Skip to main content

Deslicer Enterprise Documentation

Version: 1.16 Last Updated: August 2026 Audience: Customer platform operators, infrastructure engineers, security teams

Install and operate Deslicer AI and the Deslicer Automation Platform (DAP) in your environment using the Deslicer-provided provisioning package and curl installers.

Reading order​

ChapterFileDescription
1IntroductionTerminology and document scope
2ArchitectureSplit topology, ports, Deslicer Caddy edge
3PrerequisitesCustomer checklist, OS, DNS FQDNs, outbound allowlists
4Provisioning packageEncrypted handoff package and install state
5Install Deslicer AIInstall, Control Updates, uninstall
6TLS certificatesDeslicer Caddy for DAI and DAP; ACME or customer PEM
7Install DAPEnroll, install, Control Updates, uninstall
8Post-install configurationSMTP, models, Registry, rename System tenant
9Network and firewallRegistry, OS package, and ACME allowlists
10TroubleshootingCommon failures
11AppendixCommand cheatsheet and glossary
12Enterprise roles and accessRole presets, scope, Enterprise workspace
13AI providers and modelsProvider connections, catalog, Bedrock, custom gateway

Quick start​

  1. Collect customer-provided values (tenant name, initial super user email, DAI and DAP FQDNs).
  2. On the DAI host, run Control Host prep (creates /opt/deslicer/etc/age/keys.txt as deslicer) and share the printed age1… public key with Deslicer (or receive provision.enc.yml).
  3. Stage the package (sudo install -o deslicer -g deslicer -m 600 ./provision.enc.yml /opt/deslicer/etc/dai/provision.enc.yml) and install with bash /opt/deslicer/bin/deslicer-dai-install.sh.
  4. Sign in at https://<dai-host>/control (<dai-host> = DAI FQDN) and complete SMTP / model settings as needed.
  5. Enroll DAP from Control, then run the generated commands on the DAP host (--dai-url still uses the DAI FQDN; Observer hostname is the DAP FQDN).
  6. Manage Web certificates for DAI and DAP in Control (ACME or PEM).
  7. In the app, open Enterprise and rename the default System tenant (and organization if needed).

After install​

TaskWhere
Rename System tenant / orgChapter 8 §8.3
Roles, presets, and scopeChapter 12
Image and package updatesChapter 5 §5.7 (Deslicer AI) · Chapter 7 §7.3 and §7.5 (DAP)
Uninstall (DAP first, then DAI)Chapter 7 §7.10 · Chapter 5 §5.8
Command cheatsheetChapter 11

Document revision history​

VersionDateChanges
1.17August 2026Extra Caddy listeners (not “listens”); Nexus --update rehydrates extras from host sidecar / live Caddyfile; load balancer host IP must be extra listeners + PEM SAN; Web certificates apply stays --proxy-only
1.16August 2026Chapter 13 AI providers and models (stub); §8.5 Bedrock canonical path, upstream prefixes, commercial vs GovCloud model access, custom gateway /v1; §10.18 listed/synced model chat failures; §10.20 enterprise support scripts
1.15August 2026Chapter 7 enroll-time TLS policy step (Untrusted TLS switches, per-host certificate upload, re-copy the run line); §8.5 corrected to the Enterprise workspace AI providers & models page; §6.8 table limited to the two real switches, CA trust moved to the Web certificates path
1.14August 2026DAP installer --peer-tls-insecure; DAP unsecure remints Fresh/repair (token + flag); --update stays Nexus-only
1.13August 2026CIS / STIG-hardened servers supported; deslicer:deslicer service account; Host prep + /opt/deslicer/etc; inode-replace Download; installers fail closed (no $HOME/.config/age)
1.12August 2026Caddyfile day-0 stock replace; host-scoped PEMs; DAP unsecure remints install commands with DESLICER_PEER_TLS_INSECURE
1.11August 2026Caddyfile write-once (day-0); Control/proxy-only PEM refresh; IP+FQDN duplicate site block; peer TLS §6.8; provision.enc.yml apply examples
1.10August 2026Architecture data-flow diagrams; customer checklist; OS package allowlists; hostname/host clarity; Mermaid fullscreen; Caddy IP-vs-FQDN FAQ
1.9August 2026Interactive Drizzle schema prompts: always choose create table unless Support says otherwise
1.8August 2026Manual PEM layout and Caddyfile tls steps for customer certificates
1.7August 2026Enterprise roles, presets, and role-scope chapter; rename default System tenant/org after install
1.6August 2026Customer-facing language pass: prerequisites and install happy paths; updates wording (no day-2); Control-aligned DAP install package terms
1.5August 2026Enterprise and preview floating tracks; installer --channel; Control Updates; documented uninstall scripts
1.4August 2026Control Apply for DAP install package (online Apply, air-gap Import, Roll back)
1.3August 2026Troubleshoot local login 403 Forbidden after hostname or certificate-only updates
1.2August 2026DAP Control Update/Fresh token modes, DNS before ACME, installer --version, Retry probe
1.1August 2026Installer reads provision.yml / provision.enc.yml; age-encrypted install-state
1.0July 2026Initial enterprise install guide

← Product Documentation