Skip to main content

Install Deslicer Automation Platform

← Back to Index | Previous: TLS certificates | Next: Post-install configuration →


7.1 Overview​

Install DAP after Deslicer AI Control is reachable. Control issues an enroll token and a short-lived encrypted provision bundle for the DAP host. The DAP curl installer downloads that bundle, decrypts it with the host age identity, deploys Compose under /opt/deslicer/dap, and configures Deslicer Caddy for the DAP edge.

7.2 Prepare the DAP host​

On the DAP host:

  1. Confirm prerequisites (supported OS, sudo-capable admin, outbound HTTPS). Python 3.13+, curl, tar, and acl are installed by deslicer-dap-install.sh — they are not manual pre-enroll steps
  2. Confirm customer-provided values include the DAP host FQDN (and tenant / super-user details already used for DAI)
  3. Install the age CLI from Control (or Chapter 3 §3.4), then run Host prep so /opt/deslicer/etc/age/keys.txt exists and paste the printed age1… key into Control
  4. Ensure DNS for the public Observer hostname (<dap-host> — the DAP FQDN, not the DAI FQDN) resolves to this DAP host before you run the installer (ACME needs a working name)
  5. Ensure firewall allows the edge ports you will publish on the DAP host
  6. Docker is not required before enroll. After Control issues the bundle, download deslicer-dap-install.sh and run enroll as a non-root sudo-capable admin — the installer installs Python, curl, tar, age, acl, and Docker when needed. If Docker ends up broken, repair by re-running the installer rather than hand-installing packages (§10.3). Ensure the DAP install package is available via the Deslicer AI install path or Control → Updates → DAP → Apply before relying on this path (Chapter 3)

Default age identity path:

/opt/deslicer/etc/age/keys.txt

Control Run install does not pass --age-identity-file. The installer decrypts with sudo -u deslicer.

7.3 Enroll from Control​

  1. Sign in at https://<dai-host>/control
  2. Open Platform integrations → DAP → Enroll backend
  3. Fill the wizard fields (see below)
  4. Set this backend’s TLS policy and certificate before you copy the run command (TLS policy and certificates)
  5. Copy the generated host commands exactly — run download/enroll lines on the DAP host; --dai-url https://<dai-host> uses the DAI FQDN

Enroll wizard fields​

FieldWhat to enter
Name / slugHuman label and stable backend id (slug is used in install artifacts)
Public Observer hostnameFQDN operators and Deslicer AI will use (for example dap-103.example.com). This must resolve in public DNS to the DAP host
Age public keyRecipient key for the Control-minted provision.enc.yml (matches the host identity file)
Edge TLS modeACME (automatic HTTPS) or customer PEM, as prompted

On split installs (DAI and DAP on different hosts), Control stores the same public edge URL for both the server-side backend URL and the tenant-facing URL. Deslicer AI reaches DAP over that public hostname.

TLS policy and certificates (before you copy the run command)​

The defaults assume both edges present publicly trusted certificates. If the Observer edge or the Deslicer AI edge uses a private CA or a self-signed certificate, finish this step first. Otherwise the failure surfaces on the DAP host as an unreachable-host or certificate error rather than as a configuration message.

Where the controls live — the backend row is collapsed until you click it:

https://<dai-host>/control → Platform integrations → DAP → Backends card → click the backend row to expand → the Untrusted TLS and Web certificates panels.

The same expanded row is step 6 (Status) of the Enroll backend wizard, so first-time enroll and later edits use the same panels.

Untrusted TLS — two switches, two network paths​

Both switches are enterprise-only. With self-signed or private-CA certificates you normally need both; they do not overlap.

