From 3d487e085021e9323e85b457dff45bb433681f84 Mon Sep 17 00:00:00 2001 From: "Claude (agent)" Date: Tue, 22 Sep 2026 19:39:06 -0400 Subject: [PATCH] docs: tagged checkpoints do work on cloud-protected VPGs (#11) --- README.md | 17 ++++++++++++++++- skills/zerto-rewind/SKILL.md | 5 ++++- src/zerto_rewind_mcp/checkpoints.py | 5 ++++- src/zerto_rewind_mcp/protection.py | 3 +-- src/zerto_rewind_mcp/server.py | 5 +++-- src/zerto_rewind_mcp/status.py | 3 +-- 6 files changed, 29 insertions(+), 9 deletions(-) diff --git a/README.md b/README.md index 00512a6..fce53cf 100644 --- a/README.md +++ b/README.md @@ -64,7 +64,22 @@ Git never had the file. RPO is the journal, not last night's backup. vSphere ZVM 10.x and ZCA on AWS/Azure, same REST paths. HVM is out (separate swagger). Failover Live is not a tool. -Tagged checkpoints cannot be inserted when the **protected** site is Azure or AWS (Zerto API). Point this server at the vSphere protected ZVM. +Tagged checkpoints **do** work when the protected site is Azure or AWS. The 9.0 API +reference says they cannot be inserted; that is wrong on 10.9.10, where both were +accepted and the task reached `Completed`. + +What differs is latency and granularity, both set by the **protected** site: + +| protected at | journal gap | tag visible after | +|---|---|---| +| vSphere | 5s | ~4s | +| Azure | 60s | ~34s | +| AWS | 630s | ~128s | + +The tagged checkpoint is also stamped about 30s *after* the insert request, so on a +cloud-protected VPG a prompt mutation can land *inside* the checkpoint meant to +precede it. Recover from the newest checkpoint that already existed when the guard +ran, not from the tag. ## Not this product diff --git a/skills/zerto-rewind/SKILL.md b/skills/zerto-rewind/SKILL.md index 4360870..d57c3f2 100644 --- a/skills/zerto-rewind/SKILL.md +++ b/skills/zerto-rewind/SKILL.md @@ -70,7 +70,10 @@ so a stuck session blocks the next recovery. Find it with ## Facts that bite - A tagged checkpoint is crash-consistent, not app-quiesced. -- Tagged checkpoints are not supported when the **protected** site is Azure or AWS. Talk to the vSphere protected ZVM. +- Tagged checkpoints work on Azure and AWS protected VPGs, but they appear late: + ~34s (Azure) and ~128s (AWS) versus ~4s on vSphere, and the checkpoint is stamped + about 30s after you ask for it. On those VPGs the tag can end up *after* your + change, so treat the newest checkpoint that already existed as the rewind point. - 10.9 FLR Operator RBAC fails; Administrator is the documented workaround. - FLR cannot run during clone, test, live failover, or EJC. - Linux FLR: files >1.5GB are a bad idea; some characters in names are refused. diff --git a/src/zerto_rewind_mcp/checkpoints.py b/src/zerto_rewind_mcp/checkpoints.py index 32413ba..3c61129 100644 --- a/src/zerto_rewind_mcp/checkpoints.py +++ b/src/zerto_rewind_mcp/checkpoints.py @@ -93,7 +93,10 @@ async def wait_for_tag( raise ZertoError( f"Tagged checkpoint {tag!r} did not appear on VPG {vpg_identifier} " f"within {timeout_s:.0f}s. Do not mutate. " - "If the protected site is Azure or AWS, tagged checkpoints are not supported." + "On a cloud-protected VPG the tag routinely takes longer than this to appear " + "(measured ~34s on Azure, ~128s on AWS), so this timeout may simply be too " + "short rather than the insert having failed. Check the Zerto task before " + "assuming it did not land." ) diff --git a/src/zerto_rewind_mcp/protection.py b/src/zerto_rewind_mcp/protection.py index 0e50d2a..9c5514c 100644 --- a/src/zerto_rewind_mcp/protection.py +++ b/src/zerto_rewind_mcp/protection.py @@ -137,8 +137,7 @@ def find_from_rows(query: str, rows: list[dict[str, Any]]) -> FindResult: outcome="none", query=query, message=( - f"VM {vm.vm_name} ({vm.vm_identifier}) has no VPG. " - "Unprotected: refuse the change." + f"VM {vm.vm_name} ({vm.vm_identifier}) has no VPG. Unprotected: refuse the change." ), vm=vm, ) diff --git a/src/zerto_rewind_mcp/server.py b/src/zerto_rewind_mcp/server.py index 887cd35..f68af1e 100644 --- a/src/zerto_rewind_mcp/server.py +++ b/src/zerto_rewind_mcp/server.py @@ -133,8 +133,9 @@ async def zerto_create_tagged_checkpoint( the Zerto API accepts, so this is the only place that context can live. Name format: ai: | | vm= | change= | - Docs: tagged checkpoints are not supported when the protected site is Azure or AWS; - run this against the vSphere protected ZVM. + Works on Azure and AWS protected VPGs despite what the 9.0 API reference says, + but the tag appears late there (~34s Azure, ~128s AWS) and is stamped after the + request, so it may sit after a prompt mutation. """ try: result = await _find(query) diff --git a/src/zerto_rewind_mcp/status.py b/src/zerto_rewind_mcp/status.py index ff25f6a..d379a87 100644 --- a/src/zerto_rewind_mcp/status.py +++ b/src/zerto_rewind_mcp/status.py @@ -127,7 +127,6 @@ def can_tag(status: int | None, substatus: int | None) -> tuple[bool, str | None return False, f"VPG status is {status_name(status)}; not MeetingSLA" if substatus in SYNCING: return False, ( - f"VPG is {substatus_name(substatus)}; " - "checkpoints are not durable until sync ends" + f"VPG is {substatus_name(substatus)}; checkpoints are not durable until sync ends" ) return True, None