Skip to content

Install the agent

There are two ways to install the agent, and they end in the same place: updawgd running as a systemd service, updawgctl to enrol and inspect it, and /etc/updawg/agent.toml saying what it may do.

Either way you need an enrollment token first: in the portal, Add hosts, or Settings → Tokens → Enrollment tokens. It starts enr_ and is shown once.

Terminal window
curl -fsSL https://get.updawg.net | sudo UPDAWG_TOKEN=enr_... sh

It is short enough to read before you run it, and you should:

Terminal window
curl -fsSL https://get.updawg.net | less

It does what the guides below do by hand. It checks this is a supported Linux with systemd, adds the signed repository at pkg.updawg.net for apt or dnf (the stable channel; UPDAWG_CHANNEL=beta for the other), installs the updawg-agent package from it, enrols the host and starts updawgd.service. The package writes /etc/updawg/agent.toml only if there is none. The token reaches updawgctl through its environment, not its arguments, so other users cannot see it in ps. Anything it refuses, it refuses before changing anything.

A host that an earlier version of the one-liner set up, with the agent in /usr/local/bin, is moved onto the package: run it again. Its identity and its agent.toml stay as they are.

If you would rather not pipe anything into a root shell, or you manage repositories yourself, add the signed repository at pkg.updawg.net through your own package manager:

The repository’s indexes are signed with an OpenPGP key whose fingerprint is:

4FFF 29A6 2F24 ACF3 E043 76EE DFD5 B8C2 CBCF 67C5

Check it against the key you download before you trust it. The private half is held in a hardware security module and has never been anywhere else; our release pipeline can ask it for a signature and cannot read it.

Channel What is on it
stable Builds we have promoted after they ran on beta. Use this.
beta Every build of the agent that passed its tests, as soon as it did.

A package, once published, is never replaced: a version names the same file for ever.

Hosts without apt or dnf can run the static binaries instead: without a package manager.

Distribution Releases
Debian 12, 13
Ubuntu 20.04, 22.04, 24.04
RHEL, Rocky Linux, AlmaLinux, Oracle Linux 8, 9
Amazon Linux 2023

On x86_64 (amd64) and arm64 (aarch64), with systemd.

Terminal window
sudo updawgctl status

says whether the host is enrolled, when it last checked in, and which organization signing key it trusts — compare that fingerprint with the one in the portal. The host appears in the portal once its first inventory arrives, usually within a minute.

To see exactly what it reports about the host, without sending anything:

Terminal window
sudo updawgctl print-inventory