This repository was archived by the owner on Aug 11, 2026. It is now read-only.
Add verified recovery operations and FORGE branding - #7
Merged
Conversation
BlinkStreamTeam
marked this pull request as ready for review
August 11, 2026 19:34
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
forge-resilience0.2.0 with streaming AES-256-GCM logical backup, authenticated manifests, verification and transactional restorepg_basebackupnamed-target PITR drillWhy
FORGE must be recoverable after process, database, disk or machine replacement before it can be considered Core Complete. Backup creation alone is insufficient: copies must authenticate, retention must be failure-safe and physical WAL recovery must be drilled rather than claimed.
Implementation findings
pg_ctl -wsignals connection readiness before PITR promotion, so the drill now waits forpg_is_in_recovery() = falseValidation
npm run check: 58/58 monorepo tests passed and every workspace builtnpm run audit:production: 0 vulnerabilitiesnpm pack --dry-run: CLI, policy example and all operator/PITR scripts includedgit diff --check: passedDeliberately not claimed
The installed E: replica is a different physical disk but remains in the same PC. NAS/cloud replication, automatic failover and production-cluster WAL activation require deployment-specific storage, credentials, capacity and monitoring and are not misrepresented as complete.