Customers
| Customer | Status | Hostname | Called AE | HL7 | Database |
|---|---|---|---|---|---|
| Loading… | |||||
Model deployment
Which models each customer runs, which image tag and pull / endpoint. Tag and mode follow the model’s platform default unless set. Select cells (or a whole model row / customer column), then act; nothing changes until you review and apply. Applying updates each customer’s Model Zoo; their site admins tune thresholds and mappings there.
Onboard a customer
Creates an isolated database, signing key, patient hash salt, storage tree and the first admin users. The hostname returns 503 until every step succeeds.
Customer is fail-closed until Connectivity is configured: the new customer starts in VPN mode with no address block, so nothing is reachable from or to their network (PACS, report source, DICOM / HL7 ports) until you allocate a block, enter their gateway, pre-shared key and networks on the Connectivity page. Their admins can still sign in (web access is open until ranges are listed).
Onboarding
Platform
Platform readiness
Operators
| Name | Role | Active | Sign-in | Last sign-in |
|---|
Add operator
Operators sign in with an emailed link; a password is only needed for password sign-in. Disabling an operator signs them out everywhere. Password resets: python -m app.src.tenancy.cli platform-admin add --email …
Console access
Addresses or ranges allowed to reach this console, besides the ones that are always allowed (localhost and GUARDIAN_PLATFORM_ALLOWED_CIDRS). Enforced by Traefik on the console hostname.
VPN front door
The shared StrongSwan front door pulls every VPN customer’s tunnel from this console every 60 s (guardian-frontdoor sync: bearer token + ETag) and reports each tunnel’s state back. Nothing is copied by hand: whitelisting a customer is their Connectivity page plus the Terraform inputs below.
Sync
Tunnels
| Customer | Tunnel | Since | Last received | Today in / out | 30-day uptime | Detail | Reported |
|---|
Alerts
Checked every minute by the console: the front door going quiet (3 missed reports), a tunnel down or connecting longer than the threshold, a tunnel receiving nothing during the customer’s working hours (their time zone), and a scheduled C-ECHO to each VPN customer’s PACS through the tunnel failing repeatedly. Mail on alert, a reminder while it lasts, and one “recovered” mail. Customer network contacts (their Connectivity page) can be copied on their own alerts.
Terraform inputs (read-only)
Paste into terraform/aws/terraform.tfvars and apply: the IKE source ranges (each VPN customer’s gateway /32) and the customers that get a facing /32 (the output frontdoor_customer_facing_ips gives the address to enter in their Connectivity page).
Models
Deployed models
Each row is one model version in use; counts are customers, with the Model Zoo stoplight (active test inactive). Click a row for its customers. Channel: internal models (dev / sandbox) are hidden from customer pages and from customers’ own Model Zoo unless deployed to them. Deploy models, pick tags and pull / endpoint under Customers.
Prompts
LLM prompts
Each customer database runs its own copy of every prompt. Stock versions come from the repository through migrations; console versions were published here. A migration never overwrites a console version: it stores the new stock text inactive (stock pending review) until you adopt it. Workers pick up a published version on their next poll cycle (search prompts on the next request). Click a row to view, compare, edit and publish it below.
Prompt
Active text
Compare
History
| Version | When (UTC) | Source | By | Note | Active |
|---|
Roll back / adopt stock
For this customer only. Roll back publishes the chosen version’s text again as a new console version. Adopt stock re-activates the newest stock version, so later migrations update this prompt again.
Draft
A draft is never live. Start one from the customer’s active text, edit it, validate it, dry run it on a few exams, then publish it.
Validation
Changes vs this customer’s active text
Dry run
Runs the saved draft and the customer’s active prompt side by side on up to 5 exams of one customer, with that customer’s LLM settings. Nothing is saved: the customer database is opened read-only and results stay in this console for an hour.
The LLM is not fully deterministic: the same prompt can answer differently from run to run, so judge a change on several samples, not one.
Publish
Publishes the saved draft: each target customer’s current version is deactivated and the draft becomes its active console version (one audit entry per customer). Publish to a pilot customer first, then to the rest.
Platform settings
Platform settings
Shared by every customer on this platform: worker tuning, retention, CV transport, email, DataForge. A value set here overrides the env file; Reset returns to the env file or code default. Changes apply when the listed workers restart. Customer settings live in each customer's Configuration page (Zauron-managed; customers see them read-only).
Platform secrets
Zauron's own credentials. Keys and tokens show their first and last characters so you can tell which one is configured; passwords stay fully masked. Type a new value to replace one; values are never shown after saving.
| Secret | Current | Replace with | Source |
|---|
HL7 listener & Direct TLS
The MLLP listener every customer’s interface engine sends ORU^R01 to. Each customer’s port (the original install’s too) is on its Connectivity page. GUARDIAN_HL7_LISTEN_ADDRESS, GUARDIAN_HL7_LISTEN_ENABLED and GUARDIAN_HL7_LISTEN_PORT in the env file are only initial defaults for backwards compatibility: values saved here (and customer ports) win.
Direct TLS server certificate
Presented to Direct-mode customers (mutual TLS, no VPN). Traefik holds the platform certificate: point this at a file the orchestrator container can read, either Traefik’s ACME storage (for example the traefik-letsencrypt volume’s acme-dns.json mounted read-only; the certificate covering each customer’s hostname is used) or a PEM chain plus its key file (custom certificates: guardian.crt / guardian.key). The key is read from the file only, never stored or shown. Until a file is set, Direct-mode HL7 connections are refused.
Environment (read-only)
What the application needs before it can read its database, from the platform env file (.env.platform.template). Change these in the env file and recreate the containers.
Config imports
Customer configuration imports
Import the customer's intake form (YAML) or an existing env file to build its configuration, review and test it, then onboard it or apply it to an existing customer. The file is parsed and discarded; secrets are stored encrypted. After this, customers need no env file of their own. Download a blank intake form.
Drafts
| Name | Status | Customer | Updated |
|---|
Brands
Brands
A brand is a customer theme: a base layout (Zauron top tabs or RadAI sidebar) with the customer's colours, font, product name, logo and favicon. It applies to that customer's dashboard, viewer header and emails; their site admin cannot change it. Assign it in the customer's Configuration (Theme). No custom CSS or scripts; SVGs are cleaned.
| Brand | Layout | Product name | Used by | Updated |
|---|
Releases
Releases
Roll platform containers to a published version, or back. The host updater pulls the image, pins the version, recreates only that service, waits for its health check and rolls back automatically if it fails. On the shared platform a rollout affects every customer at once. Same actions from the host: scripts/guardian_updater/guardian_updater.py.
| Service | Pinned | Running image | Roll out to |
|---|
Stack release
Roll several services as one release. Every image is pulled first; services are then updated one at a time, orchestrator first (it runs the database migrations). The release stops at the first service that fails its health check and rolls that service back; services already updated stay on the new version (migrations are forward-only).
| Service | Pinned | Release version |
|---|
History
| When (UTC) | Service | Action | Version | Result | By | Reason / detail |
|---|
Platform health
Platform internals shared by every customer (sites see only their own integrations).
Platform alerts
Loading…
Database
Container registry
Host
Certificates
Database backups
Containers
Env template audit
Audit log
Platform audit log
| When (UTC) | Actor | Action | Customer | Detail | IP |
|---|