You're reading the open-source Community docs. Plakar also offers Control Plane, the enterprise version. It's a virtual appliance with a web-based interface for centralized backup management across your infrastructure. View Control Plane docs →

Scaleway

The Scaleway integration backs up Scaleway Instances, Block Storage volumes and Secret Manager secrets, and restores them to Scaleway. Restores add to what exists in Scaleway rather than overwriting it: disks come back as new volumes, and secret versions come back as new revisions.

The integration includes two connectors:

Connector type Description
Source connector Back up an instance, a block volume or secrets into a Kloset store.
Destination connector Restore an instance, a block volume or secrets from a Kloset store to Scaleway.

Both connectors support three protocols:

Protocol What it backs up
scaleway-instance An instance and all the block volumes it uses.
scaleway-block A single Block Storage volume.
scaleway-secret Every Secret Manager secret in a project and region.

Requirements

  • A Scaleway project, and an API access key and secret key with the permissions listed in Permissions.
  • For scaleway-instance and scaleway-block, a Scaleway Object Storage bucket, created beforehand.

Installation

The Scaleway integration is distributed as a pre-built package only. Unlike most Community integrations, it has no public source repository, so plakar pkg build cannot produce it. It remains free to install with a Plakar account. See source availability for how this differs from the other integrations.

Logging In

Pre-built packages require Plakar authentication. See Logging in to Plakar for details.

Install the Scaleway package:

$ plakar pkg add scaleway

Verify installation:

$ plakar pkg show

To list, upgrade, or remove the package, see managing packages guide.

How instance and volume backups work

Scaleway exposes the contents of a volume by exporting a snapshot of it as a QCOW2 image to Object Storage. Plakar triggers that export into the bucket set with bucket, reads the images from there, and stores them in the Kloset store with encryption and deduplication. The bucket is used as a staging area. A dedicated bucket keeps these images separate from other data.

Permissions

The API key used by Plakar must belong to an IAM application with the permissions below on the project. Each protocol only needs the permissions listed for it. See Managing IAM Policies and API Keys on Scaleway for how to create the application, its policy and its keys.

Permission Protocols Description
InstancesFullAccess scaleway-instance Full access to Instances.
BlockStorageFullAccess scaleway-instance, scaleway-block Full access to Block Storage.
ObjectStorageBucketsRead scaleway-instance, scaleway-block Read access to buckets and bucket configuration including lifecycle rules.
ObjectStorageBucketsWrite scaleway-instance, scaleway-block Access to create and edit buckets, bucket configuration including lifecycle rules.
ObjectStorageObjectsRead scaleway-instance, scaleway-block Read access to objects, tags, metadata and storage class.
ObjectStorageObjectsWrite scaleway-instance, scaleway-block Access to create and edit objects, tags, metadata and storage class.
SecretManagerReadOnly scaleway-secret Read access to secret metadata.
SecretManagerSecretAccess scaleway-secret Read access to secret values.
SecretManagerSecretCreate scaleway-secret Create new secrets.
SecretManagerSecretWrite scaleway-secret Write new secret versions.
SecretManagerSecretRestore scaleway-secret Recover secrets or versions on restore.

1. scaleway-instance protocol

The scaleway-instance protocol backs up an instance together with every block volume attached to it. The source location selects the instance by its server ID.

A destination restores an instance in one of two ways, depending on its location:

  • Onto an existing instance, with scaleway-instance://<server-id>. Each disk in the snapshot, including the original boot disk, becomes a new block volume attached to that instance. The instance keeps its own boot volume.
  • As a new instance, with scaleway-instance://spawn. Plakar creates an instance from the snapshot, reusing the name, type and boot layout of the backed-up instance where available, and starts it.

Backup flow

flowchart LR

subgraph Scaleway["Scaleway Project"]
  Instance["Instance and
attached volumes"] Bucket["Object Storage bucket
QCOW2 images"] Instance -->|"snapshot export"| Bucket end Plakar["Plakar"] Transform["Encrypt & deduplicate"] Store["Kloset Store"] Bucket --> Plakar --> Transform --> Store

Restore flow

flowchart LR

Store["Kloset Store"]

Plakar["Plakar"]

Transform["Decrypt & reconstruct"]

subgraph Scaleway["Scaleway Project"]
  Bucket["Object Storage bucket
QCOW2 images"] Volumes["New volumes"] Instance["Existing or new
instance"] Bucket --> Volumes --> Instance end Store --> Plakar --> Transform --> Bucket

Shared configuration

The following options apply to both source and destination connectors using the scaleway-instance protocol.

Option Required Description
access_key Yes Scaleway API access key.
secret_key Yes Scaleway API secret key.
project_id Yes ID of the Scaleway project, as a UUID.
bucket Yes Name of the Object Storage bucket used as a staging area.
zone No Scaleway zone of the instance, for example fr-par-1. Defaults to fr-par-1.

Source configuration

Option Required Description
location Yes scaleway-instance://<server-id>, the instance to back up.

Destination configuration

Option Required Description
location Yes scaleway-instance://<server-id> to attach the restored disks to an existing instance, or scaleway-instance://spawn to create a new instance.

