Phase 5 Backup Rollout Execution Bundle
Provide one approval-ready execution path for installing the Tier-1 backup timer and capturing first-run evidence.
Purpose
Provide one approval-ready execution path for installing the Tier-1 backup timer and capturing first-run evidence.
Scope
- Stack area:
runtime/stacks/infrastructure/databases - Artifacts used:
operations/backups/db-backup.shoperations/systemd/tier1-db-backup/install.shoperations/diagnostics/collect-tier1-backup-evidence.shoperations/systemd/tier1-db-backup/tier1-db-backup.serviceoperations/systemd/tier1-db-backup/tier1-db-backup.timerdocs/operations/templates/restore-validation-template.mdxdocs/operations/templates/production-change-record-template.mdx
Approval Gate
- Required approver: owner
- Approval rule: explicit owner approval or owner manual execution
- This bundle does not require docker compose commands.
Preconditions
- Owner approval captured in change record.
- VPS repository path confirmed (
/opt/docsdefault, or override such as/home/repo/contabo-server-setup). - Database containers are healthy before backup run.
- Sufficient free disk space is available in backup target path.
Execution Steps
0) Resolve repository root
if [ -d /opt/docs/runtime/stacks/infrastructure/databases ]; then
export REPO_ROOT=/opt/docs
else
export REPO_ROOT=/home/repo/contabo-server-setup
fi1) Create change record instance
- Open
docs/operations/change-records/cr-2026-04-15-tier1-backup-timer-rollout.mdx. - Fill approval timestamp, executor, and maintenance window.
2) Dry-run backup helper
cd "${REPO_ROOT}"
sudo operations/backups/db-backup.sh run --dry-runExpected outcome:
- Lists planned backup artifacts for enabled engines.
- No backup files written.
3) Dry-run systemd unit install preview
cd "${REPO_ROOT}"
sudo operations/systemd/tier1-db-backup/install.sh --dry-runExpected outcome:
- Shows generated service/timer definitions.
- Does not install units.
4) Install and enable weekly timer
cd "${REPO_ROOT}"
sudo operations/systemd/tier1-db-backup/install.sh --repo-root "${REPO_ROOT}"Expected outcome:
- Unit files installed under
/etc/systemd/system/. - Timer enabled and active with weekly schedule (
Sun *-*-* 03:00:00).
5) Trigger first manual backup run
cd "${REPO_ROOT}"
sudo operations/backups/db-backup.sh run --keep-last-backups 3Expected outcome:
- Backup folder created under
tmp/backups/tier1-<timestamp>. manifest.csvincludes checksums and sizes.
6) Verify timer and latest backup evidence
sudo systemctl status tier1-db-backup.timer --no-pager
sudo systemctl list-timers tier1-db-backup.timer --all --no-pager
ls -lah "${REPO_ROOT}/tmp/backups" | grep tier1-
cd "${REPO_ROOT}"
sudo operations/diagnostics/collect-tier1-backup-evidence.shExpected outcome:
- Timer is active and next run scheduled.
- Latest backup folder is present.
Evidence Capture
Capture and attach to the change record:
systemctl status tier1-db-backup.timersystemctl list-timers tier1-db-backup.timer --all- backup folder path and manifest path
- one sample checksum row from
manifest.csv - output file path from
collect-tier1-backup-evidence.sh - any warnings or non-zero exits
Rollback
If scheduling must be rolled back:
sudo systemctl disable --now tier1-db-backup.timer
sudo rm -f /etc/systemd/system/tier1-db-backup.timer /etc/systemd/system/tier1-db-backup.service
sudo systemctl daemon-reloadRollback does not delete existing backup files.
Post-Execution Updates
- Update
docs/state/next-steps.mdxfor:- backup automation implementation evidence
- timer installation evidence
- Update
docs/state/already-implemented.mdxonly after server execution is confirmed complete.
Monitoring Evaluation Execution Bundle
Approval-ready execution path for installing Cockpit, Beszel and Netdata on the host, evaluating Beszel against Netdata on real workload, and retiring the loser.
Phase 5 Encrypted Google Backup Rollout
Approval-gated rollout of verified WordPress and Tier-1 database backups to encrypted Google Drive destinations.