Golden images
Install the agent in the image; enrol each host when it first boots, never in the image.
An enrolled agent’s identity — its key pair and certificate, in /var/lib/updawg/ —
belongs to one machine. Captured into an image, every host built from it would be
the same host to Updawg. The machine ID is the same problem one level down:
Updawg recognises a host by /etc/machine-id, as systemd does, so an image must not
carry one either.
In the image
Section titled “In the image”-
Install the package from the repository (Debian, Ubuntu, RHEL family, Amazon Linux). Do not enrol.
-
Before capturing, make sure nothing identifies this machine:
Terminal window sudo systemctl stop updawgdsudo rm -rf /var/lib/updawgsudo truncate -s 0 /etc/machine-idMost image builders already empty
/etc/machine-id; the agent’s directory is the part they do not know about.
On first boot
Section titled “On first boot”Enrol from cloud-init or your provisioning tool:
UPDAWG_TOKEN=enr_... updawgctl enrollsystemctl restart updawgdupdawgd is already running and waiting; it reads the identity when it starts.