Requirements
What to prepare before installing 3AM.
Where 3AM can run
| Platform | For | Status |
|---|---|---|
| Linux server with Podman 4+ or Docker 24+ | Production | Tested: Fedora with Podman 5. Expected to work: RHEL / Rocky / Alma 8–9, Ubuntu 22.04–24.04, Debian 12, and other distributions with a supported container runtime |
| Kubernetes | Production | Tested: Kubernetes 1.34. Expected to work: 1.27+ on EKS, AKS, GKE and Rancher. OpenShift needs one extra step and is not yet certified (details) |
| Windows Server 2022 / 2025 | Production, through a Linux VM (Hyper-V) or WSL2 | Documented, not yet certified. 3AM runs as Linux containers; see Windows Server |
| macOS 13+ | Evaluation and demos | Documented, not yet certified. Podman or Docker Desktop; see macOS |
"Tested" means 3AM's install and certification suites run on it. Tell us if you run 3AM elsewhere and we will add it.
Hardware
| Size | CPU | Memory | Disk | When |
|---|---|---|---|---|
| Minimum | 2 cores | 4 GB | 20 GB | Evaluation, no on-prem model |
| Recommended | 4 cores | 8 GB | 50 GB | Most installs, with the CPU model for incident notes |
| Large | 8 cores | 16 GB | 100 GB | Many services and repositories |
| With GPU model | + NVIDIA (8 GB+ VRAM) or AMD ROCm | Better incident notes; optional |
Disk holds the audit log, the code index and incident history. The audit log is append-only by design, so plan for
it to grow. The installer's host checks and 3am-core preflight tell you if a server is too small.
Network
3AM needs no inbound connections from outside. It only makes outbound connections to the tools you connect.
| From | To | Port | Why |
|---|---|---|---|
| People | 3AM console | 8700/tcp (or your reverse proxy's 443) | The web console |
| 3AM | Each connected tool | Its API port (usually 443) | Alerts, checks, approvals, actions |
| Components | 3AM | 8700/tcp | Posting events (optional) |
The console listens on 127.0.0.1:8700 by default. Put it behind your reverse proxy or ingress for TLS and
single sign-on, or bind it to another address with --bind.
Accounts to prepare
You don't need all of these on day one. A monitoring source and an approval channel are enough to start in shadow mode.
| For | Prepare |
|---|---|
| Monitoring | Read access to Prometheus/Alertmanager, Splunk, Datadog or Grafana |
| Approvals | A Slack bot, a Symphony bot, a PagerDuty REST key, Twilio, or an SMTP relay |
| Systems 3AM may fix | A read-only database user for checks; a scoped Kubernetes service account; SSH templates |
| Code | A read-only token for GitHub, GitLab or Bitbucket |
| Tickets and CMDB | ServiceNow or Jira API access |
Each connector guide lists exactly what to create, with the least permissions that work.
From 3AM
- A licence file for this install (how to request one).
- For air-gapped sites, the install bundle (
3am-<version>.tar), with images, model and sealed packs inside.