Backup freshness
Daily ACM backups complete, but the latest recorded backup can still fail a strict two-hour drill RPO. Create a fresh backup immediately before an activation drill unless a looser RPO is accepted.
hub-dc is the active management cluster for the lab fleet. It owns ACM/MCE management, platform GitOps, hub backup scheduling, and current managed-cluster placement decisions.
Status
4.20.18.hub-dc-cluster-config recorded Synced/Healthy after the latest remediation sequence.acm-dpa reconciled, acm-dpa-1 available, hub-backup-daily enabled.hub-dr is no longer a managed cluster on hub-dc. Current managed pull placement selects spokes only.cluster-monitoring-config; no user workload monitoring pods should run on this hub.Storage
Hub storage was intentionally reduced. LVMS and RHACS remain. ODF/NooBaa, Pipelines/Tekton Results, logging, tracing, MinIO/Loki/Tempo, OpenTelemetry, Cluster Observability, and Network Observability were removed from hub live state.
lvms-vg1 is the remaining hub storage class.lvms-vg1./dev/vdb, /dev/vdc, and /dev/vdd.Risk
Daily ACM backups complete, but the latest recorded backup can still fail a strict two-hour drill RPO. Create a fresh backup immediately before an activation drill unless a looser RPO is accepted.
Hub-side managed-pull status for spoke-dr-cluster-config can remain confusing or stale. Prefer local spoke Argo status for managed-pull app truth.
A previous GitLab reachability issue was caused by stale conflicting IPs on the HAProxy VM. That was remediated and GitLab route reachability was validated.
Do not begin restore activation from hub-dc to hub-dr without explicit approval because managed cluster ownership can move.
Validation
export KUBECONFIG=<hub-dc-kubeconfig>
oc get clusterversion
oc -n open-cluster-management get mch
oc get mce
oc -n open-cluster-management-backup get dpa,bsl,backupschedule
oc -n openshift-gitops get applications.argoproj.io