feat(poc): rewind MCP, skill, and recover-ladder docs
Initial PoC: find_protection, tagged checkpoints, FLR, mutating catalog. Lab 10.9 status enums (0=Initializing, 1=MeetingSLA). Credentials stay in gitignored config.json.
This commit is contained in:
@@ -0,0 +1,54 @@
|
||||
---
|
||||
name: zerto-rewind
|
||||
description: Before changing a VM, find its Zerto VPGs and insert a tagged checkpoint. Recover files from that tag with FLR after a human confirms. Use whenever an agent will mutate a guest that might be protected by Zerto.
|
||||
---
|
||||
|
||||
# Zerto rewind
|
||||
|
||||
Zerto already journals the VM. This skill makes the agent use that journal. Git does not have the guest file. Official ZVM MCP does not insert tagged checkpoints.
|
||||
|
||||
You talk to **one** MCP: `zerto_rewind_mcp`. Do not also require official ZVM MCP.
|
||||
|
||||
## Loop (mandatory)
|
||||
|
||||
Before **every** guest-mutating tool call:
|
||||
|
||||
1. Take the hostname / VM name / Zerto `vmIdentifier` from the tool args.
|
||||
2. Call `zerto_guard_before_mutate` (or `zerto_find_protection` then `zerto_create_tagged_checkpoint`).
|
||||
3. If `ok` is not true: **stop**. Do not mutate.
|
||||
4. Then run the mutating call.
|
||||
|
||||
Reads skip the guard.
|
||||
|
||||
Unlisted MCP tools pass through. If you are about to change a protected VM with a tool that is not in the catalog, call `zerto_add_mutating_tool` (server, tool, `vm_arg`) and then guard.
|
||||
|
||||
## find_protection outcomes
|
||||
|
||||
| outcome | what you do |
|
||||
|---|---|
|
||||
| none | Unprotected or unknown. Refuse the change. Say Zerto cannot rewind this. |
|
||||
| ambiguous | Two or more VMs matched. Ask for a `vmIdentifier`. Do not guess. |
|
||||
| ok, no taggable VPG | Syncing or not Protecting. Refuse. A resync deletes checkpoints. |
|
||||
| ok, taggable VPGs | Tag **every** protecting VPG with the same tag. Wait until listed (the tool blocks). |
|
||||
|
||||
A VM can be in up to three VPGs (local backup + remote DR is common). Tag all of them.
|
||||
|
||||
## Recover
|
||||
|
||||
Human must confirm. Pass `confirmed=true` only after they say yes.
|
||||
|
||||
- Bad config / dropped file: `zerto_recover_file` from **that tag**.
|
||||
- Inspect a whole VM: `zerto_offsite_clone` or `zerto_start_failover_test`.
|
||||
- Never Failover Live. Never Move. Those are DR, not rewind.
|
||||
|
||||
## Facts that bite
|
||||
|
||||
- A tagged checkpoint is crash-consistent, not app-quiesced.
|
||||
- Tagged checkpoints are not supported when the **protected** site is Azure or AWS. Talk to the vSphere protected ZVM.
|
||||
- 10.9 FLR Operator RBAC fails; Administrator is the documented workaround.
|
||||
- FLR cannot run during clone, test, live failover, or EJC.
|
||||
- Linux FLR: files >1.5GB are a bad idea; some characters in names are refused.
|
||||
|
||||
## Tag
|
||||
|
||||
Default: `ai:<agent>:<change-id>:<utc>`. Same string on every VPG for that call.
|
||||
Reference in New Issue
Block a user