Profile
Declare domain, users, devices, hardware, provider, budget, data classes and desired apps—without secrets.
CC10 Distribution Preview
The vision is simple: describe your needs, give a sanitized CC10 package to your AI, review its plan and create an ecosystem that remains yours. The working reference comes first; reusable automation follows verified evidence.
The reproducible path
This is not a magic prompt that receives root access. It is a staged contract: inspect, model, plan, approve, apply narrowly, verify and record.
Declare domain, users, devices, hardware, provider, budget, data classes and desired apps—without secrets.
The AI checks actual hosts, DNS, storage, network and existing data before proposing a target.
Produce topology, cost boundary, threat model, migration stages, rollback and explicit human decisions.
Use pinned OpenTofu, Compose, systemd and documented service adapters within approved scope.
Test identity, role access, app workflows, backups, representative restores, security headers and monitoring.
Keep Git authoritative, detect drift, rotate credentials, onboard people and repeat acceptance after change.
Reusable layer
Infrastructure alone does not create a usable ecosystem. CC10 also captures product roles, identity, recovery, onboarding and proof.
Portable topology, failure domains, app roles, data placement and cost boundaries.
Replaceable public edge, protected DNS, pinned containers and explicit persistent state.
SSO, passkeys, least privilege, person lifecycle and operator-only surfaces.
A model-neutral instruction contract with safety gates, assumptions and required evidence.
One clear job per app, thin-client setup, recovery and device replacement workflows.
Health, access, restore and browser checks recorded after every material deployment.
The AI contract
CC10 prefers Codex and OpenAI today, but the package describes interfaces instead of binding the system to one engine. A local or European model can replace the planning layer without replacing the apps.
Credentials enter only through protected runtime stores and narrowly scoped installation steps.
Observed state, backups and ownership must be established before changing live systems.
Every risky action names impact, rollback and the evidence that will prove success.
Repeatable operations expose narrow contracts, audit records and idempotency where possible.
No AI convenience overrides an unverified disk, missing restore, unknown host key or absent approval.
Choose your path
The self-service distribution is being extracted from the working reference. Organisations that need architecture, migration, hardening or ongoing operation can engage Cong directly.