Docs

Architecture and security

What runs where, what talks to what, and how your data and access are protected.

One install, inside your network

 Your tools ──► Connectors (alerts · metrics · code · actions · tickets · approvals)
                    │   all outbound from 3AM; nothing connects in
                    ▼
   Estate map (services ⇄ repos ⇄ alerts ⇄ owners ⇄ dependencies)
                    │
   Orchestrator ── Knowledge (your repos) ── Check packs (sealed) ── Model (optional, on-prem)
                    │
   Policy ── Approval router (Slack · Symphony · PagerDuty · phone · e-mail)
                    │
   Audit log (append-only, hash-chained, signed) ──► Console · export
ComponentRuns asNotes
3am-coreOne container (/opt/3am/3am-core)Console, API, orchestrator, connectors, audit log
3am-modelOne container, optionalWrites incident notes; reachable only from 3am-core
Data volume/var/lib/3amAudit log, incidents, code index, console-managed settings, secrets
Configuration/etc/3am (read-only mount, optional)Licence, connectors, policy, sealed packs, for teams that manage config as files

Security model

  • No inbound access. 3AM polls your tools and reads its approvals from them (Slack reactions, the Symphony datafeed, PagerDuty notes, the Twilio call result). No firewall opening from outside is needed.
  • Least privilege. Each connector guide gives the narrowest permissions that work, for example a Kubernetes Role per namespace with no exec, no delete and no access to Secrets.
  • Every change is approved and rehearsed. Dry run first, then approval with the evidence, then the change, then verification. Policy, quorum, hourly budgets and a halt switch sit on top.
  • Secrets. Secrets entered in the console are stored in files only 3AM can read (mode 0600) and are never shown again or written to the audit log. In config files, secrets are references to a file or an environment variable; values written inline are refused.
  • Audit log. Every event is chained to the previous one by hash, and each segment is signed. 3am-core ledger-verify detects any edited, deleted or reordered event. Secrets and card numbers are redacted before writing.
  • Hardened containers. Non-root user, read-only root filesystem, no Linux capabilities, no-new-privileges, no shell in the image.
  • Your data stays with you. Code, alerts and evidence never leave your network. The licence is verified offline.

On this page