[bss-openc5isr] 04 Installation & Deployment
Prerequisites, installation, environment configuration, deployment and upgrade procedures. Edition: BSS — OpenC5ISR (openc5isr.bss.dev).
Start Here
Start Here
| Field | Value |
|---|---|
| Distribution | BSS — OpenC5ISR |
| Product | OpenC5ISR |
| Release | 0.15.1 |
| Deployment | openc5isr.bss.dev |
| Source | /srv/bss/releases/OpenC5ISR-v0.15.0-20app |
| Evidence | Documentation structure and release scan |
| Source fingerprint | 93926e8c834f1ed79c9017a4096f70c76d73ce4f870f104fbd0cf54b2bed50ee |
| Status | Generated baseline — human review required |
Verification boundary: This page combines platform design guidance with static evidence from the release. It does not prove that every detected interface is enabled, reachable, secure, or operational in the deployed environment.
Purpose
This book turns the scanned release into a deployment baseline. Commands and configuration must still be verified against the active instance before being treated as authoritative operations guidance.
Contents
| Section | What it contains |
|---|---|
| Planning & Prerequisites | Runtime, platform and dependency requirements inferred from the release. |
| Deployment Configuration | Environment variables, systemd, containers, Nginx and ports. |
| Installation & Lifecycle | Installation, verification, upgrade and rollback procedures. |
How to maintain this book
Generated sections are replaced from release evidence on each run. Put reviewed corrections, deployment-specific facts, links and decisions in the Maintainer Notes area below the generated block. Mark pages as reviewed only after testing them against the named distribution and release.
Maintainer Notes
Add human-reviewed deployment notes, corrections, decisions, screenshots, and links here. Content outside the generated block is preserved on future runs.
Planning & Prerequisites
Managed documentation for Planning & Prerequisites.
System Requirements
System Requirements
| Field | Value |
|---|---|
| Distribution | BSS — OpenC5ISR |
| Product | OpenC5ISR |
| Release | 0.15.1 |
| Deployment | openc5isr.bss.dev |
| Source | /srv/bss/releases/OpenC5ISR-v0.15.0-20app |
| Evidence | Runtime manifests and file inventory |
| Source fingerprint | 93926e8c834f1ed79c9017a4096f70c76d73ce4f870f104fbd0cf54b2bed50ee |
| Status | Generated baseline — human review required |
Verification boundary: This page combines platform design guidance with static evidence from the release. It does not prove that every detected interface is enabled, reachable, secure, or operational in the deployed environment.
Observed runtime profile
| Property | Observed |
|---|---|
| Languages by source-file count | PHP: 165, JavaScript: 150, Python: 74, C: 63, Shell: 34, C++: 1 |
| Framework indicators | — |
| Containerized | False |
| Node projects | 2 |
| Python requirement sets | 0 |
Manifest evidence
| Manifest | Project | Version | Runtime/base | Dependencies |
|---|---|---|---|---|
package.json |
opensof-integrated-suite | 0.15.1 | node | 0 |
edge/openssa-sensor/package.json |
openssa-mission-spectrum-console | 0.5.0 | node | 0 |
Baseline host requirements
- A supported Linux host with accurate time synchronization and administrative access for service/proxy changes.
- The runtimes and package managers evidenced above, or an OCI container engine when container definitions are authoritative.
- Sufficient CPU, memory, disk and network for enabled modules; sensor/radio/AI workloads require separate capacity sizing.
- DNS and TLS certificates for public hostnames, plus firewall policy for public, management, backend and sensor interfaces.
- A backup destination outside the active release and tested access to required databases/artifact stores.
Maintainer Notes
Add human-reviewed deployment notes, corrections, decisions, screenshots, and links here. Content outside the generated block is preserved on future runs.
Deployment Architecture
Deployment Architecture
| Field | Value |
|---|---|
| Distribution | BSS — OpenC5ISR |
| Product | OpenC5ISR |
| Release | 0.15.1 |
| Deployment | openc5isr.bss.dev |
| Source | /srv/bss/releases/OpenC5ISR-v0.15.0-20app |
| Evidence | Release layout and container evidence |
| Source fingerprint | 93926e8c834f1ed79c9017a4096f70c76d73ce4f870f104fbd0cf54b2bed50ee |
| Status | Generated baseline — human review required |
Verification boundary: This page combines platform design guidance with static evidence from the release. It does not prove that every detected interface is enabled, reachable, secure, or operational in the deployed environment.
Release layout
| Property | Observed |
|---|---|
| Release path | /srv/bss/releases/OpenC5ISR-v0.15.0-20app |
| Version | 0.15.1 |
| Top-level entries | third_party: 870edge: 100public: 68openrf: 36lib: 32drivers: 27tests: 24examples: 20data: 17ontology: 17.opennetworks-backup-20260827T210646Z: 13open-daa: 12modules: 9scenarios: 9integrations: 8open-lvc: 5common: 4open-rf: 4open-ssa: 4templates: 4models: 3open-aar-mr: 3open-bus: 3open-cop: 3open-cybersec: 3open-eyes: 3open-iia: 3open-knowledge: 3open-pnt: 3open-chat: 2open-task: 2open-track: 2rocketchat: 2standards: 2tools: 2API.md: 1CHANGELOG.md: 1DEPLOY-GODADDY.md: 1EXTERNAL-SERVICES.md: 1FIX-v0.15.1.md: 1 |
| Source fingerprint | 93926e8c834f1ed79c9017a4096f70c76d73ce4f870f104fbd0cf54b2bed50ee |
Container/service topology candidates
No Compose service was extracted; use the systemd and Nginx pages for other deployment evidence.
Recommended release pattern
/srv/<owner>/releases/<product>-vX.Y.Z/ immutable extracted release
/srv/<owner>/instances/<edition>/current symlink to active release
/etc/<product>/<edition>/ protected configuration and secrets
/var/lib/<product>/<edition>/ persistent state
/var/log/<product>/<edition>/ logs, when not solely in journald
Keep code/release artifacts immutable, configuration outside the release, persistent data outside the release, and activation as an atomic symlink/service switch. This makes rollback possible without reconstructing the prior state.
Maintainer Notes
Add human-reviewed deployment notes, corrections, decisions, screenshots, and links here. Content outside the generated block is preserved on future runs.
Deployment Configuration
Managed documentation for Deployment Configuration.
Environment Variables
Environment Variables
| Field | Value |
|---|---|
| Distribution | BSS — OpenC5ISR |
| Product | OpenC5ISR |
| Release | 0.15.1 |
| Deployment | openc5isr.bss.dev |
| Source | /srv/bss/releases/OpenC5ISR-v0.15.0-20app |
| Evidence | Static environment-reference scan; values redacted |
| Source fingerprint | 93926e8c834f1ed79c9017a4096f70c76d73ce4f870f104fbd0cf54b2bed50ee |
| Status | Generated baseline — human review required |
Verification boundary: This page combines platform design guidance with static evidence from the release. It does not prove that every detected interface is enabled, reachable, secure, or operational in the deployed environment.
