Skip to main content

Requirements

Machines​

  • Linux on amd64 or arm64, running a supported distribution, with systemd for the services.
  • DeaconGuard is a single self-contained binary; it needs nothing else installed.
  • The install script needs curl, sha256sum, and either root or sudo.

The server can run on any Debian- or RHEL-family system. Agents only install on distributions DeaconGuard can scan.

The macOS builds run the server and the CLI, but cannot scan the Mac itself.

Accounts​

ComponentRuns asWhy
Server (deaconguard-server)its own deaconguard system userIt only needs its data directory and its port.
Agent (deaconguard-agent)rootA security scanner has to see every process, system file and firewall rule.
Local mode, CLIyour userOptional checks see more when sudo is allowed.

Network​

FromToPortPurpose
BrowsersServer8443/tcpDashboard
AgentsServer8443/tcpEnrollment, receiving scans, sending results
ServerDistribution advisory feeds443/tcpSecurity data
Machines being installedGitHub, get.deaconguard.io443/tcpDownloading the package (install time only)

Agents need no inbound ports and no internet access after installation.