Open idanme-tr opened 1 day ago
@idanme-tr, can you share the permissions you have applied? And also your BSL configuration - does it have the storageAccountUri.
Also I would recommend checking if you have any leftover of PodIdentity in your cluster. That often leads to issues
What steps did you take and what happened:
I am trying to deploy Velero Helm charts to AKS using Workload Identity. I've followed the Azure plugin guide with workload identity configurations.
For some reason, Velero cannot retrieve the storage account's properties. I've provided the managed identity with more permissions than needed to make sure I do not miss anything.
I understand that this issue might not be a bug but a misconfiguration, but I can't find what it is. When I am using Storage account key and not Workload identity it works fine.
What did you expect to happen: I expected Velero to be able to authenticate using the workload identity and to be able to backup and restore as it should.
The following information will help us better understand what's going on:
If you are using velero v1.7.0+:
Please use
velero debug --backup <backupname> --restore <restorename>
to generate the support bundle, and attach to this issue, more options please refer tovelero debug --help
bundle-2024-10-20-11-47-04.tar.gz
If you are using earlier versions:
Please provide the output of the following commands (Pasting long output into a GitHub gist or other pastebin is fine.)
kubectl logs deployment/velero -n velero
velero backup describe <backupname>
orkubectl get backup/<backupname> -n velero -o yaml
velero backup logs <backupname>
velero restore describe <restorename>
orkubectl get restore/<restorename> -n velero -o yaml
velero restore logs <restorename>
Anything else you would like to add:
I am adding my Helm configurations. Lines that were commented out were different attempts but were also unsuccessful.
Environment:
Velero version (use
velero version
):Velero features (use
velero client config get features
):features <NOT SET>
Kubernetes version (use
kubectl version
):Kubernetes installer & version:
AKS 1.30.3
Cloud provider or hardware configuration:
Azure
Vote on this issue!
This is an invitation to the Velero community to vote on issues, you can see the project's top voted issues listed here.
Use the "reaction smiley face" up to the right of this comment to vote.