-y, or when you explicitly pass --simple) asks you for only two things: pack and profile. Everything else is derived from smart defaults so you can go from zero to running agent in one command. This page documents every value that gets set automatically, so you know exactly what you’re getting.
Instance size
Instance size is determined by your profile:
All instances are ARM64 Graviton. To pick a different size, use advanced mode.
Security services
Builder and account_assistant profiles enable all five AWS security services by default. Personal assistant disables them all to keep cost near zero — that profile has no AWS write access, so there is nothing to monitor.
See AWS security services enabled by Lowkey for what each service does and approximate costs.
Region
Default region:us-east-1. Override by setting AWS_REGION or AWS_DEFAULT_REGION in your shell before running the installer, or by switching to advanced mode.
Volume sizes
Root volume is 40 GB for every pack. Data volume size depends on the pack:
OpenClaw and NemoClaw use a separate data volume for persistent agent state and workspaces. Packs that don’t maintain heavy state skip the data volume.
VPC settings
Simple mode creates a new VPC every time. Advanced mode prompts for VPC reuse if anyloki:managed=true VPC already exists in the region.
IAM managed policies
The EC2 instance gets an instance profile with a policy appropriate for the profile you chose:
Every profile also gets
AmazonSSMManagedInstanceCore so you can connect via SSM Session Manager.
SSH
SSH is disabled by default. The security group setsSSHAllowedCidr=127.0.0.1/32, which means no inbound SSH is reachable from outside the instance. Use SSM Session Manager to connect.
To enable SSH, run in advanced mode and set SSHAllowedCidr to your own IP CIDR (for example, 1.2.3.4/32).
Model defaults
Each pack ships with its own default model. The installer sets this automatically — you never have to look it up:Environment naming
Simple mode auto-generates an environment name using the format<pack>-<sequence>-<timestamp-suffix>:
loki:managed=true VPCs in your region so you never collide with a previous deployment.
Resource tagging
Every resource Lowkey creates is tagged with:loki:managed=trueloki:watermark=<env-name>
What simple mode does not decide for you
You still provide:- Pack — required; no default.
- Profile — defaults to
builderif you pass-ywithout--profile. - Deploy method — defaults to CloudFormation CLI.