Backup schedule
Verified full-store backup and empty-store auto-restore
AETHER can create verified full-store recovery snapshots on a ten-hour schedule. Auto-restore only activates for a genuinely missing/new empty store, never over a non-empty store.
The recovery worker targets a verified full-store backup every ten hours and keeps a bounded history. Backup creation runs outside the public RC request worker.
A completed backup receives a tree digest and is verified before becoming eligible for restore. Incomplete backups are ignored.
A missing or genuinely brand-new empty AETHER store can restore from the newest verified backup. Historical/tombstoned/corrupt non-empty stores are not automatically overwritten.
Operators can explicitly disable auto-restore for a planned empty reset. This prevents a deliberate wipe from immediately restoring old data.