FAQ
Does DeaconGuard change anything on the machines it scans?
No. Every command it runs is a fixed, read-only string in its source. It never installs software, changes configuration or deletes files. The only third-party program it runs is a ClamAV you already installed, and only for the antivirus check.
Why does the agent run as root?
A security scanner has to see every process, every system file and the firewall rules. Without root, the deeper checks only have partial coverage, and say so. The agent opens no ports; it only connects out to your server.
Do scanned machines need internet access?
Only to download the package at install time. After that, an agent only talks to your server; the server fetches the advisory data.
Why is the server's certificate self-signed? Is that safe?
Agents trust the server by its key fingerprint, which comes with the enrollment token, so they don't depend on a certificate authority. Your browser warns once; check the fingerprint that setup printed. You can also use your own certificate. See Architecture.
Can I scan Rocky Linux, AlmaLinux or CentOS Stream?
Not yet. DeaconGuard only scans distributions whose official advisory data it can use accurately; see Supported distributions.
Can I scan containers?
No. Reports cover the host's DPKG or RPM packages and its running kernel, not software inside containers.
Does a clean report mean my machine is secure?
No. It means DeaconGuard found nothing in what it checked. Checks that couldn't run, or couldn't run fully, are marked as such and never shown as clean.
How do I scan from cloud-init or Ansible?
Create a token, then run the install command with DEACONGUARD_TOKEN or --token-file. See Agents.
Is DeaconGuard free?
Yes. It is open source under the MIT license, and you host it yourself.