Observed variables
| Variable | Secret-like | Observed default | Mechanism | Evidence |
|---|---|---|---|---|
ADDRESS |
No | — | interpolation | openrf/agent/functions/probe-n310.sh |
AEGIS_SENTINEL_LABEL |
No | COMPILED_DEPLOYMENT.aegisSentinelLabel).trim() || COMPILED_DEPLOYMENT.aegisSentinelLabel |
process.env | server.jstools/integrate_opensof_service_entries.py |
ALT |
No | — | shell | edge/openssa-sensor/install-demo-sensor.sh |
ANTHROPIC_API_KEY |
Yes | — | process.env | server.jslib/openllm/agents.jslib/openllm/providers.js |
API |
No | — | interpolation | open-cybersec/app.jspublic/open-cybersec/app.jspublic/open-llm/app.js |
API_BASE |
No | — | interpolation | open-rf/app.jspublic/open-networks/app.jspublic/open-rf/app.js |
BACKUP_ROOT |
No | — | shell | modules/open-networks/integration/install-module-files.sh |
BASE |
No | http://127.0.0.1:3000 |
shell, interpolation | DEPLOY-GODADDY.mdOPENCYBERSEC-QUICKSTART.mdOPENCYBERSEC.mdUPGRADE-v0.14.0.mdrocketchat/outgoing-webhook-test.shscenarios/run_demo_sequence.sh |
BASE_PATH |
No | — | interpolation, shell | open-rf/app.jspublic/open-rf/app.jsthird_party/ontowiki/application/scripts/travis/install-services.sh |
BLAZEGRAPH |
No | — | shell | third_party/ontowiki/application/scripts/travis/install-services.sh |
BUILD |
No | — | shell | edge/openpnt-linuxptp/SELF-TEST.shedge/openssa-sensor/install/install-native-uhd.shedge/openssa-sensor/native/uhd_spectrum_engine/build-simulation.shedge/openssa-sensor/native/uhd_spectrum_engine/build.sh |
BUILDPATH |
No | — | shell | third_party/ontowiki/application/scripts/vad/prepare.sh |
BUILD_DIR |
No | $ENGINE/build |
interpolation | edge/openssa-sensor/install/install-native-uhd.shedge/openssa-sensor/native/uhd_spectrum_engine/build-simulation.shedge/openssa-sensor/native/uhd_spectrum_engine/build.sh |
BUILD_ROOT |
No | — | shell | edge/openpnt-linuxptp/install-linuxptp.sh |
CATALINA_BASE |
No | — | shell | third_party/ontowiki/application/scripts/travis/install-services.sh |
CATALINA_HOME |
No | — | shell | third_party/ontowiki/application/scripts/travis/install-services.sh |
CFG |
No | — | shell | edge/openssa-sensor/install-demo-sensor.sh |
CONFIG |
No | — | shell | drivers/install_openpnt_agent.shedge/opencybersec/install.shedge/openssa-sensor/install/check-sensor.shedge/openssa-sensor/install/install-sensor.shopenrf/agent/functions/start-5g-ran-b210-50mhz.shopenrf/agent/functions/start-5g-ran-n78-n310.sh |
CORE_DIR |
No | — | shell | openrf/agent/functions/start-5g-core.shopenrf/agent/functions/status-5g-core.sh |
CROSS_COMPILE |
No | — | interpolation | third_party/openil_linuxptp/incdefs.sh |
CURRENT |
No | — | shell | third_party/ontowiki/application/scripts/vad/prepare.sh |
DATA_DIR |
No | path.join(ROOT |
interpolation, process.env | OPENCYBERSEC-QUICKSTART.mdOPENCYBERSEC.mdRELEASE-MANIFEST-v0.14.0.jsonUPGRADE-v0.14.0.mdserver.js |
DRIVER |
No | — | shell | edge/openssa-sensor/install-demo-sensor.shedge/openssa-sensor/install/check-sensor.shedge/openssa-sensor/install/install-ubuntu-deps.sh |
EF_STORE_ADAPTER |
No | — | getenv, shell | third_party/ontowiki/application/classes/OntoWiki/Test/IntegrationTestBootstrap.php |
ENGINE |
No | — | shell | edge/openssa-sensor/install/install-native-uhd.sh |
ENV_FILE |
No | — | shell | edge/opencybersec/install.sh |
EOD_TECH_TARGET |
No | @eodtech |
process.env | server.js |
EUID |
No | $(id -u |
interpolation, shell | drivers/install_openpnt_agent.shedge/opencybersec/install.shedge/opencybersec/uninstall.shedge/openpnt-linuxptp/install-linuxptp.shedge/openpnt-linuxptp/uninstall-linuxptp.shopenrf/agent/install.sh |
E_UNREACHABLE |
No | — | shell | third_party/ontowiki/application/scripts/travis/install-services.sh |
FG_ROOT |
No | — | shell | edge/openlvc/flightgear/opensof-lvc.xml |
FOURSTORE |
No | — | shell | third_party/ontowiki/application/scripts/travis/install-services.sh |
FUSEKI |
No | — | shell | third_party/ontowiki/application/scripts/travis/install-services.sh |
GNB |
No | — | shell | openrf/agent/functions/start-5g-ran-b210-50mhz.shopenrf/agent/functions/start-5g-ran-n78-n310.sh |
HERE |
No | — | shell | edge/openpnt-linuxptp/SELF-TEST.shedge/openpnt-linuxptp/install-linuxptp.shedge/openssa-sensor/native/uhd_spectrum_engine/build-simulation.shedge/openssa-sensor/native/uhd_spectrum_engine/build.shexamples/opencybersec/ingest-examples.shscenarios/run_demo_sequence.sh |
HOME |
No | /tmp |
process.env, shell | lib/openllm/pipeline-engine.jsopenrf/agent/functions/start-5g-core.shopenrf/agent/functions/status-5g-core.shthird_party/ontowiki/.travis.yml |
HOST |
No | 0.0.0.0 |
process.env, interpolation | server.jslib/openrf-controller/server.js |
INSTALL_DIR |
No | — | shell | edge/opencybersec/install.sh |
INSTANCE |
No | — | shell | edge/openpnt-linuxptp/install-linuxptp.sh |
ISQLFILE |
No | — | shell | third_party/ontowiki/application/scripts/vad/prepare.sh |
JOBS |
No | — | shell | edge/openpnt-linuxptp/install-linuxptp.sh |
KBUILD_OUTPUT |
No | — | interpolation, shell | third_party/openil_linuxptp/incdefs.sh |
KNOWLEDGE_NS |
No | — | interpolation | server.js |
LANG |
No | C.UTF-8 |
process.env | lib/openllm/pipeline-engine.js |
LAT |
No | — | shell | edge/openssa-sensor/install-demo-sensor.sh |
LON |
No | — | shell | edge/openssa-sensor/install-demo-sensor.sh |
MISSION_KNOWLEDGE_NS |
No | — | interpolation | server.js |
MOUNT_PATH |
No | COMPILED_DEPLOYMENT.mountPath |
process.env, interpolation | server.js |
NATIVE_SOURCE |
No | — | shell | edge/openssa-sensor/install/install-sensor.shedge/openssa-sensor/install/update-existing-sensor.sh |
NODE_ID |
No | COMPILED_DEPLOYMENT.nodeId |
process.env | server.jsedge/openssa-sensor/lib/openssa.jslib/openssa.js |
NS |
No | — | interpolation | lib/openiia.js |
OPENAAR_BATCH_SIZE |
No | 100 |
os.getenv | drivers/openaar_edge_recorder.py |
OPENAAR_CLOCK_SOURCE |
No | SYSTEM |
os.getenv | drivers/openaar_edge_recorder.py |
OPENAAR_MAX_SPOOL_MB |
No | 2048 |
os.getenv | drivers/openaar_edge_recorder.py |
OPENAAR_NODE_ID |
No | socket.gethostname( |
os.getenv | drivers/openaar_edge_recorder.py |
OPENAAR_RECONNECT_S |
No | 5 |
os.getenv | drivers/openaar_edge_recorder.py |
