# Backup and restore a elasticsearch cluster

**URL:** <https://discuss.elastic.co/t/backup-and-restore-a-elasticsearch-cluster/292740>\
**Category:** Elasticsearch\
**Tags:** snapshot-and-restore\
**Created:** [December 22, 2021, 8:55pm UTC](https://discuss.elastic.co/t/backup-and-restore-a-elasticsearch-cluster/292740 "2021-12-22T20:55:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![David\_Copperfield](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/david_copperfield/32/99260_2.png) [@David\_Copperfield](https://discuss.elastic.co/u/David_Copperfield)\
**Post date:** [December 22, 2021, 8:55pm UTC](https://discuss.elastic.co/t/backup-and-restore-a-elasticsearch-cluster/292740/1 "2021-12-22T20:55:03Z")

</div>

I have a local Elasticsearch cluster consisting of 3 master nodes and 3 data nodes, all the 6 servers are VMs inside Google Cloud. I create a snapshot repository to google GCS bucket, and save snapshots there.

The instructions followed are here: [Google Cloud Storage Repository Plugin | Elasticsearch Plugins and Integrations [7.16] | Elastic](https://www.elastic.co/guide/en/elasticsearch/plugins/current/repository-gcs.html), and sample [Backup and restore ElasticSearch data using GCS | by Chandrapal Badshah | Medium](https://medium.com/@chandrapal/backup-and-restore-elasticsearch-data-using-gcs-b047f3c680d9).

The two main issues I found are:

1, only GCP service account's key.json file works for authentication to GCS repository plugin. I can not fall back to use the GCP service account associated with the GCP Virtual Machines. While the link says it can fall back. [Getting started | Elasticsearch Plugins and Integrations [7.16] | Elastic](https://www.elastic.co/guide/en/elasticsearch/plugins/current/repository-gcs-usage.html#repository-gcs-service-authentication)  
The running Elasticsearch version is 7.8.0.

2, The GCP service account key.json has to be installed into keystore file in all 6 VMs, to get repository successfully set up, why? I installed it onto only one master node, then try repository creation but it failed with 500 return code.

Anyone in this area could shed a light into it, I'm trying to avoid key.json file, as it is rotated monthly for security reasons. Thanks,

Best,

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [December 22, 2021, 9:50pm UTC](https://discuss.elastic.co/t/backup-and-restore-a-elasticsearch-cluster/292740/2 "2021-12-22T21:50:15Z")

</div>

> [@David\_Copperfield](#):
>
> I can not fall back to use the GCP service account associated with the GCP Virtual Machines. While the link says it can fall back.

What did you try (i.e. what exactly was in your config) and what happened to indicate that it didn't work? I believe as long as the `credentials_file` setting is absent then this should work.

Note that this is a secure setting so you will need to use `elasticsearch-keystore list` to ensure that it is removed.

> [@David\_Copperfield](#):
>
> The GCP service account key.json has to be installed into keystore file in all 6 VMs... why?

All nodes need direct access to the repository to avoid the dreadful bottleneck (and massive network traffic costs) that would result from needing to send all the data through one privileged node.

> [@David\_Copperfield](#):
>
> The running Elasticsearch version is 7.8.0.

This version is [past EOL](https://www.elastic.co/support/eol) which severely limits our ability to investigate problems. You should upgrade to a supported version ASAP.

---

<div class="post-metadata">

**Author:** ![David\_Copperfield](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/david_copperfield/32/99260_2.png) [@David\_Copperfield](https://discuss.elastic.co/u/David_Copperfield)\
**Post date:** [December 25, 2021, 6:21am UTC](https://discuss.elastic.co/t/backup-and-restore-a-elasticsearch-cluster/292740/3 "2021-12-25T06:21:27Z")

</div>

HI DavidTurner,

The config is that in /etc/Elasticsearch/Elasticsearch.yml file, I have the project\_id configured,

```auto
...
gcs:
  client:
    default:
      project_id: <gcp_project_id>

```

```auto
# /usr/share/elasticsearch/bin/elasticsearch-keystore list
keystore.seed
#

```

Should I let credential file points to an empty file instead,

say,

```auto
# touch /var/tmp/empty_file.yml
# /usr/share/elasticsearch/bin/elasticsearch-keystore add-file gcs.client.default.credentials_file /var/tmp/empty_file.yml
#

```

Thanks,

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 22, 2022, 6:21am UTC](https://discuss.elastic.co/t/backup-and-restore-a-elasticsearch-cluster/292740/4 "2022-01-22T06:21:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
