NAVIGATION
ELOWEN DOCUMENTATION

Last updated: 10 October 2026

Browse documentation · Installer and setup ownership
Developer reference

Installer and setup ownership

Installer and setup ownership

src/cli/install/index.ts orchestrates preparation, licence gating, activation and recap. installArgs.ts owns the shared InstallPlan, unattended flag validation and help text; both installer front ends execute the same plan. The module parses flags without host I/O. systemdUnits.ts owns the SYSTEMD_UNITS inventory after its path constants, alongside the pure unit renderers. Install, privileged refresh and uninstall import that same inventory.

install/updateCoordinator.ts owns provisionSudoers and convergeUpdateCoordinator, used by installer preparation and privileged refresh. It remains at the install module's package depth so executable resolution is unchanged. Refresh reads the elowen-update.service unit that the update timer starts, including its identity and literal environment, validates the staged sudoers drop-in with visudo -cf before installation, then updates the coordinator and queue watcher. Identical trusted files are skipped; only a changed watcher is restarted. There are no contributions or alternative inventory paths. These operations keep their existing root trust checks, file bytes, command order and cost.

src/cli/setup.ts owns probeSetup(fetchFn, base), the single decoder of the daemon's /setup response. A successful response must contain boolean needsSetup and licenceLocked fields. HTTP, JSON and shape failures throw; transport and JSON errors retain their identity. isFirstRun and the setup command propagate/refuse failures instead of assuming an admin exists. Installer licence readiness catches failures and polls within its existing deadline; it accepts only a valid unlocked response. Each attempt uses one HTTP request and one schema validation, with no persistent state.

The installer's readiness wait is waitForActiveLicence(base) in src/cli/install/index.ts. It defaults to a 20-second budget and probes /setup every 500 ms, and it returns true only when the probe succeeds with licenceLocked false. elowen setup (src/cli/setup/command.ts) calls assertLicenceUnlocked before the wizard. A failed probe or a locked licence stops it with exit code 1. Probes are made through probeSetup in three places: the installer, isFirstRun and the setup command.

The rest of src/cli/setup.ts holds the wizard's HTTP helpers. login signs in through /auth/login. createAdmin posts to /users and then logs in. saveConfig sends a PUT /config with a brain section only, and does nothing when the plan has no provider. buildSetupPlan maps the answers to that plan, storing a blank API key as absent, and applySetup runs the account creation and config save together. Setup writes through the daemon's API, not the database.