claude-haiku-4-5
Install the customer control plane on an existing cluster.
This operator path installs the multi-service Clavenar stack and full operator console on Kubernetes or K3s. It is separate from the local clavenar‑lite developer quickstart and never creates, reconfigures, or deletes a cluster.
- 1. Prerequisites and scope
- 2. Choose Brain providers
- 3. Read-only preflight
- 4. Install the customer stack
- 5. Register the First Admin
- 6. Automation and evaluation
- 7. Optional operator mTLS
- 8. Safe uninstall
- 9. Advanced configuration
1 · Prerequisites and scope
- An existing Kubernetes or K3s cluster. Cluster provisioning, node configuration, networking, and storage installation remain operator responsibilities.
- A working
kubectlork3s kubectlcontext for the intended cluster. - Helm 3.16+ and permission to inspect and manage the target release resources.
- A default StorageClass and Kubernetes version supported by the installer preflight.
Looking for a local developer evaluation? Use the Clavenar Lite quickstart. It needs no Kubernetes cluster, Helm release, operator passkey, or Console port forward.
Choose generation and embeddings independently.
The credential-free default is deterministic mock mode. A live hosted provider uses an existing Kubernetes Secret reference; API-key bytes never enter Helm values, command arguments, installer output, or the non-secret receipt. The installer checks only the credentials selected by your flags and fails before mutation with the exact missing Secret and key.
Adapter-compatible is not qualified. No live model is qualified yet. The adapters and installer flags are available for controlled evaluation, but every candidate remains experimental until a current live receipt passes the published security, schema, latency, and cost gates.
Current model qualification matrix
gpt-4o-mini
gemini-3.5-flash-lite
anthropic.claude-3-5-haiku-20241022-v1:0
gemini-2.0-flash
llama3.2
0 / 2 hosted provider kinds have a current passing live receipt.
0 / 1 local provider kind has a current passing live receipt.
The machine-readable qualification policy and support matrix pins the exact 92-case corpus, three-run thresholds, and evidence-derived status. The receipt schema forbids a mock run from becoming support-eligible. A customer may evaluate an experimental target in its own environment; that does not change Clavenar's published support status.
For the lowest-cost current hosted option, create a Google AI API key, store it in an existing Kubernetes Secret, and select Google explicitly. Both Brain tiers then use gemini-3.5-flash-lite. The key travels through standard input rather than a process argument:
# Run in the shell that already holds the provider key. export CLAVENAR_BRAIN_GOOGLE_API_KEY="..." kubectl --context my-cluster create namespace clavenar \ --dry-run=client --output=yaml | \ kubectl --context my-cluster apply --server-side \ --field-manager=clavenar-provider-bootstrap -f - printf %s "$CLAVENAR_BRAIN_GOOGLE_API_KEY" | \ kubectl --context my-cluster --namespace clavenar \ create secret generic clavenar-brain-provider \ --from-file=google-api-key=/dev/stdin \ --dry-run=client --output=yaml | \ kubectl --context my-cluster apply --server-side \ --field-manager=clavenar-provider-secret -f - curl -fsSL https://clavenar.ai/install.sh | \ sh -s -- --context my-cluster --brain-provider google
Get the key from Google AI Studio. Anthropic uses --brain-provider anthropic with Secret key anthropic-api-key; OpenAI uses --brain-provider openai with openai-api-key. Ollama needs no Secret and accepts --brain-base-url. Override the provider defaults with --brain-fast-model and --brain-deep-model only for an explicitly reviewed evaluation; a custom model remains experimental unless the published matrix links a current passing receipt.
Persona-drift embeddings are disabled by default and have no fallback. To add Voyage, provision clavenar-brain-embedding key voyage-api-key with the same stdin pattern, then run:
curl -fsSL https://clavenar.ai/install.sh | \
sh -s -- --context my-cluster \
--brain-provider anthropic \
--embedding-provider voyage
Embedding choices are disabled, voyage, openai, and ollama. Use --embedding-model, --embedding-dimensions, and --embedding-base-url for an explicit identity. An OpenAI embedding can reuse the selected OpenAI generation Secret automatically; other hosted combinations default to the separate embedding Secret.
