Skip to content

Educational analysis

A DR plan is not evidence until restore is exercised

Backup configuration proves that jobs were requested, not that workloads, dependencies, identities, and state can be restored within meaningful objectives.

2 min read

This note is an advisory decision model. It does not claim a completed client restore drill. The analysis is based on publicly documented AWS and Kubernetes backup/restore behavior.

The claim

A disaster recovery plan proves resilience. Leadership sees a documented plan with backup schedules, RPO/RTO targets, and runbook steps. The assumption is that the organization can recover.

The mistaken assumption

Backup configuration is treated as recovery evidence. The assumption is that if backups exist, the workload can be restored. In reality, backup configuration proves that jobs were requested, not that workloads, dependencies, identities, and state can be restored within meaningful objectives.

What changes in production

Recovery requires more than restoring data. Workloads depend on identities (IAM roles, service accounts), secrets, network configuration, DNS, certificate stores, and downstream service dependencies. A backup of a database does not restore the application that reads it, the IAM role that authorizes access, or the DNS record that routes traffic to it.

According to AWS EKS documentation and Velero documentation, backup and restore operations must account for workload dependencies, persistent volume snapshots, and cluster-level resources to achieve meaningful recovery objectives.

The executive consequence

Recovery claims require a defined scope, restore drill, observed result, discrepancy log, and ownership of corrective work. A plan without exercise is a document, not evidence.

A compact decision model

objective → protected state → isolated restore → measured outcome → corrective action

Questions leadership should answer

  • What is the defined recovery scope, and what dependencies are included?
  • When was the last restore drill performed, and what was the observed outcome?
  • What discrepancies were found, and who owns the corrective work?
  • How does the recovery objective compare to the actual measured restore time?

Relevant operating evidence

Disaster recovery readiness benefits from evidence about restore drill results, dependency coverage, and corrective action ownership. A Platform Decision Review can surface these gaps before recovery commitments are made.

Bring the decision

Bring a platform decision to the Platform Decision Review and evaluate disaster recovery readiness against your actual workload dependencies and recovery objectives.

Facing a platform decision?

Bring a platform decision to the Platform Decision Review.

Bring a platform decision
enpt-br