Reliability / Recovery Readiness
Dimensions: Health · Backup · Restore Test · Monitoring · Rollback · Secrets.
DCP
| Dimension | Status | Source | Evidence | Last verification | Recommended next action |
|---|---|---|---|---|---|
| Health | PASS | REAL | Live read-only DCP /health probe. | live probe | — |
| Backup | UNKNOWN | UNKNOWN | Backup stack installed but the timer is disabled/inactive and the first real backup has not run (STATIC fact). Not verified. | never | Run the first real backup after the soak/backup gates pass; until then backup evidence stays UNKNOWN. |
| Restore Test | UNKNOWN | UNKNOWN | No restore drill has been executed against this service yet. Restore stays UNKNOWN until a real drill artifact exists. | never | Run a disposable restore drill and record the PASS/FAIL artifact; never claim restore PASS from a design alone. |
| Monitoring | WARNING | STATIC | Compose healthcheck + /health documented, but no verified alert route to the owner is proven. | never | Route a verified alert to the owner (Uptime Kuma / n8n -> Telegram) and record the first real alert. |
| Rollback | PASS | STATIC | Rollback runbook documented: revert DCP_IMAGE_TAG to the prior SHA and `docker compose up -d` (docs/PRODUCTION-DEPLOYMENT.md). | documented | Confirm the rollback procedure against the running image/version and record a drill result. |
| Secrets | PASS | STATIC | Secrets live in /etc/dev-control-plane/production.env (root:root 600, outside the repo); only names appear in the repo. | documented | Confirm secret storage/isolation with a read-only review; never render secret contents. |
Only PASS counts as verified. UNKNOWN, WARNING, FAIL and NOT_APPLICABLE never count as a pass. STATIC = documented/committed evidence, not a live probe.
PostgreSQL
| Dimension | Status | Source | Evidence | Last verification | Recommended next action |
|---|---|---|---|---|---|
| Health | PASS | REAL | Live read-only DCP /health probe. | live probe | — |
| Backup | UNKNOWN | UNKNOWN | Backup stack installed but the timer is disabled/inactive and the first real backup has not run (STATIC fact). Not verified. | never | Run the first real backup after the soak/backup gates pass; until then backup evidence stays UNKNOWN. |
| Restore Test | UNKNOWN | UNKNOWN | No restore drill has been executed against this service yet. Restore stays UNKNOWN until a real drill artifact exists. | never | Run a disposable restore drill and record the PASS/FAIL artifact; never claim restore PASS from a design alone. |
| Monitoring | WARNING | STATIC | No dedicated PostgreSQL monitoring/metrics is verified; only the DCP /health database check is documented. | never | Route a verified alert to the owner (Uptime Kuma / n8n -> Telegram) and record the first real alert. |
| Rollback | PASS | STATIC | Rollback documented: restore from a verified backup and/or revert the DCP image; schema changes are additive-only. | documented | Confirm the rollback procedure against the running image/version and record a drill result. |
| Secrets | PASS | STATIC | Kept private (no published ports); DSN supplied from the external secret file, never committed. | documented | Confirm secret storage/isolation with a read-only review; never render secret contents. |
Only PASS counts as verified. UNKNOWN, WARNING, FAIL and NOT_APPLICABLE never count as a pass. STATIC = documented/committed evidence, not a live probe.
Redis
| Dimension | Status | Source | Evidence | Last verification | Recommended next action |
|---|---|---|---|---|---|
| Health | UNKNOWN | UNKNOWN | No evidence collected. Not assumed healthy. | never | Point a safe read-only probe at the service (or expose it through DCP /health) before claiming health. |
| Backup | UNKNOWN | UNKNOWN | Backup stack installed but the timer is disabled/inactive and the first real backup has not run (STATIC fact). Not verified. | never | Run the first real backup after the soak/backup gates pass; until then backup evidence stays UNKNOWN. |
| Restore Test | UNKNOWN | UNKNOWN | No restore drill has been executed against this service yet. Restore stays UNKNOWN until a real drill artifact exists. | never | Run a disposable restore drill and record the PASS/FAIL artifact; never claim restore PASS from a design alone. |
| Monitoring | UNKNOWN | UNKNOWN | No evidence collected. Not assumed healthy. | never | Route a verified alert to the owner (Uptime Kuma / n8n -> Telegram) and record the first real alert. |
| Rollback | UNKNOWN | UNKNOWN | No evidence collected. Not assumed healthy. | never | Confirm the rollback procedure against the running image/version and record a drill result. |
| Secrets | UNKNOWN | UNKNOWN | No evidence collected. Not assumed healthy. | never | Confirm secret storage/isolation with a read-only review; never render secret contents. |
Only PASS counts as verified. UNKNOWN, WARNING, FAIL and NOT_APPLICABLE never count as a pass. STATIC = documented/committed evidence, not a live probe.
