# Continuity & Recovery

Managed documentation for Continuity &amp; Recovery.

# Backup and Recovery

<!-- BOOKSTACK-DOCUMENT-RELEASE:BEGIN -->
# Backup and Recovery

| Field | Value |
| --- | --- |
| Distribution | BSS — OpenSOF |
| Product | OpenSOF |
| Release | 0.15.1 |
| Deployment | `opensof.bss.dev` |
| Source | `/srv/bss/releases/OpenSOF-v0.15.0-20app` |
| Evidence | Continuity standard |
| Source fingerprint | `cda583b42f2a0d296b268ab5b174932a378c8be6fb52ffa1af14af896e990f6e` |
| Status | Generated baseline — human review required |

> **Verification boundary:** This page combines platform design guidance with static evidence from the release. It does not prove that every detected interface is enabled, reachable, secure, or operational in the deployed environment.

## Backup scope

| Asset | Backup requirement | Restore verification |
| --- | --- | --- |
| Release artifacts | Retain exact immutable packages/checksums; normally do not back up regenerated dependencies. | Checksum and extraction test. |
| Configuration | Versioned protected copy excluding or separately encrypting secrets. | Syntax test and controlled comparison. |
| Databases | Consistent database-native dump/snapshot with schema/version metadata. | Restore into isolated environment and run integrity/query checks. |
| Files/evidence | Content plus metadata, ownership, access policy, checksums and provenance. | Sample restore, checksum and access-control test. |
| Knowledge/ontology | Graph data, ontology versions, shapes, indexes and configuration. | SPARQL/constraint tests against restored graph. |
| Audit/history | Protected retention according to policy; preserve ordering and integrity evidence. | Query selected events and verify integrity chain. |

## Recovery order

1. Infrastructure, DNS/TLS and time.
2. Protected configuration and secrets.
3. Databases, knowledge and artifact stores.
4. OpenBus/shared backends.
5. Edition-specific applications and reverse proxy.
6. Sensors/edge agents and external integrations.
7. End-to-end acceptance tests and user access.

## Recovery objective

Define and test RPO/RTO by data class. A backup that has never been restored is an optimistic file collection, not a recovery capability.
<!-- BOOKSTACK-DOCUMENT-RELEASE:END -->

---

## Maintainer Notes

<!-- BOOKSTACK-DOCUMENT-RELEASE:NOTES-BEGIN -->
Add human-reviewed deployment notes, corrections, decisions, screenshots, and links here. Content outside the generated block is preserved on future runs.
<!-- BOOKSTACK-DOCUMENT-RELEASE:NOTES-END -->

# Troubleshooting

<!-- BOOKSTACK-DOCUMENT-RELEASE:BEGIN -->
# Troubleshooting

| Field | Value |
| --- | --- |
| Distribution | BSS — OpenSOF |
| Product | OpenSOF |
| Release | 0.15.1 |
| Deployment | `opensof.bss.dev` |
| Source | `/srv/bss/releases/OpenSOF-v0.15.0-20app` |
| Evidence | Operational diagnostic standard |
| Source fingerprint | `cda583b42f2a0d296b268ab5b174932a378c8be6fb52ffa1af14af896e990f6e` |
| Status | Generated baseline — human review required |

> **Verification boundary:** This page combines platform design guidance with static evidence from the release. It does not prove that every detected interface is enabled, reachable, secure, or operational in the deployed environment.

## Diagnostic sequence

1. State the exact user-visible symptom, start time, scope and last known good state.
2. Check DNS/routing/time before assuming an application defect.
3. Check process/container state and recent logs.
4. Test the backend locally on its bound address/port.
5. Test proxy/TLS path and WebSocket upgrade separately.
6. Test dependencies: database, OpenBus, OpenKnowledge, OpenFiles and external services.
7. Reproduce one primary workflow with correlation identifiers and capture evidence.
8. Apply the smallest reversible change, then retest all layers.

## Symptom matrix

| Symptom | Likely layer | First checks |
| --- | --- | --- |
| Connection refused | Process/socket | `systemctl status`, `ss -lntup`, local curl |
| Empty response/reset | App/upstream crash or protocol mismatch | Application logs, internal HTTP response, proxy protocol. |
| 502/504 | Reverse proxy/upstream | `nginx -t`, error log, `proxy_pass`, backend latency |
| Page loads but live data fails | WebSocket/CORS/auth | Browser network console, upgrade headers, token/role, route base. |
| Wrong distribution/branding | Nginx/service instance | Hostname routing, service unit, current release symlink, environment. |
| Tracks/tasks/products missing | Dependency/data flow | Producer logs, OpenBus/API, authorization, semantic type, time window. |
| Intermittent correlation error | Time/PNT/data quality | Clock offset, source timestamps, coordinate frame and calibration. |

## Evidence rule

Before changing configuration, preserve the relevant logs, status output, request/response, release version and timestamps. Troubleshooting without evidence tends to become configuration roulette—with worse odds and fewer free drinks.
<!-- BOOKSTACK-DOCUMENT-RELEASE:END -->

---

## Maintainer Notes

<!-- BOOKSTACK-DOCUMENT-RELEASE:NOTES-BEGIN -->
Add human-reviewed deployment notes, corrections, decisions, screenshots, and links here. Content outside the generated block is preserved on future runs.
<!-- BOOKSTACK-DOCUMENT-RELEASE:NOTES-END -->