Deployment: Invicti Platform on-premises
Installation scripts
Invicti provides installation scripts to help simplify on-premises deployments. This document explains the available scripts for Linux and Windows, where to get them, and how to use them.
For questions or issues with a specific script, contact Invicti Support.
Why this matters
Setting up Invicti Platform on-premises involves several steps where misconfigurations can cause the installation to fail. The Linux scripts automate the setup and lifecycle management of the platform, reducing manual effort and the risk of errors. The Windows pre-check script helps you catch missing requirements - such as blocked URLs or insufficient resources - before you start the installation, so you don't have to troubleshoot a failed install mid-way.
Linux installation scripts
These scripts automate the full installation and lifecycle management of Invicti Platform on-premises on Linux. Both require a clean, dedicated host with no existing workloads or Kubernetes clusters.
Download the scripts from the invicti-platform-onprem-tools GitHub repository. Each script includes a README with full usage instructions.
Before running install, use the built-in check command to verify your host meets all requirements without making any changes:
sudo ./invicti-platform-rhel.sh check # RHEL and compatible distributions
sudo ./invicti-platform.sh check # Ubuntu and Debian
- RHEL and compatible distributions
- Ubuntu and Debian
Run this script only on a clean, dedicated host with no existing Kubernetes cluster, no KEDA, and no other production workloads. If the host already runs other services, follow the Helm installation steps instead.
Supported platforms:
| Distributions | RHEL 9, Rocky Linux 9, AlmaLinux 9, CentOS Stream 9, Oracle Linux 9 |
| Kubernetes | k3s (default) or RKE2 (--k8s rke2) |
| SELinux | Enforcing - stays enforcing throughout |
| firewalld | Left running; only cluster CIDRs and required ports are opened |
| Architecture | x86_64 |
Install
Download and make executable:
curl -O https://raw.githubusercontent.com/Invicti-Security/invicti-platform-onprem-tools/main/rhel/invicti-platform-rhel.sh
chmod +x invicti-platform-rhel.sh
Then run:
sudo ./invicti-platform-rhel.sh install \
--email you@example.com --license XXXX-XXXX-XXXX-XXXX --host invicti.example.com
Use --dry-run to print every command without executing it.
Available commands
| Command | What it does |
|---|---|
install | Preflight checks, packages, SELinux, firewalld, cluster, Helm, deploy |
check | Runs all preflight checks without making any changes |
status | Health and diagnostics for an existing deployment |
upgrade | Upgrades to the latest or a pinned chart version |
reconfigure | Re-renders values.yaml from flags and applies it |
backup | Quiesces the deployment and archives all PVCs, secrets, and chart version |
restore | Restores an archive created by backup |
uninstall | Removes the release; optionally removes data, cluster scope, and the cluster |
logs | Creates a support bundle for Invicti Support (license key is redacted) |
version | Reports script, chart, Helm, cluster, OS, and SELinux state |
Known limitations
- Single-node only. Remote or managed clusters (EKS, AKS, GKE, OpenShift) aren't supported.
- Reboot when switching Kubernetes distributions. If you switch between k3s and RKE2, the uninstaller leaves behind netfilter state that breaks pod networking on the next install. The script detects this and stops. Reboot the host before reinstalling.
- 15 GB RAM is the minimum, but it isn't enough for a full deployment. The script auto-tunes warm DAST scanners down to compensate. Use 24–32 GB for a representative test environment.
Security notes
values.yaml (mode 0600) and backup archives both contain the license key. Store backups securely. The support bundle from logs redacts the license_key, but pod logs aren't scrubbed - review them before sharing externally.
Run this script only on a clean, dedicated host with no existing Kubernetes cluster, no KEDA, and no other production workloads. If the host already runs other services, follow the Helm installation steps instead.
Install
Download and make executable:
curl -O https://raw.githubusercontent.com/Invicti-Security/invicti-platform-onprem-tools/main/debian/invicti-platform.sh
chmod +x invicti-platform.sh
Basic installation:
sudo ./invicti-platform.sh install \
--email you@company.com \
--license XXXX-XXXX-XXXX \
--host invicti.company.com
Production installation with SMTP and a TLS certificate:
sudo ./invicti-platform.sh install --yes \
--email you@company.com --license XXXX --host invicti.company.com \
--smtp-host smtp.company.com --smtp-port 587 \
--smtp-user apikey --smtp-pass 'secret' --smtp-from no-reply@company.com \
--tls-cert /etc/ssl/certs/invicti.pem --tls-key /etc/ssl/private/invicti.key
Use --dry-run to print every command without executing it.
Available commands
| Command | What it does |
|---|---|
install | Preflight checks, k3s and Helm 3 setup, registry login, chart deploy |
check | Runs all preflight checks without making any changes |
status | Cluster, release, pods, storage, networking, events, and reachability |
upgrade | Upgrades to the latest or a pinned chart version |
reconfigure | Re-renders values.yaml from flags and applies it |
backup | Quiesced backup of values, secrets, PVC data, and chart version |
restore | Restores a backup, including into a different cluster |
uninstall | Removes the release; see uninstall levels below |
logs | Creates a redacted support bundle for Invicti Support |
version | Reports script, Helm, kubectl, k3s, and Kubernetes versions |
Uninstall levels
./invicti-platform.sh uninstall # release only, data survives
./invicti-platform.sh uninstall --purge-data # + PVCs and namespace (destroys data)
./invicti-platform.sh uninstall --purge # + cluster-scoped leftovers (use before a clean reinstall)
./invicti-platform.sh uninstall --purge-all # + k3s itself
--purge before reinstallingThe chart installs KEDA CRDs that Helm never removes on uninstall. These CRDs get stuck in Terminating and block a clean reinstall. uninstall --purge strips the finalizers and removes them. If you skip this step, your next install will fail on ownership conflicts.
Backup and restore
./invicti-platform.sh backup --output /mnt/backups/invicti-$(date +%F).tar.gz
./invicti-platform.sh backup --no-pvc # config only, stays online
./invicti-platform.sh restore --from /mnt/backups/invicti-2026-08-18.tar.gz
Backup archives are saved with 0600 permissions and contain your license key and any SMTP or database passwords. Store them securely.
Sizing guidance
The documented minimum is 6 CPU / 12 GB RAM / 50 GB disk per worker node, but that assumes a multi-node cluster. For a single-node installation, budget 8+ CPU and 32 GB RAM. Production storage guidance is 1.2–1.5 TB, because SeaweedFS holds scan artifacts.
Next steps
Once the installation completes, configure the network trustlist so your deployment can reach the external Invicti services it needs:
→ Trustlist requirements for Invicti Platform on-premises
For ongoing management - upgrades, backups, and uninstallation - use the script's built-in commands. Refer to the Available commands section in the relevant tab above.
Troubleshooting
The Linux script fails during installation
Make sure the host is clean and dedicated - no existing workloads or Kubernetes clusters. If you previously installed a different Kubernetes distribution on the same host, reboot before running the script again. Check the script's README in the invicti-platform-onprem-tools repository for known issues and distribution-specific notes.
Need help?
Invicti Support team is ready to provide you with technical help. Go to Help Center