OPENAAR_RECORDER_ID |
No | f"EDGE-{socket.gethostname( |
os.getenv | drivers/openaar_edge_recorder.py |
OPENAAR_REPORT_INTERVAL_S |
No | 30 |
os.getenv | drivers/openaar_edge_recorder.py |
OPENAAR_RUN_ID |
No | — | os.getenv | drivers/openaar_edge_recorder.py |
OPENAAR_SERVER |
No | http://127.0.0.1:3000 |
os.getenv | drivers/openaar_edge_recorder.py |
OPENAAR_SIGNING_KEY |
Yes | [REDACTED] |
process.env | server.js |
OPENAAR_SITE |
No | FIELD |
os.getenv | drivers/openaar_edge_recorder.py |
OPENAAR_SNAPSHOT_EVERY_EVENTS |
No | 100 |
process.env | server.js |
OPENAAR_SNAPSHOT_INTERVAL_S |
No | 30 |
process.env | server.js |
OPENAAR_SPOOL_DIR |
No | /var/lib/openaar-edge |
os.getenv | drivers/openaar_edge_recorder.py |
OPENAAR_TIME_UNCERTAINTY_NS |
No | 0 |
os.getenv | drivers/openaar_edge_recorder.py |
OPENAAR_TOPICS |
No | — | os.getenv | drivers/openaar_edge_recorder.py |
OPENAAR_TYPES |
No | — | os.getenv | drivers/openaar_edge_recorder.py |
OPENAI_API_KEY |
Yes | — | process.env | server.jslib/openllm/providers.js |
OPENANALYTICS_CONNECTOR_TIMEOUT_MS |
No | 60000 |
process.env | server.js |
OPENBUS_API_TOKEN |
Yes | [REDACTED] |
shell, os.getenv, process.env, getenv, interpolation | OPENKNOWLEDGE-OPENTASK.mdOPENLVC-DEMO.mdOPENLVC-RTI.mddemo_simulator.pyserver.jsdrivers/openaar_edge_recorder.py |
OPENBUS_MAX_HISTORY |
No | 500 |
process.env | server.js |
OPENCHAT_DEFAULT_TARGET |
No | #eod-ops |
process.env | server.js |
OPENCOP_TRACK_URL |
No | https://opencop.c24.airoapp.ai/api/tracks |
process.env | server.js |
OPENCOP_UI_URL |
No | BUILTIN_OPENCOP_UI_URL |
process.env | server.js |
OPENCYBERSEC_AGENT_TOKEN |
Yes | [REDACTED] |
shell, process.env, interpolation | OPENCYBERSEC-QUICKSTART.mdOPENCYBERSEC.mdserver.jsexamples/opencybersec/ingest-examples.sh |
OPENCYBERSEC_OPERATOR_TOKEN |
Yes | [REDACTED] |
shell, process.env, interpolation | OPENCYBERSEC-QUICKSTART.mdOPENCYBERSEC.mdserver.jsexamples/opencybersec/ingest-examples.sh |
OPENCYBERSEC_READ_TOKEN |
Yes | — | process.env | server.js |
OPENFILES_HEALTH_URL |
No | — | process.env | server.jstools/integrate_opensof_service_entries.py |
OPENFILES_PUBLIC_URL |
No | — | process.env | tools/integrate_opensof_service_entries.py |
OPENFILES_SERVICE_URL |
No | — | process.env | server.js |
OPENIIA_MAX_EVIDENCE_BYTES |
No | 12000000 |
process.env | server.js |
OPENISAC_HEALTH_URL |
No | — | process.env | server.jstools/integrate_opensof_service_entries.py |
OPENISAC_PUBLIC_URL |
No | https://bss.dev/live/isac/ |
process.env | tools/integrate_opensof_service_entries.py |
OPENISAC_SERVICE_URL |
No | — | process.env | server.js |
OPENKNOWLEDGE_EDITOR_TOKEN |
Yes | [REDACTED] |
process.env | server.js |
OPENKNOWLEDGE_GRAPH |
No | https://opensof.local/graph/core |
process.env | server.js |
OPENKNOWLEDGE_MODEL_FILE |
No | path.join(DATA |
process.env | server.js |
OPENKNOWLEDGE_ONTOWIKI_URL |
No | — | process.env | server.js |
OPENKNOWLEDGE_SPARQL_ENDPOINT |
No | — | process.env | server.js |
OPENKNOWLEDGE_TIMEOUT_MS |
No | 8000 |
process.env | server.js |
OPENLLM_AGENT_MAX_OUTPUT_BYTES |
No | — | process.env | lib/openllm/agents.js |
OPENLLM_AGENT_TIMEOUT_MS |
No | — | process.env | lib/openllm/agents.js |
OPENLLM_ALLOW_LOCAL_EXECUTION |
No | — | process.env | lib/openllm/pipeline-engine.js |
OPENLLM_ANTHROPIC_API_KEY |
Yes | [REDACTED] |
process.env | server.jslib/openllm/providers.js |
OPENLLM_ANTHROPIC_URL |
No | https://api.anthropic.com/v1').replace(/\/+$/ |
process.env | lib/openllm/providers.js |
OPENLLM_ANTHROPIC_VERSION |
No | 2023-06-01 |
process.env | lib/openllm/providers.js |
OPENLLM_CLAUDE_BIN |
No | claude |
process.env | lib/openllm/agents.js |
OPENLLM_CODEX_BIN |
No | codex |
process.env | lib/openllm/agents.js |
OPENLLM_COMMAND_MODE |
No | off').toLowerCase( |
process.env | lib/openllm/pipeline-engine.js |
OPENLLM_FALLBACK_WRITE_MAX_BYTES |
No | — | process.env | lib/openllm/pipeline-engine.js |
OPENLLM_HEALTH_TIMEOUT_MS |
No | — | process.env | lib/openllm/providers.js |
OPENLLM_MAX_AUDIT |
No | — | process.env | lib/openllm.js |
OPENLLM_MAX_RUNS |
No | — | process.env | lib/openllm/pipeline-engine.js |
OPENLLM_MODEL_CACHE_TTL_MS |
No | — | process.env | lib/openllm/providers.js |
OPENLLM_OPENAI_API_KEY |
Yes | [REDACTED] |
process.env | server.jslib/openllm/providers.js |
OPENLLM_OPENAI_URL |
No | https://api.openai.com/v1').replace(/\/+$/ |
process.env | lib/openllm/providers.js |
OPENLLM_OPENBUS_SCHEMA |
No | opensof.openbus.event/1.0 |
process.env | lib/openllm.js |
OPENLLM_OPENWEBUI_API_KEY |
Yes | [REDACTED] |
process.env | server.jslib/openllm/providers.js |
OPENLLM_OPENWEBUI_CHAT_PATH |
No | /api/chat/completions |
process.env | lib/openllm/providers.js |
OPENLLM_OPENWEBUI_HEALTH_PATH |
No | /health |
process.env | lib/openllm/providers.js |
OPENLLM_OPENWEBUI_MODELS_PATH |
No | /api/models |
process.env | lib/openllm/providers.js |
OPENLLM_OPENWEBUI_URL |
No | process.env.OPENWEBUI_URL || |
process.env | server.jslib/openllm/providers.js |
OPENLLM_OPERATOR_TOKEN |
Yes | [REDACTED] |
process.env | server.jslib/openllm.js |
OPENLLM_PROVIDER_TIMEOUT_MS |
No | — | process.env | lib/openllm/providers.js |
OPENLLM_QWEN_BIN |
No | qwen |
process.env | lib/openllm/agents.js |
OPENLLM_SANDBOX_CPUS |
No | 2 |
process.env | lib/openllm/pipeline-engine.js |
OPENLLM_SANDBOX_IMAGE |
No | openc5isr-openllm-sandbox:0.1.0 |
process.env | lib/openllm/pipeline-engine.js |
OPENLLM_SANDBOX_MEMORY |
No | 2g |
process.env | lib/openllm/pipeline-engine.js |
OPENLLM_SANDBOX_PIDS |
No | 256 |
process.env | lib/openllm/pipeline-engine.js |
OPENLLM_WORKSPACES_DIR |
No | path.join(ROOT |
process.env | server.js |
OPENLVC_FEDERATE |
No | — | interpolation | edge/openlvc/systemd/openlvc-rti-gateway.service |
OPENLVC_FEDERATION |
No | — | interpolation | edge/openlvc/systemd/openlvc-rti-gateway.service |
OPENLVC_HEALTH_URL |
No | — | process.env | server.jstools/integrate_opensof_service_entries.py |
OPENLVC_PUBLIC_URL |
No | — | process.env | tools/integrate_opensof_service_entries.py |
OPENLVC_RTI_SIDECAR_COMMAND |
No | — | interpolation | edge/openlvc/systemd/openlvc-rti-gateway.service |
OPENLVC_SERVICE_URL |
