Primero “Tier 1” DIY Deployment
Resources Allocation and Work Plan
Introduction
Primero is a digital public good designed for social impact. Primero's application code is open source and is freely available to use. However, as with any software, there are costs associated with hosting, development, deployment, operations and maintenance. We are committed to managing Primero sustainably and securely. This is our obligation to our stakeholders and data subjects. We also want to make this transformative tool available to as many organizations and partners as possible. To do this, we’ve designed a sustainable business model that allows us to be cost effective, predictable and scalable. You can read more here. When you are looking to set up Primero, there are programmatic considerations that must be taken into account including coordination with partners and data security and information sharing processes. Please consult with the in-country coordination body when looking to set up a system for case management.
For those who have opted for using the “Tier 1” DIY Open Source Digital Public Good model, this provides you with access to the open-source repo to set up your own Primero instance. You have unlimited access to the Primero Community and all documentation. To implement Primero successfully, partners must have the required technical capabilities. This includes, but is not limited to, teams capable of setting up servers, security, DNS, configuration, maintaining updates and providing support. Partners must be able to run Ansible scripts available on GitHub to receive new releases and updates. Partners should also have the capacity to monitor and manage updates and keep their stack and infrastructure updated. Tier 1 allows partners to utilize the baseline configurations of CPIMS+ but must manage their own configuration and localization. As this option is fully managed and maintained by the partner, costs for their own human resources and IT costs such as fees for hosting, SSL/TLS, and DNS (costs vary by service) must be covered by the partner.
The open source model for Primero is an implementation model we call “Tier 1”. This model has 2 sites, one “demo” and one “production”. We use the demo CPIMS+ to manage configurations (forms, roles, reports), to receive updates and security patches, and to test and train. Demo has no real data on it. For the production site, the selected data center is managed by a capable technical team who can support the infrastructure set up and maintenance. All the real data is stored on this server. This implies a higher level of accountability and management for the in-country team.
Roles and Responsibilities
In this model, it should be clear that the Primero Team is not responsible for managing or supporting any of the following and partners are responsible for:
- All infrastructure including setting up servers, hosting, setting up monitoring and security measures, security certificates, data durability/data storage, backups, DNS, and configuration of the demo and production instance
- Owning, protecting and securing the data
- Disaster recovery protocols and data breach protocols
- Installation of the latest supported version to local infrastructure
- Configuration promotion from in-country-hosted demo to locally hosted production including updates and possibly performing occasional manual data migration
- Clear process in place for configuration promotion from “demo” to “production” to receive the most up-to-date releases (which include updates and security patches)
- Primero v2 is a progressive web application (PWA) and we have an identity provider that helps us securely authenticate and manage users which your team would need to implement. If a mobile device management solution is requested for mobile devices, this must be procured and maintained.
- Checking for service availability; Docker is up and running and containers are up
The set-up of local infrastructure demands ongoing technical support and budgets. Therefore, you must select a technical partner which has demonstrated a very good capacity, strong technical infrastructure skills and understanding of the work for the project sustainability.
Summary of Skills Required for Tier 1
Below is a summary of the key skills required to provide ongoing technical support for Tier 1. You must have a team or select a technical partner which has demonstrated a very good capacity, strong technical infrastructure skills and understanding of the work for the project sustainability.
DevOps
Docker Proficiency
- Containerization Knowledge: Deploying applications using Docker containers for isolation and scalability.
- Lifecycle Management: Handling container deployment, restarting services, and monitoring performance.
- Debugging and Troubleshooting: Identifying and resolving issues within the containerized environment.
- Optimizing Resource Utilization: Managing resource allocation to ensure efficient CPU and memory usage.
SQL Server Management
- Installation and Configuration: Setting up SQL servers and configuring them for optimal performance.
- Database Administration: Performing backups, restorations, and data migrations.
- Security Management: Implementing access controls and encryption to safeguard sensitive data.
- Performance Tuning: Optimizing query performance and indexing strategies.
Ubuntu System Administration
- User and Permission Management: Creating and managing system users, groups, and roles.
