Install Deslicer Automation Platform
← Back to Index | Previous: TLS certificates | Next: Post-install configuration →
7.1 Overview
Install DAP after Deslicer AI Control is reachable. Control issues an enroll token and a short-lived encrypted provision bundle for the DAP host. The DAP curl installer downloads that bundle, decrypts it with the host age identity, deploys Compose under /opt/deslicer/dap, and configures Deslicer Caddy for the DAP edge.
7.2 Prepare the DAP host
On the DAP host:
- Confirm prerequisites (supported OS, sudo-capable admin, outbound HTTPS). Python 3.13+, curl, tar, and acl are installed by
deslicer-dap-install.sh— they are not manual pre-enroll steps - Confirm customer-provided values include the DAP host FQDN (and tenant / super-user details already used for DAI)
- Install the age CLI from Control (or Chapter 3 §3.4), then run Host prep so
/opt/deslicer/etc/age/keys.txtexists and paste the printedage1…key into Control - Ensure DNS for the public Observer hostname (
<dap-host>— the DAP FQDN, not the DAI FQDN) resolves to this DAP host before you run the installer (ACME needs a working name) - Ensure firewall allows the edge ports you will publish on the DAP host
- Docker is not required before enroll. After Control issues the bundle, download
deslicer-dap-install.shand run enroll as a non-root sudo-capable admin — the installer installs Python, curl, tar, age, acl, and Docker when needed. If Docker ends up broken, repair by re-running the installer rather than hand-installing packages (§10.3). Ensure the DAP install package is available via the Deslicer AI install path or Control → Updates → DAP → Apply before relying on this path (Chapter 3)
Default age identity path:
/opt/deslicer/etc/age/keys.txt
Control Run install does not pass --age-identity-file. The installer decrypts with sudo -u deslicer.
7.3 Enroll from Control
- Sign in at
https://<dai-host>/control - Open Platform integrations → DAP → Enroll backend
- Fill the wizard fields (see below)
- Set this backend’s TLS policy and certificate before you copy the run command (TLS policy and certificates)
- Copy the generated host commands exactly — run download/enroll lines on the DAP host;
--dai-url https://<dai-host>uses the DAI FQDN
Enroll wizard fields
| Field | What to enter |
|---|---|
| Name / slug | Human label and stable backend id (slug is used in install artifacts) |
| Public Observer hostname | FQDN operators and Deslicer AI will use (for example dap-103.example.com). This must resolve in public DNS to the DAP host |
| Age public key | Recipient key for the Control-minted provision.enc.yml (matches the host identity file) |
| Edge TLS mode | ACME (automatic HTTPS) or customer PEM, as prompted |
On split installs (DAI and DAP on different hosts), Control stores the same public edge URL for both the server-side backend URL and the tenant-facing URL. Deslicer AI reaches DAP over that public hostname.
TLS policy and certificates (before you copy the run command)
The defaults assume both edges present publicly trusted certificates. If the Observer edge or the Deslicer AI edge uses a private CA or a self-signed certificate, finish this step first. Otherwise the failure surfaces on the DAP host as an unreachable-host or certificate error rather than as a configuration message.
Where the controls live — the backend row is collapsed until you click it:
https://<dai-host>/control → Platform integrations → DAP → Backends card → click the backend row to expand → the Untrusted TLS and Web certificates panels.
The same expanded row is step 6 (Status) of the Enroll backend wizard, so first-time enroll and later edits use the same panels.
Untrusted TLS — two switches, two network paths
Both switches are enterprise-only. With self-signed or private-CA certificates you normally need both; they do not overlap.
| Switch | What it governs | Needed for self-signed? |
|---|---|---|
| DAP unsecure | Two effects. Deslicer AI skips certificate verification on its own HTTPS calls to this backend’s Observer URLs (proxy, provisioning, status, compliance) — and Control appends --peer-tls-insecure to this backend’s Fresh/repair run line so the DAP host can curl -k back to Deslicer AI while it downloads the provision bundle (§7.6) | Yes, if either the Observer edge or the DAI edge is not publicly trusted |
| Worker node unsecure | Workers and bootstrap agents on your Splunk hosts verifying the Observer certificate. Applied at provision time; enabling it also clears any Observer CA stamped on this backend | Yes, unless you install the Observer edge CA into each worker host’s trust store |
Enabling either switch requires typing the exact confirmation phrase Control shows — ACCEPT PEER TLS RISK for DAP unsecure, ACCEPT WORKER TLS RISK for Worker node unsecure. Both actions are audited, and the backend row then shows a red Unsecure SSL badge. That badge is expected; it is not an error.
