SanMarcSoft SOP Runbook

Internal Standard Operating Procedures for SanMarcSoft infrastructure, services, and operations

SanMarcSoft SOP Runbook

Internal operational runbook for all SanMarcSoft infrastructure, services, deployments, and compliance procedures.

Access: This site is restricted to authorized SanMarcSoft personnel via Cloudflare Access (GitHub OAuth).


Infrastructure

Services

Operations

Compliance

Troubleshooting

Setup


Governing Principles

All SanMarcSoft operations are governed by the Sovereign Architecture SOP (effective 2026-03-13):

  1. The Nix Law – Zero Dockerfiles for production builds. All images built with nix build + pkgs.dockerTools.buildLayeredImage.
  2. The Cross-Compile Law – Development on Apple Silicon (aarch64-darwin), all images target x86_64-linux.
  3. The Sovereign Registry Law – Production images go to Scaleway Container Registry (rg.fr-par.scw.cloud/sanmarcsoft/), EU data sovereign.
  4. The IaC Law – All infrastructure via Pulumi TypeScript. State backend on Scaleway Object Storage (fr-par).

What stays on Cloudflare (not migrated)

  • DNS + CDN (all domains)
  • Zero Trust Access
  • Workers (badges, URL shortener, waitlist)
  • KV + D1 databases