Backup and Restore Service · View 05 of 26 · 2 · People and journeys
The trough, and what answers it
- Finding the clean point is where this goes wrong. Guessing wastes a four-hour restore per guess. Clean-point search restores eight points at once and narrows down in about seven rounds (view 16).
- Cutover is the second worst moment, because an in-place restore can destroy the only copy of today's good writes. Side by side is the default, and in-place needs a second approver and a snapshot taken first (view 17).
Decisions
- The recovery restores side by side and copies back only the damaged rows. Rolling a whole database back three weeks is almost never what the business wants.
- Hourly block-incremental base copies for Tier 1 keep WAL replay under an hour. Replay, not transfer, is usually what breaks an RTO, and it never appears on a storage vendor's throughput sheet.
Stated limits
- The 60-minute RTO holds for recovery points in the last 7 days, where hourly bases are kept. From day 8 to day 35, only daily bases remain and the stated RTO is 3 hours. Older points have no PITR, only weekly and monthly copies.
- Reconciling rows the application wrote after the corruption belongs to the service team. The platform provides the clean copy and a table-level diff, not business rules.