Reconcile with same-day Forgejo backup assessment

Risk analysis R2 updated (one restore now evidenced), workplan cross-referenced
with the assessment's pickup queue; new T08 tracks cross-repo backup items.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-07-04 12:46:22 +02:00
parent 2f6f489289
commit ddea827192
2 changed files with 35 additions and 7 deletions

View file

@ -5,6 +5,8 @@ Author: claude-code (session with Bernd)
Status: baseline — to be revisited after AssetRegister and first restore drill
Source: `specs/ResilienceControlSetup.md`, `INTENT.md`, current Coulomb/Helix stack
(Gitea, k3s, CoulombCore, Bubble.io, Stripe, OpenRouter, DNS, secrets, Ansible)
Companion: `2026-07-04-forgejo-backup-strategy-assessment.md` — same-day
Forgejo/Railiance deep-dive with a concrete pickup queue for this repo
## Purpose
@ -33,8 +35,11 @@ recovery asset, offsite encrypted backups, DNS cutover procedure, quarterly rebu
The classic silent failure: dumps run for months, first real restore reveals
corruption, missing volumes, undumped databases, or an unknown passphrase.
**L4 / I5** (it converts every other risk into a total loss). Exposure today:
critical — no restore has ever been evidenced.
**Mitigation:** the TestEvidence loop itself — monthly restore drills with dated
high — exactly one restore has been evidenced: the 2026-07-04 Forgejo isolated
restore drill (RAIL-HO-WP-0005-T09, evidence in `railiance-infra`). Gitea (the
canonical source forge today), CoulombCore content, databases, Bubble exports,
and the secret vault have never been restore-tested.
**Mitigation:** the TestEvidence loop itself — recurring restore drills with dated
reports measuring actual RTO/RPO. This is the highest-leverage artifact in the repo.
### R3 — Ransomware / hostile access deletes backups too