# Backup and Restore to GCS

**URL:** <https://discuss.elastic.co/t/backup-and-restore-to-gcs/87154>\
**Category:** Elasticsearch\
**Created:** [May 25, 2017, 4:25pm UTC](https://discuss.elastic.co/t/backup-and-restore-to-gcs/87154 "2017-05-25T16:25:53Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![sbalaz01](https://avatars.discourse-cdn.com/v4/letter/s/ee59a6/32.png) [@sbalaz01](https://discuss.elastic.co/u/sbalaz01)\
**Post date:** [May 25, 2017, 4:25pm UTC](https://discuss.elastic.co/t/backup-and-restore-to-gcs/87154/1 "2017-05-25T16:25:53Z")

</div>

Hi, I've been tasked to create the backup and restore for our Elasticsearch. I want to create the backup on my local machine and then copy the snapshot to GCS. Google Cloud Storage. How can I accomplish this without creating the repository. We need to encrypt it before we copy to GCS. Anyone have any ideas?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 25, 2017, 5:37pm UTC](https://discuss.elastic.co/t/backup-and-restore-to-gcs/87154/2 "2017-05-25T17:37:09Z")

</div>

1. Create a Shared FS repository.
2. Backup.
3. Then encrypt your data and upload manually to GCS.

Would that work for you?

---

<div class="post-metadata">

**Author:** ![sbalaz01](https://avatars.discourse-cdn.com/v4/letter/s/ee59a6/32.png) [@sbalaz01](https://discuss.elastic.co/u/sbalaz01)\
**Post date:** [May 25, 2017, 5:44pm UTC](https://discuss.elastic.co/t/backup-and-restore-to-gcs/87154/3 "2017-05-25T17:44:00Z")

</div>

We created a path repo ``` [root@curl-3381698604-qgdf5:/]$ curl -XPUT '[http://elasticsearch:9200/\_snapshot/my\_backup](http://elasticsearch:9200/_snapshot/my_backup)' -d '{

> ```
> "type": "fs",
> "settings": {
> "location": "/data/backups/my_backup",
> "compress": true
> 
> ```

Add Comment Click to expand inline 8 lines

But when we try to create the backup we get

$ kubectl exec es-client-800761600-jvc98 -ti -- sh  
/ # ls -l data  
total 12  
drwxr-xr-x 2 elastics elastics 4096 May 24 23:34 backups  
drwxr-xr-x 3 elastics elastics 4096 May 24 23:34 data  
drwxr-xr-x 2 elastics elastics 4096 May 24 23:34 log

/ # ls -l data/backups/  
total 0

[root@curl-3381698604-qgdf5:/]$ curl -XPUT '[http://elasticsearch:9200/\_snapshot/my\_backup](http://elasticsearch:9200/_snapshot/my_backup)' -d '{

> ```
> "type": "fs",
> "settings": {
> "location": "/mount/backups/my_backup",
> "compress": true
> }
> 
> ```
> 
> }'  
> {"error":{"root\_cause":[{"type":"repository\_exception","reason":"[my\_backup] location [/mount/backups/my\_backup] doesn't match any of the locations specified by path.repo because this setting is empty"}],"type":"repository\_exception","reason":"[my\_backup] failed to create repository","caused\_by":{"type":"repository\_exception","reason":"[my\_backup] location [/mount/backups/my\_backup] doesn't match any of the locations specified by path.repo because this setting is empty"}},"status":500}

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 25, 2017, 9:57pm UTC](https://discuss.elastic.co/t/backup-and-restore-to-gcs/87154/4 "2017-05-25T21:57:22Z")

</div>

Please format your code using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21). It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

You need to whitelist the directory in your config with `path.repo` setting.