No | — | process.env | server.js |
OPENMAIL_HEALTH_URL |
No | — | process.env | server.jstools/integrate_opensof_service_entries.py |
OPENMAIL_PUBLIC_URL |
No | — | process.env | tools/integrate_opensof_service_entries.py |
OPENMAIL_SERVICE_URL |
No | — | process.env | server.js |
OPENNETWORKS_AGENT_SOCKET |
No | /run/opennetworks/agent.sock |
process.env | lib/open-networks/agent-client.jsmodules/open-networks/integration/native-server-example.js |
OPENNETWORKS_AGENT_TIMEOUT_MS |
No | 120000 |
process.env | lib/open-networks/agent-client.jsmodules/open-networks/integration/native-server-example.js |
OPENNETWORKS_BODY_LIMIT_BYTES |
No | 2 * 1024 * 1024 |
process.env | lib/open-networks/index.js |
OPENNETWORKS_DATA_DIR |
No | path.join(this.rootDir |
process.env | lib/open-networks/service.jsmodules/open-networks/integration/native-server-example.js |
OPENNETWORKS_EXECUTION_MODE |
No | simulate |
process.env | lib/open-networks/service.jsmodules/open-networks/integration/native-server-example.js |
OPENPNT_AGENT_TOKEN |
Yes | [REDACTED] |
os.getenv, process.env | drivers/openpnt_agent.pylib/openpnt.js |
OPENPNT_BUILD_JOBS |
No | $(getconf _NPROCESSORS_ONLN 2>/dev/null || echo 2 |
interpolation | edge/openpnt-linuxptp/install-linuxptp.sh |
OPENPNT_CLOCK_STALE_AFTER_S |
No | — | process.env | lib/openpnt-timing.js |
OPENPNT_LINUXPTP_BIN_DIR |
No | — | os.getenv | drivers/openpnt_agent.pydrivers/openpnt_linuxptp.py |
OPENPNT_NODE_ID |
No | — | os.getenv | drivers/openpnt_agent.pydrivers/openpnt_linuxptp.py |
OPENPNT_POLL_SECONDS |
No | — | os.getenv | drivers/openpnt_agent.py |
OPENPNT_POSITION_MAX_AGE_S |
No | — | process.env | lib/openpnt.js |
OPENPNT_PTP_CONFIG |
No | — | os.getenv | drivers/openpnt_agent.py |
OPENPNT_PTP_INSTANCE |
No | — | os.getenv | drivers/openpnt_agent.py |
OPENPNT_PTP_INTERFACE |
No | — | os.getenv | drivers/openpnt_agent.py |
OPENPNT_SERVER |
No | — | os.getenv | drivers/openpnt_agent.py |
OPENPNT_SPOOL_FILE |
No | — | os.getenv | drivers/openpnt_agent.py |
OPENPNT_TAI_UTC_OFFSET_S |
No | — | process.env | lib/openpnt.js |
OPENPNT_TDOA_MAX_UNCERTAINTY_NS |
No | — | process.env | lib/openpnt-timing.js |
OPENPNT_TDOA_MIN_SENSORS |
No | — | process.env | lib/openpnt-timing.js |
OPENPNT_TOKEN |
Yes | — | os.getenv | drivers/openpnt_agent.py |
OPENRF_5G_CORE_DIR |
No | $HOME/5g/magic-core |
interpolation | openrf/agent/functions/start-5g-core.shopenrf/agent/functions/status-5g-core.sh |
OPENRF_AGENT_OFFLINE_SECONDS |
No | 70 |
process.env | lib/openrf-controller/server.js |
OPENRF_AGENT_TOKEN |
Yes | [REDACTED] |
process.env, shell | server.jslib/openrf-controller/server.jsopenrf/API.md |
OPENRF_BASE_PATH |
No | /open-rf |
process.env | lib/openrf-controller/server.js |
OPENRF_DATA_DIR |
No | path.join(DATA |
process.env | server.jslib/openrf-controller/server.js |
OPENRF_DISPATCH_LEASE_SECONDS |
No | 90 |
process.env | lib/openrf-controller/server.js |
OPENRF_OPERATOR_TOKEN |
Yes | [REDACTED] |
process.env, shell | server.jslib/openrf-controller/server.jsopenrf/API.mdopenrf/README-UPSTREAM-v0.3.0.md |
OPENRF_PYTHON |
No | /usr/bin/python3 |
os.getenv | openrf/agent/src/openrf_agent/util.py |
OPENRF_RADIO_ADDRESS |
No | 192.168.20.2 |
interpolation | openrf/agent/functions/probe-n310.sh |
OPENRF_RADIO_ID |
No | N310-01 |
interpolation | openrf/agent/functions/start-5g-ran-n78-n310.sh |
OPENRF_READ_TOKEN |
Yes | — | process.env, shell | server.jslib/openrf-controller/server.jsopenrf/API.md |
OPENSOF_BASE |
No | http://127.0.0.1:3000 |
os.getenv | scenarios/run_openeyes_demo.py |
OPENSOF_EVENT_URL |
No | http://127.0.0.1:3000/api/event |
os.getenv | demo_simulator.py |
OPENSOF_ROOT |
No | https://wallacecorptech.com/live/opensof |
interpolation | examples/opencybersec/ingest-examples.sh |
OPENSOF_URL |
No | http://127.0.0.1:3000 |
shell, os.getenv, getenv, interpolation | OPENLVC-DEMO.mdedge/openlvc/README.mdedge/openlvc/dis_udp_bridge.pyedge/openlvc/rti_openbus_gateway.pyedge/openlvc/systemd/openlvc-ais-bridge.serviceedge/openlvc/systemd/openlvc-dis-bridge.service |
OPENSSA_ACTIVE_TIMEOUT_S |
No | 900 |
process.env | server.jsedge/openssa-sensor/SERVER_INTEGRATION.mdedge/openssa-sensor/lib/openssa.jslib/openssa.js |
OPENSSA_EMITTER_HISTORY_LIMIT |
No | 2000 |
process.env | edge/openssa-sensor/lib/openssa.jslib/openssa.js |
OPENSSA_EMITTER_SIGHTING_LIMIT |
No | 500 |
process.env | edge/openssa-sensor/lib/openssa.jslib/openssa.js |
OPENSSA_GEOLOCATION_HISTORY_LIMIT |
No | 100 |
process.env | edge/openssa-sensor/lib/openssa.jslib/openssa.js |
OPENSSA_ITU_REGION |
No | 2 |
process.env | server.jsedge/openssa-sensor/SERVER_INTEGRATION.mdedge/openssa-sensor/lib/openssa.jslib/openssa.js |
OPENSSA_LOCATION_PROFILE |
No | — | os.getenv | edge/openssa-sensor/drivers/ssa_sensor.py |
OPENSSA_SENSOR_TOKEN |
Yes | [REDACTED] |
process.env, os.getenv | server.jsedge/openssa-sensor/SERVER_INTEGRATION.mdedge/openssa-sensor/local_server.jsedge/openssa-sensor/demo/run_streaming_demo.pyedge/openssa-sensor/lib/openssa.jslib/openssa.js |
OPENSSA_UHD_SPECTRUM_ENGINE |
No | — | os.getenv | edge/openssa-sensor/drivers/ssa_sensor.py |
OPENWEBUI_API_KEY |
Yes | [REDACTED] |
process.env | server.jslib/openllm/providers.js |
OPENWEBUI_CHAT_PATH |
No | /api/chat/completions |
process.env | server.js |
OPENWEBUI_DEFAULT_MODEL |
No | — | process.env | server.js |
OPENWEBUI_HEALTH_PATH |
No | /health |
process.env | server.js |
OPENWEBUI_MODELS_PATH |
No | /api/models |
process.env | server.js |
OPENWEBUI_URL |
No | ).replace(/\/+$/ |
process.env | server.js |
OPEN_EYES_API_BASE |
No | — | os.getenv | drivers/raspbot_openeyes_agent.py |
OPEN_EYES_ASSET_ID |
No | ISAC-RASPBOT-01 |
os.getenv | drivers/raspbot_openeyes_agent.py |
OPEN_EYES_DEFAULT_ASSET |
No | ISAC-RASPBOT-01 |
process.env | server.js |
OPEN_EYES_HTTP_TIMEOUT |
No | 3 |
os.getenv | drivers/raspbot_openeyes_agent.py |
OPEN_EYES_LOG_LEVEL |
No | INFO |
os.getenv | drivers/raspbot_openeyes_agent.py |
OPEN_EYES_RECONNECT_DELAY |
No | 2 |
os.getenv | drivers/raspbot_openeyes_agent.py |
OPEN_EYES_STATUS_INTERVAL |
No | 0.25 |
os.getenv | drivers/raspbot_openeyes_agent.py |
OPEN_EYES_VERIFY_TLS |
No | true |