Omit provider flags to keep mock generation and disabled embeddings. This is useful for deterministic infrastructure validation but is not a live-model configuration.
The installer reports the exact namespace/Secret and data key to create. It never opens an interactive API-key prompt or silently substitutes mock mode for an explicitly selected live provider.
Rotate or roll back a provider credential
Keep the previous credential available in your secret manager until the new Brain pod is ready and a real provider-backed canary succeeds. Replace the existing Secret atomically, then restart only Brain so its environment projection is re-read. The key stays in a mode-restricted file and never appears in shell history or Helm values:
# Example for the default Anthropic Secret. Use the selected provider's key name.
kubectl --context my-cluster --namespace clavenar \
create secret generic clavenar-brain-provider \
--from-file=anthropic-api-key=/secure/provider-key.next \
--dry-run=client --output=yaml | \
kubectl --context my-cluster apply --server-side \
--field-manager=clavenar-provider-secret -f -
kubectl --context my-cluster --namespace clavenar \
rollout restart deployment/clavenar-brain
kubectl --context my-cluster --namespace clavenar \
rollout status deployment/clavenar-brain --timeout=5m
Authentication and credential failures stop on the selected target; Clavenar does not replay them to a fallback provider. Automatic fallback is available only in an explicitly reviewed external v2 routing ConfigMap and only for replay-safe availability failures. Watch the Brain provider-route dashboard by workload, provider alias, model, outcome, latency, and bounded fallback reason before retiring the old credential.
Rollback: reapply /secure/provider-key.previous to the same Secret key, restart Brain, and wait for readiness again. For an external routing ConfigMap, restore the previous complete routing document and restart Brain in the same transaction. Do not combine a credential rotation with model, endpoint, fallback-order, or policy changes; that makes a failed canary ambiguous.
Inspect the target without changing it.
The check validates cluster identity, version, node readiness, storage, permissions, release ownership, rendered manifests, and exact image digests. It creates no cluster resource or credential.
# Name the context explicitly for an auditable, non-interactive check.
curl -fsSL https://clavenar.ai/install.sh | \
sh -s -- --context my-cluster --check --yes
The installer reports that the read-only preflight completed and identifies the exact context, release, namespace, chart, and stack version.
Resolve the reported context, Kubernetes version, readiness, StorageClass, permission, ownership, or rendering error before running the install.
Converge the full customer stack.
Run the stable bootstrap from an operator workstation or directly on the cluster host. Interactive mode confirms the selected context and shows the complete plan before mutation.
# Default customer install: full Console with passkey authentication.
curl -fsSL https://clavenar.ai/install.sh | sh
This shortest command keeps Brain in credential-free mock mode and embeddings disabled. Use the live-provider command from step 2 for a semantic customer deployment; an explicit live selection never falls back to mock when its Secret is missing.
The bootstrap verifies its immutable installer payload and release assets before execution. The installer records ownership, converges the Helm release, waits for bootstrap Jobs and workloads, exercises tools/list, proves that the Ledger chain advanced, and writes a non-secret receipt ConfigMap.
The default operator profile enables the full role-gated WebAuthn Console, disables anonymous demo access, and prepares one First Admin passkey registration. A customer install never falls back to the demo console.
The final summary reports ready workloads, exact digest images, an advanced Ledger chain, and a one-use First Admin setup URL.
Rerun the same command to verify or repair the exact owned release. The installer fails closed on a foreign release or unsupported downgrade.
Register the First Admin in Chrome.
The default passkey flow uses localhost and normal browser WebAuthn. There is no client certificate, PKCS#12 import, or local CA to trust.
