
# Recovery and durability characteristics

## What SOL-42 proved

SOL-42 ran an **isolated deterministic** recovery certification service (not a full production DR exercise). Recorded scenarios include:

- Process SIGKILL and restart with intact run/approval state
- Worker lease recovery after kill
- Duplicate delivery suppression (single side effect)
- Database latency and outage fail-closed behavior
- Object storage interruption with idempotent retry
- Limiter and provider failover without double spend of budget
- Cancellation race without duplicate cancel events
- Backup hash restore with reference integrity

Evidence: `artifacts/certification/sol42-evidence.json`.

## What operators must not assume

- SOL-42 is **not** a measured production RPO/RTO for managed Supabase or object storage.
- Multi-region failover is not certified.
- Memory-only or local-disk stores that remain in deferred surfaces are not production canonical state.

## Gateway limiter durability

Distributed limiter behavior (rate, concurrency, reservation refund) is covered by SOL-22 unit tests and SOL-44 multi-instance load certification. Production Redis configuration remains an operations concern outside this doc page.
