Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Installing the Test Datastore Server

This procedure installs the confirmed AHRI TRE Test Datastore on an empty MinisForum. It does not upgrade or adopt an earlier installation. For an existing server, use Updating the Test Datastore Server. For clean-host installed-package qualification, use Preparing Secrets for Clean-Host Installed-Package Conformance instead; its harness must remain the only package installer.

The worked example installs:

  • Ubuntu MinisForum svrltreapcc02 at 192.168.31.75;
  • AHRI TRE server v0.10.8;
  • PostgreSQL ORCID validator v0.10.8; and
  • release-bound MinisForum site kit 0.3.14.

Publication gate: do not begin this procedure until the GitHub v0.10.8 release actually lists both the 0.3.14 archive and its .sha256 asset. The download in Section 4 must fail closed while those assets are unpublished.

There are three command locations:

  • WSL2 is the Ubuntu terminal on the Windows 11 desktop. Downloads and certificate signing happen there.
  • MinisForum is the Ubuntu server shell whose prompt starts with sysadmin@svrltreapcc02.
  • Browser is a Windows or MacBook browser used to retrieve the existing ORCID Sandbox application credential and later test login.

Copy each command as one complete line. Do not copy a displayed prompt. If less opens a file, press q to return to the command prompt.

Kit 0.3.14 includes the root-only persistent Injected-secret authority and boot-time projector qualified in kit 0.3.6, plus corrected canonical ORCID admission. PostgreSQL and the Trusted runtime start only after the projector has recreated and verified their files under Ubuntu’s ephemeral /run filesystem.

The server directory is the release-bound v0.10.8 package composed for kit 0.3.14. Its server manifest, site configuration, validator image, and checksums are one unit; do not combine them with an earlier kit.

Never put a password, private key, client secret, authorization code, or token in the repository, release kit, command-line argument, screenshot, ticket, or retained terminal log.

What “empty MinisForum” means

This procedure requires all of the following to be absent on the MinisForum:

  • an ahri-tre-postgresql container;
  • /data/ahri-tre/postgresql;
  • /etc/ahri-tre/config.toml; and
  • an existing AHRI TRE Managed-secret store or Datastore.

An empty server does not mean an empty certificate and credential history. The published site kit already contains the Runtime public certificate, the PostgreSQL public CA, and the public ORCID client ID. Before starting, the site operator must still possess:

  1. the Runtime private key matching the certificate in kit 0.3.14;
  2. the PostgreSQL CA private key matching the public CA in kit 0.3.14; and
  3. the ORCID Sandbox client secret for client ID APP-267KB7OA1UIVOI14.

For this installation, place the two retained private keys at these protected paths in WSL2, outside the repository:

/home/kobus/ahri-tre-pki/private/runtime-private-key.pem
/home/kobus/ahri-tre-pki/private/postgresql-ca-private-key.pem

If either private key is unavailable, stop. Do not generate a replacement and pair it with the published public material. Issue new certificates and build a new immutable site kit instead. If the intent is to restore an old Datastore, stop and use a recovery procedure with its original Deployment root identity; this fresh-install procedure creates a new identity.

1. MinisForum: verify the host foundation

Install Ubuntu 26.04 LTS x86-64, reserve 192.168.31.75 for this host, set the hostname to svrltreapcc02, and mount the persistent data filesystem at /data. Then connect by SSH and run:

hostname -s

Expected: svrltreapcc02.

ip -4 -o address show | grep -F ' 192.168.31.75/'

The command must print the assigned address.

findmnt /data
df -h /data

Both commands must show the intended persistent data filesystem. Do not continue if /data is merely a directory on the Ubuntu root filesystem.

Confirm that this really is a fresh installation:

sudo test ! -e /data/ahri-tre/postgresql && echo 'PostgreSQL data path is unused'
sudo test ! -e /etc/ahri-tre/config.toml && echo 'AHRI TRE configuration is absent'
sudo docker inspect ahri-tre-postgresql >/dev/null 2>&1; test $? -ne 0 && echo 'PostgreSQL container is absent'

All three commands must print the stated confirmation. If docker is not yet installed, the final command may instead report that sudo: docker is not found; that is acceptable at this point.

