# Enterprise deployment

Scale a dedicated fleet without silently sharing promised capacity.

Status: Architecture proposal · No enterprise SLA offered yet

## Start with a small verified fleet
Use an independent control service for accounts, inventory, billing and jobs. On the compute side, assign one host to one tenant and run a managed guest when hardware and licensing permit. Keep customer access behind a gateway; only the management service reaches the hypervisor.

## Separate the networks
Plan distinct management, tenant, storage and backup boundaries. Deny customer traffic to the local LAN and other tenants. The pilot's unmanaged switch is not a production tenant-isolation system. Add a managed switch/firewall and a UPS before public multi-customer use.

## Scale out
Enroll a new host, verify serial/specifications, patch and burn it in, test storage/network isolation, then publish capacity. Keep spare hosts outside the sellable pool. A queue should represent demand above capacity; never turn a reservation into an invented running computer.

## Scale down
Stop accepting new rentals on selected hosts, let existing allocations end or arrange an agreed migration, export/retain data under policy, revoke all access, sanitize and verify. Only then power down or retire the host. A dedicated reservation remains billable capacity even if the customer is idle unless the contract explicitly releases it.

## Recovery expectations
A whole-host fleet cannot promise seamless live migration from every failed machine. Recover from a tested image/data backup onto a compatible spare and reconnect the customer. Publish measured recovery objectives only after drills. One NAS, one switch, one ISP or one site creates a shared failure risk.

## Windows licensing
Consumer/OEM Windows activation is not proof that commercial hosted desktops are properly licensed. The appropriate Windows virtualization/hosting and application rights must be established with an authorized licensing specialist before launch.