Skip-verify leaves a real man-in-the-middle exposure. Prefer trusting the edge CA: upload the chain under Web certificates so Deslicer AI can stamp it for workers, and leave Worker node unsecure off. Use skip-verify for a pilot or as break-glass, and record the decision. Full operator rules, including what each toggle revokes: Chapter 6 §6.8.
Web certificates — upload the certificate for this host
Choose Upload certificate (PEM), paste the full chain (leaf + intermediates) into Certificate chain (PEM) and the matching key into Private key (PEM), then click Save and generate host command.
The certificate must carry the hostname from this backend’s DAP API URL (locked) — shown in the same panel — as a Subject Alternative Name. Deslicer AI rejects the upload otherwise and names the hostname it expected. If your estate was issued one certificate per host, each covering only that host’s FQDN and IP addresses, then the DAI host and the DAP host have different certificates; uploading the DAI certificate here is the most common mistake at this step. Day-0 PEM file layout on disk: §6.3.
Re-copy the run line after any TLS change
Changing DAP unsecure revokes any install token already issued for this backend, and Control re-issues the run command. Copy the run line that is on screen after you finish this step — a line copied earlier fails even when it looks correct (§7.6).
Update vs Fresh (token modes)
When you Issue install run command or Re-issue, Control chooses a token mode:
| Mode | Use when | Effect |
|---|---|---|
| Update (keep data & secrets) | Stack already installed; you want new images / repair without wiping data | Runs installer --update. Keeps existing secrets and data; applies image versions from the token, then pulls images |
| Fresh (rotate secrets) | Brand-new host, or you intentionally wipe volumes and start over | Rotates provision secrets. Conflicts with an existing Postgres volume when host config is missing or its password does not match the Fresh token |
Prefer Update for every reinstall of an existing DAP host. Use Fresh only on a clean host or after an explicit volume wipe you planned with Deslicer. If a Fresh run conflicts with existing volumes, use Update or wipe as Deslicer directs (§10.9).
There is no host CLI flag named --fresh. Fresh vs Update is selected in Control when the token is issued.
Image channels (Control Updates)
Routine image upgrades keep the same DAI provision and the same Control Update token path. Deslicer publishes digests under two floating tracks on container-registry.deslicer.io:
| Channel | Floating tip | Immutable pin |
|---|---|---|
| Enterprise (stable, default) | :enterprise | :enterprise-<version> |
| Preview (pilot) | :preview | :preview-<version> |
Re-issue an Update token from Control → Updates → DAP, then run the printed command (or the equivalent below):
# enterprise tip (default)
bash /opt/deslicer/bin/deslicer-dap-install.sh --enroll-token-file ./dap-update.token --update --channel enterprise
# preview tip (pilot hosts)
bash /opt/deslicer/bin/deslicer-dap-install.sh --enroll-token-file ./dap-update.token --update --channel preview
# optional pinned tip within a channel:
bash /opt/deslicer/bin/deslicer-dap-install.sh --enroll-token-file ./dap-update.token --update --channel enterprise --release <version>
--channel enterprise|preview selects the container image tip for this host. --update preserves Postgres/secrets and updates image versions in host config before pull and migrator — do not hand-edit .env image lines. Pilot hosts should track preview until Deslicer promotes to enterprise. Registry-side tip rollback: Deslicer re-promotes a prior digest; hosts re-run --update --channel ….
