coulomb-social/docs/resource-evidence/workload-operations-labor-2026-08.md
tegwick c521adc2f9 Publish CSOC-WP-0005 resource demand and cost evidence
Add low/base/high demand forecasts, service objectives with timestamped
observations, and workload operations labor for resource:tenant:coulomb:coulomb-social.
2026-08-12 11:07:03 +02:00

81 lines
4.1 KiB
Markdown

# Workload operations labor — coulomb-social (2026-08)
| Field | Value |
|-------|--------|
| Resource | `resource:tenant:coulomb:coulomb-social` |
| Workplan | CSOC-WP-0005-T03 |
| Created | 2026-08-12T09:03:47Z |
| Labor rate (planning) | €60 / hour (resource-control convention; not payroll) |
## Boundary — count only app workload labor here
| In scope (coulomb-social) | Out of scope (do not double-count) |
|---------------------------|-------------------------------------|
| App image build/publish for this service | k3s/node host ops (`railiance-infra` / cluster) |
| Helm values / release for coulomb-social | Shared apps-pg admin & backups (`railiance-platform`) |
| Django migrations for this app | Ingress controller / cert-manager fleet work |
| Seed/bind spaces, Forgejo webhook config for app | Forgejo platform upgrades (`railiance-forge`) |
| App incident triage (500s, bad deploy, data bugs) | KeyCape / Authelia / LLDAP platform incidents |
| App restore drill participation (app checklist) | Cluster restore of node/volumes |
| Content/model product ops (spaces ADR, smoke) | Bubble.io hosting (external product until cutover) |
## Setup labor (one-time / infrequent)
Estimates for standing up or re-standing the **Coulomb** production instance.
Recorded for total-cost models; not a timesheet.
| Activity | Hours | Cadence | Notes |
|----------|------:|---------|--------|
| Scaffold app + identity shell (historical CSOC-WP-0002) | 40 | one-time done | sunk; for amortization models only |
| App shell + spaces + Forgejo path (CSOC-WP-0004) | 24 | one-time done | sunk |
| KeyCape client registration / redirect updates | 1 | per host change | script: `scripts/register-keycape-client.sh` |
| Env secret create/rotate (names via railiance-apps tooling) | 0.5 | per rotate | operator; no secret values in repo |
| First deploy + ingress + DNS for app.coulomb.social | 2 | one-time done | with railiance-apps |
| Demo space seed + smoke | 0.5 | per env | `seed_demo_space` + browser checklist |
| Public registration enablement when NK ready | 2 | once | residual CSOC-IN-0001 |
| Bubble migration rehearsal (future CSOC-WP-0001) | 16 | per rehearsal | not yet executed |
**Setup already sunk (approx):** ~66.5 h for current parallel-host MVP
**Near-term setup residual:** ~2.5 h (seed/smoke + registration enable)
**Migration rehearsal (planned):** ~16 h when inventory/mapping ready
## Recurring labor (monthly, steady state)
Aligned with demand scenarios in `demand-forecast-2026-08.json`.
| Activity | low h | base h | high h | Notes |
|----------|------:|-------:|-------:|--------|
| Release: build image, bump tag, deploy, smoke | 1.0 | 1.5 | 2.5 | commit-SHA images |
| Migration apply + verify | 0.25 | 0.5 | 1.0 | only when schema changes |
| Space content ops (seed/bind/webhook, content incidents) | 0.25 | 0.75 | 2.0 | Forgejo is SoR; app refresh path |
| Identity smoke / session diagnostics | 0.25 | 0.5 | 1.0 | Case A; Case B when live |
| Incident response (app-owned) | 0.25 | 0.5 | 1.5 | excludes pure platform outages |
| Recovery exercise (app checklist against restored DB) | 0 | 0.25 | 0.5 | quarterly average as monthly |
| Demand/evidence refresh | 0 | 0 | 0.5 | forecast vs actual notes |
| **Total recurring** | **2.0** | **4.0** | **8.0** | matches T01 operator_hours |
### Monthly labor € proxy (internal only)
| Scenario | Hours | € @ 60 |
|----------|------:|-------:|
| low | 2 | 120 |
| base | 4 | 240 |
| high | 8 | 480 |
## What not to bill twice
- **Cluster upgrade weekend** → railiance-cluster / infra labor, even if app is
redeployed as a consumer.
- **apps-pg vacuum/backup failure** → platform labor; app only spends the hours
verifying app health after restore.
- **Forgejo disk full** → forge labor; app may open an incident for missing
content but content storage is not app labor ownership.
- **Authelia MFA outage** → NetKingdom; app documents customer impact only.
## Evidence links
- Operator runbook: `docs/deploy.md`
- Identity smoke: `docs/identity/smoke.md`
- Spaces content: `docs/spaces-content.md`
- Residuals: `docs/intakes/csoc-residuals.md`
- Demand: `docs/resource-evidence/demand-forecast-2026-08.md`