Quickstart
Ten minutes, one node, a working content pipeline. Assumes the plugins are installed and the node has restarted.
0. See what is wrong first (free, no license)
Before installing anything, point the advisor at the cluster. It reads over REST, writes nothing, and needs no license — so there is nothing to undo if you stop here.
curl -fsSL https://getoctane.lucenia.io | sh -s -- --serve
That prints a URL. Open it: shard shape, JVM pressure, mapping growth and security posture, each finding carrying the numbers it was computed from. See Advisor for every flag and the exact endpoints it reads.
The rest of this page installs the paid pieces and needs a trial.
1. Start the trial
curl -XPOST 'localhost:9200/_lucenia/license/_start_trial?issued_to=quickstart'
Thirty days, once per cluster.
2. Allow a source host
Fetching content named in a document is denied by default. Allow the one host this example uses:
# opensearch.yml, then restart
octane.content.source.allowed_hosts: ["example-docs.s3.amazonaws.com"]
Skip this if you only use inline content — step 3 works either way, and step 5 needs it.
3. Create an ingest pipeline
Extract text, then redact anything that looks like personal data — before indexing, so the raw value never reaches a segment.
PUT _ingest/pipeline/documents
{
"processors": [
{ "content_extract": { "field": "body", "target_field": "extracted" } },
{ "compliance": { "fields": ["extracted.text"], "profile": "gdpr", "audit": true } }
]
}
Note "audit": true. The first run reports what it would redact and changes nothing. That is the
order to do this in: see what a policy catches on your data before it starts destroying values on the
way in.
4. Index a document
curl -XPOST 'localhost:9200/docs/_doc?pipeline=documents' \
-H 'Content-Type: application/json' -d '{
"body": "Contact Jane Doe at jane.doe@example.com about invoice 4111 1111 1111 1111."
}'
Then look at what the pipeline recorded:
curl -s 'localhost:9200/docs/_search?pretty'
The _compliance field lists what was detected. With audit on, the text is unchanged — you are
reading a report, not a result.
5. Turn enforcement on
Drop audit once the report looks right:
PUT _ingest/pipeline/documents
{
"processors": [
{ "content_extract": { "field": "body", "target_field": "extracted" } },
{ "compliance": { "fields": ["extracted.text"], "profile": "gdpr" } }
]
}
Reindex, and the email address is masked in what gets stored.
6. Optional: an accelerated index
PUT /vectors
{
"settings": { "index.lucenia.accelerator.enabled": true },
"mappings": {
"properties": {
"embedding": { "type": "lucenia_vector", "dimension": 4, "similarity": "cosine" }
}
}
}
index.lucenia.accelerator.enabled is final — to change it, reindex. See
Accelerator.
7. Optional: run the controller in recommend mode
# /etc/octane/autoscale.yml
octane:
mode: recommend
clusters:
local:
endpoint: http://localhost:9200
/opt/octane-autoscale/bin/octane-autoscale /etc/octane/autoscale.yml
It evaluates every decider and logs what it would do. Nothing is changed, and no license is needed to recommend. Read a week of that before letting it act — see Autoscale.
Getting this onto a real cluster
Everything above is one node. On a fleet nothing is installed node by node: the plugins go into your image once and the controller rolls the cluster onto it, a node at a time, draining and clamping allocation as it goes. That path is in installing across a fleet, and the roll itself in rolling restart.
Where to go next
- Compliance — profiles, custom detectors, named policies
- Imagery — COG streaming and tiling
- Source access — the allowlist you touched in step 2
- Compatibility — before you upgrade OpenSearch