Example

Back up an instance:

$ plakar source add myinstance scaleway-instance://<server-id> \
  access_key=<access_key> \
  secret_key=<secret_key> \
  project_id=<project_id> \
  bucket=plakar-temp \
  zone=fr-par-1

$ plakar at /var/backups backup "@myinstance"

Restore a snapshot as a new instance:

$ plakar destination add myinstance-restore scaleway-instance://spawn \
  access_key=<access_key> \
  secret_key=<secret_key> \
  project_id=<project_id> \
  bucket=plakar-temp \
  zone=fr-par-1

$ plakar at /var/backups restore -to "@myinstance-restore" <snapshot_id>

2. scaleway-block protocol

The scaleway-block protocol backs up a single Block Storage volume, selected by its ID in the source location.

A destination always creates a new volume from the snapshot. Its location decides what happens to that volume:

  • scaleway-block:// leaves the new volume detached.
  • scaleway-block://<instance-id> attaches the new volume to that instance.

Backup flow

flowchart LR

subgraph Scaleway["Scaleway Project"]
  Volume["Block volume"]
  Bucket["Object Storage bucket
QCOW2 image"] Volume -->|"snapshot export"| Bucket end Plakar["Plakar"] Transform["Encrypt & deduplicate"] Store["Kloset Store"] Bucket --> Plakar --> Transform --> Store

Restore flow

flowchart LR

Store["Kloset Store"]

Plakar["Plakar"]

Transform["Decrypt & reconstruct"]

subgraph Scaleway["Scaleway Project"]
  Bucket["Object Storage bucket
QCOW2 image"] Volume["New volume
detached or attached"] Bucket --> Volume end Store --> Plakar --> Transform --> Bucket

Shared configuration

The following options apply to both source and destination connectors using the scaleway-block protocol.

Option Required Description
access_key Yes Scaleway API access key.
secret_key Yes Scaleway API secret key.
project_id Yes ID of the Scaleway project.
bucket Yes Name of the Object Storage bucket used as a staging area.

Source configuration

Option Required Description
location Yes scaleway-block://<volume-id>, the volume to back up.
zone No Zone of the volume. Defaults to fr-par-1.

Destination configuration

Option Required Description
location Yes scaleway-block:// to create a detached volume, or scaleway-block://<instance-id> to create a volume attached to that instance.
zone No Zone where the volume is created. Defaults to fr-par-1.

Example

Back up a volume:

$ plakar source add myvolume scaleway-block://<volume-id> \
  access_key=<access_key> \
  secret_key=<secret_key> \
  project_id=<project_id> \
  bucket=plakar-temp \
  zone=fr-par-1

$ plakar at /var/backups backup "@myvolume"

Restore a snapshot as a new volume attached to an instance:

$ plakar destination add myvolume-restore scaleway-block://<instance-id> \
  access_key=<access_key> \
  secret_key=<secret_key> \
  project_id=<project_id> \
  bucket=plakar-temp \
  zone=fr-par-1

$ plakar at /var/backups restore -to "@myvolume-restore" <snapshot_id>

3. scaleway-secret protocol

The scaleway-secret protocol backs up every Secret Manager secret in a project and region, with all of its versions. The status of each version, enabled or disabled, is kept.

A restore writes the secrets into the project and region set on the destination, which can differ from the ones they were backed up from. A secret with the same name and path in the target project is reused, and a missing one is created. Every backed-up version is then added as a new revision, with its enabled or disabled status. Existing versions are left untouched, so restoring the same snapshot twice adds its versions twice.

Backup flow

flowchart LR

subgraph Scaleway["Scaleway Project"]
  Secrets["Secret Manager
secrets and versions"] end Plakar["Plakar"] Transform["Encrypt & deduplicate"] Store["Kloset Store"] Secrets -->|"Secret Manager API"| Plakar --> Transform --> Store

Restore flow

flowchart LR

Store["Kloset Store"]

Plakar["Plakar"]

Transform["Decrypt & reconstruct"]

subgraph Scaleway["Target Scaleway Project"]
  Secrets["Secrets with
new revisions"] end Store --> Plakar --> Transform -->|"Secret Manager API"| Secrets

Shared configuration

The following options apply to both source and destination connectors using the scaleway-secret protocol.

Option Required Description
location Yes Always scaleway-secret://.
access_key Yes Scaleway API access key.
secret_key Yes Scaleway API secret key.
project_id Yes ID of the Scaleway project, as a UUID. For a source, the project to back up. For a destination, the project to restore the secrets into.
region No Region of the secrets. Defaults to fr-par.

Example

Back up the secrets of a project:

$ plakar source add mysecrets scaleway-secret:// \
  access_key=<access_key> \
  secret_key=<secret_key> \
  project_id=<project_id> \
  region=fr-par

$ plakar at /var/backups backup "@mysecrets"

Restore them into another project:

$ plakar destination add mysecrets-restore scaleway-secret:// \
  access_key=<access_key> \
  secret_key=<secret_key> \
  project_id=<target_project_id> \
  region=fr-par

$ plakar at /var/backups restore -to "@mysecrets-restore" <snapshot_id>

See also