Context
All 13 incident-response runbooks under docs/runbooks/ are written and operationally complete. None have been drilled against the real production environment. The backup-drill-prod.yml GitHub workflow exists but its secrets (PROD_LITESTREAM_*) must be populated and a manual run logged.
Acceptance criteria
Restore drill
Paging drill
Security disclosure drill
Severity
High — GA blocker. Cannot promise on-call response or recovery time without having exercised the paths.
Evidence pointers
final_readiness_report.html §10.2, §12 DOC-02, §13.1 item 5.
docs/runbooks/{backup-restore,hub-incident,watchtower-down,security-disclosure}.md.
.github/workflows/backup-drill-prod.yml.
Context
All 13 incident-response runbooks under
docs/runbooks/are written and operationally complete. None have been drilled against the real production environment. Thebackup-drill-prod.ymlGitHub workflow exists but its secrets (PROD_LITESTREAM_*) must be populated and a manual run logged.Acceptance criteria
Restore drill
PROD_LITESTREAM_*secrets populated in the repo settings.workflow_dispatchrun ofbackup-drill-prod.ymlfor both hub and watchtower.Paging drill
ALERTMANAGER_PAGER_WEBHOOK_URLSecret populated viasecrets-bootstrap.sh --bootstrap-monitoring.HubLiquidityLowthreshold high enough to fire).Security disclosure drill
SECURITY.md.Severity
High — GA blocker. Cannot promise on-call response or recovery time without having exercised the paths.
Evidence pointers
final_readiness_report.html§10.2, §12 DOC-02, §13.1 item 5.docs/runbooks/{backup-restore,hub-incident,watchtower-down,security-disclosure}.md..github/workflows/backup-drill-prod.yml.