This page has one goal: get it running on your machine and walk through a complete support flow. No GPU, no model API key, no need to read the docs first.
All three end up in the same place. Options 2 and 3 skip the front-end build and start faster.
Run this from the repository root. The first run needs network access and compiles the front end.
sh nexusdesk quickstart.\nexusdesk.ps1 quickstartSkip the front-end build and pull the published image directly.
NEXUSDESK_IMAGE_REGISTRY=docker.io/groundedcore/ NEXUSDESK_VERSION=latest \
docker compose -f deploy/quickstart/compose.yaml up -dImages are published to both GHCR and Docker Hub with identical content — pick whichever your network prefers. Docker Hub rate-limits anonymous pulls; GHCR does not.
On the version tag: NEXUSDESK_VERSION must be set explicitly,
because the default value local only exists for local builds.
Just trying it out? One Compose file is enough. Run this in any directory.
curl -fsSLo compose.yaml \
https://raw.githubusercontent.com/GroundedCore/nexusdesk/main/deploy/quickstart/compose.yaml
NEXUSDESK_IMAGE_REGISTRY=docker.io/groundedcore/ NEXUSDESK_VERSION=latest \
docker compose -f compose.yaml up -d⚠️ Never expose trial mode to the public internet.
To make local evaluation frictionless, trial mode injects an administrative identity when a request carries no credentials. It is intended for your own machine or a trusted intranet only. To serve real traffic, use production deployment with real identity and access control configured.
Open https://localhost:8080 and go to sample-support in the conversations workbench.
How long does delivery take?Watch how the agent retrieves from the bound knowledge base, and says it cannot confirm when there is no basis.
Create a ticket for meWatch the agent draft a ticket that is only created after a human approves it — the write-action safeguard.
Nine industry scenarios are preloaded: retail, enterprise software, manufacturing,
education, hospitality, property, logistics, HR and gaming — 9 knowledge bases and 18 agents in total,
all prefixed with [case]. Filter for them in the agent list, or just start chatting:
they are already bound to a demo model profile.
These scenarios use a simulated model and the interface marks them as demo content. They exist to validate the flow, not to show what a real model would answer.
Trial mode ships its own self-signed certificate, so access over a LAN IP or internal hostname is still a secure context — browser restrictions on secure-context APIs will not get in your way.
/data/tls/ca.crt from the container to clear itNEXUSDESK_TLS_HOSTS so the certificate covers it; see the deployment guide
If you hit an error about crypto.randomUUID or the clipboard, it is usually because
the page was opened in a non-secure context (http:// on a non-localhost address).
Access it over https:// or via localhost.
The most common cause is Docker Desktop not being in Linux container mode. Switch to “Switch to Linux containers” from the Docker Desktop tray menu and retry.
First check for a leftover container with docker ps, or change the port mapping
and restart.
Docker Hub rate-limits anonymous pulls. Point NEXUSDESK_IMAGE_REGISTRY at GHCR
instead — the content is identical.
Because there are multiple published versions, and the default local only makes
sense for local builds. This is a known piece of friction that we plan to remove.
You can validate the complete flow: knowledge retrieval, tool calls, ticket drafting and human approval, and conversation handoff. The trial model is simulated, so its answers are canned and say nothing about real model quality. To evaluate real behaviour, add a real connection in the model gateway.
Yes. It is the self-signed certificate that trial mode generates for local access.
Import /data/tls/ca.crt as described above and the warning disappears.
Trial mode persists data in named Compose volumes. docker compose down keeps them;
adding -v deletes the volumes. Use it carefully.
No. See production deployment: configure role tokens, an external PostgreSQL, and Milvus and object storage as needed.
Model profile → knowledge base → agent → publish → chat. See the platform guide in the repository.
Role tokens, external PostgreSQL, Milvus and object storage, HTTPS and backups.
Open platform: applications and keys, signed webhooks, SSE streaming, idempotency keys and call logs.