Windows School Server Qualification
Most school hosts will be Windows laptops or PCs. A machine is not suitable for the School Server role merely because Docker starts on it. Qualify the host before installation.
The production Windows installer in mn-school-be/deploy/school-bundle now runs a hardware qualification gate before the normal software preflight. A rejected machine must be remediated or replaced; do not deploy and hope performance will be acceptable later.
A School Server laptop must be treated as an appliance, not as a bursar, administrator, or teacher workstation. Do not use the same machine for normal Office, browser-heavy, meeting, or personal workloads while it hosts the school ERP.
Qualification profiles
| Requirement | Minimum supported | Production recommended |
|---|---|---|
| CPU | 4 physical cores | 6+ physical cores |
| RAM | 16 GB | 32 GB |
| System storage | 512 GB-class SSD/NVMe | 1 TB-class SSD/NVMe |
| Free space before install | 200 GiB | 350+ GiB |
| OS | 64-bit Windows | 64-bit Windows |
| Virtualization | Enabled | Enabled |
| Network | LAN available | Wired Ethernet |
| Power | Stable AC power | Healthy laptop battery and/or UPS |
| Sleep while plugged in | Must not interrupt operation | Disabled |
The production recommendation is the normal target for a school server. The minimum profile is a support floor, not a promise that every school workload will perform well at every concurrency level.
Hard rejection conditions
The qualification script exits non-zero and blocks first-time installation when it detects a production blocker such as:
- fewer than 4 physical CPU cores;
- less than 16 GB installed RAM;
- an HDD as the Windows system disk;
- a system volume smaller than a 512 GB-class drive;
- less than 200 GiB free space;
- non-64-bit Windows;
- hardware virtualization disabled in firmware;
- port 80 or 443 already occupied.
If the script cannot prove a non-critical condition, it reports a warning instead of inventing a pass. For example, unknown storage media should be manually verified as SSD/NVMe before commissioning.
Run the hardware qualification
From the extracted backend-owned school-bundle on the candidate Windows host:
powershell -ExecutionPolicy Bypass -File .\qualify-school-server.ps1
A passing machine receives an overall result of PASS or WARN. A machine with blocking failures receives REJECTED and the script exits with code 1.
The script records the result at:
runtime\server-qualification.json
Retain that report with the school commissioning/support record. It captures the observed CPU, RAM, storage capacity/free space, fast-storage confirmation, profile, thresholds, and individual checks.
Warnings that require operator judgement
The qualification report also checks conditions that may not be safe to hard-fail automatically on every Windows model:
- no active wired Ethernet adapter;
- laptop battery missing, weak, or poorly charged;
- plugged-in Windows sleep policy not set to Never;
- storage media could not be positively classified as SSD/NVMe;
- network/port inspection could not be completed automatically.
A warning is not permission to ignore the issue. Close each commissioning warning or record an approved exception.
Docker and WSL runtime preflight
Hardware qualification and software preflight are separate gates.
After hardware qualification, run:
powershell -ExecutionPolicy Bypass -File .\preflight-check.ps1
The Windows preflight verifies the release CLI/runtime requirements and also checks that:
- Docker Engine is running;
- Docker is using Linux containers;
- Docker Compose v2 is available;
- Docker exposes at least 4 CPUs to the Linux runtime;
- Docker exposes at least 8 GiB RAM;
- 12 GiB or more Docker RAM is recommended.
A 32 GB Windows laptop can still perform badly if Docker Desktop/WSL is constrained to too little CPU or memory, so do not stop at the physical hardware result.
First-time Windows installation flow
The expected order is:
You can invoke the installer directly:
powershell -ExecutionPolicy Bypass -File .\install.ps1
install.ps1 runs the qualification gate before the software preflight, so a rejected machine cannot continue through the normal Windows installation path.
Network and power rules for laptop servers
For production use:
- keep the server permanently connected to AC power;
- use wired Ethernet where practical;
- configure a stable LAN address or DHCP reservation;
- set plugged-in sleep to Never;
- ensure closing the lid does not suspend the server if the laptop will operate closed;
- use a healthy laptop battery as short-duration power resilience, and use a UPS where outage risk justifies it;
- keep Windows/Docker startup configured so the School Server recovers after reboot;
- do not let staff routinely shut down, carry away, or repurpose the host.
The laptop form factor is acceptable; uncontrolled workstation behaviour is not.
Do not confuse qualification with commissioning
A hardware-qualified host can still fail production acceptance because of a degraded SSD, thermal throttling, bad LAN configuration, Docker constraints, DNS/TLS trust problems, or application readiness failures.
Qualification means the host is allowed to proceed to installation. Production handover still requires the release verification, trusted HTTPS, bootstrap, authority, health, sync, offline, backup, and failure-certification gates documented in this manual.
Go/no-go checklist
-
qualify-school-server.ps1completed withoutREJECTED. - Qualification JSON was retained for the commissioning record.
- Any warnings have been remediated or explicitly accepted.
- Host has at least 4 physical cores and 16 GB RAM.
- System disk is confirmed SSD/NVMe and has at least 200 GiB free.
- 64-bit Windows and hardware virtualization are enabled.
- Ports 80 and 443 are free before installation.
- Docker Engine runs Linux containers and Compose v2.
- Docker runtime has at least 4 CPUs and 8 GiB RAM available.
- Wired LAN, stable power, and no-sleep policy are ready.
- The machine is dedicated to the Makronexus School Server role.