← Professional Cloud Architect: architecture and operations
08 / 8 · 30 MIN

Recovery, exercises, and RUN

Demonstrate complete recovery with boundaries, decisions, and reconciliation.

Concept and mechanism

Recovery needs more than available resources. Define who declares the incident, authorizes promotion, controls writes, and accepts the business outcome. The runbook should include contacts, access, dependencies, criteria, and evidence, with steps the team can execute. RTO and RPO are evaluated separately: recovery in 42 minutes can meet a 45-minute RTO and miss a 10-minute RPO if 18 minutes of information is absent. Record the recovered data state and possible additional sources without declaring permanent loss before investigation. When the primary returns, control divergence and reconciliation before allowing concurrent writes. A successful technical failover can still require functional work.

Guided application

In a fictional exercise, begin with a concrete hypothesis, such as maintaining processing when a zone stops responding. Define scope, signals, impact limits, abort conditions, and recovery. Rehearsal in a controlled environment allows procedure fixes before increasing exposure. A resilience diagram does not demonstrate how people, permissions, and dependencies behave during failure. Measure time to functional service and validate orders, files, and expected outcomes. If health checks turn green at 04:00 but orders are missing at 04:15, communicate partial technical recovery and keep functional validation assigned to an owner. Then document the timeline, causes, and verifiable actions. This evidence feeds architecture, capacity, training, and improvement-priority decisions.

IN PRACTICE

Partial technical recovery should be communicated as partial until reconciliation confirms the service.

Common pitfalls

Standby as a plan; exercise without abort criteria; health check as reconciliation; closure as causal resolution.

Related topics: Requirements, costs, and platform selection · Data, resilience, and events · Networking, provisioning, and capacity

Take this idea with you

Exercise people, permissions, data, and decisions alongside technology.

Create account

Reference: Disaster recovery planning · Current linked standard guide; edition date unconfirmed (2026-09-30 inspection)