docs← Back to article

Markdown for LLMs

Secure deployment: operate a private instance

The source Markdown for this article. Copy it into your assistant or download it as a text file.

Download this articlePlain text ↗
# Secure deployment: operate a private instance

## Audience

Operators who run Arxo for one organization: install it, serve it
over HTTP, watch it, scale it, upgrade it, and prove each step. Not
for canon authors (see the language and recipes topics) and not for
end users asking questions (see the guide topic).

## Prerequisites

- A host you control and a checkout or image of the tree.
- The trust habit of this section: every endpoint, flag, variable,
  and status in these articles exists in code, or is marked as a
  synthetic created-example. Load numbers, tokens, hostnames, and
  schedules are always synthetic; mechanisms are always real.
- Section vocabulary, used the same way in every article:
  "default" is what the code does unconfigured; "implementation
  limit" is what the code cannot do; "reference setting" is a
  value the tree recommends (Dockerfile, CI, code comment);
  "operator policy" is your decision, with a marked example.
  "Verified", "supported", "secure", and "isolated" are scoped
  where they are used — the binding definitions live in
  [Verification and support matrix](/operate/verification-support-matrix/).

## Route map

Read in order the first time; each article also stands alone.
The section runs two branches — serve (the main route) and MCP —
and every shared article opens with an "Applies to" table.

Serve branch (main route):

- [01 — Deployment overview](/operate/deployment-overview/):
  pick the surface and its trust boundary.
- [02 — Private HTTP service with law serve](/operate/private-http-service/):
  run a journaled `law serve` instance end to end.
- [04 — Configuration reference](/operate/configuration-reference/):
  every knob in one place, with defaults and sources.
- [15 — Upgrades and compatibility](/operate/upgrades-compatibility/),
  [16 — Backup and restore](/operate/backup-restore/),
  [17 — Rollback](/operate/rollback/): the serve lifecycle.
- [20 — Verification and support matrix](/operate/verification-support-matrix/):
  acceptance branch, checks S1–S10.

MCP branch:

- [03 — Private MCP server: local stdio and own HTTP](/operate/private-mcp-server/):
  run `law-mcp-server` for one agent or as your own endpoint.
- [05 — HTTP, TLS, and the verified reverse proxy](/operate/http-tls-reverse-proxies/),
  [07 — Tool profiles and input policy](/operate/tool-profiles-input-policy/):
  edge and tool boundary.
- [18 — Capacity planning and scaling](/operate/capacity-scaling/):
  measure the served endpoint, scale identical slices.
- [20 — Verification and support matrix](/operate/verification-support-matrix/):
  acceptance branch, checks M1–M8.

Shared, with per-branch rows:

- [06 — Authentication and access control](/operate/authentication-access-control/),
  [08 — Data flow, storage, and retention](/operate/data-flow-storage-retention/),
  [09 — Logs, audit trail, and decision journals](/operate/logs-audit-decision-journals/),
  [10 — Runtime filesystem isolation](/operate/runtime-filesystem-isolation/),
  [11 — Resource limits and cancellation](/operate/resource-limits-cancellation/),
  [12 — Health and observability](/operate/health-observability/),
  [13 — Install trust artifacts](/operate/install-trust-artifacts/),
  [14 — Offline and restricted-network operation](/operate/offline-restricted-network/),
  [19 — Troubleshooting](/operate/troubleshooting/).

## Next step

Pick your branch in [Deployment overview](/operate/deployment-overview/),
then follow it top to bottom; harden (06–12) before exposing
anything beyond loopback.