TD5 — Engineering context on a real VPS
See how this concept looks on a real VPS. These are selected concepts and inspection examples, not access to Hades.
Engineer Mode
A real VPS changes where commands run and where evidence is stored; it does not change the threat model. Inspect the active image digest, effective container user, mounts and capabilities, then compare a permitted request with a denied write. A scanner result needs its image digest, database context, time and human triage. PostgreSQL still needs a writable data volume. Hades is an observational reference; no current Hades scan result is asserted.
Inspect the host boundary
On your own host, use these read-only commands to identify the Engine and the containers it owns. Do not publish secret values or raw environment dumps.
hostname
docker context show
docker ps --format 'table {{.Names}} {{.Status}} {{.Ports}}'
On a remote route these commands run after SSH. A laptop browser remains on the laptop; it needs a tunnel to reach the remote host's loopback service.
Your engineering decision
Name the boundary this TD adds, predict a failure at that boundary, and identify an observation that would distinguish your hypothesis from another cause.
Evidence boundary
NOT YET REPLAYED ON HADES for this release. Commands here are inspection examples; they do not claim a measured Hades result. Run and explain your own assessed work.