Install on VMware (OVA)
Data Security for Dell AI Infrastructure can run as a VMware virtual appliance. The console, its databases (PostgreSQL and ClickHouse), and its web server run inside one virtual machine. The compute-heavy pipeline agents (extraction, linguistic coherence, and classify) run on Linux hosts that you provide and are installed from the console afterwards.
To run everything on Kubernetes instead, see Install on Kubernetes (Helm).
Requirements
- Appliance package: an OVF template downloaded from the Superna support site, named
<Brand>_AISecConsole.<version>-<build>-<os>.x86_64.ovf, with its-disk1.vmdkand.mffiles. vSphere lists it as Superna AI Security Console Appliance. - vSphere host: supports virtual machine hardware version 21 and has capacity for the virtual machine below.
- Network settings: a static IPv4 address with its netmask and default gateway, plus your DNS servers. DHCP is not supported. A hostname, DNS search domains, and NTP servers are optional.
- Network access: browsers and agent hosts reach the appliance on port 443. Port 80 redirects to it. The appliance needs no internet access to install, so use it for an air-gapped site.
Inside the VM, the containers use the 172.19.0.0/16 range. Do not place devices or agent hosts that the appliance must reach in that range.
Virtual machine resources
The template sets these resources:
| Resource | Value |
|---|---|
| vCPU | 10 |
| Memory | 100 GB |
| Network | 1 adapter (VMXNET3), on the network you map to mgmt |
| System disk | 60 GB (openSUSE Leap 16.0) |
| Console data disk | At least 40 GB |
| PostgreSQL data disk | At least 40 GB |
| ClickHouse data disk | At least 900 GB. Size it for your audit volume and retention. |
First boot stops if the VM has fewer than 10 vCPUs or less than 96 GiB of memory, so do not reduce them.
Deploy the OVF template
- In the vSphere Client, select Deploy OVF Template and choose the
.ovf,-disk1.vmdk, and.mffiles. - Select the name, folder, compute resource, and datastore. Map the mgmt network to the network the appliance should use.
- On Customize template, enter the settings in the table below.
- Finish the wizard and power on the VM.
| Setting | Value |
|---|---|
| mgmt IP Address, mgmt Netmask, mgmt Default Gateway | The static address of the appliance. The netmask defaults to 255.255.255.0. |
| Hostname | Optional. For example, aisec-console-prod-01. |
| DNS Servers | Space-separated DNS server addresses. |
| Domain Search List | Optional. Space-separated. |
| NTP Servers | Space-separated. Recommended, because VMware Tools does not sync the appliance clock with the host. |
| Console / PostgreSQL / ClickHouse data disk size (GB) | At least the minimums in the previous table. |
The appliance assigns the data disks by size, from smallest to largest: console, PostgreSQL, ClickHouse. Keep the console disk no larger than the PostgreSQL disk, and the PostgreSQL disk no larger than the ClickHouse disk. Otherwise the roles swap.
Complete first boot
On first start, the appliance sets itself up without internet access. This takes up to 15 minutes. It:
- Formats and mounts the data disks.
- Applies the network settings.
- Generates the database passwords and a self-signed certificate.
- Starts its services and loads the pipeline agent images.
- Opens ports 443 and 80 in its firewall.
Progress appears on the VM console and in /var/log/aisec-console-firstboot.log.
Enter the network settings manually
If you did not enter the IP settings, or the VM is not on VMware, first boot pauses.
-
Log in at the VM console as
adminwith the default password3y3gl4ss. -
Run the setup command:
sudo aisec-setup-network -
Enter the address, netmask, and gateway. DNS servers, search domains, NTP servers, and hostname are optional. First boot then resumes.
To display the current settings, run sudo aisec-setup-network --status.
Recover from a failed first boot
If first boot fails, for example because a data disk is below its minimum or the VM has too little memory, fix the cause and restart the first-boot service:
sudo systemctl restart aisec-console-firstboot.service
Log in for the first time
- Browse to
https://<appliance-ip>/and accept the certificate warning. The appliance uses a self-signed certificate that includes its IP address. - On the first visit, the console asks you to create its administrator account. Enter a username and a password of at least 8 characters.
- Continue with the Quick Start Setup Guide.
The operating-system account of the appliance is admin, with full sudo. The root account is locked. The default password is 3y3gl4ss.
Every appliance ships with the same default operating-system password. Change it the first time you log in with passwd admin.