- System Security: Configuring firewalls, managing SSH keys, and setting up intrusion detection.
- Monitoring and Logging: Implementing tools for real-time system monitoring and log analysis.
- Automating Tasks: Using shell scripting and cron jobs for routine maintenance and updates.
Server Networking and Integration
- Multi-Server communication: Establishing communication between multiple servers for load balancing and fault tolerance.
- Network Configuration: Setting up virtual networks, subnets, and routing.
- Cloud Integration: Deploying services on cloud platforms and managing hybrid environments.
- Scalability and Redundancy: Implementing failover mechanisms and high-availability solutions.
- Backup: Implementing backup strategy to ensure disaster recovery
You can read more about devops in the following resources:
https://learn.microsoft.com/en-us/training/career-paths/devops-engineer?
Networking
Network Restrictions and Access Control
- Implementing firewall rules and access control lists (ACLs) to manage traffic flow.
- Enforcing IP-based restrictions and geofencing to protect sensitive resources.
- Configuring VLANs and subnets for network segmentation and isolation.
Port Management and Security Rules
- Opening and closing ports as per the application’s requirements.
- Monitoring and controlling inbound and outbound traffic to prevent unauthorized access.
- Implementing rate limiting and traffic filtering for DDoS protection.
SSL Certificate Management
- Generating and installing SSL certificates for secure communications.
- Managing certificate renewal and revocation to maintain compliance.
- Ensuring proper encryption protocols for data-in-transit protection.
IP Whitelisting and Blacklisting
- Whitelisting trusted IP addresses for secure access to critical services.
- Blocking suspicious or malicious IP addresses to mitigate potential threats.
- Configuring dynamic IP filtering for adaptive security measures.
VPN Configuration and Management
- Setting up secure VPN tunnels for remote access and data privacy.
- Managing VPN user authentication and access control policies.
- Monitoring VPN usage and performance for seamless connectivity.
You can read more about networking in the following resources:
https://www.simplilearn.com/tutorials/networking-tutorial
Rails, React , Git and CI/CD pipeline
System Debugging and Issue Resolution
- Error Identification and Analysis: Quickly pinpoint root causes of system errors and performance bottlenecks using logging and monitoring tools.
- Effective Troubleshooting: Resolve issues related to server performance, application crashes, and configuration errors without impacting the live environment.
- Proactive Monitoring: Use tools like New Relic, Grafana, or Splunk to monitor system health and performance in real-time.
- Documentation and Reporting: Maintain comprehensive logs and error reports for future reference and compliance audits.
Version Control Management (Git Expertise)
- Repository Management: Understand how to fork repositories for independent feature development and experimentation.
- Branch Management: Create, manage, and merge branches efficiently, following Git best practices (e.g., Git Flow or GitHub Flow).
- Conflict Resolution: Handle merge conflicts and rebase branches to keep codebase clean and conflict-free.
- Commit History Management: Use meaningful commit messages, squash commits when necessary, and maintain a clean commit history for better collaboration.
Seamless System Updates and Deployment
- Pulling and Merging Updates: Retrieve the latest updates from the main repository and merge them with minimal disruption to the application.
- Staging and Testing: Implement a staging environment to test updates before deployment, ensuring compatibility and stability.
- CI/CD Integration: Leverage Continuous Integration/Continuous Deployment pipelines (e.g., Jenkins, GitLab CI, or GitHub Actions) for automated testing and deployment.
- Rollback Mechanism: Establish a robust rollback strategy to revert to previous versions in case of deployment failures.
You can read more about Rails, React , Git and CI/CD pipelines in the following resources:
Rails - https://guides.rubyonrails.org/
React - https://react.dev/learn
GIT - https://www.w3schools.com/git/
CI/CD - https://github.blog/developer-skills/github/a-beginners-guide-to-ci-cd-and-automation-on-github/
Single Sign On
Understanding the Identity Provider (IdP)
- Familiarity with Protocols: Master protocols like SAML (Security Assertion Markup Language), OAuth 2.0, and OpenID Connect (OIDC).
