# Quick start

## Outcome [#outcome]

You will have a signed Argus release running on one VPS, collecting the public
Argus site as a controlled Web target, and returning stored records through the
authenticated API. Argus stores canonical records and revisions; it does not
need an LLM for collection or querying.

## Prerequisites [#prerequisites]

Use a fresh VPS running Ubuntu 22.04 or 24.04, or Debian 12 or 13, on an
AMD64 or ARM64 host. You need a shell account that can use `sudo`, outbound
HTTPS access, and at least 5 GiB free disk space. Docker Engine with the Docker
Compose plugin may already be installed and usable by your account; otherwise
the installer can install it after an explicit approval.

Do not run this procedure on a workstation or an existing Argus instance. The
installer writes `/usr/local/bin/argus`; onboarding owns the instance under
`/opt/argus`.

## Inspect and install the signed release [#inspect-and-install-the-signed-release]

First download the small installer and inspect its non-mutating report. It
shows the detected platform, signed manifest URL, target wrapper path, and
whether Docker is usable; it does not download or change files in inspection
mode.

```bash
curl -fsSLo /tmp/argus-install.sh https://argus.gpsxtre.me/install.sh
ARGUS_INSTALL_INSPECT=1 sh /tmp/argus-install.sh
```

For the normal interactive path, install with the public one-command installer:

```bash
curl -fsSL https://argus.gpsxtre.me/install.sh | sh
```

The installer verifies the embedded Ed25519 signature for the release manifest
before it accepts the wrapper URL and SHA-256 hash, then verifies the downloaded
wrapper hash before replacing `/usr/local/bin/argus`.

If Docker Engine and Compose are already usable, the installer continues. If
they are absent, it asks from an interactive terminal before installing them
from Docker's official apt repository. A non-interactive approved install must
use the downloaded script and set `ARGUS_INSTALL_DOCKER=1`; setting it to `0`
instead makes a missing Docker installation fail safely.

```bash
ARGUS_INSTALL_DOCKER=1 sh /tmp/argus-install.sh
```

## Onboard one controlled Web watch [#onboard-one-controlled-web-watch]

Open Argus:

```bash
argus
```

Choose **Set up Argus**. The home menu is the recommended way to use Argus
from a terminal; it also gives you status, readable logs, configuration,
diagnostics, updates, service controls, and secrets without memorizing
commands. `argus onboard` starts the same setup directly.

Choose **SQLite** for this single-host start, accept port `8788`, select **Web**,
and provide a watch ID such as `argus-homepage` with this controlled URL:

```text
https://argus.gpsxtre.me/
```

Leave feeds and Web search queries empty. SearXNG is asked only after at least
one Web search query; choose managed SearXNG for a query or supply an external
endpoint. FxEmbed is asked only when X is enabled; running it privately on the
same VPS is the recommended default. Telegram accepts public
channel names only. Leave OpenRouter summaries disabled unless you intend to
provide an OpenRouter API key. The CLI asks for the Argus API token through a
hidden prompt and keeps it out of the versioned configuration.

Review the plan and confirm it. Onboarding renders the instance configuration,
creates required managed services, verifies them, and writes secrets only to
the owner-only instance secrets file.

## Verify [#verify]

Check the deployment and diagnostics in the human-readable view:

```bash
argus status
argus doctor
argus logs --tail 50
argus query latest-news
```

For scripts and AI agents, add `--json`. That returns the stable versioned CLI
envelope; a healthy result has `ok: true`. Human logs are compact by default;
`argus logs --raw` shows the exact bounded service output.

The scheduler evaluates enabled watches every 30 seconds and workers poll for
queued jobs every 5 seconds, so allow the configured five-minute schedule to
run. To request an immediate run for the controlled watch, enter the token you
created during onboarding into a shell variable, then call the authenticated
endpoint from the VPS:

```bash
read -rsp "Argus API token: " ARGUS_API_TOKEN; export ARGUS_API_TOKEN; echo
curl -X POST -H "Authorization: Bearer $ARGUS_API_TOKEN" \
  http://127.0.0.1:8788/v1/watches/argus-homepage/ingest
```

After a worker completes the queued targets, query the stored Web records. The
token stays in the shell variable rather than appearing in the command.

```bash
curl -H "Authorization: Bearer $ARGUS_API_TOKEN" \
  "http://127.0.0.1:8788/v1/records?source=web&limit=20"
unset ARGUS_API_TOKEN
```

The response contains `items` with each source URL, canonical record identity,
content hash, and ingestion timestamp. An empty result means the scheduled or
immediate job has not completed yet; inspect `argus doctor` before
changing the host.

## Next step [#next-step]

Read [core concepts](/docs/concepts) to understand the stored objects, then
use [configuration](/docs/configuration) to change versioned watches and
[operations](/docs/operations) for routine health and recovery work.