OjuIDC Master Topology — v50 Review Package
Status
AUTHORITATIVE_TOPOLOGY_SCOPE
Purpose
This document defines the intended OjuIDC topology and current operating roles for the v50 GRC documentation review package.
It distinguishes intended target-state architecture from evidence-backed governance state and operator-reported status. It supersedes hypothetical enterprise high-availability designs unless a future ratified ADR, governance decision, or explicit human approval changes the topology.
Evidence Boundary Notice
The intended OLUSO-centric architecture described in this document is subject to active evidence-boundary controls.
Current evidence records establish:
- akoda-dc01 protection status: PROTECTED_INTACT
- retirement status: BLOCKED
- boundary status: GATE_5_FRAMEWORK_RECORDED_PENDING_LOCAL_EVIDENCE
- host lifecycle state: DECOMMISSION_PREPARATION
- verification status: PENDING_HUMAN_SIGN_OFF
- final disposition: UNDECIDED
This document describes both the intended target-state architecture and current operating roles. It does not constitute authorization for AKODA retirement, decommission execution, FSMO transfer, domain-controller demotion, or resource reclamation.
Documentation claims in this package remain subject to human byte validation. WS1 endpoint: READY_FOR_HUMAN_REVIEW.
Architectural Principles
1. Evidence First
- Never claim a migration, promotion, backup, validation, or deployment is complete without evidence.
- Treat undocumented assumptions as unverified.
- Require human approval before destructive actions.
2. OLUSO-Centric Design
- Compute is replaceable.
- Knowledge is not.
- OLUSO is the intended authoritative persistence layer.
3. Recovery Over Availability
This environment is a resilience and recovery platform.
It is not:
- a true high-availability cluster
- a Windows Server Failover Cluster
- a Storage Spaces Direct deployment
- an automatic failover architecture
4. Portable Services
- Services must be redeployable.
- Data must survive node loss.
- Infrastructure should rebuild from OLUSO.
Primary Storage Foundation
OLUSO
Operational identifier
oluso
Display name (display plane only)
Olùṣọ́
Role
OLUSO is the Synology NAS and the intended authoritative storage, persistence, knowledge, backup, registry, container, and evidence layer for OjuIDC.
Intended hosts (target-state inventory)
- Docker volumes
- Synology Container Manager storage
- Gitea repositories
- Knowledge Fabric
- Ara AO assets
- OCR artifacts
- transcript archives
- SDR and ADR repositories
- governance evidence
- backup repositories
- AI models
- Ollama model cache
- translation models
- Moodle assets
- training videos
- family archives
Current platform status
Planned / not evidenced as complete in opened Gate 5 sources.
- NVMe expansion: planned
- Container Manager storage: planned
operational_completion: not_evidenced_in_opened_sources
Rule
OLUSO is the intended foundation of OjuIDC.
No architecture proposal should position another system as the primary storage authority.
Compute Plane
AGBARA
Operational identifier
agbara
Display name (display plane only)
Agbára
Device
Lenovo X1 Carbon
Role (intended target state)
- Intended primary organizational workstation
- Intended primary developer system
- Intended mixed-role operations node
- Intended primary compute platform
Responsibilities (target-state inventory)
- Open WebUI
- Ollama
- translation APIs
- trainer assistance services
- Nexus grant services
- Knowledge Fabric workers
- Docker Swarm manager
- AI development
- Ara AO development
- ITECH Development Charities operations
Rule
AGBARA is the intended primary compute platform within the target OLUSO-centric architecture.
AGBARA currently serves as the designated successor platform and hosts active transition work associated with organizational services.
Final retirement authorization for AKODA remains governed by evidence boundary controls and required approvals.
It is not the authoritative storage layer.
Current Platform Status
Operator-reported status (not verified by the Gate 5 evidence package).
The operating system image has been deployed and the platform is currently undergoing initial enrollment and configuration activities.
