Assisted setup
An optional Claude integration helps translate a reviewed description into pipeline and behavior-policy drafts. It is not needed for manual setup or local Nginx inference.
Enable the credential vault in Docker
Run python3 scripts/setup-env.py --expansion once if you have not already done so. It creates .secrets/credential-key and .env.expansion. Back up that key privately with the database; replacing it prevents recovery of encrypted SSH and provider credentials.
Create compose.credentials.yaml in your product checkout:
services:
api:
environment:
CREDENTIAL_KEY_FILE: /run/secrets/pragma-credentials
volumes:
- ./.secrets/credential-key:/run/secrets/pragma-credentials:ro
The API container runs as UID 10001. Make the key readable by that user through a targeted file ACL or equivalent host ownership policy; retain a private parent directory and do not make it world-readable. Check this against your Docker user-namespace configuration. Start with:
docker compose --env-file .env --env-file .env.expansion \
-f compose.yaml -f compose.behavior.yaml -f compose.credentials.yaml up --build -d
The same vault enables remote SSH credential storage. Native development instead sets CREDENTIAL_KEY_FILE to the private host path generated by setup.
Configure Claude in Assisted setup with a model available to your account. The provider key uses the same externally keyed credential vault as SSH credentials. Each request sends only the explicitly reviewed description, registered endpoint schemas, and a configuration example. It does not automatically send captured events, SSH details, database contents, or raw requests.
Each job makes one provider call with a 64,000-byte serialized input-context cap and a 4,096 output-token cap. A rolling 24-hour request limit bounds call volume; this is not an exact currency budget. Provider failures do not trigger automatic paid retries. Configure any currency budget in the provider account as well.
Claude generates a structured data-only draft, not just a prose report: pipeline extractors, partition definitions, window definitions, ordered features, limits, and optional behavior policy/action mappings, accompanied by a summary and assumptions. It proposes extractor/partition/window configuration against registered endpoint schemas; Rust validation checks the references. After review, Apply reviewed setup saves the pipeline versions directly; the administrator does not have to retype each field. It does not invent validated training records or automatically activate a model. Rust validates endpoint membership, field references, limits and shadow policy shape. The administrator reviews identity assumptions and business prerequisites before applying it. Pipeline creation and progress markers commit atomically. Applying an associated behavior policy prepares a snapshot and queues training using stable idempotency keys when data is available, then records training and isolated replay results. Empty or inadequate data is reported as needing attention. No module installation, server connection, model activation, or release deployment is exposed to the model.