ok so true OFFLINE backups are hard. but you can look at layered approaches or there's immutable backups etc.
I'm showing this because this works for more than backups.
and YES it's complex from an identity plane point of view (that's the whole point!)
now it gets complicated in the details. If you do this with servers/storage and locations you own Plane 4 can litterally be physically isolated at it's management/access plane. Think of a hypervisor and where the networks are physically split (outside of the requirement to have… twitter.com/i/web/status/1…
You could also do this and skip the remote repo and just wrap identity plane 2 in the same way 4 is working.
The point is: if you compromise plane 1 you don’t compromise plane 2. You can however affect the data on plane 2 by messing up the integrity of plane 1! (Confused yet) 😆… twitter.com/i/web/status/1…