Skip to content

docs: add volunteer guide for AWS ML pipeline backup and cleanup - #329

Open
arnoldcastro5000 wants to merge 6 commits into
masterfrom
docs/aws-ml-pipeline-backup-guide
Open

arnoldcastro5000 wants to merge 6 commits into
masterfrom
docs/aws-ml-pipeline-backup-guide

Conversation

@arnoldcastro5000

@arnoldcastro5000 arnoldcastro5000 commented Sep 15, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

This PR adds documentation only. It explains, in plain language for volunteers, how we safely back up an old and unused machine-learning system in our AWS account before we delete it to save cost. No infrastructure or code changes.

What this adds

A new docs folder docs/aws-ml-pipeline-backup/:

  • index.md - the volunteer guide. Written in simplified technical English, with a glossary of every AWS term. Covers what we back up, where it goes, the safety rule, the cost, and who does what.
  • runbook.md - the detailed engineer runbook (exact commands).
  • console-runbook.md - the same steps as clicks in the AWS web console, validated against AWS docs.
  • data-loss-risk-register.md - the safety reference: how backups can silently fail and how we prevent it.
  • A link to the guide from docs/index.md.

Why

The AWS account holds a dormant tree-image ML pipeline, idle about 15 months, costing roughly $500/month. Deleting it saves about $350 to $425/month. We must copy any real data to safe, cheap storage first. This documentation records that backup plan so any volunteer can understand and help run it.

Scope and status

  • Documentation only. No Terraform, Kubernetes, or code is touched.
  • The plan is not executed yet. Running it needs a person with AWS admin access to first create the archive bucket and IAM roles, and to turn on deletion protection for the old resources. The current account login is read-only.
  • Deleting the old system is a separate, later task, gated on a signed backup manifest.

How to review

Read docs/aws-ml-pipeline-backup/index.md first (about 5 minutes). It links the detailed runbooks. Check that the language is clear for a non-expert volunteer.

Notes

  • Account <ACCOUNT_ID>. Backup target: a new S3 bucket in eu-central-1, with versioning on, Glacier Instant Retrieval, kept indefinitely.

  • Console navigation was validated against AWS documentation on 2026-09-15.

  • Live re-check on 2026-09-23: the 18-resource inventory is unchanged. The re-check added a SETUP step to protect the sources (RDS deletion protection, DeleteOnTermination=false on the EBS root volumes, EC2 termination protection), made the stop of the 2 running instances mandatory, and added a Spot-request warning for i-04b.

  • 2026-09-23: the archive bucket now has versioning on (was off). Reason: the Deny-delete bucket policy can be removed by any of the 7 IAM users plus root that have s3:PutBucketPolicy, and the archive becomes the only copy after the sources are deleted.

  • 2026-09-23: the archive bucket policy now also denies lifecycle, versioning, policy and bucket-delete changes (except the break-glass role), because a lifecycle Expiration rule can delete objects without the delete APIs. SETUP applies the policy last. Validated with IAM Access Analyzer (0 findings).

Add a plain-language guide, written in simplified technical English for
volunteers, explaining how we back up an old, unused machine-learning
system in the AWS account before deleting it to save cost.

Includes:
- docs/aws-ml-pipeline-backup/index.md - volunteer guide with a glossary
- docs/aws-ml-pipeline-backup/runbook.md - detailed engineer runbook
- docs/aws-ml-pipeline-backup/console-runbook.md - AWS console clickpaths
- docs/aws-ml-pipeline-backup/data-loss-risk-register.md - safety reference
- link from docs/index.md

Documentation only. No infrastructure or code changes.
Remove the 12-digit AWS account ID from the volunteer guide and the
runbooks, including where it appeared inside the archive bucket name and
IAM ARNs. Replace every occurrence with <ACCOUNT_ID>. Resource IDs are
kept. No functional change; documentation only.
@arnoldcastro5000 arnoldcastro5000 self-assigned this Sep 15, 2026
Move all account-specific values into a 'Configuration' block at the top
of each runbook and use tokens ($ACCOUNT_ID, $ARCHIVE_BUCKET,
$UNLOAD_ROLE_ARN, $BREAKGLASS_ROLE_ARN) in the body. No IAM ARN now
carries an account ID. The volunteer guide drops the account number and
refers to the bucket generically. Also de-link two template files that
are not part of this docs set, to avoid broken links.
@arnoldcastro5000
arnoldcastro5000 marked this pull request as ready for review September 15, 2026 01:01
A live re-check on 2026-09-23 found the inventory unchanged, but no
source had deletion protection:

- Add a SETUP step to enable RDS deletion protection on both
  databases, set 7-day retention on eu-north-1, set
  DeleteOnTermination=false on the 4 EBS root volumes, and enable
  termination protection on the On-Demand instances.
- Make the stop of running instances i-04b and i-0e1 mandatory
  before the snapshot (both write 0.2-0.8 GB per day).
- Warn that i-04b is a persistent Spot instance: cancelling its
  disabled Spot request while it is stopped terminates it.
- Record the new vector in the data-loss risk register.
The archive relied on a Deny-delete bucket policy that any principal
with s3:PutBucketPolicy can remove. An IAM scan on 2026-09-23 found 7
IAM users plus root with that permission, most without MFA. After the
sources are deleted, the archive is the only copy.

- Enable bucket versioning at creation (Object Lock stays off; it
  can be added later without a new bucket).
- Transition noncurrent versions to Glacier Instant Retrieval too;
  keep zero Expiration and no NoncurrentVersionExpiration rules.
- Note that MFA Delete cannot be used with a lifecycle rule.
- Update the risk register and the volunteer guide.
IAM Access Analyzer found no syntax issue, but the Deny on the delete
APIs alone does not stop deletes. A lifecycle Expiration rule deletes
objects without those APIs, and AWS requires a Deny on
s3:PutLifecycleConfiguration to block deletes. The policy, versioning
and bucket-delete actions were also open, so an admin could remove
the protection first.

- Add a Deny on PutLifecycleConfiguration, PutBucketVersioning,
  PutBucketPolicy, DeleteBucketPolicy and DeleteBucket for every
  principal except the break-glass role.
- Reorder SETUP: bucket, lifecycle rule, IAM roles, then the bucket
  policy last.
- Document how to create the archive-breakglass role (MFA-only
  trust, root path).
- Fix the DataSync step reference (4.2, not 3.2).

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant