CLI reference
Run deaconguard help for this list on your machine, and deaconguard version for the installed version.
Scanning
| Command | Does |
|---|---|
deaconguard host add [--allow-sudo] | Register this machine (Linux). |
deaconguard host list | List hosts. |
deaconguard host sudo HOST_ID on|off | Allow or stop the deeper checks using sudo. |
deaconguard host remove HOST_ID | Remove a host; for an agent host, also revoke its agent. |
deaconguard scan HOST_ID [--checks LIST] [--json] | Scan a host. LIST is a comma-separated choice of packages,integrity,malware,config,antivirus. |
deaconguard scan --local [--allow-sudo] [--checks LIST] [--json] | Scan this machine without registering it. |
deaconguard report REPORT_ID [--json] | Show a saved report. |
Setup
Run as root after installing the package; the install script runs these for you.
| Command | Does |
|---|---|
deaconguard setup server [--listen ADDRESS:PORT] [--tls-cert FILE --tls-key FILE] [--admin-user NAME] [--admin-password-file FILE] | Create the first account and start the server service. |
deaconguard setup agent [--token-file FILE] [--force] | Enroll (asks for the token unless given) and start the agent service. |
Server and dashboard
| Command | Does |
|---|---|
deaconguard serve | Local dashboard at http://127.0.0.1:7480, no sign-in. |
deaconguard serve --listen 0.0.0.0:8443 [--tls-cert FILE --tls-key FILE] | Server: HTTPS dashboard with sign-in; agents can enroll. |
deaconguard user add|passwd USERNAME [--password-stdin] | Create an account, or change its password. |
deaconguard user list | List accounts. |
deaconguard user remove USERNAME | Remove an account and sign it out. |
deaconguard token create --server-url https://HOST:8443 | Create a single-use enrollment token, valid for 24 hours, and print the install command. |
On a server installed as a service, run user and token commands as the service user: sudo -u deaconguard deaconguard ….
Agent
| Command | Does |
|---|---|
deaconguard agent enroll TOKEN [--force] | Enroll with the server that made the token. |
deaconguard agent run | Wait for scans; this is what the deaconguard-agent service runs. |
deaconguard agent status | Show where this machine is enrolled. |