Installing the Test Datastore Server
This procedure installs the confirmed AHRI TRE Test Datastore on an empty MinisForum. It does not upgrade or adopt an earlier installation. For an existing server, use Updating the Test Datastore Server. For clean-host installed-package qualification, use Preparing Secrets for Clean-Host Installed-Package Conformance instead; its harness must remain the only package installer.
The worked example installs:
- Ubuntu MinisForum
svrltreapcc02at192.168.31.75; - AHRI TRE server v0.10.8;
- PostgreSQL ORCID validator v0.10.8; and
- release-bound MinisForum site kit 0.3.14.
Publication gate: do not begin this procedure until the GitHub v0.10.8 release actually lists both the 0.3.14 archive and its
.sha256asset. The download in Section 4 must fail closed while those assets are unpublished.
There are three command locations:
- WSL2 is the Ubuntu terminal on the Windows 11 desktop. Downloads and certificate signing happen there.
- MinisForum is the Ubuntu server shell whose prompt starts with
sysadmin@svrltreapcc02. - Browser is a Windows or MacBook browser used to retrieve the existing ORCID Sandbox application credential and later test login.
Copy each command as one complete line. Do not copy a displayed prompt. If
less opens a file, press q to return to the command prompt.
Kit 0.3.14 includes the root-only persistent Injected-secret authority and
boot-time projector qualified in kit 0.3.6, plus corrected canonical ORCID
admission. PostgreSQL and the Trusted runtime start only after the projector
has recreated and verified their files under Ubuntu’s ephemeral /run
filesystem.
The server directory is the release-bound v0.10.8 package composed for kit 0.3.14. Its server manifest, site configuration, validator image, and checksums are one unit; do not combine them with an earlier kit.
Never put a password, private key, client secret, authorization code, or token in the repository, release kit, command-line argument, screenshot, ticket, or retained terminal log.
What “empty MinisForum” means
This procedure requires all of the following to be absent on the MinisForum:
- an
ahri-tre-postgresqlcontainer; /data/ahri-tre/postgresql;/etc/ahri-tre/config.toml; and- an existing AHRI TRE Managed-secret store or Datastore.
An empty server does not mean an empty certificate and credential history. The published site kit already contains the Runtime public certificate, the PostgreSQL public CA, and the public ORCID client ID. Before starting, the site operator must still possess:
- the Runtime private key matching the certificate in kit 0.3.14;
- the PostgreSQL CA private key matching the public CA in kit 0.3.14; and
- the ORCID Sandbox client secret for client ID
APP-267KB7OA1UIVOI14.
For this installation, place the two retained private keys at these protected paths in WSL2, outside the repository:
/home/kobus/ahri-tre-pki/private/runtime-private-key.pem
/home/kobus/ahri-tre-pki/private/postgresql-ca-private-key.pem
If either private key is unavailable, stop. Do not generate a replacement and pair it with the published public material. Issue new certificates and build a new immutable site kit instead. If the intent is to restore an old Datastore, stop and use a recovery procedure with its original Deployment root identity; this fresh-install procedure creates a new identity.
1. MinisForum: verify the host foundation
Install Ubuntu 26.04 LTS x86-64, reserve 192.168.31.75 for this host, set the
hostname to svrltreapcc02, and mount the persistent data filesystem at
/data. Then connect by SSH and run:
hostname -s
Expected: svrltreapcc02.
ip -4 -o address show | grep -F ' 192.168.31.75/'
The command must print the assigned address.
findmnt /data
df -h /data
Both commands must show the intended persistent data filesystem. Do not
continue if /data is merely a directory on the Ubuntu root filesystem.
Confirm that this really is a fresh installation:
sudo test ! -e /data/ahri-tre/postgresql && echo 'PostgreSQL data path is unused'
sudo test ! -e /etc/ahri-tre/config.toml && echo 'AHRI TRE configuration is absent'
sudo docker inspect ahri-tre-postgresql >/dev/null 2>&1; test $? -ne 0 && echo 'PostgreSQL container is absent'
All three commands must print the stated confirmation. If docker is not yet
installed, the final command may instead report that sudo: docker is not
found; that is acceptable at this point.
