Overview: Every maintenance window is an attack window. In Setup Mode the kernel logs but stops blocking. On the maintenance kernel, Root Lock by HeartSuite is not loaded at all.

These guides cover how to make changes without leaving a hole an attacker can use. The Dashboard shows the current protection state — including Lockdown status — and the Suggested Next Step throughout maintenance.

Maintenance is a time period during which you temporarily step out of Lockdown to make changes. It is not a separate mode. Root Lock has two modes: Setup Mode and Lockdown.

During maintenance you either switch to Setup Mode (the kernel logs but stops blocking) or boot the maintenance kernel (Root Lock is not loaded). The Dashboard’s Maintenance ([m]) detects whether the immutable seal is active and opens the matching path.

Installing packages, applying patches, and editing configuration happen in Setup Mode once the window is open — that is where blocking is off and logging stays on. After the first Lockdown, opening that window takes a console GRUB pick: Maintenance: unseal and return to Root Lock. The seal lifts automatically and you land back in Setup Mode on the Root Lock kernel. A one-reboot switch with no GRUB is only when the strip already says Lockdown not applied.

The Maintenance grid button is shown in Lockdown. Keyboard [m] also works in Setup Mode after you have unsealed.

Which change is this?

Installing packages, replacing program files, and updating Root Lock itself are different jobs, and they take different paths out of Lockdown.

SituationPath
OS packages, configuration, replacing program filesUnseal, then work in Setup Mode — Protecting During Maintenance
Root Lock kernel and DashboardUnseal if sealed, then one stock boot — Updating Root Lock
Many hosts already in LockdownReprovision from an updated image rather than opening a console on every node — Enterprise Adoption Guide

In this section