M9-10 Backup, Disaster Recovery & Failover Validation¶
Milestone: M9 — Hardening and Compliance SOW Reference: NFR1 Requirement Clarity: 🟡 The original v3 doc specified 30-day backup retention and geographically-distributed backups; the SOW dropped both specifics, leaving only "automated daily backups" and "full system restoration within 24 hours" — confirm whether the stricter original terms still apply Dev Status: ❌ Not started — no backup automation, multi-AZ, or DR configuration exists anywhere in the repo
Overview¶
Demonstrate the platform meets its availability/recoverability targets: 99.9% uptime, automatic failover within 5 minutes, automated daily backups, full restoration within 24 hours.
Backend Tasks¶
- Confirm backup retention period and geographic distribution requirement with Curo
- Set up automated daily backups (RDS snapshots or equivalent, depending on the AWS hosting decision at M4-01)
- Set up active-active/multi-AZ configuration for automatic failover
- Run and document a full restore-from-backup test
Frontend Tasks¶
- N/A
Dependencies¶
- M4-01 AWS hosting decision — backup/DR approach is entirely dependent on the chosen AWS services.
Acceptance Criteria¶
- Demonstrated failover within 5 minutes
- Active-active configuration validated
- Recovery process documented
- Automated daily backups demonstrated
- Successful restore from backup demonstrated
- Recovery completed within DR target (per SOW Appendix 3, Availability Testing / Backup & Recovery)
Existing Reference Material¶
None — this is genuinely new infrastructure work.
Blockers & Risks¶
- Needs decision: backup retention/geo-distribution scope (see Requirement Clarity above).
- Same AWS-decision dependency as other M9 infra tasks.