# Install DuranteOS

**The primary way to install DuranteOS is to give this page to your AI and say "install this."**

DuranteOS is the Life Operating System that Durante Technologies runs: a fork of [LifeOS](https://github.com/danielmiessler/LifeOS) kept in a private repository, with upstream releases merged in rather than copied over. The install is AI-native, so you hand this page to whatever AI coding assistant you already use and it does the whole install for you, with permission at each step.

---

## For you (the human)

**Start here: the repo is private, and only its owner can let you in.** Send them your GitHub username and this line:

> Please give `<your-github-username>` read access to `durante-tech/duranteos`.

The invite arrives as an email from GitHub and has to be accepted. An unaccepted invite eventually expires, and then the owner has to send it again. Nothing below works until you have accepted it, and no script will ask you for a token.

Once you are in, two more things:

1. **That access on this machine:** either an SSH key registered with GitHub, or `gh auth login` (`brew install gh` on macOS, your package manager on Linux, first).
2. **macOS or Linux.** The background services run under launchd on macOS and under `systemd --user` on Linux.

Then paste this to your AI (Claude Code, Cursor, Codex, any assistant that can read files and run commands):

> **Read https://duranteos.com/install and install DuranteOS for me.**

Prefer a terminal? The shortcut for Claude Code, on macOS or Linux:

```
curl -fsSL https://duranteos.com/install.sh | bash
```

Its sha256 is published beside it at `https://duranteos.com/install.sh.sha256`; the script prints the commit it installed. Pin a release instead of `main` with `DURANTEOS_REF` (current: `v7.40.4-duranteos.1`, also in [`/version.json`](https://duranteos.com/version.json)). Plan first without writing anything:

```
curl -fsSL https://duranteos.com/install.sh | DURANTEOS_DRY_RUN=1 bash
```

---

## For the AI assistant — read this fully before you touch anything

You are installing DuranteOS for your human. The install is **additive**: you touch only the repo's own files, you never overwrite files Claude Code already placed without backing them up, and you ask before the one privileged step (the background services: launchd on macOS, `systemd --user` on Linux). Each step below states its evidence; do not proceed past a step whose evidence you cannot show.

### 0. Prerequisites

- `uname -s` is `Darwin` or `Linux`. `curl`, `git` present (on macOS `xcode-select --install` provides git; on Linux the distribution package).
- `bun` ≥ 1.2 (`curl -fsSL https://bun.sh/install | bash` if missing).
- Claude Code present (`claude --version`); if not, `curl -fsSL https://claude.ai/install.sh | bash`.
- GitHub access: `git ls-remote git@github.com:durante-tech/duranteos.git HEAD` succeeds, or `gh auth status` succeeds and `git -c credential.helper='!gh auth git-credential' ls-remote https://github.com/durante-tech/duranteos.git HEAD` succeeds. If neither, separate the two failures before you report anything, because they need different actions. Probe the credential on its own with `ssh -T -o BatchMode=yes -o ConnectTimeout=10 -o StrictHostKeyChecking=accept-new git@github.com` (it exits 1 on success and prints "successfully authenticated") or with `gh auth status`. **No credential on this machine:** they set up auth (`gh auth login` after installing `gh` with `brew` on macOS or the distribution package on Linux, or an SSH key) and re-run. **A credential that works while the repo stays invisible:** they have not been invited yet, so give them the line to send the owner, `Please give <username> read access to durante-tech/duranteos.` (read the username with `gh api user --jq .login`), and tell them the invite arrives as an email from GitHub that has to be accepted. Stop and say which of the two it is rather than guessing. Never ask them for a token.

### 1. Place the repo at `~/.claude` without clobbering it

`git clone` refuses a non-empty directory, and `~/.claude` already exists on any machine that ran Claude Code once:

```
cd ~/.claude
cp -p CLAUDE.md CLAUDE.md.pre-duranteos 2>/dev/null; cp -p settings.json settings.json.pre-duranteos 2>/dev/null
git init -q && git remote add origin git@github.com:durante-tech/duranteos.git
git fetch -q origin main vendor
git checkout -q -f -B main origin/main && git branch -q vendor origin/vendor
```

Evidence: `git status --porcelain | wc -l` is 0, `test -f LIFEOS/FORK.md` (the fork marker), `cat LIFEOS/VERSION`.

If `~/.claude/.git` already exists with this repo as origin, the machine is already installed: `git pull` updates it. If it has a different origin, stop and ask.

### 2. Run the engine

The repo carries the deterministic installer, Layer 2. Run it from a plain terminal, not from inside a Claude Code session, and pass the paths explicitly (the tools also read `LIFEOS_CONFIG_DIR` / `LIFEOS_DIR` from the environment and a session inherits stale values):

```
bun ~/.claude/skills/LifeOS/Tools/CloneInstall.ts --repo-dir ~/.claude --config-root ~/.claude --config-dir ~/.config/LIFEOS
```

That prints a plan. Add `--apply` to perform it, and `--yes` only after the human agrees to install the background services (launchd on macOS, `systemd --user` on Linux). The steps it performs, each idempotent: dependencies, USER tree scaffold, the two per-machine symlinks, `settings.json` generated once from `settings.system.json` plus the USER overlay, identity imports, the Pulse Observability build, the Pulse seed, services, and an integrity check.

Evidence: the JSON report shows every step `done` or `already-done`; `readlink ~/.claude/LIFEOS/USER` points into `~/.config/LIFEOS/USER`; `jq '[.hooks | .. | .command? // empty] | length' ~/.claude/settings.json` equals the same count on `settings.system.json`.

### 3. Secrets

Create `~/.claude/.env` (gitignored, never committed). `/LifeOS doctor` inside Claude Code names the keys each capability needs; a missing key degrades that capability only.

### 4. Verify, then onboard

- `bun ~/.claude/LIFEOS/TOOLS/CarrierProbe.ts` once, after Claude Code is logged in.
- `bun ~/.claude/LIFEOS/TOOLS/IntegrityCheck.ts` → CLEAN. `curl -s -o /dev/null -w '%{http_code}' localhost:31337/` → 200.
- Start every session with `lifeos`, the launcher shim the engine writes at `~/.local/bin/lifeos`. It is what carries the LifeOS system prompt into the session; a plain `claude` loads CLAUDE.md and the hooks and none of the constitutional layer. `~/.local/bin` is where Claude Code's own installer lives, so it is normally already on your PATH.
- A fresh session opens with the LifeOS banner and a `🧠 MEMORY` line.
- Then `/LifeOS interview`: name the DA, fill identity and TELOS. Everything it writes lands in the human's own USER tree (`~/.config/LIFEOS/USER`), which they should keep in a private repo of their own. It is never shared with anyone.

### What never leaves this machine

`~/.config/LIFEOS/USER`, `~/.claude/LIFEOS/MEMORY`, `~/.claude/.env`, `settings.user.json`. The repo you cloned carries no one's life; the USER tree carries only this human's.

### Staying current

`git -C ~/.claude pull` brings the other machines' system changes. Upstream LifeOS releases arrive through `skills/LifeOS/Workflows/VendorMerge.md`. Never run `OverlaySystem.ts`, `DeployCore.ts` or `DeployComponents.ts` with `--apply` here: they refuse a fork-marked tree, and the refusal is correct.
