Skip to content
docs
Arxo ↗

Secure deployment: operate a private instance

For LLMs4 sections

Operators who run Arxo for one organization: install it, serve it over HTTP, watch it, scale it, upgrade it, and prove each step. Not for canon authors (see the language and recipes topics) and not for end users asking questions (see the guide topic).

  • A host you control and a checkout or image of the tree.
  • The trust habit of this section: every endpoint, flag, variable, and status in these articles exists in code, or is marked as a synthetic created-example. Load numbers, tokens, hostnames, and schedules are always synthetic; mechanisms are always real.
  • Section vocabulary, used the same way in every article: “default” is what the code does unconfigured; “implementation limit” is what the code cannot do; “reference setting” is a value the tree recommends (Dockerfile, CI, code comment); “operator policy” is your decision, with a marked example. “Verified”, “supported”, “secure”, and “isolated” are scoped where they are used — the binding definitions live in Verification and support matrix.

Read in order the first time; each article also stands alone. The section runs two branches — serve (the main route) and MCP — and every shared article opens with an “Applies to” table.

Pick your branch in Deployment overview, then follow it top to bottom; harden (06–12) before exposing anything beyond loopback.

Documentation for Arxo. Writings — blog.arxo.io.

Anonymous visit counts on stats.arxo.io, no cookies.