Hserver Failure Notes: Backup and DR · intermediate
A Backup Timer Firing Is Not Proof That the Backup Finished
Scheduling evidence and completion evidence belong to different layers of a batch job.
Backup services are bounded by timeouts and successful runs emit protected receipts or complete timestamped sets that posture checks can validate independently of the timer history.
The managed backup units made scheduling explicit, but a timer activation only proves that systemd attempted to start the service. It does not prove PostgreSQL dumped successfully, archives completed or checksums were written. Trigger state and job outcome were being conflated. Batch reliability requires a durable completion signal from the work itself.
Reliable batch systems separate scheduler health, execution health and output validity. Each stage can fail while the others look normal.
Alert on missing recent completion receipts, not just failed timers. A scheduler that runs perfectly can repeatedly launch a job that never produces a recovery point. The concrete hserver evidence is commit a4e34d2, so this note is tied to an actual production change rather than a hypothetical failure.