Skip to content

Install with Ansible

These tasks add the signed repository, install the package, and enrol a host only if it is not enrolled already: /var/lib/updawg/identity.json exists once it is. Keep the token in Ansible Vault; an enrollment token can enrol hosts into your organization until it expires or is revoked.

- name: Updawg agent
hosts: all
become: true
vars:
updawg_channel: stable
# updawg_enrollment_token: from vault
tasks:
- name: Repository key (apt)
ansible.builtin.get_url:
url: https://pkg.updawg.net/updawg.asc
dest: /etc/apt/keyrings/updawg.asc
mode: "0644"
when: ansible_facts.os_family == "Debian"
- name: Repository (apt)
ansible.builtin.apt_repository:
repo: "deb [signed-by=/etc/apt/keyrings/updawg.asc] https://pkg.updawg.net/apt {{ updawg_channel }} main"
filename: updawg
when: ansible_facts.os_family == "Debian"
- name: Repository (dnf)
ansible.builtin.yum_repository:
name: updawg
description: Updawg
baseurl: "https://pkg.updawg.net/rpm/{{ updawg_channel }}"
repo_gpgcheck: true
gpgcheck: false
gpgkey: https://pkg.updawg.net/updawg.asc
when: ansible_facts.os_family == "RedHat"
- name: The agent
ansible.builtin.package:
name: updawg-agent
state: present
- name: Enrol, once
ansible.builtin.command: updawgctl enroll
args:
creates: /var/lib/updawg/identity.json
environment:
UPDAWG_TOKEN: "{{ updawg_enrollment_token }}"
no_log: true
notify: Restart updawgd
handlers:
# The agent reads its identity when it starts.
- name: Restart updawgd
ansible.builtin.systemd:
name: updawgd
state: restarted

/etc/apt/keyrings exists on Debian 12 and Ubuntu 22.04 and later; on Ubuntu 20.04, create it first. To manage /etc/updawg/agent.toml too, template it after installing the package: the package never overwrites an edited copy.