Install Deslicer AI
← Back to Index | Previous: Provisioning package | Next: TLS certificates →
5.1 Overview
On the DAI host, run Control Host prep, stage provision.enc.yml, then run the installer. The installer:
- Downloads the Deslicer AI installer package from the artifact registry
- Decrypts host-staged
provision.enc.ymlin memory (sudo -u deslicer) - Logs in to the container registry using credentials from the package
- Deploys the Compose stack under
/opt/deslicer/ai - Writes age-encrypted install state (
install-state.enc.yml) as0600 deslicer - Configures Deslicer Caddy so
https://<dai-host>/and/controlterminate TLS on this DAI host (replace<dai-host>with your DAI FQDN, not the DAP hostname) - Prepares Control so DAP enroll can proceed when the DAI host can reach the artifact registry
Run as a sudo-capable admin in group deslicer. Do not run as root. On air-gapped hosts, use --skip-dap-bundle-seed and Import the DAP package later under Control → Updates → DAP.
5.2 Prerequisites on this DAI host
Before downloading the installer:
- Confirm customer-provided values (tenant name, initial super user email, DAI FQDN).
- Size the DAI host to the capacity baseline: 8+ GiB RAM minimum (16+ GiB recommended for pilots), 4+ vCPU, 100+ GiB disk. The installer requires at least ~8 GiB RAM before pulling images (cloud “8 GB” instances usually pass).
- Install the age CLI (Chapter 3 §3.4) so
ageandage-keygenare onPATH - Generate the DAI host age identity (Chapter 4 §4.2)
- Confirm Python 3.13+ is available as
python3(see Chapter 3) - Docker is not required before first install — the installer installs Docker when missing (Chapter 3, §10.3)
awk '/^MemTotal:/ {printf "%.1f GiB\n", $2/1024/1024}' /proc/meminfo
command -v age && command -v age-keygen
age --version
sudo -u deslicer test -r /opt/deslicer/etc/age/keys.txt
# Optional: python3 --version (installer installs 3.13+ when missing)
# After a successful install (or to verify an existing engine):
sudo docker info
5.3 Host prep and download the installer
Once (requires sudo) — then re-login or newgrp deslicer. Prefer the block Control prints. Shape:
sudo groupadd -f deslicer
id deslicer >/dev/null 2>&1 || sudo useradd --system --gid deslicer \
--home-dir /opt/deslicer --create-home --shell /usr/sbin/nologin deslicer
sudo usermod -aG deslicer "$(id -un)"
sudo mkdir -p /opt/deslicer/bin /opt/deslicer/var/logs/ai \
/opt/deslicer/var/logs/ansible /opt/deslicer/var/logs/dai \
/opt/deslicer/var/lib/dai-install /opt/deslicer/dai-install \
/opt/deslicer/etc/age /opt/deslicer/etc/dai
sudo chown deslicer:deslicer /opt/deslicer /opt/deslicer/bin \
/opt/deslicer/var /opt/deslicer/var/logs /opt/deslicer/var/logs/ai \
/opt/deslicer/var/logs/ansible /opt/deslicer/var/logs/dai \
/opt/deslicer/var/lib /opt/deslicer/var/lib/dai-install \
/opt/deslicer/dai-install /opt/deslicer/etc /opt/deslicer/etc/age \
/opt/deslicer/etc/dai
sudo chmod 2770 /opt/deslicer /opt/deslicer/bin /opt/deslicer/var \
/opt/deslicer/var/logs /opt/deslicer/var/logs/ai \
/opt/deslicer/var/logs/ansible /opt/deslicer/var/logs/dai \
/opt/deslicer/var/lib /opt/deslicer/var/lib/dai-install \
/opt/deslicer/dai-install
sudo chmod g-s,u=rwx,go= /opt/deslicer/etc /opt/deslicer/etc/age /opt/deslicer/etc/dai
sudo -u deslicer age-keygen -o /opt/deslicer/etc/age/keys.txt
sudo -u deslicer age-keygen -y /opt/deslicer/etc/age/keys.txt
Do not chown -R /opt/deslicer. age-keygen -o fails if keys.txt already exists — that is intended.
