Skip to content

Backups and restore drills

The database is the source of truth; attachments live in MinIO/S3.

  • Backups: pg_dump of Postgres plus a matching object-volume archive, per the staging runbook’s backup section. An off-machine copy replicates the newest pair to a second destination with sha256 verification, rotation, and a monitored last-success marker — and honestly refuses to call a same-disk copy “off-machine”.
  • Restore drills: two levels. The quick drill restores the dump into a scratch container; the full drill additionally serves the restored objects from an isolated MinIO and verifies metadata↔object correspondence, file hashes, and that blocked scan states stay blocked. A backup that has never been restored is a rumor.
  • Retention: attachments follow an explicit policy (ATTACHMENT_RETENTION) — soft-deleted files purge after 30 days, upload orphans after 7, quarantined files lose their bytes after 90 while the detection stays on record. The purge command is dry-run by default and refuses vague targets.

Procedures: STAGING_RUNBOOK.