Skip to content

OjuIDC Master Topology — v50 Review Package

Status

AUTHORITATIVE_TOPOLOGY_SCOPE

Purpose

This document defines the intended OjuIDC topology and current operating roles for the v50 GRC documentation review package.

It distinguishes intended target-state architecture from evidence-backed governance state and operator-reported status. It supersedes hypothetical enterprise high-availability designs unless a future ratified ADR, governance decision, or explicit human approval changes the topology.

Evidence Boundary Notice

The intended OLUSO-centric architecture described in this document is subject to active evidence-boundary controls.

Current evidence records establish:

  • akoda-dc01 protection status: PROTECTED_INTACT
  • retirement status: BLOCKED
  • boundary status: GATE_5_FRAMEWORK_RECORDED_PENDING_LOCAL_EVIDENCE
  • host lifecycle state: DECOMMISSION_PREPARATION
  • verification status: PENDING_HUMAN_SIGN_OFF
  • final disposition: UNDECIDED

This document describes both the intended target-state architecture and current operating roles. It does not constitute authorization for AKODA retirement, decommission execution, FSMO transfer, domain-controller demotion, or resource reclamation.

Documentation claims in this package remain subject to human byte validation. WS1 endpoint: READY_FOR_HUMAN_REVIEW.


Architectural Principles

1. Evidence First

  • Never claim a migration, promotion, backup, validation, or deployment is complete without evidence.
  • Treat undocumented assumptions as unverified.
  • Require human approval before destructive actions.

2. OLUSO-Centric Design

  • Compute is replaceable.
  • Knowledge is not.
  • OLUSO is the intended authoritative persistence layer.

3. Recovery Over Availability

This environment is a resilience and recovery platform.

It is not:

  • a true high-availability cluster
  • a Windows Server Failover Cluster
  • a Storage Spaces Direct deployment
  • an automatic failover architecture

4. Portable Services

  • Services must be redeployable.
  • Data must survive node loss.
  • Infrastructure should rebuild from OLUSO.

Primary Storage Foundation

OLUSO

Operational identifier

oluso

Display name (display plane only)

Olùṣọ́

Role

OLUSO is the Synology NAS and the intended authoritative storage, persistence, knowledge, backup, registry, container, and evidence layer for OjuIDC.

Intended hosts (target-state inventory)

  • Docker volumes
  • Synology Container Manager storage
  • Gitea repositories
  • Knowledge Fabric
  • Ara AO assets
  • OCR artifacts
  • transcript archives
  • SDR and ADR repositories
  • governance evidence
  • backup repositories
  • AI models
  • Ollama model cache
  • translation models
  • Moodle assets
  • training videos
  • family archives

Current platform status

Planned / not evidenced as complete in opened Gate 5 sources.

  • NVMe expansion: planned
  • Container Manager storage: planned
  • operational_completion: not_evidenced_in_opened_sources

Rule

OLUSO is the intended foundation of OjuIDC.

No architecture proposal should position another system as the primary storage authority.


Compute Plane

AGBARA

Operational identifier

agbara

Display name (display plane only)

Agbára

Device

Lenovo X1 Carbon

Role (intended target state)

  • Intended primary organizational workstation
  • Intended primary developer system
  • Intended mixed-role operations node
  • Intended primary compute platform

Responsibilities (target-state inventory)

  • Open WebUI
  • Ollama
  • translation APIs
  • trainer assistance services
  • Nexus grant services
  • Knowledge Fabric workers
  • Docker Swarm manager
  • AI development
  • Ara AO development
  • ITECH Development Charities operations

Rule

AGBARA is the intended primary compute platform within the target OLUSO-centric architecture.

AGBARA currently serves as the designated successor platform and hosts active transition work associated with organizational services.

Final retirement authorization for AKODA remains governed by evidence boundary controls and required approvals.

It is not the authoritative storage layer.

Current Platform Status

Operator-reported status (not verified by the Gate 5 evidence package).

The operating system image has been deployed and the platform is currently undergoing initial enrollment and configuration activities.

