Plan recovery

Define RPO and RTO

Choose acceptable data loss and recovery time for each workload before choosing tools or schedules.

Two numbers drive every backup decision. Write them down before you touch any tool.

The Recovery Point Objective (RPO) is how much recent data you can afford to lose. If you back up nightly and the disk dies at 11 PM, you lose a day of work. Your real RPO is 24 hours, whether you chose it or not.

The Recovery Time Objective (RTO) is how long recovery may take. From “it’s broken” to “it works again”. That includes finding credentials, downloading data, and verifying the result. Not just the restore command.

Set targets per dataset

Different data deserves different numbers. Here are targets for two datasets:

family photos: RPO 1 day, RTO 3 days
customer orders: RPO 5 minutes, RTO 1 hour

Losing a day of photos is sad but survivable. Nobody needs them back within the hour. Losing five minutes of paid orders costs money and trust. That dataset needs frequent backups and a fast, rehearsed restore.

Each number points at a mechanism. RPO maps to backup frequency and replication. An RPO of 5 minutes means continuous archiving or streaming replication, because no nightly dump can meet it. RTO maps to restore speed, people, instructions, and replacement infrastructure. A 1 hour RTO means a written runbook and somewhere ready to restore to.

Do the bandwidth math

RTO promises die on transfer speed. Check yours before you promise anything:

# 500 GB over a 100 Mbit/s connection:
# 500 * 8 / 0.1 / 3600 = ~11 hours, before verification

If your data lives in remote object storage and your office uplink is 100 Mbit/s, a “restore within 2 hours” target is fiction. Either keep a local copy too, or change the target to match reality. I prefer the honest number over the nice one.

Replication is not history

One warning. Replication copies deletions and corruption right away. A replica gives you a great RPO against hardware failure and nothing against DROP TABLE. Only versioned backups let you go back in time. You usually want both.

Try this: write RPO and RTO for the two most important datasets from your inventory. If you can’t name a mechanism that meets each number, the number is a wish, not a target.

Lesson completed