[{"data":1,"prerenderedAt":375},["ShallowReactive",2],{"navigation":3,"\u002Foperations\u002Fbackup-restore":250,"\u002Foperations\u002Fbackup-restore-surround":370},[4,28,56,91,117,135,169,224],{"title":5,"path":6,"stem":7,"children":8,"icon":27},"Start here","\u002Fgetting-started","1.getting-started\u002F1.index",[9,11,15,19,23],{"title":10,"path":6,"stem":7},"Introduction",{"title":12,"path":13,"stem":14},"Decisions and open gates","\u002Fgetting-started\u002Fdecisions","1.getting-started\u002F2.decisions",{"title":16,"path":17,"stem":18},"Scope and non-goals","\u002Fgetting-started\u002Fscope","1.getting-started\u002F3.scope",{"title":20,"path":21,"stem":22},"Organization pilot","\u002Fgetting-started\u002Fpilot","1.getting-started\u002F4.pilot",{"title":24,"path":25,"stem":26},"Economics and quotas","\u002Fgetting-started\u002Feconomics","1.getting-started\u002F5.economics","i-lucide-compass",{"title":29,"path":30,"stem":31,"children":32,"icon":55},"Architecture","\u002Farchitecture","2.architecture\u002F1.index",[33,35,39,43,47,51],{"title":34,"path":30,"stem":31},"System architecture",{"title":36,"path":37,"stem":38},"Trust zones","\u002Farchitecture\u002Ftrust-zones","2.architecture\u002F2.trust-zones",{"title":40,"path":41,"stem":42},"Control plane","\u002Farchitecture\u002Fcontrol-plane","2.architecture\u002F3.control-plane",{"title":44,"path":45,"stem":46},"Organization tenancy","\u002Farchitecture\u002Ftenancy","2.architecture\u002F4.tenancy",{"title":48,"path":49,"stem":50},"Core data model","\u002Farchitecture\u002Fdata-model","2.architecture\u002F5.data-model",{"title":52,"path":53,"stem":54},"Codebase organization","\u002Farchitecture\u002Fcodebase","2.architecture\u002F6.codebase","i-lucide-layers",{"title":57,"icon":58,"path":59,"stem":60,"children":61,"page":90},"Identity and security","i-lucide-shield-check","\u002Fsecurity","3.security",[62,66,70,74,78,82,86],{"title":63,"path":64,"stem":65},"Identity and sessions","\u002Fsecurity\u002Fidentity","3.security\u002F1.identity",{"title":67,"path":68,"stem":69},"Domains and TLS","\u002Fsecurity\u002Fdomains","3.security\u002F2.domains",{"title":71,"path":72,"stem":73},"Ingress and egress","\u002Fsecurity\u002Fnetworking","3.security\u002F3.networking",{"title":75,"path":76,"stem":77},"Access policies and WAF-lite","\u002Fsecurity\u002Faccess-policies","3.security\u002F4.access-policies",{"title":79,"path":80,"stem":81},"Secrets and integrations","\u002Fsecurity\u002Fsecrets-integrations","3.security\u002F5.secrets-integrations",{"title":83,"path":84,"stem":85},"Governance and ownership","\u002Fsecurity\u002Fgovernance","3.security\u002F6.governance",{"title":87,"path":88,"stem":89},"Threat model","\u002Fsecurity\u002Fthreat-model","3.security\u002F7.threat-model",false,{"title":92,"icon":93,"path":94,"stem":95,"children":96,"page":90},"Building applications","i-lucide-code","\u002Fdevelopment","4.development",[97,101,105,109,113],{"title":98,"path":99,"stem":100},"AI and MCP","\u002Fdevelopment\u002Fai-mcp","4.development\u002F1.ai-mcp",{"title":102,"path":103,"stem":104},"Source control","\u002Fdevelopment\u002Fsource-control","4.development\u002F2.source-control",{"title":106,"path":107,"stem":108},"Sandboxed builds","\u002Fdevelopment\u002Fbuilds","4.development\u002F3.builds",{"title":110,"path":111,"stem":112},"Runtime contract and SDK","\u002Fdevelopment\u002Fruntime-contract","4.development\u002F4.runtime-contract",{"title":114,"path":115,"stem":116},"APIs and protocols","\u002Fdevelopment\u002Fapi","4.development\u002F5.api",{"title":118,"icon":119,"path":120,"stem":121,"children":122,"page":90},"Runtime and delivery","i-lucide-rocket","\u002Fdelivery","5.delivery",[123,127,131],{"title":124,"path":125,"stem":126},"Runtime clusters and previews","\u002Fdelivery\u002Fruntime-clusters","5.delivery\u002F1.runtime-clusters",{"title":128,"path":129,"stem":130},"Deployments and approvals","\u002Fdelivery\u002Fdeployments","5.delivery\u002F2.deployments",{"title":132,"path":133,"stem":134},"Databases and recovery","\u002Fdelivery\u002Fdata-recovery","5.delivery\u002F3.data-recovery",{"title":136,"icon":137,"path":138,"stem":139,"children":140,"page":90},"Operations","i-lucide-activity","\u002Foperations","6.operations",[141,145,149,153,157,161,165],{"title":142,"path":143,"stem":144},"Observability and