- Access Management: Gain administrative access to configure authentication flows and manage user roles and permissions.
- Audit and Logging: Track authentication events and monitor suspicious login activities for security compliance.
You can read more about SSO in the following resources:
https://www.onelogin.com/learn/how-single-sign-on-works
If the above skills and resources are not available, refer to the other business model options for your deployment or reach out to the Primero Team for additional guidance.
Total Cost of Ownership
This resource plan outlines the capacity requirements, budget estimates, and sustainability considerations for implementing Primero Tier 1 (DIY/Open Source). Tier 1 provides complete control and zero licensing fees, but requires full technical self-sufficiency. This analysis separates costs based on whether you have existing capacity/infrastructure versus the need to build from scratch.
Tier 1 means you are fully independent - no UNICEF/Primero support beyond documentation and community forums. Your team must handle everything: setup, security, configuration, updates, operations, and maintenance.
SCENARIO 1: BUILD NEW TEAM + NEW INFRASTRUCTURE
Assumption
- No existing HR capacity → Hire 100% (1.7 FTE)
- No existing infrastructure → Procure 100%
- Starting completely from scratch
ONE-TIME INVESTMENT COSTS
Sample Estimated Costs (Southeast Asia Market Rates)
Item | Description | Cost (USD) | Notes |
Training (ELIMINATED) | Self-learning via Primero resources | $0 | |
Infrastructure Setup | |||
Production and Demo Server Setup | VM/cloud provisioning | $7,000 | Production and Demo |
Network & Security Config | Firewall, VPN, bastion | $1,500 | Security infrastructure |
SSL/TLS Certificates | 3-year (2 servers) | $800 | Both environments |
DNS Registration | Domain (3 years) | $150 | Production domain |
Backup Infrastructure | Production only | $1,500 | Production backup |
Security Audit (Reduced) | Infrastructure review | $1,500 | Reduced scope, focusing on infrastructure configuration review, not full penetration testing. Primero application has been extensively tested. Find the details here |
Software & Tools | |||
Monitoring Tools Setup | Initial configuration | $500 | Setup only |
Documentation | System documentation | $800 | Runbooks, procedures |
Contingency (10%) | $1,175 | ||
TOTAL ONE-TIME | $13,925 |
ANNUAL RECURRING COSTS
- Human Resources: Sample Estimated Costs (Cambodia Market Rates)
Role | FTE | Monthly (USD) | Annual (USD) | Justification |
DevOps/Infrastructure Engineer | 0.6 FTE | $1,440 | $17,280 | Operations, updates |
System Administrator | 0.3 FTE | $450 | $5,400 | Infrastructure monitoring |
Database Administrator | 0.2 FTE | $360 | $4,320 | PostgreSQL (2 DBs) |
Primero Admin | 0.6 FTE | $900 | $10,800 | Config + support combined |
TOTAL HR | 1.7 FTE | $3,150 | $37,800 |
FTE: Full-time equivalent
- Infrastructure Costs
New Cloud Infrastructure - Azure Southeast Asia
Item | Monthly (USD) | Annual (USD) | Notes |
Production Cloud Hosting | $150 | $1,800 | 8GB RAM, 2 CPU, 500GB |
Demo Cloud Hosting | $100 | $1,200 | Smaller |
Managed PostgreSQL - Production | $100 | $1,200 | Recommended |
Managed PostgreSQL - Demo | $60 | $720 | Smaller |
Backup - Production Only | $50 | $600 | Production critical |
Backup - Demo Config | $10 | $120 | Config only |
SSL/TLS Annual Renewal | $22 | $267 | Both certificates |
SMTP Service | $25 | $300 | Email notifications |
Monitoring Tools | $40 | $480 | Both environments |
CDN/Data Transfer | $40 | $480 | Bandwidth costs |
TOTAL INFRASTRUCTURE | $597 | $7,167 |
- Support & Maintenance
Item | Monthly (USD) | Annual (USD) | Notes |
External Support (ELIMINATED) | $0 | $0 | Assumption: not required or can be covered by contingency |
