Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Recovery Drill

ppk drill mysql is a MySQL recovery drill separate from production restore. It verifies decrypt, unpack, import, and app data dirs in isolation; it does not overwrite production by default.

Command Format:

ppk drill mysql \
  --project-key <PROJECT_KEY> \
  --backup-file <BACKUP_FILE> \
  [--target-db-name <TARGET_DB_NAME>] \
  [--config-home <CONFIG_HOME>] \
  [--apply]

Without --apply, only print the drill plan—no download, decrypt, unpack, or DB import. Confirm target DB, workspace, and keys first:

ppk drill mysql \
  --project-key project-a \
  --backup-file /data/backups/project-a.ppke \
  --target-db-name ppk_drill_project_a \
  --config-home /etc/peppykeep/conf \
  --prompt-for-private-key-passphrase \
  --apply

General

  • --project-key: override the project id in config.
  • --backup-file: local .ppk / .ppke, also .tar.gz / .tar.gz.enc; remote objects must be downloaded first.
  • --target-db-name: drill target database; defaults to ppk_drill_<project>_<timestamp>.
  • --workspace-dir: workspace for download, decrypt, unpack, and reporting.
  • --decrypt-private-key-file: private key used for encrypted artifacts.
  • --check-sql-file: custom SQL validation script.
  • --keep-workspace: keep the workspace on success; on failure it is kept by default for troubleshooting.
  • --drop-target-db --confirm-target-db <NAME>: drop the drill DB only after explicit confirmation.

Drill phase

  1. Verify authorization and inputs.
  2. Prepare an isolated workspace.
  3. Decrypt the artifact, then unpack the archive.
  4. Inspect summaries under ppk_data/sql/, ppk_data/data/, etc.; legacy layouts use data/sql/ and data/data/.
  5. Import the SQL dump into an isolated drill database.
  6. Run default or custom SQL checks; output JSON/text reports.

Drills do not in-place restore production, restart apps, or perform full DR failover. Log duration, missing dependencies, permission issues, and reports regularly.