Concelier Mirror Operations

This runbook is for operators who stand up and maintain a Stella Ops Concelier advisory mirror. It covers the supported deployment surfaces, mirror setup, and credential rotation and recovery. For the export surfaces that feed a mirror, see the exporters operations guide.

Supported Scope

Concelier mirror operations support Docker Compose, Offline Kit, signed release manifests, and host/service-manager deployments.

Kubernetes and Helm mirror deployment paths are retired. Do not create Kubernetes Secrets, CronJobs, LoadBalancers, Helm values, or kubectl-based mirror procedures for Stella Ops.

Mirror Setup

  1. Select the mirror release manifest and verify its SHA-256.
  2. Provision mirror credentials in the approved Compose environment file or host secret store.
  3. Stage advisory feed bundles through the Offline Kit or approved internal mirror.
  4. Start the mirror gateway through the supported Compose profile or host service manager.
  5. Verify mirror health through the gateway endpoint and Concelier connector health checks.
  6. Record source feed ids, bundle hashes, mirror config hash, and health output in release or operations evidence.

Rotation And Recovery

Unsupported Legacy Paths

Do not use Helm charts, devops/helm values, Kubernetes Secrets, Kubernetes CronJobs, Kubernetes LoadBalancers, or kubectl commands for Concelier mirror deployment.