Administer

Availability & HA posture

Current tier

No automatic HA

Single node with a verified restore — no automatic HA. A controller failure means restoring from the latest verified backup, not an automatic failover. This is the honest, current posture, not a roadmap promise.

Measured recovery evidence

Pass
Drill performed
12 Jul 2026, 15:00
Restore host
restore-test01.zala.local (clean host)
Measured RPO
690 min
Measured RTO
47 min

What automatic failover would require

0 / 4

None of these gates are met today — automatic failover is not offered until every one of them is.

Quorum mechanism across at least 2 additional nodes Not met
Fencing evidence — a failed node cannot keep writing after failover Not met
A provisioned, kept-current standby node Not met
A witnessed takeover drill with a passing outcome Not met

Cold-standby roadmap

Provision a cold-standby node Planned
Replicate verified backups to the standby continuously Planned
Run a witnessed takeover drill end to end Gated
Declare cold-standby supported for production use Gated