What the agent collects
This is the whole list. To see the exact bytes a host would send, on the host, without sending anything:
sudo updawgctl print-inventory --jsonFor every field the agent sends, message by message, see every field, exactly. It is generated from the agent’s own protocol, and this site does not build while a field is missing from it.
When it enrols
Section titled “When it enrols”- Hostname and
/etc/machine-id(how Updawg recognises a rebuilt host). - Distribution, release and codename, from
/etc/os-release. - Kernel version and CPU architecture.
- Virtualisation type, if any.
- The agent’s version, and a certificate signing request for a key pair it generated itself. The private key never leaves the host.
With every check-in
Section titled “With every check-in”About once a minute, while it waits for work:
- Boot ID and uptime — how an unplanned reboot is noticed.
- Whether a reboot is required, and which services need restarting after updates.
- How many updates are pending, and how many the package manager calls security.
- Whether another tool holds the package manager’s lock.
- Load average, memory used (as a percentage) and free space on
/. - A hash of the last inventory it uploaded, and the IDs of jobs it is running.
- What
/etc/updawg/agent.tomlallows: the mode and the job kinds it would accept. - Whether it can take snapshots, and if not, why.
With an inventory
Section titled “With an inventory”Every six hours, after every job that changes the host, and whenever the service asks for a fresh one:
- Installed packages: name, version, architecture, the repository it came from, and the source package it was built from.
- Available updates: name, architecture, installed and candidate versions, the repository, the source package, and any advisory the package manager names for it (ID, severity, kind, fixed version).
- Packages an upgrade would remove, and what replaces them.
- Held packages (
apt-mark hold,dnf versionlock). - Repositories: ID, type, whether enabled, and whether it is the distribution’s own. For a third-party repository, its URL — with any user name, password, query and fragment removed. A secret written into a URL’s path cannot be told from a directory and would be sent as it is; do not put credentials there.
- Whether the package sources are pinned to a release or a dated snapshot.
After a job
Section titled “After a job”What the job did: its outcome, the packages it changed from and to, the output of the package manager while it ran, the result of each health check, and any snapshot it took.
- The contents of files, other than
/etc/os-releaseand/etc/machine-id. - Environment variables, process lists or command lines.
- Users, logins, SSH keys, shell history or any credential.
- Network configuration, open ports or neighbouring hosts.
- Cloud instance metadata: the agent does not query metadata endpoints.