Appendix
← Back to Index | Previous: Troubleshooting
11.1 Command cheatsheet
Prefer Control-printed host commands when available. Use installer --version to confirm the script on the host matches the version Control / Deslicer specified for your engagement.
Hostname placeholders: replace <dai-host> with the DAI FQDN and run DAI commands on the DAI host. Replace <dap-host> (when shown) with the DAP FQDN and run DAP enroll/install on the DAP host. Leave Deslicer registry hostnames (artifact-registry.deslicer.io, …) unchanged.
Use Control’s printed URL for install/linux/{enterprise|preview}/. Examples below use enterprise.
Deslicer AI — install and update
# Host prep (once, sudo) — then re-login or: newgrp deslicer
sudo groupadd -f deslicer
id deslicer >/dev/null 2>&1 || sudo useradd --system --gid deslicer \
--home-dir /opt/deslicer --create-home --shell /usr/sbin/nologin deslicer
sudo usermod -aG deslicer "$(id -un)"
sudo mkdir -p /opt/deslicer/bin /opt/deslicer/var/logs/ai \
/opt/deslicer/var/logs/ansible /opt/deslicer/var/logs/dai \
/opt/deslicer/var/lib/dai-install /opt/deslicer/dai-install \
/opt/deslicer/etc/age /opt/deslicer/etc/dai
sudo chown deslicer:deslicer /opt/deslicer /opt/deslicer/bin \
/opt/deslicer/var /opt/deslicer/var/logs /opt/deslicer/var/logs/ai \
/opt/deslicer/var/logs/ansible /opt/deslicer/var/logs/dai \
/opt/deslicer/var/lib /opt/deslicer/var/lib/dai-install \
/opt/deslicer/dai-install /opt/deslicer/etc /opt/deslicer/etc/age \
/opt/deslicer/etc/dai
sudo chmod 2770 /opt/deslicer /opt/deslicer/bin /opt/deslicer/var \
/opt/deslicer/var/logs /opt/deslicer/var/logs/ai \
/opt/deslicer/var/logs/ansible /opt/deslicer/var/logs/dai \
/opt/deslicer/var/lib /opt/deslicer/var/lib/dai-install \
/opt/deslicer/dai-install
sudo chmod g-s,u=rwx,go= /opt/deslicer/etc /opt/deslicer/etc/age /opt/deslicer/etc/dai
sudo -u deslicer age-keygen -o /opt/deslicer/etc/age/keys.txt
sudo -u deslicer age-keygen -y /opt/deslicer/etc/age/keys.txt
# Download (inode replace, no sudo)
curl -fsSL https://artifact-registry.deslicer.io/install/linux/enterprise/deslicer-dai-install.sh \
-o /opt/deslicer/bin/deslicer-dai-install.sh.new
chmod 775 /opt/deslicer/bin/deslicer-dai-install.sh.new
mv -f /opt/deslicer/bin/deslicer-dai-install.sh.new \
/opt/deslicer/bin/deslicer-dai-install.sh
bash /opt/deslicer/bin/deslicer-dai-install.sh --version
sudo install -o deslicer -g deslicer -m 600 ./provision.enc.yml \
/opt/deslicer/etc/dai/provision.enc.yml
bash /opt/deslicer/bin/deslicer-dai-install.sh
bash /opt/deslicer/bin/deslicer-dai-install.sh --update --channel enterprise
bash /opt/deslicer/bin/deslicer-dai-install.sh --repair
bash /opt/deslicer/bin/deslicer-dai-install.sh --status
Do not chown -R /opt/deslicer. age-keygen -o fails if keys.txt already exists.
Deslicer AI — uninstall
Uninstall DAP first if this Control instance still has an enrolled backend (Chapter 7 §7.10).