os.getenv | drivers/raspbot_openeyes_agent.py |
OPEN_EYES_VIDEO_FPS |
No | 15 |
os.getenv | drivers/raspbot_openeyes_agent.py |
OPEN_SOF |
No | — | shell | OPENKNOWLEDGE-OPENTASK.md |
OWHG |
No | — | shell | third_party/ontowiki/application/scripts/makeRelease.sh |
PATH |
No | /usr/sbin:/usr/bin:/sbin:/bin |
os.getenv, process.env, shell | edge/opencybersec/opencybersec_agent.pylib/openllm/pipeline-engine.jslib/openllm/util.jstests/openpnt_agent_smoke_test.pytests/openpnt_linuxptp_wrapper_smoke_test.pythird_party/ontowiki/application/scripts/travis/install-services.sh |
PHPVERSION |
No | — | shell | third_party/ontowiki/application/scripts/travis/install-extensions.sh |
PHP_ |
No | — | shell | third_party/ontowiki/application/scripts/travis/install-extensions.sh |
PORT |
No | 3000 |
process.env, interpolation | server.jsedge/openssa-sensor/local_server.jslib/openrf-controller/server.js |
PUBLIC_BASE_URL |
No | COMPILED_DEPLOYMENT.publicBaseUrl).replace(/\/+$/ |
process.env, interpolation | server.js |
PWD |
No | — | shell | third_party/ontowiki/application/scripts/vad/prepare.sh |
PYTHONUNBUFFERED |
No | 1 |
systemd | openrf/agent/systemd/openrf-agent.service |
RASPBOT_BROWSER_WS_URL |
No | — | process.env | server.js |
RASPBOT_CONTROL_URL |
No | — | process.env | server.js |
RASPBOT_LOCAL_URL |
No | http://127.0.0.1:6001 |
os.getenv | drivers/raspbot_openeyes_agent.py |
RASPBOT_STREAM_URL |
No | — | process.env | server.js |
RASPBOT_WS_URL |
No | — | os.getenv | drivers/raspbot_openeyes_agent.py |
RES |
No | — | interpolation | lib/openiia.js |
RESULTFILE |
No | — | shell | third_party/ontowiki/application/scripts/vad/prepare.sh |
ROCKETCHAT_AUTH_TOKEN |
Yes | [REDACTED] |
process.env | server.js |
ROCKETCHAT_BOT_USERNAME |
No | openc5.bot |
process.env | server.js |
ROCKETCHAT_EMBED_URL |
No | — | process.env | server.js |
ROCKETCHAT_INCOMING_WEBHOOK_URL |
No | — | process.env | server.js |
ROCKETCHAT_OUTGOING_TOKEN |
Yes | [REDACTED] |
process.env, interpolation | server.jsrocketchat/outgoing-webhook-test.sh |
ROCKETCHAT_PUBLIC_URL |
No | ROCKETCHAT_URL || '').replace(/\/+$/ |
process.env | server.js |
ROCKETCHAT_URL |
No | ).replace(/\/+$/ |
process.env, interpolation | server.js |
ROCKETCHAT_USER_ID |
No | — | process.env | server.js |
ROLE |
No | — | shell | edge/openssa-sensor/install-demo-sensor.sh |
ROOT |
No | — | shell | edge/opencybersec/install.shedge/openpnt-linuxptp/SELF-TEST.shedge/openpnt-linuxptp/install-linuxptp.shedge/openssa-sensor/install-demo-sensor.shedge/openssa-sensor/install/install-native-uhd.shedge/openssa-sensor/install/install-sensor.sh |
RUN_GROUP |
No | — | shell | openrf/agent/install.sh |
RUN_ID |
No | — | shell | OPENCYBERSEC.md |
RUN_USER |
No | — | shell | openrf/agent/install.sh |
SERVICE |
No | — | shell | edge/opencybersec/install.sh |
SERVICE_GROUP |
No | — | shell | edge/openssa-sensor/install/install-sensor.shedge/openssa-sensor/install/update-existing-sensor.sh |
SERVICE_USER |
No | — | shell | edge/openssa-sensor/install/install-sensor.shedge/openssa-sensor/install/update-existing-sensor.sh |
SESAME |
No | — | shell | third_party/ontowiki/application/scripts/travis/install-services.sh |
SITE_ID |
No | COMPILED_DEPLOYMENT.siteId |
process.env | server.jsedge/openssa-sensor/lib/openssa.jslib/openssa.js |
SOURCE |
No | — | shell | edge/openpnt-linuxptp/install-linuxptp.sh |
SOURCE_ROOT |
No | — | shell | modules/open-networks/integration/install-module-files.sh |
SRC |
No | — | shell | drivers/install_openpnt_agent.sh |
SSA_API |
No | — | interpolation | edge/openssa-sensor/public/open-ssa/app.jsopen-ssa/app.jspublic/open-ssa/app.js |
STAMP |
No | — | shell | modules/open-networks/integration/install-module-files.sh |
STICKER |
No | — | shell | third_party/ontowiki/application/scripts/vad/prepare.sh |
STICKERBEGIN |
No | — | shell | third_party/ontowiki/application/scripts/vad/prepare.sh |
SUDO_USER |
No | $USER |
interpolation | edge/openssa-sensor/install/install-sensor.shedge/openssa-sensor/install/update-existing-sensor.shopenrf/agent/install.sh |
SUITE_VERSION |
No | — | interpolation | server.jstools/integrate_opensof_service_entries.py |
TARGET_ROOT |
No | — | shell | modules/open-networks/integration/install-module-files.sh |
TASK |
No | — | shell | rocketchat/outgoing-webhook-test.sh |
TOKEN |
Yes | — | shell | edge/openssa-sensor/install-demo-sensor.shrocketchat/outgoing-webhook-test.sh |
TOMCAT_VERSION |
No | — | shell | third_party/ontowiki/application/scripts/travis/install-services.sh |
TRACK_API |
No | — | interpolation | integrations/opencop-openeyes/patched-static/map.js |
TRAVIS_PHP_VERSION |
No | — | shell | third_party/ontowiki/application/scripts/travis/install-extensions.shthird_party/ontowiki/application/scripts/travis/install-services.sh |
UHD_INCLUDE_DIRS |
No | — | interpolation | edge/openssa-sensor/native/uhd_spectrum_engine/CMakeLists.txt |
UHD_LIBRARIES |
No | — | interpolation | edge/openssa-sensor/native/uhd_spectrum_engine/CMakeLists.txt |
USER |
No | — | shell | edge/openssa-sensor/SENSOR_INSTALL.mdedge/openssa-sensor/install-demo-sensor.shedge/openssa-sensor/install/install-sensor.shedge/openssa-sensor/install/update-existing-sensor.shopenrf/README-UPSTREAM-v0.3.0.mdthird_party/ontowiki/application/scripts/travis/install-services.sh |
VIRTTMP |
No | — | shell | third_party/ontowiki/application/scripts/vad/prepare.sh |
VIRTUOSO |
No | — | shell | third_party/ontowiki/application/scripts/travis/install-services.sh |
VIRTUOSO_T |
No | — | shell | third_party/ontowiki/application/scripts/vad/prepare.sh |
WORK |
No | — | shell | edge/openssa-sensor/install-demo-sensor.sh |
Configuration policy
- Store edition-specific configuration outside the immutable release directory.
- Do not store passwords, tokens, private keys or complete credentials in BookStack, source control, command history or URLs.
- Document variable purpose, valid values, default behavior, reload/restart requirement and owning service.
- Use separate secrets per distribution/instance and rotate them through a recorded procedure.
- Validate required variables before service start and fail clearly instead of silently selecting unsafe defaults.
