Backup and Restore Service · View 13 of 26 · 4 · Data
Decisions
- Retention depth is set by the corruption detection window. With an assumed 30 days to notice logical corruption, Tier 1 keeps 35 days of PITR and 12 monthly copies, not 7 days of snapshots.
- A restore extends the lock on the artefacts it reads by 7 days before reading. Extending retention needs no approval because it can only make data safer, and it closes the race of a copy expiring mid-restore.
- Tier 3 copies are written to the custody cluster in the opposite data centre from their source, so losing a site never takes a bucket and its only copy together.
Numbers
- Custody A holds about 5 PB usable at the retention horizon. That assumes the 3% daily change is all new bytes, which is the pessimistic case. Custody B is sized at about 4 PB.
- Deleted-resource firebreak: 90 days regardless of tier, because the deletion may be the incident.
Risks
- Lawful erasure and immutable tape conflict. The regulatory set uses a data key per datastore per month, so erasure is done by destroying the key. The certificate states the date the last key-ledger backup that held that key expires.