Cenovel / Deploy

Install the appliance

Prepare a customer-managed native appliance and verify the release before use.

Before you begin

Confirm the release bundle, trusted public key, VM resources, storage mounts, console DNS name, and TLS certificate plan with your deployment owner. The native installer targets Debian 13 amd64.

Installation tooling exists in the source, but the recorded vSphere acceptance programme has not been executed on real hardware. These instructions are not a production acceptance certificate or a promise of downloadable OVA media.

Install from a verified release

The native installer accepts a signed .cenovel bundle and a trusted public key. Follow the installation procedure supplied with that release; check the database and application data mounts before activating services.

Secure the recovery account

Native first boot creates a recovery passphrase. Store it in the district password manager before removing its display copy.

cenovelctl recovery show
cenovelctl recovery acknowledge

Configure the console

Set the native console address in /etc/cenovel/appliance.conf, validate it, and restart the API, worker, and Caddy when changing deployment configuration.

cenovelctl config check
systemctl restart caddy cenovel-api cenovel-worker

The supplied Caddy configuration uses an internal CA. Establish trust on staff workstations or provision a district certificate before using the console.

Check the installed appliance

cenovelctl status
cenovelctl health
cenovelctl diagnose

Sign in with the configured local recovery account, then configure staff access and an off-box backup destination.

Read the operator reference
2. Native installation and first checks

Confirm release media, the trusted release public key, VM resources, data
mounts, DNS, and TLS with the deployment owner. The native installer accepts
a signed .cenovel release bundle; it verifies the bundle before staging the
release. These instructions do not promise downloadable OVA media.

Native first boot provisions protected credentials and the local recovery
passphrase. Save the passphrase in the district password manager before
acknowledging it:

    cenovelctl recovery show
    cenovelctl recovery acknowledge

Acknowledge removes the display copy. Native console deployment settings,
including its hostname and public URL, are in /etc/cenovel/appliance.conf.
Validate changes and restart the affected services:

    cenovelctl config check
    systemctl restart caddy cenovel-api cenovel-worker

The supplied Caddy configuration uses an internal CA. Establish trust on
staff workstations or provision the district's certificate. Then check:

    cenovelctl status
    cenovelctl health
    cenovelctl diagnose

Reviewed against the current source code. Native appliance administration commands require the appropriate host privileges; validate deployment procedures on your own release before production use.