railiance-platform/history/2026-09-06-primary-backup-correction.md
codex d05c3000c5
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Verify Scaleway primary recovery and distinguish secondary backup coverage
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
2026-09-06 00:34:43 +02:00

34 lines
1.9 KiB
Markdown

# Primary backup correction and verified Scaleway recovery
The operator reaffirmed that primary backup moved to Scaleway. Corrected the
platform scope, Forgejo/credential runbooks and service records: Nextcloud is an
independent secondary, not the primary proof for the platform.
Live inspection found Scaleway Barman configuration on apps-pg, platform-pg and
platform-pg-2, with successful September 5 backups. forgejo-db, net-kingdom-pg and
state-hub-db have no native destination. The current Forgejo full archive helper
still uploads only to Nextcloud. Prior account migration did not cover that gap.
Executed the bounded apps-pg restore from Scaleway into a separate namespace.
Ready in 42.64 seconds, expected consumer databases present, 13 public tables in
coulomb_social_db, and both connection limits remained 20. Production stayed
Ready. The scratch namespace and its namespaced resources were removed.
No credential value or application rows were printed or recorded. The exact
existing S3 fields were copied only within the protected apply stream.
Evidence: `docs/evidence/scaleway-primary-restore-2026-09-06.json`.
Implementation: `scripts/verify_scaleway_primary_restore.py`.
The date is the operator's Europe/Berlin date; evidence retains exact UTC times.
Prepared exact Forgejo primary extension requirements in
`docs/backup-provider-coverage.md`. It needs an independent archive destination,
reviewed runtime delivery and full artifact recovery, not just a provider-name
change. Existing database restore success does not close the Forgejo or
Nextcloud-secondary acceptance gates in WP-0029.
A fresh attended login for the validated Nextcloud secondary archive failed
before command handoff; revocation could not be confirmed. No new secondary
transfer ran. The encrypted staging from September 5 remains available and no
old-share revocation is asserted. A fresh attended login and old-share owner
confirmation/custody remain necessary. All 200 repository tests passed.