2. MinisForum: install operating-system prerequisites
Install the utilities consumed by the release-bound scripts:
sudo apt-get update
sudo apt-get install -y age ca-certificates curl jq openssl
The host-side PostgreSQL operator uses PostgreSQL 18 psql, pg_dump, and
pg_restore even though the database server itself runs in Docker. Configure
the PostgreSQL project’s repository and install only its client package by
following the official Ubuntu package instructions:
sudo apt-get install -y postgresql-common
sudo /usr/share/postgresql-common/pgdg/apt.postgresql.org.sh
sudo apt-get update
sudo apt-get install -y postgresql-client-18
psql --version
pg_dump --version
Both version commands must report PostgreSQL 18. Do not install an Ubuntu PostgreSQL server package; the released managed container owns the server.
Install Docker Engine using Docker’s current official Ubuntu instructions. Use one supported Docker installation; do not mix Ubuntu’s conflicting Docker packages with Docker’s official packages.
Verify the result on the MinisForum:
sudo systemctl enable --now docker.service
sudo docker version
sudo docker network inspect bridge --format '{{(index .IPAM.Config 0).Gateway}}'
For kit 0.3.14 the last command must print 172.17.0.1. The generated HBA
policy is restricted to that exact bridge gateway. Stop rather than editing
the generated policy if the address differs.
3. WSL2: verify retained certificate authority material
Run these commands in WSL2, not on the MinisForum:
sudo test -s /home/kobus/ahri-tre-pki/private/runtime-private-key.pem
sudo test -s /home/kobus/ahri-tre-pki/private/postgresql-ca-private-key.pem
test -s /home/kobus/ahri-tre-pki/public/postgresql-ca-chain.pem
Confirm that the PostgreSQL CA private key matches its public certificate without displaying the key:
sudo openssl pkey -in /home/kobus/ahri-tre-pki/private/postgresql-ca-private-key.pem -pubout -outform DER | sha256sum
openssl x509 -in /home/kobus/ahri-tre-pki/public/postgresql-ca-chain.pem -pubkey -noout | openssl pkey -pubin -outform DER | sha256sum
The two SHA-256 values must be identical. Stop if they differ.
4. WSL2: download and verify the published kit
Create a version-specific download directory:
mkdir -p ~/ahri-tre-install/v0.10.8
Download the complete site kit and checksum from GitHub:
gh release download v0.10.8 --repo AHRIORG/ahri-tre-rs --pattern 'ahri-tre-test-datastore-deployment-kit-0.3.14.tar.gz' --pattern 'ahri-tre-test-datastore-deployment-kit-0.3.14.tar.gz.sha256' --dir ~/ahri-tre-install/v0.10.8
Verify the archive:
cd ~/ahri-tre-install/v0.10.8
sha256sum --check ahri-tre-test-datastore-deployment-kit-0.3.14.tar.gz.sha256
Stop unless the result is:
ahri-tre-test-datastore-deployment-kit-0.3.14.tar.gz: OK
5. WSL2: transfer the public kit
Create a protected transfer directory on the MinisForum:
ssh sysadmin@192.168.31.75 'umask 077; mkdir -p ~/ahri-tre-transfer/v0.10.8'
Copy the verified release files:
scp ahri-tre-test-datastore-deployment-kit-0.3.14.tar.gz ahri-tre-test-datastore-deployment-kit-0.3.14.tar.gz.sha256 sysadmin@192.168.31.75:ahri-tre-transfer/v0.10.8/
The kit contains only public configuration, certificates, binaries, the validator image, and provenance evidence. Secret material is projected separately below.
6. MinisForum: verify and extract the kit
Connect from WSL2:
ssh sysadmin@192.168.31.75
On the MinisForum, run:
cd ~/ahri-tre-transfer/v0.10.8
sha256sum --check ahri-tre-test-datastore-deployment-kit-0.3.14.tar.gz.sha256
Stop unless the result says OK. Then extract and enter the kit:
tar -xzf ahri-tre-test-datastore-deployment-kit-0.3.14.tar.gz
cd ~/ahri-tre-transfer/v0.10.8/ahri-tre-test-datastore-deployment-kit-0.3.14
All relative server/... and site/... paths from this point refer to this
directory on the MinisForum.
