Skip to main content

Prerequisites

← Back to Index | Previous: Architecture | Next: Provisioning package →


3.1 Customer-provided values checklist​

Collect these before Deslicer builds the provisioning package and before you run installers. Cross-check the same values in Chapter 4 (provision fields) and Chapter 5 / Chapter 7 (install / enroll).

ItemWho uses itNotes
Tenant nameDeslicer handoff + Enterprise workspaceDisplay name for the customer tenant (rename the default System tenant after install if needed — Chapter 8)
Initial super user emailProvision / Control bootstrap adminFirst operator sign-in identity for Control and local admin bootstrap
DAI host FQDNDNS, TLS, provision daiPublic / app URLPublic name browsers open as https://<dai-host>/ and https://<dai-host>/control
DAP host FQDNDNS, TLS, Control Enroll backendPublic name for Observer API on 443 and Observer UI on 8443 (https://<dap-host>/, https://<dap-host>:8443)

Also confirm before kickoff:

  • Two Linux VMs sized per §3.8 (DAI host and DAP host)
  • DNS A/AAAA (or CNAME) for both FQDNs points at the correct product host
  • Outbound allowlists for Deslicer registries and OS package repositories (Chapter 9)
  • Inbound 443 (and 80 for ACME) on the DAI host; 443 + 8443 (and 80 for ACME) on the DAP host
  • Splunk management API reachability from both the DAI host and the DAP host (:8089 HTTPS) when Splunk integration is in scope

If you cannot publish DNS FQDNs, read Chapter 6 §6.7 before planning IP-only URLs.

3.2 Supported operating systems​

Installers auto-detect a supported Linux distribution:

FamilyExamples
Debian-basedUbuntu, Debian
RHEL-basedRHEL, Rocky Linux, AlmaLinux, Oracle Linux 9, Oracle Linux 10
Amazon LinuxAmazon Linux 2023

Architecture: x86_64 or ARM64, matching the images in your provisioning package.

CIS Benchmark and STIG-hardened servers are supported on every family in the table (including Amazon Linux 2023 CIS). Host prep creates a deslicer:deslicer layout under /opt/deslicer so installers work with umask 027, no-sudo Download/Run, and a root-only /etc/ansible when present. Do not relax CIS file modes as a workaround. See Chapter 10.

3.3 Host accounts and privileges​

RequirementDetail
Install userSudo-capable admin on the DAI host and the DAP host, also in group deslicer (Host prep adds you; re-login). Run installers as yourself — not as root, not as deslicer
Service accountFrozen to deslicer:deslicer. Owns /opt/deslicer/etc secrets and Compose
Root loginDo not wrap installers in sudo; they die if EUID=0. Use sudo only for packages, Caddy, Docker, and sudo -u deslicer decrypt
PythonPython 3.13+ (installer installs it when missing)
age CLIage and age-keygen on PATH before first install (see §3.4)
DockerInstalled by the installer if missing (requires sudo)

Before the installer starts, install only the age CLI (§3.4) for keypair generation and encrypted handoffs. The DAI and DAP installers install other host packages they need at runtime (including Python 3.13, curl, acl, and Docker). For DAP backends, Control shows age install commands for your OS; everything else is handled by deslicer-dap-install.sh after you download it.

On RHEL / Rocky / Alma / Oracle, do not hand-install python3.13 with a bare dnf install — let the installer enable the required repositories. If prep fails with No match for argument: python3.13, see Chapter 10 §10.17. Install age from the official age release (not dnf install age).

Docker: both DAI and DAP install Docker when it is missing. Do not pre-install Docker CE yourself. If the installer stops with REBOOT REQUIRED, reboot and re-run the same enroll/install command. If docker.service fails after packages are present, see Chapter 10 §10.3.

On Amazon Linux 2023, keep the distro curl-minimal package. Do not force-install the full curl RPM — it conflicts with curl-minimal and breaks Python preflight. Leave distro Docker packages alone; the installer handles them.