Security Audit | $83 | $1,000 | Primero receives ongoing security updates from UNICEF, find the details here If required for compliance: $1,000/year (reduced scope) |
Ongoing Training (ELIMINATED) | $0 | $0 | Assumption: the team is self-sufficient with the Primero resource and community |
Software Licenses/Updates | $50 | $600 | Ubuntu Pro, tools |
TOTAL SUPPORT | $133 | $1,600 |
|
Contingency (10%): $4,657
TOTAL COST OF OWNERSHIP
Category | Year 1 | Annual (Year 2+) | 5-Year Total |
NEW CASH COSTS | $65,149 | $51,224 | $270,045 |
Opportunity Costs | $0 | $0 | $0 |
TRUE TOTAL COST | $65,149 | $51,224 | $270,045 |
SCENARIO 2: PARTIAL RESOURCES AVAILABLE
Assumptions
• 50% HR available (0.85 FTE existing) → Hire 50% (0.85 FTE new)
• 50% infrastructure available → Procure 50%
• Can leverage existing systems and team
SCENARIO 3: 100% EXISTING RESOURCE (CAPACITY + INFRASTRUCTURE)
Assumptions
• 100% HR available (1.7 FTE existing with spare capacity) → No new hiring
• 100% infrastructure available → incremental costs can also be absorbed
• Existing team absorbs Primero workload
TOTAL COST OF OWNERSHIP - COMPLETE TIER COMPARISON
Tier/Scenario | New Investment (5yr) | Opportunity Cost (5yr) | TRUE Total Cost (5yr) |
Tier 1 - Scenario 1 | $270,045 | $0 | $270,045 |
Tier 1 - Scenario 2 | $135,023 | $135,023 | $270,045 |
Tier 1 - Scenario 3 | $0 | $270,045 | $270,045 |
Tier 4 - Scenario 1 | $239,663 | $0 | $239,663 |
Tier 4 - Scenario 2 | $119,832 | $119,832 | $239,663 |
Tier 4 - Scenario 3 | $0 | $239,663 | $239,663 |
Tier 3 – without hiring Primero Admin | $42,250 | $36,000 | $78,250 |
Tier 3 – Hire Primero Admin | $78,250 | $0 | $78,250 |
- Tier 1 TOC 5 Years = $270,045 (Year 1: $13,925 setup + $51,224 HR&Infra, Year 2-5: $51,224 HR&Infra)
- Tier 4 TOC 5 Years = $239,663 (Year 1: $6,963 setup + $34,780 HR&Infra + $25,000 Primero fee), Year 2-5: $34,780 HR&Infra + $8,450 Primero fee)
Tier 1 | Tier 4 | Tier 3 | |
5-Year Cost | $270,045 | $239,663 | $78,250 |
FTE Required | 1.7 | 1.15 | 0.5 |
Production Management | You | You | Primero Team |
Demo Management | You | Primero Team | Primero Team |
Release management | You | Primero Team | Primero Team |
Professional Support | Community only | 4hr/wk, 2hr/mo | 4hr/wk, 2hr/mo |
Configuration Tools | Manual | Automated | Automated |
Training | Self-learning | Included | Included |
Tier 3 (Saas):
Lowest TRUE cost: $78,250 vs $239K-270K for alternatives (3x less)
Minimum FTE: 0.5 vs 1.15-1.7 for alternatives (70% less)
Lowest risk: Primero support included
Predictable budget: Fixed $8,450/year
Focus on mission: Program delivery, not IT infrastructure
Comparing the local hosting options: Tier 4 and Tier 1
Tier 4 needs 32% less FTE (1.15 vs 1.7)
Tier 4 needs less infrastructure (production only)
Tier 4 Net benefit: $30,383 less compared with Tier 1
TIER 1: RISKS & MITIGATION MEASURES
Risk | Impact | Probability | Mitigation |
Staff turnover/knowledge loss | High | High | Cross-training, comprehensive documentation, knowledge transfer protocols |
Infrastructure failure | High | Low-Medium | Regular backups, disaster recovery plan, redundant systems |
Security vulnerabilities | Critical | Medium | Regular patching, security audits, firewall rules, access controls |
Version compatibility issues | Medium | Medium | Test upgrades in staging environment, maintain backup before updates |
Scenario 3 specific |
|
|
|
Resource prioritization conflicts | High | High | Clear SLAs, escalation paths, clear agreements |
Other project dominates resources | High | Medium-High | Guaranteed minimum allocation, regular reviews |
Infrastructure changes impact Primero | Medium | Medium | Change management process, Primero representation in decisions, testing protocols |
Insufficient dedicated focus on Primero | High | Medium-High | Dedicated Primero administrator, separate documentation, quarterly reviews |
