| Host | Backend | TLS | Cert expiry | Policy |
|---|---|---|---|---|
console.meridian.example | platform-portal:8080 | TLS 1.3 | 68d auto-renew | rate-limit 100 r/s/IP |
api.meridian.example | platform-core:9000 | TLS 1.3 | 68d auto-renew | WAF + mTLS for /webhooks |
idp.meridian.example | platform-identity:8443 | TLS 1.3 | 68d auto-renew | geo-fence EU |
grafana.meridian.example | monitoring-grafana:3000 | TLS 1.3 | 68d auto-renew | SSO required · internal LB |
help.Edit the declared configuration. Nothing mutates directly — your edit becomes a diff, is validated against schema and policy, and ships as a plan.
domain: meridian.example # assumability: never — a human stated it tls_mode: letsencrypt acme_email: platform@meridian.example infra_mode: provisioned # confirmed at install (gates 3 params) location: westeurope # confirmed — decides where data lands data_plane_enabled: true data_plane_mode: shared public_access_cidrs: [193.110.0.0/16, 185.44.8.0/22, 80.13.9.0/24] observability: enabled registry_mode: mirrored
public_access_cidrs (+1 range) — approved by a.moraThe config replays non-interactively — this install is repeatable from its record.
| Operation | Initiator | Started | Duration | Result | |
|---|---|---|---|---|---|
| upgrade 0.1.88 → 0.1.91 | kai.tran | today 14:02 | — | running 64% | view live |
| backup (scheduled) | system | today 09:00 | 7m | verified | journal |
| drift scan | system | yesterday | 3m | clean | report |
| DR restore test | priya.n | 6d ago | 11m | passed · RTO 11m | report |
| config change v41 | kai.tran | 2d ago | 2m | applied | diff |
| upgrade 0.1.86 → 0.1.88 | partner: NordOps | 2026-07-15 | 26m | verified · zero vendor involvement | journal |
| cert renewal | system | 2026-07-02 | 1m | auto | journal |