SIMULATION No cameras, door controllers or dispatch links are connected to this host. Device telemetry, video and alarms are synthetic. Platform services, permissions, audit chain, package install and sandbox are real.

PK-261005-001 · ONVIF Profile S/T — cameras & encoders

v0.1.1 · target OHCHS · built 2026-10-05 12:08:38 EDT by soc-op-01
P1 3 P2 2 Unacked 5 Video 17/19 16:07:33 EDT OPSOC Operator 01
BuiltSandboxApprovedPromoted
bundle sha256 06ee6e51ac060b6d… 12 files mode read_only

Next gate

Gates are operated by District IT. Current role can review the package but not advance it.

README.md

sha256 91b0f1aecaa94afc624e…
1# ONVIF Profile S/T — cameras & encoders
2
3**Build** `PK-261005-001` · **Version** `0.1.1` · **Target site** Oxford Hills Comprehensive High School · **Mode** READ-ONLY
4
5Generated by Integration Bot (tpl-r4) for the MSAD 17 Security Platform.
6After promotion this package is owned and operated by **District IT**. There is no vendor or developer service contract behind it.
7
8## What it does
9- Protocol: SOAP 1.2 / HTTP(S) · WS-UsernameToken (digest) · RTSP/RTP media
10- Capabilities: discover, health, live_uri, events
11- Normalizes vendor events to `msad17.event/1` (the same taxonomy the alarm queue uses)
12
13## Endpoints called (egress is limited to these)
14| Method | Path | Purpose |
15|---|---|---|
16| `POST` | `/onvif/device_service` | GetDeviceInformation · GetSystemDateAndTime (model, firmware, NTP drift) |
17| `POST` | `/onvif/media_service` | GetProfiles · GetStreamUri (RTSP per profile) |
18| `POST` | `/onvif/event_service` | CreatePullPointSubscription · PullMessages (long-poll) |
19
20## Event mapping
21| Vendor key | Platform type | Priority | Meaning |
22|---|---|---|---|
23| `tns1:VideoSource/SignalLoss` | `video.loss` | P2 | Video loss |
24| `tns1:VideoSource/GlobalSceneChange/ImagingService` | `video.tamper` | P2 | Camera tamper / scene change |
25| `tns1:RuleEngine/CellMotionDetector/Motion` | `video.motion` | INFO | Motion (after hours zone) |
26| `tns1:Device/Trigger/DigitalInput` | `io.duress` | P1 | Duress / panic input |
27
28Unmapped vendor events are **counted and reported** on the Health page — never silently dropped. Add a row to `mapping/event-map.json`, rebuild, re-run sandbox.
29
30## Secrets
31This package contains **no credentials**. Configure these references in the platform secret store:
32- `${secret:msad17/ohchs/video/username}`
33- `${secret:msad17/ohchs/video/password}`
34
35## Install / verify (District IT)
361. Integration Bot → this build → **Run sandbox** (no network; fixtures only). Expect 5 mapped / 1 unmapped.
372. Optional offline check on any PHP 8.2+ box: `php tests/SandboxTest.php` → `SANDBOX PASS`.
383. Verify integrity: `sha256sum -c SHA256SUMS`.
394. **Approve** (reviewer 1) → **Promote** (reviewer 2, must differ). Promotion registers the connector read-only.
405. On the VPS runtime, point `config.base_url` at a **lab device first**, confirm events on the alarm queue, then widen `device_map`.
41
42## Rollback
43Demote this build in Integration Bot. The previously promoted build for this stack re-activates. Nothing on the device is changed by install or rollback.
44
45## Licensing / compliance
46None. Conformance varies by firmware — validate per model.
47
48## Notes
49Hardware-agnostic baseline for existing cameras (incl. COPS-funded). DigitalInput is mapped to duress only for inputs listed in config.duress_inputs.