Confirm the public site identity:
jq '{hostname, ipv4_address, kit_version, datastore_id, runtime_dns_name, client_id: .oidc.client_id, validator: .validator_release.image_reference}' site/site-inputs.json
Expected values include svrltreapcc02, 192.168.31.75, 0.3.14,
ahri-tre-test, runtime.svrltreapcc02.home.arpa,
APP-267KB7OA1UIVOI14, and validator 0.10.8.
7. MinisForum: install local name resolution
The Runtime HTTPS name resolves to the MinisForum LAN address. PostgreSQL’s TLS name resolves locally while the connection route remains loopback-only.
Check for conflicting entries:
grep -nE 'runtime\.svrltreapcc02\.home\.arpa|postgres\.svrltreapcc02\.home\.arpa' /etc/hosts || true
If either name already maps to another address, correct that entry instead of adding a duplicate. Otherwise add the two mappings:
printf '%s\n' '192.168.31.75 runtime.svrltreapcc02.home.arpa' '127.0.0.1 postgres.svrltreapcc02.home.arpa' | sudo tee -a /etc/hosts >/dev/null
Verify them:
getent ahostsv4 runtime.svrltreapcc02.home.arpa
getent ahostsv4 postgres.svrltreapcc02.home.arpa
The first output must include 192.168.31.75; the second must include
127.0.0.1.
Before client qualification, also apply the Runtime mapping from
site/name-resolution.md to Windows, WSL2, and the MacBook. Do not map the
PostgreSQL name on clients; PostgreSQL is not exposed to the LAN.
Review the generated firewall plan:
less site/firewall-plan.json
It requires default-deny inbound traffic, SSH administration, Runtime HTTPS
from 192.168.31.0/24, and no non-loopback PostgreSQL access. Press q, then
apply that policy with Ubuntu’s firewall. Allow SSH before enabling the
firewall so the current connection is not locked out:
sudo apt-get install -y ufw
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow OpenSSH
sudo ufw allow from 192.168.31.0/24 to 192.168.31.75 port 443 proto tcp
sudo ufw deny 5432/tcp
sudo ufw enable
sudo ufw status verbose
Do not continue unless the existing SSH session remains connected and the
reported policy matches site/firewall-plan.json.
8. MinisForum: install the AHRI TRE server package
For a blank host use install.sh, never upgrade.sh:
sudo server/install.sh
This installs the v0.10.8 binaries and creates the service identities, but it does not start the Runtime before its configuration and Secrets exist.
Verify the identities and component manifest:
id ahri-tre-runtime
getent group ahri-tre-oidc
sudo test -s /usr/share/ahri-tre/server/component-versions.json && echo 'Server manifest installed'
All three checks must succeed.
Create the root-owned shared projection namespaces before creating Secret
leaves. Mode 0711 permits traversal to separately restricted leaf
directories without making any Secret value readable:
sudo install -d -o root -g root -m 0755 /run/secrets
sudo install -d -o root -g root -m 0711 \
/run/secrets/ahri-tre \
/run/secrets/oidc \
/run/secrets/postgres \
/run/secrets/postgres/tls \
/run/secrets/runtime
Verify the shared namespace contract:
test "$(sudo stat -c '%U:%G:%a' /run/secrets)" = root:root:755
for namespace in ahri-tre oidc postgres postgres/tls runtime; do
test "$(sudo stat -c '%U:%G:%a' "/run/secrets/$namespace")" = root:root:711
done
9. MinisForum and WSL2: issue the PostgreSQL server certificate
On the MinisForum, generate the PostgreSQL server private key and public CSR.