Download (no sudo) after re-login — inode replace:
curl -fsSL https://artifact-registry.deslicer.io/install/linux/enterprise/deslicer-dai-install.sh \
-o /opt/deslicer/bin/deslicer-dai-install.sh.new
chmod 775 /opt/deslicer/bin/deslicer-dai-install.sh.new
mv -f /opt/deslicer/bin/deslicer-dai-install.sh.new \
/opt/deslicer/bin/deslicer-dai-install.sh
Prefer the Host prep + download blocks Control / Blueprint print for your engagement (channel may be preview).
Confirm version before first install (bash /opt/deslicer/bin/deslicer-dai-install.sh --version). Current artifacts are ≥ 1.4.38. Ansible Galaxy home/cache stays under /opt/deslicer/var/lib/dai-install/.ansible. See CIS notes in Chapter 10.
5.4 First install
Stage the encrypted package, then run the installer with no --provision / --age-identity flags:
sudo install -o deslicer -g deslicer -m 600 ./provision.enc.yml \
/opt/deslicer/etc/dai/provision.enc.yml
bash /opt/deslicer/bin/deslicer-dai-install.sh
Decrypt uses sudo -u deslicer. --provision / --age-identity remain automation overrides only.
5.5 What success looks like
After the installer finishes:
| Check | Expectation |
|---|---|
| Compose project | Containers healthy under /opt/deslicer/ai |
| Install state | /opt/deslicer/ai/install-state.enc.yml exists (0600 deslicer) |
| Loopback app | http://127.0.0.1:13000 responds on the host |
| Loopback Control | http://127.0.0.1:13001 responds on the host |
| Public HTTPS | https://<dai-host>/ and https://<dai-host>/control reachable through Caddy |
Sign in at:
https://<dai-host>/control
Use the admin credentials from your provision package. Change passwords on first login when prompted.
If sign-in returns 403 {"error":"Forbidden"}, the browser URL does not match the public app URL configured on the host (common after a hostname change or --proxy-only TLS apply). See Chapter 10 §10.13.
5.6 Status and troubleshooting (no provision file)
After install, use the same installer binary for guided host checks. Neither command needs --provision or --age-identity.
On networked hosts, install and update runs refresh the on-disk installer from the artifact registry when a newer published copy is available. Use --skip-self-update (or DESLICER_DAI_SKIP_SELF_UPDATE=1) on air-gapped hosts.
If self-update prints mv: … Permission denied against /opt/deslicer/bin/deslicer-dai-install.sh, the operator layout is not valid (2770 + group deslicer). Re-login or newgrp deslicer, verify test -w /opt/deslicer/bin, then re-download with inode replace (without sudo). See Chapter 10.
| Mode | Command | What it covers |
|---|---|---|
| Status | bash /opt/deslicer/bin/deslicer-dai-install.sh --status | Install health: Compose status, ports, HTTPS probes, and encryption-key presence (values redacted) |
| Troubleshoot | bash /opt/deslicer/bin/deslicer-dai-install.sh --troubleshoot | Status snapshot plus filtered application logs and Control DAP package cache writability |
| Fix DAP cache | bash /opt/deslicer/bin/deslicer-dai-install.sh --troubleshoot --fix-dap-bundle-cache | Repair Control install-package cache permissions when Control → Updates → DAP fails with a write error |
Prefer these over memorizing ad-hoc docker / ss / curl one-liners. See Chapter 10 for symptom → command mapping.
5.7 Updates and repair
Later runs use host-staged secrets. Do not pass --provision or --age-identity.
| Mode | Command |
|---|---|
| Update (stable tip) | bash /opt/deslicer/bin/deslicer-dai-install.sh --update --channel enterprise |
| Update (preview tip) | bash /opt/deslicer/bin/deslicer-dai-install.sh --update --channel preview |
| Update (pinned release) | bash /opt/deslicer/bin/deslicer-dai-install.sh --update --channel enterprise --release <version> |
| Repair | bash /opt/deslicer/bin/deslicer-dai-install.sh --repair |
Customer images use two floating tracks on container-registry.deslicer.io:
| Channel | Floating tag | Who |
|---|---|---|
| Enterprise (stable, default) | :enterprise | Production customer hosts |
| Preview | :preview | Pilot / early-access hosts before a coordinated promote to enterprise |
--channel enterprise|preview selects the tip. Optional --release <version> pins to the immutable tag :<channel>-<version> (for example :enterprise-1.4.2 or :preview-1.4.2). Omit any enterprise- / preview- prefix from --release.
