In Amazon DocumentDB, you can copy manual and automatic snapshots within the same AWS Region or to a different AWS Region within the same account. You can also share snapshots owned by other AWS accounts in the same AWS Region. However, you can't copy a cluster snapshot across AWS Regions and AWS account in a single step. These actions must be performed individually.
As an alternative to copying, you can also share manual snapshots with other AWS accounts. For more information, see Sharing Amazon DocumentDB cluster snapshots.
Note
Amazon DocumentDB bills you based upon the amount of backup and snapshot
data you keep and the period of time that you keep it. For more
information about the storage associated with Amazon DocumentDB backups and
snapshots, see Understanding backup storage usage.
For pricing information about Amazon DocumentDB storage, see Amazon DocumentDB Pricing
Topics
Copying shared snapshots
You can copy snapshots shared to you by other AWS accounts. If you are copying an encrypted snapshot that has been shared from another AWS account, you must have access to the AWS KMS encryption key that was used to encrypt the snapshot.
You can only copy a shared snapshot in the same AWS Region, whether the snapshot is encrypted or not. For more information, see Handling encryption.
Copying snapshots across AWS Regions
When you copy a snapshot to an AWS Region that is different from the source snapshot's AWS Region, each copy is a full snapshot. A full snapshot copy contains all of the data and metadata required to restore the Amazon DocumentDB cluster.
Depending on the AWS Regions involved and the amount of data to be copied, a cross-region snapshot copy can take hours to complete. In some cases, there might be a large number of cross-region snapshot copy requests from a given source AWS Region. In these cases, Amazon DocumentDB might put new cross-region copy requests from that source AWS Region into a queue until some in-progress copies complete. No progress information is displayed about copy requests while they are in the queue. Progress information is displayed when the copy starts.
Limitations
The following are some limitations when you copy snapshots:
-
If you delete a source snapshot before the target snapshot becomes available, the snapshot copy may fail. Verify that the target snapshot has a status of
AVAILABLE
before you delete a source snapshot. -
You can have up to five snapshot copy requests in progress to a single destination Region per account.
-
Depending on the regions involved and the amount of data to be copied, a cross-region snapshot copy can take hours to complete. For more information, see Copying snapshots across AWS Regions.
Handling encryption
You can copy a snapshot that has been encrypted using an AWS KMS encryption key. If you copy an encrypted snapshot, the copy of the snapshot must also be encrypted. If you copy an encrypted snapshot within the same AWS Region, you can encrypt the copy with the same AWS KMS encryption key as the original snapshot, or you can specify a different AWS KMS encryption key. If you copy an encrypted snapshot across Regions, you can't use the same AWS KMS encryption key for the copy as used for the source snapshot, because AWS KMS keys are Region-specific. Instead, you must specify an AWS KMS key valid in the destination AWS Regionn.
The source snapshot remains encrypted throughout the copy process. For more information, see Data protection in Amazon DocumentDB.
Note
For Amazon DocumentDB cluster snapshots, you can't encrypt an unencrypted cluster snapshot when you copy the snapshot.
Parameter group considerations
When you copy a snapshot across Regions, the copy doesn't include the parameter group used by the original Amazon DocumentDB cluster. When you restore a snapshot to create a new cluster, that cluster gets the default parameter group for the AWS Region it is created in. To give the new cluster the same parameters as the original, you must do the following:
-
In the destination AWS Region, create an Amazon DocumentDB cluster parameter group with the same settings as the original cluster. If one already exists in the new AWS Region, you can use that one.
-
After you restore the snapshot in the destination AWS Region, modify the new Amazon DocumentDB cluster and add the new or existing parameter group from the previous step. For more information, see Modifying an Amazon DocumentDB cluster.
Copying a cluster snapshot
You can copy an Amazon DocumentDB cluster using the AWS Management Console or the AWS CLI, as follows.
To make a copy of a cluster snapshot using the AWS Management Console, complete the following steps. This procedure works for copying encrypted or unencrypted cluster snapshots, in the same AWS Region or across Regions.
-
Sign in to the AWS Management Console, and open the Amazon DocumentDB console at https://console.aws.amazon.com/docdb
. -
In the navigation pane, choose Snapshots, and then choose the button to the left of the snapshot that you want to copy.
Tip
If you don't see the navigation pane on the left side of your screen, choose the menu icon (
) in the upper-left corner of the page.
-
From the Actions menu, choose Copy.
-
In the resulting Make Copy of cluster snapshot page, complete the Settings section.
-
Destination Region — Optional. To copy the cluster snapshot to a different AWS Region, choose that AWS Region for Destination Region.
-
New snapshot identifier — Enter a name for the new snapshot.
Target snapshot naming constraints:
-
Cannot be the name of an existing snapshot.
-
Length is [1—63] letters, numbers, or hyphens.
-
First character must be a letter.
-
Cannot end with a hyphen or contain two consecutive hyphens.
-
Must be unique for all clusters across Amazon RDS, Neptune, and Amazon DocumentDB per AWS account, per Region.
-
-
Copy tags — To copy any tags you have on your source snapshot to your snapshot copy, choose Copy tags.
-
-
Complete the Encryption-at-rest section.
-
Encryption at rest — If your snapshot is not encrypted, these options are not available to you because you cannot create an encrypted copy from an unencrypted snapshot. If your snapshot is encrypted, you can change the AWS KMS key used during encryption at rest.
For more information about encrypting snapshot copies, see Copy cluster snapshot encryption.
For more information about encryption at rest, see Encrypting Amazon DocumentDB data at rest.
-
AWS KMS Key — From the drop-down list, choose one of the following:
-
(default) aws/rds — The account number and AWS KMS key ID are listed following this option.
-
<some-key-name> — If you created a key, it is listed and available for you to choose.
-
Enter a key ARN — In the ARN box, enter the Amazon Resource Name (ARN) for your AWS KMS key. The format of the ARN is
arn:aws:kms:<region>:<accountID>:key/<key-id>
.
-
-
-
To make a copy of the selected snapshot, choose Copy snapshot. Alternatively, you can choose Cancel to not make a copy of the snapshot.