forked from EduCraft/curriculum-project-hub
49 lines
2.6 KiB
Markdown
49 lines
2.6 KiB
Markdown
# Audit backup, migration, and disaster recovery safety
|
|
|
|
Type: research
|
|
Status: resolved
|
|
|
|
## Question
|
|
|
|
What backup, restore, workspace/database consistency, migration compatibility,
|
|
and disaster-recovery guarantees are needed to deploy current persistent data
|
|
safely, and what evidence or tooling is missing to prove them?
|
|
|
|
## Answer
|
|
|
|
The Hub has no production backup/restore control plane. PostgreSQL can be
|
|
logically dumped and restored, but authoritative state is split across the
|
|
database, mutable Project workspaces, credentials/key material, and a
|
|
schema-compatible release with no shared checkpoint or recovery manifest.
|
|
RPO/RTO, retention, off-host/immutable storage, encryption/key custody,
|
|
full-service versus Organization-selective restore, monitoring, and recovery
|
|
drills are all undefined.
|
|
|
|
Executed probes proved that the current deploy `rsync --delete` removes the
|
|
documented in-tree workspace root, a failed Project transaction leaves an
|
|
orphan workspace, and an older application query fails after a destructive
|
|
migration. A deliberately failed Prisma migration rolled back that probe's DDL
|
|
but left a blocking failed migration record; the official contract does not
|
|
make PostgreSQL migrations transactional by default. A positive custom-format
|
|
round trip restored 24 tables and all nine current migration records, proving
|
|
only database-level portability on the local PostgreSQL 14.20 setup.
|
|
|
|
The complete state map, probe commands/results, root causes, required recovery
|
|
contract, and release evidence are in the
|
|
[backup, migration, and disaster-recovery audit](../assets/backup-migration-disaster-recovery-audit.md).
|
|
Official PostgreSQL, Prisma, systemd, and rsync semantics with claim-level links
|
|
are in [backup and migration primary sources](../assets/backup-migration-primary-sources.md).
|
|
|
|
The newly-clear decision and implementation frontier is:
|
|
|
|
- [Decide recovery objectives, backup retention, and restore scope](39-decide-recovery-objectives.md)
|
|
- [Implement coherent backup sets and verified restore](40-verified-backup-restore.md)
|
|
- [Make the Project workspace lifecycle recoverable](41-recoverable-project-workspace-lifecycle.md)
|
|
- [Establish migration compatibility and failed-migration recovery](14-migration-compatibility-and-recovery.md)
|
|
|
|
Persistent-path provisioning and release-tree isolation remain owned by
|
|
[Provision a runnable non-root Hub service](10-provision-nonroot-service.md)
|
|
and [Make application releases atomic and rollbackable](12-atomic-releases-and-rollback.md).
|
|
Full recovery/cutover procedures and drill evidence remain owned by
|
|
[Write and drill production incident recovery runbooks](31-write-and-drill-incident-runbooks.md).
|