Skip to main content

Post-install configuration

← Back to Index | Previous: Install DAP | Next: Network and firewall →


8.1 Where operators configure the platform​

After Deslicer AI is up, use two operator surfaces:

SurfaceURLPurpose
Controlhttps://<dai-host>/controlPlatform settings, DAP enroll, certificates, Updates
Enterprise workspacehttps://<dai-host>/dashboard/enterpriseOrganization, tenants, members, roles, and access

End users use https://<dai-host>/. Operators use Control for host/platform settings and the Enterprise workspace for customer access structure.

  1. Confirm TLS (Chapter 6)
  2. Rename the default System tenant (and organization if still named System) — §8.3
  3. System settings — SMTP for invites and notifications
  4. AI models and keys — provider connections and models for chat / agents — §8.5
  5. DAP — enroll and verify (Chapter 7)
  6. Registry — platform integration when not already seeded from the provisioning package
  7. Web certificates — revisit ACME/PEM if DNS or certs change
  8. Roles and access — assign presets and scopes before inviting many users (Chapter 12)
  9. Updates — use Control → Updates for Deslicer AI images, DAP images, and the DAP install package (Chapter 5 §5.7, Chapter 7 §7.5)

8.3 Rename the default System tenant​

Packaged and bootstrap installs often create an organization and first tenant named System. Rename them to descriptive business names before you invite operators or create additional tenants.

Why

  • Invites, tenant switchers, DAP context, and audit trails are easier to read with real names
  • Multi-tenant engagements should not leave a leftover “System” label next to customer tenants

Where

  1. Sign in to the application as an enterprise admin (typically Enterprise Owner or Enterprise Admin).
  2. Open Enterprise → Tenants (/dashboard/enterprise/tenants) and rename the tenant inline, or open Enterprise → Settings (/dashboard/enterprise/settings) to rename the organization and any tenant in one place.

Who

You need enterprise and tenant management capabilities (seeded on enterprise_owner / enterprise_admin). See Chapter 12.

What renaming changes

Renaming updates the display name operators and members see. It does not change tenant UUIDs, delete data, or require reinstall.

8.4 SMTP​

Configure your corporate SMTP relay in Control system settings. Until SMTP works:

  • Invitations and password resets may fail
  • Operational alerts that depend on email will not deliver

Use TLS to your relay as required by your security standard. Store credentials only in Control / secret stores—not in ticket text.

8.5 AI models and keys​

Provider connections and the models offered in the chat picker are configured in the Enterprise workspace, not in Control:

https://<dai-host>/dashboard/enterprise/ai-models — Enterprise → AI providers & models

Control’s Configuration → AI Models & Keys menu entry is an unimplemented placeholder; it renders “Module scaffolded. Implementation pending.” Do not configure providers there.

Who can open it: the page requires an enterprise deployment and a platform super admin. Any other signed-in user gets a 404 rather than a permission prompt.

TabWhat it holds
Provider connectionsDeployment-wide connections: Bedrock, Azure OpenAI, Vertex AI, and Custom gateway (any OpenAI-compatible endpoint)
ModelsThe catalog rows registered against those connections — this is what the chat picker offers
Team keys (BYOK)Per-team OpenAI, Anthropic, and Google keys that team admins manage themselves

Direct OpenAI / Anthropic / Google credentials are team keys, not provider connections.

Bedrock is a provider connection, not a team key. Add it on Provider connections, not Team keys (BYOK). Team-scoped Bedrock keys are a secondary path for individual teams; the platform operator procedure is always Provider connections → Bedrock first.

The page’s own first-run strip gives the order: Add a provider connection → Register models → Confirm in chat picker. Run Sync now after registering models so the LLM proxy picks up the definitions, then use the per-model Test action. Sync now only writes definitions to the proxy and issues no completion, so a model can read as synced and still fail; Test sends one real completion and is the step that proves the model works.

Full walkthroughs, prefix rules, Bedrock IAM, and troubleshooting: Chapter 13.

Upstream prefixes (Model ID vs Upstream)​

Connection kindUpstream model formEnforced at save?
Bedrockbedrock/… or bedrock_mantle/…Yes — wrong shape is rejected
Custom gatewaySame as gateway id; sync adds openai/ when neededRewritten on sync
Azure OpenAIazure/<deployment>No — fails at Test if wrong
Vertex AIvertex_ai/<model>No — fails at Test if wrong

The Add model dialog shows the same hints per connection kind.

Bedrock — model access (commercial vs GovCloud)​

Listing or registering a model does not prove you can invoke it. IAM bedrock:InvokeModel and AWS account model access are separate checks.

AWS partitionEnable access
CommercialMarketplace permissions (aws-marketplace:Subscribe, aws-marketplace:ViewSubscriptions); many models auto-enable on first invoke. Do not rely on the Bedrock console Model access page — AWS documents it for GovCloud.
GovCloud (US)Bedrock console → Model access, per model and region

If chat fails after Test connection is green, read the AWS error: missing IAM action, missing entitlement, and wrong inference-profile id all present differently. See Chapter 13 §13.3 and §13.7.

Custom gateway — manual model add​

Set API base to include /v1 (e.g. https://llm-gateway.example.com/v1). Discover calls {api_base}/models with no auto-append.

For Custom gateway connections, prefer Discover on the Models tab. When you must add a model by hand:

  1. Copy the exact id from GET {gateway}/v1/models into both Model ID and Upstream model (same value).
  2. Do not type openai/ yourself — Deslicer adds the LiteLLM transport prefix on Sync now.
  3. Run Sync now, then Test the row. After a Deslicer AI update that changes prefix handling, Sync now again on existing rows.
Gateway listsType in both fieldsGateway receives after sync
gpt-5-nanogpt-5-nanogpt-5-nano
openai/gpt-5-nano (nested LiteLLM proxy)openai/gpt-5-nanoopenai/gpt-5-nano

Footgun: a friendly Model ID (orange-nano) with Upstream openai/gpt-5-nano skips the double-prefix path and the gateway may reject the call. Use the gateway id in both fields.

Details: Chapter 13 §13.4.

8.6 Registry integration​

If the Registry API key was not applied automatically from the provisioning package, configure the Registry platform integration in Control using the key from your handoff. This is separate from the container registry username and password used for Docker pulls during install.

8.7 DAP backend hygiene​

In Platform integrations → DAP:

  • Confirm the backend URL matches what workers and Deslicer AI should call
  • Keep enroll tokens short-lived; mint new ones for additional hosts
  • Apply certificate changes through Control Web certificates (PEM refresh, Caddyfile regenerate, reload). Do not hand-edit /etc/caddy/Caddyfile (Chapter 6). Day-0 Manual Certs file placement: §6.3.

8.8 Operational backups​

Agree a backup plan with Deslicer for:

  • Application databases (AI and DAP Postgres when local)
  • /opt/deslicer/*/.env and install answers (secrets)
  • Age identities and PEM private keys

When retiring a host, reverse install order: uninstall DAP (§7.10), then Deslicer AI (§5.8).


← Back to Index | Previous: Install DAP | Next: Network and firewall →