Secure deployment: operate a private instance
For LLMs4 sections
Audience
Section titled “Audience”Operators who run Arxo for one organization: install it, serve it over HTTP, watch it, scale it, upgrade it, and prove each step. Not for canon authors (see the language and recipes topics) and not for end users asking questions (see the guide topic).
Prerequisites
Section titled “Prerequisites”- A host you control and a checkout or image of the tree.
- The trust habit of this section: every endpoint, flag, variable, and status in these articles exists in code, or is marked as a synthetic created-example. Load numbers, tokens, hostnames, and schedules are always synthetic; mechanisms are always real.
- Section vocabulary, used the same way in every article: “default” is what the code does unconfigured; “implementation limit” is what the code cannot do; “reference setting” is a value the tree recommends (Dockerfile, CI, code comment); “operator policy” is your decision, with a marked example. “Verified”, “supported”, “secure”, and “isolated” are scoped where they are used — the binding definitions live in Verification and support matrix.
Route map
Section titled “Route map”Read in order the first time; each article also stands alone. The section runs two branches — serve (the main route) and MCP — and every shared article opens with an “Applies to” table.
Serve branch (main route):
- 01 — Deployment overview: pick the surface and its trust boundary.
- 02 — Private HTTP service with law serve:
run a journaled
law serveinstance end to end. - 04 — Configuration reference: every knob in one place, with defaults and sources.
- 15 — Upgrades and compatibility, 16 — Backup and restore, 17 — Rollback: the serve lifecycle.
- 20 — Verification and support matrix: acceptance branch, checks S1–S10.
MCP branch:
- 03 — Private MCP server: local stdio and own HTTP:
run
law-mcp-serverfor one agent or as your own endpoint. - 05 — HTTP, TLS, and the verified reverse proxy, 07 — Tool profiles and input policy: edge and tool boundary.
- 18 — Capacity planning and scaling: measure the served endpoint, scale identical slices.
- 20 — Verification and support matrix: acceptance branch, checks M1–M8.
Shared, with per-branch rows:
- 06 — Authentication and access control, 08 — Data flow, storage, and retention, 09 — Logs, audit trail, and decision journals, 10 — Runtime filesystem isolation, 11 — Resource limits and cancellation, 12 — Health and observability, 13 — Install trust artifacts, 14 — Offline and restricted-network operation, 19 — Troubleshooting.
Next step
Section titled “Next step”Pick your branch in Deployment overview, then follow it top to bottom; harden (06–12) before exposing anything beyond loopback.
Documentation for Arxo. Writings — blog.arxo.io.
Anonymous visit counts on stats.arxo.io, no cookies.