SwitchWhat it governsNeeded for self-signed?
DAP unsecureTwo effects. Deslicer AI skips certificate verification on its own HTTPS calls to this backend’s Observer URLs (proxy, provisioning, status, compliance) — and Control appends --peer-tls-insecure to this backend’s Fresh/repair run line so the DAP host can curl -k back to Deslicer AI while it downloads the provision bundle (§7.6)Yes, if either the Observer edge or the DAI edge is not publicly trusted
Worker node unsecureWorkers and bootstrap agents on your Splunk hosts verifying the Observer certificate. Applied at provision time; enabling it also clears any Observer CA stamped on this backendYes, unless you install the Observer edge CA into each worker host’s trust store

Enabling either switch requires typing the exact confirmation phrase Control shows — ACCEPT PEER TLS RISK for DAP unsecure, ACCEPT WORKER TLS RISK for Worker node unsecure. Both actions are audited, and the backend row then shows a red Unsecure SSL badge. That badge is expected; it is not an error.

Skip-verify leaves a real man-in-the-middle exposure. Prefer trusting the edge CA: upload the chain under Web certificates so Deslicer AI can stamp it for workers, and leave Worker node unsecure off. Use skip-verify for a pilot or as break-glass, and record the decision. Full operator rules, including what each toggle revokes: Chapter 6 §6.8.

Web certificates — upload the certificate for this host​

Choose Upload certificate (PEM), paste the full chain (leaf + intermediates) into Certificate chain (PEM) and the matching key into Private key (PEM), then click Save and generate host command.

The certificate must carry the hostname from this backend’s DAP API URL (locked) — shown in the same panel — as a Subject Alternative Name. Deslicer AI rejects the upload otherwise and names the hostname it expected. If your estate was issued one certificate per host, each covering only that host’s FQDN and IP addresses, then the DAI host and the DAP host have different certificates; uploading the DAI certificate here is the most common mistake at this step. Day-0 PEM file layout on disk: §6.3.

Re-copy the run line after any TLS change​

Changing DAP unsecure revokes any install token already issued for this backend, and Control re-issues the run command. Copy the run line that is on screen after you finish this step — a line copied earlier fails even when it looks correct (§7.6).

Update vs Fresh (token modes)​

When you Issue install run command or Re-issue, Control chooses a token mode:

ModeUse whenEffect
Update (keep data & secrets)Stack already installed; you want new images / repair without wiping dataRuns installer --update. Keeps existing secrets and data; applies image versions from the token, then pulls images
Fresh (rotate secrets)Brand-new host, or you intentionally wipe volumes and start overRotates provision secrets. Conflicts with an existing Postgres volume when host config is missing or its password does not match the Fresh token

Prefer Update for every reinstall of an existing DAP host. Use Fresh only on a clean host or after an explicit volume wipe you planned with Deslicer. If a Fresh run conflicts with existing volumes, use Update or wipe as Deslicer directs (§10.9).

There is no host CLI flag named --fresh. Fresh vs Update is selected in Control when the token is issued.

Image channels (Control Updates)​

Routine image upgrades keep the same DAI provision and the same Control Update token path. Deslicer publishes digests under two floating tracks on container-registry.deslicer.io:

ChannelFloating tipImmutable pin
Enterprise (stable, default):enterprise:enterprise-<version>
Preview (pilot):preview:preview-<version>

Re-issue an Update token from Control → Updates → DAP, then run the printed command (or the equivalent below):

# enterprise tip (default)
bash /opt/deslicer/bin/deslicer-dap-install.sh --enroll-token-file ./dap-update.token --update --channel enterprise
# preview tip (pilot hosts)
bash /opt/deslicer/bin/deslicer-dap-install.sh --enroll-token-file ./dap-update.token --update --channel preview
# optional pinned tip within a channel:
bash /opt/deslicer/bin/deslicer-dap-install.sh --enroll-token-file ./dap-update.token --update --channel enterprise --release <version>

--channel enterprise|preview selects the container image tip for this host. --update preserves Postgres/secrets and updates image versions in host config before pull and migrator — do not hand-edit .env image lines. Pilot hosts should track preview until Deslicer promotes to enterprise. Registry-side tip rollback: Deslicer re-promotes a prior digest; hosts re-run --update --channel ….

