diff --git a/lib/backup-stack.ts b/lib/backup-stack.ts index c9a980c..07aaad0 100644 --- a/lib/backup-stack.ts +++ b/lib/backup-stack.ts @@ -253,13 +253,14 @@ export class BackupStack extends cdk.Stack { // the locked offsite vault ("offsite for everything"). Same role and rule // as phase-1; a separate selection keeps the phase-1 critical set readable. // - // Still EXPLICIT-ARN (not tag-based) on purpose: the file-share volumes are - // standalone CDK-managed (RETAIN) and the DynamoDB tables are owned by other - // stacks, so tagging them here would drift those stacks — the same reason - // phase-1 avoided tags. Tradeoff: if a volume is replaced (new vol-id) it - // silently drops from this selection; scheduled drift detection + the audit - // re-run are the backstop. Identifiers verified against the live account - // 2026-06-03. + // Still EXPLICIT-ARN (not tag-based) on purpose: the DynamoDB tables are + // owned by other stacks, so tagging them here would drift those stacks. + // File-share left this account on 2026-09-29 (PLAT-77). Both of its volume + // ARNs are out of this selection so a later delete of the retained volume + // does not fail the backup job. Tradeoff: if a volume is replaced (new + // vol-id) it silently drops from this selection; scheduled drift detection + // and the audit re-run are the backstop. Identifiers verified against the + // live account 2026-06-03. // // Excluded by intent: the ledgerflow tables — the whole LedgerFlow stack // was decommissioned 2026-06-03 (audit Day 4), so they no longer exist. @@ -290,9 +291,7 @@ export class BackupStack extends cdk.Stack { // the vault CMK, as the C-7 database-1 smoke-test confirmed) ...[ "vol-05cb0eb5c145d799b", // SeaHavenIndustries-dev - "vol-054cf918f227d88f6", // file-share (20 GiB) "vol-00f05a5a809697ce5", // forgejo - "vol-04d951cccacc435b5", // file-share NAS (500 GiB) "vol-07094902194638fff", // syslog-server "vol-0c2cbe9e71517a517", // Mutual Aid Data "vol-0fe224f13812f47e7", // jump box