https://my.digitalrcc.com (Vercel project drcc-web, repo
tcecure/drcc-lab-companion) is the student and staff portal that replaces the
distributed PDF guides. It reads lab data; it never controls the lab.
| View | Audience | Source |
|---|---|---|
/dashboard, /student/start, /student/quick-start |
Student | Their own seat: pod, lab username, access window, next step |
/student/guides, /guides/<code> |
Student | Digital lab completion guides (the former PDFs) |
/student/training |
Student | Per-pod progress from the training tracker |
/student/support, /support/request |
Student / public | Support tickets |
/admin + /admin/lab-status |
Staff | Proxmox health and utilization (Lab Health Monitoring) |
/admin/import |
Staff | Bulk student upload (CSV) with pod assignment |
/admin/queue |
Staff | Active cohort queue plus Finished cohorts archive |
/admin/progress |
Staff | Per-cohort standings, frozen snapshots, staff star ratings |
/admin/community-impact |
Staff / donors | PII-free Impact metrics and Presentation Mode |
/admin/community-impact/live |
Admin | Live Operations — per-student Moodle activity and lab mapping |
/admin/email-jobs |
Staff | Outbound student mail queue and delivery state |
/admin/users, /admin/guides, /admin/support |
Staff | Accounts, guide content, tickets |
| Public home page | Visitors | Student-facing known-issues list (Current Cohort Lab Notices) |
Cohorts are date-driven: cohort 1 opened August 16, 2026, cohort 2 on
September 6, 2026, and every cohort from there runs on a 14-day cadence with
a 14-day access window and 20 seats. Student numbers are assigned at 01:00
America/New_York on the cohort start date.
Staff upload a participant CSV at /admin/import, choose the cohort and the pod
for each learner, and the portal:
studentXX / PODXX and sends the seat-assignment email.An import into a cohort already running seats the learners immediately
rather than waiting for the 01:00 assignment job. The current cohort (3)
was imported this way on September 21, 2026 with three learners on Pod01–Pod03.
Lab passwords are deliberately not in these emails. The seat email points
students at the portal; the portal-managed credential store is still to be built
(see Backlog).
When a cohort's access window closes its assignments move to completed, the
learners drop out of the active list, and /admin/queue lists them under
Finished cohorts with a link to their frozen record at
/admin/progress?cohort=<n>.
/admin/progress keeps one snapshot row per cohort
(public.cohort_progress_snapshots, RLS on, service-role only):
interim while the access window is open — overwritten from the tracker onfinal once the window closes — frozen and never rewritten, which is whatSnapshots also carry waived_labs, so labs that were credited rather than
performed are dropped from both sides of the score. Cohort 1 carries M3-L2.
Cohort 1's final snapshot was reconstructed from the last pre-reset AWX verify
jobs and captured 2026-08-31.
Finished cohorts carry a manual 1–5 star rating per student
(public.student_cohort_ratings, one row per student per cohort, RLS on with no
public policy — writes go through the server action behind requireManager()).
/admin/progress beside the student's name; Clear removes it.The Moodle projection feeds two deliberately separated views:
| View | Route | Audience | Contents |
|---|---|---|---|
| Impact | /admin/community-impact |
donors, staff, Presentation Mode | aggregate enrollment and completion metrics only — no name, email, Moodle id, IP or session detail |
| Live Operations | /admin/community-impact/live |
administrators only | per-student Moodle activity, lab mapping, Guacamole sessions, access window |
Both are read-only: the pages issue no mutating request to Moodle or Guacamole.
Activity status comes only from real Moodle standard-log events — Active now
is an event within 15 minutes, then 2 hours, 24 hours and 7 days. A login or an
open Guacamole tab alone does not make anyone active. Definitions, collector
schedule and rollback are in docs/live-operations.md in the portal repo.
Most Moodle learners have no portal account yet, so their Live Ops rows carry no
lab mapping; that resolves as cohorts register through the portal.