# Cluster reachable directly from the computer where Chrome runs: kubectl --context my-cluster --namespace clavenar \ port-forward service/clavenar-console 8085:8085 # Remote server: run this single command where Chrome runs. # Replace USER@SERVER with the cluster host. ssh -t -L 8085:127.0.0.1:8085 USER@SERVER \ "kubectl --namespace clavenar port-forward service/clavenar-console 8085:8085"
Paste the exact one-use http://localhost:8085/register#bootstrap=... URL printed by the installer into Chrome. The setup token travels in the URL fragment, is removed from browser history before the ceremony request, and is never written to the installer receipt. The deployment bootstrap cannot create a second Admin.
Chrome completes the platform-passkey or security-key ceremony and opens the authenticated, role-gated Console.
Keep the port-forward command running, use the exact URL printed by the installer, and confirm that local port 8085 is available.
Keep unattended installs explicit.
Automation must name its Kubernetes context. The evaluation profile is a deliberate demo-only opt-in and is not a customer installation shortcut.
# Non-interactive customer installation. curl -fsSL https://clavenar.ai/install.sh | \ sh -s -- --context my-cluster --yes # Explicit evaluation only: anonymous demo access is enabled. curl -fsSL https://clavenar.ai/install.sh | \ sh -s -- --context my-cluster --profile evaluation
Use --profile evaluation only for a disposable evaluation environment. Production and customer environments use the default operator profile or an explicitly reviewed custom-values path with anonymous demo access disabled.
Select native client certificates only when required.
Passkey authentication is the customer default. Environments with an explicit browser-certificate requirement can instead provide public operator trust or create a local Admin credential outside the cluster.
Select --console-auth mtls. Supply an existing public CA and operator registry with --operator-ca and --operator-registry, or use --operator-bootstrap-dir to create the local credential bundle. Only public trust reaches Kubernetes; signer and client private keys stay outside the cluster.
curl -fsSL https://clavenar.ai/install.sh | \
sh -s -- --context my-cluster --console-auth mtls \
--operator-ca /secure/public/ca.crt \
--operator-registry /secure/public/operators.json
# Or create a local Admin credential in an operator-controlled directory.
curl -fsSL https://clavenar.ai/install.sh | \
sh -s -- --context my-cluster --console-auth mtls \
--operator-bootstrap-dir /secure/operator-bootstrap
Remove workloads without silently deleting state.
Persistent data and the namespace are retained by default. Data deletion is a separate destructive operation with exact target confirmation.
The chart-managed shared authentication Secret is retained so the one-time Admin bootstrap and existing HIL sessions cannot reset silently. An optional public-only operator trust registry is also retained; it contains no signer or client private key. The uninstaller verifies its immutable payload, cluster identity, Helm release, installer receipt, and PVC retention policy before showing its plan. It never deletes the namespace.
# Read-only uninstall preflight. curl -fsSL https://clavenar.ai/uninstall.sh | \ sh -s -- --context my-cluster --check --yes # Remove the Helm release; retain namespace and persistent data. curl -fsSL https://clavenar.ai/uninstall.sh | sh # Non-interactive removal must name the context. curl -fsSL https://clavenar.ai/uninstall.sh | \ sh -s -- --context my-cluster --yes
Destructive operation. The command below removes only chart-created PVCs after both the flag and exact namespace/release token are supplied. Claims provided through existingClaim values are not selected.
curl -fsSL https://clavenar.ai/uninstall.sh | \
sh -s -- --context my-cluster --yes --delete-data \
--confirm-data-deletion clavenar/clavenar
Move from the safe default only with an explicit requirement.
The installer owns the standard customer path. Use the operator recipes for custom Helm values, external PostgreSQL, SAML, notifications, observe-mode rollout, and evidence egress.
The lifecycle is governed by clavenar.cluster-install/v1. The public package, image, and Helm release matrix is governed by clavenar.external-install/v1. Protected publication runs the public commands in a disposable acceptance cluster, repeats installation to prove the idempotent verify path, and retains source and cluster receipts.