Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
This article describes how to restore Azure Cosmos DB by using Azure CLI (preview).
Note
The original location recovery (OLR) option isn't supported. Instead, use the alternate-location recovery (ALR) option to restore from a recovery point and create a new Azure Cosmos DB account, keeping both the source and restored database accounts.
In this article, you learn how to:
- Trigger a restore.
- Track a restore job.
Trigger a restore for Azure Cosmos DB account
Azure Backup restores an Azure Cosmos DB account from a vault recovery point to a target Azure Cosmos DB account.
To trigger restore for an Azure Cosmos DB account, run the following commands:
Grant the Backup vault's managed identity the required permissions on the target Azure Cosmos DB account. Reuse
az dataprotection backup-instance update-msi-permissionswith--operation Restore.List the recovery points for the protected item by using the az dataprotection recovery-point list command, and capture the recovery point ID.
az dataprotection recovery-point list \ --resource-group testBkpVaultRG \ --vault-name TestBkpVault \ --backup-instance-name testcosmosaccount-testcosmosaccount-00000000-0000-0000-0000-000000000000 -o tablePrepare the restore request by using the az dataprotection backup-instance restore initialize-for-data-recovery command, providing the ARM ID of the target Azure Cosmos DB account. Save the output to a JSON file.
targetCosmosDBAccountId="/subscriptions/aaaa0a0a-bb1b-cc2c-dd3d-eeeeee4e4e4e/resourceGroups/targetcosmosrg/providers/Microsoft.DocumentDB/databaseAccounts/targetcosmosaccount" az dataprotection backup-instance restore initialize-for-data-recovery \ --datasource-type AzureCosmosDB \ --source-datastore VaultStore \ --restore-location westus \ --target-resource-id $targetCosmosDBAccountId \ --recovery-point-id <recoveryPointId> > cosmosdb_restore.json(Optional) Validate the restore request by using the az dataprotection backup-instance validate-for-restore command.
az dataprotection backup-instance validate-for-restore \ --resource-group testBkpVaultRG \ --vault-name TestBkpVault \ --backup-instance-name testcosmosaccount-testcosmosaccount-00000000-0000-0000-0000-000000000000 \ --restore-request-object cosmosdb_restore.jsonTrigger the restore by using the az dataprotection backup-instance restore trigger command.
az dataprotection backup-instance restore trigger \ --resource-group testBkpVaultRG \ --vault-name TestBkpVault \ --backup-instance-name testcosmosaccount-testcosmosaccount-00000000-0000-0000-0000-000000000000 \ --restore-request-object cosmosdb_restore.json
Track the restore job for an Azure Cosmos DB account
Azure Backup creates a job when you trigger a restore operation. Track restore jobs the same way you track backup jobs, filtering on the Restore operation.
az dataprotection job list \
--resource-group testBkpVaultRG \
--vault-name TestBkpVault -o table
az dataprotection job list-from-resourcegraph \
--datasource-type AzureCosmosDB \
--operation Restore
View a protected item
A protected item (backup instance) represents the Azure Cosmos DB account that's protected in the Backup vault. Use the az dataprotection backup-instance list and az dataprotection backup-instance show commands.
# List all protected items in the vault
az dataprotection backup-instance list \
--resource-group testBkpVaultRG \
--vault-name TestBkpVault -o table
# Show a specific protected item by name
az dataprotection backup-instance show \
--resource-group testBkpVaultRG \
--vault-name TestBkpVault \
--name testcosmosaccount-testcosmosaccount-00000000-0000-0000-0000-000000000000
To view protected items across all Backup vaults and subscriptions, use the az dataprotection backup-instance list-from-resourcegraph command.
az dataprotection backup-instance list-from-resourcegraph \
--datasource-type AzureCosmosDB \
--protection-status ProtectionConfigured -o table