2. MinisForum: install operating-system prerequisites

Install the utilities consumed by the release-bound scripts:

sudo apt-get update
sudo apt-get install -y age ca-certificates curl jq openssl

The host-side PostgreSQL operator uses PostgreSQL 18 psql, pg_dump, and pg_restore even though the database server itself runs in Docker. Configure the PostgreSQL project’s repository and install only its client package by following the official Ubuntu package instructions:

sudo apt-get install -y postgresql-common
sudo /usr/share/postgresql-common/pgdg/apt.postgresql.org.sh
sudo apt-get update
sudo apt-get install -y postgresql-client-18
psql --version
pg_dump --version

Both version commands must report PostgreSQL 18. Do not install an Ubuntu PostgreSQL server package; the released managed container owns the server.

Install Docker Engine using Docker’s current official Ubuntu instructions. Use one supported Docker installation; do not mix Ubuntu’s conflicting Docker packages with Docker’s official packages.

Verify the result on the MinisForum:

sudo systemctl enable --now docker.service
sudo docker version
sudo docker network inspect bridge --format '{{(index .IPAM.Config 0).Gateway}}'

For kit 0.3.14 the last command must print 172.17.0.1. The generated HBA policy is restricted to that exact bridge gateway. Stop rather than editing the generated policy if the address differs.

3. WSL2: verify retained certificate authority material

Run these commands in WSL2, not on the MinisForum:

sudo test -s /home/kobus/ahri-tre-pki/private/runtime-private-key.pem
sudo test -s /home/kobus/ahri-tre-pki/private/postgresql-ca-private-key.pem
test -s /home/kobus/ahri-tre-pki/public/postgresql-ca-chain.pem

Confirm that the PostgreSQL CA private key matches its public certificate without displaying the key:

sudo openssl pkey -in /home/kobus/ahri-tre-pki/private/postgresql-ca-private-key.pem -pubout -outform DER | sha256sum
openssl x509 -in /home/kobus/ahri-tre-pki/public/postgresql-ca-chain.pem -pubkey -noout | openssl pkey -pubin -outform DER | sha256sum

The two SHA-256 values must be identical. Stop if they differ.

4. WSL2: download and verify the published kit

Create a version-specific download directory:

mkdir -p ~/ahri-tre-install/v0.10.8

Download the complete site kit and checksum from GitHub:

gh release download v0.10.8 --repo AHRIORG/ahri-tre-rs --pattern 'ahri-tre-test-datastore-deployment-kit-0.3.14.tar.gz' --pattern 'ahri-tre-test-datastore-deployment-kit-0.3.14.tar.gz.sha256' --dir ~/ahri-tre-install/v0.10.8

Verify the archive:

cd ~/ahri-tre-install/v0.10.8
sha256sum --check ahri-tre-test-datastore-deployment-kit-0.3.14.tar.gz.sha256

Stop unless the result is:

ahri-tre-test-datastore-deployment-kit-0.3.14.tar.gz: OK

5. WSL2: transfer the public kit

Create a protected transfer directory on the MinisForum:

ssh sysadmin@192.168.31.75 'umask 077; mkdir -p ~/ahri-tre-transfer/v0.10.8'

Copy the verified release files:

scp ahri-tre-test-datastore-deployment-kit-0.3.14.tar.gz ahri-tre-test-datastore-deployment-kit-0.3.14.tar.gz.sha256 sysadmin@192.168.31.75:ahri-tre-transfer/v0.10.8/

The kit contains only public configuration, certificates, binaries, the validator image, and provenance evidence. Secret material is projected separately below.

6. MinisForum: verify and extract the kit

Connect from WSL2:

ssh sysadmin@192.168.31.75

On the MinisForum, run:

cd ~/ahri-tre-transfer/v0.10.8
sha256sum --check ahri-tre-test-datastore-deployment-kit-0.3.14.tar.gz.sha256

Stop unless the result says OK. Then extract and enter the kit:

tar -xzf ahri-tre-test-datastore-deployment-kit-0.3.14.tar.gz
cd ~/ahri-tre-transfer/v0.10.8/ahri-tre-test-datastore-deployment-kit-0.3.14

All relative server/... and site/... paths from this point refer to this directory on the MinisForum.