---

<div class="post-metadata">

**Author:** ![patM](https://avatars.discourse-cdn.com/v4/letter/p/9d8465/32.png) [@patM](https://discuss.elastic.co/u/patM)\
**Post date:** [May 25, 2017, 10:44pm UTC](https://discuss.elastic.co/t/backup-and-restore-to-gcs/87154/5 "2017-05-25T22:44:47Z")

</div>

our elasticsearch.yml has

```
path:
    data: /data/data
    logs: /data/log
    repo: /data/backups

$ curl -XPUT 'http://elasticsearch:9200/_snapshot/my_backup' -d '{
> "type": "fs",
> "settings": {
> "location": "/data/backups/my_backup",
> "compress": true
> }
> }'
 {  
   "error":{  
  "root_cause":[  
     {  
        "type":"repository_verification_exception",
        "reason":"[my_backup] [[I-1gwDl4TTiP3wukksl2IA, 'RemoteTransportException[[es-data-2][10.84.1.18:9300][internal:admin/repository/verify]]; nested: RepositoryVerificationException[[my_backup] a file written by master to the store [/data/backups/my_backup] cannot be accessed on the node [{es-data-2}{I-1gwDl4TTiP3wukksl2IA}{n47lzZ8pTAm9SWJ0PMK8Wg}{10.84.1.18}{10.84.1.18:9300}]. This might indicate that the store [/data/backups/my_backup] is not shared between this node and the master node or that permissions on the store don't allow reading files written by the master node];'], [B1c0QQ_lRAu_EK8N6xHO5A, 'RemoteTransportException[[es-data-1][10.84.3.23:9300][internal:admin/repository/verify]]; nested: RepositoryVerificationException[[my_backup] a file written by master to the store [/data/backups/my_backup] cannot be accessed on the node [{es-data-1}{B1c0QQ_lRAu_EK8N6xHO5A}{AAZGTaTFSHGhAOEu3O9-Ng}{10.84.3.23}{10.84.3.23:9300}]. This might indicate that the store [/data/backups/my_backup] is not shared between this node and the master node or that permissions on the store don't allow reading files written by the master node];'], [rsKtAeB7TBCoXgQIvw9w7g, 'RemoteTransportException[[es-master-3164650403-vwtq0][10.84.2.16:9300][internal:admin/repository/verify]]; nested: RepositoryVerificationException[[my_backup] a file written by master to the store [/data/backups/my_backup] cannot be accessed on the node [{es-master-3164650403-vwtq0}{rsKtAeB7TBCoXgQIvw9w7g}{5PSio-OOTKaV5SFMKIV0Zw}{10.84.2.16}{10.84.2.16:9300}]. This might indicate that the store [/data/backups/my_backup] is not shared between this node and the master node or that permissions on the store don't allow reading files written by the master node];'], [lQ92eZngTC-DCuJAysPsVg, 'RemoteTransportException[[es-master-3164650403-s4z63][10.84.1.17:9300][internal:admin/repository/verify]]; nested: RepositoryVerificationException[[my_backup] a file written by master to the store [/data/backups/my_backup] cannot be accessed on the node [{es-master-3164650403-s4z63}{lQ92eZngTC-DCuJAysPsVg}{_dt8gCY3SfKQIIClCgw19A}{10.84.1.17}{10.84.1.17:9300}]. This might indicate that the store [/data/backups/my_backup] is not shared between this node and the master node or that permissions on the store don't allow reading files written by the master node];'], [lLXa-6tzRiS83XQKEWe8bg, 'RemoteTransportException[[es-data-0][10.84.2.18:9300][internal:admin/repository/verify]]; nested: RepositoryVerificationException[[my_backup] a file written by master to the store [/data/backups/my_backup] cannot be accessed on the node [{es-data-0}{lLXa-6tzRiS83XQKEWe8bg}{jD5r6jgtS8iUUF9kOdo08Q}{10.84.2.18}{10.84.2.18:9300}]. This might indicate that the store [/data/backups/my_backup] is not shared between this node and the master node or that permissions on the store don't allow reading files written by the master node];']]"
     }
  ],
  "type":"repository_verification_exception",
