coulomb-social/docs/resource-evidence/workload-operations-labor-2026-08.md
tegwick c521adc2f9 Publish CSOC-WP-0005 resource demand and cost evidence
Add low/base/high demand forecasts, service objectives with timestamped
observations, and workload operations labor for resource:tenant:coulomb:coulomb-social.
2026-08-12 11:07:03 +02:00

4.1 KiB

Workload operations labor — coulomb-social (2026-08)

Field Value
Resource resource:tenant:coulomb:coulomb-social
Workplan CSOC-WP-0005-T03
Created 2026-08-12T09:03:47Z
Labor rate (planning) €60 / hour (resource-control convention; not payroll)

Boundary — count only app workload labor here

In scope (coulomb-social) Out of scope (do not double-count)
App image build/publish for this service k3s/node host ops (railiance-infra / cluster)
Helm values / release for coulomb-social Shared apps-pg admin & backups (railiance-platform)
Django migrations for this app Ingress controller / cert-manager fleet work
Seed/bind spaces, Forgejo webhook config for app Forgejo platform upgrades (railiance-forge)
App incident triage (500s, bad deploy, data bugs) KeyCape / Authelia / LLDAP platform incidents
App restore drill participation (app checklist) Cluster restore of node/volumes
Content/model product ops (spaces ADR, smoke) Bubble.io hosting (external product until cutover)

Setup labor (one-time / infrequent)

Estimates for standing up or re-standing the Coulomb production instance. Recorded for total-cost models; not a timesheet.

Activity Hours Cadence Notes
Scaffold app + identity shell (historical CSOC-WP-0002) 40 one-time done sunk; for amortization models only
App shell + spaces + Forgejo path (CSOC-WP-0004) 24 one-time done sunk
KeyCape client registration / redirect updates 1 per host change script: scripts/register-keycape-client.sh
Env secret create/rotate (names via railiance-apps tooling) 0.5 per rotate operator; no secret values in repo
First deploy + ingress + DNS for app.coulomb.social 2 one-time done with railiance-apps
Demo space seed + smoke 0.5 per env seed_demo_space + browser checklist
Public registration enablement when NK ready 2 once residual CSOC-IN-0001
Bubble migration rehearsal (future CSOC-WP-0001) 16 per rehearsal not yet executed

Setup already sunk (approx): ~66.5 h for current parallel-host MVP
Near-term setup residual: ~2.5 h (seed/smoke + registration enable)
Migration rehearsal (planned): ~16 h when inventory/mapping ready

Recurring labor (monthly, steady state)

Aligned with demand scenarios in demand-forecast-2026-08.json.

Activity low h base h high h Notes
Release: build image, bump tag, deploy, smoke 1.0 1.5 2.5 commit-SHA images
Migration apply + verify 0.25 0.5 1.0 only when schema changes
Space content ops (seed/bind/webhook, content incidents) 0.25 0.75 2.0 Forgejo is SoR; app refresh path
Identity smoke / session diagnostics 0.25 0.5 1.0 Case A; Case B when live
Incident response (app-owned) 0.25 0.5 1.5 excludes pure platform outages
Recovery exercise (app checklist against restored DB) 0 0.25 0.5 quarterly average as monthly
Demand/evidence refresh 0 0 0.5 forecast vs actual notes
Total recurring 2.0 4.0 8.0 matches T01 operator_hours

Monthly labor € proxy (internal only)

Scenario Hours € @ 60
low 2 120
base 4 240
high 8 480

What not to bill twice

  • Cluster upgrade weekend → railiance-cluster / infra labor, even if app is redeployed as a consumer.
  • apps-pg vacuum/backup failure → platform labor; app only spends the hours verifying app health after restore.
  • Forgejo disk full → forge labor; app may open an incident for missing content but content storage is not app labor ownership.
  • Authelia MFA outage → NetKingdom; app documents customer impact only.
  • Operator runbook: docs/deploy.md
  • Identity smoke: docs/identity/smoke.md
  • Spaces content: docs/spaces-content.md
  • Residuals: docs/intakes/csoc-residuals.md
  • Demand: docs/resource-evidence/demand-forecast-2026-08.md