Confirm the public site identity:

jq '{hostname, ipv4_address, kit_version, datastore_id, runtime_dns_name, client_id: .oidc.client_id, validator: .validator_release.image_reference}' site/site-inputs.json

Expected values include svrltreapcc02, 192.168.31.75, 0.3.14, ahri-tre-test, runtime.svrltreapcc02.home.arpa, APP-267KB7OA1UIVOI14, and validator 0.10.8.

7. MinisForum: install local name resolution

The Runtime HTTPS name resolves to the MinisForum LAN address. PostgreSQL’s TLS name resolves locally while the connection route remains loopback-only.

Check for conflicting entries:

grep -nE 'runtime\.svrltreapcc02\.home\.arpa|postgres\.svrltreapcc02\.home\.arpa' /etc/hosts || true

If either name already maps to another address, correct that entry instead of adding a duplicate. Otherwise add the two mappings:

printf '%s\n' '192.168.31.75 runtime.svrltreapcc02.home.arpa' '127.0.0.1 postgres.svrltreapcc02.home.arpa' | sudo tee -a /etc/hosts >/dev/null

Verify them:

getent ahostsv4 runtime.svrltreapcc02.home.arpa
getent ahostsv4 postgres.svrltreapcc02.home.arpa

The first output must include 192.168.31.75; the second must include 127.0.0.1.

Before client qualification, also apply the Runtime mapping from site/name-resolution.md to Windows, WSL2, and the MacBook. Do not map the PostgreSQL name on clients; PostgreSQL is not exposed to the LAN.

Review the generated firewall plan:

less site/firewall-plan.json

It requires default-deny inbound traffic, SSH administration, Runtime HTTPS from 192.168.31.0/24, and no non-loopback PostgreSQL access. Press q, then apply that policy with Ubuntu’s firewall. Allow SSH before enabling the firewall so the current connection is not locked out:

sudo apt-get install -y ufw
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow OpenSSH
sudo ufw allow from 192.168.31.0/24 to 192.168.31.75 port 443 proto tcp
sudo ufw deny 5432/tcp
sudo ufw enable
sudo ufw status verbose

Do not continue unless the existing SSH session remains connected and the reported policy matches site/firewall-plan.json.

8. MinisForum: install the AHRI TRE server package

For a blank host use install.sh, never upgrade.sh:

sudo server/install.sh

This installs the v0.10.8 binaries and creates the service identities, but it does not start the Runtime before its configuration and Secrets exist.

Verify the identities and component manifest:

id ahri-tre-runtime
getent group ahri-tre-oidc
sudo test -s /usr/share/ahri-tre/server/component-versions.json && echo 'Server manifest installed'

All three checks must succeed.

Create the root-owned shared projection namespaces before creating Secret leaves. Mode 0711 permits traversal to separately restricted leaf directories without making any Secret value readable:

sudo install -d -o root -g root -m 0755 /run/secrets
sudo install -d -o root -g root -m 0711 \
  /run/secrets/ahri-tre \
  /run/secrets/oidc \
  /run/secrets/postgres \
  /run/secrets/postgres/tls \
  /run/secrets/runtime

Verify the shared namespace contract:

test "$(sudo stat -c '%U:%G:%a' /run/secrets)" = root:root:755
for namespace in ahri-tre oidc postgres postgres/tls runtime; do
  test "$(sudo stat -c '%U:%G:%a' "/run/secrets/$namespace")" = root:root:711
done

9. MinisForum and WSL2: issue the PostgreSQL server certificate

On the MinisForum, generate the PostgreSQL server private key and public CSR. Numeric ownership 999:999 is the PostgreSQL identity inside the released container; Ubuntu does not need a host user named 999.