  "reason":"[my_backup] [[I-1gwDl4TTiP3wukksl2IA, 'RemoteTransportException[[es-data-2][10.84.1.18:9300][internal:admin/repository/verify]]; nested: RepositoryVerificationException[[my_backup] a file written by master to the store [/data/backups/my_backup] cannot be accessed on the node [{es-data-2}{I-1gwDl4TTiP3wukksl2IA}{n47lzZ8pTAm9SWJ0PMK8Wg}{10.84.1.18}{10.84.1.18:9300}]. This might indicate that the store [/data/backups/my_backup] is not shared between this node and the master node or that permissions on the store don't allow reading files written by the master node];'], [B1c0QQ_lRAu_EK8N6xHO5A, 'RemoteTransportException[[es-data-1][10.84.3.23:9300][internal:admin/repository/verify]]; nested: RepositoryVerificationException[[my_backup] a file written by master to the store [/data/backups/my_backup] cannot be accessed on the node [{es-data-1}{B1c0QQ_lRAu_EK8N6xHO5A}{AAZGTaTFSHGhAOEu3O9-Ng}{10.84.3.23}{10.84.3.23:9300}]. This might indicate that the store [/data/backups/my_backup] is not shared between this node and the master node or that permissions on the store don't allow reading files written by the master node];'], [rsKtAeB7TBCoXgQIvw9w7g, 'RemoteTransportException[[es-master-3164650403-vwtq0][10.84.2.16:9300][internal:admin/repository/verify]]; nested: RepositoryVerificationException[[my_backup] a file written by master to the store [/data/backups/my_backup] cannot be accessed on the node [{es-master-3164650403-vwtq0}{rsKtAeB7TBCoXgQIvw9w7g}{5PSio-OOTKaV5SFMKIV0Zw}{10.84.2.16}{10.84.2.16:9300}]. This might indicate that the store [/data/backups/my_backup] is not shared between this node and the master node or that permissions on the store don't allow reading files written by the master node];'], [lQ92eZngTC-DCuJAysPsVg, 'RemoteTransportException[[es-master-3164650403-s4z63][10.84.1.17:9300][internal:admin/repository/verify]]; nested: RepositoryVerificationException[[my_backup] a file written by master to the store [/data/backups/my_backup] cannot be accessed on the node [{es-master-3164650403-s4z63}{lQ92eZngTC-DCuJAysPsVg}{_dt8gCY3SfKQIIClCgw19A}{10.84.1.17}{10.84.1.17:9300}]. This might indicate that the store [/data/backups/my_backup] is not shared between this node and the master node or that permissions on the store don't allow reading files written by the master node];'], [lLXa-6tzRiS83XQKEWe8bg, 'RemoteTransportException[[es-data-0][10.84.2.18:9300][internal:admin/repository/verify]]; nested: RepositoryVerificationException[[my_backup] a file written by master to the store [/data/backups/my_backup] cannot be accessed on the node [{es-data-0}{lLXa-6tzRiS83XQKEWe8bg}{jD5r6jgtS8iUUF9kOdo08Q}{10.84.2.18}{10.84.2.18:9300}]. This might indicate that the store [/data/backups/my_backup] is not shared between this node and the master node or that permissions on the store don't allow reading files written by the master node];']]"
   },
   "status":500
}
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 26, 2017, 4:27am UTC](https://discuss.elastic.co/t/backup-and-restore-to-gcs/87154/6 "2017-05-26T04:27:31Z")

</div>

The same dir must exist on every node and shared by all nodes

---

<div class="post-metadata">

**Author:** ![patM](https://avatars.discourse-cdn.com/v4/letter/p/9d8465/32.png) [@patM](https://discuss.elastic.co/u/patM)\
**Post date:** [May 31, 2017, 10:27pm UTC](https://discuss.elastic.co/t/backup-and-restore-to-gcs/87154/7 "2017-05-31T22:27:38Z")

</div>

Thks

Well It does exist on every nodes

I'm not sure about the "shared by all nodes" part?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 1, 2017, 2:34am UTC](https://discuss.elastic.co/t/backup-and-restore-to-gcs/87154/8 "2017-06-01T02:34:29Z")

</div>

Can you run the following command on node 10.84.1.18:

