# Vexa Delivery - [Vexa Delivery](https://delivery.vexa.ai/index.md): Your running self-hosted Vexa service that stays up to date. - [How it works](https://delivery.vexa.ai/how-it-works.md): We publish, your cluster pulls and checks, it rolls out or back, a receipt returns. - [Install](https://delivery.vexa.ai/install.md): Nothing running yet: five steps you run yourself, one command each — or one command for all of them. - [Upgrade](https://delivery.vexa.ai/upgrade.md): You already run Vexa: tell us your setup, get a bundle that fits it. - [Preflight](https://delivery.vexa.ai/preflight.md): Know before first sync whether your cluster will run what the channel delivers. - [The channel](https://delivery.vexa.ai/channel.md): Where your releases live, who may pull them, and how your credential arrives. - [Verify](https://delivery.vexa.ai/verify.md): What your change board can check without contacting Vexa — and exactly how. - [Operations](https://delivery.vexa.ai/operations.md): Day-2: how updates arrive, your production gate, rollback, break-glass. - [The station gate](https://delivery.vexa.ai/station-gate.md): Your specification, checked before a release reaches you — and a dated report of which guarantees held. - [Telemetry ladder](https://delivery.vexa.ai/telemetry-ladder.md): What your side chooses to send back, at which rung, on whose authority. - [What's proven, and where](https://delivery.vexa.ai/tested.md): Every claim in these docs against the run that backs it — and the runs that have not happened yet. - [Security model](https://delivery.vexa.ai/security.md): What runs where, what leaves your cluster, and what you pin. - [For your auditors](https://delivery.vexa.ai/governance.md): What each subscription artifact answers in a change-control review. - [Support](https://delivery.vexa.ai/support.md): Evidence-bound tickets and channel advisories. - [Kubernetes](https://delivery.vexa.ai/environments/kubernetes.md): What a generic Kubernetes cluster must provide before the setup script runs - [GKE](https://delivery.vexa.ai/environments/gke.md): Running the kit on GKE Standard. - [EKS](https://delivery.vexa.ai/environments/eks.md): Amazon EKS — what the provider profile sets, what the cluster must provide, and how far the evidence goes - [AKS](https://delivery.vexa.ai/environments/aks.md): Running the kit on Azure AKS. - [OpenShift](https://delivery.vexa.ai/environments/openshift.md): What an OpenShift project must provide — including shared clusters where you hold a namespace, not the cluster - [vexa_state_report.py](https://delivery.vexa.ai/reference/vexa-state-report.md): What is running here, before you upgrade it. - [vexa_preflight.py](https://delivery.vexa.ai/reference/vexa-preflight.md): Will this cluster run what the channel delivers? - [vexa_smoke.py](https://delivery.vexa.ai/reference/vexa-smoke.md): Did the installed release actually work here? - [vexa_validate.py](https://delivery.vexa.ai/reference/vexa-validate.md): Preflight, install, smoke and bundle in one command. - [bootstrap.sh](https://delivery.vexa.ai/reference/kit-bootstrap.md): Fetch and signature-verify the kit tree from the channel. - [install.sh](https://delivery.vexa.ai/reference/kit-install.md): Install the station: Argo subscription plus admission policy. - [self-update.sh](https://delivery.vexa.ai/reference/kit-self-update.md): Move a bootstrapped kit tree to a newer signed kit version. - [The mail edge](https://delivery.vexa.ai/mail-edge.md): The mailbox is the product's front door — Gmail, generic IMAP, or Microsoft Graph, plus the Graph admin runbook. - [Microsoft 365](https://delivery.vexa.ai/environments/microsoft365.md): What your Microsoft 365 administrator does once, so Vexa can host the Minutes mailbox inside your tenant. - [Acceptance](https://delivery.vexa.ai/engineering/acceptance.md): What must be true before a version of this software is distributed to anyone. - [Engineering](https://delivery.vexa.ai/engineering/index.md): How Vexa Delivery is built, decided and proven — the decision record, the receipts and the plans. - [Durability and disaster recovery](https://delivery.vexa.ai/engineering/durability.md): Git is the record; the bucket is a copy. What a total bucket loss actually costs. - [OpenShift setup and target parity](https://delivery.vexa.ai/engineering/openshift-parity.md): How the delivery station lands on a tenant-scoped OpenShift, how we reproduce that environment for validation, and where each property matches the target - [MVP0 implementation state](https://delivery.vexa.ai/receipts/2026-08-21-mvp0-implementation.md): What is built, what was proven live on the Akamai cluster, and what is not done. - [M2 kit test — throwaway