Guides / AWS Aurora

Back up AWS Aurora.

AWS Aurora runs PostgreSQL, MySQL with standard connectivity — which means encrypted, verified, off-platform backups take a connection string and three minutes.

Find your connection details

Use the cluster reader endpoint for dumps — consistent reads without loading the writer.

# host looks like:
mycluster.cluster-abc123.eu-west-1.rds.amazonaws.com

The manual way

PostgreSQL (port 5432):

pg_dump -h mycluster.cluster-abc123.eu-west-1.rds.amazonaws.com -U USER mydb | gzip > backup.sql.gz

MySQL (port 3306):

mysqldump -h mycluster.cluster-abc123.eu-west-1.rds.amazonaws.com -u USER --single-transaction mydb | gzip > backup.sql.gz

One-shot and unencrypted. Scheduling, encryption, retention, verification and alerting are still on you — that's the part xbackupman automates.

The automated way

  1. 1. Add your AWS Aurora connection — the same host, user and password, encrypted at rest.
  2. 2. Point backups at storage you own (S3, R2, B2, MinIO, Drive…).
  3. 3. Pick a schedule — down to every 5 minutes; unchanged runs dedup to pointers.

FAQ

Does xbackupman support AWS Aurora?

Yes — AWS Aurora exposes standard PostgreSQL, MySQL connectivity, and xbackupman connects with the same credentials you use anywhere else. No special integration or agent is needed on the provider's side.

Are AWS Aurora backups encrypted?

Every dump is encrypted with AES-256-GCM using your organization's key before it leaves the worker, then stored in S3-compatible storage you own. AWS Aurora (and your storage provider) only ever see ciphertext.

Doesn't AWS Aurora already take backups?

Provider snapshots live inside the same account and platform as the database — one compromised credential or billing lapse can take both. Independent, encrypted, restore-verified copies in storage you control are what off-platform backups are for.