Checkpoint 1 is the human-attested, immutable historical baseline for a scope. It combines state facts with recovery evidence so that a service does not receive agent write authority on the strength of an untested backup claim.
Checkpoint 1
The manifest cannot be edited or deleted by an agent. Evidence may later become stale, but the original record remains intact. A checkpoint is not automatically the correct rollback destination after data has changed; recovery must still evaluate compatibility, RPO/RTO and external effects.
Minimum evidence manifest
| Evidence group | Examples |
|---|---|
| Application and infrastructure | Image/release digest, config hash, IaC revision, provider resource IDs. |
| Database and restore | Schema digest, backup ID, PITR coverage, restore job and startup/health/data checks. |
| Network and dependencies | Routes, DNS, load balancer policy, service graph, owners and external limits. |
| Operational baseline | Health, performance/saturation, cost and evidence timestamps. |
Restore verification
- Choose a consistency boundary and recovery point.
- Validate backup integrity and the required key/log chain.
- Restore in an isolated environment with production DNS and side effects blocked.
- Start a compatible application version with test-safe secrets.
- Run health, read/write synthetic and data-consistency checks.
- Record actual RTO, RPO/window and redacted machine-readable evidence.
- Require human review and signature; a FAIL or UNKNOWN result cannot become VERIFIED.
Recovery hierarchy
The least disruptive safe recovery is selected by compatibility, authority, data-loss window and blast radius—not by a fixed sequence. Candidates may include restarting a process, rolling back an image/configuration, recovering infrastructure, or a database restore/PITR with data-owner authority. External payments, consumed queues and new data may need compensation or reconciliation rather than time travel.
DESIGN LIMIT
The MVP proposes a PostgreSQL restore-test fixture and imported customer backup evidence. Automatic restoration of a production database remains outside MVP scope.
Control-plane recovery
After control-plane recovery, the environment remains frozen. The audit chain is checked against an independent witness, old permits are revoked, in-flight work is reconciled and provider logs are compared before a human requests return to normal. Missing evidence is not treated as evidence that nothing happened.