Skip to main content
this document is for:

Deployment: Invicti Platform on-premises

Installation scripts

Invicti provides installation scripts to help simplify on-premises deployments. This document explains the available scripts for Linux and Windows, where to get them, and how to use them.

note

For questions or issues with a specific script, contact Invicti Support.

Why this matters​

Setting up Invicti Platform on-premises involves several steps where misconfigurations can cause the installation to fail. The Linux scripts automate the setup and lifecycle management of the platform, reducing manual effort and the risk of errors. The Windows pre-check script helps you catch missing requirements - such as blocked URLs or insufficient resources - before you start the installation, so you don't have to troubleshoot a failed install mid-way.

Linux installation scripts​

These scripts automate the full installation and lifecycle management of Invicti Platform on-premises on Linux. Both require a clean, dedicated host with no existing workloads or Kubernetes clusters.

Download the scripts from the invicti-platform-onprem-tools GitHub repository. Each script includes a README with full usage instructions.

Verify before installing

Before running install, use the built-in check command to verify your host meets all requirements without making any changes:

sudo ./invicti-platform-rhel.sh check    # RHEL and compatible distributions
sudo ./invicti-platform.sh check # Ubuntu and Debian
Clean host required

Run this script only on a clean, dedicated host with no existing Kubernetes cluster, no KEDA, and no other production workloads. If the host already runs other services, follow the Helm installation steps instead.

Supported platforms:

DistributionsRHEL 9, Rocky Linux 9, AlmaLinux 9, CentOS Stream 9, Oracle Linux 9
Kubernetesk3s (default) or RKE2 (--k8s rke2)
SELinuxEnforcing - stays enforcing throughout
firewalldLeft running; only cluster CIDRs and required ports are opened
Architecturex86_64

Install

Download and make executable:

curl -O https://raw.githubusercontent.com/Invicti-Security/invicti-platform-onprem-tools/main/rhel/invicti-platform-rhel.sh
chmod +x invicti-platform-rhel.sh

Then run:

sudo ./invicti-platform-rhel.sh install \
--email you@example.com --license XXXX-XXXX-XXXX-XXXX --host invicti.example.com

Use --dry-run to print every command without executing it.

Available commands

CommandWhat it does
installPreflight checks, packages, SELinux, firewalld, cluster, Helm, deploy
checkRuns all preflight checks without making any changes
statusHealth and diagnostics for an existing deployment
upgradeUpgrades to the latest or a pinned chart version
reconfigureRe-renders values.yaml from flags and applies it
backupQuiesces the deployment and archives all PVCs, secrets, and chart version
restoreRestores an archive created by backup
uninstallRemoves the release; optionally removes data, cluster scope, and the cluster
logsCreates a support bundle for Invicti Support (license key is redacted)
versionReports script, chart, Helm, cluster, OS, and SELinux state

Known limitations

  • Single-node only. Remote or managed clusters (EKS, AKS, GKE, OpenShift) aren't supported.
  • Reboot when switching Kubernetes distributions. If you switch between k3s and RKE2, the uninstaller leaves behind netfilter state that breaks pod networking on the next install. The script detects this and stops. Reboot the host before reinstalling.
  • 15 GB RAM is the minimum, but it isn't enough for a full deployment. The script auto-tunes warm DAST scanners down to compensate. Use 24–32 GB for a representative test environment.

Security notes

Sensitive files

values.yaml (mode 0600) and backup archives both contain the license key. Store backups securely. The support bundle from logs redacts the license_key, but pod logs aren't scrubbed - review them before sharing externally.


Next steps​

Once the installation completes, configure the network trustlist so your deployment can reach the external Invicti services it needs:

→ Trustlist requirements for Invicti Platform on-premises

For ongoing management - upgrades, backups, and uninstallation - use the script's built-in commands. Refer to the Available commands section in the relevant tab above.

Troubleshooting​

The Linux script fails during installation

Make sure the host is clean and dedicated - no existing workloads or Kubernetes clusters. If you previously installed a different Kubernetes distribution on the same host, reboot before running the script again. Check the script's README in the invicti-platform-onprem-tools repository for known issues and distribution-specific notes.


Need help?​

Invicti Support team is ready to provide you with technical help. Go to Help Center

Was this page useful?