Install without a package manager
For a host where the package isn’t an option, the agent also comes as two static
binaries, which you download and verify yourself. They are the current stable
build, at https://get.updawg.net/agent/latest/: x86_64 builds at the top, arm64
builds in aarch64/. They run on any supported distribution.
The package is the better choice wherever apt or dnf exists.
1. Download and verify
Section titled “1. Download and verify”mkdir updawg && cd updawgbase=https://get.updawg.net/agent/latestarch=$(uname -m); case $arch in aarch64|arm64) dir=aarch64/ ;; *) dir= ;; esacfor f in SHA256SUMS "${dir}updawgd" "${dir}updawgctl" updawgd.service; do curl -fsSL --create-dirs -o "$f" "$base/$f"donesha256sum --check --ignore-missing SHA256SUMSEvery line must say OK. --ignore-missing because SHA256SUMS also lists the
other architecture’s files and install.sh.
2. Install
Section titled “2. Install”sudo install -m 0755 "${dir}updawgd" "${dir}updawgctl" /usr/local/bin/sudo install -m 0644 updawgd.service /etc/systemd/system/updawgd.servicesudo install -d -m 0755 /etc/updawgThen write /etc/updawg/agent.toml. The one the installer writes is:
server = "https://agents.updawg.net"mode = "managed"
[permissions]allow = ["refresh", "preflight", "apply_patch", "dist_upgrade", "reboot", "snapshot", "self_update"]deny = []Every kind in allow still has to be approved and signed by your organization
before the agent will do it. Take a kind out to keep this host from ever doing it,
or set mode = "observe" for a host that must only report.
3. Enrol and start
Section titled “3. Enrol and start”sudo UPDAWG_TOKEN=enr_... /usr/local/bin/updawgctl enrollsudo systemctl daemon-reloadsudo systemctl enable --now updawgd.serviceUpdates
Section titled “Updates”Nothing updates these binaries on its own schedule. Your organization proposes an update in the portal, or turns on automatic updates, and the agent swaps its own binaries after checking them against a manifest signed with the release key. See updating the agent.