7.4 Host prep, download the installer, and check the version​

Run the Prepare the host (once) block Control prints first (requires sudo), then re-login or newgrp deslicer. Shape:

sudo groupadd -f deslicer
id deslicer >/dev/null 2>&1 || sudo useradd --system --gid deslicer \
--home-dir /opt/deslicer --create-home --shell /usr/sbin/nologin deslicer
sudo usermod -aG deslicer "$(id -un)"
sudo mkdir -p /opt/deslicer/bin /opt/deslicer/var/logs/dap \
/opt/deslicer/var/lib/dap-install /opt/deslicer/etc/age
sudo chown deslicer:deslicer /opt/deslicer /opt/deslicer/bin \
/opt/deslicer/var /opt/deslicer/var/logs /opt/deslicer/var/logs/dap \
/opt/deslicer/var/lib /opt/deslicer/var/lib/dap-install \
/opt/deslicer/etc /opt/deslicer/etc/age
sudo chmod 2770 /opt/deslicer /opt/deslicer/bin /opt/deslicer/var \
/opt/deslicer/var/logs /opt/deslicer/var/logs/dap \
/opt/deslicer/var/lib /opt/deslicer/var/lib/dap-install
sudo chmod g-s,u=rwx,go= /opt/deslicer/etc /opt/deslicer/etc/age
sudo -u deslicer age-keygen -o /opt/deslicer/etc/age/keys.txt
sudo -u deslicer age-keygen -y /opt/deslicer/etc/age/keys.txt

Do not chown -R /opt/deslicer. age-keygen -o fails if keys.txt already exists.

Then the Download block (inode replace, no sudo):

curl -fsSL https://artifact-registry.deslicer.io/install/linux/enterprise/deslicer-dap-install.sh \
-o /opt/deslicer/bin/deslicer-dap-install.sh.new
chmod 775 /opt/deslicer/bin/deslicer-dap-install.sh.new
mv -f /opt/deslicer/bin/deslicer-dap-install.sh.new \
/opt/deslicer/bin/deslicer-dap-install.sh

Confirm the script before enroll:

bash /opt/deslicer/bin/deslicer-dap-install.sh --version

Expect ≥ 1.9.49 on current enterprise/preview artifacts. Use the download command and version pin Control shows for your engagement.

7.5 DAP install package updates​

Greenfield: after Deslicer AI is healthy and can reach the artifact registry, Control is ready for the first DAP enroll without a separate Apply step.

Control → Updates → DAP (install package)​

Open Control → Updates → DAP:

StatusMeaning
Up to dateCache matches the latest published install package for your channel
Update availableA newer package is published (or the cache is empty with discovery OK)—use Apply update
UnknownRegistry unreachable (typical air-gap)—use Import package with a Deslicer-provided tarball and checksum, or re-run deslicer-dai-install.sh --repair when registry access returns
ActionWhen to use
Apply updateOnline hosts: download the versioned artifact, verify checksum, and stage it in Control. Next DAP enroll / --update uses that package. Does not change the Deslicer AI application image
Import packageAir-gapped hosts: upload the tarball Deslicer shipped offline; Control applies the same verify and stage path. Confirm the checksum Deslicer provided before import
Roll backRestore the previous verified package when a new apply causes install failures

If enroll fails because no install package is staged, re-run deslicer-dai-install.sh --repair (or Import package), then mint a fresh enroll token.

7.6 Run install with the enroll token​

  1. In Control, issue a Fresh or Repair run command (day-0 enroll and TLS remint keep the token)
  2. On the DAP host, run that command as the sudo-capable admin (pipe the token; do not put it on argv)

Control shows commands similar to:

printf '%s' 'ENROLL_TOKEN' | bash /opt/deslicer/bin/deslicer-dap-install.sh \
--dai-url https://<dai-host> \
--enroll-token-file -

When DAP unsecure is on, Control stamps --peer-tls-insecure on this Fresh/repair line (required for curl -k against an untrusted DAI edge). Copy the new run line after toggling.

--update is Nexus-only (already-installed stack): no enroll token, no --dai-url, and no --peer-tls-insecure. It is not the remint after DAP unsecure.

Security: Prefer --enroll-token-file - with a pipe, or a 0600 token file. Do not put the enroll token on the process command line in shared shell history.

