# Restore S3

This guide shows you how to restore a S3 backup to the source S3 bucket, a new S3 bucket or an existing S3 bucket.

You could also look at the [AWS S3 Restore documentation](https://docs.aws.amazon.com/aws-backup/latest/devguide/restoring-s3.html)

## Things to consider

You need to make some decisions before you start the restore:

- Where do you want to restore the backup to (source, new or existing S3 bucket)?
- Do you want to restore the entire backup or just specific folders? Do you have the URI of the folders you want to restore?
- If you have point-in-time-restore: from when do you want to restore the backup?

## Before you begin

You need to:

- Complete [Set up AWS Backup](../initial-setup-of-your-aws-environment/set-up-aws-backup.md)
- Have at least one snapshot available (by default a S3 backup is completed nightly)
- Have enough time - a restore can take up to hours

## Step 1: Have the right permissions

If you want to restore to an existing bucket, you need to temporarily enable ACL on that bucket:

- Go to the AWS S3 service
- Select the bucket you want to restore to
- Select **Permissions** > **Object Ownership** > **Edit**
- Select **ACLs enabled** and **Save changes**

<figure markdown="span">
![Enable ](../images/backup/restore-s3-enable-acls.png){ width="900" }
</figure>

<!-- prettier-ignore-start -->
!!! info
    If you are using Golden Path boilerplate:backup v3.2.0 or later, you have the necessary permissions.
<!-- prettier-ignore-end -->

If you are _NOT_ using Golden Path boilerplate:backup v3.2.0 or later, upgrade to the latest version of the boilerplate, or add extra permissions to the role used for the restore (for example: `aws-backup-<timestamp>`):

- Go to the AWS IAM service
- Select **Roles** > **aws-backup-<timestamp>**
- In **Permissions policies** > **Add permissions** > **Attach policies**
- Select **AWSBackupServiceRolePolicyForS3Restore** and **Add permissions**

## Step 2: Find a snapshot to restore

In the AWS console find the AWS Backup. Under **Protected resources** you find the backup resources.

Select the resource you want to restore. Under **Recovery points** you find the snapshots available.

Select the recovery point you want to restore and click **Restore**.

## Step 3: Configure restore

1. Under **Settings** > **Restore type** you can choose between **Restore entire bucket** or **Item level restore**.

1. Under **Settings** > **Restore destination** you can choose between **Restore to source bucket**, **Use existing bucket** or **Create new bucket**.

1. Under **Restore role** you need to choose an IAM role with the necessary permissions.
   If you are using golden path boilerplate:backup v3.2.0 or later, the role aws-backup-<timestamp> contains the necessary permissions.

1. Select **Restore backup**

<figure markdown="span">
![Settings for restore backup](../images/backup/restore-s3-settings.png){ width="900" }
</figure>

<figure markdown="span">
![Restore role](../images/backup/restore-s3-restore-role.png){ width="900" }
</figure>

## Step 4: Verify

You reach a page where you can track the progress. The restore can take up to hours, but the restored
files become available as soon as they are restored.

<figure markdown="span">
![Enable ](../images/backup/restore-s3-monitoring.png){ width="900" }
</figure>

<!-- prettier-ignore-start -->
!!! question Troubleshooting - The restore went OK but the files are still missing
      If the restore went OK but the files are still missing, you should check the following:

     * Did you restore to the correct bucket?
     * Did you restore the correct folders?
     * Did you restore from the correct snapshot?
      * Did the files exist at the time of the snapshot?
<!-- prettier-ignore-end -->

## Step 5: Clean up

If you have turned on the ACL on the existing bucket, you should turn it off again in one of two ways:

Either run Terraform to restore the settings of your S3 bucket.

Or turn it off manually:

- Go to the AWS S3 service
- Select the bucket you restored to
- Select **Permissions** > **Object Ownership** > **Edit**
- Select **ACLs disabled (recommended)** and **Save changes**
