# Validation record — 2026-10-04 This is an adapted setup bundle. It has not been deployed on the recipient's server or domain. ## Passed - Read the source deployment's image metadata without changing the VPS. All seven digest pins in `compose.yml` match those recorded in `images.json`. - Ran `configure.py` against disposable settings in a private copy, producing fresh secrets and all five configuration files. - Parsed the generated YAML and JSON and verified that no template markers remained. PostgreSQL/Synapse, Coturn/Synapse and LiveKit/JWT secrets matched. - Verified `.env` mode `0600` and generated-directory mode `0700`. - Re-ran the initializer and confirmed that it refused to overwrite the installation; existing file contents remained unchanged. - Docker Compose v5.5.1 validated the complete seven-service model, variable interpolation, dependencies, image pins, network names, source paths and the TCP 7881 / UDP 7882 mapping. - Ran the documented signing-key generation command in a temporary local container using the pinned Synapse v1.159.0 image. The new signing key was written to the disposable data directory. - Loaded the generated config through that image's `HomeServerConfig` parser. Parsing succeeded; the MatrixRTC feature flags and transport URL were present in the effective Synapse configuration. - Checked the shareable files for the original credentials, server domain/IPs, VPS-specific paths and generated test secrets. None are included. - Verified that the documented archive file list excludes generated config, `.env`, `settings.env`, data and backups. Local container checks used Docker Engine 29.8.1 on Linux/aarch64 through Docker Desktop. The source deployment uses Linux/amd64; the full seven-image stack and Coturn host networking have not been validated on other architectures. ## Required on the new server - DNS, provider/host firewall rules, certificate issuance and IPv4 reachability. - First PostgreSQL initialization, complete service startup and resource sizing. - Account creation, login, messaging, uploads and federation. - MatrixRTC token issuance and client discovery, external encrypted audio/video calls, selected UDP candidate, TCP fallback and TURN allocation where used. - A backup restore in isolation, preserving the signing key and server name. The original deployment had working external calls; its corrected UDP 7882 path was also checked with two external synthetic LiveKit clients exchanging audio. That is source-deployment evidence, not a substitute for the new-server checks.