7.7 What the DAP installer does​

  1. Probes Deslicer AI at --dai-url
  2. Downloads the Control-issued provision.enc.yml
  3. Decrypts with sudo -u deslicer and /opt/deslicer/etc/age/keys.txt
  4. On --update, reconciles secrets from live host config and applies image versions from the token
  5. Deploys the DAP stack and configures Caddy when edge TLS is enabled
  6. Signals install-complete back to Control

This provision.enc.yml is not your original Deslicer handoff package. It is minted for this enroll.

DNS and certificates during install​

  • Publish the A/AAAA (or CNAME) for the public Observer hostname before the first install that enables ACME
  • If DNS was wrong during the first attempt, fix DNS, then restart Caddy on the DAP host so it can leave ACME backoff and obtain a certificate
  • Until TLS succeeds, browsers may show certificate warnings; Control probes may report TLS or DNS errors

7.8 Verify in Control​

CheckExpectation
Install statusactive (not stuck on failed)
Health badgeHealthy (backend /health + provisioning key)
ActiveBackend marked Active
Observer healthPublic HTTPS health URL from Control succeeds
Observer UIUI URL from Control loads
Deslicer AI → DAPFrom the DAI host, Observer integration succeeds

Stuck “failed” with Healthy​

If the header shows failed / Inactive / dns_error while the live probe is Healthy, an earlier enroll attempt failed (often DNS) and the row was not activated.

  • Reload Platform integrations → DAP
  • Use Retest connection or Retry probe
  • A green health check now activates the backend, clears the last error, and marks the backend Active

On split installs the probe label is Backend /health (the public Observer URL Deslicer AI uses server-side).

7.9 Update and proxy-only apply​

For later stack image updates, use Control → Updates → DAP, copy the per-backend host upgrade command, and run it on that DAP host (§7.3).

After a successful DAP --update, Control → Updates → DAP backends can show Installed / Available from host digests. Unknown until the first such update on that host is expected.

Control → Updates stays Nexus-only --update for stack images. That command regenerates Caddy routes and keeps extra listeners via /etc/deslicer/edge-proxy-extra-listeners.json (first run after this recovery can seed the sidecar from the live Caddyfile). It is not the path for TLS or extra-listener edits.

When certificates or extra listeners change, use the proxy-only apply command Control prints from Web certificates (see Chapter 6). That command fetches PEMs from DAI (enroll path), regenerates /etc/caddy/Caddyfile, and reloads Caddy. Do not hand-edit the Caddyfile. Day-0 PEM file layout: §6.3.

7.10 Uninstall​

Uninstall removes the DAP Compose project and local volumes on this host. Docker Engine remains installed.

Order:

  1. In Control, delete or deactivate the DAP backend for this host (required before teardown; do not leave a live enroll pointing at a removed stack).
  2. On the DAP host, run deslicer-dap-uninstall.sh.
  3. Uninstall Deslicer AI only if you are retiring the DAI host as well (Chapter 5 §5.8).
curl -fsSL https://artifact-registry.deslicer.io/install/linux/enterprise/deslicer-dap-uninstall.sh \
-o /opt/deslicer/bin/deslicer-dap-uninstall.sh.new
chmod 775 /opt/deslicer/bin/deslicer-dap-uninstall.sh.new
mv -f /opt/deslicer/bin/deslicer-dap-uninstall.sh.new \
/opt/deslicer/bin/deslicer-dap-uninstall.sh
bash /opt/deslicer/bin/deslicer-dap-uninstall.sh \
--compose-dir /opt/deslicer/dap
OptionEffect
--compose-dir PATHCompose project to tear down (default /opt/deslicer/dap)
--keep-workspaceRetain the installer workspace under /opt/deslicer/var/lib/dap-install

This destroys local DAP data in Docker volumes for that project. Confirm with Deslicer before production teardown. If your engagement uses an external database you intend to keep, retain backups separately before uninstall.

This guide covers platform stack removal only. Splunk worker-host package uninstall is out of scope.


← Back to Index | Previous: TLS certificates | Next: Post-install configuration →