Every field, exactly
This is what the agent collects, field by field. It is generated from a list the agent’s own tests produce, by building every message it sends with every field filled in, and the site does not build while a field on that list is missing here. Nothing is sent that is not on this page.
When it enrols
Section titled “When it enrols”Once, with the enrollment token, to get the host its identity.
| Field | What it is |
|---|---|
agent_version |
The agent’s version. |
csr |
A certificate signing request for a key pair the agent generated on the host. The private key never leaves it. |
facts.arch |
The CPU architecture. |
facts.cloud.instance_id |
Reserved, as above. Never sent. |
facts.cloud.provider |
Reserved for cloud facts. This agent never sends it, and does not query cloud metadata endpoints. |
facts.cloud.region |
Reserved, as above. Never sent. |
facts.codename |
Its VERSION_CODENAME, if it has one. |
facts.distro |
The distribution’s ID from /etc/os-release. |
facts.kernel |
The running kernel’s version. |
facts.version |
Its VERSION_ID. |
facts.virtualization |
The virtualisation type, if any. |
hostname |
The host’s name. |
machine_id |
/etc/machine-id, how Updawg recognises a rebuilt host. |
token |
The enrollment token. Used once to admit the host. |
When it renews its certificate
Section titled “When it renews its certificate”Before the host’s certificate expires.
| Field | What it is |
|---|---|
agent_version |
The agent’s version. |
csr |
A certificate signing request, for the same key pair or a new one. |
With every check-in
Section titled “With every check-in”About once a minute, while it waits for work.
| Field | What it is |
|---|---|
agent_version |
The agent’s version. Sent on every check-in, so an upgrade done by hand shows up within a minute. |
boot_id |
The kernel’s boot ID. It changes on every boot, which is how an unplanned reboot is noticed. |
install.channel |
The channel its package repository follows (stable or beta), read from /etc/apt/sources.list.d/updawg.list or /etc/yum.repos.d/updawg.repo. Not sent for a binary install. |
install.method |
How the agent was installed, apt, dnf, binary (install.sh’s binaries) or other, which decides how it updates itself. |
inventory_hash |
The hash of the last inventory it uploaded, so the service knows whether to ask for a new one. |
local_policy.mode |
The mode in /etc/updawg/agent.toml, observe or managed. |
local_policy.permitted_job_kinds[] |
The job kinds agent.toml permits. |
max_hold_s |
How long it would like the service to hold the request open while it waits for work. |
metrics.load1 |
The one-minute load average. |
metrics.mem_used_pct |
Memory in use, as a percentage. |
metrics.root_free_bytes |
Free space on /, in bytes. |
running_job_ids[] |
The jobs it is running. |
snapshots.provider |
The snapshot provider it would use, such as ZFS or LVM. |
snapshots.reason |
Why it can’t take snapshots, when it can’t. |
state.package_lock_held |
Whether another tool holds the package manager’s lock. |
state.pending_updates |
How many updates are available. |
state.reboot_required |
Whether the host needs a reboot (yes, no or unknown). |
state.security_updates |
How many of them the package manager calls security updates. |
state.services_need_restart[] |
Services that need restarting to pick up updated libraries. |
uptime_s |
Seconds since the host booted. |
With an inventory
Section titled “With an inventory”Every six hours, after every job that changes the host, and whenever the service asks. A full inventory lists every installed package; a delta lists those added and removed since the last one.
