Deslicer provisioning package
← Back to Index | Previous: Prerequisites | Next: Install Deslicer AI →
4.1 What Deslicer delivers
Deslicer provides a provisioning package, typically named:
provision.enc.yml
or, when encryption is not used for your engagement:
provision.yml
Treat this file as a secret. It contains engagement answers, registry credentials, and related configuration for your install. The DAI installer reads this file; it never writes back into it.
4.2 Age keypair on the DAI host
Install the age CLI first (Chapter 3 §3.4). Confirm the customer-provided values checklist (tenant name, initial super user email, DAI and DAP FQDNs) before Deslicer encrypts the package.
Run Host prep from Control (Chapter 5 §5.3). That creates /opt/deslicer/etc/age/keys.txt as 0600 deslicer and prints the public recipient:
sudo -u deslicer age-keygen -y /opt/deslicer/etc/age/keys.txt
Send the public key (age1…) to Deslicer so they can encrypt provision.enc.yml for this DAI host. Do not overwrite keys.txt if it already exists. The installer encrypts /opt/deslicer/ai/install-state.enc.yml to the same recipient.
4.3 Decrypt (optional)
The installer decrypts provision.enc.yml in memory — you do not need a cleartext copy on disk.
If you need a local inspection copy of an admin-readable ciphertext:
sudo -u deslicer cat /opt/deslicer/etc/age/keys.txt | age -d -i - ./provision.enc.yml
Keep cleartext copies off the host secrets tree. Delete them when install-state is in place.
4.4 What the installer needs from the package
Stage the encrypted package as 0600 deslicer at /opt/deslicer/etc/dai/provision.enc.yml, then run deslicer-dai-install.sh with no --provision / --age-identity flags. CLI flags remain an automation override, not the Control path.
| Field area | Purpose |
|---|---|
| DAI hostname / app URL | Public DAI FQDN (<dai-host>) for Deslicer AI and Control |
| Admin bootstrap | Initial Control / super user identity (email from the prerequisites checklist) |
| Container registry username / password | Image pulls from the Deslicer container registry |
| Optional LLM / engagement defaults | When included for your engagement |
Keep these hostname fields aligned with live DNS (same spelling):
| Provision field | Role |
|---|---|
deployment.urls.daiPublic | Preferred source for the public DAI URL (Caddy site + app URL) |
app.domainName | Keep identical to the daiPublic hostname for handoffs |
A mismatch between the URL operators open in the browser and the public app URL on the host causes local login 403 Forbidden (Chapter 10 §10.13).
If a required field is missing, contact Deslicer to re-export the provisioning package — do not hand-edit a parallel answers file.
The Registry product API key in the full package is for Control / product integration. Docker pulls use the container registry username and password from the provision package.
4.5 Install state (age-encrypted on the host)
On first successful install the installer writes:
/opt/deslicer/ai/install-state.enc.yml
This file is 0600 deslicer, encrypted to the host age recipient, and holds the generated master_seed (and related secrets) for --update / --repair. Keep /opt/deslicer/etc/age/keys.txt and this file in place.
4.6 Two different encrypted bundles
Do not confuse these files:
| Bundle | Issued by | Used by |
|---|---|---|
Deslicer provisioning package (provision.enc.yml) | Deslicer at engagement handoff | deslicer-dai-install.sh on the DAI host |
Control-issued DAP provision bundle (provision.enc.yml on the DAP host) | Deslicer AI Control at DAP enroll time | deslicer-dap-install.sh on the DAP host |
The DAP installer downloads and decrypts the Control-issued bundle with /opt/deslicer/etc/age/keys.txt. That is a separate ciphertext from the original Deslicer handoff package.
4.7 Handling secrets
- Store age identities and passwords in your secret manager
- Host secrets stay
0600 deslicerunder/opt/deslicer/etc/(andai/install-state.enc.yml) - Do not paste registry passwords into tickets or chat
- After first successful DAI install, preserve those host files for
--update/--repair
← Back to Index | Previous: Prerequisites | Next: Install Deslicer AI →