Admin operationsInfinigraphNot available on AuraIntroduced in 2025.12
Sharded property databases are managed similarly to standard Neo4j databases, with some differences in certain administrative operations.
Managing aliases for sharded databases
When creating an alias for a sharded database, use the virtual database name when specifying it as the alias target.
The following example shows how to create the alias foo for the sharded database foo-sharded:
CREATE ALIAS foo FOR DATABASE `foo-sharded`
Managing servers with sharded databases
Graph references in server management commands must refer to shards. The virtual sharded database is rejected or ignored.
The following example shows how to enable a server and allow allocating the property shard foo-sharded-p000:
ENABLE SERVER 'serverId' OPTIONS { allowedDatabases: ['foo-sharded-p000'] }
Backup and restore
A sharded property database is a database made up of multiple databases. This means that when you want to back up a database, you must back up all the shards individually, resulting in a sharded property database backup that is composed of multiple smaller backup chains.
Backup chains for each shard are produced using the neo4j-admin database backup command.
For the graph shard, its backup chain must contain one full artefact and 0+ differential artefacts.
Each property shard’s backup chain must contain only one full backup and no differential backups.
In practical terms, this means that to back up a sharded property database, you start with a full backup of the graph shard and then all of the property shards; any subsequent differential backups would only need to be of the graph shard.
This is because the transaction log of the property shards is the same as the graph shard log and is simply filtered when applied, so only the graph shard log is required for a restore.
Backing up a sharded property database
For example, assume there is a sharded property database called foo with a graph shard and 2 property shards.
-
Back up each shard, for example:
bin/neo4j-admin database backup "foo*" --to-path=/backups --from=localhost:6361 --remote-address-resolution -
Check the validity of the resulting backups. For details on command syntax and options, see Validate a database backup.
bin/neo4j-admin backup validate --from-path=s3://bucket/backups --database="foo"The output will indicate whether the backups are valid. For example:
| DATABASE | PATH | STATUS | | foo-g000 | /bucket/backups/foo-g000-2025-06-11T21-04-42.backup | OK | | foo-p000 | /bucket/backups/foo-p000-2025-06-11T21-04-37.backup | OK | | foo-p001 | /bucket/backups/foo-p001-2025-06-11T21-04-40.backup | OK |
Restoring a sharded property database
You can use the CREATE DATABASE command to seed a sharded property database from a valid backup.
The following example seeds the sharded property database baz from backups stored in an S3 bucket:
CYPHER 25 CREATE DATABASE baz SET GRAPH SHARD { TOPOLOGY 3 PRIMARIES 0 SECONDARIES }
SET PROPERTY SHARDS { COUNT 2 TOPOLOGY 1 REPLICA }
OPTIONS {seedUri:"s3://bucket/backups/"};
Understanding backup validation
Due to potential synchronization issues that might occur when shard backups are not on the exact same transaction IDs (since backups can be taken in parallel or sequentially), the restore process is designed to be very lenient to different shards at different transaction IDs. As a result, a sharded property database backup is considered valid if the store files of each property shard are within the range of transactions recorded in the graph shard’s transaction log.
For example, assume the graph shard’s store files are at tx 10 and it has transaction logs from tx 11-36, and property shard 1’s store files are at 13 and property shard 2’s store files are at 30, then at restore time, all databases can be recovered and made consistent up to transaction 36.
You can use the command neo4j-admin backup validate to check whether a collection of backup chains for a database is valid.
For details on command syntax and options, see Validate a database backup.
Additional actions may be required to create a validated backup if a property shard is ahead or behind the range of transactions in the graph shard backup chain.
| DATABASE | PATH | STATUS | | foo-g000 | /backups/foo-g000-2025-06-11T21-04-42.backup | OK | | foo-p000 | /backups/foo-p000-2025-06-11T21-04-37.backup | Backup is behind (3 < 5) the graph shard backup chain | | foo-p001 | /backups/foo-p001-2025-06-11T21-04-40.backup | Backup is ahead (12 > 8) of the graph shard backup chain |
To form a validated backup, you must ensure that each property shard’s store files are within the range of transactions recorded in the graph shard’s transaction log.
In the example above, property shard foo-p000 is behind the graph shard backup chain, and property shard foo-p001 is ahead of the graph shard backup chain.
To form a valid sharded property database backup, you need to:
-
Take a full backup of the property shard
foo-p000so that its store at least includes transaction 5. -
Take a differential backup of the graph shard, so that at least transaction 12 is included in its transaction log, so
foo-p001is included in its range.
Once a valid sharded properties database backup is created, differential backups can be performed by taking differential backups of the graph shard, extending the range of the graph shard chain. Continuing with the example, the graph chain contains transactions from 11 to 36, property shard 1’s store files are at 13, and property shard 2’s store files are at 30. You then take a differential backup of the graph shard containing transactions 37 to 50. At restore time, all databases can be recovered up to transaction 50 and made consistent.