n8n
| Dimension | Status | Source | Evidence | Last verification | Recommended next action |
|---|---|---|---|---|---|
| Health | UNKNOWN | UNKNOWN | No evidence collected. Not assumed healthy. | never | Point a safe read-only probe at the service (or expose it through DCP /health) before claiming health. |
| Backup | UNKNOWN | UNKNOWN | Backup stack installed but the timer is disabled/inactive and the first real backup has not run (STATIC fact). Not verified. | never | Run the first real backup after the soak/backup gates pass; until then backup evidence stays UNKNOWN. |
| Restore Test | UNKNOWN | UNKNOWN | No restore drill has been executed against this service yet. Restore stays UNKNOWN until a real drill artifact exists. | never | Run a disposable restore drill and record the PASS/FAIL artifact; never claim restore PASS from a design alone. |
| Monitoring | WARNING | STATIC | n8n is the documented alert path (signed webhook, HMAC from env), but no end-to-end alert has been verified. | never | Route a verified alert to the owner (Uptime Kuma / n8n -> Telegram) and record the first real alert. |
| Rollback | UNKNOWN | UNKNOWN | No evidence collected. Not assumed healthy. | never | Confirm the rollback procedure against the running image/version and record a drill result. |
| Secrets | PASS | STATIC | Webhook signing secret only from DCP_AUTOMATION_HMAC_SECRET (env); config/commit never holds it (fail-closed if absent). | documented | Confirm secret storage/isolation with a read-only review; never render secret contents. |
Only PASS counts as verified. UNKNOWN, WARNING, FAIL and NOT_APPLICABLE never count as a pass. STATIC = documented/committed evidence, not a live probe.
Authelia
| Dimension | Status | Source | Evidence | Last verification | Recommended next action |
|---|---|---|---|---|---|
| Health | UNKNOWN | UNKNOWN | No evidence collected. Not assumed healthy. | never | Point a safe read-only probe at the service (or expose it through DCP /health) before claiming health. |
| Backup | UNKNOWN | UNKNOWN | Backup stack installed but the timer is disabled/inactive and the first real backup has not run (STATIC fact). Not verified. | never | Run the first real backup after the soak/backup gates pass; until then backup evidence stays UNKNOWN. |
| Restore Test | UNKNOWN | UNKNOWN | No restore drill has been executed against this service yet. Restore stays UNKNOWN until a real drill artifact exists. | never | Run a disposable restore drill and record the PASS/FAIL artifact; never claim restore PASS from a design alone. |
| Monitoring | UNKNOWN | UNKNOWN | No evidence collected. Not assumed healthy. | never | Route a verified alert to the owner (Uptime Kuma / n8n -> Telegram) and record the first real alert. |
| Rollback | UNKNOWN | UNKNOWN | No evidence collected. Not assumed healthy. | never | Confirm the rollback procedure against the running image/version and record a drill result. |
| Secrets | UNKNOWN | UNKNOWN | Auth/secrets evidence not verified; secret contents never rendered. | never | Confirm secret storage/isolation with a read-only review; never render secret contents. |
Only PASS counts as verified. UNKNOWN, WARNING, FAIL and NOT_APPLICABLE never count as a pass. STATIC = documented/committed evidence, not a live probe.
Uptime Kuma
| Dimension | Status | Source | Evidence | Last verification | Recommended next action |
|---|---|---|---|---|---|
| Health | UNKNOWN | UNKNOWN | No evidence collected. Not assumed healthy. | never | Point a safe read-only probe at the service (or expose it through DCP /health) before claiming health. |
| Backup | UNKNOWN | UNKNOWN | Backup stack installed but the timer is disabled/inactive and the first real backup has not run (STATIC fact). Not verified. | never | Run the first real backup after the soak/backup gates pass; until then backup evidence stays UNKNOWN. |
| Restore Test | UNKNOWN | UNKNOWN | No restore drill has been executed against this service yet. Restore stays UNKNOWN until a real drill artifact exists. | never | Run a disposable restore drill and record the PASS/FAIL artifact; never claim restore PASS from a design alone. |
| Monitoring | WARNING | STATIC | Uptime Kuma is present as a monitoring tool, but the monitor set and alert delivery to the owner are unverified. | never | Route a verified alert to the owner (Uptime Kuma / n8n -> Telegram) and record the first real alert. |
| Rollback | UNKNOWN | UNKNOWN | No evidence collected. Not assumed healthy. | never | Confirm the rollback procedure against the running image/version and record a drill result. |
| Secrets | UNKNOWN | UNKNOWN | No evidence collected. Not assumed healthy. | never | Confirm secret storage/isolation with a read-only review; never render secret contents. |
Only PASS counts as verified. UNKNOWN, WARNING, FAIL and NOT_APPLICABLE never count as a pass. STATIC = documented/committed evidence, not a live probe.
