0939204061
No restore procedure existed anywhere in this repo. The backup pipeline is well commented but nothing described how to get data back, and the README the backup script already referenced was missing. Covers the shared backup engine and its stage ordering, a restore procedure for both MariaDB and Postgres with the rootless-podman command form, data-tree restore including the uid 33 chown, and the maintenance-mode/files:scan reconcile. Two things worth stating plainly: - Untested backups are not a control. No rehearsal has been recorded. - Do not blindly re-run libresign:configure:openssl on a restored instance -- it mints a new root CA and invalidates the trust chain on every document already signed under the old one. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>