Skip to content

Heritage — infrastructure-management and incubator

Non-secret decisions and inventory harvested from pre-Conductor infrastructure workspaces, now under hector-sanchez-eu/software-estate-incubator (and older workspace / Pipeline Management).
Not live authority for new deploys — Conductor Software + Operate docs win on conflict.


Where it lived

Path Origin
software-estate-incubator/infrastructure/infrastructure-management Former D:\workspaces\professional\software\shared\infrastructure-management
.../vps-management-ui Admin UI for ai-sandbox OpenClaw
.../workspace-control-plane Pre-Conductor registry/standards for shared workspaces
.../self-hosted-git-gitea Gitea-on-DigitalOcean GitHub backup plan
.../platform-control-smoke Smoke tests for Platform Control
hector-sanchez-eu/workspace / 01 - Pipeline Management Promote/deploy PowerShell tool chest

Evidence registry keys: incubator:infrastructure/* in docs/evidence/estate/source-registry.yml.


Decisions worth keeping (descriptive)

Recorded as observations from STATUS/DECISIONS notes — promote to Software/Operate locks only via normal Conductor change process if still desired:

Topic Heritage note Conductor today
Default self-host Hetzner VPS + Coolify explored host.konstant default; Coolify not required
Managed DB defaults Neon / Turso / Supabase mentioned Inventory gap — not locked here
Secrets SoR Bitwarden Secrets Manager Locked — secret-gate + Bitwarden
Machine accounts ci-nonprod, ci-prod, ops-bootstrap Keep naming via Bitwarden items; unlock with secret-gate
DNS Move to Hetzner Cloud API; old DNS console deprecated hetzner-dns-cli
Edge Cloudflare tunnel for konstant eval cloudflare-tunnel-cli
Control plane Platform Control as mutation authority Live tool — tooling
GCP projects Multiple GCP project inventories under gcp/ host.gcp still stub; inventories are recovery evidence

VPS / DO notes (recovery)

  • DigitalOcean VPS configs and keys existed under nested vps/digitalocean/keys quarantined; never re-import secrets into Conductor.
  • Hetzner VPS management briefly claimed sdhector/hetzner-vps-management as mirror; org copies under hector-sanchez-eu/ are the ones in the harvest list.

What to do with incubator infra

  1. Keep incubator repo as consolidation warehouse.
  2. Prefer Conductor Operate pages for day-to-day authority.
  3. hetzner-vps* and vps-deployment-toolkit GitHub-archived 2026-07-30 — not the whole incubator.
  4. Do not regenerate docs/generated/corpus/ from this heritage.