master-zapier-plan-draft/packages/verae-ops
George Lambert 1b199ca4d4
Some checks are pending
offline / test (push) Waiting to run
Separate Zapier, web, API, and leaf access planes with NATS authz
Zapier is one ingress. Direct web, customer API, and S2S leaf nodes are their own services. Every hop to an internal subject must pass verae.access.authz.check (default deny by plane).
2026-09-11 16:05:05 -04:00
..
01-dependencies.md Document every repo in Sphinx, catalog PDFs, and verae-ops 2026-09-11 14:36:17 -04:00
02-docker.md Document every repo in Sphinx, catalog PDFs, and verae-ops 2026-09-11 14:36:17 -04:00
03-proxmox.md Document every repo in Sphinx, catalog PDFs, and verae-ops 2026-09-11 14:36:17 -04:00
04-virtual-servers.md Document every repo in Sphinx, catalog PDFs, and verae-ops 2026-09-11 14:36:17 -04:00
05-dedicated-hardware.md Document every repo in Sphinx, catalog PDFs, and verae-ops 2026-09-11 14:36:17 -04:00
06-linking-services.md Document every repo in Sphinx, catalog PDFs, and verae-ops 2026-09-11 14:36:17 -04:00
07-maintenance.md Document every repo in Sphinx, catalog PDFs, and verae-ops 2026-09-11 14:36:17 -04:00
docker-compose.yml Separate Zapier, web, API, and leaf access planes with NATS authz 2026-09-11 16:05:05 -04:00
GETTING-STARTED.md Separate Zapier, web, API, and leaf access planes with NATS authz 2026-09-11 16:05:05 -04:00
NATS.md Document every repo in Sphinx, catalog PDFs, and verae-ops 2026-09-11 14:36:17 -04:00
package.json Document every repo in Sphinx, catalog PDFs, and verae-ops 2026-09-11 14:36:17 -04:00
README.md Fix catalog PDF links; add bring-online guide; feature zappier billing 2026-09-11 14:59:13 -04:00
SUMMARY.md Document every repo in Sphinx, catalog PDFs, and verae-ops 2026-09-11 14:36:17 -04:00

verae-ops — install, run, maintain

How to stand up Verae Time × Zapier on Docker, Proxmox, generic VMs, or dedicated hardware, and how to link dependent services.

Forgejo: https://git.georgelambert.org/marchon/verae-ops
Clone: ssh://git@git.georgelambert.org:2223/marchon/verae-ops.git
Catalog: https://zapier.georgelambert.org/packages/verae-ops/README.pdf
System map: https://zapier.georgelambert.org/overview/README.pdf

This is the operations repo. Application code lives in the other independent git repositories.

Reading order

  1. GETTING-STARTED.md — install, first-up, monitor (read this first)
  2. 01-dependencies.md — what must exist, who talks to whom
  3. 02-docker.md — Compose (NATS 3-node cluster + HTTPS edges)
  4. 03-proxmox.md — LXC / QEMU VMs
  5. 04-virtual-servers.md — cloud or hypervisor VMs
  6. 05-dedicated-hardware.md — bare metal (NS1-style)
  7. 06-linking-services.md — env vars, URLs, replica floors
  8. 07-maintenance.md — upgrade, backup, fleet, NATS

Public PDFs of the same files: https://zapier.georgelambert.org/packages/verae-ops/<name>.pdf.

Non-negotiables

Rule Why
Zapier cloud → HTTPS only (zappier-edge) Never NATS, never api.veraetime.net
NATS binds loopback or a private docker/VM net Not on the public NIC
Tree-node min 3, pause does not count Bulk Merkle lookups
Private keys stay on disk; git stores paths machines.json identityFile
Operator console is loopback :3850 Not a public site

Quick lab (one machine)

git clone ssh://git@git.georgelambert.org:2223/marchon/verae-ops.git
cd verae-ops
docker compose up --build

Then: zappier http://127.0.0.1:3000/ middleware http://127.0.0.1:3100/health NATS monitoring http://127.0.0.1:8222/

Production layout is three NATS nodes + fleet-spread workers; see 02-docker.md and 05-dedicated-hardware.md.