Atlas Infinite always encrypts your data at rest. Because encryption is always in effect, the restore process that you follow depends on which type of encryption your Atlas Infinite cluster uses:
Default encryption: Atlas creates and manages the encryption keys for your Atlas Infinite cluster.
Customer-managed keys (CMK/BYOK): You manage the encryption keys for your Atlas Infinite cluster.
Each encryption type supports a different set of restore scenarios and uses a different procedure. To restore an Atlas Core cluster instead, see Restore Your Cluster.
Supported Restore Scenarios
The following table shows which restore scenarios Atlas Infinite supports in public preview.
In this table, the encryption option (default or CMK) refers to how the data you want to restore was encrypted:
For snapshot restores, this is the encryption option that the source cluster used when Atlas took the snapshot. This might not be the encryption option that the source cluster uses now.
For Continuous Cloud Backup restores, this is the encryption option that the source cluster used when Atlas took the base snapshot, and every encryption option that the source cluster used between that snapshot and the point in time you restore to. For example, if the cluster changed encryption keys during that period, each of those encryption options applies.
Restore Scenario | Default Encryption | Customer-Managed Keys |
|---|---|---|
Same project | Supported | Supported |
Different project, same organization | Supported | Supported* |
*Only if the target cluster uses or used the same CMK.
You can restore a default encryption snapshot to a cluster that uses customer-managed keys, and a customer-managed key snapshot to a cluster that uses default encryption. In both cases, the target cluster must have access to the key that encrypted the backup, either because it uses that key or used it before.
Atlas Infinite supports both snapshot restores and continuous cloud backup restores. You can't restore a backup to an Atlas Infinite cluster that runs in a different region, cloud provider, or organization.
Restore Considerations
For the full list of limitations for Atlas Infinite on public preview, see Public Preview Availability.
In addition to the prerequisites, consider the following restore-specific requirements and limitations:
- If the
DefaultRWConcernvalue on the source snapshot differs from theDefaultRWConcernvalue on the target cluster, Atlas overrides the value on the source snapshot with the value on the target cluster. If there is no value configured for theDefaultRWConcernon the target cluster, Atlas keeps the value ofDefaultRWConcernfrom the snapshot without explicit configuration. This may differ from the default value for that MongoDB version.
Restore with Default Encryption
If you are using the Atlas-managed default encryption, follow this process to restore an Atlas Infinite cluster from a snapshot or from a continuous cloud backup.
Required Access
To monitor a backup restore job until it completes, you must have Project Read Only access or higher to the specific project.
To start a restore job, you must have Project Backup Recovery Operator, Project Backup Manager, or Project Owner access to the project.
For cross-organization or cross-project restores, the required permissions apply to both the source and target projects. You must have the necessary permissions: Project Backup Manager or Project Owner in both projects to initiate or manage such restore operations.
Procedure
Select the restore type and the interface that you want to use:
Restore with Customer-Managed Keys
Follow this process when you manage the encryption keys for your Atlas Infinite cluster. With customer-managed keys, you can restore only to a Atlas Infinite cluster in the same project.
Required Access
To restore an encrypted or unencrypted snapshot created in an Atlas project to the same project, you require the Project Backup Manager role.
To restore an encrypted or unencrypted snapshot created in a source Atlas project to a different target project, you require the Project Owner role in the target project.
Procedure
In Atlas, go to the Backup details for your project.
If it's not already displayed, select the organization that contains your project from the Organizations menu in the navigation bar.
If it's not already displayed, select your project from the Projects menu in the navigation bar.
In the sidebar, click Backup under the Database heading.
The Backup details display.
Click the cluster link.
Select the target Atlas Project.
From the Restore dialog box, select the target Atlas Project to which you want to restore. With customer-managed keys, you must select the same project that contains the source Atlas Infinite cluster. The authenticated Atlas user must have the Project Owner role for that project.
Select the Cluster to restore to.
The target Atlas Infinite cluster must run the same or greater version of MongoDB as the MongoDB Version of the snapshot.
After the restoration procedure, Atlas triggers a key rotation for the MongoDB encryption key. Atlas then encrypts the new MongoDB encryption keys based on the configured Encryption at Rest using Customer Key Management provider for the target Atlas Infinite cluster.