A backup you never restored is a rumor
Updated

Backups count only after a restore test: checksum the archive, restore to scratch, and verify the content opens.
Everyone has backups until the day they need them. Then the archive is truncated, the wrong directory was captured, or the restore procedure exists only in one person's memory. A backup becomes real through one ritual: restore it somewhere harmless and prove the content opens.
The restore ritual
Version the archive. Dated names beat overwriting one file forever. Keep enough generations to survive discovering corruption late.
Checksum at creation. Hash the archive the moment it is written and store the hash beside it. Verify before every restore; a mismatch stops the ritual before false hope.
Restore to scratch and open the content. Extract into an empty directory and actually read the files: list them, open the important ones, count rows where rows matter. A green extract with garbage inside is still a failure.
Worked example: a fictional fixture backup
The context below is fictional. Fictional job nightly-fixtures (fictional) archives /srv/fixtures into a dated file with a checksum. One morning the checksum mismatches: the disk filled mid-write and truncated the archive.
Because the ritual runs before trust, nobody discovers this during a real incident. The fix is retention plus alerting on the checksum step, and the proof is a scratch restore that opens every fixture file.
Checklist: a backup worth its name
- Dated, versioned archives with stored checksums.
- Restore tested to scratch on schedule.
- Content opened and verified, not just extracted.
- Checksum failures alert before anyone needs the data.
Related reading
- Hands on: Backup, Restore, Verify Checksum.
- DevOps Foundations Module 4 covers the storage sequence.
Straight answers
Frequently asked questions
How often should I test restores?
Every backup generation change, and on a schedule otherwise. An untested change to the backup job voids all previous confidence.
Checksum or just file size?
Checksum. Size matches on truncated and corrupted archives; a hash does not.
Where should the restore test go?
Scratch space, never over live data. A restore test that can overwrite production is a second disaster.