On this page
Network
Allow port 8443 only from the networks your administrators and agents are in.
Agents need no inbound ports. Their only connection is outbound, to the server.
Certificates
The self-signed certificate is safe for agents, which pin its key . For browsers, check the fingerprint once, or use your own certificate with --tls-cert and --tls-key.
Back up /var/lib/deaconguard/tls/. If the key is lost, agents must be enrolled again.
Accounts
Use a long, unique password for every dashboard account. Every account is an administrator.
Remove accounts that are no longer needed: sudo -u deaconguard deaconguard user remove NAME. This signs them out everywhere.
Review the Audit log for unexpected sign-ins, tokens or enrollments.
Enrollment tokens
Create a token just before you enroll a machine, and revoke tokens you didn't use.
Treat an unused token like a password: anyone with it can enroll a machine with your server until it expires.
Keep it current
Upgrade regularly; security fixes go into the latest minor version. Watch the repository's releases on GitHub to be notified.
Verify releases you install by hand.