Backup and Restore Service  ·  View 20 of 26  ·  6 · Operations

CI/CD — No Capture Against an Uncertified Version Pair

How a new engine or tool version is proven restorable before any production copy depends on it.

Editable source SVG draw.io All views
Detect Version watcher Renovate Engine versions seen from discovery Build Merge request GitLab CE Sign image cosign → Harbor Certify Restore matrix engine × tool Depth 3 passes? Publish Certified pairs signed file in Git Release Argo CD sync Canary on Tier 3 then 2, then 1 CI/CD — No Capture Against an Uncertified Version Pair Security / platform Application we own Decision point Data store synchronous An engine upgraded ahead of certification blocks its own captures and pages the owner the same hour. v 1.0 · owner Backup Platform · date 2026-09

Decisions

  • The certification matrix restores real data at depth 3 for every engine version seen in the estate against every tool version in use. A pair that passes is added to a signed file in Git. Adapters read that file and refuse any pair not in it.
  • Engine versions come from discovery, not from what teams say they run. The versions that cause trouble are the ones nobody planned.
  • Adapter releases go to Tier 3 first, then Tier 2, then Tier 1, each after a clean rehearsal cycle. A capture tool is the one component where a subtle bug does no visible harm until it is needed.

Numbers

  • A matrix run covers about 40 pairs and takes 3 to 4 hours on the rehearsal cluster, overnight. A new PostgreSQL minor version is certified the day after it is first seen.

Risks

  • An owner who upgrades before certification finishes has blocked captures for up to a day, and gets paged. That is the design working: an hour of RPO-at-risk that everyone can see is better than months of copies that cannot be restored.