Backup and restore
Octane stores state in three different places, and they restore differently. Knowing which is which is the difference between a restore that works and one that produces an index nothing can open.
| What | Where it lives | In a snapshot? |
|---|---|---|
| Accelerated index data | The index's own segments | Yes, with the index |
| Graph edges, vocabularies | Ordinary fields in ordinary indices | Yes, with the index |
| The license and the trial record | Cluster state | Yes |
| Named compliance policies | Cluster state | Yes |
| Controller policies, drains, leases, restart plans | .octane-* indices | Yes, when matched |
| Ingest and search pipelines | Cluster state | Yes |
| The graph traversal scratch directory | Node-local disk, outside any commit | No, and it does not need to be |
Install the plugins before you restore
An accelerated index cannot be opened without octane-accelerator. The codec is recorded in
every segment, so a restore onto a cluster that lacks the plugin produces shards that will not open —
the same one-way door described under removing the plugin,
reached from the other direction.
The same applies to cluster state. octane-license registers the license custom and octane-content
registers the compliance-policy custom; restoring a snapshot that carries them onto a cluster without
those plugins means the state cannot be deserialized.
So the order is: install the plugins, start the cluster, then restore. In the install order described
in Install — octane-license first, because the
others declare it as an extended plugin and a node without it does not start.
The license travels with the snapshot
The license lives in cluster state, so it is written into snapshots alongside it, and the trial record travels with it. Restoring a snapshot onto a different cluster carries the record that a trial was started — which is intended, and is what stops a trial being renewed indefinitely by snapshotting and restoring somewhere new. See A trial travels with a snapshot.
If the restored cluster is a genuinely separate deployment, it needs its own license. It will not get a second trial.
Named compliance policies travel the same way. A restored cluster redacts according to the policies the source cluster had, which is usually what you want and is worth checking when it is not.
The controller's indices
The five .octane-* indices are hidden, so a wildcard that does not include hidden indices will skip
them. Decide deliberately:
- Include them and a restore brings back autoscale policies — useful when rebuilding the same cluster.
- Exclude them when restoring into a different cluster. Drain records and leases describe nodes that do not exist there, and a restored drain record refers to an allocation exclusion that was never written.
If you restore drains or leases by accident, the safe move is to delete those two indices and let the controller recreate them; it treats a missing index as no work in progress. Policies are the only one of the five worth keeping across clusters.
Snapshotting while the controller is running
A snapshot in progress makes the safety service return Wait rather than Unsafe — the controller
pauses drains until the snapshot finishes rather than fighting it. No coordination is required, but a
drain will not start while a snapshot runs, and a long snapshot delays scaling.
Stopping the controller before a snapshot is not necessary. If you do stop it mid-drain, the drain
record survives in .octane-drains and the controller resumes from it — see
Troubleshooting.
A restore checklist
- Install
octane-license, then the plugins the source cluster had. - Confirm the accelerator version matches what the segments expect — an accelerated index restored onto a node with an incompatible accelerator will not open. See Compatibility.
- Restore, excluding
.octane-drainsand.octane-drain-leasesif this is a different cluster. - Check the license:
GET /_lucenia/license. A restored trial record may mean this cluster needs a license immediately. - Start the controller last, so it observes a settled cluster.