Cluster-wide recycle bin #
Accidental deletes used to be a race against the sweeper: deleting a namespace only dropped metadata, and the data directories drifted into the trash WITHOUT a recovery snapshot — permanently unrestorable. The recycle bin is now a first-class, cluster-wide surface with a namespace-centric view, a pre-restore integrity check, and one-request restore:
# One cluster-wide list — every node's trash merged by item, grouped by
# namespace, with the delete-time snapshot summary of each item.
GET /_cluster/trash
Deleting a namespace captures a restore snapshot for every collection it contains, so the WHOLE namespace comes back as a unit — original schemas, shard UUIDs, partition routing and placements included:
POST /_cluster/trash/<item>/restore
{ "new_name": "website_recovered" }
Before anything moves, the restore runs a read-only verification across
the cluster: every shard group must still have a complete copy somewhere
(allocation directory + segment manifest with all declared files; with
?deep=true, a footer parse of every segment file catches truncation
and corruption by name). An item whose data is provably incomplete is
refused with 409 and the full report — not silently restored with
empty shards:
POST /_cluster/trash/<item>/verify?deep=true
The console’s Data → Trash page builds on the same endpoints: items grouped under their deleted namespaces, per-item verification reports, and restores that refuse to proceed on a red check unless explicitly forced.