# P12 RDS, Aurora, and DynamoDB recovery workbook

Use with AWS234. This is a no-create incident and architecture artifact.

## Business contract

| Data set | Owner | Failure scenarios | RPO | RTO | Consistency/integrity invariants | Retention | Cutover authority |
|---|---|---|---|---|---|---|---|
| Orders relational database |  | AZ/instance/Region/logical corruption/operator deletion/key loss |  |  |  |  |  |
| Order-status key-value table |  |  |  |  |  |  |  |

## RDS/Aurora source inventory

| Field | Evidence |
|---|---|
| Engine/version and instance or cluster topology |  |
| Writer/reader/proxy/custom endpoints and DNS TTL |  |
| Single-AZ, Multi-AZ instance, Multi-AZ cluster, Aurora replicas/global DB |  |
| Backup retention/window, earliest/latest restorable UTC |  |
| Manual/automated/AWS Backup snapshots and owners |  |
| Cross-Region automated backup/snapshot copies |  |
| KMS key policy/grants and deletion state |  |
| Subnet/parameter/option/security groups and CA certificate |  |
| Secrets/rotation/database users and IAM authentication |  |
| Logs, events, alarms, Performance Insights/Database Insights evidence |  |
| Dependencies: DNS, app version, queues/files/cache |  |

## DynamoDB source inventory

| Field | Evidence |
|---|---|
| Table ARN/Region/status/key schema |  |
| Billing mode/capacity/autoscaling |  |
| GSIs/LSIs and item-count/size baseline |  |
| PITR status and earliest/latest restorable UTC |  |
| On-demand/AWS Backup recovery points |  |
| SSE key/policy/grants |  |
| TTL, Streams, Contributor Insights, alarms, tags, deletion protection |  |
| Global Table mode/replicas/status/replication latency/conflict model |  |
| Resource/IAM policies and application routing |  |

## Recovery-point decision

- Incident start and last known good business transaction in UTC:
- Corruption/deletion propagation window:
- Chosen point and why it precedes the bad change:
- Latest possible point age and calculated data loss:
- Manual snapshot/on-demand backup versus PITR rationale:
- Key and permissions proven before restore:
- Independent copy/account/Region evidence:

## Isolated restore target

| Control | RDS/Aurora target | DynamoDB target |
|---|---|---|
| Unique name/endpoint |  |  |
| Isolated network/resource policy |  |  |
| Class/storage/capacity/index exclusions |  |  |
| KMS key |  |  |
| Parameter/option/subnet/security settings |  | N/A |
| Tags/deletion protection/PITR/backup |  |  |
| Streams/TTL/autoscaling/alarms | N/A |  |
| No production writers proved |  |  |

## Validation and reconciliation

| Layer | Test | Expected result | Evidence | Owner |
|---|---|---|---|---|
| Control plane | restore state/time/point | available/active from exact point |  |  |
| Schema/index | objects, keys, indexes | expected versions |  |  |
| Integrity | checksums/counts/FK/business totals | baseline/invariants pass |  |  |
| Security | approved access and denied production path | least privilege |  |  |
| Application | read-only smoke test | compatible release/read path |  |  |
| Delta | writes after restore point | classified/replayed exactly once |  |  |
| Performance | warm-up/query/capacity | within cutover threshold |  |  |

Never copy the entire damaged source over the clean restore. Reconcile known-good
transactions using immutable journals, Streams/CDC/audit records and idempotent
business keys; quarantine ambiguous writes for owner review.

## Cutover, rollback, and cleanup

- Change approval and go/no-go checks:
- Writer freeze/fencing mechanism:
- Final delta and invariant result:
- Client DNS/proxy/config update and cache/connection handling:
- Monitoring and rollback window:
- Old source read-only/quarantine retention:
- Restored target backup/PITR/deletion protection enabled:
- Final RPO and end-to-end RTO measured:
- Temporary snapshots/tables/instances/exports/logs cleaned with exact IDs:
- Monthly steady-state and one-recovery cost estimate:
