Start here. This is the orientation page for engineers — what the stack is, the house rules you must follow, where the live work tracker lives, and links to a training page for every tool we run.
Confidential — Xzopia Limited (NI620366)
| You want… | Go to |
|---|---|
| What's happening right now, current tasks, what just got done | Session Handoff (wiki id=15) — the live tracker, updated every working session |
| The roadmap / phase plan / where we're heading | Project Status (wiki id=2) |
| How to use a specific tool (training) | The training pages listed below |
| How a thing was built/configured (reference) | The per-tool runbooks/setup docs in xzopia/docs/… |
| Who has access to what | Access Register (wiki id=21) |
| Mistakes we've already made (don't repeat them) | Lessons Learned (wiki id=3) |
This Hub is stable orientation. It deliberately does not track day-to-day status — that's Session Handoff's job, so this page doesn't go stale.
mcp.xzopiasecure.com). No scripts — manual changes only, with Simon, and only after a backup (/backup-server --server server4). Server 3 is decommissioning (its MCP services were drained to S4) — no changes except drain-verification and wind-down.~/.ssh/xzopia_server1), root login disabled. Password auth is off. Never re-enable it.nano, not by pasting into tools.github.com/Silentrunnerx/xzopia-deploy. Docs flow repo → wiki via Claude Code. Do not hand-edit wiki pages (except Session Handoff) — direct edits get overwritten on the next sync. If you change something doc-worthy, raise it so it goes into the repo properly.| Layer | Tool | Where | Training page |
|---|---|---|---|
| RMM (devices, monitoring, remote, patching) | TacticalRMM + MeshCentral | S1 · rmm/mesh.xzopiasecure.com | id=18 (existing) |
| PSA (tickets, billing, client records) | ITFlow | S2 · psa.xzopiasecure.com | id=18 (existing) |
| VoIP (phone system) | FusionPBX / FreeSWITCH | S5 · pbx.xzopiasecure.com | FusionPBX training |
| Client knowledge base | Wiki.js | S2 · kb.xzopiasecure.com | Wiki.js training |
| Internal documentation | BookStack | S2 · docs.xzopiasecure.com | BookStack training |
| Secrets vault | Vaultwarden | S2 · vault.xzopiasecure.com | Vaultwarden training |
| CRM | Twenty CRM | S2 · crm.xzopiasecure.com | Twenty CRM training |
| M365 multi-tenant management | CIPP | Azure (SWA + Function App cippbun2i) |
CIPP training |
| AI/automation integrations | MCP servers | S4 (live production) / S3 (decommissioning) | MCP training |
| Backups | Restic → Backblaze B2 | S2 + S5 | Backups training |
| Server security baseline | UFW / Fail2Ban / ClamAV / Lynis | all servers | Security baseline |
| SIEM (future) | Wazuh | S6 (planned) | Wazuh training (stub) |
Work through these in order. Tick off the per-page checklists as you go.
Capture it. Gaps you find during training are exactly what our internal BookStack runbooks should answer. Note the question, and it becomes a candidate for a new internal runbook — that's how the knowledge base grows.
Xzopia Limited (NI620366) | simon@xzopia.com | Bangor, Northern Ireland
Source of truth is the repo — promote via Claude Code; do not hand-edit in the wiki.