Skip to content

Golden images

Install the agent in the image; enrol each host when it first boots, never in the image.

An enrolled agent’s identity — its key pair and certificate, in /var/lib/updawg/ — belongs to one machine. Captured into an image, every host built from it would be the same host to Updawg. The machine ID is the same problem one level down: Updawg recognises a host by /etc/machine-id, as systemd does, so an image must not carry one either.

  1. Install the package from the repository (Debian, Ubuntu, RHEL family, Amazon Linux). Do not enrol.

  2. Before capturing, make sure nothing identifies this machine:

    Terminal window
    sudo systemctl stop updawgd
    sudo rm -rf /var/lib/updawg
    sudo truncate -s 0 /etc/machine-id

    Most image builders already empty /etc/machine-id; the agent’s directory is the part they do not know about.

Enrol from cloud-init or your provisioning tool:

Terminal window
UPDAWG_TOKEN=enr_... updawgctl enroll
systemctl restart updawgd

updawgd is already running and waiting; it reads the identity when it starts.