如何将AWS Elasticsearch迁移至另一个AWS账户?
Hey there! Since you’ve already nailed down EC2 and RDS migrations, let’s walk through reliable methods to move your AWS OpenSearch Service cluster to a new account. Here are two proven approaches:
Method 1: Snapshot and Restore (Most Common for Full Migrations)
This is the go-to method for one-time migrations, leveraging S3 as a shared snapshot repository.
Step 1: Set up a shared S3 snapshot repository in the source account
- Create an S3 bucket in your source account to store cluster snapshots.
- Create an IAM role for OpenSearch Service with permissions to read/write to this bucket (attach a restricted policy for just your target bucket instead of full S3 access for better security).
- Register this S3 bucket as a snapshot repository in your source OpenSearch cluster via the console or API:
PUT _snapshot/my-shared-repo { "type": "s3", "settings": { "bucket": "my-opensearch-snapshots", "region": "us-east-1", "role_arn": "arn:aws:iam::SOURCE_ACCOUNT_ID:role/OpenSearchSnapshotRole" } }
Step 2: Create a cluster snapshot
- In the source OpenSearch console, navigate to Snapshots > Create snapshot, select your new repository, and choose to snapshot the entire cluster or specific indices.
- Wait for the snapshot to complete successfully (you can monitor progress in the console).
Step 3: Grant the new account access to the snapshot and S3 bucket
- Update your S3 bucket policy to allow the new account to read objects and list the bucket. Example policy snippet:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::NEW_ACCOUNT_ID:root" }, "Action": ["s3:GetObject", "s3:ListBucket"], "Resource": [ "arn:aws:s3:::my-opensearch-snapshots", "arn:aws:s3:::my-opensearch-snapshots/*" ] } ] } - Also, update the snapshot repository’s permissions in the source cluster to explicitly allow the new account to read snapshots.
- Update your S3 bucket policy to allow the new account to read objects and list the bucket. Example policy snippet:
Step 4: Register the same S3 repository in the new account
- In the new account, create an IAM role with permissions to read from the shared S3 bucket.
- Register the S3 bucket as a snapshot repository in your new OpenSearch cluster (use the same bucket name and region, and the new account’s IAM role ARN).
Step 5: Restore the snapshot to a new cluster
- In the new account’s OpenSearch console, go to Snapshots, select the shared repository, choose your source snapshot, and click Restore.
- Restore to a new cluster (recommended to avoid conflicts) or an existing compatible cluster. Wait for the restore process to finish.
Method 2: Cross-Account Cluster Replication (Minimal Downtime)
Use this method if you need to minimize downtime and keep data in sync during the migration.
Prerequisites:
- Source and target clusters must run compatible OpenSearch versions (check AWS’s official compatibility matrix to avoid issues).
- Network connectivity between source and target clusters (e.g., VPC peering, transit gateway, or restricted public access with security group rules).
Migration Steps:
- Step 1: Configure permissions in the source account
- Create an IAM role in the source account that allows the target account’s OpenSearch cluster to replicate data. Attach a policy that grants
es:ReplicateFrompermissions on the source cluster. - Update the source cluster’s access policy to allow the target account’s IAM role to initiate replication.
- Create an IAM role in the source account that allows the target account’s OpenSearch cluster to replicate data. Attach a policy that grants
- Step 2: Set up the target cluster in the new account
- Create a new OpenSearch cluster in the new account with matching version, instance type, and configuration (like storage, plugins) as the source cluster.
- Step 3: Enable cross-account replication
- In the target cluster’s console, navigate to Replication > Create replication rule.
- Enter the source cluster’s ARN, select the IAM role you created in the source account, and choose which indices to replicate (or select all).
- Step 4: Switch traffic to the target cluster
- Once replication shows as fully synced, update your application’s endpoint to point to the new cluster.
- Verify all operations (queries, indexing, plugin functionality) work as expected, then decommission the source cluster.
- Step 1: Configure permissions in the source account
Key Notes to Avoid Pitfalls
- Version Compatibility: Never restore a snapshot to a cluster running an older OpenSearch/Elasticsearch version. Ensure the target cluster version is identical or a compatible newer release.
- Security Hardening: Restrict IAM roles and S3 bucket policies to only the necessary accounts and resources—avoid over-permissioning to reduce security risks.
- Post-Migration Testing: Validate data integrity (compare index counts, run sample queries) and confirm all custom configurations (like domain access policies, plugins) are working in the new cluster.
内容的提问来源于stack exchange,提问作者Sathishkumar Jayaraj

