Install script
The install script is the recommended way to install and upgrade DeaconGuard.
Server
curl -fsSL https://get.deaconguard.io | sh -
Agent
Run the command from the dashboard's Enroll a machine dialog. It carries the machine's single-use enrollment token:
curl -fsSL https://get.deaconguard.io | DEACONGUARD_TOKEN=deaconguard1.… sh -
What the script does
- Detects the distribution and the processor (amd64 or arm64).
- Downloads the matching
.debor.rpmpackage and the release'schecksums.txtfrom GitHub over HTTPS. - When cosign is installed, verifies that
checksums.txtwas signed by DeaconGuard's release workflow. - Checks the package against
checksums.txt. Nothing is installed when a check fails. - Installs the package, then runs
deaconguard setup serverordeaconguard setup agent.
get.deaconguard.io redirects to the latest release's install.sh on GitHub.
Server or agent?
| You run | The script sets up |
|---|---|
… | sh - on a new machine | a server |
… | DEACONGUARD_TOKEN=… sh - | an agent, enrolled with that token |
… | sh - on a machine that is already an enrolled agent | an upgrade of the agent (it never turns an agent into a server) |
… | sh -s -- --server or --agent | the mode you name |
Root and sudo
Run the script as a normal user. Downloads and checks run as you; installing the package and setting up the service use sudo, which may ask for your password. As root, the script runs without sudo.
Options
Options go after sh -s --:
curl -fsSL https://get.deaconguard.io | sh -s -- --listen 0.0.0.0:9443
| Option or variable | Effect |
|---|---|
DEACONGUARD_TOKEN=… | Enroll an agent with this token. |
DEACONGUARD_VERSION=0.4.0 or --version 0.4.0 | Install that release instead of the latest. |
--server, --agent | Choose the mode explicitly. |
Server: --listen, --tls-cert/--tls-key, --admin-user/--admin-password-file | See Server. |
Agent: --token-file FILE, --force | See Agents. |
Read the script first
To read the script before running it:
curl -fsSLO https://github.com/Cloudopsshell/deaconguard/releases/latest/download/install.sh
less install.sh
sh install.sh
Without the script
To install the package yourself, see Manual install.