Remove retired database-1 + ledgerflow-pos from backup selections (audit Day 4) (#9)
Some checks are pending
Deploy / deploy (push) Waiting to run

database-1 (audit H-19) and the LedgerFlow stack (incl. ledgerflow-pos) were
decommissioned 2026-06-03. Drop database-1 from the critical-data selection and
ledgerflow-pos from phase2-offsite-everything so daily jobs don't target missing
resources. database-1's final recovery point is retained encrypted in the
seahaven-offsite vault (7yr); ledgerflow-pos has a final on-demand DynamoDB
backup. Deployed before merge (seahaven-backup UPDATE_COMPLETE).
This commit is contained in:
Adam Moussa 2026-06-03 11:45:37 -04:00 • committed by GitHub
parent f2a0cc40d6
commit 1d6668090c
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -150,10 +150,10 @@ export class BackupStack extends cdk.Stack {
role: backupRole,
// allowRestores omitted (defaults false) — backup-only, see role comment.
resources: [
// RDS
backup.BackupResource.fromArn(
`arn:aws:rds:us-east-1:${this.account}:db:database-1`
),
// RDS. database-1 was retired 2026-06-03 (audit H-19: idle SQL Server
// Express, snapshot-and-delete) — its final recovery point lives in the
// offsite vault; removed from the selection so backup jobs don't fail on
// a missing resource.
backup.BackupResource.fromArn(
`arn:aws:rds:us-east-1:${this.account}:db:proposal-system-db`
),
@ -188,10 +188,10 @@ export class BackupStack extends cdk.Stack {
// re-run are the backstop. Identifiers verified against the live account
// 2026-06-03.
//
// Excluded by intent: the 4 deprecated ledgerflow delete-targets
// (ledgerflow-edi-transactions/-sessions/-invoices/-settings) — being
// retired, not protected. database-1 is in the phase-1 selection above and
// must be removed there when it is deleted (audit H-19).
// Excluded by intent: the ledgerflow tables — the whole LedgerFlow stack
// was decommissioned 2026-06-03 (audit Day 4), so they no longer exist.
// database-1 was retired the same day and removed from the phase-1 selection
// above (audit H-19).
plan.addSelection("Phase2Resources", {
backupSelectionName: "phase2-offsite-everything",
role: backupRole,
@ -207,7 +207,6 @@ export class BackupStack extends cdk.Stack {
"front-sla-alerts",
"internal-portal-data",
"last-war-bot",
"ledgerflow-pos",
"meal-order-manager-orders",
"pending-site-review",
"seahaven-conversations",