Recovery Drill
ppk drill mysql is a MySQL recovery drill separate from production restore. It verifies decrypt, unpack, import, and app data dirs in isolation; it does not overwrite production by default.
Command Format:
ppk drill mysql \
--project-key <PROJECT_KEY> \
--backup-file <BACKUP_FILE> \
[--target-db-name <TARGET_DB_NAME>] \
[--config-home <CONFIG_HOME>] \
[--apply]
Without --apply, only print the drill plan—no download, decrypt, unpack, or DB import. Confirm target DB, workspace, and keys first:
ppk drill mysql \
--project-key project-a \
--backup-file /data/backups/project-a.ppke \
--target-db-name ppk_drill_project_a \
--config-home /etc/peppykeep/conf \
--prompt-for-private-key-passphrase \
--apply
General
--project-key: override the project id in config.--backup-file: local.ppk/.ppke, also.tar.gz/.tar.gz.enc; remote objects must be downloaded first.--target-db-name: drill target database; defaults toppk_drill_<project>_<timestamp>.--workspace-dir: workspace for download, decrypt, unpack, and reporting.--decrypt-private-key-file: private key used for encrypted artifacts.--check-sql-file: custom SQL validation script.--keep-workspace: keep the workspace on success; on failure it is kept by default for troubleshooting.--drop-target-db --confirm-target-db <NAME>: drop the drill DB only after explicit confirmation.
Drill phase
- Verify authorization and inputs.
- Prepare an isolated workspace.
- Decrypt the artifact, then unpack the archive.
- Inspect summaries under
ppk_data/sql/,ppk_data/data/, etc.; legacy layouts usedata/sql/anddata/data/. - Import the SQL dump into an isolated drill database.
- Run default or custom SQL checks; output JSON/text reports.
Drills do not in-place restore production, restart apps, or perform full DR failover. Log duration, missing dependencies, permission issues, and reports regularly.