Prepare access without secrets
Keep the SSH private key locally. Supply only a supported public key, or choose later setup. Record the intended username, hostname and a second recovery path.
Name the recoverable set
List the database, uploads, runtime configuration and non-secret deployment record. A backup label is not proof that all four are recoverable.
Define one isolated restore
Choose a disposable directory or database, one record or file to verify, and a stop condition that prevents production overwrite.
Example readiness note
“Public key tested locally; app database plus uploads exported; restore target is a separate test database; success is one normal read.” Keep this note with the selected plan.
Documentation used
Primary references for this page. Check the documentation for the version installed in your own environment.