Install with cloud-init
User data runs once, as root, on a host’s first boot. The token in it is readable by anyone who can read the instance’s metadata, so give each fleet a token that expires, and revoke it once the hosts are in.
With the one-liner:
#cloud-configruncmd: - curl -fsSL https://get.updawg.net | UPDAWG_TOKEN=enr_... shWith the repository, on Debian or Ubuntu:
#cloud-configruncmd: - install -d -m 0755 /etc/apt/keyrings - curl -fsSL -o /etc/apt/keyrings/updawg.asc https://pkg.updawg.net/updawg.asc - echo "deb [signed-by=/etc/apt/keyrings/updawg.asc] https://pkg.updawg.net/apt stable main" > /etc/apt/sources.list.d/updawg.list - apt-get update - apt-get install -y updawg-agent - UPDAWG_TOKEN=enr_... updawgctl enroll - systemctl restart updawgdand on the RHEL family or Amazon Linux 2023:
#cloud-configyum_repos: updawg: name: Updawg baseurl: https://pkg.updawg.net/rpm/stable enabled: true repo_gpgcheck: true gpgcheck: false gpgkey: https://pkg.updawg.net/updawg.ascruncmd: - dnf install -y updawg-agent - UPDAWG_TOKEN=enr_... updawgctl enroll - systemctl restart updawgd