sudo install -d -m 0700 /run/secrets/postgres/tls/private-key
sudo chown 999:999 /run/secrets/postgres/tls/private-key
sudo env OPENSSL_CONF=/dev/null openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:3072 -out /run/secrets/postgres/tls/private-key/value
sudo chown 999:999 /run/secrets/postgres/tls/private-key/value
sudo chmod 0400 /run/secrets/postgres/tls/private-key/value
sudo env OPENSSL_CONF=/dev/null openssl req -new -key /run/secrets/postgres/tls/private-key/value -subj '/CN=postgres.svrltreapcc02.home.arpa' -addext 'subjectAltName=DNS:postgres.svrltreapcc02.home.arpa' -out /tmp/postgres.svrltreapcc02.home.arpa.csr
sudo chown sysadmin:sysadmin /tmp/postgres.svrltreapcc02.home.arpa.csr

In WSL2, copy only the public CSR back and verify it:

install -d -m 0700 /home/kobus/ahri-tre-pki/requests
scp sysadmin@192.168.31.75:/tmp/postgres.svrltreapcc02.home.arpa.csr /home/kobus/ahri-tre-pki/requests/
openssl req -in /home/kobus/ahri-tre-pki/requests/postgres.svrltreapcc02.home.arpa.csr -verify -noout

Still in WSL2, create the public certificate extension file:

printf '%s\n' 'basicConstraints=critical,CA:FALSE' 'keyUsage=critical,digitalSignature,keyEncipherment' 'extendedKeyUsage=serverAuth' 'subjectAltName=DNS:postgres.svrltreapcc02.home.arpa' > /tmp/postgresql-server-certificate.ext

Sign the public CSR with the retained PostgreSQL CA:

sudo openssl x509 -req -sha256 -days 825 -in /home/kobus/ahri-tre-pki/requests/postgres.svrltreapcc02.home.arpa.csr -CA /home/kobus/ahri-tre-pki/public/postgresql-ca-chain.pem -CAkey /home/kobus/ahri-tre-pki/private/postgresql-ca-private-key.pem -CAcreateserial -extfile /tmp/postgresql-server-certificate.ext -out /home/kobus/ahri-tre-pki/public/postgres.svrltreapcc02.home.arpa.pem

Copy only the public leaf certificate to the MinisForum:

scp /home/kobus/ahri-tre-pki/public/postgres.svrltreapcc02.home.arpa.pem sysadmin@192.168.31.75:ahri-tre-transfer/v0.10.8/

On the MinisForum, install and verify it:

sudo install -D -m 0444 ~/ahri-tre-transfer/v0.10.8/postgres.svrltreapcc02.home.arpa.pem /etc/ahri-tre/postgresql/tls/certificate.pem
sudo chown 999:999 /etc/ahri-tre/postgresql/tls/certificate.pem
sudo env OPENSSL_CONF=/dev/null openssl verify -CAfile site/postgresql/public-ca-chain.pem /etc/ahri-tre/postgresql/tls/certificate.pem
sudo env OPENSSL_CONF=/dev/null openssl x509 -in /etc/ahri-tre/postgresql/tls/certificate.pem -noout -checkhost postgres.svrltreapcc02.home.arpa
sudo stat -c '%u:%g:%a %n' /etc/ahri-tre/postgresql/tls/certificate.pem /run/secrets/postgres/tls/private-key/value

The certificate check must succeed. The final output must show 999:999:444 for the certificate and 999:999:400 for the private key.

10. MinisForum: create the PostgreSQL password projections

Create the protected directories:

sudo install -d -o root -g root -m 0700 /run/secrets/postgres/bootstrap-password /run/secrets/postgres/administrator-passfile
sudo install -d -o ahri-tre-runtime -g ahri-tre-runtime -m 0700 /run/secrets/postgres/administrator-password

Start a temporary root shell:

sudo bash

The prompt changes from $ to #. Paste this block at the # prompt:

set -eu
umask 077
postgres_password="$(env OPENSSL_CONF=/dev/null openssl rand -hex 32)"
printf '%s' "$postgres_password" > /run/secrets/postgres/bootstrap-password/value
printf '%s' "$postgres_password" > /run/secrets/postgres/administrator-password/value
printf '%s\n' "postgres.svrltreapcc02.home.arpa:5432:*:ahri_tre_administrator:${postgres_password}" > /run/secrets/postgres/administrator-passfile/value
unset postgres_password
printf '%s' 'site-v3' > /run/secrets/postgres/administrator-password/version
chown root:root /run/secrets/postgres/bootstrap-password/value /run/secrets/postgres/administrator-passfile/value
chmod 0400 /run/secrets/postgres/bootstrap-password/value
chmod 0600 /run/secrets/postgres/administrator-passfile/value
chown ahri-tre-runtime:ahri-tre-runtime /run/secrets/postgres/administrator-password/value /run/secrets/postgres/administrator-password/version
chmod 0400 /run/secrets/postgres/administrator-password/value /run/secrets/postgres/administrator-password/version
exit

