Five steps: approve the server connection, download the verified installer, run it on that server, confirm the connection, then configure and start a service. The steps below explain the checks that protect the connection and the settings your service needs.
Overview
The installer connects the server; it is not your application. It registers the launcher, which manages the local agents. For managed-package services, agents prepare the approved application and execute the install, build, and start instructions in its configuration.
Your host provides the application runtime and dependencies. The service configuration supplies commands, ports, environment requirements, health checks, and managed routes. Execution remains on your server; selected operational and security data reaches the hosted plane, and managed-package uploads may include source files.
Requirements
Supported Linux host
A Linux server that supports systemd and the runtimes your application needs: Node, Python, Go, Rust, Java, or another compatible runtime. The commands below are Linux-specific.
Administrative access
Admin access to create users, register the service, and set up the reverse proxy.
DNS and network
A domain name, inbound HTTPS access, and outbound HTTPS to Infraveil.
Launcher install command
A one-time install command from the dashboard after logging in and selecting your workspace.
Connect the server and configure the service
Start from your authenticated workspace and follow Trust Console to connect the intended server. Use the current installer flow below; instructions that create an infraveil-agent user, copy launcher.py, or edit Customization/config.json describe older standalone setups.
1. Approve the server connection
Open Trust Console from your workspace and follow the server-connection prompts. It issues a one-use setup authorization that expires after five minutes. Keep the customer Ed25519 release-signing private key under your control; it is separate from the server’s enrollment authorization.
2. Download the verified installer
Download the customized infraveil.py offered for this connection. The browser must verify its published hash before download proceeds. Use that verified installer, not a standalone launcher script or an installer from another workspace.
3. Run it on the Linux server
Run the verified installer on the intended supported Linux host using the one-use setup authorization. Enrollment exchanges that five-minute authorization for a host-bound, one-use launcher ticket; neither is a reusable login credential.
4. Confirm the server is connected
Confirm the server’s installed launcher identity, host binding, customer release key, and Trust & Receipts state before assigning services. The current elevated Linux/systemd install defaults the launcher service to root; it is not a rootless or no-system-change installation.
5. Configure and start a service
Validate infraveil.json for the installed release, including service commands, ports, health checks, managed routes, and policy settings. Choose the release and its approval policy, then start the configured service and check its health. Manual, exact-hash allowlist, and automatic release approval are separate from host enrollment and assistant/remediation permissions.
Managed routes, proxy, and TLS
The authenticated installer manages the current launcher registration. The elevated Linux/systemd path currently defaults that launcher service to root. Do not recreate the legacy infraveil-agent/launcher.py unit shown in older standalone documentation.
Review the runtime contract
Use the validated infraveil.json to identify service ports and configured managed routes. Confirm launcher reporting and the configured local health probe before exposing traffic.
Keep the network boundary explicit
Configure DNS, TLS, and any upstream edge protection appropriate for the environment. Infraveil origin-side gateway policy applies only to configured traffic that reaches the managed gateway; it does not protect saturated links, upstream volumetric attacks, or bypass listeners.
Operations
Check the configured local health endpoint before opening traffic. The commands below are examples: use your actual service port, health path, and installed service-unit name, and check NGINX only if it is part of your setup.
Use the operating controls to manage releases, supervise configured services, and apply policy to managed gateway routes. Follow process state and health checks; inspect service logs and incident context when something fails. Reported versions, crashes, restart loops, and resource pressure help you choose a supported restart or recovery action.
curl http://127.0.0.1:5050/
sudo systemctl status infraveil.service
sudo nginx -tRecovery and redeployment
For an ordinary service failure, inspect health, process state, logs, and the current release. Use the configured restart budget or a supported restart, rollback, or recovery action. Check health afterward. A rollback needs compatible packages, application data, and configuration; it does not undo every database or persistent-data change.
For a compromised host, isolate it, rotate affected credentials, restore or rebuild a trusted environment, and re-enroll if its machine identity is no longer trusted before restoring service traffic. If an unused install authorization expires or is revoked, request a fresh authorized setup command; do not confuse an enrollment problem with a running-service failure.