# Run the platform in your environment

Source: https://www.testifysec.com/docs/platform/appliance-walkthrough

Follow a local appliance from first sign-in to signed test evidence and offline verification.

Follow a local appliance from first sign-in to signed test evidence and offline verification.

[Jump to the written guide ↓](https://www.testifysec.com/docs/platform/appliance-walkthrough#follow-along)

## Follow along

 

**Goal:** start a local evaluation appliance, sign in, and record evidence against its configured trust services. This guide covers a local evaluation, not a production deployment. Authentication attributes a session to a principal; it does not prove physical biometric presence.

 

### Before you start

 

Obtain the release archive for your operating system and a valid license through your TestifySec account. Verify the downloaded archive against its published release metadata. Read the [deployment requirements](https://www.testifysec.com/docs/platform/appliance) before choosing storage, network, or identity settings.

 

The following commands assume a POSIX shell and an extracted archive containing `judge-api` and `.env.example`. On Windows, use the release's PowerShell instructions. Use the supported release and license provided for your evaluation.

 

### 1. Configure persistent local state

 

In the extracted archive, create the configuration once:

 

```sh
cp .env.example testifysec.env
```

 

Edit `testifysec.env` to set your license path and a writable persistent directory:

 

```text
ENTITLEMENT_LICENSE_PATH=./your-license.json
STANDALONE_DIR=./judge-data
SELF_HOST_MINIMAL=true
```

 

Replace `your-license.json` with your actual file name. Keep both the license and the data directory out of source control. Without a persistent directory, the standalone temporary state is deleted on exit.

 

### 2. Start the appliance

 

```sh
./judge-api serve --standalone
```

 

**Expected:** startup succeeds and prints the local application URL. Keep the process running. Open that URL in your browser; do not expose this local evaluation endpoint directly to the internet.

 

### 3. Provision your administrator

 

In another terminal in the same directory, create a private password file using your password manager or editor. Restrict access to it, then replace the example email and name below with your own:

 

```sh
chmod 600 admin.pw
./judge-api bootstrap-admin \
  --email you@company.example --name 'Your Name' \
  --password-file admin.pw
```

 

**Expected:** the administrator is created. Sign in through the application and complete the identity setup offered by your release. Remove the temporary password file after provisioning according to your workstation's secret-handling policy.

 

### 4. Connect CI/lock

 

Use the exact origin printed at startup. For the default loopback evaluation endpoint:

 

```sh
cilock login --platform-url http://localhost:8080
```

 

Complete the browser approval as the intended user. An autonomous agent must use its own approved enrollment flow; it must not borrow the administrator's session. A session-bound credential does not prove that a human personally ran a subsequent command.

 

### 5. Record work and verify it

 

In a disposable Go repository with tests:

 

```sh
cilock run --platform-url http://localhost:8080 \
  --step test -o tests.json -- go test ./...
```

 

**Expected:** the command runs and produces an evidence envelope. Review the stored evidence in the appliance when storage is configured. To reproduce the final policy-verification portion, follow [the policy walkthrough](https://www.testifysec.com/docs/cilock/recovery-policy) with your own policy signer and trusted roots.

 

## Troubleshooting and cleanup

 

An invalid license or unwritable state directory must be fixed before continuing. Do not solve a certificate error by disabling TLS verification. Stop the foreground process with Ctrl+C when finished; retain the configured state directory if you want the same identities and evidence after restart. Review production TLS, backup, restore, and update procedures separately before using real workloads.

[Browse the other walkthroughs](https://www.testifysec.com/resources#walkthroughs)
