Getting started
From a bundle to a running, activated platform with its first hosts reporting. Plan for about twenty minutes.
Requirements
| You need | Details |
|---|---|
| A Linux server | Any current 64-bit distribution: Ubuntu, Debian, RHEL, Rocky or Alma. Intel/AMD or ARM. |
| Size | 4 CPU cores, 8 GB RAM and 40 GB free disk for a small estate. Give it more as the number of hosts grows. |
| Docker | Docker Engine 24 or newer with the Compose plugin, usable by the account you install with. |
| Tools | bash, curl and tar. openssl only if the installer is to create a self-signed certificate. |
| Internet | Not required. Lawliet installs and runs air-gapped. |
Network
| Port | Direction | Purpose |
|---|---|---|
443/tcp | Users and agents to the server | Console, API and agent heartbeats |
80/tcp | Optional | Redirects to HTTPS |
5514/udp, 5514/tcp | Devices to the server | Syslog from network devices and servers |
123/udp | Both ends | Time sync. Signed commands are refused when clocks drift too far. |
Monitored hosts open no port at all. Every connection starts at the agent.
Install
Copy the bundle to the server, check its SHA-256 against the one we sent, then:
tar xzf lawliet-docker-*.tar.gz
cd lawliet-*/
./lawliet install
The installer checks the machine, asks a few questions (the address users will reach, and how to handle the certificate), generates every secret, starts the stack and verifies the API, the console and the database schema. It ends by printing the console address, a one-time administrator password and the installation fingerprint.
First sign-in
- Open the console address and sign in with the one-time password.
- Choose your own password: at least 12 characters, common passwords refused.
- Set up two-factor authentication with any TOTP app, and save the ten recovery codes.
Activate
Until a licence is installed, the console opens on its activation screen. It shows the installation fingerprint, which is also printed by ./lawliet licence on the server.
- Send the fingerprint to us. It identifies this installation and nothing else: no host name, address or data.
- Paste the licence key you receive into the activation screen, or run
./lawliet licence <key-file>on the server.
The licence is checked on your server. Nothing is sent anywhere, and the key works on this installation only.
Enrol your hosts
On the server, ./lawliet token prints a ready-to-run install command for Linux, Windows and macOS, with the server address and enrolment token filled in. The same commands are under Environment, Install agent in the console.
# Linux, as root
curl -sSL https://your-server/api/v1/agents/download/linux | sudo bash -s -- \
--server https://your-server --token <enrolment-token>
Within a minute the host appears under Environment. See Agents for the other platforms and for self-signed certificates.
Add your team
Create an account for each person under Settings, Users, and give each a role. Every new user sets their own password and enrols two-factor at first sign-in. If you use the security officer roles, see dual control.

