Linux
Install 3AM on a Linux server or VM with Podman or Docker.
1. Install a container runtime
3AM needs Podman 4+ or Docker 24+, and bash. Nothing else: no Python, no Compose.
sudo dnf install -y podmanDocker works the same way; the installer uses whichever it finds (Podman first). To choose, pass
--runtime docker.
Rootless or root
Rootless Podman (a normal user) is recommended. 3AM's containers run as a non-root user either way.
2. Get the bundle onto the server
scp 3am-0.1.0.tar you@the-server:~
ssh you@the-server
tar -xf 3am-0.1.0.tar && cd 3am-0.1.0Online installs without a bundle pull images from your registry instead: set THREEAM_REGISTRY=registry.bank/3am
before running the installer.
3. Run the installer
./install.shIt asks once before changing anything (--yes skips the question) and ends with:
==> 3AM is running
Console http://127.0.0.1:8700
Admin token 9Qe… (shown once; also in the 3am-data volume at admin-token)
Next open the console, install the licence, connect your toolsInstaller options
| Option | Default | Meaning |
|---|---|---|
--port | 8700 | Console port |
--bind | 127.0.0.1 | Address the console listens on. Use 0.0.0.0 behind your reverse proxy or to reach it from other machines |
--profile | auto | cpu, gpu, or none (no model: incident notes use a template) |
--config DIR | none | A directory mounted read-only at /etc/3am with licence.json, connectors.json, policy.json, packs/ |
--runtime | Podman, else Docker | Force podman or docker |
--host-network | off | 3AM shares the host's network. Only for labs whose tools listen on this host's loopback |
--yes | off | Don't ask before installing |
--uninstall [--purge] | See Uninstall |
4. Make it survive reboots
The containers restart on failure. To start them after a reboot, let your user run services without a login session and enable Podman's restart service:
sudo loginctl enable-linger "$USER"
systemctl --user enable --now podman-restart.service5. Reach the console
The console listens on 127.0.0.1:8700, so only the server itself can reach it. Choose one:
ssh -L 8700:127.0.0.1:8700 you@the-server
# then open http://localhost:8700 on your laptopInstall with Compose
If your team runs Compose, the bundle includes compose/compose.yaml with the same containers and hardening.
cd 3am-0.1.0
for f in images/*.tar; do podman load -i "$f"; done # or: docker load -i "$f"
cd compose
cp .env.example .env
sed -i "s/^THREEAM_INGEST_TOKEN=.*/THREEAM_INGEST_TOKEN=$(od -An -N18 -tx1 /dev/urandom | tr -d ' \n')/" .env
docker compose up -d # or: podman compose up -d
docker compose logs core | grep "console admin token"For an NVIDIA GPU, add the override: docker compose -f compose.yaml -f compose.gpu.yaml up -d, and set
THREEAM_MODEL=qwen2.5:7b-instruct in .env.
Next
Install the licence, then connect your tools in the setup wizard.