{"slug":"alibaba-live-rds-polardb-mutation-guard","title":"alibaba-live-rds-polardb-mutation-guard","summary":"Gate RDS/PolarDB instance deletion, spec downgrade, and backup policy removal — database deletion without verified backup is permanently destructive.","platform":"Claude","tags":[],"authorName":"LLM Mart","authorSlug":"llm-mart","score":0,"source":"github","price":null,"verified":false,"createdAt":"2026-10-05T21:50:46.645951Z","repo":{"url":"https://github.com/VincentChuWaiChow/vanguard-frontier-agentic","stars":24,"forks":3,"license":"Apache-2.0","updatedAt":"2026-10-05T13:00:24Z"},"bodyHtml":"<hr>\n<h2>name: alibaba-live-rds-polardb-mutation-guard\ndescription: Gate RDS/PolarDB instance deletion, spec downgrade, and backup policy removal — database deletion without verified backup is permanently destructive.\nallowed-tools: Read Grep Glob\nmetadata:\nauthor: \"github: VincentChuWaiChow\"\nversion: \"0.1.0\"\nupdated: \"2026-05-08\"\ncategory: database</h2>\n<h1>Alibaba Cloud Live RDS/PolarDB Mutation Guard</h1>\n<h2>Purpose</h2>\n<p>Act as the guarded live Alibaba Cloud operator for alibaba-live-rds-polardb-mutation-guard work. Gate every RDS or PolarDB instance deletion, spec downgrade, and backup policy removal with a complete backup verification and explicit operator approval. Treat database deletion without verified backup as an irreversible data-loss event.</p>\n<h2>When to Use</h2>\n<p>Use this skill when:</p>\n<ul>\n<li>An RDS or PolarDB instance deletion is being requested</li>\n<li>A spec downgrade (instance type reduction) is being planned for an RDS or PolarDB instance</li>\n<li>A backup policy is being removed or modified to reduce retention period or disable automated backups</li>\n<li>An operator needs to verify backup status and restore readiness before any destructive database operation</li>\n<li>A database endpoint or high-availability configuration change is being made during business hours</li>\n</ul>\n<h2>When NOT to Use</h2>\n<p>Do not use this skill when:</p>\n<ul>\n<li>The task is a read-only RDS/PolarDB audit with no mutation intent</li>\n<li>The task involves only SQL query execution or data-level operations</li>\n<li>The task involves creating a new RDS/PolarDB instance (no existing data at risk)</li>\n<li>The task involves minor parameter group changes that do not affect availability or data retention</li>\n</ul>\n<h2>Key Risk Facts</h2>\n<ul>\n<li><strong>RDS/PolarDB instance deletion</strong> removes all instance data, parameter groups, and backups associated with the instance immediately upon deletion (backups may have a brief retention window depending on configuration — verify explicitly). This action cannot be reversed.</li>\n<li><strong>Spec downgrade during peak hours</strong> causes connection resets and query timeouts during the instance resize window. Downgrading to an instance type that cannot handle current load causes cascading failures in dependent applications.</li>\n<li><strong>Backup policy removal</strong> leaves the database unprotected for the period between the last backup and the next backup cycle. If the instance fails during this window, data from that period is lost.</li>\n<li><strong>All three actions</strong> require the 6-step live-guard gate: (1) identity confirm, (2) backup verification, (3) blast radius assessment, (4) explicit approval, (5) execution, (6) post-change verification.</li>\n</ul>\n<h2>Pre-Flight Checklist</h2>\n<p>Before executing any RDS or PolarDB mutation, verify all of the following:</p>\n<ol>\n<li><strong>Instance identity confirmed</strong> — confirm the exact instance ID, region, engine type (MySQL/PG/SQL Server/MariaDB for RDS; MySQL/PG/Oracle for PolarDB), and account. Run <code>aliyun rds DescribeDBInstances</code> or check PolarDB console to confirm.</li>\n<li><strong>Backup existence verified</strong> — confirm a recent automated or manual backup exists. Check: backup creation time, backup status (Completed), backup size, and retention period. A backup that cannot be listed is not a verified backup.</li>\n<li><strong>Restore tested or documented</strong> — for critical instances, verify the backup is restorable by checking the last restore test date. If never tested, flag as high risk.</li>\n<li><strong>Current spec and load assessed</strong> — for downgrade: compare current CPU/memory/IOPS utilization to the target spec limits. If current utilization is within 20% of target spec limits, the downgrade is high risk.</li>\n<li><strong>Blast radius assessed</strong> — which applications depend on this instance? what is the connection string? what downstream services will fail during the maintenance window?</li>\n<li><strong>Change window confirmed</strong> — spec downgrades and deletions should be executed during a planned maintenance window with application owners notified.</li>\n</ol>\n<h2>Required Confirmation</h2>\n<p>The operator must explicitly state all of the following before any mutation is executed:</p>\n<ul>\n<li>\"I confirm the instance is <code>&lt;INSTANCE_ID&gt;</code> of type <code>&lt;ENGINE&gt;</code> in region <code>&lt;REGION&gt;</code> in account <code>&lt;ACCOUNT_ID&gt;</code>.