docs: plan PSD server deployment program
This commit is contained in:
@@ -0,0 +1,151 @@
|
||||
# PSD Server — Survey Report
|
||||
|
||||
> Template only. The completed report and raw inventory remain in protected server storage. Do not
|
||||
> include passwords, tokens, cookies, private keys, password hashes, raw claims, full container
|
||||
> environments, patient-identifying data, or unbounded logs.
|
||||
|
||||
## Decision
|
||||
|
||||
- Result: `SURVEY_GO` / `SURVEY_NO_GO`
|
||||
- Timestamp UTC:
|
||||
- Operator:
|
||||
- Protected evidence path:
|
||||
- Report SHA-256:
|
||||
- Blocking unknowns:
|
||||
|
||||
## Host
|
||||
|
||||
- OS/version/kernel:
|
||||
- Architecture:
|
||||
- Docker/Compose versions:
|
||||
- CPU/RAM/free disk:
|
||||
- Approved service UID/GID:
|
||||
- Local terminal/CyberArk constraints:
|
||||
|
||||
## Legacy ThothII
|
||||
|
||||
- Source path/SHA/dirty state:
|
||||
- Compose/controller path and project:
|
||||
- Services/images:
|
||||
- Published ports:
|
||||
- Networks:
|
||||
- Volumes/binds:
|
||||
- Data/config/secret reference paths:
|
||||
- Current health:
|
||||
- Active sessions/users:
|
||||
- Recovery/maintenance state:
|
||||
- Backup procedure and owner:
|
||||
- Exact stop/start commands:
|
||||
|
||||
## New installation roots
|
||||
|
||||
- Adjacent source root:
|
||||
- Operator root:
|
||||
- Secret root:
|
||||
- Data root:
|
||||
- Pi-state root:
|
||||
- Workspace-registry root:
|
||||
- Backup root:
|
||||
- Protected evidence root:
|
||||
- Port reserved for Project A:
|
||||
|
||||
## Nginx, TLS, and load balancer
|
||||
|
||||
- Nginx version/config owner:
|
||||
- Relevant virtual-host/include files:
|
||||
- Current ThothII upstream:
|
||||
- Forwarded headers/SSE behavior:
|
||||
- Certificate subject/SAN/issuer/expiry:
|
||||
- Certificate generation/renewal owner:
|
||||
- Load-balancer owner/config surface:
|
||||
- Health check/TLS boundary/source addresses:
|
||||
- Temporary hostname allowlist possible: yes/no
|
||||
- Exact reload/rollback procedure:
|
||||
|
||||
## Aritmolab
|
||||
|
||||
- Public origin observed:
|
||||
- Source/deployment path and SHA:
|
||||
- Compose/network identity:
|
||||
- Sidebar file/line/link target:
|
||||
- Historical `.it`/`.com` discrepancy resolved as:
|
||||
- Build/test/deploy procedure:
|
||||
- Configuration owner:
|
||||
|
||||
## Authentik
|
||||
|
||||
- Installed version/image:
|
||||
- Deployment path/services:
|
||||
- Base URL/issuer conventions:
|
||||
- Existing Aritmolab application/provider pattern:
|
||||
- Groups relevant to ThothII:
|
||||
- Credential reference paths and usability:
|
||||
- Export/backup procedure:
|
||||
- API/OpenAPI version:
|
||||
- Required human help:
|
||||
|
||||
## Supabase/PostgreSQL
|
||||
|
||||
- Existing database name:
|
||||
- PostgreSQL/pooler/PostgREST components:
|
||||
- Direct container-to-database route:
|
||||
- TLS mode/CA reference:
|
||||
- Existing schemas:
|
||||
- Existing `thoth_sessions` state:
|
||||
- PostgREST exposed schemas:
|
||||
- Backup/restore mechanism:
|
||||
- Proposed runtime/migrator role names:
|
||||
- Role-creation owner:
|
||||
|
||||
## PSD DWH
|
||||
|
||||
- Database/schema:
|
||||
- Direct host/port from core:
|
||||
- Runtime role reference:
|
||||
- Read-only grant proof result:
|
||||
- TLS requirements:
|
||||
- REST binding retained for Mac:
|
||||
|
||||
## Workspace Git
|
||||
|
||||
- Remote/branch/access:
|
||||
- Current main SHA:
|
||||
- Server deploy-key scope:
|
||||
- Descriptor schema/transports:
|
||||
- Evidence/annotations state:
|
||||
- Curator with push authority:
|
||||
|
||||
## Pi, LLM, Qdrant, and Ollama
|
||||
|
||||
- Pi version/provider/model/thinking:
|
||||
- Credential reference:
|
||||
- LLM endpoint reachability:
|
||||
- Qdrant/Ollama image architecture support:
|
||||
- Capacity assessment:
|
||||
|
||||
## Topology
|
||||
|
||||
Describe the observed final flow and every trust boundary. Reference a protected diagram if the
|
||||
topology itself is considered sensitive.
|
||||
|
||||
## Intended changes by owner
|
||||
|
||||
| Owner/component | Exact files/objects | Project | Rollback |
|
||||
|---|---|---|---|
|
||||
| New ThothII | | A/B | |
|
||||
| Workspace curator | | A | |
|
||||
| Nginx | | A optional/B | |
|
||||
| Load balancer | | A optional/B | |
|
||||
| Aritmolab | | B | |
|
||||
| Authentik | | B | |
|
||||
| Supabase | | B | |
|
||||
|
||||
## GO/NO-GO rationale
|
||||
|
||||
- Verified old-stack rollback:
|
||||
- Verified secret custody:
|
||||
- Verified read-only DWH:
|
||||
- Verified configuration owners:
|
||||
- Verified resources:
|
||||
- Unresolved risks:
|
||||
- Final rationale:
|
||||
Reference in New Issue
Block a user