DR restore drill — <YYYY-Qn>

Procedure: dr-restore-drill.md. Cadence: quarterly.

Observed RPO

Field Value
Backup picked <backup_id>
Backup created_at <iso>
Observed RPO (now − created_at) <HH:MM:SS>
Target ≤ 24h
Pass? <✅ / ❌>

Measured RTO

Wall-clock from POST /cp/backups/:id/restore-token to ledger-row match in the restored Postgres.

Phase Started Finished Duration Notes
A — manifest fetch
B — restore-token mint
C — cipher-byte download
D — decrypt (KMS / AES-GCM)
E — untar
F — Postgres + ledger sanity
Total RTO Target ≤ 60m

Pass? <✅ / ❌>

Crypto contract verification

Ledger sanity check

Field Live cluster Restored cluster Match?
Row id
customer_id
timestamp
cost_usd
tokens_in / tokens_out

Issues found

<bullets — process gaps, surprises, infra friction. Open incidents/Linear issues with the action items below.>

Action items

# Action Owner Due Tracker