3:03cluster on Google Cloud with a WordPress
- 3:05and MySQL stack, two deployments, two
- 3:07services, a config map, a secret, and
- 3:10two persistent volume claims backed by
- 3:12the PD CSI driver. They are all in a
- 3:15demo namespace. This is a realistic
- 3:17stateful workload where the data inside
- 3:19the volumes actually matters. I have
- 3:21already set up the GKE cluster with the
- 3:23CSI snapshot support. The fully set up
- 3:26steps are in the GitHub repo linked in
- 3:27the description. So, let me deploy the
- 3:29app.
- 3:34Our namespace is created, and we have
- 3:36plenty of resources inside demo folder.
- 3:39Let's apply the remainings.
- 3:47Let's wait for MySQL and WordPress pods
- 3:50to be ready.
- 3:52We have MySQL database, WordPress pod.
- 3:55Uh we have service, of course, to access
- 3:57WordPress website. Our pods are managed
- 3:59by deployments. It contains replica
- 4:01sets, config map for WordPress
- 4:03configuration, and we have MySQL
- 4:05database access credentials inside this
- 4:07secret. Of course, we have persistent
- 4:09volume claim for MySQL and WordPress.
- 4:11Now, let's set up WordPress through the
- 4:13browser. We already have load balancer
- 4:16access.
- 4:20Okay, select language, provide a website
- 4:22title.
- 4:32Install WordPress. It's installed.
- 4:39Okay, let's create a sample post so we
- 4:42can verify after restoration.
- 5:04Okay, our content is here. This part is
- 5:06important. We now have an actual user
- 5:09data inside the persistent volumes. The
- 5:11MySQL PVC has our WordPress database
- 5:13with this custom page, and the WordPress
- 5:15PVC has the PHP files and uploads. If we
- 5:18lose these volumes, we'll lose
- 5:20everything. Our WordPress website is
- 5:22ready. Now, let's install Pluker. I'm
- 5:24installing the Kubernetes branch, which
- 5:26has built-in Kubernetes support.
- 5:31Okay, it's installed. Now, install the
- 5:34S3 integration package. Remember, we
- 5:36will back up our data into S3 buckets.
- 5:39In order to use S3 package, we need to
- 5:41log in via GitHub first.
- 5:46So, in order to finalize the login, just
- 5:48open this in browser and provide your
- 5:51credentials.
- 5:57Okay.
- 5:58I'm now logged in. Go back to terminal.
- 6:01Now, we can add S3 package.
- 6:04Okay, it's already installed because I
- 6:06did it before. Next step is configuring
- 6:09Plakar to store backups in an S3 bucket.
- 6:11Plakar uses a store concept and named
- 6:14reference to a remote backend. In order
- 6:16to create a store in our case, we need
- 6:18to provide our AWS credentials because
- 6:21it will be stored in bucket. I already
- 6:22defined it in my environment variables.
- 6:25So, here is the command.
- 6:28We add a new store which is called
- 6:30backup and the location is your bucket's
- 6:33full location. I will be using Plakar
- 6:35demo VP backup buckets and my credential
- 6:38is AWS access key ID and secret access
- 6:40key. Let's add this store.
- 6:43Okay, it's added. Now, we initialize an
- 6:45encrypted closet on that S3 store. We
- 6:47will set the pass phrase as an
- 6:49environment variable so we don't have to
- 6:51type it every time.
- 6:56Plakar will use this pass phrase to
- 6:58encrypt your backups and notice the
- 7:00bucket itself is just dumb storage.
- 7:03Plakar encrypts everything client-side
- 7:04before it ever reach S3. AWS can't read
- 7:07your data. Your IAM admin can't read
- 7:10your data. Nobody can except you. One
- 7:12last thing. Plakar's Kubernetes
- 7:14integration connects via the Kubernetes
- 7:16API server. So, we need to keep CTL
- 7:18proxy running.
- 7:22Let me show you what's in our cluster
- 7:24right now.
- 7:28We have a WordPress deployment, a MySQL
- 7:30deployment, two services, a config map,
- 7:33a secret, and two PVCs. One for MySQL
- 7:35data, one for WordPress files. And
- 7:37remember, we created a custom WordPress
- 7:40page. That data is living inside the
- 7:42MySQL PVC right now. Now, let's take a
- 7:44full backup. First, we backup all the
- 7:47manifests, deployments, services,
- 7:49secrets, config maps, everything.