7.4 Host prep, download the installer, and check the version
Run the Prepare the host (once) block Control prints first (requires sudo), then re-login or newgrp deslicer. Shape:
sudo groupadd -f deslicer
id deslicer >/dev/null 2>&1 || sudo useradd --system --gid deslicer \
--home-dir /opt/deslicer --create-home --shell /usr/sbin/nologin deslicer
sudo usermod -aG deslicer "$(id -un)"
sudo mkdir -p /opt/deslicer/bin /opt/deslicer/var/logs/dap \
/opt/deslicer/var/lib/dap-install /opt/deslicer/etc/age
sudo chown deslicer:deslicer /opt/deslicer /opt/deslicer/bin \
/opt/deslicer/var /opt/deslicer/var/logs /opt/deslicer/var/logs/dap \
/opt/deslicer/var/lib /opt/deslicer/var/lib/dap-install \
/opt/deslicer/etc /opt/deslicer/etc/age
sudo chmod 2770 /opt/deslicer /opt/deslicer/bin /opt/deslicer/var \
/opt/deslicer/var/logs /opt/deslicer/var/logs/dap \
/opt/deslicer/var/lib /opt/deslicer/var/lib/dap-install
sudo chmod g-s,u=rwx,go= /opt/deslicer/etc /opt/deslicer/etc/age
sudo -u deslicer age-keygen -o /opt/deslicer/etc/age/keys.txt
sudo -u deslicer age-keygen -y /opt/deslicer/etc/age/keys.txt
Do not chown -R /opt/deslicer. age-keygen -o fails if keys.txt already exists.
Then the Download block (inode replace, no sudo):
curl -fsSL https://artifact-registry.deslicer.io/install/linux/enterprise/deslicer-dap-install.sh \
-o /opt/deslicer/bin/deslicer-dap-install.sh.new
chmod 775 /opt/deslicer/bin/deslicer-dap-install.sh.new
mv -f /opt/deslicer/bin/deslicer-dap-install.sh.new \
/opt/deslicer/bin/deslicer-dap-install.sh
Confirm the script before enroll:
bash /opt/deslicer/bin/deslicer-dap-install.sh --version
Expect ≥ 1.9.49 on current enterprise/preview artifacts. Use the download command and version pin Control shows for your engagement.
7.5 DAP install package updates
Greenfield: after Deslicer AI is healthy and can reach the artifact registry, Control is ready for the first DAP enroll without a separate Apply step.
Control → Updates → DAP (install package)
Open Control → Updates → DAP:
| Status | Meaning |
|---|---|
| Up to date | Cache matches the latest published install package for your channel |
| Update available | A newer package is published (or the cache is empty with discovery OK)—use Apply update |
| Unknown | Registry unreachable (typical air-gap)—use Import package with a Deslicer-provided tarball and checksum, or re-run deslicer-dai-install.sh --repair when registry access returns |
| Action | When to use |
|---|---|
| Apply update | Online hosts: download the versioned artifact, verify checksum, and stage it in Control. Next DAP enroll / --update uses that package. Does not change the Deslicer AI application image |
| Import package | Air-gapped hosts: upload the tarball Deslicer shipped offline; Control applies the same verify and stage path. Confirm the checksum Deslicer provided before import |
| Roll back | Restore the previous verified package when a new apply causes install failures |
If enroll fails because no install package is staged, re-run deslicer-dai-install.sh --repair (or Import package), then mint a fresh enroll token.
7.6 Run install with the enroll token
- In Control, issue a Fresh or Repair run command (day-0 enroll and TLS remint keep the token)
- On the DAP host, run that command as the sudo-capable admin (pipe the token; do not put it on
argv)
Control shows commands similar to:
printf '%s' 'ENROLL_TOKEN' | bash /opt/deslicer/bin/deslicer-dap-install.sh \
--dai-url https://<dai-host> \
--enroll-token-file -
When DAP unsecure is on, Control stamps --peer-tls-insecure on this Fresh/repair line (required for curl -k against an untrusted DAI edge). Copy the new run line after toggling.
--update is Nexus-only (already-installed stack): no enroll token, no --dai-url, and no --peer-tls-insecure. It is not the remint after DAP unsecure.
Security: Prefer --enroll-token-file - with a pipe, or a 0600 token file. Do not put the enroll token on the process command line in shared shell history.
