Future work
The large-scale projects planned for ISC³ — the ones too big to live as an item in Open points / TODOs. Each has its own page here describing the target state and how we get there; nothing on this page is deployed.
What belongs here: a project that changes the shape of the infrastructure (new hardware generation, a service moving off the rack, a new site), spans more than a session of work, and needs a design decision before anyone touches a machine. Everything smaller — a setting to change, a box to patch, a spare to order — is a todo item.
Each page carries its own Status line; when a project ships, its page moves out of this section to where the thing it created is documented, and the outcome is recorded in the journal.
The projects
| Project | What it is | Status |
|---|---|---|
| ISC³ datacenter | The two-site datacenter (building 19 + 23N307): executive summary, full design and execution plan, and the considered scenarios as the decision record. | Plan retained 2026-08-20 — racks and the two R740xd ordered, rack delivery 30 October 2026 |
| ISC GitLab | Self-hosted GitLab for the ~150 users of the programme, virtualised on the production cluster, with CI runners. The install runbook is provisioning/gitlab/install-runbook.md. | Design aligned to the retained architecture (2026-08-26); deployment is phase 2 |
| ISC Learn → managed hosting | Move the Moodle instance off the self-managed hannibal VPS onto a managed cloud server, so the OS, PHP, MySQL, TLS and base backups stop being ours. Deliberately stays off the rack. | Proposal — nothing executed |
| Exam VDI | Browser-based exam environments for BYOD laptops: SEB locks the student machine, Guacamole delivers per-student exam VMs hosted on carnaval; a non-exam variant gives generic lab desktops. No new hardware. | Proposal — not started |
| Kubernetes on carnaval | A 3-node HA k3s cluster in VMs on the playground cluster, all three GPUs schedulable, rebuilt from a template + playbook rather than backed up. Teaching cluster first, edu-ID student access as phase 2. | Design agreed — nothing built |
| Thermal protection & emergency shutdown | A layered reaction to over-temperature: warn, shed heat, shut down gracefully — instead of relying only on the component-level hard trip, which did not fire in June 2026. | Layer 1 (warn humans) implemented August 2026, the rest not |
| Service ideas | A vetted backlog of candidate services for the production cluster — student-facing (PaaS, JupyterHub, internal LLM…) and admin-facing (NetBox, Oxidized, Healthchecks…) — with the ground rules any pick inherits. | Idea pool — nothing deployed |