Back up the complete service
Include the database, filestore, configuration, custom source references and the secrets recovery process. Missing attachments can make a database-only restore unusable.
Keep copies apart
Use encrypted off-site retention and protect deletion rights. Document who can access backups and how credentials are recovered during an incident.
Verify every artifact
Record size, timestamp, checksum and archive listing. Alerts must distinguish a job that ran from a backup that was actually produced.
Practice restoration
Restore into isolation, start Odoo, open representative documents and run critical journeys. Measure the observed recovery time and remaining manual actions.
Review after change
Repeat the exercise after major upgrades, storage changes or new integrations. Recovery documentation should be usable by someone other than its author.