Netdata
| Dimension | Status | Source | Evidence | Last verification | Recommended next action |
|---|---|---|---|---|---|
| Health | UNKNOWN | UNKNOWN | No evidence collected. Not assumed healthy. | never | Point a safe read-only probe at the service (or expose it through DCP /health) before claiming health. |
| Backup | UNKNOWN | UNKNOWN | Backup stack installed but the timer is disabled/inactive and the first real backup has not run (STATIC fact). Not verified. | never | Run the first real backup after the soak/backup gates pass; until then backup evidence stays UNKNOWN. |
| Restore Test | UNKNOWN | UNKNOWN | No restore drill has been executed against this service yet. Restore stays UNKNOWN until a real drill artifact exists. | never | Run a disposable restore drill and record the PASS/FAIL artifact; never claim restore PASS from a design alone. |
| Monitoring | WARNING | STATIC | Netdata is present for metrics, but scraped coverage and alert routing are unverified. | never | Route a verified alert to the owner (Uptime Kuma / n8n -> Telegram) and record the first real alert. |
| Rollback | UNKNOWN | UNKNOWN | No evidence collected. Not assumed healthy. | never | Confirm the rollback procedure against the running image/version and record a drill result. |
| Secrets | UNKNOWN | UNKNOWN | No evidence collected. Not assumed healthy. | never | Confirm secret storage/isolation with a read-only review; never render secret contents. |
Only PASS counts as verified. UNKNOWN, WARNING, FAIL and NOT_APPLICABLE never count as a pass. STATIC = documented/committed evidence, not a live probe.
Homepage
| Dimension | Status | Source | Evidence | Last verification | Recommended next action |
|---|---|---|---|---|---|
| Health | UNKNOWN | UNKNOWN | No evidence collected. Not assumed healthy. | never | Point a safe read-only probe at the service (or expose it through DCP /health) before claiming health. |
| Backup | UNKNOWN | UNKNOWN | Backup stack installed but the timer is disabled/inactive and the first real backup has not run (STATIC fact). Not verified. | never | Run the first real backup after the soak/backup gates pass; until then backup evidence stays UNKNOWN. |
| Restore Test | UNKNOWN | UNKNOWN | No restore drill has been executed against this service yet. Restore stays UNKNOWN until a real drill artifact exists. | never | Run a disposable restore drill and record the PASS/FAIL artifact; never claim restore PASS from a design alone. |
| Monitoring | UNKNOWN | UNKNOWN | No evidence collected. Not assumed healthy. | never | Route a verified alert to the owner (Uptime Kuma / n8n -> Telegram) and record the first real alert. |
| Rollback | UNKNOWN | UNKNOWN | No evidence collected. Not assumed healthy. | never | Confirm the rollback procedure against the running image/version and record a drill result. |
| Secrets | UNKNOWN | UNKNOWN | Dashboard may hold service keys; storage/isolation not verified. | never | Confirm secret storage/isolation with a read-only review; never render secret contents. |
Only PASS counts as verified. UNKNOWN, WARNING, FAIL and NOT_APPLICABLE never count as a pass. STATIC = documented/committed evidence, not a live probe.
9Router
| Dimension | Status | Source | Evidence | Last verification | Recommended next action |
|---|---|---|---|---|---|
| Health | UNKNOWN | UNKNOWN | No evidence collected. Not assumed healthy. | never | Point a safe read-only probe at the service (or expose it through DCP /health) before claiming health. |
| Backup | UNKNOWN | UNKNOWN | Backup stack installed but the timer is disabled/inactive and the first real backup has not run (STATIC fact). Not verified. | never | Run the first real backup after the soak/backup gates pass; until then backup evidence stays UNKNOWN. |
| Restore Test | UNKNOWN | UNKNOWN | No restore drill has been executed against this service yet. Restore stays UNKNOWN until a real drill artifact exists. | never | Run a disposable restore drill and record the PASS/FAIL artifact; never claim restore PASS from a design alone. |
| Monitoring | UNKNOWN | UNKNOWN | No evidence collected. Not assumed healthy. | never | Route a verified alert to the owner (Uptime Kuma / n8n -> Telegram) and record the first real alert. |
| Rollback | UNKNOWN | UNKNOWN | No evidence collected. Not assumed healthy. | never | Confirm the rollback procedure against the running image/version and record a drill result. |
| Secrets | UNKNOWN | UNKNOWN | No evidence collected. Not assumed healthy. | never | Confirm secret storage/isolation with a read-only review; never render secret contents. |
Only PASS counts as verified. UNKNOWN, WARNING, FAIL and NOT_APPLICABLE never count as a pass. STATIC = documented/committed evidence, not a live probe.