Current work includes:

  • Windows enrollment preparation
  • Autopilot configuration capture
  • Baseline configuration
  • Workload onboarding
  • Organizational service deployment

Operational readiness should not be inferred solely from operating system deployment.

Distinction:

  • Target Compute Platform: AGBARA
  • Current Operational State: OS Installed · Awaiting Enrollment · Awaiting Configuration · Awaiting Workload Deployment
  • Operator-reported OS: Windows 11 Enterprise Insider at OOBE / initial setup

AKODA (i5 / identity root)

Operational identifiers

akoda, akoda-dc01

Display name (display plane only)

Àkọ́dá

Evidence-backed lifecycle state

Field Value
Protection PROTECTED_INTACT
Retirement BLOCKED
Lifecycle DECOMMISSION_PREPARATION
executionBlocked true
Verification PENDING_HUMAN_SIGN_OFF
Final disposition UNDECIDED

Sources: docs/evidence/EvidenceBoundarySummary.md, docs/evidence/EvidenceBoundarySummary.json, docs/evidence/audit_report.md.

Rule

AKODA remains protected and active under evidence-boundary controls. This document does not authorize retirement, demotion, FSMO transfer, or resource reclamation.


HP 840 G6 i7

Operational identifier

akoda_i7 (planned personal / innovation platform)

Device

HP 840 G6 i7

Role

  • Personal development system
  • Innovation lab
  • Recovery validation node
  • Planned EA FC development platform

Responsibilities

  • EA FC development
  • experimental AI
  • sandbox workloads
  • testing
  • recovery exercises
  • validation activities

Migration Note

This system is the planned successor platform for personal and innovation workloads currently associated with AKODA transition planning.

Bring-up dependency

Bring-up and any resource-dependent use that assumes AKODA i5 retirement remain dependent on:

  • AKODA retirement authorization
  • required evidence recorded
  • human sign-off recorded

AKODA remains protected under active evidence-boundary controls. Retirement, resource reclamation, and final disposition remain pending required evidence, approvals, and human sign-off.

Rule

The HP 840 G6 i7 is not the primary OjuIDC node.


IRIN / GEEKOM

Operational identifier

irin

Display name (display plane only)

Irìn

Hardware / location

GEEKOM · Silver Spring

Role (intended / planned)

  • Delegated operations node
  • Family services node
  • Remote access / remote support node
  • Demo environment
  • External entry point
  • Cloudflare Tunnel endpoint (planned / preferred path)
  • Recovery operations node
  • Planned writable domain controller (domain_controller_validation: pending_evidence)

Responsibilities

  • family support
  • remote assistance
  • trainer access services
  • demo environment
  • external entry point
  • recovery operations

Current platform status

Operator-reported status (not verified by the Gate 5 evidence package).

  • OS state: Windows 11 25H2 (operator-reported)
  • Writable DC validation: pending evidence
  • Delegated services configuration: pending

Rule

IRIN/GEEKOM is not a cluster member.

IRIN/GEEKOM is a delegated services and recovery platform. Orthographic display name Irìn is display-plane only; operational paths, parameters, JSON keys, and DNS labels use ASCII irin.


Network Architecture

Tailscale Status

Do not assume Tailscale.

Tailscale is not part of the current strategic architecture.

External Connectivity

External connectivity is provided through Cloudflare infrastructure.

Cloudflare-Managed Domains

  • olutech.systems
  • olutechsys.com
  • itechcharities.org

Preferred External Access Mechanism

Cloudflare Tunnel

Traffic Flow

Internet
→ Cloudflare
→ Cloudflare Tunnel
→ IRIN/GEEKOM (irin)
→ Internal OjuIDC Services

Potential Service Endpoints
gitea.olutech.systems
ai.olutech.systems
support.olutechsys.com
learn.itechcharities.org

Rule

Avoid recommendations requiring inbound firewall exposure whenever Cloudflare Tunnel can satisfy requirements.