7.7 What the DAP installer does
- Probes Deslicer AI at
--dai-url - Downloads the Control-issued
provision.enc.yml - Decrypts with
sudo -u deslicerand/opt/deslicer/etc/age/keys.txt - On
--update, reconciles secrets from live host config and applies image versions from the token - Deploys the DAP stack and configures Caddy when edge TLS is enabled
- Signals install-complete back to Control
This provision.enc.yml is not your original Deslicer handoff package. It is minted for this enroll.
DNS and certificates during install
- Publish the A/AAAA (or CNAME) for the public Observer hostname before the first install that enables ACME
- If DNS was wrong during the first attempt, fix DNS, then restart Caddy on the DAP host so it can leave ACME backoff and obtain a certificate
- Until TLS succeeds, browsers may show certificate warnings; Control probes may report TLS or DNS errors
7.8 Verify in Control
| Check | Expectation |
|---|---|
| Install status | active (not stuck on failed) |
| Health badge | Healthy (backend /health + provisioning key) |
| Active | Backend marked Active |
| Observer health | Public HTTPS health URL from Control succeeds |
| Observer UI | UI URL from Control loads |
| Deslicer AI → DAP | From the DAI host, Observer integration succeeds |
Stuck “failed” with Healthy
If the header shows failed / Inactive / dns_error while the live probe is Healthy, an earlier enroll attempt failed (often DNS) and the row was not activated.
- Reload Platform integrations → DAP
- Use Retest connection or Retry probe
- A green health check now activates the backend, clears the last error, and marks the backend Active
On split installs the probe label is Backend /health (the public Observer URL Deslicer AI uses server-side).
7.9 Update and proxy-only apply
For later stack image updates, use Control → Updates → DAP, copy the per-backend host upgrade command, and run it on that DAP host (§7.3).
After a successful DAP --update, Control → Updates → DAP backends can show Installed / Available from host digests. Unknown until the first such update on that host is expected.
Control → Updates stays Nexus-only --update for stack images. That command regenerates Caddy routes and keeps extra listeners via /etc/deslicer/edge-proxy-extra-listeners.json (first run after this recovery can seed the sidecar from the live Caddyfile). It is not the path for TLS or extra-listener edits.
When certificates or extra listeners change, use the proxy-only apply command Control prints from Web certificates (see Chapter 6). That command fetches PEMs from DAI (enroll path), regenerates /etc/caddy/Caddyfile, and reloads Caddy. Do not hand-edit the Caddyfile. Day-0 PEM file layout: §6.3.
7.10 Uninstall
Uninstall removes the DAP Compose project and local volumes on this host. Docker Engine remains installed.
Order:
- In Control, delete or deactivate the DAP backend for this host (required before teardown; do not leave a live enroll pointing at a removed stack).
- On the DAP host, run
deslicer-dap-uninstall.sh. - Uninstall Deslicer AI only if you are retiring the DAI host as well (Chapter 5 §5.8).
curl -fsSL https://artifact-registry.deslicer.io/install/linux/enterprise/deslicer-dap-uninstall.sh \
-o /opt/deslicer/bin/deslicer-dap-uninstall.sh.new
chmod 775 /opt/deslicer/bin/deslicer-dap-uninstall.sh.new
mv -f /opt/deslicer/bin/deslicer-dap-uninstall.sh.new \
/opt/deslicer/bin/deslicer-dap-uninstall.sh
bash /opt/deslicer/bin/deslicer-dap-uninstall.sh \
--compose-dir /opt/deslicer/dap
| Option | Effect |
|---|---|
--compose-dir PATH | Compose project to tear down (default /opt/deslicer/dap) |
--keep-workspace | Retain the installer workspace under /opt/deslicer/var/lib/dap-install |
This destroys local DAP data in Docker volumes for that project. Confirm with Deslicer before production teardown. If your engagement uses an external database you intend to keep, retain backups separately before uninstall.
This guide covers platform stack removal only. Splunk worker-host package uninstall is out of scope.
← Back to Index | Previous: TLS certificates | Next: Post-install configuration →