The prompt returns to $. Verify equality without displaying the password:

sudo cmp --silent /run/secrets/postgres/bootstrap-password/value /run/secrets/postgres/administrator-password/value && echo 'PostgreSQL password projections match'

The confirmation must be printed.

11. Browser and MinisForum: project the ORCID client secret

In a browser, sign in to ORCID Sandbox Developer Tools, open application APP-267KB7OA1UIVOI14, and copy its client secret. Confirm that its redirect URI is exactly:

https://runtime.svrltreapcc02.home.arpa/v1/runtime-login/callback

Back at the MinisForum SSH prompt, create the protected directory:

sudo install -d -o root -g ahri-tre-oidc -m 0750 /run/secrets/oidc/client-secret

Start a temporary root shell:

sudo bash

At the # prompt, run:

IFS= read -r -s -p 'Paste the ORCID Sandbox client secret, then press Enter: ' orcid_client_secret

Paste the secret and press Enter. No characters are displayed. Then run:

printf '\n'
test -n "$orcid_client_secret"
umask 027
printf '%s' "$orcid_client_secret" > /run/secrets/oidc/client-secret/value
unset orcid_client_secret
printf '%s' 'site-v3' > /run/secrets/oidc/client-secret/version
chown root:ahri-tre-oidc /run/secrets/oidc/client-secret/value /run/secrets/oidc/client-secret/version
chmod 0440 /run/secrets/oidc/client-secret/value /run/secrets/oidc/client-secret/version
exit

Verify only ownership and modes:

sudo stat -c '%U:%G %a %n' /run/secrets/oidc/client-secret/value /run/secrets/oidc/client-secret/version

Both lines must start with root:ahri-tre-oidc 440.

12. WSL2 and MinisForum: project the Runtime private key

In WSL2, copy the retained matching Runtime key to a temporary protected file on the MinisForum:

sudo install -o kobus -g kobus -m 0400 /home/kobus/ahri-tre-pki/private/runtime-private-key.pem /tmp/runtime-private-key.transfer
scp /tmp/runtime-private-key.transfer sysadmin@192.168.31.75:runtime-private-key.transfer
rm -- /tmp/runtime-private-key.transfer

On the MinisForum, project it and remove the transfer copy:

sudo install -d -o ahri-tre-runtime -g ahri-tre-runtime -m 0700 /run/secrets/runtime/private-key
sudo install -o ahri-tre-runtime -g ahri-tre-runtime -m 0400 /home/sysadmin/runtime-private-key.transfer /run/secrets/runtime/private-key/value
printf '%s' 'site-v3' | sudo tee /run/secrets/runtime/private-key/version >/dev/null
sudo chown ahri-tre-runtime:ahri-tre-runtime /run/secrets/runtime/private-key/version
sudo chmod 0400 /run/secrets/runtime/private-key/version
rm -- /home/sysadmin/runtime-private-key.transfer
sudo -u ahri-tre-runtime env OPENSSL_CONF=/dev/null openssl pkey -in /run/secrets/runtime/private-key/value -check -noout

The final command must report a valid key.

13. MinisForum and WSL2: create and back up the root identity

The root identity decrypts this Deployment’s Managed-secret store. It is not an ORCID identity or TLS key. Create it only once:

sudo install -d -o root -g root -m 0700 /root/ahri-tre-recovery
sudo test ! -e /root/ahri-tre-recovery/minisforum-root-identity.txt || { echo 'STOP: root identity already exists'; exit 1; }
sudo bash -c 'set -eu; umask 077; age-keygen | sed -n "/^AGE-SECRET-KEY-1/p" > /root/ahri-tre-recovery/minisforum-root-identity.txt; test -s /root/ahri-tre-recovery/minisforum-root-identity.txt'

