Install FAQ
Questions that come up when planning an installation, especially about setups you might expect but that the Istari Digital Platform handles differently. Each answer explains the design choice and links to the page with the steps.
Agents
Can I run the agent as a Windows service?
No. On Windows the agent runs under a signed-in user account, because that is what lets it run the desktop tools most jobs depend on.
What running as a signed-in user gives you
- Every module works on the same agent. Many integrations drive a desktop application, such as Excel, Word, CAD tools, or anything else automated through its user interface or COM. Windows runs services in an isolated session with no desktop, so those tools either fail to start or stop partway through a job. Under a signed-in account they get the desktop they expect, and one agent can host all of your Windows modules.
- No privileged or dedicated account. The agent does not need
SYSTEM,Local Service, or an Istari Digital service account. It runs as a named operator account you already manage, so jobs can use the license servers, network shares, and files that account can use, and nothing else.
What to plan for
On Windows, the agent starts when the operating account signs in, not when the host boots. Install the agent on Windows covers choosing that account and keeping the host available for jobs. If your site policy does not allow any local or domain account to run the agent, contact support@istaridigital.com before you plan a deployment.
For tools that need no desktop and a host that must serve jobs from boot, a Linux agent runs under systemd. See Run the agent as a service.
On Windows, does headless mode let the agent run with nobody signed in?
No. On Windows, headless mode hides the agent's system tray icon and menu; the agent still runs under the operating account and starts when that account signs in. Use it on a host where the operator stays signed in but you do not want the tray menu.
Linux is different: with headless mode turned on, the agent runs under systemd and serves jobs from boot with nobody signed in. See Run the agent as a service and istari_digital_agent_headless_mode.
The installer's signing certificate has expired. Is the signature still valid?
Yes. Each release is signed with a certificate valid for about 72 hours, so the certificate on any release older than a few days has expired. A timestamp from Microsoft proves the file was signed while the certificate was valid, which keeps the signature valid afterwards. An expired certificate on an Istari Digital installer is expected, not a security finding. How the packages are signed has a worked example and the command to verify a release yourself.
Can the agent use a SOCKS proxy?
No. The agent supports HTTP and HTTPS forward proxies, including proxies that inspect TLS traffic. A SOCKS proxy URL is rejected with an error when set explicitly, and ignored with a warning when it comes from environment variables. See Proxy configuration.
Control plane
What is the difference between the fileservice and the registry service?
They are the same service. The documentation calls it the registry service. Fileservice is the legacy name, still used where the deployment has not been renamed: environment variables that start with FILE_SERVICE_, the Kubernetes secret and deployment istari-fileservice, and the Helm fileservice values. The public hostname is already registry. See the note on Registry Service Secret.
Can I change the infosec-level schema later?
No. An administrator chooses the classification schema, US_DOD or AUS, once, when infosec levels are first enabled, and it cannot be changed afterward. Confirm which schema your organization needs before you enable the feature. See Enabling Experimental Infosec Levels.