{
  "schema": "unitiqx.connector-resilience.v1",
  "updated_utc": "2026-10-11T07:20:29.510381+00:00",
  "scope": "No external provider credentials, user identities or private host secrets disclosed",
  "connections": [
    {
      "name": "Desktop Commander",
      "location": "Hostinger VPS direct file/process access",
      "verification": "Verified",
      "permission_type": "Read / write",
      "pros": "Detailed terminal, files, process, test receipts",
      "cons": "Connector availability and central VPS dependency",
      "recommendation": "Primary owner execution; not failover"
    },
    {
      "name": "OpenSSH with public keys",
      "location": "Hostinger VPS via existing port 22",
      "verification": "Host configured; external key login not tested",
      "permission_type": "Read / write if authorized",
      "pros": "Independent protocol, widely supported tooling, recovery if app connector fails",
      "cons": "Key custody, bastion and audit needed; same VPS failure domain",
      "recommendation": "Second management protocol when properly tested"
    },
    {
      "name": "GitHub connector",
      "location": "External hosted repositories",
      "verification": "Connected account verified",
      "permission_type": "Repo read / write within scopes",
      "pros": "Version history, branches, reviews, CI, off-host copy",
      "cons": "No direct Hostinger root shell; repository backup not automatically configured",
      "recommendation": "Preferred external code and policy mirror"
    },
    {
      "name": "Vercel connector",
      "location": "Separate edge/static hosting",
      "verification": "Connected project access verified",
      "permission_type": "Own project deploy / preview",
      "pros": "Independent site delivery, previews, rollback capabilities",
      "cons": "Does not mirror Hostinger databases or VPS state automatically",
      "recommendation": "Secondary publisher for static front-end"
    },
    {
      "name": "Railway connector",
      "location": "Separate application runtime",
      "verification": "Connected account verified",
      "permission_type": "Own projects and services",
      "pros": "Build/deploy workloads outside VPS, logs and metrics",
      "cons": "Cost/quota, vendor constraints, state migration required",
      "recommendation": "Potential secondary compute platform"
    },
    {
      "name": "DigitalOcean connector",
      "location": "Alternative cloud VMs",
      "verification": "Connected account verified",
      "permission_type": "Own cloud resources with scope",
      "pros": "Independent compute/VM snapshots and recovery host options",
      "cons": "Not a Hostinger management connector; can incur charges; no replica provisioned",
      "recommendation": "Future warm/cold standby location"
    },
    {
      "name": "Render connector",
      "location": "Separate hosting",
      "verification": "Connection available; workspace unresolved",
      "permission_type": "Own services after selecting scope",
      "pros": "Another independent runtime/publisher option",
      "cons": "No mapped service inventory yet; provisioning may cost",
      "recommendation": "Unverified standby option"
    },
    {
      "name": "Dropbox connector",
      "location": "External file storage",
      "verification": "Connected account verified",
      "permission_type": "Files within storage scopes",
      "pros": "Offsite immutable-style copies if configured, file revisions",
      "cons": "Not a runnable replica; no VPS backup uploaded here",
      "recommendation": "Candidate independent artifact store"
    },
    {
      "name": "Google Drive connector",
      "location": "External document storage",
      "verification": "Connected account verified",
      "permission_type": "Documents/files within scopes",
      "pros": "Second storage/account provider for runbooks and receipts",
      "cons": "Not instant system recovery; copy not configured",
      "recommendation": "Recovery instructions and receipts mirror"
    },
    {
      "name": "Datadog connector",
      "location": "Independent observability SaaS",
      "verification": "Connected, zero hosts returned",
      "permission_type": "Read telemetry when instrumented",
      "pros": "Monitoring can operate outside the VPS failure domain",
      "cons": "No observed VPS agent/host yet",
      "recommendation": "Independent outage detection after onboarding"
    },
    {
      "name": "Self-hosted Gitea",
      "location": "Same VPS Docker",
      "verification": "Container running",
      "permission_type": "Local git source versions",
      "pros": "Fast local versioning and repo UI",
      "cons": "Same VPS disk/failure domain; not offsite backup",
      "recommendation": "Daily development source"
    },
    {
      "name": "Self-hosted n8n",
      "location": "Same VPS Docker",
      "verification": "Container running",
      "permission_type": "Configured workflow actions",