Numeric ownership 999:999 is the PostgreSQL identity inside the released
container; Ubuntu does not need a host user named 999.
sudo install -d -m 0700 /run/secrets/postgres/tls/private-key
sudo chown 999:999 /run/secrets/postgres/tls/private-key
sudo env OPENSSL_CONF=/dev/null openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:3072 -out /run/secrets/postgres/tls/private-key/value
sudo chown 999:999 /run/secrets/postgres/tls/private-key/value
sudo chmod 0400 /run/secrets/postgres/tls/private-key/value
sudo env OPENSSL_CONF=/dev/null openssl req -new -key /run/secrets/postgres/tls/private-key/value -subj '/CN=postgres.svrltreapcc02.home.arpa' -addext 'subjectAltName=DNS:postgres.svrltreapcc02.home.arpa' -out /tmp/postgres.svrltreapcc02.home.arpa.csr
sudo chown sysadmin:sysadmin /tmp/postgres.svrltreapcc02.home.arpa.csr
In WSL2, copy only the public CSR back and verify it:
install -d -m 0700 /home/kobus/ahri-tre-pki/requests
scp sysadmin@192.168.31.75:/tmp/postgres.svrltreapcc02.home.arpa.csr /home/kobus/ahri-tre-pki/requests/
openssl req -in /home/kobus/ahri-tre-pki/requests/postgres.svrltreapcc02.home.arpa.csr -verify -noout
Still in WSL2, create the public certificate extension file:
printf '%s\n' 'basicConstraints=critical,CA:FALSE' 'keyUsage=critical,digitalSignature,keyEncipherment' 'extendedKeyUsage=serverAuth' 'subjectAltName=DNS:postgres.svrltreapcc02.home.arpa' > /tmp/postgresql-server-certificate.ext
Sign the public CSR with the retained PostgreSQL CA:
sudo openssl x509 -req -sha256 -days 825 -in /home/kobus/ahri-tre-pki/requests/postgres.svrltreapcc02.home.arpa.csr -CA /home/kobus/ahri-tre-pki/public/postgresql-ca-chain.pem -CAkey /home/kobus/ahri-tre-pki/private/postgresql-ca-private-key.pem -CAcreateserial -extfile /tmp/postgresql-server-certificate.ext -out /home/kobus/ahri-tre-pki/public/postgres.svrltreapcc02.home.arpa.pem
Copy only the public leaf certificate to the MinisForum:
scp /home/kobus/ahri-tre-pki/public/postgres.svrltreapcc02.home.arpa.pem sysadmin@192.168.31.75:ahri-tre-transfer/v0.10.8/
On the MinisForum, install and verify it:
sudo install -D -m 0444 ~/ahri-tre-transfer/v0.10.8/postgres.svrltreapcc02.home.arpa.pem /etc/ahri-tre/postgresql/tls/certificate.pem
sudo chown 999:999 /etc/ahri-tre/postgresql/tls/certificate.pem
sudo env OPENSSL_CONF=/dev/null openssl verify -CAfile site/postgresql/public-ca-chain.pem /etc/ahri-tre/postgresql/tls/certificate.pem
sudo env OPENSSL_CONF=/dev/null openssl x509 -in /etc/ahri-tre/postgresql/tls/certificate.pem -noout -checkhost postgres.svrltreapcc02.home.arpa
sudo stat -c '%u:%g:%a %n' /etc/ahri-tre/postgresql/tls/certificate.pem /run/secrets/postgres/tls/private-key/value
The certificate check must succeed. The final output must show 999:999:444
for the certificate and 999:999:400 for the private key.
10. MinisForum: create the PostgreSQL password projections
Create the protected directories:
sudo install -d -o root -g root -m 0700 /run/secrets/postgres/bootstrap-password /run/secrets/postgres/administrator-passfile
sudo install -d -o ahri-tre-runtime -g ahri-tre-runtime -m 0700 /run/secrets/postgres/administrator-password
Start a temporary root shell:
sudo bash
The prompt changes from $ to #. Paste this block at the # prompt:
set -eu
umask 077
postgres_password="$(env OPENSSL_CONF=/dev/null openssl rand -hex 32)"
printf '%s' "$postgres_password" > /run/secrets/postgres/bootstrap-password/value
printf '%s' "$postgres_password" > /run/secrets/postgres/administrator-password/value
printf '%s\n' "postgres.svrltreapcc02.home.arpa:5432:*:ahri_tre_administrator:${postgres_password}" > /run/secrets/postgres/administrator-passfile/value
unset postgres_password
printf '%s' 'site-v3' > /run/secrets/postgres/administrator-password/version
chown root:root /run/secrets/postgres/bootstrap-password/value /run/secrets/postgres/administrator-passfile/value
chmod 0400 /run/secrets/postgres/bootstrap-password/value
chmod 0600 /run/secrets/postgres/administrator-passfile/value
chown ahri-tre-runtime:ahri-tre-runtime /run/secrets/postgres/administrator-password/value /run/secrets/postgres/administrator-password/version
chmod 0400 /run/secrets/postgres/administrator-password/value /run/secrets/postgres/administrator-password/version
exit
The prompt returns to $. Verify equality without displaying the password:
sudo cmp --silent /run/secrets/postgres/bootstrap-password/value /run/secrets/postgres/administrator-password/value && echo 'PostgreSQL password projections match'
The confirmation must be printed.