Maintainer Notes
Add human-reviewed deployment notes, corrections, decisions, screenshots, and links here. Content outside the generated block is preserved on future runs.
systemd Services
systemd Services
| Field | Value |
|---|---|
| Distribution | BSS — OpenC5ISR |
| Product | OpenC5ISR |
| Release | 0.15.1 |
| Deployment | openc5isr.bss.dev |
| Source | /srv/bss/releases/OpenC5ISR-v0.15.0-20app |
| Evidence | Release and readable host service definitions |
| Source fingerprint | 93926e8c834f1ed79c9017a4096f70c76d73ce4f870f104fbd0cf54b2bed50ee |
| Status | Generated baseline — human review required |
Verification boundary: This page combines platform design guidance with static evidence from the release. It does not prove that every detected interface is enabled, reachable, secure, or operational in the deployed environment.
Observed service units
| Unit | Description | User | Working directory | ExecStart | Restart | Evidence |
|---|---|---|---|---|---|---|
| opencybersec-agent.service | OpenCyberSec Defensive Edge Sensor Agent | opencybersec | — |
/opt/opencybersec-agent/opencybersec_agent.py --config /etc/opencybersec-agent.json |
on-failure | edge/opencybersec/systemd/opencybersec-agent.service |
| openlvc-ais-bridge.service | OpenLVC AIS NMEA Bridge | rocketman | /opt/opensof/edge/openlvc |
/usr/bin/python3 /opt/opensof/edge/openlvc/ais_nmea_bridge.py --opensof ${OPENSOF_URL} --token [REDACTED] --bind 0.0.0.0 --port 10110 |
on-failure | edge/openlvc/systemd/openlvc-ais-bridge.service |
| openlvc-dis-bridge.service | OpenLVC IEEE DIS UDP Bridge | rocketman | /opt/opensof/edge/openlvc |
/usr/bin/python3 /opt/opensof/edge/openlvc/dis_udp_bridge.py --opensof ${OPENSOF_URL} --token [REDACTED] --bind 0.0.0.0 --port 3000 |
on-failure | edge/openlvc/systemd/openlvc-dis-bridge.service |
| openlvc-flightgear-bridge.service | OpenLVC FlightGear UDP Bridge | rocketman | /opt/opensof/edge/openlvc |
/usr/bin/python3 /opt/opensof/edge/openlvc/flightgear_bridge.py --opensof ${OPENSOF_URL} --token [REDACTED] --bind 0.0.0.0 --port 5505 |
on-failure | edge/openlvc/systemd/openlvc-flightgear-bridge.service |
| openlvc-rti-gateway.service | OpenLVC OpenBus to HLA RTI Gateway | rocketman | /opt/opensof/edge/openlvc |
/usr/bin/python3 /opt/opensof/edge/openlvc/rti_openbus_gateway.py --opensof ${OPENSOF_URL} --token [REDACTED] --federation ${OPENLVC_FEDERATION} --federate ${OPENLVC_FEDERATE} --sidecar-command ${OPENLVC_RTI_SIDECAR_COMMAND} |
on-failure | edge/openlvc/systemd/openlvc-rti-gateway.service |
| openpnt-phc2sys@.service | OpenPNT linuxptp phc2sys instance %i | root | — |
/opt/openpnt/bin/openpnt-linuxptp run phc2sys --instance /etc/openpnt/linuxptp/instances/%i.json --bin-dir /opt/openpnt/linuxptp/bin |
on-failure | edge/openpnt-linuxptp/systemd/openpnt-phc2sys@.service |
| openpnt-ptp4l@.service | OpenPNT linuxptp ptp4l instance %i | root | — |
/opt/openpnt/bin/openpnt-linuxptp run ptp4l --instance /etc/openpnt/linuxptp/instances/%i.json --bin-dir /opt/openpnt/linuxptp/bin |
on-failure | edge/openpnt-linuxptp/systemd/openpnt-ptp4l@.service |
| openpnt-ts2phc@.service | OpenPNT linuxptp ts2phc instance %i | root | — |
/opt/openpnt/bin/openpnt-linuxptp run ts2phc --instance /etc/openpnt/linuxptp/instances/%i.json --bin-dir /opt/openpnt/linuxptp/bin |
on-failure | edge/openpnt-linuxptp/systemd/openpnt-ts2phc@.service |
| openrf-agent.service | OpenRF Radio Agent | OPENRF_USER | /opt/openrf-agent |
/usr/local/bin/openrf-agent --config /etc/openrf/openrf-agent.json |
always | openrf/agent/systemd/openrf-agent.service |
| openc5isr-bss.service | OpenC5ISR - openc5isr.bss.dev | bss-ops | /srv/bss/instances/openc5isr/current |
/usr/local/bin/npm start |
on-failure | /etc/systemd/system/openc5isr-bss.service |
Authoritative deployment checklist
- Copy unit files to /etc/systemd/system only from a reviewed release/deployment source.
- Run systemctl daemon-reload after unit changes, then enable/start the intended instance.
- Use a dedicated non-login service account with read-only release access and only required persistent-state permissions.
- Set WorkingDirectory and absolute ExecStart paths; do not depend on an interactive shell profile.
- Add health-aware dependencies and restart limits so a bad backend does not create a restart storm.
Verification commands
systemctl cat <unit>.service
systemctl status <unit>.service --no-pager
systemctl show <unit>.service -p User -p Group -p WorkingDirectory -p ExecStart
journalctl -u <unit>.service -n 200 --no-pager
Maintainer Notes
Add human-reviewed deployment notes, corrections, decisions, screenshots, and links here. Content outside the generated block is preserved on future runs.
Nginx Configuration
Nginx Configuration
| Field | Value |
|---|---|
| Distribution | BSS — OpenC5ISR |
| Product | OpenC5ISR |
| Release | 0.15.1 |
| Deployment | openc5isr.bss.dev |
| Source | /srv/bss/releases/OpenC5ISR-v0.15.0-20app |
| Evidence | Release and readable host Nginx configuration |
| Source fingerprint | 93926e8c834f1ed79c9017a4096f70c76d73ce4f870f104fbd0cf54b2bed50ee |
| Status | Generated baseline — human review required |
Verification boundary: This page combines platform design guidance with static evidence from the release. It does not prove that every detected interface is enabled, reachable, secure, or operational in the deployed environment.
Observed proxy configuration
| Evidence | server_name | listen | location | proxy_pass |
|---|---|---|---|---|
/etc/nginx/sites-available/openc5isr.bss.dev |
openc5isr.bss.dev openc5isr.bss.dev |
443 ssl [::]:443 ssl 80 [::]:80 |
/ws/raspbot / |
http://127.0.0.1:8096/ws/raspbothttp://127.0.0.1:3202/ |
Proxy requirements
- Terminate TLS with a valid certificate and redirect clear-text HTTP to HTTPS.
- Preserve Host, X-Real-IP, X-Forwarded-For and X-Forwarded-Proto headers.
- Configure WebSocket upgrade headers on real-time routes.
- Set upload/body/time limits deliberately for imagery, video, files and long-running analytics.
- Keep each distribution hostname mapped to its intended service/port; test routing after every release.
- Run nginx -t before reload and retain the last-known-good configuration.
Verification commands
sudo nginx -t
sudo systemctl reload nginx
curl -I https://openc5isr.bss.dev/
Maintainer Notes
Add human-reviewed deployment notes, corrections, decisions, screenshots, and links here. Content outside the generated block is preserved on future runs.
Ports and Network Bindings
Ports and Network Bindings
| Field | Value |
|---|---|
| Distribution | BSS — OpenC5ISR |
| Product | OpenC5ISR |
| Release | 0.15.1 |
| Deployment | openc5isr.bss.dev |
| Source | /srv/bss/releases/OpenC5ISR-v0.15.0-20app |
| Evidence | Static numeric port extraction |
| Source fingerprint | 93926e8c834f1ed79c9017a4096f70c76d73ce4f870f104fbd0cf54b2bed50ee |
| Status | Generated baseline — human review required |
Verification boundary: This page combines platform design guidance with static evidence from the release. It does not prove that every detected interface is enabled, reachable, secure, or operational in the deployed environment.
