Deploy Guard
Where Guard can run, what every install has in common, and which page to read for your platform.
Guard runs where you run it: your laptop, a home server, or a server you rent. We host nothing that holds a key.
The setup below takes what you set on this site (your rules, the account you watched), asks where Guard should run, and writes one command. Your key is typed on the machine where Guard runs, never on this page.
Your settings from this site
The default rules. Set your own on the playground, or paste a rules code.
- 5× max
- 2.0% at stop
- no stop: Guard sets one
- liq. ≥ 10%
- size ≤ 200%
- open ≤ 6%
- daily 6%
- drawdown 25%
- 5/5 markets
- paper mode
Markets are set on the playground. Your rules are saved in this browser and used everywhere on this site.
Where Guard runs
Next to your bot. If your bot runs on a server, Guard runs on the same server.
Other ways to run it: Docker · One-click · Packages.
Ubuntu 24.04 or Debian 12 is best: the key is stored encrypted with systemd-creds. No port is opened; Guard listens on 127.0.0.1:8547.
Any machine with Docker: linux/amd64 or linux/arm64. The state, including the key, lives on a named volume. Details: Docker.
On your own account at the platform; we never see the server. Its operators could in principle read Guard's state: use an account holding only what you are willing to lose. Details: One-click templates.
Secrets: typed on the server, never here
This page never asks for a key, and no command it makes contains one. Shell history, screen sharing and this browser would all keep it.
For testnet and mainnet. Create an API wallet in the Hyperliquid app: it can trade, it cannot withdraw. Guard asks for its key with hidden input on the server and stores it encrypted for the service. API wallets
A webhook URL is a bearer secret too. Add it on the server, in Guard's config, after the setup. Configuration
Public values: safe to enter here, checked in this browser
$ ssh -t you@your-server "curl -fsSL https://zunderlabs.com/i | sh -s -- --rules zr1_eyJ2IjoxLCJt…✓ installer verified: Sigstore signature of the v1.0.0 checksums (zunderlabs/zunder-guard)✓ zunder-guard 1.0.0 installed to /usr/local/bin · service user zunder-guard Your rules from zunderlabs.com max leverage 5× · loss at stop 2% · no stop: Guard sets one 2% away liquidation ≥ 10% · size ≤ 200% · open risk ≤ 6% daily loss stop 6% · drawdown halt 25% · markets: allKeep these rules? [Y/edit] › YHyperliquid account address › 0x8c41…a90fMode [paper/testnet/mainnet] › paper✓ paper mode: real prices, no orders, no key needed ✓ Guard is running (systemd: zunder-guard) · 127.0.0.1:8547 · paperClient key for your bot (shown once): zc_7Hq2…Lm9xNext: point your bot at http://127.0.0.1:8547
Run this from your computer
One command with your rules. It connects to your server, installs Guard after checking its signature, and asks you the rest there.
ssh -t you@your-server "curl -fsSL https://zunderlabs.com/i | sh -s -- --rules zr1_eyJ2IjoxLCJt…siKiJdfQ" Hover or focus a part of the command to see what it does.
Prefer to read first? curl -fsSLO https://zunderlabs.com/i && less i, then sh i --rules …. Or verify by hand: Verify a release.
Check it, then point your bot at it
On the machine where Guard runs:
curl -fsS http://127.0.0.1:8547/healthz# 200 and "ok": Guard is upzunder-guard status# mode, rules, risk state, the last decisions What every install has in common
Section titled “What every install has in common”- It starts in paper mode. Real prices, no orders sent. Testnet next. Mainnet only when you type it (Paper, testnet and mainnet).
- It listens on localhost only (
127.0.0.1:8547) unless you configure otherwise. - It talks to Hyperliquid only. The relay and telemetry are off unless you turn them on (Network footprint).
- Every release can be verified before you run it (Verify a release).
- The API wallet key is created by you in the Hyperliquid app and given to Guard on your machine. It never passes through us.
Pick a page
Section titled “Pick a page”| You have | Read |
|---|---|
| a Mac | Homebrew |
| Windows | winget |
| Linux, or a server over SSH | One SSH command |
| Docker anywhere | Docker |
| no server yet | One-click templates |
filled in from your settings ·
Where it should run
Section titled “Where it should run”Next to your bot. Guard listens on localhost, so the bot and Guard belong on the same machine, or in the same private network.
Close to Hyperliquid helps a little, not a lot. Guard’s own work takes about 0.07 ms per order (Latency); the network to Hyperliquid is the larger part. Zunder’s research treats a host in Tokyo (ap-northeast-1) as next to Hyperliquid (docs/decisions.md, 5 Oct 2026).
Where the key lives
Section titled “Where the key lives”- A Linux server (the SSH command): encrypted with
systemd-creds(systemd 250 or newer: Ubuntu 24.04, Debian 12 and later), with the host key and the TPM where there is one. systemd decrypts it only when it starts the service, into memory only the service can read. A copy of the disk without the host key is useless. Root on the running machine can still read it, as root can read any process’s memory. On older systemd: a file readable only by Guard’s own user, and the installer warns. - Docker: a file in the volume, mode 0600, owned by the container’s user.
- macOS and Windows: the system keychain.
Everywhere: the key belongs to an API wallet that can trade but cannot withdraw, on an account that holds only what you are willing to risk. It is typed into Guard’s hidden prompt, never into a command line, a URL or this site.
This page as plain Markdown, for people and LLMs: /docs/deploy.md