# PerconaServerMongoDBRestores changing users passwords

**URL:** <https://forums.percona.com/t/perconaservermongodbrestores-changing-users-passwords/18013>\
**Category:** Percona Operator for MongoDB\
**Tags:** percona\
**Created:** [October 14, 2022, 8:00pm UTC](https://forums.percona.com/t/perconaservermongodbrestores-changing-users-passwords/18013 "2022-10-14T20:00:25Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jonathon](https://avatars.discourse-cdn.com/v4/letter/j/85f322/32.png) [@jonathon](https://forums.percona.com/u/jonathon)\
**Post date:** [October 14, 2022, 8:00pm UTC](https://forums.percona.com/t/perconaservermongodbrestores-changing-users-passwords/18013/1 "2022-10-14T20:00:25Z")

</div>

Hello,

We are evaluating the mongodb operator for prod use, and I have been testing the backup and recovery functionality. It is working well, maybe even a little too well.

Test setup:

1. Create initial cluster with PerconaServerMongoDBs, load in data, ensure logical and pitr are backed up to s3.
2. Create new cluster with a different PerconaServerMongoDBs
3. Create PerconaServerMongoDBRestores to restore backup onto new cluster.

Data is recovered, but all the users passwords are changed to what the initial cluster had.  
Is there a way to only target a single database for the backup?

---

<div class="post-metadata">

**Author:** ![jonathon](https://avatars.discourse-cdn.com/v4/letter/j/85f322/32.png) [@jonathon](https://forums.percona.com/u/jonathon)\
**Post date:** [October 14, 2022, 9:05pm UTC](https://forums.percona.com/t/perconaservermongodbrestores-changing-users-passwords/18013/2 "2022-10-14T21:05:15Z")

</div>

Looked in the specs for PerconaServerMongoDB, PerconaServerMongoDBRestore, and PerconaServerMongoDBBackup, not really seeing anything that would help with this.

---

<div class="post-metadata">

**Author:** ![jonathon](https://avatars.discourse-cdn.com/v4/letter/j/85f322/32.png) [@jonathon](https://forums.percona.com/u/jonathon)\
**Post date:** [October 14, 2022, 9:10pm UTC](https://forums.percona.com/t/perconaservermongodbrestores-changing-users-passwords/18013/3 "2022-10-14T21:10:53Z")

</div>

> **[Percona Operator for MongoDB - About backups](https://docs.percona.com/percona-operator-for-mongodb/backups.html#restore-the-cluster-from-a-previously-saved-backup)**
>
> You can backup your data in two ways:

Ah, I see 😕

> When restoring to a new Kubernetes-based environment, make sure it has a Secrets object with the same user passwords as in the original cluster.

---

<div class="post-metadata">

**Author:** ![jonathon](https://avatars.discourse-cdn.com/v4/letter/j/85f322/32.png) [@jonathon](https://forums.percona.com/u/jonathon)\
**Post date:** [October 14, 2022, 9:59pm UTC](https://forums.percona.com/t/perconaservermongodbrestores-changing-users-passwords/18013/4 "2022-10-14T21:59:15Z")

</div>

OK I have a working setup. When creating the mongodb cluster in the first place create the users secret. This way it can easily be used when creating another cluster to recover to in case of disaster on the original cluster.

---

<div class="post-metadata">

**Author:** ![Sergey\_Pronin](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/sergey_pronin/32/14887_2.png) [@Sergey\_Pronin](https://forums.percona.com/u/Sergey_Pronin)\
**Post date:** [October 19, 2022, 6:09pm UTC](https://forums.percona.com/t/perconaservermongodbrestores-changing-users-passwords/18013/5 "2022-10-19T18:09:01Z")

</div>

Hello @jonathon ,

glad to see that you figured it out! Yeah, it is described in this doc: [About backups - Percona Operator for MongoDB](https://docs.percona.com/percona-operator-for-mongodb/backups.html#restore-the-cluster-from-a-previously-saved-backup)

> When restoring to a new Kubernetes-based environment, make sure it has a Secrets object with the same user passwords as in the original cluster. More details about secrets can be found in [System Users](https://docs.percona.com/percona-operator-for-mongodb/users.html#users-system-users). The name of the required Secrets object can be found out from the `spec.secrets` key in the `deploy/cr.yaml` (`my-cluster-name-secrets` by default).
