▲ 52 r/nexthink+2 crossposts

Does anyone actually test their database restores on a schedule?

Every backup thread ends with "an untested backup is not a backup," everyone upvotes, and then (in my experience) nobody has an automated restore test anywhere.

Genuinely curious about the state of practice:

  1. Do you restore-test on a schedule, or only when something breaks / an audit demands it?
  2. If you automated it, what did you build? (ephemeral instance? scripts like pgbackrest_auto? CI job?)
  3. If you didn't, what stopped you? (time? nowhere safe to restore to? nobody asked?)
  4. For those with SOC 2/ISO: did the audit change anything, or did you just produce a doc that says you test quarterly?

Trying to understand if this gap is real or if I just keep landing in teams that are bad at it.

reddit.com
u/DEX_Nexthink — 3 days ago
▲ 13 r/grc+1 crossposts

Those of you through a Type II audit — how do you actually produce backup restore-test evidence?

Doing some research on a pain I keep hitting as a devops engineer. SOC 2 A1.2/A1.3 wants evidence that you test recovery, not just that backups ran, and Type II wants it continuously over the observation window.

For those who've been through it:

  1. What did your auditor actually accept as restore-test evidence? (screenshots? a runbook doc? ticket trail?)
  2. How often do you really run test restores vs. what your policy says?
  3. Who owns this: compliance, or whoever runs the databases?
  4. Is this a "scramble the week before the audit" thing or genuinely automated for anyone?

Trying to figure out if this is as universally duct-taped as it looks from where I sit. War stories appreciated.

reddit.com
u/ahmadpiran — 6 days ago