Verify Scaleway primary recovery and distinguish secondary backup coverage
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
codex 2026-09-06 00:34:43 +02:00
parent 9269d9d8f4
commit d05c3000c5
10 changed files with 170 additions and 7 deletions

View file

@ -131,3 +131,20 @@ and a create-only workload share. Encrypted fixture recovery and consumer
refresh are verified; full application restore and predecessor invalidation
remain RPF-WP-0029-T02. See the
[latest blocked-workplan review](history/2026-09-05-blocked-workplan-closure-review.md).
## Backup authority correction — 2026-09-06
Scaleway Standard Multi-AZ (`nl-ams`) is the primary backup destination under
RESOURCE-WP-0002. Nextcloud is the independent secondary-copy lane. The live
Scaleway paths cover apps-pg, platform-pg and platform-pg-2. An isolated apps-pg
restore from that primary succeeded in 42.64 seconds; production remained ready
and scratch resources were removed. See
[primary recovery evidence](docs/evidence/scaleway-primary-restore-2026-09-06.json).
Coverage is per asset: live forgejo-db, net-kingdom-pg and state-hub-db have no
native Barman destination. The Forgejo full-archive helper still targets
Nextcloud; no Forgejo blob/archive destination on Scaleway was evidenced.
The account cutover and archive-integrity fix do not establish that coverage.
WP-0029 retains secondary credential invalidation/recovery; its completion
must not be presented as full primary-backup assurance.