Transaction log pruning and recovery
In a sharded property database, property shards pull transaction log entries from the graph shard and apply them to their stores. Thus, it is required that the graph shard does not prune an entry from its transaction log until every replica of each property shard has pulled and applied that entry. Otherwise, a property shard replica that has not yet applied the latest entry will be unable to do so and will be severed, leading to data inconsistency. If this happens to all replicas of a given property shard, then the whole sharded property database is in an unrecoverable state.
To ensure enough transaction logs are kept, you must set db.tx_log.rotation.retention_policy accordingly.
A suitable heuristic is to ensure that the transaction log kept covers the transactions written between successive full backups of the sharded property database.
It is also important to ensure that there is space for the transaction logs and that the server does not run out of disk space.
Starting from Neo4j 2026.01, to prevent property shard replicas from becoming severed, the system automatically monitors the transaction apply lag of property shard replicas and prevents the graph shard from pruning entries that property shard replicas have not yet applied to their stores.
This mechanism prevents any property shard replica from falling behind the transaction log range available on the graph shard.
If the inability to prune persists, then the system puts the sharded property database into read-only mode to prevent the server from running out of disk space.
Once the underlying cause behind the lagging property shard is resolved, you can switch the sharded property database back into read-write mode by performing the following steps:
-
Ensure that all replicas of all property shards are caught up with the graph shard’s transaction log using the following query against the
systemdatabase:CYPHER 25 SHOW DATABASES YIELD name, type, role, lastCommittedTxn, replicationLag, shardTxnLagThe
replicationLagcolumn shows how far behind each replica is from its primary, and theshardTxnLagcolumn shows how far behind each property shard is from the graph shard.
If any replica shows a non-zeroreplicationLagorshardTxnLag, wait for it to catch up.
Once all replicas show zeroreplicationLagandshardTxnLag, the sharded property database is ready to be brought back to read-write mode. -
Run the Cypher command
ALTER DATABASE <sharded-db-name> SET ACCESS READ WRITEagainst thesystemdatabase to bring the sharded property database back to read-write mode.
|
In case of a system failover
The monitoring mechanism introduced in 2026.01, described in the previous paragraphs, should prevent property shards from being severed. However, in the unlikely event shards do fail, you can recover them using one of the following options:
|
Glossary
- allocator
-
A component in the cluster that allocates databases to servers according to the topology constraints specified and an allocation strategy.
- asynchronous replication
-
Asynchronous replication is used by secondary copies to poll for new transactions, which means they cannot be guaranteed to have received the most recent transactions. This enables efficient scale-out of read-performance.
- Aura instance
-
A fully-managed DBMS represented by a single instance ID, that is running in the Neo4j Aura cloud.
- auto-commit transaction
-
An automatically committed transaction that contains a single query.
- Bolt protocol
-
Bolt is a protocol used for interaction between Neo4j instances and drivers.
- bookmark
-
A marker the client can request from the cluster to ensure that it is able to read its own writes so that the application’s state is consistent and only databases that have a copy of the bookmark are permitted to respond.
- category (Bloom)
-
A category is based on a node label and is defined in a Perspective as a way of visually distinguishing nodes with the same label(s).
- causal consistency
-
All servers in a cluster agree on the order in which transactions take place. The position of a server on the causal chain can be guaranteed using a bookmark.
- cluster
-
A Neo4j DBMS that spans multiple servers working together to increase fault tolerance and/or read scalability. Databases on a cluster may be configured to replicate across servers in the cluster thus achieving read scalability or high availability.
- client application
-
Software that interacts with a Neo4j server.
- commit
-
A commit is the successful completion of a transaction, which ensures durability of any changes made. For more details, visit Operations Manual → Transaction management.
- composite database
-
Composite databases are the means to access partitioned graph data with a single Cypher query.
- constraint
-
Constraints are sets of data modeling rules that ensure the data is consistent and reliable.
- Cypher®
-
Neo4j’s graph query language.
- data model
-
A data model defines how information is organized in a database. A good data model will make querying and understanding your data easier. In Neo4j, the data models have a graph structure.
- database
-
A database is a container used by the DBMS to manage and store graph data. The physical structure of data is controlled by the database.
- database vs graph
-
Databases are the physical containers of graph data. Graphs are the logical structure of data in Neo4j.
- Database Management System
-
Database Management System, or DBMS, capable of managing multiple databases. A DBMS may run on a single server, or span several servers configured as a cluster.
- database schema
-
The prescribed property existence and datatypes for nodes and relationships.
- deallocate
-
An act of removing a database from a server or a server from a cluster without loss of data or reduced fault tolerance.
- degree (of a node)
-
The number of relationships of a specific node; loops are counted twice.
- disaster recovery
-
A manual intervention to restore availability of a cluster, or databases within a cluster.
- driver
-
A software library that provides access to Neo4j from a particular programming language.
- election
-
In the event that the Raft leader becomes unresponsive, followers automatically trigger an election and vote for a new leader.
- entity
-
A node or a relationship.
