Operator Guide
This guide is for whoever deploys LyEve and keeps it running, from a trial on a laptop to a
production install with paying tenants. LyEve ships as two container images, the engine
(ghcr.io/lyeve-labs/lyeve-core) and the admin console (ghcr.io/lyeve-labs/lyeve-admin),
on PostgreSQL, MySQL 8+ or SQL Server. The pages below hold the detail.
Your first hour
Section titled “Your first hour”- Installation: run the engine and the admin console, and the settings a production engine refuses to start without.
- Quickstart: create the first administrator with the setup token and check the engine answers.
- Docker Compose: both images and the proxy in front of them, the shortest path to a working console.
- Configuration: every setting, and a minimal production environment.
- Harden your instance: secrets, signing, cookies, CORS, proxies and rate limits.
- Production checklist: what to confirm before you go live.
Common jobs
Section titled “Common jobs”| I need to... | Read |
|---|---|
| Pick a host for the engine, the console and the database | Deployment |
| Run on free hosting | Free-tier overview |
| Run on Kubernetes | Kubernetes |
| Apply a license, or see what it grants | Licensing and tiers |
| Choose which features start | Licensing and tiers |
| Run more than one replica | Scaling |
| Back up and restore one tenant | Back up and restore tenants |
| Move content in from another system, or move the database | Migrate existing content |
| Serve several customers from one install | Tenants |
| Copy configuration from staging to production | Promote configuration |
| Store media in S3 or another bucket | Object storage |
| Send email | |
| Point health checks at the right path | Health, metrics and debugging |
| Work out why a request fails | Troubleshooting |
Watch a running instance
Section titled “Watch a running instance”Each tool answers one question best.
| Question | Use | Needs |
|---|---|---|
| What happened, and what did this one request do? | Logs: search, live tail, levels you change without a restart, shipping to Loki or Elasticsearch | Free |
| How do the numbers move over time? | Metrics export: Prometheus scraping, or pushes to an OTLP collector, Datadog or New Relic | Free |
| Which errors are new, and is one spiking? | Error tracking: errors grouped and triaged, with trends and an alert on a spike | Free, with email alerts and 30 days of events. Chat, PagerDuty and webhook alerts and older events need alerts-pro |
| What exactly did that call send and get back? | Request capture: recent requests, a diff of two, and a replay | Free |
| Which endpoints are slow, and where does the time go? | Request profiling: the slowest endpoints, CPU and heap profiles, a flame graph | Free |
| Which database queries are slow, and what index would help? | Slow query analysis: query plans and index suggestions | query-monitor |
| Is the endpoint up, seen from outside? | Synthetic monitoring: scheduled checks with an alert after repeated failures | Free up to three probes per tenant. More, or more often, needs synthetic-monitoring-pro |
| Who calls what, how often, and how fast? | API analytics: volume, error rate and latency by endpoint, tenant and client | apianalytics |
| Did a scheduled job stop working? | Alerts: an email, a chat message, a PagerDuty incident or a signed webhook after repeated failures | Free by email. The other channels need alerts-pro |
| Is one tenant using more than its share? | Tenant quotas: request, storage and bandwidth limits per tenant, with warnings and blocking | usage-pro |
Related
Section titled “Related”- Deployment: every host guide.
- Security controls: what a running install enforces, and how to check it.
- Developer guide: what the people building on your instance read.