      "pros": "Can orchestrate tasks and retries",
      "cons": "Same VPS; tool permissions and execution must be scoped",
      "recommendation": "Alternate local workflow operator, not break-glass root"
    },
    {
      "name": "Portainer",
      "location": "Same VPS Docker",
      "verification": "Container running",
      "permission_type": "Docker administration when authenticated",
      "pros": "Direct container lifecycle recovery",
      "cons": "Powerful and high risk if anonymously exposed; same VPS",
      "recommendation": "Authenticated container management"
    },
    {
      "name": "Uptime Kuma / Netdata",
      "location": "Same VPS Docker",
      "verification": "Containers running",
      "permission_type": "Read local telemetry",
      "pros": "Operational visibility and local alerts",
      "cons": "Same VPS cannot reliably report its own total outage",
      "recommendation": "Local detection, pair with external monitor"
    },
    {
      "name": "Caddy + HTTPS addresses",
      "location": "Same VPS, two public hostnames",
      "verification": "Both HTTPS checks passed",
      "permission_type": "Public content read-only",
      "pros": "Different hostname entrances, TLS and routing",
      "cons": "Not two separate servers or regional failover",
      "recommendation": "Primary public ingress"
    },
    {
      "name": "Factory OS and upgrade gate",
      "location": "Same VPS staged worker",
      "verification": "Gate acceptance/rejection tested",
      "permission_type": "Private staged candidates only",
      "pros": "Backups, quality controls, deterministic receipts",
      "cons": "Static criteria not enough for total product superiority",
      "recommendation": "Block regressions; require browser/security approval"
    }
  ],
  "failure_scenarios": [
    {
      "scenario": "Host completely lost",
      "current": "Not recovered automatically",
      "priority_action": "P0: offline encrypted backups + independent compute restore rehearsal"
    },
    {
      "scenario": "Remote Desktop connector unavailable",
      "current": "SSH protocol exists; login outside VPS unproven",
      "priority_action": "P0: test separate keyed break-glass access and approvals"
    },
    {
      "scenario": "Bad source change",
      "current": "A staged quality gate now rejects one deliberate regression",
      "priority_action": "P0: enforce real browser+security tests and immutable rollback before promotion"
    },
    {
      "scenario": "External model provider unavailable",
      "current": "Local Ollama alternatives installed but CPU limited",
      "priority_action": "P1: functional fallback router with measured latency/quality benchmarks"
    },
    {
      "scenario": "Public request surge",
      "current": "Public model worker has rate limits/concurrency caps",
      "priority_action": "P1: fair queue, abuse alerts, independent CDN/WAF if available"
    },
    {
      "scenario": "Local archive corrupt",
      "current": "SHA256 + isolated sample restore passed",
      "priority_action": "P0: multiple offsite copies + periodic full recovery proof"
    },
    {
      "scenario": "VPS database corrupted",
      "current": "Two SQLite backups/consistency checks available",
      "priority_action": "P0: signed periodic restore drills, tested point-in-time recovery"
    },
    {
      "scenario": "Credential compromise",
      "current": "Private public gateway guard checks passed",
      "priority_action": "P0: identity broker, MFA, credential rotation and audit; deeper penetration testing"
    },
    {
      "scenario": "Chat history purge",
      "current": "VPS continuity handoff exists; full archive not imported",
      "priority_action": "P1: long-term project decisions indexed on VPS plus offsite replication"
    },
    {
      "scenario": "DNS or public hostname failure",
      "current": "Two hostnames share one server",
      "priority_action": "P1: health-checked failover to independently hosted static recovery page"
    }
  ],
  "policies": [
    "No connector becomes trusted solely because it is installed",
    "Minimum two distinct access mechanisms for recurring critical workflows",
    "Independent failure domains required for genuine redundancy",
    "No production release without non-regression, improvement evidence and rollback",
    "New features stay staged until browser, security and owner gates pass",
    "Chaos tests run in disposable services only unless a separate production test is explicitly authorized"
  ],
  "live_qa": "/suites/qa.json",
  "quality_gate": "/planes/quality.json",
  "next_unfinished": [
    "Configure at least two independently hosted encrypted offsite backups",
    "Verify off-VPS authorized SSH recovery and key storage",
    "Create real external monitoring of VPS",
    "Create external static mirror and rehearse origin outage",
    "Operationally connect GitHub source mirror, CI, and protected approval flow"
  ]
}
