| Physical node |
The dedicated mapping between the device and order, baseline node operation, and device status in the console. |
Using the device for the order’s intended purpose, managing workloads, and migrating data during the term. |
Device identifier, node, and term start and end times. |
| Console account |
Providing account access, order management, instance status, and the ticketing entry point. |
Protecting login credentials, identifying anomalous access, and promptly updating or revoking related permissions. |
Recent access, order changes, and ticket history. |
| Remote connection |
Providing connection details and status information for the corresponding device in the console. |
Verifying the address and host fingerprint, protecting remote credentials, and configuring trusted clients. |
Node, address, fingerprint, and connection account. |
| System account |
Providing a usable macOS graphical interface and command-line environment. |
Creating unique accounts, enforcing least privilege, rotating credentials, and removing former team members. |
Account list, public-key list, and administrator privileges. |
| Application and CI/CD |
Maintaining service operation for the physical node and console. |
Managing Xcode, dependencies, runners, scripts, repository permissions, and release workflows. |
Runner account, working directory, and token scope. |
| Code and secrets |
Not deciding where customers store code and secrets or how they authorize and rotate them. |
Using a controlled secret-management system and avoiding plaintext in scripts, repositories, and logs. |
Secret purpose, scope, owner, and revocation method. |
| Logs and support |
Investigating physical-node and console issues based on ticket information. |
Providing accurate times, reproduction steps, and sanitized logs without sending secrets. |
Error codes, versions, timeline, and actions taken. |
| Backup and migration |
Displaying order and device term information in the console. |
Defining a backup strategy, verifying recoverability, and migrating data before the term ends. |
Backup integrity, recovery tests, and token revocation. |