11. Browser and MinisForum: project the ORCID client secret
In a browser, sign in to
ORCID Sandbox Developer Tools,
open application APP-267KB7OA1UIVOI14, and copy its client secret. Confirm
that its redirect URI is exactly:
https://runtime.svrltreapcc02.home.arpa/v1/runtime-login/callback
Back at the MinisForum SSH prompt, create the protected directory:
sudo install -d -o root -g ahri-tre-oidc -m 0750 /run/secrets/oidc/client-secret
Start a temporary root shell:
sudo bash
At the # prompt, run:
IFS= read -r -s -p 'Paste the ORCID Sandbox client secret, then press Enter: ' orcid_client_secret
Paste the secret and press Enter. No characters are displayed. Then run:
printf '\n'
test -n "$orcid_client_secret"
umask 027
printf '%s' "$orcid_client_secret" > /run/secrets/oidc/client-secret/value
unset orcid_client_secret
printf '%s' 'site-v3' > /run/secrets/oidc/client-secret/version
chown root:ahri-tre-oidc /run/secrets/oidc/client-secret/value /run/secrets/oidc/client-secret/version
chmod 0440 /run/secrets/oidc/client-secret/value /run/secrets/oidc/client-secret/version
exit
Verify only ownership and modes:
sudo stat -c '%U:%G %a %n' /run/secrets/oidc/client-secret/value /run/secrets/oidc/client-secret/version
Both lines must start with root:ahri-tre-oidc 440.
12. WSL2 and MinisForum: project the Runtime private key
In WSL2, copy the retained matching Runtime key to a temporary protected file on the MinisForum:
sudo install -o kobus -g kobus -m 0400 /home/kobus/ahri-tre-pki/private/runtime-private-key.pem /tmp/runtime-private-key.transfer
scp /tmp/runtime-private-key.transfer sysadmin@192.168.31.75:runtime-private-key.transfer
rm -- /tmp/runtime-private-key.transfer
On the MinisForum, project it and remove the transfer copy:
sudo install -d -o ahri-tre-runtime -g ahri-tre-runtime -m 0700 /run/secrets/runtime/private-key
sudo install -o ahri-tre-runtime -g ahri-tre-runtime -m 0400 /home/sysadmin/runtime-private-key.transfer /run/secrets/runtime/private-key/value
printf '%s' 'site-v3' | sudo tee /run/secrets/runtime/private-key/version >/dev/null
sudo chown ahri-tre-runtime:ahri-tre-runtime /run/secrets/runtime/private-key/version
sudo chmod 0400 /run/secrets/runtime/private-key/version
rm -- /home/sysadmin/runtime-private-key.transfer
sudo -u ahri-tre-runtime env OPENSSL_CONF=/dev/null openssl pkey -in /run/secrets/runtime/private-key/value -check -noout
The final command must report a valid key.
