Three S3 console tasks on the same two buckets, all argued in backups.md. (1) Replica policy. The deployed DenyDestroyExceptRoot statement blocks delete, lock bypass, and policy changes for every non-root principal, but not s3:PutObject or s3:PutLifecycleConfiguration: a stolen <s3-admin> key can still write new object versions to <replica-bucket> or schedule a lifecycle purge that takes effect as locks expire (deletion of an already-locked version stays impossible until its own retention date regardless). Add two deny statements via the account root: deny s3:PutObject to everyone but the replication role, and deny lifecycle / Object Lock configuration changes to everyone but root. Closes the deferred-purge and write-pollution gaps; see backups.md. (2) Object Lock on the backup bucket. The media bucket has GOVERNANCE / 365 days bucket-wide; the backup bucket has lifecycle expiration but no immutability layer. Locking daily dumps for, say, 90 days would prevent both accidental and malicious erasure of the most recent recovery points by anyone holding the <s3-admin> profile. (3) Cross-region replication for the DB dump bucket. Every daily pg_dump auto-mirrored to a second region (e.g. vidit-backup-prod-us-east-1) via S3 Replication Configuration. Today the entire backup catalog lives in eu-west-3, same blast radius as the production media bucket (pre-replication) and the Railway PG. The media bucket already has this; the DB dump bucket does not yet. ~10 minutes of configuration once it matters.
Imported from planning/backlog.md.
Three S3 console tasks on the same two buckets, all argued in
backups.md. (1) Replica policy. The deployedDenyDestroyExceptRootstatement blocks delete, lock bypass, and policy changes for every non-root principal, but nots3:PutObjectors3:PutLifecycleConfiguration: a stolen<s3-admin>key can still write new object versions to<replica-bucket>or schedule a lifecycle purge that takes effect as locks expire (deletion of an already-locked version stays impossible until its own retention date regardless). Add two deny statements via the account root: denys3:PutObjectto everyone but the replication role, and deny lifecycle / Object Lock configuration changes to everyone but root. Closes the deferred-purge and write-pollution gaps; seebackups.md. (2) Object Lock on the backup bucket. The media bucket has GOVERNANCE / 365 days bucket-wide; the backup bucket has lifecycle expiration but no immutability layer. Locking daily dumps for, say, 90 days would prevent both accidental and malicious erasure of the most recent recovery points by anyone holding the<s3-admin>profile. (3) Cross-region replication for the DB dump bucket. Every dailypg_dumpauto-mirrored to a second region (e.g.vidit-backup-prod-us-east-1) via S3 Replication Configuration. Today the entire backup catalog lives in eu-west-3, same blast radius as the production media bucket (pre-replication) and the Railway PG. The media bucket already has this; the DB dump bucket does not yet. ~10 minutes of configuration once it matters.Imported from planning/backlog.md.