Requirements
Machines
- Linux on amd64 or arm64, running a supported distribution, with systemd for the services.
- DeaconGuard is a single self-contained binary; it needs nothing else installed.
- The install script needs
curl,sha256sum, and either root orsudo.
The server can run on any Debian- or RHEL-family system. Agents only install on distributions DeaconGuard can scan.
The macOS builds run the server and the CLI, but cannot scan the Mac itself.
Accounts
| Component | Runs as | Why |
|---|---|---|
Server (deaconguard-server) | its own deaconguard system user | It only needs its data directory and its port. |
Agent (deaconguard-agent) | root | A security scanner has to see every process, system file and firewall rule. |
| Local mode, CLI | your user | Optional checks see more when sudo is allowed. |
Network
| From | To | Port | Purpose |
|---|---|---|---|
| Browsers | Server | 8443/tcp | Dashboard |
| Agents | Server | 8443/tcp | Enrollment, receiving scans, sending results |
| Server | Distribution advisory feeds | 443/tcp | Security data |
| Machines being installed | GitHub, get.deaconguard.io | 443/tcp | Downloading the package (install time only) |
Agents need no inbound ports and no internet access after installation.