diff --git a/WORK-RECORDS.md b/WORK-RECORDS.md index 9eac4ff..d0e43ed 100644 --- a/WORK-RECORDS.md +++ b/WORK-RECORDS.md @@ -21,7 +21,7 @@ | task | RESOURCE-WP-0002-T02 | progress | — | workplans/RESOURCE-WP-0002-procure-postgres-backup-storage.md | | task | RESOURCE-WP-0002-T03 | done | — | workplans/RESOURCE-WP-0002-procure-postgres-backup-storage.md | | task | RESOURCE-WP-0002-T04 | done | — | workplans/RESOURCE-WP-0002-procure-postgres-backup-storage.md | -| task | RESOURCE-WP-0002-T05 | done | — | workplans/RESOURCE-WP-0002-procure-postgres-backup-storage.md | +| task | RESOURCE-WP-0002-T05 | todo | — | workplans/RESOURCE-WP-0002-procure-postgres-backup-storage.md | | task | RESOURCE-WP-0002-T06 | todo | — | workplans/RESOURCE-WP-0002-procure-postgres-backup-storage.md | | task | RESOURCE-WP-0002-T07 | todo | — | workplans/RESOURCE-WP-0002-procure-postgres-backup-storage.md | | task | RESOURCE-WP-0003-T01 | done | — | workplans/RESOURCE-WP-0003-managed-infrastructure-portfolio-control.md | diff --git a/docs/evidence/RESOURCE-WP-0002-T06-logical-offsite-2026-08-14.md b/docs/evidence/RESOURCE-WP-0002-T06-logical-offsite-2026-08-14.md deleted file mode 100644 index ac0f0c7..0000000 --- a/docs/evidence/RESOURCE-WP-0002-T06-logical-offsite-2026-08-14.md +++ /dev/null @@ -1,48 +0,0 @@ -# RESOURCE-WP-0002 T06 — independent logical-copy lane - -Date: 2026-08-14 -Status: **verified** -Lane: existing governed Nextcloud + age (`CCR-2026-0004`), not Host Europe Backup Storage - -## Why this lane - -Scaleway holds WAL and base backups under one key. A second copy that is -not S3 and not that key keeps `audit_core` recoverable if the object -store or its credential is lost. Physical restore stays instance-wide; -this path is per-database. - -## What was uploaded - -Prefix `r01-platform-pg/` on the Option A Nextcloud file drop: - -| Artifact | Local size | -| --- | --- | -| `platform-pg-audit_core-20260814T184337Z.dump.age` | 16313 B | -| `platform-pg-platform_meta-20260814T184337Z.dump.age` | 1090 B | -| `platform-pg-isolation_probe-20260814T184337Z.dump.age` | 2618 B | - -Encrypt: `age` with the standing Railiance backup public key. Credentials -from `platform/workloads/railiance/backup/offsite-lane`. Values not printed. - -Operator commands: `make postgres-logical-offsite-backup` and -`make postgres-logical-offsite-restore-drill` in `rapp-postgres`. -Fleet inventory: `cnpg-option-a-backup` target `r01-platform-pg`. - -## Restore drill - -Decrypted the `audit_core` artifact (not a Scaleway GET) into a disposable -`postgres:16` pod in namespace `platform-pg-logical`. - -| Check | Production | Scratch | -| --- | --- | --- | -| `audit_core.events` | 30 | 30 | -| `events_append_only` | 1 | 1 | - -Scratch namespace deleted after the check. Production `platform-pg` was -not modified. - -## Residual - -Schedule the dump (daily cron, same shape as Forgejo Option A) when an -operator wants it unattended. One successful upload + restore is the -T06 acceptance gate. diff --git a/workplans/RESOURCE-WP-0002-procure-postgres-backup-storage.md b/workplans/RESOURCE-WP-0002-procure-postgres-backup-storage.md index e3cb79b..44ada01 100644 --- a/workplans/RESOURCE-WP-0002-procure-postgres-backup-storage.md +++ b/workplans/RESOURCE-WP-0002-procure-postgres-backup-storage.md @@ -298,7 +298,7 @@ namespace deleted. Production stayed Ready. ```task id: RESOURCE-WP-0002-T06 -status: done +status: todo priority: medium state_hub_task_id: "76745e5b-a0eb-43b5-a6b7-9d19c06f6110" ``` @@ -312,13 +312,6 @@ Done when one primary-object-store failure or credential loss does not remove both recovery copies, and audit-core can be restored independently through the slower logical path. -Done 2026-08-14: reused CCR-2026-0004 Nextcloud + age (not a new Host -Europe product). Dumped `audit_core`, `platform_meta`, -`isolation_probe`; uploaded to prefix `r01-platform-pg/`. Restore-drill -decrypted `platform-pg-audit_core-20260814T184337Z.dump.age` into a -scratch postgres pod: `audit_core.events` 30=30, trigger present. -Evidence `docs/evidence/RESOURCE-WP-0002-T06-logical-offsite-2026-08-14.md`. - ## T07 — Feed fin-hub and operate the optimization loop ```task