# S3 repository plugin: Is it possible to restore a snapshot from a non-read-only repository using a read-only access\_key?

**URL:** <https://discuss.elastic.co/t/s3-repository-plugin-is-it-possible-to-restore-a-snapshot-from-a-non-read-only-repository-using-a-read-only-access-key/68289>\
**Category:** Elasticsearch\
**Created:** [December 7, 2016, 11:16am UTC](https://discuss.elastic.co/t/s3-repository-plugin-is-it-possible-to-restore-a-snapshot-from-a-non-read-only-repository-using-a-read-only-access-key/68289 "2016-12-07T11:16:42Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![jos](https://avatars.discourse-cdn.com/v4/letter/j/2bfe46/32.png) [@jos](https://discuss.elastic.co/u/jos)\
**Post date:** [December 7, 2016, 11:16am UTC](https://discuss.elastic.co/t/s3-repository-plugin-is-it-possible-to-restore-a-snapshot-from-a-non-read-only-repository-using-a-read-only-access-key/68289/1 "2016-12-07T11:16:42Z")

</div>

Hello all,

I am trying to restore a snapshot from an s3 bucket created with Elasticsearch 2.2.1, using Elasticsearch 5.0.2. The bucket is not read-only, but the access\_key for AWS only has read-only access.

When I try to restore a snapshot using:

```
POST http://localhost:9200/_snapshot/repo_name/snapshot_name/_restore
{
  "index_settings": {
    "index.number_of_replicas": 0
  }
}

```

It produces the following error:

```
{
  "error": {
    "root_cause": [
      {
        "type": "repository_exception",
        "reason": "[repo_name] failed to update the repository index blob with indices data on startup"
      }
    ],
    "type": "repository_exception",
    "reason": "[repo_name] failed to update the repository index blob with indices data on startup",
    "caused_by": {
      "type": "i_o_exception",
      "reason": "Unable to upload **** (anonymized this),
      "caused_by": {
        "type": "amazon_s3_exception",
        "reason": "Access Denied (Service: Amazon S3; Status Code: 403; Error Code: AccessDenied; Request ID: 1AE8CE8E63CB4BB8)"
      }
    }
  },
  "status": 500
}

```

If I search for that particular error message in the source code, it seems like this exception is thrown when the repository is not read-only and it tries to update some information in that repository, which of course is not allowed if you have an AWS access\_key with read-only access.

So my question is: Is there a way to restore that snapshot using a read-only AWS access\_key? Or do I have to have an AWS access\_key with write access?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 7, 2016, 11:55am UTC](https://discuss.elastic.co/t/s3-repository-plugin-is-it-possible-to-restore-a-snapshot-from-a-non-read-only-repository-using-a-read-only-access-key/68289/2 "2016-12-07T11:55:43Z")

</div>

Try to create the repo with `readonly` instead of `read_only`. There is a bug in the docs.

> <https://github.com/elastic/elasticsearch/issues/22007>

---

<div class="post-metadata">

**Author:** ![jos](https://avatars.discourse-cdn.com/v4/letter/j/2bfe46/32.png) [@jos](https://discuss.elastic.co/u/jos)\
**Post date:** [December 7, 2016, 3:04pm UTC](https://discuss.elastic.co/t/s3-repository-plugin-is-it-possible-to-restore-a-snapshot-from-a-non-read-only-repository-using-a-read-only-access-key/68289/3 "2016-12-07T15:04:33Z")

</div>

The repo is _not_ read-only, and is supposed to be that. It is also hosted by another company, so I cannot change it even if I wanted to.

My question still remains: can you do a read-only snapshot restore on a non-read-only repo?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 7, 2016, 10:44pm UTC](https://discuss.elastic.co/t/s3-repository-plugin-is-it-possible-to-restore-a-snapshot-from-a-non-read-only-repository-using-a-read-only-access-key/68289/4 "2016-12-07T22:44:49Z")

</div>

How do you create the repository in your elasticsearch cluster?

---

<div class="post-metadata">

**Author:** ![jos](https://avatars.discourse-cdn.com/v4/letter/j/2bfe46/32.png) [@jos](https://discuss.elastic.co/u/jos)\
**Post date:** [December 8, 2016, 8:18am UTC](https://discuss.elastic.co/t/s3-repository-plugin-is-it-possible-to-restore-a-snapshot-from-a-non-read-only-repository-using-a-read-only-access-key/68289/5 "2016-12-08T08:18:54Z")

</div>

I create the repo in my cluster like this (using fake names in this example):

```
PUT http://localhost:9200/_snapshot/repo_name?verify=false
{
  "type": "s3",
  "settings": {
    "bucket": "bucket_name",
    "access_key": " *******",
    "secret_key": " *******",
    "base_path": "some/path",
    "compress": "true",
  }
}

```

I am aware that I use verify=false. I need to, because verification will fail for the same reason, which is that my AWS access\_key is read-only. In version 2.X however, the snapshot restore would still work. In version 5.0.2, I can't get it to work, that's why I am asking if there is something I am missing, or if I am running into a (new or old) limitation of the snapshot restore.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 8, 2016, 8:33am UTC](https://discuss.elastic.co/t/s3-repository-plugin-is-it-possible-to-restore-a-snapshot-from-a-non-read-only-repository-using-a-read-only-access-key/68289/6 "2016-12-08T08:33:05Z")

</div>

Can you try:

```auto
PUT http://localhost:9200/_snapshot/repo_name?verify=false
{
  "type": "s3",
  "settings": {
    "bucket": "bucket_name",
    "access_key": " *******",
    "secret_key": " *******",
    "base_path": "some/path",
    "compress": "true",
    "readonly": true
  }
}

```

---

<div class="post-metadata">

**Author:** ![jos](https://avatars.discourse-cdn.com/v4/letter/j/2bfe46/32.png) [@jos](https://discuss.elastic.co/u/jos)\
**Post date:** [December 8, 2016, 8:36am UTC](https://discuss.elastic.co/t/s3-repository-plugin-is-it-possible-to-restore-a-snapshot-from-a-non-read-only-repository-using-a-read-only-access-key/68289/7 "2016-12-08T08:36:08Z")

</div>

I was just doing that, out of curiosity, and that is indeed what I was looking for. I just was misunderstanding how a repository works in elasticsearch. I thought it was just a pointer to the bucket in S3 (which is hosted by the other company), but I am actually creating a bit more than that in my own cluster, or so it seems.

Thanks David, for your help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 5, 2017, 8:36am UTC](https://discuss.elastic.co/t/s3-repository-plugin-is-it-possible-to-restore-a-snapshot-from-a-non-read-only-repository-using-a-read-only-access-key/68289/8 "2017-01-05T08:36:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
