Neon Law
  • Services
  • Book Consultation opens in a new tab
  • Sign in

Operating Neon Law Navigator

Our firm runs Neon Law Navigator on Google Cloud. This workshop is for admin users with access to the private source repository: the people who own billing, secrets, OIDC, runtime configuration, and release verification. It stands up your own instance — the same Rust stack our attorneys use, on your own Google Cloud project, for your own community.

One command does most of the work: navigator ops gcp setup, a provisioner written in Rust that talks to Google's REST APIs directly and ships with a dry-run so you can read the whole plan before a single packet leaves your laptop.

Two things to hold up front. This provisions billable Google Cloud resources — a GKE Autopilot cluster and five core storage buckets, with optional archive and telemetry lanes — so it is not free, and you should set a budget alert before you begin. This is a deployment guide for admin users standing up infrastructure. With that said: you can run the same stack we run. Let's stand it up.

Bring your own typeface license. Neon Law Navigator source code is owned by Neon Law IP LLC. GORP Serif is proprietary font software licensed separately from TrashType and is not covered by the repository's code licenses. If your deployment serves GORP, obtain and maintain the appropriate TrashType license, keep its license notice with your font files, and follow the TrashType terms. Otherwise, replace GORP with a typeface you are licensed to serve before launch. > Start locally with an authorized checkout. You do not need a cloud account to see Neon Law Navigator run. cargo run -p cli -- dev up brings the whole stack up locally in KIND (the store, OIDC, storage, the workflow broker, embedded Rego), then source .devx/env and cargo run -p neon serves it on localhost. Boot it locally, inspect the canonical seed, and only come back here when you want it on the public internet. The full local loop is in the checkout's AGENTS.md.

Set the budget alert before you provision — one command caps the surprise so the bill cannot run away while you learn:


gcloud billing budgets create --billing-account "$BILLING_ACCOUNT_ID" \
  --display-name "Neon Law Navigator" --budget-amount 200USD \
  --threshold-rule percent=0.5 --threshold-rule percent=0.9

Idle, the stack runs on the order of an Autopilot cluster's baseline plus five mostly empty buckets — budget for it, watch the first invoice, and size the cluster down if it is more than you need.

Start →View all slidesView as Markdown
1

Chapter 1

Intro

  1. 1Deploy your own
  2. 2Agenda
2

Chapter 2

Prepare Google Cloud

  1. 3Bring your own project
  2. 4Dry-run first
  3. 5Private assets and domain restricted sharing
  4. 6The Navigator deployment matrix
  5. 7The `/app` mount and HTTP route ownership
  6. 8`neon` — the whole brand seam
  7. 9Live rollout checkpoint
  8. 10Set one site to one version
3

Chapter 3

Provision the Infrastructure

  1. 11The APIs that light up
  2. 12Network and storage buckets
  3. 13How a Project portal reaches a client
  4. 14A document's bytes and authorization are separate
  5. 15A private image registry
  6. 16The cluster comes up
  7. 17What setup owns — and what follows it
4

Chapter 4

Environment Matrix

  1. 18Three operating modes, two deployment profiles
  2. 19The deployment that says its matters are sample
  3. 20Configuration precedence: the first source wins
  4. 21Local dev controls: inputs read by `navigator dev`
  5. 22Local runtime: what `.devx/env` generates
  6. 23The store: SurrealDB
  7. 24Where SurrealDB authorization lives
  8. 25Deployed runtime: core web and worker wiring
  9. 26Deployed runtime: identity and access
  10. 27Deployed runtime: email, signatures, and billing
  11. 28Deployed runtime: repositories, content, AI, and scheduled work
  12. 29Provision and ship: variables read by the operator CLI
  13. 30Ancillary operations and opt-in test controls
  14. 31When sample data appears
5

Chapter 5

Configure the Trust Boundaries

  1. 32Secrets: the invariants that gate the boot
  2. 33Sign-in: bring an OIDC provider; passwords live there, not here
  3. 34Role rings: who can do what
  4. 35Provider signup and parity across the deployments
  5. 36The external surface — every third party, in one place
  6. 37The two service deployments
  7. 38Security architecture
6

Chapter 6

Ship the Instance

  1. 39Ship and verify
  2. 40Post the verified handoff in `#navigator`
  3. 41Point your domain at the instance (optional)
  4. 42Drive it from the CLI
  5. 43Make it yours — white-label under your own brand
  6. 44This is how we set up our production deployment
7

Chapter 7

Wrap Up

  1. 45Canonical references
Neon Law
  • X opens in a new tab
  • LinkedIn opens in a new tab
  • YouTube opens in a new tab
  • API opens in a new tab
  • Blog opens in a new tab
  • Contact
  • Glossary opens in a new tab
  • Navigator opens in a new tab
  • Notations opens in a new tab
  • Presentations opens in a new tab
  • Privacy opens in a new tab
  • Team opens in a new tab
  • Terms opens in a new tab
  • Testimonials
  • UX opens in a new tab
  • contact@neonlaw.com
  • +1 510 800 2080
  • Nevada
    5150 Mae Anne AveSte 405-9002Reno, NV 89523
  • New York
    12 E 49th St18th FloorNew York, NY 10017
  • Justice Technology AssociationMission-Aligned Partner opens in a new tab

Attorney advertisement. Nothing here is legal advice without a signed retainer for an active project. Past results do not guarantee future outcomes.

© 2026 Shook Law PLLC

NEON LAW® is a registered trademark of Shook Law PLLC, U.S. Reg. No. 6,325,650 opens in a new tab

Powered by Neon Law Navigator 26.10.4

Everyone deserves to be seen. Made with ❤️ in 🗽.