meridian-health / prod Upgrading

Meridian Health · azure westeurope · EU sovereign profile · imported 2026-02-11 · everything below is a resource: UID, version, owner, labels, health, events, audit
Live operation

Health

explains why, not just what
Overall
Healthy — upgrade in flight
Control plane
3/3 nodes ready · API p99 84 ms
Workloads
41/41 deployments available
Data
Postgres primary healthy · PITR enabled
Ingress
TLS valid 71d · DNS resolving
Backups
last verified restore test: 6d ago ✓ · Backup & DR

Versions

Platform
0.1.88 → 0.1.91 (upgrading, 64%)
Kubernetes
AKS 1.31.7
Engine
cf 0.1.91
Infra module
sha256:44af…9e12
Config version

Certificates & DNS

portal.meridian.example
valid 71d Let's Encrypt · auto-renews
api.meridian.example
valid 71d
idp.meridian.example
valid 71d
DNS
managed · A records reconciled 2h ago
Issuer
cert-manager · letsencrypt-prod

Capacity

7-day trend
CPU (cluster)
61%
Memory
72%
Storage
4.1 TB
Forecast: memory reaches 85% in ~6 weeks at current growth. Node-pool scale-up is available as a planned, approval-gated operation.

Recent events

14:02 today
Upgrade run-8842 started (kai.tran)
09:00 today
Scheduled backup verified ✓
yesterday
Drift scan: clean
6d ago
DR restore test passed (11m RTO)

Ingress & certificates

folded from Network — per-host routes, TLS, and edge policy
HostBackendTLSCert expiryPolicy
console.meridian.exampleplatform-portal:8080TLS 1.368d auto-renewrate-limit 100 r/s/IP
api.meridian.exampleplatform-core:9000TLS 1.368d auto-renewWAF + mTLS for /webhooks
idp.meridian.exampleplatform-identity:8443TLS 1.368d auto-renewgeo-fence EU
grafana.meridian.examplemonitoring-grafana:3000TLS 1.368d auto-renewSSO required · internal LB

Live topology — network · compute · data

click any element to inspect · rendered from live inventory
Internet users · 3 CIDRs Load balancer 20.31.44.9 · 443 Ingress (Traefik) TLS · letsencrypt · 3 hosts VNET 10.240.0.0/16 · AZURE WESTEUROPE AKS 1.31.7 · subnet 10.240.4.0/22 system 3 × D4as_v5 22 pods · all ready READY apps 4 × D8as_v5 61 pods · 3 rolling UPGRADING workloads-gpu 2 × NC6s_v3 8 lab pods READY PostgreSQL (managed) HA · PITR 14d · 10.240.8.4 PRIMARY HEALTHY Object storage backups · recordings PRIVATE ENDPOINT NAT egress allow-list: 2 endpoints LOCKED Registry mirror (ACR) 34 signed images · 0.1.91 staged IN SYNC Monitoring stack metrics · logs · traces · alerts SCRAPING 214 TARGETS Identity (OIDC) idp.meridian.example FEDERATED

apps node pool

Access

audited · session-recorded
Console access is authenticated via SSO, scoped by role, and every interactive session lands in the audit trail. No SSH keys are ever distributed.

Service metrics

scraped by the embedded monitoring stack · dashed marker = upgrade run-8842 started

Request rate

req/s by service

Latency p99

ms by endpoint

Error rate

% of requests · 5xx

CPU utilisation

% by node pool

Memory utilisation

% by node pool

PostgreSQL connections

of 400 max

Kubernetes resources

live from the cluster · read is free, mutation is a planned operation

Select a resource

Click any row to inspect it — details, live actions, console access.

Access

audited · session-recorded
Consoles are SSO-authenticated, role-scoped, and recorded to the audit trail. Read commands are free; mutating verbs route through the same planned-operation gates as the UI. No SSH keys are ever distributed.

Configuration — version 41

validated · versioned · approval-gated
domain: meridian.example          # assumability: never — a human stated it
tls_mode: letsencrypt
acme_email: platform@meridian.example
infra_mode: provisioned            # confirmed at install (gates 3 params)
location: westeurope               # confirmed — decides where data lands
data_plane_enabled: true
data_plane_mode: shared
public_access_cidrs: [193.110.0.0/16, 185.44.8.0/22, 80.13.9.0/24]
observability: enabled
registry_mode: mirrored

Version history

diff · approve · roll back
v41 · 2d ago · kai.tran
Widened public_access_cidrs (+1 range) — approved by a.mora
v40 · 9d ago · priya.n
Enabled observability stack — approved
v39 · 12d ago · rollback
Rolled back v38 (ingress annotation broke uploads) — one click, prior versioned copy
v38 · 12d ago · marc.d
Ingress annotation change — superseded by rollback

Interview record

every silent default recorded with its reason
Asked (never assumable)
domain, acme_email — no default may be invented
Confirmed
location, infra_mode, data_plane_mode — shown before apply, each gates others
Assumed (justified)
storage_class, backup window, log retention, cert issuer… — each recorded with its reason

The config replays non-interactively — this install is repeatable from its record.

OperationInitiatorStartedDurationResult
upgrade 0.1.88 → 0.1.91kai.trantoday 14:02running 64%view live
backup (scheduled)systemtoday 09:007mverifiedjournal
drift scansystemyesterday3mcleanreport
DR restore testpriya.n6d ago11mpassed · RTO 11mreport
config change v41kai.tran2d ago2mapplieddiff
upgrade 0.1.86 → 0.1.88partner: NordOps2026-07-1526mverified · zero vendor involvementjournal
cert renewalsystem2026-07-021mautojournal
Zero vendor hours: the 0.1.86 → 0.1.88 upgrade above was executed end-to-end by a partner engineer — preflight, approval, verification, done.