- 7:58Okay, that captures the entire cluster
- 8:00state as YAML manifests, but manifests
- 8:03alone don't include the data inside your
- 8:05volumes. For that, we will use Pluker's
- 8:07CSI integration. It creates a snapshot
- 8:10of each PVC, mounts it in a temporary
- 8:12pod, ingests the file system data, and
- 8:15cleans up the snapshot. Let's back up
- 8:17both PVCs. Here, we provide a snapshot
- 8:19class, PD snap class. This is used for
- 8:22GKE clusters. So, by using this class,
- 8:25it will take a snapshot of your PVC
- 8:27content. And here, demo namespace and
- 8:29MySQL PVC. Let's back up it into S3.
- 8:38Now, we will do the same for WordPress
- 8:40backup. This time, it will be demo
- 8:42namespace and WordPress PVC.
- 8:46Okay, WordPress backup is also
- 8:48completed. That's the difference between
- 8:49backing up a definitions and backing up
- 8:52data. With Kubernetes protocol, you get
- 8:54the manifests. With Kubernetes plus CSI
- 8:57protocol, you get the actual volume
- 8:59contents. Together, you have a complete
- 9:01backup. Let's verify what was backed up.
- 9:06We can see our snapshot with its IDs.
- 9:08The smallest one is for manifest, of
- 9:11course. This is for MySQL, and this is
- 9:13for WordPress backup content. Now, let's
- 9:16browse what's inside. This is one of
- 9:19Pluker's killer features. You can
- 9:20inspect any snapshot without restoring
- 9:22it.
- 9:25So, you provide ID.
- 9:28Inside demo namespace, what are the
- 9:30backup content? As you can see, apps,
- 9:32discovery, they are API groups under
- 9:34demo namespace. Let's check this one.
- 9:38You can see every resource organized
- 9:40cleanly. Config maps, secrets, services,
- 9:42PVCs under the core API group, as you
- 9:45can see here. Let's check apps group.
- 9:48Deployments and replica sets are under
- 9:51the apps group, and each one stored as a
- 9:53YAML file, and you can inspect
- 9:55individually. And in the separate PVC
- 9:57snapshots, we have the actual file
- 9:59system contents of each volume. And all
- 10:01of this is sitting in S3, fully
- 10:03encrypted with AES 256
- 10:06GCM. AWS sees encrypted blobs, only you
- 10:09hold the key. Now, let's come to the fun
- 10:12part. Let's break the things. Let's
- 10:13delete demo namespace.
- 10:16As you can see, everything is gone.
- 10:19So, no demo namespace at all. And just
- 10:22like that, our WordPress site, our MySQL
- 10:24database, our custom page, our services,
- 10:27our config, our secrets, our PVCs with
- 10:29all the data inside, everything in the
- 10:32demo namespace gone. This is the
- 10:33scenario every ops team dreads. The PVCs
- 10:36are gone, and with them, all the MySQL
- 10:38data, including that custom WordPress
- 10:41page we created. But, our backup is safe
- 10:43in S3. Let's bring it all back,
- 10:45including the data. First, let's confirm
- 10:48our backup is still safe in S3.
- 10:51Here's our snapshot. Now, here is the
- 10:53key insight. Pluker lets you restore
- 10:55individual resources from the snapshot
- 10:57tree. We don't have to do a full blast
- 10:59restore. We go step-by-step in the right
- 11:02order. First, restore the namespace.
- 11:04Without the namespace, nothing else can
- 11:06be created.
- 11:11The manifests are located inside this
- 11:13snapshot, so I will use that ID, and
- 11:18the namespace is restored. Let's verify
- 11:20it. As you can see, it is being created.
- 11:23So, namespace is back. Now, let's
- 11:26restore our resources one by one. We
- 11:28will use same command, but the path will
- 11:30be different for each resource. The
- 11:32first one is config map.
- 11:35Okay, the second one is secret.
- 11:39Services.
- 11:41Service for MySQL, then service for
- 11:44WordPress.
