Operations
Access and administration
The workspace is local-only. Keep administration on the local deployment path and do not rely on email delivery, public access, or external notification flows.
The bootstrap administrator is loca@localhost. Because invitations, password resets, and account recovery are unavailable, confirm that this account can sign in before changing its credentials or its administrative role. Maintain a documented, tested local recovery procedure before making any access-affecting change.
There is no OMP reviewer in the first rollout. Operator review and release decisions remain human responsibilities.
Upgrade procedure
Use the version pinned in the deployment source. Before changing that pin:
- Read the upstream release notes and deployment compatibility notes for the target version.
- Create a backup and verify that a restore can be performed in an isolated environment.
- Record the source revision and the deployed version.
- Update only the explicit version pin, apply the normal local deployment procedure, and verify local sign-in with the bootstrap administrator.
- Keep the prior known-good pin available until the updated workspace is accepted.
Do not use an unpinned image tag or an implicit “latest” update path.
Backup and restore prerequisite
A backup is not sufficient evidence by itself. Before upgrades, configuration changes, or account-risking administration, an isolated restore must have been completed successfully from a current backup. The restore exercise must verify the restored workspace can start and that local administrator access is available without email-based recovery.
Incident response
If administrator access is lost, stop and use the documented local recovery procedure against a verified backup or isolated recovery environment. Do not expose recovery material, secret values, or realm-creation links in this wiki or in operational logs.