Skip to main content

Server

The server hosts the dashboard, stores results, evaluates packages against the advisories and hands scans to agents. The install script sets it up for you. After installing the package yourself, run:

sudo deaconguard setup server

Setup creates the first dashboard account, enables and starts the deaconguard-server service on port 8443, and prints the dashboard's addresses and the certificate's fingerprint. Running it again keeps the existing accounts and settings.

The certificate​

On its first start the server creates a self-signed certificate in /var/lib/deaconguard/tls/. Browsers warn about it once; check that the fingerprint matches the one setup printed.

Agents don't depend on that warning: every enrollment token carries the certificate's fingerprint, and agents trust only that certificate. See Architecture.

Setup options​

These options work with deaconguard setup server, and the install script passes them on.

OptionUse
--listen ADDRESS:PORTListen elsewhere than 0.0.0.0:8443.
--tls-cert FILE --tls-key FILEUse your own certificate. Use absolute paths; the deaconguard user must be able to read both files. Agents enrolled earlier keep working when the new certificate is trusted by their system for the server's name; otherwise enroll them again.
--admin-user NAME --admin-password-file FILECreate the first account without prompts, for automation. Delete the file afterwards.

Setup saves these in /etc/systemd/system/deaconguard-server.service.d/10-setup.conf, so package upgrades keep them.

Accounts​

Manage dashboard accounts as the deaconguard user:

sudo -u deaconguard deaconguard user add alice
sudo -u deaconguard deaconguard user passwd alice
sudo -u deaconguard deaconguard user list
sudo -u deaconguard deaconguard user remove alice

Every account is an administrator. Changing a password or removing an account signs it out everywhere.

Built-in protections​

  • Failed sign-ins and enrollments are rate-limited per address.
  • Sessions last 12 hours.
  • The Audit log page records sign-ins, tokens, enrollments, scans and removals.

Running without systemd​

deaconguard serve --listen 0.0.0.0:8443

Any address other than loopback turns on HTTPS and sign-in. Create an account first with deaconguard user add.