Backups and restore drills
The database is the source of truth; attachments live in MinIO/S3.
- Backups:
pg_dumpof Postgres plus a matching object-volume archive, per the staging runbook’s backup section. An off-machine copy replicates the newest pair to a second destination with sha256 verification, rotation, and a monitored last-success marker — and honestly refuses to call a same-disk copy “off-machine”. - Restore drills: two levels. The quick drill restores the dump into a scratch container; the full drill additionally serves the restored objects from an isolated MinIO and verifies metadata↔object correspondence, file hashes, and that blocked scan states stay blocked. A backup that has never been restored is a rumor.
- Retention: attachments follow an explicit policy (ATTACHMENT_RETENTION) — soft-deleted files purge after 30 days, upload orphans after 7, quarantined files lose their bytes after 90 while the detection stays on record. The purge command is dry-run by default and refuses vague targets.
Procedures: STAGING_RUNBOOK.