AWS Managed ElasticSearch Data Migration to another domain

Few weeks back, we decided to migrate our complete infrastructure to a single AWS region (which is closer to our client) for achieving better latencies and less data transfer cost.

There were multiple components migrated to a single AWS region and ElasticSearch was one of them. Although migration steps are documented on ElasticSearch website, there are multiple AWS concepts one needs to understand  to execute it properly. Here, we have tried to dive deep into migration steps and login behind those steps.

ElasticSearch data migration is trivial and only requires knowledge of ElasticSearch in case of a self managed publicly accessible cluster but things get tricky when it comes to AWS managed clusters as AWS doesn’t allow you to access config yml file and there are a lot of other AWS IAM concepts one needs to understand for executing it  properly.

In this blog we are going to discuss the step-by-step AWS managed ElasticSearch data migration process using  snapshot and restore methods  and how it is different from self hosted ElasticSearch data migration in detail.

Overview

Assumtion: ElasticSearch domain need to be created in destination region with same cluster configuration.

Take snapshot

Snapshot: A snapshot is a backup taken from a running ElasticSearch cluster. You can take snapshots of an entire cluster, including all its data streams and indices. You can also take snapshots of only specific data streams or indices in the cluster.

Repository: The repository is a place where you can store all your snapshots data.

Note: You must register a snapshot repository before you can perform snapshot and restore operations.You have multiple options available for defining a repository given that both old and new ElasticSearch should be able to access that location like a shared file system, AWS S3, HDFS etc. We will be discussing only the AWS S3 option in this blog post.

Register snapshot repository using AWS S3 bucket

ElasticSearch provides APIs for both registering repositories and taking snapshots.

How roles and user works in AWS

Let’s create a role to delegate permission to Amazon Elasticsearch Service to take a snapshot into S3.

Create S3 Bucket and Configure IAM Role

  1. Create S3 bucket in the same region where the ElasticSearch domain exists and another bucket in destination region.

  2. Create a new role theSnapshotRole without any permissions.

  3. Create below Policy and add it to the newly created role. It will enable ElasticSearch to access both S3 bucket.

  4. Update trust relationship for theSnapshotRole role.

Note: We need to update trust relationships for newly created roles which will enable ElasticSearch to assume roles. This assume role permission will allow ElasticSearch service to use theSnapshotRole as its own.

Configure IAM user

Once we are done with role creation, we need to create new user or we need to give PassRole permission to existing user which will allow user to pass newly created theSnapshotRole to ElasticSearch service and as theSnapshotRole already configured with assumeRole permission, it can access S3 bucket.

Register snapshot repository

Once we are done with the new role and user creation, let's start with repository registration. There are two ways of registering repositories on ElasticSearch.

  1. Using postman if your ElasticSearch cluster can be accessed directly.

Postman

  1. If your ElasticSearch cluster is in a VPC that you cannot access directly, you will need access to EC2 which is in the same VPC and that can execute below scripts.

Python script

Response

Take snapshot of current ElasticSearch data

After registering repository successfully, we need to run below script for taking snapshot of current ElasticSearch data.

Response

Verify snapshot

Copy S3 data to new region s3

You can copy s3 bucket data using AWS console

aws s3 cp s3://awsexamplesourcebucket s3://awsexampledestinationbucket

Restore Snapshot

  1. Register current snapshot repository with new ElasticSearch domain

  2. Restore snapshot of old ElasticSearch data into new ElasticSearch

  3. Verify restored indexes and alias.

  4. Verify index data

Take-away!

References:

[Migrate data from an Amazon ES domain\ \ Amazon Web Services, Inc.\ \ [Migrating from Amazon Elasticsearch Service | Elasticsearch Service Documentation | Elastic\ \ Elastic\ \

Disqus Comments

We were unable to load Disqus. If you are a moderator please see our troubleshooting guide.

G

Join the discussion…

Comment

Log in with
or sign up with Disqus or pick a name

Disqus is a discussion network

Read full terms and conditions

This comment platform is hosted by Disqus, Inc. I authorize Disqus and its affiliates to:

Acknowledge I am 18 or older

Favoriting means this is a discussion worth sharing. It gets shared to your followers' Disqus feeds, and gives the creator kudos!

Find More Discussions

Share

isn't iam user require access/grant es:ESHttpPut action, attached as a policy to the IAM user?

And to the last part to restore snapshot of old ElasticSearch data into new ElasticSearch (2.),

which elasticsearch-domain-endpoint are we suppose to add? is old one or new one? tried the new or destination domain endpoint but not works for me.

Thank you btw for these clear and wonderful instruction.

see more

Show more replies

Load more comments

live.rezync.com

live.rezync.com is blocked

This page has been blocked by an extension

ERR_BLOCKED_BY_CLIENT

Reload

This page has been blocked by an extension

pippio.com

pippio.com is blocked

This page has been blocked by an extension

ERR_BLOCKED_BY_CLIENT

Reload

This page has been blocked by an extension