Operator guide¶
For the person who installs Kosmos and keeps it running for a firm.
A new server goes in this order: install, configure outgoing email (nobody can sign in without it), then add the integrations the firm uses, then set up backups and monitoring before real work begins.
Install¶
- Install with the script: one command for a development machine or a production server, and what it changes on the machine.
- Install by hand: every step the script performs, for other platforms or for repairing a partial install.
- Configuration: the
config/.envfile and its two templates.
The systemd, nginx and gunicorn templates are documented beside the files
themselves, in
deploy/README.md.
Integrations¶
Each integration stays off until it is configured.
- Outgoing email: SMTP, sender addresses, and why sign-in depends on it.
- File storage: local disk or an S3-compatible bucket, and how files are served.
- AI providers and research: AI is optional;
API keys (in
config/.envor Settings), what a server without AI shows, semantic search, CourtListener, chat retention, and what data leaves the server. - Online payments: LawPay, Stripe or Confido, webhooks, and settlement.
- Google Workspace: the shared Google setup, Calendar, Contacts and Drive.
- Gmail sync: case email from each user's mailbox.
- Intakes from forwarded email: Mailgun inbound routing.
- Drafting with LibreOffice: the companion extension.
- Claude Desktop: per-user access through an MCP server.
Operate¶
- Background worker: what it does, what breaks without it, schedules, and the commands an operator uses.
- Monitoring: health checks, logs, error emails and failed tasks.
- Backup and restore: what holds a firm's data and how to protect it.
- Upgrading: moving an install to newer code.
- Troubleshooting: dependency and migration problems.
Access and security¶
- Users and permissions: sign-in, roles, the permission switches and what each one gates.
- Security checklist: what to check before the server holds real client data, and what the code does and does not do for you.
Reference¶
Environment variables, management commands and scheduled jobs are generated from the code. The permissions matrix lists every access check and where it lives.