Observed port candidates
| Port | Protocol | Evidence | Source |
|---|---|---|---|
| 1 | tcp | port mapping to 30 | public/open-lvc/index.html |
| 1 | tcp | port mapping to 80 | third_party/openil_linuxptp/config.c |
| 1 | tcp | port mapping to 80 | third_party/openil_linuxptp/configs/G.8275.1.cfg |
| 1 | tcp | port mapping to 80 | third_party/openil_linuxptp/configs/automotive-master.cfg |
| 1 | tcp | port mapping to 80 | third_party/openil_linuxptp/configs/automotive-slave.cfg |
| 1 | tcp | port mapping to 80 | third_party/openil_linuxptp/configs/default.cfg |
| 1 | tcp | port mapping to 80 | third_party/openil_linuxptp/configs/gPTP.cfg |
| 2 | tcp | port mapping to 00 | tests/openpnt_agent_smoke_test.py |
| 10 | tcp | port mapping to 150 | third_party/ontowiki/extensions/datagathering/scripts/jquery.autocomplete.js |
| 11 | tcp | port mapping to 43 | third_party/ontowiki/extensions/themes/silverblue/scripts/libraries/jquery.dimensions.js |
| 11 | tcp | port mapping to 20 | third_party/ontowiki/extensions/translations/ru/core.csv |
| 12 | tcp | port mapping to 00 | third_party/ontowiki/extensions/exconf/Archive.php |
| 13 | tcp | port mapping to 11 | data/openssa.json |
| 13 | tcp | port mapping to 15 | third_party/ontowiki/application/config/SysBase.rdf |
| 13 | tcp | port mapping to 59 | third_party/ontowiki/application/scripts/vad/ow_vad_sticker_template.xml |
| 13 | tcp | port mapping to 29 | third_party/ontowiki/extensions/themes/silverblue/scripts/libraries/jquery.simplemodal.js |
| 14 | tcp | port mapping to 53 | data/openssa.json |
| 15 | tcp | port mapping to 04 | data/openssa.json |
| 18 | tcp | port mapping to 30 | third_party/ontowiki/extensions/datagathering/scripts/jquery.autocomplete.js |
| 19 | tcp | port mapping to 29 | third_party/ontowiki/extensions/exconf/resources/exconf.css |
| 19 | tcp | port mapping to 08 | third_party/ontowiki/extensions/filter/resources/jquery.treeview.js |
| 20 | tcp | command argument | UPGRADE-v0.11.0.md |
| 21 | tcp | port mapping to 01 | third_party/ontowiki/extensions/exconf/pclzip.lib.php |
| 21 | tcp | port mapping to 39 | third_party/ontowiki/extensions/exconf/resources/togglebutton.css |
| 30 | tcp | port mapping to 10 | edge/openssa-sensor/lib/openssa.js |
| 30 | tcp | port mapping to 10 | lib/openssa.js |
| 80 | tcp | port mapping to 443 | third_party/ontowiki/extensions/themes/silverblue/scripts/libraries/jquery-1.9.1.js |
| 200 | tcp | port mapping to 404 | edge/openssa-sensor/lib/openssa.js |
| 200 | tcp | port mapping to 422 | lib/open-networks/service.js |
| 200 | tcp | port mapping to 404 | lib/openllm.js |
| 200 | tcp | port mapping to 404 | lib/openssa.js |
| 200 | tcp | port mapping to 404 | third_party/ontowiki/extensions/themes/silverblue/scripts/libraries/jquery-1.9.1.js |
| 201 | tcp | port mapping to 200 | lib/openrf-controller/server.js |
| 319 | tcp | command argument | third_party/openil_linuxptp/udp.c |
| 319 | tcp | command argument | third_party/openil_linuxptp/udp6.c |
| 320 | tcp | command argument | third_party/openil_linuxptp/udp.c |
| 320 | tcp | command argument | third_party/openil_linuxptp/udp6.c |
| 401 | tcp | port mapping to 400 | lib/openrf-controller/server.js |
| 413 | tcp | port mapping to 400 | lib/open-networks/index.js |
| 443 | tcp | port mapping to 80 | server.js |
| 1000 | tcp | port mapping to 20 | public/open-networks/app.js |
| 1000 | tcp | port mapping to 200 | third_party/ontowiki/extensions/themes/silverblue/scripts/libraries/jquery-ui-1.8.22.js |
| 3000 | tcp | URL | OPENCYBERSEC-QUICKSTART.md |
| 3000 | tcp | URL | OPENLVC-RTI.md |
| 3000 | tcp | URL | README-OPENEYES.md |
| 3000 | tcp | URL | SCENARIOS.md |
| 3000 | tcp | URL | demo_simulator.py |
| 3000 | tcp | URL | drivers/eod_technician_agent.py |
| 3000 | tcp | URL | drivers/n310_sensor_agent.py |
| 3000 | tcp | URL | drivers/openaar_edge_recorder.py |
| 3000 | tcp | URL | drivers/openanalytics-agent.env.example |
| 3000 | tcp | URL | drivers/raspbot_task_agent.py |
| 3000 | tcp | URL | drivers/sse_to_udp_task_bridge.py |
| 3000 | tcp | command argument | edge/openlvc/README.md |
| 3000 | tcp | URL | edge/openlvc/ais_nmea_bridge.py |
| 3000 | tcp | URL | edge/openlvc/dis_udp_bridge.py |
| 3000 | tcp | URL | edge/openlvc/flightgear_bridge.py |
| 3000 | tcp | URL | edge/openlvc/rti_openbus_gateway.py |
| 3000 | tcp | command argument | edge/openlvc/systemd/openlvc-dis-bridge.service |
| 3000 | tcp | URL | edge/openssa-sensor/QUICKSTART-B210.md |
| 3000 | tcp | URL | edge/openssa-sensor/README.md |
| 3000 | tcp | URL | edge/openssa-sensor/config/ssa-sensor-simulation.json |
| 3000 | tcp | URL | edge/openssa-sensor/config/ssa-sensor-uhd-b210-local.json |
| 3000 | tcp | URL | edge/openssa-sensor/demo/run_streaming_demo.py |
| 3000 | tcp | URL | lib/openllm/providers.js |
| 3000 | tcp | URL | open-daa/open-analytics/app.js |
| 3000 | tcp | URL | rocketchat/outgoing-webhook-test.sh |
| 3000 | tcp | URL | scenarios/run_demo_sequence.sh |
| 3000 | tcp | URL | scenarios/run_eod_floor_mission.py |
| 3000 | tcp | URL | scenarios/run_follow_mission.py |
| 3000 | tcp | URL | scenarios/run_fusion_demo.py |
| 3000 | tcp | URL | scenarios/run_openeyes_demo.py |
| 3000 | tcp | URL | scenarios/send_eod_message.py |
| 3000 | tcp | URL | server.js |
| 3030 | tcp | command argument | third_party/ontowiki/application/scripts/travis/README.md |
| 3600 | tcp | configuration directive | server.js |
| 5505 | tcp | command argument | OPENLVC-DEMO.md |
| 5505 | tcp | command argument | edge/openlvc/README.md |
| 5505 | tcp | command argument | edge/openlvc/systemd/openlvc-flightgear-bridge.service |
| 6001 | tcp | URL | README-OPENEYES.md |
| 6001 | tcp | command argument | drivers/README-RASPBOT-OPENEYES.txt |
| 6001 | tcp | URL | drivers/openpnt_raspbot_guidance.py |
| 6001 | tcp | URL | drivers/raspbot-openeyes.env.example |
| 6001 | tcp | URL | drivers/raspbot_openeyes_agent.py |
| 7101 | tcp | command argument | SCENARIOS.md |
| 8075 | tcp | command argument | openrf/README-UPSTREAM-v0.3.0.md |
| 8075 | tcp | URL | openrf/agent/config/openrf-agent.json |
| 8080 | tcp | URL | third_party/ontowiki/application/scripts/travis/README.md |
| 8080 | tcp | URL | third_party/ontowiki/application/scripts/travis/install-services.sh |
| 8088 | tcp | URL | third_party/ontowiki/application/scripts/travis/README.md |
| 8095 | tcp | URL | openrf/API.md |
| 8800 | tcp | URL | drivers/mock_rocketchat.py |
| 8888 | tcp | URL | drivers/openanalytics-agent.json.example |
| 8888 | tcp | URL | open-daa/open-analytics/app.js |
| 8888 | tcp | URL | public/open-daa/open-analytics/app.js |
| 8890 | tcp | URL | third_party/ontowiki/application/scripts/travis/README.md |
| 8890 | tcp | URL | third_party/ontowiki/application/scripts/vad/vad.ini |
| 9000 | tcp | URL | open-lvc/app.js |
| 9999 | tcp | URL | third_party/ontowiki/application/scripts/travis/install-services.sh |
| 10110 | tcp | command argument | edge/openlvc/README.md |
| 10110 | tcp | command argument | edge/openlvc/systemd/openlvc-ais-bridge.service |
| 18782 | tcp | URL | tests/compiled_deployment_smoke_test.py |
Port governance
A numeric occurrence is only a candidate. Confirm the owning process with ss -lntup, the service with systemctl, the container mapping with docker compose ps, and the public route with Nginx. Document whether each port binds to loopback, a management interface, an operational network or all interfaces.
