了解这一点的一个有趣的测试是执行以下过程:
- 创建索引
- 索引一个文档
- 创建第一个快照 A
- 索引第二个文档
- 创建第二个快照 B
- 删除第一个快照A
- 删除索引
- 恢复快照 B
你认为第一个文件已经消失了吗?让我们找出来......这里是重现上述过程的所有步骤:
# 1. create an index
PUT test
# 2. index one document
PUT test/_doc/1
{
"id": 1
}
# 3. create a first snapshot A
PUT /_snapshot/my-snapshots/snapshot_a?wait_for_completion=true
{
"indices": "test",
"ignore_unavailable": true,
"include_global_state": false
}
# 4. index a second document
PUT test/_doc/2
{
"id": 2
}
# 5. create a second snapshot B
PUT /_snapshot/my-snapshots/snapshot_b?wait_for_completion=true
{
"indices": "test",
"ignore_unavailable": true,
"include_global_state": false
}
# 6. delete the first snapshot A
DELETE /_snapshot/my-snapshots/snapshot_a
# 7. delete the index
DELETE test
# 8. restore the snapshot B
POST /_snapshot/found-snapshots/snapshot_b/_restore
# 9. And now check the content of the index
GET test/_search
=>
"hits" : [
{
"_index" : "test",
"_type" : "_doc",
"_id" : "1",
"_score" : 1.0,
"_source" : {
"id" : 1
}
},
{
"_index" : "test",
"_type" : "_doc",
"_id" : "2",
"_score" : 1.0,
"_source" : {
"id" : 2
}
}
]
因此,最重要的是旧文档仍包含在较新的快照中,删除旧快照并不意味着删除旧文档。
快照包含创建快照时存在的所有分片段文件的精确副本。随着时间的推移,较小的段文件会得到merged into bigger ones。当下一个快照发生时,它将复制较新的较大段文件,而较旧的快照仍将包含较旧的较小段文件。
但是,这并不意味着只保留最新的快照并认为所有数据都在其中总是安全的,但是如果您每天进行快照,我认为只保留最后 10 个快照是安全的,并且期望所有数据都在那里。
最后值得注意的是,当你delete a snapshot时,ES 会删除所有与快照关联的未被其他快照使用的文件,这基本上使删除快照本质上是安全的。