DIGITAL PRODUCT · AI VM SETUP BLUEPRINT

Don’t just let AI set up your server. Make it prove you can recover it.

This blueprint gives your AI agent a controlled workflow for setup, security and backups. It adapts each step to your environment, documents the results and can test complete recovery on a fresh VM.

1-hour VM setup observed in the SSH/S3 test · recovery tested on GCP and SSH/S3 · 12 months of updates

EXAMPLE COMPLETION · FULL RECOVERY SELECTED
RUN COMPLETE

Your agent reports the result, not just the commands.

You

Set up a recovery-proven VM for public websites and private internal tools. Keep administration private.

Agent

Setup complete. Your VM foundation passed all selected checks.

  • Public HTTPS and private administration paths verified
  • k3s and persistent storage verified
  • Private registry recovered from its durable source
  • Encrypted off-VM backups scheduled
  • Latest backup decrypted and restored successfully
  • Clean-checkout recovery instructions saved
FULL RECOVERY REHEARSALPASSED

A fresh VM was rebuilt from protected recovery material. The restored backup and measured recovery time are recorded in the handover.

Your VM is ready for public and private workloads.

Next workflows ready
  • Deploy a workload
  • Migrate an existing workload
  • Day-2 operations
  • Repeat the recovery drill

The agent can only report a full recovery pass when the optional rehearsal was selected and observed. Otherwise it reports the remaining gap.

FIND YOUR STARTING POINT

How exposed is your self-hosted setup?

Three or four short questions show where the blueprint helps and whether the agent-led path fits the way you use AI. No infrastructure is touched and your answers stay in this browser.

Question 1 of 4

What is your current situation?

RECOVERY IS A PATH, NOT A BACKUP ICON

The machine can disappear. The system can come back.

Recovery-critical configuration, images and data live away from the VM. The agent follows the recorded path onto fresh infrastructure and proves the selected outcome.

01

VM or disk is lost

The original machine is treated as unavailable, not as the hidden source of truth.

02

The agent rebuilds

The blueprint gives the agent the order, guardrails and verification points.

  • Private stack repository
  • Protected off-VM backup
  • Durable private image registry
03

The platform returns

Configuration, images and selected data are restored on a clean VM and checked.

ONE VM · TWO SEPARATE DOORS

Public apps stay reachable. Internal apps stay internal.

Public and private workloads use separate ingress paths. Internal tools are reached through the private tunnel, not merely protected by another login screen.

PUBLIC PATH
InternetAny visitor
Public ingressHTTPS
Public appsWebsites · public APIs
PRIVATE PATH
Your deviceAuthorized operator
Internal ingressWireGuard tunnel
Internal appsAdmin tools · registry · business apps

No public route to internal applicationsA request arriving from the internet cannot cross into the private ingress path.

WHAT IS RUNNING AT THE END

A workload-ready base you can understand and recover.

Not a demo and not just generated commands. Every selected stage ends with observable acceptance criteria, and every gap remains visible.

A hardened VM

Pinned supported image, restricted host access, firewall and a documented recovery path.

Private access

Human administration and internal routes use a private path rather than sharing the public application edge.

k3s with TLS routes

A small Kubernetes base with separated public/private routing, storage and verified TLS.

Identities & secrets

Scoped identities and secret references are separated from the sanitized configuration repository.

A restore that was run

Protected off-VM material is decrypted, checked and restored in isolation.

A customer-owned handover

Sanitized recovery configuration, evidence, status endpoints and operating instructions remain with you.

WHAT IS INSIDE

Twelve controlled stages. Click into every outcome.

The agent adapts each stage to the environment you explicitly identify. These are not provider-specific commands copied blindly: every stage has an operator decision, observable proof and a recorded handover.

00

Intake

Establish the real target, experience level and required external services.

What the agent does
Asks only facts it cannot derive: VM status, accounts, domains, backup destination, repository and setup mode.
What you approve
Confirms the exact environment and whether any existing data must be preserved.
What proves it worked
A recorded scope with explicit unknowns—never an inherited CLI default or guessed VM.

What it is not

  • Not a one-click installer. The agent develops each stage in your run folder and validates it on your VM.
  • Not a hosting service. Your account, your VM, your data.
  • Not an application installer. Workload deployment and migration begin as explicit next workflows after the base is accepted.

This is the prompt you paste

No hosted control plane and no installation of global skills. The package is a folder; the prompt is the entry point.

Read START-HERE.md and skills/vm-blueprint/SKILL.md.
Start run ssh-s3-001 in discovery mode. Target is a new SSH VM with S3-compatible storage VM.
Interview me about the business and workloads, then prepare the adapted plan.
Do not provision resources yet. Record missing inputs and benchmark metadata.

AI VM SETUP BLUEPRINT · €119

Build the recovery path before you need it.

Get the complete agent-executable blueprint, private repository access and 12 months of updates. One company may use it across unlimited internal and client VMs.

Come back Wednesday, 30 September at 13:00 CEST.

PREFER A HAND?

Guided Launch · €999

Your AI performs the implementation. We review the architecture, help resolve important decisions and join you for the final acceptance and recovery session. Includes a kickoff, limited asynchronous support and a final evidence review; migration is separate.

Discuss Guided Launch

A few useful answers.

Can I return a digital product?

You confirm immediate delivery at checkout and waive the 14-day withdrawal right, as required for digital content in the EU. If the package does not work as described, write to us and we solve it or refund.

Do I really need a paid AI plan?

Yes for a complete run. The agent reads the package, your answers and command output across twelve stages. Free tiers stop far earlier. You can buy now and run later.

Which CLI works best?

The package uses the same explicit file-based entry point with Claude Code and Codex. The setup guide covers both. Other agents are not advertised until they have been validated.

What if a stage fails?

The run records the failure, tries at most twice per hypothesis and then marks the stage blocked with a reason. You continue from the recorded state instead of starting over.

How do updates reach me?

Through the private Git repository (git pull). Each release lists measured runs and what changed.

What does the licence cover?

One company may use the Blueprint an unlimited number of times across its own VMs and environments and to provide services on client-owned or client-controlled environments. You may deliver generated customer-specific artifacts, but may not redistribute or resell the Blueprint itself.