Engine Backup and Restore

Engine Backup and Restore A workflow diagram generated by Archify. 01 / Human maintenance decisions 02 / backup-restore.ts 03 / RecoveryAdapter (trusted host) Approve backup · source verified first · Human maintenance decisions · human Approve backup source verified first human UNKNOWN attempts · block activation · Human maintenance decisions UNKNOWN attempts block activation activateRestore · current-state evidence · Human maintenance decisions · human activateRestore current-state evidence human SQLite checkpoint · WAL pages + inventory · backup-restore.ts SQLite checkpoint WAL pages + inventory Seal manifest · audit prefix + tables · backup-restore.ts Seal manifest audit prefix + tables Publish backup · stage, flush, rename · backup-restore.ts · never overwrite Publish backup stage, flush, rename never overwrite Restore commit · epoch reserved, hold set · backup-restore.ts · RESTORE HOLD Restore commit epoch reserved, hold set RESTORE HOLD Source changed · fails closed · RecoveryAdapter (trusted host) Source changed fails closed Adapter verifies · identity + provenance · RecoveryAdapter (trusted host) Adapter verifies identity + provenance createBackup content differs restoreBackup bytes rechecked SnapshotManifest unsettled attempts protected epoch allocator Legend Agent logic Policy Tool action Context / trace

Six Recovery Boundaries

  • • snapshot-copied, backup-verified, backup-published, epoch-reserved, restore-committed, restore-published
  • • Restore never overwrites the source or an existing destination

Hold Until Activated

  • • The installation-wide RESTORE HOLD is checked by epoch acquisition and the final dispatch gates
  • • Old approvals are revoked, policies made indeterminate, schedules and controls paused

What Survives

  • • Accounting, reservations, attempts, idempotency records and occurrence cursors survive restore
  • • Clock restoration keeps the protected high-water mark under a separate uncertainty hold