Installing Root Lock by HeartSuite – Part 2
Overview: No commands are needed after the first boot into the Root Lock by HeartSuite kernel. Root Lock by HeartSuite reads the startup and shutdown logs and adds the programs it finds to the allowlist — the Dashboard appears when this is complete and directs you into Phase 2 (Program Allowlisting).
Cloud users skip this step. On a pre-configured cloud instance, the Dashboard confirms Phase 1 (System Verification) is complete on first boot.
What happens after the first boot
Root Lock by HeartSuite reads the startup and shutdown logs, adds the programs it finds to the allowlist, and reboots. This repeats until no new programs are found — typically three to five passes, depending on the distribution.
While setup is running, you will see:
Over SSH: each time you reconnect, the login shows a brief status line and drops you at a regular shell — no action needed:
HeartSuite Phase 1 is running — step N of unknown total. The system reboots automatically. Reconnect in a few minutes.On the serial console (
virsh console, AWS/Azure/GCP serial console, IPMI SOL): attach and press Enter — the console autologs in and shows the current step. No action needed.
The first time you connect and the Dashboard appears, setup is complete. The Dashboard shows the reboot history and the Suggested Next Step directs you into Phase 2 (Program Allowlisting).
If the Dashboard does not appear
If setup is still running, SSH reconnects show the status line above instead of the Dashboard. Wait a few minutes and reconnect.
If repeated reconnects still show the status line rather than the Dashboard:
Open the serial console (
virsh console <vm>for KVM, AWS/Azure/GCP serial console, IPMI SOL) and press Enter to see the current step. If it has not advanced across reboots, runjournalctl -u heartsuite-phase1to see the setup output.Verify the Root Lock by HeartSuite kernel is loaded:
uname -rExpected output ends in
HeartSuite(for example,6.18.9-HeartSuite-1.0).If the wrong kernel booted, reboot and select the Root Lock by HeartSuite kernel from the GRUB menu manually.
If setup stops with an error
If something goes wrong during setup, the next login shows an error with the reason and the last output from the setup process.
Two options are available:
[r]Retry — restarts the setup from where it stopped.[q]Open shell — drops you to a shell to investigate before retrying.
The boot setup must complete before you activate Lockdown. If the initial allowlist is incomplete, the system may hang on boot or shutdown after activating Lockdown.
When the Dashboard appears and Phase 1 is confirmed, continue to Verifying Installation.
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.