GET https://training.digitalrcc.com/api/v1/pods/<NN>/progress
Authorization: Bearer <token>
| Behaviour | Result |
|---|---|
| Valid token, existing pod | 200 with the normalized payload |
| Missing/incorrect token | 401 |
| Unknown pod (e.g. 99) | 404 |
| Any method other than GET | 405 |
| Tracker/verifier unreadable | 200 with status: "unavailable" — never a false 0% |
Payload (trimmed):
{
"podName": "Pod01",
"studentNumber": "01",
"checkedAt": "2026-08-19T10:56:11Z",
"overallPercentage": 25,
"completedModules": 1,
"totalModules": 6,
"currentModule": "IA",
"status": "in_progress",
"modules": [
{"id": "AC", "title": "Access Control", "status": "completed", "percentage": 100},
{"id": "IA", "title": "Identification & Authentication", "status": "in_progress", "percentage": 17}
],
"trackerUrl": "https://training.digitalrcc.com/pod/01"
}
Modules are the six lab families (AC, IA, SI, SC, MP, PE). Valid statuses are
not_started, in_progress, completed, unavailable; percentages are
integers 0–100. The route is GET-only, scoped by the pod in the path, and returns
no student email, credentials, or other pods' data.
Deployed on the tracker host crc-ai-ide-01 (192.168.1.61, reachable as
pve1 → devin-adm@192.168.1.61) — the public hostname terminates on the nginx
edge at 192.168.1.55, but the app itself runs on .61. Source:
ebarlowjr2/tcecure_cyberlab, docs/pod-progress-api.md.
| Side | Variable | Purpose |
|---|---|---|
| Tracker host | POD_PROGRESS_API_TOKEN |
Accepted bearer token |
Vercel (drcc-web) |
TRAINING_TRACKER_BASE_URL |
Tracker origin (https://training.digitalrcc.com) |
Vercel (drcc-web) |
TRAINING_TRACKER_API_TOKEN |
Same token, stored sensitive |
Vercel (drcc-web) |
MOODLE_BASE_URL |
https://lms.digitalrcc.com |
Vercel (drcc-web) |
EMAIL_DELIVERY_MODE |
live — student mail over the Workspace relay (Email Delivery) |
Vercel (drcc-web) |
CRON_SECRET |
Protects the capture/sync/mail-worker cron routes |
Rotate the tracker token on the tracker host first, then the Vercel value. The
portal fetches server-side only, so no token reaches a browser — which also
means no CORS or CSP change is required (an iframe embed would need
frame-src).
Collectors depend on exact route paths. systemd timers and cron on the AWX
host and the gateway post to the/admin/community-impact,/admin/community-impact/live
and/admin/progressingest/capture API routes. If those routes are renamed,
the collectors 404 silently and Live Ops and snapshot capture stop with no
on-screen error.
A missing token, HTTP error, timeout (8 s) or malformed payload renders an
explicit "unavailable" state. Validation rejects a payload whose studentNumber
does not match the requested pod, whose status is outside the four allowed
values, or whose percentages are not integers 0–100. Portal mapping comes from
student_cohort_assignments.pod_name.
The staff support console lives on the same application, but is served from
https://labops.digitalrcc.com on drcc-labops-01 (192.168.1.65) rather than
Vercel:
| Route | Purpose |
|---|---|
/labops |
Support requests, investigation history, audit |
/admin/labops/approvals |
Held agent actions awaiting Allow/Refuse |
/admin/labops/chat |
Direct Chat — ask the assistant a question with no support ticket |
Owner-only for this release and enforced server-side on every route; every write
capability (AWX, GitHub, Wiki.js, support notes) is switched off. Full detail on
DigitalRCC LabOps AI.
| Page | Purpose |
|---|---|
| Email Delivery | Sending domain, relay and the five templates |
| DigitalRCC LabOps AI | Support-triage assistant and Direct Chat |
| Training Tracker | Tracker dashboard and AWX data flow |
| Lab Health Monitoring | Proxmox health feed |
| Current Cohort Lab Notices | Source of the public known-issues list |