Container Strategy

Primary Orchestration

  • Docker
  • Docker Swarm, lightweight

Current Objective

  • service portability
  • service recovery
  • rapid redeployment

Not Current Objective

  • enterprise high availability
  • multi-manager quorum
  • Storage Spaces Direct
  • live migration
  • automatic failover

Storage Rule

Container data should reside on OLUSO whenever practical. NVMe expansion and Container Manager deployment remain planned until evidenced.

Current Migration Program

Active Initiative

AKODA Transition and Evidence Validation Program

Objective

Prepare resources required for:

  • transition activities toward AGBARA (intended primary compute)
  • establishment of OLUSO as authoritative storage platform (intended)
  • planned installation and use of two 1TB NVMe drives
  • planned Synology Container Manager deployment
  • planned Docker storage migration
  • planned persistent model storage
  • planned Knowledge Fabric storage

Rule

No recommendation should delay the OLUSO build when required evidence, required approvals, and governance controls have been recorded.

Strategic End State

OLUSO = Intended Knowledge + Storage + Recovery Authority

AGBARA = Intended Organizational Compute

HP 840 G6 i7 = Personal Innovation Platform (planned)

IRIN/GEEKOM = Delegated Operations and External Access (planned writable DC pending evidence)

Cloudflare = External Connectivity Layer

Ara AO = Knowledge Fabric and AI Platform

Agent Behavior Rules

When proposing architecture, agents should favor:

  • recovery
  • rebuildability
  • governance
  • evidence
  • storage centralization
  • OLUSO as center of gravity

Agents should avoid:

  • imaginary high-availability features
  • assumed clustering
  • unapproved topology changes
  • replacing OLUSO as system of record
  • assuming Tailscale
  • assuming WSFC
  • assuming S2D
  • assuming automatic failover
  • claiming AKODA retirement complete without evidence

AKODA Transition Program

Phase 1 — AKODA Evidence Validation

Before any retirement authorization, verify:

  • data migration staging complete at C:\OjuIDC_Migration_Staging
  • user profiles copied
  • repositories copied
  • scripts copied
  • secrets exported through the approved Vaultwarden workflow
  • ProgressLedger evidence recorded

Phase 2 — Free Hardware Resources

Current State

AKODA (i5 / akoda-dc01) Protected and Active Retirement BLOCKED (evidence-backed)

AGBARA OS Deployed Pending Configuration (operator-reported; not evidence-package verified)

IRIN/GEEKOM Pending Delegated Services Configuration Planned writable DC pending evidence (operator-reported OS Win11 25H2)

OLUSO Pending NVMe Storage Expansion operational_completion: not_evidenced_in_opened_sources

Target Sequence

  1. Evidence Validation
  2. Human Approval
  3. IRIN/GEEKOM Configuration
  4. Writable DC Validation
  5. AGBARA Configuration
  6. Workload Migration
  7. AKODA Retirement Authorization
  8. AKODA Decommission Execution
  9. NVMe Reallocation
  10. OLUSO Expansion
  11. Container Manager Deployment
  12. OLUSO-Centric Operations

Phase 3 — OLUSO NVMe Build (planned)

Planned install:

  • NVMe 1TB #1
  • NVMe 1TB #2

Planned primary usage:

  • Container Manager
  • Docker volumes
  • AI models
  • Gitea storage
  • Knowledge Fabric

OLUSO ├── Volume_Docker │ ├── container-manager │ ├── docker-volumes │ ├── gitea │ ├── openwebui │ └── ollama │ └── Volume_KnowledgeFabric ├── transcripts ├── ocr ├── videos ├── training ├── governance └── evidence

Phase 4 — First OLUSO-Hosted Services (planned)

Planned move off workstation storage:

  • Gitea
  • Container Registry
  • Open WebUI data
  • Ollama model storage
  • Knowledge Fabric assets

Architecture Transition

The intended transition is:

Compute-Centric ↓ OLUSO-Centric

This is the target architecture for OjuIDC. It is not evidence of completed cutover, retirement, or WS2 authorization.