chore(backup): drop the missing file-share volume from phase 2 (PLAT-77) (#167)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run

* chore(backup): drop retired file-share volumes from phase 2 (PLAT-77)

The 20 GiB volume is already gone and the 500 GiB volume is only a rollback hold, so the backup selection should not include either one.

* fix(backup): keep the file-share rollback volume in phase 2 (PLAT-77)

The 500 GiB disk is the rollback hold until 2026-10-06, so it stays in the offsite selection. Only the missing 20 GiB volume comes out.
This commit is contained in:
Adam Moussa 2026-09-29 23:51:26 +00:00 • committed by GitHub
parent 7e706aef2f
commit 78e4bcf128
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -253,13 +253,15 @@ export class BackupStack extends cdk.Stack {
// the locked offsite vault ("offsite for everything"). Same role and rule
// as phase-1; a separate selection keeps the phase-1 critical set readable.
//
// Still EXPLICIT-ARN (not tag-based) on purpose: the file-share volumes are
// standalone CDK-managed (RETAIN) and the DynamoDB tables are owned by other
// stacks, so tagging them here would drift those stacks — the same reason
// phase-1 avoided tags. Tradeoff: if a volume is replaced (new vol-id) it
// silently drops from this selection; scheduled drift detection + the audit
// re-run are the backstop. Identifiers verified against the live account
// 2026-06-03.
// Still EXPLICIT-ARN (not tag-based) on purpose: the DynamoDB tables are
// owned by other stacks, so tagging them here would drift those stacks.
// vol-054cf918f227d88f6 (file-share, 20 GiB) no longer exists and is out of
// this selection. vol-04d951cccacc435b5 stays through the PLAT-77 rollback
// hold (RetainUntil 2026-10-06) so that disk keeps its offsite copy. Remove
// it when the hold ends. Tradeoff: if a volume is replaced (new vol-id) it
// silently drops from this selection; scheduled drift detection and the
// audit re-run are the backstop. Identifiers verified against the live
// account 2026-06-03.
//
// Excluded by intent: the ledgerflow tables — the whole LedgerFlow stack
// was decommissioned 2026-06-03 (audit Day 4), so they no longer exist.
@ -290,9 +292,8 @@ export class BackupStack extends cdk.Stack {
// the vault CMK, as the C-7 database-1 smoke-test confirmed)
...[
"vol-05cb0eb5c145d799b", // SeaHavenIndustries-dev
"vol-054cf918f227d88f6", // file-share (20 GiB)
"vol-00f05a5a809697ce5", // forgejo
"vol-04d951cccacc435b5", // file-share NAS (500 GiB)
"vol-04d951cccacc435b5", // file-share NAS rollback hold until 2026-10-06
"vol-07094902194638fff", // syslog-server
"vol-0c2cbe9e71517a517", // Mutual Aid Data
"vol-0fe224f13812f47e7", // jump box