Incident response¶
- Contain access. Disable automatic failover if ownership is uncertain, revoke affected sessions and provider credentials, and preserve minimal timestamps and identifiers.
- Assess scope. Identify the affected instance, event, data categories, recipients, processors, backups and time window without copying unnecessary personal data into tickets.
- Recover safely. Use a verified signed release and an encrypted, deeply verified recovery snapshot. Do not bypass HA fencing or restore root bootstrap automatically.
- Notify the controller. The controller determines applicable GDPR, FADP, contractual and supervisory-notification duties and deadlines.
- Rotate dedicated credentials. Treat Cloudflare, SMTP, Git, SSH, recovery, application and evidence keys as separate trust domains.
- Record decisions locally. Keep factual, bounded evidence. Do not claim that a signature proves physical deletion.
- Review. Fix the cause, validate single-node and HA behavior, and publish a new signed patch release when shipped code changed.
Never attach production databases, .env, private keys, activation links, participant schedules or recovery packages to a public issue.