| Field | What it is |
|---|---|
base_hash |
For a delta, the hash of the inventory it is relative to. |
collected_at |
When it was collected. |
facts.arch |
The CPU architecture. |
facts.codename |
Its VERSION_CODENAME, if it has one. |
facts.distro |
The distribution’s ID from /etc/os-release. |
facts.ecosystem |
deb or rpm. |
facts.fqdn |
Its fully qualified domain name, if it has one. |
facts.hostname |
The host’s name. |
facts.kernel |
The running kernel’s version. |
facts.machine_id |
/etc/machine-id. |
facts.version_id |
Its VERSION_ID. |
facts.virtualization |
The virtualisation type, if any. |
frozen.kind |
What pins the host’s package sources in time, releasever (dnf) or snapshot (a dated archive). |
frozen.latest |
The newest release the host is offered, where the agent can tell. |
frozen.pinned |
What they are pinned to, such as 9.2 or 20240101T000000Z. |
hash |
The hash of the inventory after this one is applied. |
held_packages[] |
Packages held back (apt-mark hold, dnf versionlock). |
modules_reported |
Whether every package says its module stream, so one without is not modular. |
packages.added[].arch |
Its architecture. |
packages.added[].module |
On the RHEL family, the module stream it was installed from, such as nodejs:20. Without the build version and context. |
packages.added[].name |
An installed package’s name. |
packages.added[].repo |
The repository it came from. |
packages.added[].source.name |
The source package it was built from. |
packages.added[].source.version |
The source package’s version. |
packages.added[].version |
Its version. |
packages.removed[].arch |
Its architecture. |
packages.removed[].name |
A package removed since the last inventory. |
packages.removed[].version |
Its version. |
removals[].arch |
Its architecture. |
removals[].installed |
Its installed version. |
removals[].name |
A package an upgrade would remove. |
removals[].replaced_by.arch |
That package’s architecture. |
removals[].replaced_by.name |
The package that replaces it, if any. |
removals[].replaced_by.repo |
The repository that package comes from. |
removals[].replaced_by.version |
That package’s version. |
repositories[].enabled |
Whether it is enabled. |
repositories[].id |
A configured repository’s ID. |
repositories[].kind |
Its type, deb or rpm. |
repositories[].third_party |
Whether it is someone other than the distribution’s. |
repositories[].url |
For a third-party repository only, its URL, with any user name, password, query and fragment removed. A secret written into a URL’s path cannot be told from a directory and would be sent as it is. |
type |
full or delta. |
updates[].advisories[].fixed_in |
The version that fixes it. |
updates[].advisories[].id |
An advisory the package manager names for the update, such as USN-7000-1 or RHSA-2026:1234. |
updates[].advisories[].kind |
The advisory’s kind, such as security or bugfix. |
updates[].advisories[].severity |
The advisory’s severity, as the package manager gives it. |
updates[].arch |
Its architecture. |
updates[].candidate |
The version the package manager would install. |
updates[].installed |
The installed version. |
updates[].name |
A package with an update available. |
updates[].repo |
The repository the update comes from. |
updates[].source.name |
The source package it is built from. |
updates[].source.version |
The source package’s version. |
When it receives a job
Section titled “When it receives a job”Whether it will run it.
| Field | What it is |
|---|---|
accepted |
Whether it accepted the job. |
at |
When it decided. |
rejection_reason |
Why not, when it didn’t, such as a job kind agent.toml doesn’t permit. |
While a job runs
Section titled “While a job runs”The output of the package manager and of the agent itself, line by line. Package managers print package names, versions and repository URLs here.
| Field | What it is |
|---|---|
at |
When the line was written. |
line |
The line. |
seq |
Its position in the log. |
stream |
agent, stdout or stderr. |
When a job finishes
Section titled “When a job finishes”What the job did.
| Field | What it is |
|---|---|
changes[].arch |
Its architecture. |
changes[].from |
The version before. |
changes[].name |
A package the job changed. |
changes[].to |
The version after. |
error |
What went wrong, when the job failed. |
finished_at |
When it finished. |
health_checks[].detail |
When it failed, why — an exit status with one line of the command’s output, a timeout, or the HTTP status it got. |
health_checks[].duration_ms |
How long it took. |
health_checks[].name |
A health check from agent.toml, run after the job. |
health_checks[].passed |
Whether it passed. |
inventory_hash |
The hash of the inventory after the job. |
preflight[].items[] |
The things it found, such as packages or mount points. |
preflight[].name |
A preflight check’s name. |
preflight[].status |
pass, warn or fail. |
preflight[].summary |
What it found. |
reboot_required |
Whether the host needs a reboot now. |
snapshot_id |
The snapshot it took before changing anything, if it took one. |
started_at |
When it started. |
status |
succeeded, failed or rejected_by_host. |