153 lines
3.6 KiB
Markdown
153 lines
3.6 KiB
Markdown
# PSD Server — Survey Report
|
|
|
|
> Template only. The completed report and raw inventory remain in protected server storage. Do not
|
|
> include passwords, tokens, cookies, private keys, password hashes, raw claims, full container
|
|
> environments, patient-identifying data, or unbounded logs.
|
|
|
|
## Decision
|
|
|
|
- Project A private result: `SURVEY_GO_PROJECT_A_PRIVATE` / `SURVEY_NO_GO`
|
|
- Project B result: `SURVEY_GO_PROJECT_B` / `SURVEY_NO_GO`
|
|
- Timestamp UTC:
|
|
- Operator:
|
|
- Protected evidence path:
|
|
- Report SHA-256:
|
|
- Blocking unknowns by scope:
|
|
|
|
## Host
|
|
|
|
- OS/version/kernel:
|
|
- Architecture:
|
|
- Docker/Compose versions:
|
|
- CPU/RAM/free disk:
|
|
- Approved service UID/GID:
|
|
- Local terminal/CyberArk constraints:
|
|
|
|
## Legacy ThothII
|
|
|
|
- Source path/SHA/dirty state:
|
|
- Compose/controller path and project:
|
|
- Services/images:
|
|
- Published ports:
|
|
- Networks:
|
|
- Volumes/binds:
|
|
- Data/config/secret reference paths:
|
|
- Current health:
|
|
- Active sessions/users:
|
|
- Recovery/maintenance state:
|
|
- Backup procedure and owner:
|
|
- Exact stop/start commands:
|
|
|
|
## New installation roots
|
|
|
|
- Adjacent source root:
|
|
- Operator root:
|
|
- Secret root:
|
|
- Data root:
|
|
- Pi-state root:
|
|
- Workspace-registry root:
|
|
- Backup root:
|
|
- Protected evidence root:
|
|
- Port reserved for Project A:
|
|
|
|
## Nginx, TLS, and load balancer
|
|
|
|
- Nginx version/config owner:
|
|
- Relevant virtual-host/include files:
|
|
- Current ThothII upstream:
|
|
- Forwarded headers/SSE behavior:
|
|
- Certificate subject/SAN/issuer/expiry:
|
|
- Certificate generation/renewal owner:
|
|
- Load-balancer owner/config surface:
|
|
- Health check/TLS boundary/source addresses:
|
|
- Temporary hostname allowlist possible: yes/no
|
|
- Exact reload/rollback procedure:
|
|
|
|
## Aritmolab
|
|
|
|
- Public origin observed:
|
|
- Source/deployment path and SHA:
|
|
- Compose/network identity:
|
|
- Sidebar file/line/link target:
|
|
- Historical `.it`/`.com` discrepancy resolved as:
|
|
- Build/test/deploy procedure:
|
|
- Configuration owner:
|
|
|
|
## Authentik
|
|
|
|
- Installed version/image:
|
|
- Deployment path/services:
|
|
- Base URL/issuer conventions:
|
|
- Existing Aritmolab application/provider pattern:
|
|
- Groups relevant to ThothII:
|
|
- Credential reference paths and usability:
|
|
- Export/backup procedure:
|
|
- API/OpenAPI version:
|
|
- Required human help:
|
|
|
|
## Supabase/PostgreSQL
|
|
|
|
- Existing database name:
|
|
- PostgreSQL/pooler/PostgREST components:
|
|
- Direct container-to-database route:
|
|
- TLS mode/CA reference:
|
|
- Existing schemas:
|
|
- Existing `thoth_sessions` state:
|
|
- PostgREST exposed schemas:
|
|
- Backup/restore mechanism:
|
|
- Proposed runtime/migrator role names:
|
|
- Role-creation owner:
|
|
|
|
## PSD DWH
|
|
|
|
- Database/schema:
|
|
- Direct host/port from core:
|
|
- Runtime role reference:
|
|
- Read-only grant proof result:
|
|
- TLS requirements:
|
|
- REST binding retained for Mac:
|
|
|
|
## Workspace Git
|
|
|
|
- Remote/branch/access:
|
|
- Current main SHA:
|
|
- Server deploy-key scope:
|
|
- Descriptor schema/transports:
|
|
- Evidence/annotations state:
|
|
- Curator with push authority:
|
|
|
|
## Pi, LLM, Qdrant, and Ollama
|
|
|
|
- Pi version/provider/model/thinking:
|
|
- Credential reference:
|
|
- LLM endpoint reachability:
|
|
- Qdrant/Ollama image architecture support:
|
|
- Capacity assessment:
|
|
|
|
## Topology
|
|
|
|
Describe the observed final flow and every trust boundary. Reference a protected diagram if the
|
|
topology itself is considered sensitive.
|
|
|
|
## Intended changes by owner
|
|
|
|
| Owner/component | Exact files/objects | Project | Rollback |
|
|
|---|---|---|---|
|
|
| New ThothII | | A/B | |
|
|
| Workspace curator | | A | |
|
|
| Nginx | | A optional/B | |
|
|
| Load balancer | | A optional/B | |
|
|
| Aritmolab | | B | |
|
|
| Authentik | | B | |
|
|
| Supabase | | B | |
|
|
|
|
## GO/NO-GO rationale
|
|
|
|
- Verified old-stack rollback:
|
|
- Verified secret custody:
|
|
- Verified read-only DWH:
|
|
- Verified configuration owners:
|
|
- Verified resources:
|
|
- Unresolved risks:
|
|
- Final rationale:
|