audit","\u002Foperations\u002Fobservability","6.operations\u002F1.observability",{"title":146,"path":147,"stem":148},"Operating model","\u002Foperations\u002Foperating-model","6.operations\u002F2.operating-model",{"title":150,"path":151,"stem":152},"Deploy and roll back","\u002Foperations\u002Fdeploy-rollback","6.operations\u002F3.deploy-rollback",{"title":154,"path":155,"stem":156},"Back up and restore","\u002Foperations\u002Fbackup-restore","6.operations\u002F4.backup-restore",{"title":158,"path":159,"stem":160},"Upgrade and patch","\u002Foperations\u002Fupgrades","6.operations\u002F5.upgrades",{"title":162,"path":163,"stem":164},"Rotate keys and credentials","\u002Foperations\u002Fkey-rotation","6.operations\u002F6.key-rotation",{"title":166,"path":167,"stem":168},"Incidents and access revocation","\u002Foperations\u002Fincidents","6.operations\u002F7.incidents",{"title":170,"path":171,"stem":172,"children":173,"icon":223},"Implementation plan","\u002Froadmap","7.roadmap\u002F01.index",[174,175,179,183,187,191,195,199,203,207,211,215,219],{"title":170,"path":171,"stem":172},{"title":176,"path":177,"stem":178},"Phase 0: architecture spikes and ADRs","\u002Froadmap\u002Fphase-0","7.roadmap\u002F02.phase-0",{"title":180,"path":181,"stem":182},"Phase 1: control-plane foundation","\u002Froadmap\u002Fphase-1","7.roadmap\u002F03.phase-1",{"title":184,"path":185,"stem":186},"Phase 2: managed source and change sets","\u002Froadmap\u002Fphase-2","7.roadmap\u002F04.phase-2",{"title":188,"path":189,"stem":190},"Phase 3: sandboxed build system","\u002Froadmap\u002Fphase-3","7.roadmap\u002F05.phase-3",{"title":192,"path":193,"stem":194},"Phase 4: runtime and data plane","\u002Froadmap\u002Fphase-4","7.roadmap\u002F06.phase-4",{"title":196,"path":197,"stem":198},"Phase 5: deployment, preview, migration, and recovery","\u002Froadmap\u002Fphase-5","7.roadmap\u002F07.phase-5",{"title":200,"path":201,"stem":202},"Phase 6: Entra identity and security policy","\u002Froadmap\u002Fphase-6","7.roadmap\u002F08.phase-6",{"title":204,"path":205,"stem":206},"Phase 7: MCP and AI-native workflow","\u002Froadmap\u002Fphase-7","7.roadmap\u002F09.phase-7",{"title":208,"path":209,"stem":210},"Phase 8: Pilot hardening","\u002Froadmap\u002Fphase-8","7.roadmap\u002F10.phase-8",{"title":212,"path":213,"stem":214},"Phase 9: developer hybrid and v1 GA","\u002Froadmap\u002Fphase-9","7.roadmap\u002F11.phase-9",{"title":216,"path":217,"stem":218},"Test strategy","\u002Froadmap\u002Ftesting","7.roadmap\u002F12.testing",{"title":220,"path":221,"stem":222},"Definition of done","\u002Froadmap\u002Fdefinition-of-done","7.roadmap\u002F13.definition-of-done","i-lucide-list-checks",{"title":225,"icon":226,"path":227,"stem":228,"children":229,"page":90},"Reference","i-lucide-book-open","\u002Freference","8.reference",[230,234,238,242,246],{"title":231,"path":232,"stem":233},"Plan coverage","\u002Freference\u002Fplan-coverage","8.reference\u002F1.plan-coverage",{"title":235,"path":236,"stem":237},"Decision register","\u002Freference\u002Fdecisions","8.reference\u002F2.decisions",{"title":239,"path":240,"stem":241},"Glossary","\u002Freference\u002Fglossary","8.reference\u002F3.glossary",{"title":243,"path":244,"stem":245},"Sources","\u002Freference\u002Fsources","8.reference\u002F4.sources",{"title":247,"path":248,"stem":249},"Contributing and docs access","\u002Freference\u002Fcontributing","8.reference\u002F5.contributing",{"id":251,"title":154,"body":252,"description":363,"extension":364,"links":365,"meta":366,"navigation":367,"path":155,"seo":368,"stem":156,"__hash__":369},"docs\u002F6.operations\u002F4.backup-restore.md",{"type":253,"value":254,"toc":353},"minimark",[255,266,271,280,283,287,306,310,336,340,343,347,350],[256,257,258],"warning",{},[259,260,261,265],"p",{},[262,263,264],"strong",{},"Procedure specification — not yet operationally validated."," Before pilot use, the operations owner must attach exact console\u002FAPI\u002FCLI actions, environment identifiers, access requirements, escalation contacts, and rehearsal evidence. No platform command names or completed drills are implied here.",[267,268,270],"h2",{"id":269},"backup-inventory","Backup inventory",[259,272,273,274,279],{},"Track control-plane PostgreSQL, Forgejo metadata and repositories, signed artifacts, app databases, routing\u002Fpolicy metadata, and recoverable secrets\u002FKMS material. Document the weaker ",[275,276,278],"a",{"href":277},"\u002Fdelivery\u002Fdata-recovery#kv","KV