curl -fsSL https://artifact-registry.deslicer.io/install/linux/enterprise/deslicer-dai-uninstall.sh \
-o /opt/deslicer/bin/deslicer-dai-uninstall.sh.new
chmod 775 /opt/deslicer/bin/deslicer-dai-uninstall.sh.new
mv -f /opt/deslicer/bin/deslicer-dai-uninstall.sh.new \
/opt/deslicer/bin/deslicer-dai-uninstall.sh
bash /opt/deslicer/bin/deslicer-dai-uninstall.sh \
--compose-dir /opt/deslicer/ai
DAP — install and update (shape only — use Control’s exact command)
# Host prep on the DAP host (no etc/dai) — then re-login or: newgrp deslicer
sudo groupadd -f deslicer
id deslicer >/dev/null 2>&1 || sudo useradd --system --gid deslicer \
--home-dir /opt/deslicer --create-home --shell /usr/sbin/nologin deslicer
sudo usermod -aG deslicer "$(id -un)"
sudo mkdir -p /opt/deslicer/bin /opt/deslicer/var/logs/dap \
/opt/deslicer/var/lib/dap-install /opt/deslicer/etc/age
sudo chown deslicer:deslicer /opt/deslicer /opt/deslicer/bin \
/opt/deslicer/var /opt/deslicer/var/logs /opt/deslicer/var/logs/dap \
/opt/deslicer/var/lib /opt/deslicer/var/lib/dap-install \
/opt/deslicer/etc /opt/deslicer/etc/age
sudo chmod 2770 /opt/deslicer /opt/deslicer/bin /opt/deslicer/var \
/opt/deslicer/var/logs /opt/deslicer/var/logs/dap \
/opt/deslicer/var/lib /opt/deslicer/var/lib/dap-install
sudo chmod g-s,u=rwx,go= /opt/deslicer/etc /opt/deslicer/etc/age
sudo -u deslicer age-keygen -o /opt/deslicer/etc/age/keys.txt
sudo -u deslicer age-keygen -y /opt/deslicer/etc/age/keys.txt
curl -fsSL https://artifact-registry.deslicer.io/install/linux/enterprise/deslicer-dap-install.sh \
-o /opt/deslicer/bin/deslicer-dap-install.sh.new
chmod 775 /opt/deslicer/bin/deslicer-dap-install.sh.new
mv -f /opt/deslicer/bin/deslicer-dap-install.sh.new \
/opt/deslicer/bin/deslicer-dap-install.sh
bash /opt/deslicer/bin/deslicer-dap-install.sh --version
printf '%s' 'ENROLL_TOKEN' | bash /opt/deslicer/bin/deslicer-dap-install.sh \
--dai-url https://<dai-host> \
--enroll-token-file -
# When Control DAP unsecure is on, the Fresh/repair line includes:
# --peer-tls-insecure
# Nexus-only --update (already-installed stack; no token, no --dai-url)
bash /opt/deslicer/bin/deslicer-dap-install.sh --update --channel enterprise
# Proxy-only apply when Control prints it (certificates / Caddy only)
printf '%s' 'ENROLL_TOKEN' | bash /opt/deslicer/bin/deslicer-dap-install.sh \
--dai-url https://<dai-host> \
--enroll-token-file - \
--proxy-only
DAP — uninstall
Delete or deactivate the Control backend first, then:
curl -fsSL https://artifact-registry.deslicer.io/install/linux/enterprise/deslicer-dap-uninstall.sh \
-o /opt/deslicer/bin/deslicer-dap-uninstall.sh.new
chmod 775 /opt/deslicer/bin/deslicer-dap-uninstall.sh.new
mv -f /opt/deslicer/bin/deslicer-dap-uninstall.sh.new \
/opt/deslicer/bin/deslicer-dap-uninstall.sh
bash /opt/deslicer/bin/deslicer-dap-uninstall.sh \
--compose-dir /opt/deslicer/dap
Platform stack uninstall only. Splunk worker-host package uninstall is out of scope.
Age decrypt (optional inspect of a local ciphertext)
Host identity is 0600 deslicer. Pipe it into age as the invoking admin:
sudo -u deslicer cat /opt/deslicer/etc/age/keys.txt \
| age -d -i - -o provision.yml ./provision.enc.yml
Local health (DAI host)
bash /opt/deslicer/bin/deslicer-dai-install.sh --status
curl -fsS http://127.0.0.1:13000/api/health
curl -fsS -o /dev/null -w '%{http_code}\n' http://127.0.0.1:13001/
11.2 Glossary
| Term | Short definition |
|---|---|
| Control | Deslicer AI management UI at /control |
| DAP | Deslicer Automation Platform |
| Edge proxy | Deslicer-managed Caddy on the product host |
| Engagement | Customer deployment instance |
| Enterprise channel | Stable floating image tip (:enterprise) |
| Enterprise workspace | Customer access UI at /dashboard/enterprise |
| Install package | DAP install package applied from Control → Updates → DAP |
| Install state | Age-encrypted /opt/deslicer/ai/install-state.enc.yml |
| Observer API | DAP API surface |
| Preview channel | Early-access floating image tip (:preview) |
| Provisioning package | Deslicer handoff (provision.yml or provision.enc.yml) |
| Role scope | Organization-wide vs tenant-limited capability boundary |
11.3 Related Deslicer contacts
| Need | Contact |
|---|---|
| Install support | support@deslicer.com |
| Registry / Nexus access | Deslicer delivery team for your engagement |
11.4 Document map
| Topic | Chapter |
|---|---|
| Terminology | 01 |
| Ports and Caddy | 02, 06 |
| Package and answers | 04 |
| DAI install / updates / uninstall | 05 |
| DAP install / updates / uninstall | 07 |
| Firewall | 09 |
| Troubleshooting | 10 |
| Roles, presets, scope | 12 |
| Rename System tenant | 08 §8.3 |
← Back to Index | Previous: Troubleshooting | Next: Enterprise roles and access →