Current work includes:
- Windows enrollment preparation
- Autopilot configuration capture
- Baseline configuration
- Workload onboarding
- Organizational service deployment
Operational readiness should not be inferred solely from operating system deployment.
Distinction:
- Target Compute Platform: AGBARA
- Current Operational State: OS Installed · Awaiting Enrollment · Awaiting Configuration · Awaiting Workload Deployment
- Operator-reported OS: Windows 11 Enterprise Insider at OOBE / initial setup
AKODA (i5 / identity root)
Operational identifiers
akoda, akoda-dc01
Display name (display plane only)
Àkọ́dá
Evidence-backed lifecycle state
| Field | Value |
|---|---|
| Protection | PROTECTED_INTACT |
| Retirement | BLOCKED |
| Lifecycle | DECOMMISSION_PREPARATION |
executionBlocked |
true |
| Verification | PENDING_HUMAN_SIGN_OFF |
| Final disposition | UNDECIDED |
Sources: docs/evidence/EvidenceBoundarySummary.md,
docs/evidence/EvidenceBoundarySummary.json,
docs/evidence/audit_report.md.
Rule
AKODA remains protected and active under evidence-boundary controls. This document does not authorize retirement, demotion, FSMO transfer, or resource reclamation.
HP 840 G6 i7
Operational identifier
akoda_i7 (planned personal / innovation platform)
Device
HP 840 G6 i7
Role
- Personal development system
- Innovation lab
- Recovery validation node
- Planned EA FC development platform
Responsibilities
- EA FC development
- experimental AI
- sandbox workloads
- testing
- recovery exercises
- validation activities
Migration Note
This system is the planned successor platform for personal and innovation workloads currently associated with AKODA transition planning.
Bring-up dependency
Bring-up and any resource-dependent use that assumes AKODA i5 retirement remain dependent on:
- AKODA retirement authorization
- required evidence recorded
- human sign-off recorded
AKODA remains protected under active evidence-boundary controls. Retirement, resource reclamation, and final disposition remain pending required evidence, approvals, and human sign-off.
Rule
The HP 840 G6 i7 is not the primary OjuIDC node.
IRIN / GEEKOM
Operational identifier
irin
Display name (display plane only)
Irìn
Hardware / location
GEEKOM · Silver Spring
Role (intended / planned)
- Delegated operations node
- Family services node
- Remote access / remote support node
- Demo environment
- External entry point
- Cloudflare Tunnel endpoint (planned / preferred path)
- Recovery operations node
- Planned writable domain controller (
domain_controller_validation: pending_evidence)
Responsibilities
- family support
- remote assistance
- trainer access services
- demo environment
- external entry point
- recovery operations
Current platform status
Operator-reported status (not verified by the Gate 5 evidence package).
- OS state: Windows 11 25H2 (operator-reported)
- Writable DC validation: pending evidence
- Delegated services configuration: pending
Rule
IRIN/GEEKOM is not a cluster member.
IRIN/GEEKOM is a delegated services and recovery platform.
Orthographic display name Irìn is display-plane only; operational paths,
parameters, JSON keys, and DNS labels use ASCII irin.
Network Architecture
Tailscale Status
Do not assume Tailscale.
Tailscale is not part of the current strategic architecture.
External Connectivity
External connectivity is provided through Cloudflare infrastructure.
Cloudflare-Managed Domains
- olutech.systems
- olutechsys.com
- itechcharities.org
Preferred External Access Mechanism
Cloudflare Tunnel
Traffic Flow
Internet
→ Cloudflare
→ Cloudflare Tunnel
→ IRIN/GEEKOM (irin)
→ Internal OjuIDC Services
Potential Service Endpoints
gitea.olutech.systems
ai.olutech.systems
support.olutechsys.com
learn.itechcharities.org
Rule
Avoid recommendations requiring inbound firewall exposure whenever Cloudflare Tunnel can satisfy requirements.
