Masterplan Optimiser
Step 6 of 1346%

Operator Guide

MP-OPT Management Console

Use one guarded SSH interface for deployment, configuration, recovery, logs, and high availability instead of memorising Compose and database commands.

Open the console

VPS SSH

ssh deploy@VPS_ADDRESS
mp-opt

Run it only in an interactive SSH session. The launcher resolves the current repository, opens a full-screen terminal UI and keeps nested operations inside the main menu.

Menu areas

AreaUse it for
System overviewHealth, versions, disk space and recovery readiness.
Deploy and servicesPull/deploy, rebuild, start, stop, restart and service status.
ConfigurationSMTP, runtime limits, recovery recipient, database/application/VAPID rotation and domain changes.
Snapshots and recoveryCreate, verify, export, import, restore and delete encrypted recovery points.
Root administrator recoveryReset root authentication without deleting application data.
DatabaseStatistics, encrypted database snapshots, restore and guarded complete wipe.
High availabilityReplication, peer state, TLS, switchover, automatic failover and certification readiness.
LogsRecent, time-bounded or live backend, database and Caddy logs.
Maintenance and diagnosticsValidation, redacted diagnostics, audit-chain checks, recovery evidence and safe cache cleanup.

Safe operating patterns

  • Use View redacted configuration instead of printing .env.
  • Use the Logs menu; live logs stop cleanly and temporary viewer files are removed.
  • Use Validate Compose, Caddy, health and permissions after host changes.
  • Let destructive actions create and deep-verify their rollback snapshot before confirming.
  • In HA mode, disable automatic failover before restore, wipe, key consolidation or other long maintenance.

Permission and health checks in Server v3.9.14

Every TUI action declares the access it needs before it starts. The console checks that profile again after the action, so a deployment, restore, service recreation, key rotation, evidence action, or HA transition cannot silently leave a shared path unusable by its container or host service. Systemd path directives are interpreted semantically, including their valid optional prefix, and still fail when access is missing or broader than intended.

Validate Compose, Caddy, health and permissions also tests the Backend's effective UID, Caddy and PostgreSQL access, bind mounts, runtime queues and receipts, protected host state, and systemd write paths. It checks access without displaying secret contents.

Commissioning records deployment, local service stability, witness readiness, first-bundle acceptance, HA service activation, public routing, installation validation, SMTP and browser setup separately. The current action therefore names the step that actually needs attention, and reconnecting reconciles accepted work instead of repeating it.

Scheduled recovery snapshots use the same host-local execution lease as commissioning. A timer invocation waits for setup for up to five minutes and then defers successfully if the lease is still held. This keeps final health checks stable without turning an expected overlap into a failed systemd unit.

Structured commissioning status

Server v3.9.18 exposes a root-local structured view of the same commissioning engine used by the TUI. It is intended for careful automation and diagnosis on the host; it is not a network administration API.

VPS SSH

mp-opt setup status --json
mp-opt setup events --jsonl --after 0
mp-opt setup reconcile --json

Status and events omit secret handoffs. Mutating steps still require the execution lease, an exact checkpoint, schema-validated protected input and an idempotency key. Opening the TUI at the same time cannot create a second commissioning writer.

Updates in an HA pair

  1. Disable automatic failover from the current holder.
  2. Deploy the non-holder first.
  3. Deploy the holder.
  4. Require matching Git commits, healthy services and a fresh successful replication.
  5. Perform a planned switchover test before re-enabling automatic failover.