\"</li>\n<li>\"I have verified a backup exists: backup ID <code>&lt;BACKUP_ID&gt;</code>, created at <code>&lt;TIMESTAMP&gt;</code>, status <code>&lt;Completed&gt;</code>.\"</li>\n<li>\"I have assessed the blast radius: <code>&lt;DESCRIPTION OF DEPENDENT APPLICATIONS&gt;</code>.\"</li>\n<li>\"I understand that instance deletion is permanent and all data will be irrecoverable without a verified backup.\"</li>\n<li>\"I approve this <code>&lt;deletion / spec downgrade / backup policy change&gt;</code>.\"</li>\n<li>For deletion: \"I confirm the backup is restorable and all dependent applications have been notified.\"</li>\n<li>For spec downgrade: \"I confirm the current peak utilization is <code>&lt;RATE&gt;%</code> of the target spec and the change window is <code>&lt;WINDOW&gt;</code>.\"</li>\n</ul>\n<h2>Execution Steps</h2>\n<ol>\n<li>Capture pre-change instance state: instance metadata, current spec, backup list.</li>\n<li>Verify backup status and restore readiness.</li>\n<li>Present the planned action, backup verification results, and blast radius to the operator for explicit approval.</li>\n<li>Execute the mutation:\n<ul>\n<li>Delete instance: <code>aliyun rds DeleteDBInstance --DBInstanceId &lt;ID&gt;</code> or PolarDB equivalent.</li>\n<li>Spec downgrade: <code>aliyun rds ModifyDBInstanceSpec</code> or PolarDB <code>ModifyDBNodeClass</code> — schedule during maintenance window.</li>\n<li>Backup policy change: <code>aliyun rds ModifyBackupPolicy</code> or PolarDB equivalent.</li>\n</ul>\n</li>\n<li>Confirm the action is completed and document the result.</li>\n</ol>\n<h2>Rollback Procedure</h2>\n<ul>\n<li><strong>Backup policy change</strong> (reversible): Restore the previous backup policy settings immediately.</li>\n<li><strong>Spec downgrade</strong> (reversible): Re-upgrade to the previous spec via <code>aliyun rds ModifyDBInstanceSpec</code>. Note: re-upgrade takes time and a connection reset occurs again.</li>\n<li><strong>Instance deletion</strong> (NOT reversible without backup): If a backup exists, restore from backup to a new instance. Restoration takes time proportional to database size. The original endpoint is gone — applications must be reconfigured to the new instance endpoint.</li>\n<li><strong>Instance deletion without backup</strong> (NOT reversible): There is no recovery path. Contact Alibaba Cloud Support immediately — recovery is not guaranteed.</li>\n</ul>\n<h2>Post-Change Verification</h2>\n<ol>\n<li>For deletion: confirm instance is removed from the console and DNS no longer resolves.</li>\n<li>For spec downgrade: confirm the new instance spec is active and monitor CPU/memory/IOPS metrics for the first 30 minutes.</li>\n<li>For backup policy change: confirm the new policy is active and the next backup is scheduled.</li>\n<li>Check ActionTrail for the database mutation event.</li>\n<li>Monitor CloudMonitor for application-level connection errors or latency spikes.</li>\n</ol>\n<h2>Response Shape</h2>\n<ol>\n<li>Instance ID, engine type, region, and account confirmed</li>\n<li>Backup existence and restore readiness verified</li>\n<li>Blast radius and dependent application assessment</li>\n<li>Change window and load assessment (for spec downgrade)</li>\n<li>Operator confirmation received</li>\n<li>Execution confirmation</li>\n<li>Post-change monitoring results</li>\n</ol>\n","files":[{"path":"metadata.json","sizeBytes":887,"isText":true},{"path":"references/official-sources.md","sizeBytes":578,"isText":true},{"path":"references/workflow-and-output.md","sizeBytes":1717,"isText":true},{"path":"SKILL.md","sizeBytes":6895,"isText":true}],"reviewScore":null,"reviewSummary":null,"trust":{"provenance":"trusted-source-unreviewed","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow.","bodySource":null},"bodyLocked":false,"purchaseUrl":null,"sourceUrl":null,"report":{"provenance":"trusted-source-unreviewed","screen":{"ran":true,"outcome":"clean","suspicious":0,"notes":0,"hiddenCharacters":false},"virusScan":{"engine":"clamav","status":"clean","scannedAt":"2026-10-05T21:51:57.870064Z","sha256":"567BEA77A735A236EF42F9D51A607270F1790619F2DDDB6EC7063F164A851485","sizeBytes":4812},"review":null,"source":{"repositoryUrl":"https://github.com/VincentChuWaiChow/vanguard-frontier-agentic","path":"skills/alibaba/alibaba-live-rds-polardb-mutation-guard","license":"Apache-2.0","commit":"febe32a08e78fd06b1e466187410d673f1958d87","subtreeSha":"AB70B4AE9EF8BF5306FA3D8F5207E7C418EFCD76CAEDD373B967F1A0BC214474","lastSyncedAt":"2026-10-05T21:51:58.639905Z"},"reviewedAt":"2026-10-05T21:53:57.595334Z","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow."},"install":[{"target":"skills-cli","command":"npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/alibaba/alibaba-live-rds-polardb-mutation-guard"},{"target":"claude-code","command":"claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart"},{"target":"git","command":"git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git"}]}