recovery contract"," separately. Store recovery material outside the primary runtime volume with controlled access and encryption.",[259,281,282],{},"App backup proposals are frequent online recovery points targeting a 15-minute RPO, daily copies retained 30 days, monthly copies retained 12 months, and pre-migration snapshots retained at least 30 days. These are pilot defaults pending contract and drill validation.",[267,284,286],{"id":285},"routine-backup-verification","Routine backup verification",[288,289,290,294,297,300,303],"ol",{},[291,292,293],"li",{},"Inventory every production app\u002Fenvironment and confirm a scheduled backup policy exists.",[291,295,296],{},"Check last successful recovery point, copy destination, encryption\u002Fkey version, integrity result, and retention state.",[291,298,299],{},"Alert on failed backups, stale recovery points, missing keys, or retention violations. Assign an operator and affected app owner.",[291,301,302],{},"Restore samples into isolated validation environments; a successful upload alone is not evidence of recoverability.",[291,304,305],{},"Record backup and restore metrics without logging application rows, credentials, or sensitive export URLs.",[267,307,309],{"id":308},"app-database-restore","App database restore",[288,311,312,315,318,321,324,327,330,333],{},[291,313,314],{},"Identify the incident, app\u002Fenvironment, selected recovery point, current schema, and compatible artifact. Describe potential lost writes since that point.",[291,316,317],{},"Obtain the authorized human recovery decision; record it separately from artifact rollback approval.",[291,319,320],{},"Restore into a new DB instance. Verify tenant scope, decryption, integrity, migration checksums, and schema compatibility.",[291,322,323],{},"Attach the new instance to an isolated validation environment. Restrict access and integrations; validate approved workflow checks.",[291,325,326],{},"Review results and authorize cutover. Quiesce writes where required and record the final recovery boundary.",[291,328,329],{},"Atomically switch the DB binding to the validated instance and run production health checks.",[291,331,332],{},"Retain the prior DB under the approved recovery window. Record both instance IDs, approver, timestamps, and validation evidence.",[291,334,335],{},"If validation fails before cutover, leave the live binding intact. If writes occurred after cutover, do not switch back blindly; reconcile the competing write histories under incident control.",[267,337,339],{"id":338},"platform-reconstruction","Platform reconstruction",[259,341,342],{},"Restore authoritative PostgreSQL and Forgejo from a compatible recovery set. Reestablish KMS\u002Fsecrets access and cluster identity. Reconcile a replacement runtime from desired state, signed artifacts, route\u002Fpolicy metadata, and app DB recovery points. Check cluster assignment and tenant boundaries before opening traffic. KV caches may need regeneration under their documented policy.",[267,344,346],{"id":345},"export-and-drills","Export and drills",[259,348,349],{},"Verify full Git-history export plus SQLite\u002FSQL\u002FCSV exports, migrations, and schema manifests can be restored independently. Scope and audit each export; record expiry and access control without storing secret-bearing URLs in evidence.",[259,351,352],{},"Measure achieved data-loss interval and recovery duration against the pilot targets of RPO ≤15 minutes and RTO ≤4 hours. Record failures and rerun after fixes. These targets are not contractual SLAs until validated and agreed.",{"title":354,"searchDepth":355,"depth":356,"links":357},"",1,2,[358,359,360,361,362],{"id":269,"depth":356,"text":270},{"id":285,"depth":356,"text":286},{"id":308,"depth":356,"text":309},{"id":338,"depth":356,"text":339},{"id":345,"depth":356,"text":346},"Backup checks, isolated database restores, export, and reconstruction of runtime infrastructure.","md",null,{},true,{"title":154,"description":363},"60_uLL2Xe8Z8hcK8fM1Hd5qGDifIDg7DaZLD3Dwv9HQ",[371,373],{"title":150,"path":151,"stem":152,"description":372,"children":-1},"Operator procedure for approved immutable deployments and schema-aware artifact rollback.",{"title":158,"path":159,"stem":160,"description":374,"children":-1},"Canary validation, controlled runtime updates, compatibility checks, and rollback planning.",1790019415368]