Masterplan Optimiser

Operator Guide

Standalone Commissioning

Prove that the first server can be administered, published to, used, and recovered before admitting important data or adding a second VPS.

Outcome and prerequisites

Complete this runbook after installation, root-passkey registration, and recovery-key configuration. Have a trusted workstation with the desktop application, an authenticator for the root passkey, and a protected destination outside the VPS for the portable snapshot.

1. Verify the host and management boundary

MP-OPT

Open the management console and confirm that configuration validation, application health, PostgreSQL health, hostname, and TLS checks pass. Resolve warnings before continuing.

Browser

Sign in at the final production hostname with the root passkey. Confirm that Security, High Availability, and Audit Log are visible and that the browser reports a valid HTTPS connection.

Expected result: the production hostname is stable, root authentication succeeds, and no service is being accessed through an IP address or temporary hostname.

2. Prove an end-to-end publish

Browser

Create a disposable commissioning event, create the minimum required access, and generate its desktop publishing secret.

Workstation

In the desktop application, configure the MP-OPT Server URL and publish secret. Publish a small finalised masterplan and a small General Schedule.

Browser

Confirm an authorised user sees the private schedule, the public General Schedule exposes only its intended content, and the event History view records the publish.

Expected result: authenticated and public data remain separated, the publish is recorded, and no project credentials appear in exported project data.

3. Prove external recovery

MP-OPT

Create a named complete recovery snapshot. Deep-verify it using the private age identity through the hidden prompt, then export one portable copy to the trusted workstation.

Workstation

Accept the copy only after the generated transfer workflow reportsMP-OPT SNAPSHOT VERIFIED. Store the encrypted package and private identity separately, each with a second protected copy.

Expected result: the recorded package hash matches, the snapshot receipt and manifest verify, and the private identity is absent from the VPS.

4. Record the baseline and hand off

  • Record the hostname, deployment date, snapshot name, package SHA-256, verification date, and custodians.
  • Remove the disposable event and revoke its publishing secret if it will not be retained.
  • Give planners and web administrators links to the User Guide, not access to VPS or recovery credentials.
  • Schedule routine health, snapshot-age, external-copy, and restore-practice reviews.