Before You Begin
Overview: Confirm the requirements below match your system, then follow Cloud Path or Local Path on that host. On Local Path, finish distribution updates and the packages this host will run before you install.
System requirements
- Operating System: x86 (64-bit) Linux — Debian 11–13, Ubuntu-derived, Alpine, or RPM-based (Rocky 9.7 validated; Fedora 41, CentOS Stream 9 validated; RHEL/AlmaLinux/SLES: customer validation). See Distro Compatibility Matrix.
- Execution environment: bare metal or a full virtual machine with hardware virtualization (KVM, cloud hypervisors, VMware). The Local Path command is the same on both. Shared-kernel container guests (OpenVZ, LXC, Docker/Podman guests sharing the provider kernel) are not a fit by design. If a VPS or cloud guest has no
/dev/kvm, install there; nesting a second guest causes the installer to stop at the start. See Bare metal, virtual machines, and nested VMs and Deployment Scenarios. - Access Level: Root access (sudo privileges).
- Skills: Basic familiarity with the Linux command line.
If your setup differs, check the Introduction for compatibility details.
Finish the OS first
On Local Path, complete distribution updates and install the packages and services this host will actually run. Then install Root Lock. During initial setup, Root Lock records startup and shutdown programs from those boots. Package-install helpers, compilers, and one-shot probes that execute in that window become allowlist entries even if they never execute again.
After the Dashboard appears, run the workload you will keep — not compilers, probes, or other one-shot tools. After Lockdown, add software through Protecting During Maintenance.
Choosing your setup path
Launch a pre-installed Root Lock by HeartSuite instance on AWS, Google Cloud, Azure, DigitalOcean, Linode, or another provider. No download or kernel installation required — you boot directly into Setup Mode and the Dashboard appears on first login.
Ready? Launch your instance, then continue to Verifying Installation.
Finish distribution updates and the packages this host will actually run, then download the installation package from heartsecsuite.com, extract, install the Root Lock kernel, and complete the Installation setup through multiple reboot cycles before reaching the Dashboard.
Ready? Continue to Obtaining Root Lock.
Cloud Path and Local Path merge at the Dashboard after initial setup is complete. Cloud users continue to Verifying Installation. Local users continue to Obtaining Root Lock.
Many hosts still install through Cloud Path or Local Path on each machine. Ansible, Terraform, and GitOps apply allowlist policy after that install — see Central Policy.
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.