Skip to main content

Introduction

← Back to Index | Next: Architecture →


1.1 What this guide covers​

This guide walks you through installing Deslicer AI and the Deslicer Automation Platform (DAP) on infrastructure you operate (your data center, cloud project, or agreed MSP environment)—not Deslicer SaaS.

You will:

  1. Use a Deslicer-provided provisioning package to obtain install answers and registry access
  2. Install Deslicer AI with the published curl installer
  3. Terminate public HTTPS with Deslicer-managed Caddy on the DAI and DAP hosts
  4. Enroll and install DAP from Deslicer AI Control
  5. Finish operator settings (SMTP, AI models, certificates) in Control
  6. Rename the default System tenant in the Enterprise workspace, then assign roles (Chapter 8, Chapter 12)
  7. Apply updates from Control → Updates, and uninstall with the published teardown scripts when retiring a DAI or DAP host

1.2 Key terminology​

TermDefinition
Deslicer AIApplication for end users: web UI, data plane, and supporting containers (database, LLM proxy, and related services).
ControlDeslicer AI management UI on the same hostname under /control. Operators use Control after install for platform settings and DAP enrollment.
Enterprise workspaceCustomer access management UI at /dashboard/enterprise (tenants, members, roles, teams). Not the same as Control.
Deslicer Automation Platform (DAP)Required automation component: Observer API and Observer management UI.
Observer APIDAP HTTP API used by workers, insights, and Deslicer AI integration.
Deslicer provisioning packageHandoff file (provision.yml or age-encrypted provision.enc.yml) from Deslicer that carries engagement answers and credentials.
Install stateAge-encrypted host file (/opt/deslicer/ai/install-state.enc.yml) that stores the generated master seed for updates.
DAI host / DAP hostThe two product servers in a split install. Prefer these terms over bare “host” when either product could be meant.
<dai-host> / <dap-host>Placeholders for the public DAI FQDN and DAP FQDN. Do not interchange them in commands.
Edge proxy (Caddy)Deslicer-supplied reverse proxy on each product host. It terminates TLS and routes to loopback application ports.
Container registryDeslicer registry used to pull product images (container-registry.deslicer.io and related hosts).
Artifact registryHost for install scripts and packages (artifact-registry.deslicer.io).
EngagementA customer deployment instance planned and handed off by Deslicer.

1.3 Install sequence (summary)​

Host prep on DAI host (deslicer:deslicer, etc/age keygen)
→ send printed age1… recipient to Deslicer
→ stage provision.enc.yml under /opt/deslicer/etc/dai/
→ deslicer-dai-install.sh (app + Caddy; host-staged secrets)
→ sign in to Control
→ enroll DAP (public hostname DNS ready) → Update or Fresh token from Control
→ Host prep + deslicer-dap-install.sh on DAP host (stack + Caddy; --update when Control issues Update)
→ verify Control probe Active / Healthy → Web certificates and post-install settings

1.4 Document scope​

In scope

  • Split-host enterprise install (DAI host and DAP host)
  • CIS Benchmark / STIG-hardened Linux hosts (Amazon Linux 2023, RHEL-family, Debian-family)
  • Curl installers and uninstallers from the artifact registry
  • Deslicer Caddy TLS for DAI and DAP
  • Control enroll for DAP, Control → Updates, and post-install operator settings
  • Outbound network allowlists for registries and ACME

Out of scope

  • Deslicer SaaS tenancy
  • Splunk host enrollment and worker package uninstall (covered in product runbooks after the platform is up)
  • Assisted installs performed by Deslicer on your behalf

← Back to Index | Next: Architecture →