Maintainer Notes
Add human-reviewed deployment notes, corrections, decisions, screenshots, and links here. Content outside the generated block is preserved on future runs.
Installation & Lifecycle
Managed documentation for Installation & Lifecycle.
Installation Procedure
Installation Procedure
| Field | Value |
|---|---|
| Distribution | BSS — OpenC5ISR |
| Product | OpenC5ISR |
| Release | 0.15.1 |
| Deployment | openc5isr.bss.dev |
| Source | /srv/bss/releases/OpenC5ISR-v0.15.0-20app |
| Evidence | Release manifests plus controlled deployment pattern |
| Source fingerprint | 93926e8c834f1ed79c9017a4096f70c76d73ce4f870f104fbd0cf54b2bed50ee |
| Status | Generated baseline — human review required |
Verification boundary: This page combines platform design guidance with static evidence from the release. It does not prove that every detected interface is enabled, reachable, secure, or operational in the deployed environment.
Candidate build/install entry points
| Evidence | Invocation | Declared action |
|---|---|---|
package.json |
npm run start |
npm run verify:startup && node server.js |
package.json |
npm run test |
python3 tests/integrated_smoke_test.py && python3 tests/openknowledge_opentask_ontology_smoke_test.py && python3 tests/opendaa_opendata_smoke_test.py && python3 tests/opendaa_openanalytics_smoke_test.py && python3 tests/opencop_smoke_test.py && python3 tests/smoke_test.py && python3 tests/openeyes_smoke_test.py && python3 tests/raspbot_agent_smoke_test.py && python3 tests/openpnt_smoke_test.py && python3 tests/openpnt_linuxptp_wrapper_smoke_test.py && python3 tests/openpnt_agent_smoke_test.py && python3 tests/external_integrations_smoke_test.py && python3 tests/compiled_deployment_smoke_test.py && node tests/openssa/test_openssa.js && python3 tests/openssa/test_sensor.py && python3 tests/openssa_opensof_smoke_test.py && python3 tests/openrf_opensof_smoke_test.py && python3 tests/openlvc_edge_gateway_test.py && python3 tests/openlvc_smoke_test.py && python3 tests/opencybersec_smoke_test.py && python3 tests/opencybersec_agent_smoke_test.py && python3 tests/openiia_smoke_test.py && python3 tests/openaar_mr_smoke_test.py |
package.json |
npm run verify:startup |
node -e "require('./lib/openpnt-timing'); require('./lib/openpnt'); console.log('startup dependencies OK')" |
edge/openssa-sensor/package.json |
npm run start |
node local_server.js 3000 |
edge/openssa-sensor/package.json |
npm run check |
node --check lib/openssa.js && node --check public/open-ssa/app.js && node --check local_server.js && python3 -m py_compile drivers/ssa_sensor.py tools/*.py demo/run_streaming_demo.py tests/*.py |
edge/openssa-sensor/package.json |
npm run test |
npm run check && node tests/test_openssa.js && python3 -m unittest discover -s tests -v |
third_party/ontowiki/Makefile |
make clean |
Make target |
third_party/ontowiki/Makefile |
make codebeautifier |
Make target |
third_party/ontowiki/Makefile |
make codesniffer |
Make target |
third_party/ontowiki/Makefile |
make composer-install |
Make target |
third_party/ontowiki/Makefile |
make debianize |
Make target |
third_party/ontowiki/Makefile |
make default |
Make target |
third_party/ontowiki/Makefile |
make deploy |
Make target |
third_party/ontowiki/Makefile |
make devenv |
Make target |
third_party/ontowiki/Makefile |
make directories |
Make target |
third_party/ontowiki/Makefile |
make getcomposer |
Make target |
third_party/ontowiki/Makefile |
make help |
Make target |
third_party/ontowiki/Makefile |
make help-cs |
Make target |
third_party/ontowiki/Makefile |
make help-test |
Make target |
third_party/ontowiki/Makefile |
make install |
Make target |
third_party/ontowiki/Makefile |
make list-events |
Make target |
third_party/ontowiki/Makefile |
make odbctest |
Make target |
third_party/ontowiki/Makefile |
make test |
Make target |
third_party/ontowiki/Makefile |
make test-directories |
Make target |
third_party/ontowiki/Makefile |
make test-extensions |
Make target |
third_party/ontowiki/Makefile |
make test-integration-mysql |
Make target |
third_party/ontowiki/Makefile |
make test-integration-virtuoso |
Make target |
third_party/ontowiki/Makefile |
make test-unit |
Make target |
third_party/ontowiki/debian/Makefile/Makefile |
make clean |
Make target |
third_party/ontowiki/debian/Makefile/Makefile |
make default |
Make target |
third_party/ontowiki/debian/Makefile/Makefile |
make package |
Make target |
third_party/ontowiki/debian/Makefile/Makefile |
make prepare |
Make target |
Controlled installation procedure
- Record the release artifact name, version, checksum, source and approval.
- Back up configuration, persistent data, database state and the active proxy/service definitions.
- Extract the release into a new immutable version directory; do not overwrite the active release.
- Install dependencies using the release manifests and pinned lock files. Review install scripts before executing them as a privileged user.
- Create/update edition-specific configuration and secrets outside the release directory.
- Run unit/static tests and a local health check before switching production traffic.
- Activate atomically through the current symlink/container tag/service definition, then restart only affected services.
- Validate process state, local endpoints, Nginx routing, WebSockets, login, primary workflow and logs.
- Record actual results and keep the previous release until the acceptance window completes.
Do not assume
The generator deliberately does not invent an install command when the release does not provide enough evidence. Promote a command into this page only after it has been executed successfully on a clean or controlled target.
Maintainer Notes
Add human-reviewed deployment notes, corrections, decisions, screenshots, and links here. Content outside the generated block is preserved on future runs.
Upgrade and Rollback
Upgrade and Rollback
| Field | Value |
|---|---|
| Distribution | BSS — OpenC5ISR |
| Product | OpenC5ISR |
| Release | 0.15.1 |
| Deployment | openc5isr.bss.dev |
| Source | /srv/bss/releases/OpenC5ISR-v0.15.0-20app |
| Evidence | Lifecycle pattern and optional release comparison |
| Source fingerprint | 93926e8c834f1ed79c9017a4096f70c76d73ce4f870f104fbd0cf54b2bed50ee |
| Status | Generated baseline — human review required |
Verification boundary: This page combines platform design guidance with static evidence from the release. It does not prove that every detected interface is enabled, reachable, secure, or operational in the deployed environment.
Pre-upgrade gate
- Previous release path and rollback command are known and tested.
- Database/configuration migrations are identified, backed up and reversible or explicitly irreversible.
- External interfaces and dependent modules have compatibility expectations recorded.
- A maintenance/communications plan exists for user-visible interruption.
- Acceptance tests and responsible reviewer are assigned.
Upgrade sequence
backup → stage new release → install/validate dependencies → migrate if required
→ switch active release → restart affected services → smoke/acceptance tests
→ observe → approve or roll back
Rollback sequence
stop traffic/affected service → restore compatible data/config if required
→ repoint active release → restart → validate local/public endpoints
→ record incident and preserve failed-release evidence
Release-specific comparison
No previous release was supplied. Run with --compare /path/to/previous-release to generate a static change inventory.
Maintainer Notes
Add human-reviewed deployment notes, corrections, decisions, screenshots, and links here. Content outside the generated block is preserved on future runs.