如何按要求配置AWS RDS (PostgreSQL)自动备份策略?
Got it, let's walk through exactly how to set up automated backups for your AWS RDS PostgreSQL instances to match your production and UAT requirements. I'll cover both RDS native tools (for simpler daily backups) and custom scripting (to hit that 4-hour full backup cadence for production).
1. Production Environment (Every 4-Hour Full Backup, Retain 1 Month)
AWS RDS's built-in automated snapshots only run once daily, so we'll need a custom backup workflow to meet your 4-hour frequency requirement. Here's how to pull it off:
Step 1: Build a pg_dump Backup Script
Create a shell script that uses pg_dump to take a full database backup, then pushes it to S3 for durable storage. Here's a working example:
#!/bin/bash # Configure your RDS and S3 details DB_HOST="your-production-rds-endpoint.rds.amazonaws.com" DB_NAME="your-target-db" DB_USER="your-db-username" BACKUP_FILENAME="prod-db-backup-$(date +%Y%m%d-%H%M%S).sql" S3_BACKUP_BUCKET="your-prod-backup-bucket" # Run full PostgreSQL backup pg_dump -h $DB_HOST -U $DB_USER -d $DB_NAME -F c -b -v > $BACKUP_FILENAME # Upload backup to S3 aws s3 cp $BACKUP_FILENAME s3://$S3_BACKUP_BUCKET/ # Clean up local backup file to save space rm $BACKUP_FILENAME
Pro tip: Make sure the IAM role associated with your execution environment (EC2, Lambda, etc.) has permissions to connect to RDS and write to your S3 bucket.
Step 2: Schedule the Script
Use AWS EventBridge (formerly CloudWatch Events) or EC2 cron to trigger the script every 4 hours:
- Lambda: Package the script as a Lambda function (use a custom bash runtime or wrap it in Python) and set a cron expression:
0 */4 * * ? * - EC2: Add this line to your EC2 user's crontab to run the script on schedule and log output:
0 */4 * * * /path/to/your/prod-backup-script.sh >> /var/log/prod-db-backups.log 2>&1
Step 3: Enforce 1-Month Retention
Set up an S3 Lifecycle Policy to auto-delete backups older than 30 days:
- Open your backup bucket in the AWS S3 Console
- Go to Management > Lifecycle rules
- Create a rule that applies to all backup objects, then set Expire objects to 30 days after creation
2. UAT Environment (Daily Backup, Retain 1 Week)
Since daily backups align with RDS's native snapshot schedule, you can choose between two easy options:
Option A: Use RDS Built-In Automated Backups (Simplest)
This handles both daily backups and automatic cleanup in one place:
- Navigate to your UAT RDS instance in the AWS Console
- Go to Configuration > Backup
- Enable Automated backups (they run daily during your specified window)
- Set the Backup retention period to 7 days
RDS will automatically delete snapshots older than 7 days for you.
Option B: Custom Script Approach (Consistent with Production)
If you want to keep your backup workflow uniform across environments:
- Adjust the backup script to point to your UAT RDS endpoint and dedicated UAT S3 bucket
- Schedule it with a cron expression of
0 0 * * ? *(daily at midnight UTC) in EventBridge/Lambda, or0 0 * * *in EC2 crontab - Set the UAT S3 bucket's Lifecycle Policy to expire objects after 7 days
Quick Best Practices
- Verify your security groups allow inbound access from the environment running your backup script (EC2/Lambda) to your RDS instances
- Test backups regularly by restoring them to a test instance to confirm data integrity
- For Lambda functions, allocate enough memory and timeout to handle large database backups
内容的提问来源于stack exchange,提问作者Shahid Rasool

