Keep a gate up while you change the system
After Lockdown, Maintenance unseals from the console and returns you to Setup Mode. How to shorten the unprotected period, keep a recovery path, and lock down again.
Overview: Every maintenance window is an attack window. In Setup Mode the kernel logs but stops blocking. On the maintenance kernel, Root Lock by HeartSuite is not loaded at all.
These guides cover how to make changes without leaving a hole an attacker can use. The Dashboard shows the current protection state — including Lockdown status — and the Suggested Next Step throughout maintenance.
Maintenance is a time period during which you temporarily step out of Lockdown to make changes. It is not a separate mode. Root Lock has two modes: Setup Mode and Lockdown.
During maintenance you either switch to Setup Mode (the kernel logs but stops blocking) or boot the maintenance kernel (Root Lock is not loaded). The Dashboard’s Maintenance ([m]) detects whether the immutable seal is active and opens the matching path.
Installing packages, applying patches, and editing configuration happen in Setup Mode once the window is open — that is where blocking is off and logging stays on. After the first Lockdown, opening that window takes a console GRUB pick: Maintenance: unseal and return to Root Lock. The seal lifts automatically and you land back in Setup Mode on the Root Lock kernel. A one-reboot switch with no GRUB is only when the strip already says Lockdown not applied.
YES and reboot once. You stay on the Root Lock kernel in Setup Mode. No GRUB pick.The Maintenance grid button is shown in Lockdown. Keyboard [m] also works in Setup Mode after you have unsealed.
Installing packages, replacing program files, and updating Root Lock itself are different jobs, and they take different paths out of Lockdown.
| Situation | Path |
|---|---|
| OS packages, configuration, replacing program files | Unseal, then work in Setup Mode — Protecting During Maintenance |
| Root Lock kernel and Dashboard | Unseal if sealed, then one stock boot — Updating Root Lock |
| Many hosts already in Lockdown | Reprovision from an updated image rather than opening a console on every node — Enterprise Adoption Guide |
/lib/modules.YES for one stock boot. The default stays Root Lock.After Lockdown, Maintenance unseals from the console and returns you to Setup Mode. How to shorten the unprotected period, keep a recovery path, and lock down again.
Every write in a protected directory is versioned before it lands. Under Lockdown, other programs are not intended to reach those versions.
The Dashboard expands the kernel allowlist cache up to 255. Larger allowlists stay valid; the cache keeps the most recently used entries.
If kmod can execute, limit which module files it may read before Lockdown. Directory grants under /lib/modules are the real risk.
Unseal if Lockdown is applied, then run the bundle from a terminal in Setup Mode. Type YES to take one stock boot. The default stays Root Lock. You land in Setup Mode on the new kernel.
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.