Dependency risk if other project ends | High | Low-Medium | Transition plan, gradual independence roadmap, identified dedicated resources |
Technical debt from shared architecture | Medium | Medium | Regular technical reviews, Primero-specific requirements documented, refactoring budget |
KEY SUCCESS FACTORS FOR TIER 1
Technical Success Factors:
1. Strong Linux/DevOps skills - Non-negotiable for Tier 1
2. Ansible proficiency - Must be comfortable running and customizing playbooks
3. Staging environment - ALWAYS test before applying to production
4. Comprehensive backups - Automated, tested monthly, offsite
5. Monitoring and alerting - Know about problems before users report them
6. Security hardening - SSH keys, firewalls, regular audits
7. Version control - All configuration in Git repositories
8. Keep Skills Current - Primero evolves - Ruby on Rails, PostgreSQL, Ubuntu versions,
Organizational Success Factors:
1. Realistic expectations - Tier 1 requires ongoing effort
2. Adequate staffing - Don't understaff based on optimistic estimates
3. Multi-year commitment - Don't start if funding uncertain beyond Year 1
4. Executive support - Leadership understands and supports technical needs
5. Documentation culture - Everything documented
6. Continuous learning - Staff development budget and time allocation
7. Community engagement - Active in Primero community, learn from others, monitor GitHub for issues/updates, contribute back when possible
User Adoption Success Factors:
1. User-centered configuration - Design for actual workflows, not ideal workflows
2. Comprehensive training - Not one-time, but ongoing support
3. Change management - Prepare users for new system, address concerns
4. Feedback loops - Regular user input, continuous improvement
5. Champion network - Super users in each team to support peers
6. Responsive support - Users get help when they need it
WHEN TIER 1 FAILS - WARNING SIGNS
🚩Red Flags That Indicate Problems:
Staff spending >60% time on maintenance vs improvements
Repeated missed updates - falling behind on security patches
Frequent unplanned downtime - users can't access system
Key person left and no one can maintain - tribal knowledge loss
Security incidents or near-misses - unauthorized access attempts
Backup failures - backups not running or not tested
Performance degradation - system slow, users complaining
Staff burnout - team overwhelmed, considering leaving
Configuration errors - frequent mistakes breaking functionality
Update failures - Ansible playbooks not working, system broken
If You See These Signs - Take Action!
Don't suffer in silence - If Tier 1 isn't working, it's better to switch tiers than to risk data loss, security breaches, or program failure.
Getting Started with the Deployment Process (Technical)
If the above skills and resources are available and you are ready to deploy the system you can follow this section outlines the standardized Tier 1 deployment process.
The demo and production environments use an Ansible-based deployment procedure. The process relies on updating the central inventory file within the Primero repository and executing Ansible commands to perform controlled rollouts.
To complete the Tier 1 deployment you will need 3 servers:
- Chef server – A ubuntu server which will contain the Primero repository and passwordless sudo access to both demo and production servers. The primero repo will also include Ansible files and configurations.
- Demo server – A ubuntu server which will host the demo application.
- Production server – A ubuntu server which will host the production application.
As a best practice, all deployments must be performed on the demo environment first, validated thoroughly, and only then applied to production.
