Capability

Appliance and app catalog

Bring up a known local runtime, add only the catalog apps you need, and use the same lifecycle for additional packaged runtimes.

Enrolled appliance

Encrypted bootstrap path

Managed app catalog

Schema-guided configuration

Operational need

Teams need a supportable local path for collection, scanning, relays, and execution without hand-building another platform to operate.

The team gets a practical local platform whose bootstrap, selected apps, current health, changes, and failures stay visible instead of becoming a bespoke infrastructure project.

Operating signals

  • The operating workflow is useful, but monitoring, scanning, relay, or endpoint capability is missing at one or more sites.
  • An app was requested, but operators cannot tell whether its desired configuration is actually synced and healthy on the appliance.
  • Local tooling has grown into a custom stack with unclear ownership, upgrade paths, and recovery steps.

What you get

Enrolled applianceEncrypted bootstrap pathManaged app catalogSchema-guided configurationDesired and observed stateReconcile and release pathExtensible app runtime contract

Where it starts

Common starting points.

These examples enter the product surface that owns their state. They do not all become a case, ticket, owner, or shared evidence record automatically.

A new site has no local operations stack. How quickly can it become useful?

Enroll the appliance, import its protected bootstrap material, confirm prerequisites, and initialize a known base runtime before selecting apps.

Which apps fit this appliance and workflow?

Browse the catalog with categories, dependencies, and configuration requirements visible before installation.

Did the requested app configuration actually reach the runtime?

Compare the install state with observed synchronization, health, freshness, and any retained error instead of treating a completed job as proof.

Can an app be changed, repaired, or removed without shell work?

Edit schema-guided configuration and scoped secrets, reapply through reconciliation, or remove the install from the same appliance record.

Which local capabilities can we add without building them ourselves?

Choose from the SRE toolkit, relays, diagram and lint services, monitoring, vulnerability, endpoint, and security apps included in the catalog.

Can the baseline stay supportable as the site changes?

Keep appliance releases, app desired state, observed health, reconciliation, and failure context on explicit product paths.

How do we add another local execution runtime?

Package it through the app lifecycle with a configuration schema, installation path, ingress requirements, reconciliation, and health checks.

How it works

How work moves.

The product path below names its inputs, decisions, controls, and output without implying the same lifecycle applies to every capability.

  1. 01

    Enroll the appliance

    Register the local runtime so its identity, connection state, version, and target environment are visible.

  2. 02

    Pass bootstrap gates

    Confirm the appliance is online, encryption is ready, and its protected bootstrap bundle is present before initialization.

  3. 03

    Choose catalog apps

    Select the required apps and provide their schema-guided configuration and scoped secrets.

  4. 04

    Reconcile and observe

    Apply the requested state through the queue, then compare install status with observed synchronization and health.

  5. 05

    Operate and evolve

    Use app output in wider workflows, reapply or remove apps when needed, and keep the appliance on a known release path.

Product model

Local platform model.

The diagrams show how an appliance moves from enrolled hardware to a protected base runtime, how catalog apps cross into the local environment, and how desired configuration stays separate from observed health.

Appliance deployment

Enrolled appliance to app-ready runtime.

Bootstrap begins only after the appliance is online, encryption is ready, and its protected bundle is present. Phase status and errors stay visible until the local runtime is ready for catalog apps.

Diagram showing appliance enrollment, online and encryption checks, protected bootstrap bundle, phase orchestration, and an app-ready local runtime.

App catalog

Select capabilities instead of assembling a stack.

Catalog apps carry dependency, configuration, secret, ingress, and deployment requirements. Operators choose only what the appliance needs.

Diagram showing an app catalog supplying selected monitoring, security, relay, SRE, and utility apps to an appliance.

App lifecycle

Requested state is checked against running state.

Install, edit, reapply, and removal flow through reconciliation. The product shows requested install state beside observed synchronization, health, freshness, and retained errors.

Diagram showing app configuration and secrets flowing through a reconcile job to desired state, observed synchronization and health, and repair actions.

Support boundary

A known baseline without hiding local ownership.

The platform supplies the appliance lifecycle, catalog definitions, and reconcile path. The customer still chooses sites, apps, configuration, access, and where existing integrations replace or extend local capability.

Diagram separating the GAEZLA-managed appliance and catalog baseline, the local runtime boundary, and customer-owned sites, app choices, configuration, access, and integrations.

What it includes

What the record shows.

These parts participate in the workflow. The record shows what was used and why it mattered.

Local appliance

An enrolled runtime exposes connection, version, bootstrap, health, and lifecycle state from one appliance record.

Appliance inventory, bootstrap, health, and release surfaces

Protected bootstrap

Initialization requires an online appliance, encryption readiness, and a valid per-appliance bootstrap bundle before phases can begin.

Encryption configuration, sealed bundle, preflight, and phase log

App catalog

Catalog entries include category, dependencies, ingress, required capabilities, and configuration schemas; the same contract can carry additional packaged runtimes.

Catalog browser and app detail

App configuration

Operators use app-specific schemas for configuration and manage secrets on the scoped install instead of maintaining ad hoc manifests.

Install wizard, schema forms, secrets, and ingress policies

Reconciliation

Install, update, reapply, and removal create visible work whose finalizer connects queue completion to the requested app state.

Install records, sync jobs, queue, and reconcile log

Observed runtime state

Synchronization, health, observation time, and retained errors show whether requested state matches what is actually running.

Deployment sync, runtime health, freshness, and repair status

Control model

Controls stay specific to the workflow.

Integrations, AI assistance, routines, and agents use different permissions and records. The controls below describe this capability rather than a universal approval model.

Bootstrap cannot start until appliance identity, online state, encryption, and bundle prerequisites are satisfied.

App selection keeps dependencies, required capabilities, and configuration requirements visible before install.

Configuration and secrets are scoped to the selected app install and applied through reconciliation.

A completed execution is not presented as customer-visible success until finalization records the requested change as applied.

Desired install state and observed synchronization and health remain separate so drift and stale observations stay visible.

A local runtime is packaged, configured, and installed as an app so its deployment and health remain governed alongside its API capability.

Value over time

Product path for Appliance.

Bootstrap

Install the base runtime

The defined bootstrap path installs the local runtime and deployment controller.

Configure

Select optional apps

App configuration and installation remain explicit operator actions.

Operate

Inspect lifecycle and status

Reconcile jobs, ingress synchronization, and runtime status remain visible.

Next step

Want to see appliance on your stack?

Book a walkthrough and I will map this workflow to the integrations and controls you already use.