13. MinisForum and WSL2: create and back up the root identity
The root identity decrypts this Deployment’s Managed-secret store. It is not an ORCID identity or TLS key. Create it only once:
sudo install -d -o root -g root -m 0700 /root/ahri-tre-recovery
sudo test ! -e /root/ahri-tre-recovery/minisforum-root-identity.txt || { echo 'STOP: root identity already exists'; exit 1; }
sudo bash -c 'set -eu; umask 077; age-keygen | sed -n "/^AGE-SECRET-KEY-1/p" > /root/ahri-tre-recovery/minisforum-root-identity.txt; test -s /root/ahri-tre-recovery/minisforum-root-identity.txt'
Project it for the Runtime:
sudo install -d -o ahri-tre-runtime -g ahri-tre-runtime -m 0700 /run/secrets/ahri-tre/root-identity
sudo install -o ahri-tre-runtime -g ahri-tre-runtime -m 0400 /root/ahri-tre-recovery/minisforum-root-identity.txt /run/secrets/ahri-tre/root-identity/value
printf '%s' 'site-v3' | sudo tee /run/secrets/ahri-tre/root-identity/version >/dev/null
sudo chown ahri-tre-runtime:ahri-tre-runtime /run/secrets/ahri-tre/root-identity/version
sudo chmod 0400 /run/secrets/ahri-tre/root-identity/version
Create a temporary transfer copy:
sudo install -o sysadmin -g sysadmin -m 0400 /root/ahri-tre-recovery/minisforum-root-identity.txt /home/sysadmin/minisforum-root-identity.transfer
In WSL2, retrieve the separate recovery copy:
install -d -m 0700 /home/kobus/ahri-tre-recovery
scp sysadmin@192.168.31.75:/home/sysadmin/minisforum-root-identity.transfer /home/kobus/ahri-tre-recovery/minisforum-root-identity.txt
chmod 0400 /home/kobus/ahri-tre-recovery/minisforum-root-identity.txt
grep -q '^AGE-SECRET-KEY-1' /home/kobus/ahri-tre-recovery/minisforum-root-identity.txt && echo 'Separate root-identity backup is valid'
Back on the MinisForum, remove only the temporary transfer file:
rm -- /home/sysadmin/minisforum-root-identity.transfer
Keep the WSL2 recovery copy separate from Datastore backups.
14. MinisForum: verify every Secret projection
This check displays only paths, numeric identities, and modes:
sudo stat -c '%U(%u):%G(%g) %a %n' /run/secrets /run/secrets/ahri-tre /run/secrets/oidc /run/secrets/postgres /run/secrets/postgres/tls /run/secrets/runtime /run/secrets/postgres/bootstrap-password/value /run/secrets/postgres/administrator-password/value /run/secrets/postgres/administrator-password/version /run/secrets/postgres/administrator-passfile/value /run/secrets/postgres/tls/private-key/value /run/secrets/oidc/client-secret/value /run/secrets/oidc/client-secret/version /run/secrets/runtime/private-key/value /run/secrets/runtime/private-key/version /run/secrets/ahri-tre/root-identity/value /run/secrets/ahri-tre/root-identity/version
Compare the output with site/injected-secrets.json. Required results are:
- bootstrap password:
root:root 400; - administrator password and version:
ahri-tre-runtime:ahri-tre-runtime 400; - administrator passfile:
root:root 600; - PostgreSQL key: numeric
999:999 400; - ORCID client secret and version:
root:ahri-tre-oidc 440; - Runtime key and version:
ahri-tre-runtime:ahri-tre-runtime 400; and - root identity and version:
ahri-tre-runtime:ahri-tre-runtime 400.
The Ubuntu host may display UID/GID 999 with unrelated names. The numeric
values are authoritative. Never use cat, less, head, or an editor on a
Secret value file.
15. MinisForum: install the boot-time Secret projector
This explicit installation copies the current, verified projections into the
root-only persistent authority at
/var/lib/ahri-tre/injected-secret-authority. It then installs and starts the
projector service. It does not print Secret contents.
sudo site/install-secret-projector.sh --confirm-host svrltreapcc02 --confirm-address 192.168.31.75
Expected:
installed and verified the boot-time Injected-secret projector
Verify both persistent sources and ephemeral projections:
sudo /usr/libexec/ahri-tre/secret-projector.sh verify
Expected: verified persistent and projected Injected secrets.
sudo systemctl is-active ahri-tre-secret-projector.service
Expected: active. Do not continue if capture or verification fails. Never
open files beneath the persistent authority with cat, less, or an editor.
The authority is Secret material, not a normal Datastore backup: exclude it
from broad file backups and protect the MinisForum system disk and root account
to the same standard as the original private keys and passwords.