Install the pipeline agents
The agents run on Linux hosts with Docker that you provide.
- Open the console by its DNS name, if you want the agents to use that name. Do this before you copy the one-line installer.
- Go to System Operations > Fleet Management > Agent Installation and generate the enrollment credentials.
- Run the one-line installer on each agent host. The hosts download the agent images from the appliance over port 443.
The page lists the host requirements and the ports that agent hosts need between them. For details, see Agent Installation.
Upgrade
Each release has three parts, all downloaded from the Superna support site.
| Part | How to apply |
|---|---|
| Console | Upload the console tar on Settings > Software Update and click Apply Upgrade. Expect about 1 to 2 minutes of downtime. A failed upgrade reverts on its own. Alternatively, run sudo aisec-upgrade <tar> from the appliance shell. See Software Update for details and rollback. |
| Platform update | A .run file that updates the scripts, services, and configuration of the appliance. See the procedure below. |
| Pipeline agent images | Upload the new image for each stage on Agents Upgrade and roll it out to your agent hosts. |
To apply the platform update:
-
Copy the
.runfile to the appliance. -
Preview the update:
bash aisec-console-installation-update-<version>.run --dry-run -
Apply the update:
sudo bash aisec-console-installation-update-<version>.run
The --rollback option restores the previous platform update and reinstalls the services and helpers of that version. It does not change the console version.
Operate the appliance
Maintenance operations
Only one maintenance operation can run at a time. The platform update, aisec-apply-sizing set, aisec-reset-credentials, and aisec-os-patch (when it stops the application or reboots) each refuse to start while another operation or a software update is in progress. They fail with Another maintenance operation is running (exit code 9).
While an operation runs, a Software Update upload or apply fails. Retry when it finishes. To see what holds the lock, run:
sudo fuser -v /run/lock/aisec-console-maintenance.lock
Memory limits
Change the memory limits of the console and databases from the shell, not the web UI:
sudo aisec-apply-sizing show
sudo aisec-apply-sizing set KEY=VALUE
The command checks that the new limits fit the VM and restores the previous values if a service does not come back healthy.
Do not apply a PostgreSQL tier under Settings > Database > Sizing on the appliance. Those tiers are sized for other deployments and break its PostgreSQL.
Database passwords
Rotate the database passwords with sudo aisec-reset-credentials. Add --dry-run to preview.
Operating-system patches
Patches are applied automatically:
- The package list is refreshed daily.
- Patches of all categories are installed weekly, without rebooting.
- A patch that updates Docker restarts all services of the appliance. This means a minute or more of downtime and interrupts any update in progress.
Run sudo aisec-os-patch status to show the state. Run sudo aisec-os-patch disable-auto to turn automatic patching off.
Data disks
You can enlarge the data disks in vSphere while the appliance runs. The appliance grows the filesystem within 5 minutes.
Backups
Back up the whole virtual machine with your VM backup software, using a standard block-level backup. This is the only way to back up the ClickHouse data.
Settings > Backup & Restore saves a PostgreSQL dump, the settings with their encryption key, and the logs, but not ClickHouse. See Backup.
Troubleshooting
Start with these commands:
sudo bash /opt/superna/installation/scripts/verify-zero-touch.sh
systemctl status aisec-console-app aisec-console-postgres aisec-console-clickhouse aisec-console-upgrade-watcher
sudo journalctl -u aisec-console-app.service -b
sudo aisec-upgrade --status
| Topic | What to do |
|---|---|
| Overall check | verify-zero-touch.sh checks the whole appliance and ends with ALL CHECKS PASSED when it is healthy. curl -k https://127.0.0.1/api/health on the appliance checks the console alone. |
| First-boot log | /var/log/aisec-console-firstboot.log |
| Console log | sudo journalctl -u aisec-console-app.service. docker logs works only while the container runs. |
| Database logs | sudo journalctl -u aisec-console-postgres.service -u aisec-console-clickhouse.service |
| Upgrade logs | /opt/superna/upgradeimages/upgrade-watcher.log (UTC timestamps) and /var/log/aisec-console-upgrade-cli.log |
| Restart a service | sudo systemctl restart aisec-console-app (or aisec-console-postgres, aisec-console-clickhouse). Do not use docker restart or docker stop on the containers of the appliance, because systemd runs them. |
| Database service stops with exit code 78 | Its container image is missing. The appliance never downloads images, so load the image again. |
| A tool exits with code 9 | Another maintenance operation is running. See Maintenance operations. |