Project it for the Runtime:

sudo install -d -o ahri-tre-runtime -g ahri-tre-runtime -m 0700 /run/secrets/ahri-tre/root-identity
sudo install -o ahri-tre-runtime -g ahri-tre-runtime -m 0400 /root/ahri-tre-recovery/minisforum-root-identity.txt /run/secrets/ahri-tre/root-identity/value
printf '%s' 'site-v3' | sudo tee /run/secrets/ahri-tre/root-identity/version >/dev/null
sudo chown ahri-tre-runtime:ahri-tre-runtime /run/secrets/ahri-tre/root-identity/version
sudo chmod 0400 /run/secrets/ahri-tre/root-identity/version

Create a temporary transfer copy:

sudo install -o sysadmin -g sysadmin -m 0400 /root/ahri-tre-recovery/minisforum-root-identity.txt /home/sysadmin/minisforum-root-identity.transfer

In WSL2, retrieve the separate recovery copy:

install -d -m 0700 /home/kobus/ahri-tre-recovery
scp sysadmin@192.168.31.75:/home/sysadmin/minisforum-root-identity.transfer /home/kobus/ahri-tre-recovery/minisforum-root-identity.txt
chmod 0400 /home/kobus/ahri-tre-recovery/minisforum-root-identity.txt
grep -q '^AGE-SECRET-KEY-1' /home/kobus/ahri-tre-recovery/minisforum-root-identity.txt && echo 'Separate root-identity backup is valid'

Back on the MinisForum, remove only the temporary transfer file:

rm -- /home/sysadmin/minisforum-root-identity.transfer

Keep the WSL2 recovery copy separate from Datastore backups.

14. MinisForum: verify every Secret projection

This check displays only paths, numeric identities, and modes:

sudo stat -c '%U(%u):%G(%g) %a %n' /run/secrets /run/secrets/ahri-tre /run/secrets/oidc /run/secrets/postgres /run/secrets/postgres/tls /run/secrets/runtime /run/secrets/postgres/bootstrap-password/value /run/secrets/postgres/administrator-password/value /run/secrets/postgres/administrator-password/version /run/secrets/postgres/administrator-passfile/value /run/secrets/postgres/tls/private-key/value /run/secrets/oidc/client-secret/value /run/secrets/oidc/client-secret/version /run/secrets/runtime/private-key/value /run/secrets/runtime/private-key/version /run/secrets/ahri-tre/root-identity/value /run/secrets/ahri-tre/root-identity/version

Compare the output with site/injected-secrets.json. Required results are:

  • bootstrap password: root:root 400;
  • administrator password and version: ahri-tre-runtime:ahri-tre-runtime 400;
  • administrator passfile: root:root 600;
  • PostgreSQL key: numeric 999:999 400;
  • ORCID client secret and version: root:ahri-tre-oidc 440;
  • Runtime key and version: ahri-tre-runtime:ahri-tre-runtime 400; and
  • root identity and version: ahri-tre-runtime:ahri-tre-runtime 400.

The Ubuntu host may display UID/GID 999 with unrelated names. The numeric values are authoritative. Never use cat, less, head, or an editor on a Secret value file.

15. MinisForum: install the boot-time Secret projector

This explicit installation copies the current, verified projections into the root-only persistent authority at /var/lib/ahri-tre/injected-secret-authority. It then installs and starts the projector service. It does not print Secret contents.

sudo site/install-secret-projector.sh --confirm-host svrltreapcc02 --confirm-address 192.168.31.75

Expected:

installed and verified the boot-time Injected-secret projector

Verify both persistent sources and ephemeral projections:

sudo /usr/libexec/ahri-tre/secret-projector.sh verify

Expected: verified persistent and projected Injected secrets.

sudo systemctl is-active ahri-tre-secret-projector.service

Expected: active. Do not continue if capture or verification fails. Never open files beneath the persistent authority with cat, less, or an editor. The authority is Secret material, not a normal Datastore backup: exclude it from broad file backups and protect the MinisForum system disk and root account to the same standard as the original private keys and passwords.