```
ls -l /data/backups/my_backup
```

---

<div class="post-metadata">

**Author:** ![sbalaz01](https://avatars.discourse-cdn.com/v4/letter/s/ee59a6/32.png) [@sbalaz01](https://discuss.elastic.co/u/sbalaz01)\
**Post date:** [June 1, 2017, 5:38pm UTC](https://discuss.elastic.co/t/backup-and-restore-to-gcs/87154/9 "2017-06-01T17:38:13Z")

</div>

David,

I believe that Patrick has already submitted that. It’s probably in the thread below.

Suzanne

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 1, 2017, 5:53pm UTC](https://discuss.elastic.co/t/backup-and-restore-to-gcs/87154/10 "2017-06-01T17:53:32Z")

</div>

Was that run on node 10.84.1.18?

---

<div class="post-metadata">

**Author:** ![sbalaz01](https://avatars.discourse-cdn.com/v4/letter/s/ee59a6/32.png) [@sbalaz01](https://discuss.elastic.co/u/sbalaz01)\
**Post date:** [June 1, 2017, 6:15pm UTC](https://discuss.elastic.co/t/backup-and-restore-to-gcs/87154/11 "2017-06-01T18:15:50Z")

</div>

David,

Patrick asked “If repository-gcs plugin is tls/ssl able for data transit to an ecrypted gcs bucket?”

Suzanne

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 1, 2017, 6:34pm UTC](https://discuss.elastic.co/t/backup-and-restore-to-gcs/87154/12 "2017-06-01T18:34:21Z")

</div>

Sorry. I don't read that in the thread. But I'm on a mobile so I'm probably not seeing it. Can you link to this question please?

---

<div class="post-metadata">

**Author:** ![sbalaz01](https://avatars.discourse-cdn.com/v4/letter/s/ee59a6/32.png) [@sbalaz01](https://discuss.elastic.co/u/sbalaz01)\
**Post date:** [June 1, 2017, 6:57pm UTC](https://discuss.elastic.co/t/backup-and-restore-to-gcs/87154/13 "2017-06-01T18:57:10Z")

</div>

Let me know if you got this.

Suzanne

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 1, 2017, 7:19pm UTC](https://discuss.elastic.co/t/backup-and-restore-to-gcs/87154/14 "2017-06-01T19:19:12Z")

</div>

What?

---

<div class="post-metadata">

**Author:** ![sbalaz01](https://avatars.discourse-cdn.com/v4/letter/s/ee59a6/32.png) [@sbalaz01](https://discuss.elastic.co/u/sbalaz01)\
**Post date:** [June 1, 2017, 8:29pm UTC](https://discuss.elastic.co/t/backup-and-restore-to-gcs/87154/15 "2017-06-01T20:29:50Z")

</div>

David,

Patrick asked “if repository-gcs plugin is tls/ssl able for data transit to an ecrypted gcs bucket?”

Let me know if you got this.

Suzanne

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 1, 2017, 8:42pm UTC](https://discuss.elastic.co/t/backup-and-restore-to-gcs/87154/16 "2017-06-01T20:42:38Z")

</div>

I don't think he ever asked this. Can you tell me where he asked that?

---

<div class="post-metadata">

**Author:** ![sbalaz01](https://avatars.discourse-cdn.com/v4/letter/s/ee59a6/32.png) [@sbalaz01](https://discuss.elastic.co/u/sbalaz01)\
**Post date:** [June 1, 2017, 9:35pm UTC](https://discuss.elastic.co/t/backup-and-restore-to-gcs/87154/17 "2017-06-01T21:35:35Z")

</div>

No worries. Sorry, it might have been me when I replied. I took him off the email.

Suzanne

---

<div class="post-metadata">

**Author:** ![patM](https://avatars.discourse-cdn.com/v4/letter/p/9d8465/32.png) [@patM](https://discuss.elastic.co/u/patM)\
**Post date:** [June 2, 2017, 9:08pm UTC](https://discuss.elastic.co/t/backup-and-restore-to-gcs/87154/18 "2017-06-02T21:08:04Z")

</div>

Sorry for hijacking the thread with another topic 🙂

I've moved this specific plugin question here

> [@Repository-gcs plugin and tls/ssl transit encryption](https://discuss.elastic.co/t/repository-gcs-plugin-and-tls-ssl-transit-encryption/88132):
>
> Wondering if the repository-gcs plugin is tls/ssl able for data transit to an encrypted gcs bucket? I assume it pushes data in the clear: [https://www.elastic.co/guide/en/elasticsearch/plugins/current/repository-gcs-usage.html](https://www.elastic.co/guide/en/elasticsearch/plugins/current/repository-gcs-usage.html) If not, is there a way to augment or request enhancement? or is there a way to encrypt a snapshot on the fly before it hits the plugin? Thks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 30, 2017, 9:08pm UTC](https://discuss.elastic.co/t/backup-and-restore-to-gcs/87154/19 "2017-06-30T21:08:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
