diff --git a/lib/backup-stack.ts b/lib/backup-stack.ts index 2ac94f6..76f126f 100644 --- a/lib/backup-stack.ts +++ b/lib/backup-stack.ts @@ -150,10 +150,10 @@ export class BackupStack extends cdk.Stack { role: backupRole, // allowRestores omitted (defaults false) — backup-only, see role comment. resources: [ - // RDS - backup.BackupResource.fromArn( - `arn:aws:rds:us-east-1:${this.account}:db:database-1` - ), + // RDS. database-1 was retired 2026-06-03 (audit H-19: idle SQL Server + // Express, snapshot-and-delete) — its final recovery point lives in the + // offsite vault; removed from the selection so backup jobs don't fail on + // a missing resource. backup.BackupResource.fromArn( `arn:aws:rds:us-east-1:${this.account}:db:proposal-system-db` ), @@ -188,10 +188,10 @@ export class BackupStack extends cdk.Stack { // re-run are the backstop. Identifiers verified against the live account // 2026-06-03. // - // Excluded by intent: the 4 deprecated ledgerflow delete-targets - // (ledgerflow-edi-transactions/-sessions/-invoices/-settings) — being - // retired, not protected. database-1 is in the phase-1 selection above and - // must be removed there when it is deleted (audit H-19). + // Excluded by intent: the ledgerflow tables — the whole LedgerFlow stack + // was decommissioned 2026-06-03 (audit Day 4), so they no longer exist. + // database-1 was retired the same day and removed from the phase-1 selection + // above (audit H-19). plan.addSelection("Phase2Resources", { backupSelectionName: "phase2-offsite-everything", role: backupRole, @@ -207,7 +207,6 @@ export class BackupStack extends cdk.Stack { "front-sla-alerts", "internal-portal-data", "last-war-bot", - "ledgerflow-pos", "meal-order-manager-orders", "pending-site-review", "seahaven-conversations",