Skip to content
PERINGER Data Solutions, back to home

Back

Solution

Backup and recovery

A successful job proves neither integrity, isolation nor recovery time. I separate the credentials, isolate the copy, restore in front of you with the duration measured, then have management decide the acceptable downtime and data loss for each service.

On the day it matters

In practice

  • Credential separation: the backup store refuses the accounts that administer production, so one stolen password doesn’t open both
  • An isolated or immutable copy for a defined period, chosen for the threat, then tested against administrative deletion, expiry and capacity
  • For each hosted service, the native retention, restore and export mechanisms tested; an additional backup only where they fall short
  • A restore genuinely performed in front of you, system by system, with the measured duration written down
  • Recovery objectives per service: accepted downtime and data loss, then the architecture that holds them, from a plain restore to a standby site
  • A recovery rehearsal: one service failed over to the standby and brought back, with timings, gaps and decisions recorded
  • A test cadence based on criticality, change and risk, with a procedure your team runs

Systems involved

  • Proxmox Backup Server, restic, Veeam and the backup tools in place
  • Object storage with locking, S3 Object Lock for instance, and ZFS
  • Microsoft 365, Google Workspace and the retention features of hosted services
  • PostgreSQL, SQL Server and the databases to restore
  • Swiss hosts and Swiss cloud regions for the off-site copy

Service lineServers and hosting →

The systems to bring back

The same work, against each sector’s own constraints. Every card opens the full sector.

How it runs

  1. Inventory

    You choose what has to survive, for how long, and the acceptable downtime per service. Drawing up the list is how the data still outside any backup gets found.

  2. Separation

    Credentials, the immutable or isolated copy and the off-site copy get designed together, then their configuration is tested.

  3. Restore

    A real restore, onto a side environment, timed. That’s the moment the backup stops being a hypothesis.

  4. Rehearsal

    One service fails over to the standby and returns, with roles, timings and decisions recorded. Your team then owns the test calendar.

Test the fit: Backup and recovery

Describe the context, constraints and decision you need to make. The first conversation qualifies scope, boundaries and the next useful step.

Describe the situation