16. MinisForum: install managed PostgreSQL

Review, but do not edit, the generated policy:

less site/postgresql/deployment-contract.json
less site/postgresql/pg_hba.conf
less site/postgresql/pg_ident.conf

Press q after each file. Then install PostgreSQL:

sudo site/postgresql/install.sh --confirm-host svrltreapcc02 --confirm-address 192.168.31.75

Wait for health:

sudo docker inspect --format '{{.Config.Image}} {{.State.Health.Status}}' ahri-tre-postgresql

Expected:

ahri-tre/postgresql-orcid-validator:0.10.8 healthy

Confirm PostgreSQL is loopback-only:

sudo ss -ltnp '( sport = :5432 )'

The local address must be 127.0.0.1:5432, never 0.0.0.0:5432 or 192.168.31.75:5432.

17. MinisForum: provision the Runtime and create the Datastore

Run the release-bound provisioner once:

sudo site/provision.sh --confirm-host svrltreapcc02 --confirm-address 192.168.31.75

The command installs Application configuration, initializes the Managed-secret store, starts the Runtime, and creates ahri-tre-test. It may print only the commands that perform visible work.

Verify everything explicitly:

sudo systemctl is-active ahri-tre-runtime.service

Expected: active.

sudo site/verify-readiness.sh

Expected: MinisForum v3 site is ready.

D=ahri-tre-test; R=/usr/libexec/ahri-tre/ahri-tre-runtime; sudo -u ahri-tre-runtime env LD_LIBRARY_PATH=/usr/lib/ahri-tre "$R" datastore reconcile "$D"

Expected: JSON containing "status":"ready". Record its public datastore_id; do not alter the binding.

18. MinisForum: prove reboot persistence

Reboot the MinisForum:

sudo reboot

The SSH connection closes. Wait about one minute, then reconnect from WSL2:

ssh sysadmin@192.168.31.75

On the MinisForum, verify the ordered services:

sudo systemctl is-active ahri-tre-secret-projector.service ahri-tre-postgresql.service ahri-tre-runtime.service

Expected: three lines, each saying active.

sudo /usr/libexec/ahri-tre/secret-projector.sh verify
cd ~/ahri-tre-transfer/v0.10.8/ahri-tre-test-datastore-deployment-kit-0.3.14
sudo site/verify-readiness.sh

Expected: projection verification succeeds and readiness prints MinisForum v3 site is ready. If any service or check fails, keep the persistent authority and all rollback material, and diagnose before continuing.

19. MinisForum: make the first Datastore backup

Create and verify a bounded backup:

sudo install -d -o root -g root -m 0700 /var/backups/ahri-tre/manual
sudo site/backup.sh /var/backups/ahri-tre/manual/initial-v0.10.8.dump
sudo find /var/backups/ahri-tre -maxdepth 2 -type f -printf '%TY-%Tm-%Td %TH:%TM %p\n' | sort

Keep the Deployment root identity backup separate from these data backups. Both are required for recovery.

20. Browser/client and MinisForum: qualify ORCID admission

On the MinisForum, admit one real ORCID Sandbox identity using its canonical public iD:

sudo site/admit-user.sh REPLACE_WITH_ADMITTED_ORCID_ID

Replace the final value with the real canonical hyphenated iD, in the form 0000-0000-0000-0000. Do not add the internal orcid_ role prefix.

From a configured WSL2 or MacBook client:

  1. sign in with that Sandbox identity and open the ahri-tre-test Datastore Session; it must succeed;
  2. sign out and use a second real, valid Sandbox identity that was not admitted; Session opening must be rejected; and
  3. retain only the outcome, never a token.

The deterministic invalid-token evidence is already published in site/validator/qualification-result.json. Do not mint synthetic ORCID tokens on the MinisForum.

Only these public files may proceed to the client installation workflows:

  • site/client.toml;
  • site/public-ca-chain.pem; and
  • site/name-resolution.md.

Do not publish Application configuration, PostgreSQL policy, Secret projections, private keys, credentials, or validator administration material.

Installing a future release

Do not replace version numbers mechanically. A future installation must use a site kit generated for the intended hostname, address, certificates, ORCID registration, storage paths, and release artifacts. Download its archive and checksum together, follow that kit’s release-specific requirements, and never mix files between kit versions.