Install the agent
There are two ways to install the agent, and they end in the same place: updawgd
running as a systemd service, updawgctl to enrol and inspect it, and
/etc/updawg/agent.toml saying what it may do.
Either way you need an enrollment token first: in the portal, Add hosts, or
Settings → Tokens → Enrollment tokens. It starts enr_ and is shown once.
The one-liner
Section titled “The one-liner”curl -fsSL https://get.updawg.net | sudo UPDAWG_TOKEN=enr_... shIt is short enough to read before you run it, and you should:
curl -fsSL https://get.updawg.net | lessIt does what the guides below do by hand. It checks this is a supported Linux with
systemd, adds the signed repository at pkg.updawg.net for apt or dnf (the
stable channel; UPDAWG_CHANNEL=beta for the other), installs the
updawg-agent package from it, enrols the host and starts updawgd.service. The
package writes /etc/updawg/agent.toml only if there is none. The token reaches
updawgctl through its environment, not its arguments, so other users cannot see it
in ps. Anything it refuses, it refuses before changing anything.
A host that an earlier version of the one-liner set up, with the agent in
/usr/local/bin, is moved onto the package: run it again. Its identity and its
agent.toml stay as they are.
The package repository
Section titled “The package repository”If you would rather not pipe anything into a root shell, or you manage
repositories yourself, add the signed repository at pkg.updawg.net through your
own package manager:
- Debian and Ubuntu — apt
- RHEL, Rocky Linux, AlmaLinux and Oracle Linux — dnf
- Amazon Linux 2023 — dnf
The repository’s indexes are signed with an OpenPGP key whose fingerprint is:
4FFF 29A6 2F24 ACF3 E043 76EE DFD5 B8C2 CBCF 67C5Check it against the key you download before you trust it. The private half is held in a hardware security module and has never been anywhere else; our release pipeline can ask it for a signature and cannot read it.
Channels
Section titled “Channels”| Channel | What is on it |
|---|---|
stable |
Builds we have promoted after they ran on beta. Use this. |
beta |
Every build of the agent that passed its tests, as soon as it did. |
A package, once published, is never replaced: a version names the same file for ever.
Hosts without apt or dnf can run the static binaries instead: without a package manager.
Supported
Section titled “Supported”| Distribution | Releases |
|---|---|
| Debian | 12, 13 |
| Ubuntu | 20.04, 22.04, 24.04 |
| RHEL, Rocky Linux, AlmaLinux, Oracle Linux | 8, 9 |
| Amazon Linux | 2023 |
On x86_64 (amd64) and arm64 (aarch64), with systemd.
After installing
Section titled “After installing”sudo updawgctl statussays whether the host is enrolled, when it last checked in, and which organization signing key it trusts — compare that fingerprint with the one in the portal. The host appears in the portal once its first inventory arrives, usually within a minute.
To see exactly what it reports about the host, without sending anything:
sudo updawgctl print-inventory