EntPEP private server: private model + data lake on one machine
================================================================

For a small proof of concept: the model server the agents call instead of Anthropic (Ollama behind
nginx with API keys) and the data lake they query (ClickHouse behind nginx), on one Ubuntu server
with an NVIDIA GPU (AWS g6.xlarge: NVIDIA L4 24 GB, 4 vCPU, 16 GB). Details, sizing and the AWS
commands: agent/docs/poc-backend-install.md in the EntPEP repository.

  agent VMs  ──https :443──▶  nginx (TLS, API key)               ──▶ Ollama      127.0.0.1:11434
  agent host ──https :8443─▶  nginx (allowlist, EntPEP logins)   ──▶ ClickHouse  127.0.0.1:8123

Install
-------
  curl -sSfO https://entpep.com/dl/combined-private-install-v1.tgz
  tar xzf combined-private-install-v1.tgz && cd combined-private-install-v1
  sudo ./install.sh --hostname private.example.com --certbot you@example.com --allow <agent host IP>

  * --cert fullchain.pem --key privkey.pem instead of --certbot for the customer's certificate.
  * On a GPU without a driver it installs the NVIDIA driver and stops: reboot, run it again.
  * It pulls the model (qwen3:14b, about 9 GB), installs ClickHouse, loads the demo data, checks both
    services and prints what to set on the agent host.
  * Re-running is safe: API keys, passwords, audit rows and grants are kept.
  * ./install.sh --help lists every option (--model, --no-llm, --no-datalake, ...).

Ports (inbound)
---------------
  TCP 443   private model API     from the agent hosts
  TCP 8443  data lake             from the agent hosts
  TCP 22    SSH                   from your admin address
  TCP 80    Let's Encrypt only    from anywhere (not needed with your own certificate)
Ollama (11434) and ClickHouse (8123, 9000, ...) listen on 127.0.0.1 only.

Afterwards
----------
  Model key           sudo head -1 /etc/entpep-llm/keys     new: sudo entpep-llm-key new
  Data lake logins    /etc/entpep-datalake/host.pass, desk.pass (copy to the agent host, 0600)
  Allow a host        sudo entpep-datalake allow <ip>       (and open 443/8443 to it)
  Fresh demo data     sudo entpep-datalake reset --yes
  Status              sudo entpep-datalake status ; ollama ps ; nvidia-smi

Files in this package
---------------------
  install.sh          the installer
  llm-setup.sh        Ollama tuning, boot warm-up, API keys, nginx :443 (also agent/private-llm/setup.sh)
  datalake-setup.sh   ClickHouse, logins, nginx :8443 bridge (also agent/datalake/setup.sh)
  datalake-seed.sql   data lake schema, demo tables, desk users and row policies
  VERSION, SHA256SUMS