- 11:47Notice we are skipping kube-root-ca
- 11:49certificate config map because that's an
- 11:52auto-managed config map that Kubernetes
- 11:54recreates on its own. We only restore
- 11:56what we actually own. As a third step,
- 11:57we will restore the PVCs with their
- 12:00data. First, we create a fresh empty
- 12:02PVCs. As you can see, we already have
- 12:05PVC manifest inside demo here. We will
- 12:07create a fresh PVC from them.
- 12:11Remember, they are completely new PVCs.
- 12:14We don't have any data inside this. I
- 12:16mean, the custom web page. So, we can
- 12:18import the data from our backup into
- 12:20this one.
- 12:22Let's list the snapshot IDs again. So,
- 12:25this will be WordPress. This will be
- 12:27MySQL.
- 12:30You see, we are using CSI in the
- 12:31protocol in order to copy the content
- 12:34from snapshot.
- 12:35In demo namespace for MySQL.
- 12:39And we need to provide our snapshot ID,
- 12:41which is this one.
- 12:42So, we are trying to restore data into
- 12:45the Kubernetes by using CSI driver and
- 12:48the destination is demo namespace and
- 12:51MySQL PVC, which exists before here.
- 12:54Now, let's do the same for WordPress.
- 12:57WordPress snapshot ID is this one.
- 12:59And the PVC name is WordPress.
- 13:03Okay, both PVC restore is completed.
- 13:05Pluker creates a temporary pod, mounts
- 13:07the PVC, and writes the backed up file
- 13:10system data back into it. The MySQL
- 13:12database and WordPress files are fully
- 13:14restored right now, not just empty
- 13:16volumes, but the actual data. Since we
- 13:18have the PVC content, let's restore the
- 13:21final stuff, which is the deployment.
- 13:25Okay, first one is MySQL. This is just a
- 13:28manifest and second one is WordPress.
- 13:32Now, let's wait for both pods to be
- 13:34ready.
- 13:35MySQL is already up and running and
- 13:38WordPress is also up and running. Let's
- 13:40list all the resources inside demo
- 13:43namespace.
- 13:44Okay, MySQL's running, PostgreSQL
- 13:46running, services running, deployments
- 13:49and secrets persistent volumes.
- 13:51Deployments are back, services are back,
- 13:53config map secrets PVs is all the
- 13:55resource and healthy. But, here is the
- 13:57real test. Let's check if our custom
- 14:00WordPress page survived.
- 14:04So, here it is. Our custom WordPress
- 14:06page Hello Placker is back. The MySQL
- 14:09data inside the PVC was fully restored.
- 14:11This is the power of Kubernetes and CSI
- 14:14driver protocol and it doesn't just
- 14:17restore definitions. It restores the
- 14:19data. That granularity is something you
- 14:21just don't get with at CD only backups
- 14:24or Velero. You can browse any snapshot,
- 14:26pick exactly which resources to restore
- 14:28and skip the ones Kubernetes manage on
- 14:30its own. And with Kubernetes and CSI
- 14:32protocol, your stateful volume data is
- 14:35protected, too. We are back. Full
- 14:36recovery, zero drama and data included.
- 14:39So, check out Placker.io for the full
- 14:41documentation and Kubernetes guide and
- 14:43the link is in the description. If this
- 14:45was helpful, please smash that like
- 14:47button. It actually helps a ton.
- 14:49Subscribe if you want more content on
- 14:51cloud infrastructure and data
- 14:53protection. If you have any question,
- 14:54please put them in the comments. I read
- 14:57all of them one by one. One more thing,
- 14:59we did all of this manually today to
- 15:01understand the context how it works.
- 15:03But, the proper backup strategy should
- 15:05be automated and version control. If you
- 15:08want a follow-up video on how to do this
- 15:10by using infrastructure as code, maybe
- 15:12by way of Helm, maybe a Kubernetes
- 15:14operator, drop a comment below and let
- 15:17me know. If there is enough interest, it
- 15:19will be the next video and see you in
- 15:20the next one.
About this transcript
This page contains the full transcript of Kubernetes Backup Done Right, with Plakar by HuseyinCodes, generated from the public captions YouTube serves with the video. The transcript has 2,269 words across 365 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.