LKE](https://delivery.vexa.ai/receipts/2026-08-21-m2-throwaway-test.md): The customer kit proven end-to-end: install, pull, admit, deny, the prod gate, every preflight failure class. - [Week-exit rehearsal — playing the customer against the live channel](https://delivery.vexa.ai/receipts/2026-08-24-week-exit-rehearsal.md): One agent, no hands: mint the real entry, publish the kit, bootstrap a fresh cluster from nothing but a subscriber credential, install, verify, gate, self-upgrade. Fourteen defects, eleven fixed, three open. - [The signature layout the customer's admission controller can read](https://delivery.vexa.ai/receipts/2026-08-25-signature-layout.md): Measured against live Kyverno 1.19.0: which cosign writes which layout, which layouts admit, which deny, and what the live pilot-stable channel was left holding. - [Verifying our signatures on the real authenticated channel](https://delivery.vexa.ai/receipts/2026-08-25-kyverno-authenticated-channel.md): Kyverno 1.19.0, stock, holding no registry credential of any kind, verifying against live channel.vexa.ai: signed ADMITTED, unsigned DENIED, wrong key DENIED. The fix is anonymous signature reads at the Caddy edge. - [Channel hardening — expiry, revocation, the two-directional contract, the submit path](https://delivery.vexa.ai/receipts/2026-08-25-channel-hardening.md): Four features that live in signed artifacts or customer-pinned config, proven against the live channel, the live edge and a live cluster. Three defects found by running it. - [2026 08 25 dogfood staging](https://delivery.vexa.ai/receipts/2026-08-25-dogfood-staging.md) - [2026 08 25 throwaway clean pull](https://delivery.vexa.ai/receipts/2026-08-25-throwaway-clean-pull.md) - [2026 08 25 throwaway adoption](https://delivery.vexa.ai/receipts/2026-08-25-throwaway-adoption.md) - [2026 08 25 prod adoption](https://delivery.vexa.ai/receipts/2026-08-25-prod-adoption.md) - [CLI reference](https://delivery.vexa.ai/reference/index.md): Every verb the delivery chain exposes, generated from the code. - [vexa_channel.py](https://delivery.vexa.ai/reference/vexa-channel.md): Turn a released Vexa version into a signed channel entry. - [vexa_station.py](https://delivery.vexa.ai/reference/vexa-station.md): Ingest a customer station bundle, then gate publishes on its contract. - [vexa_stations.py](https://delivery.vexa.ai/reference/vexa-stations.md): Read and write the channel/station ledger that outlives the bucket. - [vexa_subscriber.py](https://delivery.vexa.ai/reference/vexa-subscriber.md): Manage credentials on the channel registry. - [release.sh](https://delivery.vexa.ai/reference/kit-release.md): Package and publish a signed version of the customer kit. - [ADR-0001 — Repository charter](https://delivery.vexa.ai/adr/0001-repo-charter.md): vexa-delivery, EE, supersedes the vexa-platform promotion tooling. - [ADR-0002 — Channel format](https://delivery.vexa.ai/adr/0002-channel-format.md): Signed OCI entries, stations as subscriptions, the signing model left open. - [ADR-0003 — Customer kit shape](https://delivery.vexa.ai/adr/0003-customer-kit-shape.md): Stock Argo CD + Kyverno + preflight: we ship configuration, not an agent. - [ADR-0004 — The node model](https://delivery.vexa.ai/adr/0004-node-model.md): Every station is consume → deploy → validate → sign. - [ADR-0005 — Kit license split](https://delivery.vexa.ai/adr/0005-kit-license-split.md): The kit is Apache-2.0; the factory stays proprietary. - [ADR-0006: The internal channel — Vexa is subscriber zero](https://delivery.vexa.ai/adr/0006-internal-channel.md): Our own staging → prod runs on the same channel machinery we sell, fed by candidate entries that accumulate station verdicts - [ADR-0007: The station bundle — deterministic station state](https://delivery.vexa.ai/adr/0007-station-bundle.md): The station's own machinery ships as a signed chart on the channel; one bootstrap object installs the app that installs Vexa - [ADR-0008 — The whole repository is Apache-2.0](https://delivery.vexa.ai/adr/0008-repository-apache-2.md): Open license, private repo, access per person; customer material moves out. - [ADR-0009 — The repository goes public](https://delivery.vexa.ai/adr/0009-public-visibility.md): The visibility decision ADR-0008 explicitly deferred: public, whole repository, on a fresh history. - [Prod migration plan — vexa-production onto the internal channel](https://delivery.vexa.ai/plans/2026-08-25-prod-migration.md): How vexa-production stops being helm-cranked and becomes subscriber #1 at a pinned position. Written 2026-08-25. NOT EXECUTED. - [Ticketing — design draft](https://delivery.vexa.ai/design/ticketing.md): Evidence-bound support: the sink, the lanes, automated events, metering.