1. Deployment Workflow
The deployment workflow consists of four core stages:
1. Backup and preparation
2. Updating deployment configuration
3. Executing Ansible deployment commands
4. Post-deployment validation
Each stage is mandatory and must be completed in sequence.
2. Detailed Deployment Steps
There are two sets of processes for deployment:
- Initial deployment: First step is initial deployment. This is the same process for both the demo and production environments
- Upgrading: This is the process needed when you need to update the the already deployed environment to the latest version
Initial Deployment
Step 1 — Setup chef and target server
Before initiating any deployment you need to set up the chef and the target servers. The target server is either production or demo server.
- Chef Server – This ubuntu server does not require a high configuration setup. A 4-8 gb ram with 50-100 GB storage is enough.
The ubuntu version can be the latest. It should have passwordless and sudo access to demo and production. - Target Server – This is the same for both demo and production. The target server should be of high configuration specially production. It should contain the latest ubuntu version.
Step 2 — Configure ansible inventory file
The inventory file is in the ansible folder inside the Primero repo. Set up all the data needed in the inventory file. You can set up multiple server details in a single inventory file hence you can have the demo and production details in the same inventory file.
---
all:
hosts:
demo-hostname:
ansible_user: 'ubuntu'
primero_host: 'primero.example.com'
primero_tag: 'latest'
production-hostname:
ansible_user: 'ubuntu'
primero_host: 'primero.example.com'
primero_tag: 'latest'
For the production environment you need to set up the secrets and environmental variables too. Secrets need to be saved in secrets.yml inside the same ansible folder.
Step 3 — Run Ansible Deployment Commands
Once the configuration has been reviewed and confirmed, execute the appropriate Ansible command, specifying the target environment.
You need to activate the python venv in order to run ansible using following commands:-
$ cd ansible
$ bin/activate
After that, inside the python environment run following commands:-
ansible-playbook bootstrap.yml -i inventory/inventory.yml -l target-hostname
ansible-playbook application-primero.yml --tags "local-env" -e @secrets.yml -i inventory/inventory.yml -l target-hostname
ansible-playbook application-primero.yml --tags configure,start -i inventory/inventory.yml -l target-hostname
ansible-playbook certbot.yml -i inventory/inventory.yml -l target-hostname
You might encounter some errors when deploying, try to fix those and keep running only that command which returned the error.
Once all the commands have been successfully executed the setup is complete.
You can then run db:seed and other migrations inside the target machine docker.
Upgrading
Step 1 — Perform a Complete Backup
Before initiating any upgrade:
- Ensure you have a working, restorable backup of the environment you are upgrading.
- Do not delete the backup until you have fully confirmed that the upgrade has been completed successfully.
- Perform a new backup every time before starting a deployment.
This step mitigates risk and ensures system recoverability in the event of deployment issues.
Step 2 — Update Inventory Configuration
In the 'inventory.yml' file located within the Ansible folder of the Primero repository:
1. Update the following parameters with the target version:
- primero_tag
- primero_repo_branch
2. When upgrading:
- Update the Demo section for Demo deployments.
- Update the Production section for Production deployments.
These values determine the exact Primero version that will be deployed.
Step 3 — Run Ansible Deployment Commands
Once the configuration has been reviewed and confirmed, execute the appropriate Ansible command, specifying the target environment.
command:
ansible-playbook application-primero.yml --tags configure,start -i inventory/inventory.yml -l target-hostname
If errors occur, review the logs, resolve issues, and re-run until deployment completes successfully.
Step 4 — Validate the Deployment
After successful completion of the Ansible execution:
1. Confirm the system is now running the intended upgrade version.
2. Perform a full functional validation, including existing and new features.
3. Verify critical workflows, user access, and data integrity.
Only after thorough assessment should the deployment be considered complete.
Summary
The Tier 1 Primero deployment process relies on a controlled, repeatable Ansible-based approach. Following the above workflow—backup, configuration update, deployment execution, and validation—ensures safe and consistent upgrades across demo and production environments.

