External Storages
Backup & Restore (BR), TiDB Lighting, and Dumpling support reading and writing data on the local filesystem and on Amazon S3. BR also supports reading and writing data on the Google Cloud Storage (GCS) and Azure Blob Storage (Azblob). These are distinguished by the URL scheme in the --storage parameter passed into BR, in the -d parameter passed into TiDB Lightning, and in the --output (-o) parameter passed into Dumpling.
Schemes
The following services are supported:
URL parameters
Cloud storages such as S3, GCS and Azblob sometimes require additional configuration for connection. You can specify parameters for such configuration. For example:
Use Dumpling to export data to S3:
./dumpling -u root -h 127.0.0.1 -P 3306 -B mydb -F 256MiB \ -o 's3://my-bucket/sql-backup?region=us-west-2'Use TiDB Lightning to import data from S3:
./tidb-lightning --tidb-port=4000 --pd-urls=127.0.0.1:2379 --backend=local --sorted-kv-dir=/tmp/sorted-kvs \ -d 's3://my-bucket/sql-backup?region=us-west-2'Use TiDB Lightning to import data from S3 (using the path style in the request mode):
./tidb-lightning --tidb-port=4000 --pd-urls=127.0.0.1:2379 --backend=local --sorted-kv-dir=/tmp/sorted-kvs \ -d 's3://my-bucket/sql-backup?force-path-style=true&endpoint=http://10.154.10.132:8088'Use BR to back up data to GCS:
./br backup full -u 127.0.0.1:2379 \ -s 'gcs://bucket-name/prefix'Use BR to back up data to Azblob:
./br backup full -u 127.0.0.1:2379 \ -s 'azure://container-name/prefix'
S3 URL parameters
$AWS_ACCESS_KEY_IDand$AWS_SECRET_ACCESS_KEYenvironment variables$AWS_ACCESS_KEYand$AWS_SECRET_KEYenvironment variables- Shared credentials file on the tool node at the path specified by the
$AWS_SHARED_CREDENTIALS_FILEenvironment variable - Shared credentials file on the tool node at
~/.aws/credentials - Current IAM role of the Amazon EC2 container
- Current IAM role of the Amazon ECS task
GCS URL parameters
When credentials-file is not specified, the migration tool will try to infer the credentials from the environment, in the following order:
- Content of the file on the tool node at the path specified by the
$GOOGLE_APPLICATION_CREDENTIALSenvironment variable - Content of the file on the tool node at
~/.config/gcloud/application_default_credentials.json - When running in GCE or GAE, the credentials fetched from the metadata server.
Azblob URL parameters
To ensure that TiKV and BR use the same storage account, BR determines the value of account-name. That is, send-credentials-to-tikv = true is set by default. BR infers these keys from the environment in the following order:
- If both
account-nameandaccount-keyare specified, the key specified by this parameter is used. - If
account-keyis not specified, then BR tries to read the related credentials from environment variables on the node of BR.- BR reads
$AZURE_CLIENT_ID,$AZURE_TENANT_ID, and$AZURE_CLIENT_SECRETfirst. At the same time, BR allows TiKV to read the above three environment variables from the respective nodes and access using Azure AD (Azure Active Directory).$AZURE_CLIENT_ID,$AZURE_TENANT_ID, and$AZURE_CLIENT_SECRETrespectively refer to the application IDclient_id, the tenant IDtenant_id, and the client passwordclient_secretof Azure application.- To learn how to check whether the operating system has configured
$AZURE_CLIENT_ID,$AZURE_TENANT_ID, and$AZURE_CLIENT_SECRET, or if you need to configure these variables as parameters, refer to Configure environment variables as parameters.
- BR reads
- If the above three environment variables are not configured in the BR node, BR tries to read
$AZURE_STORAGE_KEYusing an access key.
Command-line parameters
In addition to the URL parameters, BR and Dumpling also support specifying these configurations using command-line parameters. For example:
./dumpling -u root -h 127.0.0.1 -P 3306 -B mydb -F 256MiB \
-o 's3://my-bucket/sql-backup' \
--s3.region 'us-west-2'
If you have specified URL parameters and command-line parameters at the same time, the URL parameters are overwritten by the command-line parameters.
S3 command-line parameters
To export data to non-AWS S3 cloud storage, specify the cloud provider and whether to use virtual-hosted style. In the following examples, data is exported to the Alibaba Cloud OSS storage:
Export data to Alibaba Cloud OSS using Dumpling:
./dumpling -h 127.0.0.1 -P 3306 -B mydb -F 256MiB \ -o "s3://my-bucket/dumpling/" \ --s3.endpoint="http://oss-cn-hangzhou-internal.aliyuncs.com" \ --s3.provider="alibaba" \ -r 200000 -F 256MiBBack up data to Alibaba Cloud OSS using BR:
./br backup full --pd "127.0.0.1:2379" \ --storage "s3://my-bucket/full/" \ --s3.endpoint="http://oss-cn-hangzhou-internal.aliyuncs.com" \ --s3.provider="alibaba" \ --send-credentials-to-tikv=true \ --ratelimit 128 \ --log-file backuptable.logExport data to Alibaba Cloud OSS using TiDB Lightning. You need to specify the following content in the YAML-formatted configuration file:
[mydumper] data-source-dir = "s3://my-bucket/dumpling/?endpoint=http://oss-cn-hangzhou-internal.aliyuncs.com&provider=alibaba"
GCS command-line parameters
Azblob command-line parameters
| Command-line parameter | Description |
| --azblob.account-name | The account name of the storage |
| --azblob.account-key | The access key |
| --azblob.access-tier | Access tier of the uploaded objects (for example, Hot, Cool, Archive). If access-tier is not set (the value is empty), the value is Hot by default. |
BR sending credentials to TiKV
By default, when using S3, GCS, or Azblob destinations, BR will send the credentials to every TiKV node to reduce setup complexity.
However, this is unsuitable on cloud environment, where every node has their own role and permission. In such cases, you need to disable credentials sending with --send-credentials-to-tikv=false (or the short form -c=0):
./br backup full -c=0 -u pd-service:2379 -s 's3://bucket-name/prefix'
When using SQL statements to back up and restore data, you can add the SEND_CREDENTIALS_TO_TIKV = FALSE option:
BACKUP DATABASE * TO 's3://bucket-name/prefix' SEND_CREDENTIALS_TO_TIKV = FALSE;
This option is not supported in TiDB Lightning and Dumpling, because the two applications are currently standalone.