16. MinisForum: install managed PostgreSQL
Review, but do not edit, the generated policy:
less site/postgresql/deployment-contract.json
less site/postgresql/pg_hba.conf
less site/postgresql/pg_ident.conf
Press q after each file. Then install PostgreSQL:
sudo site/postgresql/install.sh --confirm-host svrltreapcc02 --confirm-address 192.168.31.75
Wait for health:
sudo docker inspect --format '{{.Config.Image}} {{.State.Health.Status}}' ahri-tre-postgresql
Expected:
ahri-tre/postgresql-orcid-validator:0.10.8 healthy
Confirm PostgreSQL is loopback-only:
sudo ss -ltnp '( sport = :5432 )'
The local address must be 127.0.0.1:5432, never 0.0.0.0:5432 or
192.168.31.75:5432.
17. MinisForum: provision the Runtime and create the Datastore
Run the release-bound provisioner once:
sudo site/provision.sh --confirm-host svrltreapcc02 --confirm-address 192.168.31.75
The command installs Application configuration, initializes the Managed-secret
store, starts the Runtime, and creates ahri-tre-test. It may print only the
commands that perform visible work.
Verify everything explicitly:
sudo systemctl is-active ahri-tre-runtime.service
Expected: active.
sudo site/verify-readiness.sh
Expected: MinisForum v3 site is ready.
D=ahri-tre-test; R=/usr/libexec/ahri-tre/ahri-tre-runtime; sudo -u ahri-tre-runtime env LD_LIBRARY_PATH=/usr/lib/ahri-tre "$R" datastore reconcile "$D"
Expected: JSON containing "status":"ready". Record its public
datastore_id; do not alter the binding.
18. MinisForum: prove reboot persistence
Reboot the MinisForum:
sudo reboot
The SSH connection closes. Wait about one minute, then reconnect from WSL2:
ssh sysadmin@192.168.31.75
On the MinisForum, verify the ordered services:
sudo systemctl is-active ahri-tre-secret-projector.service ahri-tre-postgresql.service ahri-tre-runtime.service
Expected: three lines, each saying active.
sudo /usr/libexec/ahri-tre/secret-projector.sh verify
cd ~/ahri-tre-transfer/v0.10.8/ahri-tre-test-datastore-deployment-kit-0.3.14
sudo site/verify-readiness.sh
Expected: projection verification succeeds and readiness prints MinisForum v3 site is ready. If any service or check fails, keep the persistent authority
and all rollback material, and diagnose before continuing.
19. MinisForum: make the first Datastore backup
Create and verify a bounded backup:
sudo install -d -o root -g root -m 0700 /var/backups/ahri-tre/manual
sudo site/backup.sh /var/backups/ahri-tre/manual/initial-v0.10.8.dump
sudo find /var/backups/ahri-tre -maxdepth 2 -type f -printf '%TY-%Tm-%Td %TH:%TM %p\n' | sort
Keep the Deployment root identity backup separate from these data backups. Both are required for recovery.
20. Browser/client and MinisForum: qualify ORCID admission
On the MinisForum, admit one real ORCID Sandbox identity using its canonical public iD:
sudo site/admit-user.sh REPLACE_WITH_ADMITTED_ORCID_ID
Replace the final value with the real canonical hyphenated iD, in the form
0000-0000-0000-0000. Do not add the internal orcid_ role prefix.
From a configured WSL2 or MacBook client:
- sign in with that Sandbox identity and open the
ahri-tre-testDatastore Session; it must succeed; - sign out and use a second real, valid Sandbox identity that was not admitted; Session opening must be rejected; and
- retain only the outcome, never a token.
The deterministic invalid-token evidence is already published in
site/validator/qualification-result.json. Do not mint synthetic ORCID tokens
on the MinisForum.
Only these public files may proceed to the client installation workflows:
site/client.toml;site/public-ca-chain.pem; andsite/name-resolution.md.
Do not publish Application configuration, PostgreSQL policy, Secret projections, private keys, credentials, or validator administration material.
Installing a future release
Do not replace version numbers mechanically. A future installation must use a site kit generated for the intended hostname, address, certificates, ORCID registration, storage paths, and release artifacts. Download its archive and checksum together, follow that kit’s release-specific requirements, and never mix files between kit versions.