Install on Amazon Linux 2023
For Amazon Linux 2023, on x86_64 and aarch64. Or use the one-liner.
1. Add the repository
Section titled “1. Add the repository”sudo tee /etc/yum.repos.d/updawg.repo > /dev/null <<'REPO'[updawg]name=Updawgbaseurl=https://pkg.updawg.net/rpm/stableenabled=1repo_gpgcheck=1gpgcheck=0gpgkey=https://pkg.updawg.net/updawg.ascREPOrepo_gpgcheck=1 makes dnf check the signature on the repository’s metadata, which
fixes the SHA-256 of every package in it. gpgcheck=0 because the packages
themselves carry no signature of their own: the signed metadata is what vouches for
them. Replace stable with beta for every build as soon as it passes its tests.
2. Install and enrol
Section titled “2. Install and enrol”sudo dnf install updawg-agentdnf asks once whether to import the repository’s key. Accept it only if the
fingerprint it shows is 4FFF 29A6 2F24 ACF3 E043 76EE DFD5 B8C2 CBCF 67C5.
sudo UPDAWG_TOKEN=enr_... updawgctl enrollsudo systemctl restart updawgdThe package starts updawgd, which waits while the host is not enrolled; the
restart is what makes it pick up the identity enroll wrote. sudo updawgctl status
shows where it stands.
What the package installs
Section titled “What the package installs”| Path | What |
|---|---|
/usr/bin/updawgd, /usr/bin/updawgctl |
The agent and its command line |
/usr/lib/systemd/system/updawgd.service |
The service, enabled and started on install |
/etc/updawg/agent.toml |
Its configuration — %config(noreplace), so an upgrade never replaces your edits |
/var/lib/updawg/ |
Its identity and state, written on enrolment |
Upgrades arrive with your ordinary dnf upgrade, and restart the service only if it
was running.
Amazon Linux’s release lock
Section titled “Amazon Linux’s release lock”Amazon Linux 2023 pins every host to the release it was built from, so dnf finds
nothing newer until somebody moves it. The agent reports that pin, and the portal
shows such a host as pinned rather than up to date — and as pinned, behind when
a newer release is on offer. See dnf check-release-update.