3.4 Install the age CLI​

Both installers need the age tools: they encrypt install-state on first success and decrypt provision.enc.yml / enroll bundles when age-encrypted. Install before generating a host keypair or running deslicer-dai-install.sh. These are the same per-OS commands Control shows when you enroll a DAP backend.

Ubuntu / Debian:

sudo apt-get update
sudo apt-get install -y age
age --version
age-keygen --version

RHEL / Rocky / Alma / Oracle / Amazon Linux:

ARCH="$(uname -m)"
case "$ARCH" in
x86_64) AGE_ARCH=amd64 ;;
aarch64|arm64) AGE_ARCH=arm64 ;;
*) echo "unsupported arch: $ARCH" >&2; exit 1 ;;
esac
curl -fsSL "https://dl.filippo.io/age/latest?for=linux/${AGE_ARCH}" -o /tmp/age.tar.gz
sudo tar -C /usr/local/bin -xzf /tmp/age.tar.gz --strip-components=1 age/age age/age-keygen
sudo chmod 755 /usr/local/bin/age /usr/local/bin/age-keygen
rm -f /tmp/age.tar.gz
age --version
age-keygen --version

Confirm both commands resolve:

command -v age
command -v age-keygen

3.5 DNS and certificates​

ItemRequirement
DAI FQDN (<dai-host>)DNS A/AAAA (or CNAME) for the DAI host FQDN used in install answers / provision URLs
DAP FQDN (<dap-host>)DNS for the FQDN you enter in Control Enroll backend must resolve to the DAP host before DAP install/ACME (split installs: this is also the URL Deslicer AI probes)
DAP hostnames / portsSame public DAP name(s) Control shows for Observer API (443) / UI (8443)
Inbound 80 and 443Required on the DAI host for ACME HTTP-01 (when using automatic HTTPS) and public HTTPS
Inbound DAP edge portsOpen 443 (Observer API) and 8443 (Observer UI) on the DAP host by default. If Control shows different ports for your engagement, open those instead

When a command or Control snippet includes a hostname placeholder, substitute the FQDN for that product host only — do not reuse the DAI FQDN in DAP enroll fields, or the DAP FQDN in DAI provision URLs.

3.6 Outbound network​

Both the DAI host and the DAP host need outbound HTTPS (443) to Deslicer registries and, for ACME, to the certificate authority. Installers also need outbound access to OS package repositories (and related mirrors) so they can install Python, Docker, acl, and other runtime packages. See Chapter 9: Network and firewall for the full allowlist (Deslicer + OS + ACME + optional IdP/SMTP/LLM).

Minimum Deslicer product destinations:

Destination hostnamePurpose
artifact-registry.deslicer.ioInstall scripts and packages
container-registry.deslicer.ioDocker/OCI image pulls
package-registry.deslicer.ioPackage channels when used by bootstrap tooling
nexus-registry.deslicer.ioNexus admin/API when required by your engagement
registry.deslicer.ioRegistry metadata API (Control / product integration)

3.7 Cryptographic material​

ItemWho providesPurpose
Age CLI (age / age-keygen)Customer (install per §3.4)Encrypt install-state; decrypt provision.enc.yml when used
Age identityCustomer (Host prep: sudo -u deslicer age-keygen into /opt/deslicer/etc/age/keys.txt)Decrypt the Deslicer provisioning package and DAP enroll bundles
Container registry username + passwordDeslicer (in the provisioning package)docker login during install
Registry API keyDeslicer (in the package; used in Control)Product registry integration—not the Docker pull password

3.8 Capacity (baseline)​

Exact sizing depends on your engagement. As a starting point for a pilot split install:

HostCPUMemoryDisk
DAI host4+ vCPU16+ GiB100+ GiB for images and databases
DAP host4+ vCPU8+ GiB80+ GiB

The Deslicer AI installer requires at least ~8 GiB RAM on the DAI host before pulling images (cloud “8 GB” instances usually pass). Prefer 16+ GiB for pilots; undersized hosts typically OOM during Compose start.

Confirm sizing with Deslicer for production fleets.


← Back to Index | Previous: Architecture | Next: Provisioning package →