- expression (Cypher)
-
A component of a Cypher query which produces values. It may be used in projections, as a predicate, or when setting properties on graph elements.
- fabric
-
Fabric is the architectural design of a unified system that provides a single access point to local or distributed graph data.
- fault tolerance
-
A guarantee that a cluster can maintain a database’s persistence and availability in the event of one or more servers failing.
- follower
-
A primary copy of a database acting as a follower, receives and acknowledges synchronous writes from the leader.
- Generative AI (GenAI)
-
A type of artificial intelligence (AI) system that generates text, images, or other media in response to prompts.
- graph
-
A logical representation of a set of nodes where some pairs are connected by relationships.
- index
-
Data structure that improves read performance of a database.
- knowledge graph
-
A specific type of graph that has an organizing principle so that a user (or a computer system) can reason about the underlying data. The organizing principle provides an additional layer of structure that adds context to support knowledge discovery.
- label
-
Marks a node as a member of a named and indexed subset. A node may be assigned zero or more labels.
- leader
-
A single primary copy of a database is designated as the leader. It receives all write transactions from clients and replicates writes synchronously to followers and asynchronously to secondary copies of the database.
- main database
-
In terms of Neo4j Enterprise Studio, the database(s) containing the user’s data. Can exist in the same Neo4j deployment as the tool asset database.
- motif
-
A description of a specific pattern within a graph.
- node
-
A node represents an entity or discrete object in your graph data model. Nodes can be connected by relationships, hold data in properties, and are classified by labels.
- operator
-
A symbol representing a mathematical or logical operation.
- parameter
-
Named value provided when running a Cypher statement.
- path
-
A sequence of nodes and the relationships connecting them, that does not contain duplicate relationships. Several paths can match a pattern.
- pattern
-
A specific arrangement of nodes and relationships that can be matched in a graph. A pattern follows a motif.
- perspective (Bloom)
-
A Perspective defines a certain business view or domain that can be found in the target Neo4j graph. A single Neo4j graph can be viewed through different Perspectives, each tailored for a different business purpose.
- primary
-
A copy of the database that is able to process write transactions and is eligible to be elected as a leader. It participates in fault tolerant writes as it is part of the majority required to acknowledge and commit write transactions.
- primary vs secondary
-
In a cluster, databases can operate in either primary or secondary mode. Primary databases are able to process write and read transactions, ensuring fault tolerance. Secondary databases are replicated asynchronously from primaries, and their main purpose is to provide read scaling within the cluster.
- project (Aura)
-
An isolated environment in the unified Aura console that contains its own database instances, configurations, and resources. Preceded by tenant in the classic Aura console.
- property
-
Properties are key-value pairs that are used for storing data on nodes and relationships.
- query (Cypher)
-
A statement that retrieves or writes information to a database.
- Raft group
-
A group of servers that are participating in hosting a particular database in primary mode.
- Raft group member
-
A server that is participating in a Raft group. A server can be a member of one or more groups.
- Raft log
-
A shared log between all Raft group members that is guaranteed to be consistently updated and viewed by those members. The log contains both database data and operational state of the Raft group.
- Raft protocol
-
The networking mechanism that enables a database to replicate its data across multiple servers to give high availability for accessing the data and high durability to the data stored.
- read scaling
-
Distributing query load by creating additional database copies hosted in secondary mode (read-only).
- relationship
-
A relationship represents a connection between nodes in your graph data model. Relationships connect a source node to a target node, hold data in properties, and are classified by type.
- secondary
-
An asynchronously replicated copy of the database that provides read scaling within the cluster.
- seed
-
A seed is a database dump or a full backup used to create a database on a cluster. This is sometimes called seeding.
- server
-
A physical machine, a virtual machine, or a container running an instance of Neo4j. Servers can be standalone or part of a cluster.
- session
-
A causally linked sequence of transactions.
- session consistency
-
An alternative name for Neo4j’s causal consistency.
- standalone
-
A single server running Neo4j and not part of a cluster.
- synchronous replication
-
Synchronous replication requires the leader primary to replicate a transaction and block the commit until a quorum of the follower primaries acknowledges that the transaction is successfully replicated. Once the transaction is replicated, the commit is allowed to proceed. This ensures data durability and consistency within the cluster.
- system database
-
A database used by Neo4j to store system information.
- tenant (Aura)
-
An isolated environment in the classic Aura console that contains its own database instances, configurations, and resources. Replaced by project in the unified Aura console.
- tool asset database
-
In terms of Neo4j Enterprise Studio, the database where tools' assets are stored. This can be in the same Neo4j deployment as the main database(s) or in a separate deployment.
- topology
-
A configuration that describes how the copies of a database should be spread across the servers in a cluster, see primary mode and secondary mode.
- transaction
-
A transaction comprises a unit of work performed against a database. It is treated in a coherent and reliable way, independent of other transactions. Transactions comply with the ACID consistency model (atomic, consistent, isolated, and durable).