On this page
WP-16 Business Continuity & Disaster Recovery
Summary
Minimize downtime and data loss in the event of site failure or corruption.
Scope
- Define continuity tiers and map services to explicit RPO/RTO objectives.
- Maintain backup, restore, and failover runbook ownership for critical services.
- Execute regular disaster-recovery exercises and retain evidence of outcomes.
Architecture Context
- Domain architecture index: Platform Architecture
- OpenShift runtime context where relevant: Platform Architecture
Decision Context
Dependencies
Acceptance Criteria
- Tiered RTO/RPO targets are defined and approved per critical service class.
- Annual DR exercise meets target objectives for each critical service class and records evidence artifacts.
- Critical rollback-scope services for cutover exercises are explicitly fixed as: ingress plus DNS/LB control path, IAM/SSO access path, platform API/control-plane access path for production-bound clusters, and stateful data-access path for critical services.
- Cutover rollback execution meets the maximum 60-minute rollback budget for the defined rollback-scope services, measured from incident-commander rollback trigger timestamp until all rollback-scope services are restored and healthy in Location A.
- Certified runbooks exist for critical services and include explicit trigger, escalation, and fallback criteria.