Skip to content

feat(platform): verify locked metadata backup repository - #7

Open
zhouning wants to merge 1 commit into
mainfrom
feat/ar1-metadata-fabric-durable-backup-contract
Open

feat(platform): verify locked metadata backup repository#7
zhouning wants to merge 1 commit into
mainfrom
feat/ar1-metadata-fabric-durable-backup-contract

Conversation

@zhouning

Copy link
Copy Markdown
Owner

Summary

  • add an isolated, versioned MinIO repository profile with Object Lock and runtime-only credentials
  • round-trip the three real Metadata Fabric backup artifacts by version ID before restoring into new PVCs
  • freeze a fail-closed production S3/KMS/workload-identity policy contract and update ADR/roadmap/system-of-record evidence
  • register the bounded local runner in platform truth and add required CI coverage

Live evidence

  • total rehearsal: 143.107s; repository-backed recovery: 115.137s
  • bucket versioning: Enabled; Object Lock: Enabled; retention: GOVERNANCE/1 day
  • all three retained version deletions were rejected
  • runner-local artifacts were deleted, downloaded by version ID, and used to recover 176 OpenMetadata tables, 39 Gravitino tables, and 79 OpenSearch indexes
  • repository evidence: 07834430fb140e147624f4ab3c93e6d7907648e91a149cb19db178ea6085d1ed
  • recovery evidence: 3cf46cc83a8feaa4142893a06f84e9008a7d805a64fb6708d176ca976a4dbd62

The verified scope is only local_same_cluster_isolated_s3_compatible_repository. Production target/retention, TLS/KMS, OIDC, NetworkPolicy enforcement, cross-cluster/cross-region recovery, RPO/RTO, GDA writes, and production readiness remain false.

Verification

  • 482 passed required platform tests
  • 4 passed runtime dependency constraint tests
  • 3 passed PostgreSQL ledger/gateway integration tests against temporary PostGIS 16
  • all platform and Metadata Fabric validators returned valid
  • committed repository and recovery evidence integrity verified
  • repository Kustomize render, shell syntax, and git diff --check passed
  • frontend npm run build passed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant