Enterprise operations (hub)

Short pages for binding, identity, automation flags, LLM boundaries, Fleet, and backup/upgrade — all cross-linking Configuration reference and the high-risk env matrix.

Landing · Updated

Operator spine (what each page proves)

Concern Read for
Local vs outbound Which sockets bind locally vs require egress (network binding, LLM boundaries).
Disk writes & retention Where snapshots/logs land on disk (backup & upgrades).
Repo mutation Whether automation flags may alter repos (allowlists).
Rollback / availability Upgrade sequencing + outage drills (deployment, backup & upgrades).
Audit evidence Logs + manifests operators can attach to incidents (incident response).

Enterprise operator spine

How each hub page traces a trigger through a bounded system step to a reviewable operator outcome.

  1. Actor / triggerThe operator or automation event that starts the concern on this page.
  2. System stepThe bounded Lenses configuration or process that responds to the trigger.
  3. Outcome / handoffThe provable result operators attach to incidents or change records.
Each hub row is intentionally short so operators can deep-link into focused runbooks
Topic Page
Security overview & .lenses-local Security and local-first operations
Network binding & proxies Enterprise — network binding
OIDC & reverse proxies Enterprise — OIDC sessions
LENSES_ALLOW_* flags Enterprise — actions allowlists
LLM data boundaries Enterprise — LLM boundaries
Forge Fleet Enterprise — Fleet integration
Backup, retention, upgrades Enterprise — backup and upgrades

Verify

Every LENSES_* variable listed in env matrix appears in Configuration reference.

What to do next