Dedicated Node Boundaries

Reliability starts with clear physical boundaries and a defined response process—not vague promises.

OnceMac assigns a dedicated physical Mac mini node to every order. Its compute, memory, and local storage are not shared with other customers, with a 99.9% availability target.

NODE ASSIGNMENT Dedicated Node Assembly Record
Monitoring Active
A dedicated physical Mac node on the bench
Order Relationship
1 order = 1 physical node
Resource Boundary
Dedicated compute, memory, and local storage
Operating Scope
6 nodes running year-round
Availability Target
99.9%
Resource Isolation

One order corresponds to one dedicated device.

Dedicated means physical resources are not shared with other customers—it does not mean a set of virtual quotas carved from a shared host.

Dedicated Physical Node Allocation

After order confirmation, the console records the configuration, node, and term, then assigns the corresponding Mac mini to the order. The same device is not assigned to another customer during the term.

Explainable Performance Boundaries

The CPU, unified memory, and base SSD belong to the physical node. Build queues are not contending with sudden load from other tenants, making the setup better suited to fixed toolchains and continuous tasks.

Administrator Access Still Has Boundaries

Customers can configure the full macOS graphical and command-line environments, while remaining responsible for system accounts, SSH keys, software licenses, signing materials, and business data.

Service Target & Observation Window

99.9% is a verifiable service target.

Status records are aggregated by calendar day. Event determinations are based on platform monitoring, connection records, and ticket evidence; customer configuration errors are not counted against platform availability.

99.9% Service Availability Target

What We Monitor

We monitor physical node health, management-link reachability, and critical platform services. Customer-initiated shutdowns, local network issues, incorrect firewall rules, and customer workloads that cause unavailability are not classified as platform incidents.

Most Recent 90 Calendar Days Daily Status Records
Operational
If the Target Is Missed Review service credits under the applicable terms

If the issue is confirmed to be OnceMac's responsibility and the applicable order commitment is not met, OnceMac will provide service credits according to the terms, calculation scope, and request process in the service terms.

Review Applicable Rules
Access Control

Lock down entry points first, then give automation only the access it needs.

Key-based access, least privilege, and revocable access must work together. Doing only one still leaves the risk of long-lived credentials or shared accounts.

Recommended Permission Baseline

  • Use Dedicated SSH KeysGenerate separate keys for each person or runner. Do not share one private key across the team or store private keys in a code repository.
  • Use Least Privilege for Daily TasksEscalate privileges only to install tools, modify system services, or adjust network rules. Run build tasks under a dedicated account.
  • Protect Console Accounts SeparatelyNever reuse console credentials as node system passwords. After a team change, review both console access and accounts on the node.
  • Rotate Credentials After EventsWhen someone leaves, a device is lost, a key may be exposed, or an automation runner is retired, revoke the old credentials immediately and issue new ones.
  • Customers Manage Signing MaterialsCode-signing certificates, private keys, and related passwords should follow an approved team secrets-management process and should not remain in plaintext in node directories.
JOIN

Team Member Joins

Create a personal account and dedicated key. Grant only the directory, repository, and build permissions required for the current role, and record who authorized them.

LEAVE

Team Member Leaves

Revoke system accounts, SSH public keys, repository tokens, and automation keys; review running tasks; and replace any credentials that were shared.

Network & Connectivity Boundaries

The platform keeps the entry point reachable; you decide who can enter.

The management entry point, remote connections, and business traffic belong to different responsibility layers. When something goes wrong, identifying the layer first can significantly shorten troubleshooting.

Responsibilities for Console Access, Remote Connections, and Business Traffic
Scope OnceMac Responsible Customer Responsible Recommended Checks
Console Management Access Account entry, order records, node status, and support ticket channel Account credential protection, member authorization, and suspicious-login review Login records, member list, and recent actions
SSH & Graphical Connections Core network reachability and node-side connection conditions Key permissions, system accounts, firewall, and source restrictions Local network, ports, key permissions, and source address
Build & Business Traffic Physical node core network and upstream-link observation Proxies, dependency sources, repository access, application listeners, and traffic policies DNS, routing, proxy configuration, and target-service response
Suspicious Access Investigation Use platform records to confirm node and management-side anomalies Review system logs, authorized keys, processes, and task changes Source, time range, account, command, and redacted logs

Shortest Troubleshooting Sequence

Verify the local network first, then check node status in the console, inspect SSH key permissions and the system firewall, and finally submit a ticket with the time range and redacted output.

