Backup and Restore Service · View 23 of 26 · 6 · Operations
Decisions
- The MVP ships the rehearsal loop with the first engine, not after the last. A platform that captures six engines and proves none is the problem this project exists to fix.
- PostgreSQL and Kubernetes volumes come first because they are 44 of the 120 datastores and 5 of the 6 Tier 1 stores.
- The tape custodian is Phase 3 in the requirement, but tape hardware has the longest lead time. The library is ordered in the MVP so that Phase 3 is configuration work, not procurement.
Exit criteria
- MVP: 30 consecutive days with every Tier 1 datastore proven daily, one timed manual restore with the control plane switched off, and one catalogue rebuild from a scan, diffed clean.
- Phase 2: every datastore enrolled, zero unprotected resources older than 72 hours, first quarterly gameday published.
Risks
- Until Phase 2, MySQL, TiDB and ClickHouse keep their existing backups. The report marks them 'legacy, unproven' rather than leaving them off, so the gap stays visible.