The summary.
MONITOR FROM OUTSIDE
A service cannot reliably report its own unavailability.
Send alerts somewhere independent of the service being monitored.
DURING A PROVIDER OUTAGE
Tell affected people before they discover it, and change nothing in your own configuration.
Reconfiguring in response to someone else's outage produces a second problem to fix afterwards.
WHAT RESILIENCE ACTUALLY REQUIRES AT SMALL SCALE
Your own backups, a fallback connection, and knowing what you would do for a day without each service.
Not multi-provider architecture. Complexity causes more outages than it prevents at this size.
KEEP THE PLAN OUTSIDE THE CLOUD
A continuity plan stored only in the service that failed is not a plan.
WATCH FOR PROVIDER CHANGES
Deprecations, pricing and terms change without you deciding anything, and the notices arrive at the account address.
That address must be read.
WHEN LEAVING
Export and verify first, run both briefly, then cancel.
Cancelling first loses access and frequently the data. Establish the retention period before you cancel.
REVIEW ANNUALLY
Would we adopt this again today, at this price, on these terms?