Troubleshoot Connectivity
Data & Media Handling

Review delivery, use, offboarding, and reassignment as separate stages.

Follow the node lifecycle. If your project requires specific certifications, audit reports, or contractual media standards, confirm the applicable scope through the support email before ordering.

  1. 01

    Before Delivery

    Verify the device and order configuration, prepare the base system and connection requirements, and record the node assignment in the order. Customers receive a dedicated physical node, not a shared resource quota.

  2. 02

    During the Term

    Customers are responsible for work directories, repository credentials, build caches, signing materials, and business data. Store sensitive information encrypted and avoid writing it to long-lived scripts, logs, or shell history.

  3. 03

    Before Offboarding

    Export essential artifacts and logs first, verify that business backups can be restored, then revoke repository tokens, SSH public keys, and automation credentials. Do not treat the node's local disk as the only copy.

  4. 04

    Before Reassignment

    The node is assigned to a subsequent order only after it enters the re-preparation process. If specific handling requirements exceed the standard service scope, agree on them in writing before order confirmation; do not substitute an unconfirmed certification name for the actual process.

Monitoring & Incident Response

Confirm the impact first, then isolate, recover, and review.

Monitoring focuses on the health of core services and does not read customer code. When customer data is needed for troubleshooting, collect only the information necessary to resolve the issue, with sensitive details redacted.

HEALTH

Node Health

Check whether the node is online, whether critical management capabilities respond, and whether hardware status requires further review.

REACH

Network Reachability

Check the management link, node core network, and upstream connections to distinguish platform-network issues from problems with the customer's target service.

CAPACITY

Core Capacity

Watch essential capacity signals for the node and platform services. Customers must set their own thresholds for work directories and build caches.

CHANGE

Operational Changes

Record changes affecting node delivery, management access, or network paths so they can be correlated with the timeline if an incident occurs.

Incident Response Workflow

Every step has a defined output, avoiding repeated changes to the customer environment before the cause is confirmed.

  1. 01

    Confirm

    Check the node, order, start time, affected entry point, and reproducible conditions to determine whether the issue affects one node, one link, or the platform.

  2. 02

    Isolate

    Limit further spread of the impact, preserve necessary evidence, and avoid unconfirmed actions that could overwrite original logs.

  3. 03

    Recover

    Restore the available path first, then verify connectivity, builds, and critical tasks. Explain the scope before changing customer configuration.

  4. 04

    Review

    Organize the timeline, cause, impact, and follow-up actions. When customer cooperation is needed, provide actionable configuration or backup guidance.

Service Continuity & Transparency

Nodes run year-round, with updates based on impact.

OnceMac's six nodes operate continuously 365 days a year. Unexpected incidents prioritize service recovery and impact reduction.

When an Incident Has an Impact, Updates Should Answer Four Questions

What Is Affected
State the affected nodes, management entry points, or connection scope instead of using a vague “service incident” label.
When Did It Start
Provide the confirmed time range. If the cause is not yet confirmed, clearly separate facts, hypotheses, and items still under investigation.
What Is Happening Now
Explain whether the team is confirming, isolating, or recovering, and whether customers should pause tasks, preserve logs, or use another connection path.
When Is the Next Update
Continue updating when new facts emerge or the response stage changes; after recovery, add verification results and any necessary follow-up recommendations.

Your Business Still Needs Recovery Capability

A reliability target does not replace business backups. Keep at least these four types of copies outside the node:

  • Repository and branch-protection records
  • Build artifacts and release reports
  • Environment inventory, Brewfile, and initialization scripts
  • Encrypted backups of necessary credentials and rotation records

If an incident affects an existing order, submit a ticket in the console with the order number, node, time range, reproduction steps, and redacted logs.

Submit a Console Ticket

Need to confirm contractual security requirements?

Send your configuration, nodes, data types, audit requirements, and desired activation date to support@oncemac.com. The team will respond based on the actual service scope; do not use an unconfirmed certification name in place of technical requirements.

Organize Contact Information

Dedicated physical nodes, with clear boundaries before you begin.

Choose the right Mac mini from three available configurations and select your connection location across six nodes. All orders are billed in USD.