A sync rebuilds application tables from BigQuery. It does not rebuild access grants. The chart backs up each <schema>.access_policy table and, when configured, its <schema>.access_log audit trail.
Set backup.enabled to create one CronJob per configured schema. Each job exports <schema>.access_policy and <schema>.access_log, uploads both dumps to the separate backup S3/GCS-compatible service, then prunes access_log rows older than backup.accessLog.retentionDays:
<backup.prefix>/<schema>/<date>/access_policy.dump
<backup.prefix>/<schema>/<date>/access_log.dump
The chart default prefix is:
backups/access_policy
Backups contain only access-policy and audit-log data. They do not contain PostgreSQL tables, Parquet files, or the full database.
jobs:
existingSecret: data-proxy-jobs
backup:
enabled: true
schedule: "0 3 * * *"
prefix: backups/access_policy
accessLog:
retentionDays: 90
s3:
endpointURL: https://storage.googleapis.com
bucket: access-policy-backupsThe shared jobs Secret supplies the PostgreSQL maintenance-role password. The backup CronJob and the cleanup CronJob both connect as the jobs role, so neither runs as the database owner.
The default schedule is daily at 03:00 UTC. Configure bucket lifecycle rules for retention; the chart does not delete backup objects.
Download the dump and inspect it before restoring:
rclone copy \
":s3:<bucket>/backups/access_policy/<schema>/<date>/access_policy.dump" \
access_policy.dump
pg_restore --list access_policy.dump- Download the reviewed dump from the separate backup service.
- Restore it into a temporary database or table.
- Compare it with
<schema>.access_policy. - Apply reviewed rows only.
Do not load an unreviewed backup into a live policy table.
← Previous · Home · Next →