Operations

Living operational document for the Norbeck Security Orchestrator (NSO). Covers how to install, configure, operate, and interpret results from the platform. Maintained alongside the application — every code change that affects setup or operation must update the relevant page here.

Living document policy. Any change to install steps, env vars, routes, workflows, scanners, severity handling or security posture must update the matching operations page and append an entry in the changelog, bumping OPERATIONS_DOC_VERSION in src/lib/operations-doc.ts.

Current version: 2.4.0 · Last updated: 2026-08-11

How this document is organized

  • Install & setup — prerequisites, env vars, first run, worker image.
  • Configure — Lovable Cloud, Turnstile, workers, tenant caps, secret rotation.
  • Day-to-day — assets, DNS verification, queueing scans, triaging findings.
  • Reading results — severity scale, per-scanner output, triage and reporting.
  • Security posture — current scan posture and the v2 report.
  • Dashboard — live operational snapshot.
  • Changelog — every doc and app change.

Audience

Internal NSO staff: onboarding engineers, MSP tier-1/2, AppSec, advisory.

Client-facing services are catalogued at /services.