# How to backup on-prem Elasticsearch cluster to S3 bucket and restore reverse way

**URL:** <https://discuss.elastic.co/t/how-to-backup-on-prem-elasticsearch-cluster-to-s3-bucket-and-restore-reverse-way/265320>\
**Category:** Elasticsearch\
**Tags:** snapshot-and-restore\
**Created:** [February 24, 2021, 10:34am UTC](https://discuss.elastic.co/t/how-to-backup-on-prem-elasticsearch-cluster-to-s3-bucket-and-restore-reverse-way/265320 "2021-02-24T10:34:09Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rafiqul](https://avatars.discourse-cdn.com/v4/letter/r/db5fbb/32.png) [@rafiqul](https://discuss.elastic.co/u/rafiqul)\
**Post date:** [February 24, 2021, 10:34am UTC](https://discuss.elastic.co/t/how-to-backup-on-prem-elasticsearch-cluster-to-s3-bucket-and-restore-reverse-way/265320/1 "2021-02-24T10:34:09Z")

</div>

Hello  
I have a Elasticsearch cluster installed in my on-premise infrastructure. Also installed repository plug-in by running

bin/elasticsearch-plugin install repository-s3

'''  
curl -X PUT "localhost:9200/\_snapshot/tenant\_s3\_repository?pretty" -H 'Content-Type: application/json' -d'  
{  
"type": "s3",  
"settings": {  
"bucket": "tenant-snapshot"  
}  
}  
'  
'''

While I executed this raised error:  
'''  
{  
"error" : {  
"root\_cause" : [  
{  
"type" : "repository\_verification\_exception",  
"reason" : "[tenant\_s3\_repository] path is not accessible on master node"  
}  
],  
"type" : "repository\_verification\_exception",  
"reason" : "[tenant\_s3\_repository] path is not accessible on master node",  
"caused\_by" : {  
"type" : "i\_o\_exception",  
"reason" : "Unable to upload object [tests-Vc1KJgFnQ3G6HqYKBRsIsA/master.dat] using a single upload",  
"caused\_by" : {  
"type" : "amazon\_service\_exception",  
"reason" : "Internal Server Error (Service: null; Status Code: 500; Error Code: null; Request ID: null)"  
}  
}  
},  
"status" : 500  
}  
'''

I know i have to register a repository, But i dont know how to. Did not even find any documentation on it.

I would appreciate your suggestions and guideline. Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 25, 2021, 2:45am UTC](https://discuss.elastic.co/t/how-to-backup-on-prem-elasticsearch-cluster-to-s3-bucket-and-restore-reverse-way/265320/2 "2021-02-25T02:45:13Z")

</div>

Welcome to our community! 😃

The documentation here goes into that - [Snapshot and restore | Elasticsearch Reference [7.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.11/snapshot-restore.html)

---

<div class="post-metadata">

**Author:** ![rafiqul](https://avatars.discourse-cdn.com/v4/letter/r/db5fbb/32.png) [@rafiqul](https://discuss.elastic.co/u/rafiqul)\
**Post date:** [March 2, 2021, 9:19am UTC](https://discuss.elastic.co/t/how-to-backup-on-prem-elasticsearch-cluster-to-s3-bucket-and-restore-reverse-way/265320/3 "2021-03-02T09:19:05Z")

</div>

Useful link, thanks for sharing Mark.

I have made full poof steps for version 6.8. here are those.

Taking a snapshot of on-prem to S3

Custom Policy: We will create a custom policy with the following policy document:

{  
"Statement": [  
{  
"Action": [  
"s3:ListBucket",  
"s3:GetBucketLocation",  
"s3:ListBucketMultipartUploads",  
"s3:ListBucketVersions"  
],  
"Effect": "Allow",  
"Resource": [  
"arn:aws:s3:::S3-BUCKET-NAME"  
]  
},  
{  
"Action": [  
"s3:GetObject",  
"s3:PutObject",  
"s3:DeleteObject",  
"s3:AbortMultipartUpload",  
"s3:ListMultipartUploadParts"  
],  
"Effect": "Allow",  
"Resource": [  
"arn:aws:s3:::S3-BUCKET-NAME/\*"  
]  
}  
],  
"Version": "2012-10-17"  
}

IAM User: Then, we will create an IAM user attaching the custom policy. We need to collect the ACCESS\_KEY\_ID and SECRET\_ACCESS\_KEY.

S3 Elasticsearch Plugin Installation :  
Install S3 plugin:

cd /usr/share/elasticsearch  
sudo bin/elasticsearch-plugin install --batch repository-s3

For easy setup, set -Des.allow\_insecure\_settings=true to /etc/elasticsearch/jvm.options.

Snapshot Repository Registration :

curl -X PUT "localhost:9200/\_snapshot/REPOSITORY\_NAME?pretty" -H 'Content-Type: application/json' -d'  
{  
"type": "s3",  
"settings": {  
"bucket": "S3-BUCKET-NAME",  
"region": "AWS\_REGION",  
"access\_key": "ACCESS\_KEY\_ID",  
"secret\_key": "SECRET\_ACCESS\_KEY"  
}  
}  
'

Taking Snapshot :  
We can take a snapshot from running elasticsearch cluser by the following command, Here, SNAPSHOT\_NAME is unique per REPOSITORY\_NAME.

curl -X PUT "localhost:9200/\_snapshot/REPOSITORY\_NAME/SNAPSHOT\_NAME?wait\_for\_completion=true&pretty" -H 'Content-Type:application/json' -d'  
{  
"indices": "index\_1,index\_2",  
"ignore\_unavailable": true,  
"include\_global\_state": false  
}  
'

Example

Registering snapshot for on-prem

curl -XPUT "localhost:9200/\_snapshot/tenant-repo?pretty" -H 'Content-Type: application/json' -d'  
{  
"type": "s3",  
"settings": {  
"bucket": "tenant-snapshot",  
"region": "us-west-2",  
"access\_key": "AKIAUZIOM7PN2URJHIPO",  
"secret\_key": "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"  
}  
}  
'

Taking a snapshot(method-1)  
curl -X PUT "localhost:9200/\_snapshot/tenant-repo/tenant-snap01?wait\_for\_completion=true&pretty" -H 'Content-Type:application/json' -d'  
{  
"indices": "index\_1,index\_2",  
"ignore\_unavailable": true,  
"include\_global\_state": false  
}  
'

Taking a snapshot(method-2)  
curl -XPUT 'localhost:9200/\_snapshot/tenant-repo/tenant-snap01'

To restore all the indices to target ES cluster:  
Another process of repository registration and restoration.

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 30, 2021, 9:19am UTC](https://discuss.elastic.co/t/how-to-backup-on-prem-elasticsearch-cluster-to-s3-bucket-and-restore-reverse-way/265320/4 "2021-03-30T09:19:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