Container Strategy
Primary Orchestration
- Docker
- Docker Swarm, lightweight
Current Objective
- service portability
- service recovery
- rapid redeployment
Not Current Objective
- enterprise high availability
- multi-manager quorum
- Storage Spaces Direct
- live migration
- automatic failover
Storage Rule
Container data should reside on OLUSO whenever practical. NVMe expansion and Container Manager deployment remain planned until evidenced.
Current Migration Program
Active Initiative
AKODA Transition and Evidence Validation Program
Objective
Prepare resources required for:
- transition activities toward AGBARA (intended primary compute)
- establishment of OLUSO as authoritative storage platform (intended)
- planned installation and use of two 1TB NVMe drives
- planned Synology Container Manager deployment
- planned Docker storage migration
- planned persistent model storage
- planned Knowledge Fabric storage
Rule
No recommendation should delay the OLUSO build when required evidence, required approvals, and governance controls have been recorded.
Strategic End State
OLUSO = Intended Knowledge + Storage + Recovery Authority
AGBARA = Intended Organizational Compute
HP 840 G6 i7 = Personal Innovation Platform (planned)
IRIN/GEEKOM = Delegated Operations and External Access (planned writable DC pending evidence)
Cloudflare = External Connectivity Layer
Ara AO = Knowledge Fabric and AI Platform
Agent Behavior Rules
When proposing architecture, agents should favor:
- recovery
- rebuildability
- governance
- evidence
- storage centralization
- OLUSO as center of gravity
Agents should avoid:
- imaginary high-availability features
- assumed clustering
- unapproved topology changes
- replacing OLUSO as system of record
- assuming Tailscale
- assuming WSFC
- assuming S2D
- assuming automatic failover
- claiming AKODA retirement complete without evidence
AKODA Transition Program
Phase 1 — AKODA Evidence Validation
Before any retirement authorization, verify:
- data migration staging complete at C:\OjuIDC_Migration_Staging
- user profiles copied
- repositories copied
- scripts copied
- secrets exported through the approved Vaultwarden workflow
- ProgressLedger evidence recorded
Phase 2 — Free Hardware Resources
Current State
AKODA (i5 / akoda-dc01) Protected and Active Retirement BLOCKED (evidence-backed)
AGBARA OS Deployed Pending Configuration (operator-reported; not evidence-package verified)
IRIN/GEEKOM Pending Delegated Services Configuration Planned writable DC pending evidence (operator-reported OS Win11 25H2)
OLUSO Pending NVMe Storage Expansion operational_completion: not_evidenced_in_opened_sources
Target Sequence
- Evidence Validation
- Human Approval
- IRIN/GEEKOM Configuration
- Writable DC Validation
- AGBARA Configuration
- Workload Migration
- AKODA Retirement Authorization
- AKODA Decommission Execution
- NVMe Reallocation
- OLUSO Expansion
- Container Manager Deployment
- OLUSO-Centric Operations
Phase 3 — OLUSO NVMe Build (planned)
Planned install:
- NVMe 1TB #1
- NVMe 1TB #2
Planned primary usage:
- Container Manager
- Docker volumes
- AI models
- Gitea storage
- Knowledge Fabric
Recommended Logical Layout (planned)
OLUSO ├── Volume_Docker │ ├── container-manager │ ├── docker-volumes │ ├── gitea │ ├── openwebui │ └── ollama │ └── Volume_KnowledgeFabric ├── transcripts ├── ocr ├── videos ├── training ├── governance └── evidence
Phase 4 — First OLUSO-Hosted Services (planned)
Planned move off workstation storage:
- Gitea
- Container Registry
- Open WebUI data
- Ollama model storage
- Knowledge Fabric assets
Architecture Transition
The intended transition is:
Compute-Centric ↓ OLUSO-Centric
This is the target architecture for OjuIDC. It is not evidence of completed cutover, retirement, or WS2 authorization.