Keep the same provision file for upgrades: Deslicer moves the tip under the chosen floating tag, then --update preserves secrets/DB and updates image versions in host config before compose pull and migrator run. You do not re-issue a new provision YAML for routine image upgrades, and you do not hand-edit .env image lines.
Control → Updates → Deslicer AI
- Sign in at
https://<dai-host>/control - Open Updates → Deslicer AI
- Choose enterprise or preview, optionally select a release
- Copy the host command and run it on the DAI host as the sudo-capable admin
Selecting an older release than currently running may be unsafe if an interim release already migrated the schema (migrations are forward-only).
Interactive database schema prompts
Some Deslicer AI updates pause after the database is ready and run an interactive schema apply (Drizzle). The installer attaches to your terminal so you can answer prompts.
When Drizzle asks whether a table is created or renamed from another table, always choose create table (+ <name> create table). Do not choose rename (~ <old> › <new> rename table) unless Deslicer Support has given you an explicit rename instruction for that update.
Drizzle often pairs a new table with an unrelated existing table as a rename guess. Choosing rename can destroy or merge live data.
If you are unsure, stop the update (Ctrl+C), keep the install-state and age identity, and contact Deslicer Support with the prompt text and ansible log path printed by the installer.
Pilot path: run a pilot host on --channel preview and verify --update before Deslicer promotes the same digests to :enterprise.
Rollback (registry tip): Deslicer re-promotes a previous digest to the floating tip (and may publish a new :<channel>-<version>). Re-run --update --channel … on the host to follow the tip. Customer-side digest editing is not supported.
Control → Updates prints Nexus-only --update for image upgrades. That command regenerates Caddy routes and keeps extra listeners via the host sidecar (see Chapter 6). It is not the path for certificate or extra-listener edits.
For certificate-only or extra-listener changes, use Control Web certificates and the host apply command it shows (see Chapter 6). That path refreshes PEMs, regenerates the Deslicer-managed Caddyfile, and reloads Caddy (--proxy-only; DAI’s printed line also includes installer --update). Prefer that path over a full Compose recreate when only TLS material changed.
Do not hand-edit /etc/caddy/Caddyfile or run ad-hoc caddy validate / caddy reload on the Control/installer path. Day-0 Manual Certs PEM placement is covered in Chapter 6 §6.3.
Hostname / public URL changes need a full --update (not --proxy-only alone) so host configuration and app containers pick up the new public app URL.
5.8 Uninstall
Uninstall removes the Deslicer AI Compose project and local volumes on this DAI host. Docker Engine remains installed. If DAP is enrolled against this Control instance, uninstall DAP first (Chapter 7 §7.10).
curl -fsSL https://artifact-registry.deslicer.io/install/linux/enterprise/deslicer-dai-uninstall.sh \
-o /opt/deslicer/bin/deslicer-dai-uninstall.sh.new
chmod 775 /opt/deslicer/bin/deslicer-dai-uninstall.sh.new
mv -f /opt/deslicer/bin/deslicer-dai-uninstall.sh.new \
/opt/deslicer/bin/deslicer-dai-uninstall.sh
bash /opt/deslicer/bin/deslicer-dai-uninstall.sh \
--compose-dir /opt/deslicer/ai
| Option | Effect |
|---|---|
--compose-dir PATH | Compose project to tear down (default /opt/deslicer/ai) |
--keep-workspace | Retain the installer workspace under /opt/deslicer/var/lib/dai-install |
This destroys local application data in Docker volumes for that project. Confirm with Deslicer before production teardown. Preserve age identity and any backups you need before running uninstall.
5.9 Existing database
If you intentionally reuse an existing application database volume or external database, the installer supports an allow-existing-db flag. Only use it when Deslicer has documented that path for your engagement:
bash /opt/deslicer/bin/deslicer-dai-install.sh --allow-existing-db
5.10 Next steps
← Back to Index | Previous: Provisioning package | Next: TLS certificates →