Docs

Install

Current status, what an install will need, and what the one-line installer will and will never do.

On this page
Status

Firekeeper is not released. There is no installer, no image and no release yet. The command below works today, but it only prints this status. It changes nothing on your machine.

The command

curl -fsSL https://firekeeper.sh/install | sh

Today the script prints what Firekeeper is, says that no release is published, points back to this page, and exits. It makes no network calls, writes no files and does not use sudo.

You should read any script before you pipe it to a shell. To read this one first:

curl -fsSL https://firekeeper.sh/install.sh

The whole script sits inside a main function that is called on its last line. If the download is cut short, the shell never reaches that line and nothing runs.

What an install will need

  • An AWS organization. Firekeeper watches the accounts in it. One organization and the EKS clusters in it make one estate.
  • An EKS cluster to run the hub in. One hub watches your whole estate.
  • An operator with admin rights, for setup only. Setup creates the read-only roles in your accounts and installs the hub in your cluster. After setup, Firekeeper runs with the read-only roles alone.
  • A license file. Licenses are free today. Firekeeper checks the license offline when it starts. See Licensing.

What the installer will do

  • Create the read-only roles that Watch needs.
  • Install the hub in your EKS cluster.

What the installer will never do

  • Use sudo or ask for your password.
  • Send your credentials, or anything about your estate, to firekeeper.sh or to us.
  • Give Firekeeper write access to your accounts for Watch.
  • Turn on Defend. Defend is in development, and when it exists it will stay off until you turn it on.
  • Run a half-downloaded script.

When it is released

This page will change first. Until then, the command above is safe to run and does nothing but print the status.