SecDeploy — release train & deployer¶
SecDeploy turns the suite’s independent components into one versioned product: it pins a compatible, tested set of component tags (a suite “bill of materials”) and stands the whole stack up on each supported target, from a single command — air-gap friendly.
What it does¶
One suite manifest (
suite.toml) pins every component’s version for a release, so deploying a suite version gives you exactly that combination on any target.Optional identity & trust tier — SecCert, SecSSO, and secdns are the “start-from-zero” CA/IdP/DNS stack; provide them, or drop any you already run with
--without.Multi-host placement via
secsite.toml— describe your hosts and which tier (identity / inference / gateway / collab / edge) runs where, with an interactiveconfigurewizard (CLI or a local web page).Two supported targets —
macos(Docker Compose eval box) andfedora-fips(native, hardened systemd services linking the system OpenSSL FIPS provider, for production).Air-gapped bundles — build on a connected host, carry one checksummed tarball into the enclave, and deploy offline.
Whole-suite operations — backup/restore into one FIPS-encrypted archive, deploy-audit hash-chain verification, and a suite-wide evidence command that pulls every reachable component’s evidence bundle into one file.
Quickstart¶
uv run secdeploy verify # validate the manifest + target assets
uv run secdeploy plan macos # show pinned versions + steps for a target
uv run secdeploy fetch # checkout every component at its pinned ref → ./work
uv run secdeploy deploy macos # stand the suite up
Learn more¶
SecDeploy on GitHub — source, issues, releases.
SecDeploy docs — get-started, configuring a site, per-target deploy guides, feature docs (voice, agent pool, analysis sidecars), and the compliance mapping.