Spec

User guide · Spec for AWS

Copy your company’s data out of AWS

How to set up Spec, give it read-only access, copy your databases and files to a computer you own, check the copy and search it.

Early access: we set Spec up with you. Steps done on the Spec computer are done together for now.

Spec

The app your people use to search the copy, on their phones, tablets and computers. The Spec computer itself is set up with you.

On this page

  1. What Spec does
  2. What you need
  3. What it costs
  4. Step 1: Give Spec read-only access
  5. Step 2: Check before copying
  6. Step 3: Copy your data
  7. Step 4: Check your copy
  8. Step 5: Keep the copy up to date
  9. Step 6: Search
  10. People and roles
  11. What is copied, and what isn’t yet
  12. Your data if you stop
  13. If something goes wrong
  14. Early access

What Spec does

Spec takes a full copy of your company’s data out of Amazon Web Services (AWS) and keeps it on a computer you own. Then your people can search all of it there, even with the internet switched off.

What Spec doesn’t do

More: your own copy, yours to keep, and how to keep it in your own country.

What you need

What it costs

Spec for AWS costs a fifth of what AWS charges each month to keep the same amount of data in S3 Standard, AWS’s normal storage. For 1 TB, that’s $4.71 a month with Spec, where AWS charges $23.55. For 10 TB, $47.10.

Work out your price · AWS’s announcement about the download fee

This compares prices, not bills. You also need the Spec computer, and your AWS bill only goes down if you delete the data in AWS.

Step 1: Give Spec read-only access

Spec needs to read your data, and nothing more. Your AWS admin sets this up once.

For a database

Make a login that can only read. Run this in your database as its admin. If your tables are in another schema than public, repeat the two GRANT lines with that schema’s name.

-- Run as your database's admin. Choose a long password of your own.
CREATE ROLE spec_reader LOGIN PASSWORD 'a-long-password-you-choose';
GRANT USAGE ON SCHEMA public TO spec_reader;
GRANT SELECT ON ALL TABLES IN SCHEMA public TO spec_reader;
ALTER ROLE spec_reader SET default_transaction_read_only = on;

On Amazon RDS you can use an AWS login (IAM database authentication) instead of a password. We set that up with you.

For files in S3

Give Spec an AWS login with this policy. Replace your-bucket with your bucket’s name. It lets Spec list the files and read them, nothing else.

{
  "Version": "2012-10-17",
  "Statement": [
    { "Effect": "Allow", "Action": "s3:ListBucket", "Resource": "arn:aws:s3:::your-bucket" },
    { "Effect": "Allow", "Action": "s3:GetObject",  "Resource": "arn:aws:s3:::your-bucket/*" }
  ]
}

If the bucket is encrypted with your own KMS key, also allow kms:Decrypt on that key.

Where the logins go

Step 2: Check before copying

Before a copy starts, Spec checks that it can read everything. You need the Operator or Admin role.

  1. Sign in at specit.app/app, or open the Spec app.
  2. Open Data. Your database is listed under Configured sources. (Sources are added on the Spec computer; during early access, we add them with you.)
  3. Tap Review migration, then Run preflight.
  4. Wait for Preflight passed. It shows the number of tables, an estimate of the size, the working space and the free disk.

The check looks at access to the database, the tables and their keys, the column types, the search model and the free disk. If it fails, it says why: see If something goes wrong.

Step 3: Copy your data

  1. After Preflight passed, tap Start migration. Spec checks again, then starts copying.
  2. Open Activity to follow each stage. The copy runs on the Spec computer and carries on if you close the page. The page refreshes every five seconds.
  3. When every check has passed, the copy says Ready for review. Open it and tap Review publication, then confirm.
  4. Publishing switches your search to the new copy. Until then, your people keep searching the previous one, and the previous one is kept so it can be switched back.

Step 4: Check your copy

Open Archive. Every copy keeps an archive of the tables it read, with their rows, files and size, and a manifest that lists the fingerprint of every file.

ButtonWhat it does
Check integrityChecks every file of the archive against its fingerprint.
Test restoreLoads every table into a separate test database, compares it with the archive row for row, recreates the keys, then throws the test away.
Prepare downloadPacks the archive into one file. Then Download archive, and compare the file’s SHA-256 with the one shown.
Remove archiveDeletes that archive from the Spec computer. It can’t be undone: download it first if you need it.

Operators and admins start these. Members can download a prepared archive and read the results.

A passed restore test shows the rows restore exactly. It doesn’t bring back your database’s users, permissions, functions or indexes: those stay in AWS or in your own records.

Step 5: Keep the copy up to date

After the first copy, Spec fetches only what changed since the last one. During early access, we set how often with you.

Admins control copies in Admin → Internet and copies:

What to do when the internet goes down

People and roles

RoleCan
MemberSearch and read.
OperatorAlso run copies from AWS and look after the archives.
AdminAlso add and remove people, and change the internet and copy settings.

Add a person

  1. Open Admin. Under Add a person, enter their email, a name and a role.
  2. Tap Add and show a password. The temporary password is shown only once.
  3. Give it to them in person or by phone, not by email.
  4. They sign in with it, add Face ID or a fingerprint, and choose their own password in Settings.

Look after people

What is copied, and what isn’t yet

Databases

Files in S3

Your data if you stop

If something goes wrong

The app says what went wrong. The usual reasons, and what to do:

If Spec can’t be reached at all, see If the internet goes down.

Early access