Server
The server hosts the dashboard, stores results, evaluates packages against the advisories and hands scans to agents. The install script sets it up for you. After installing the package yourself, run:
sudo deaconguard setup server
Setup creates the first dashboard account, enables and starts the deaconguard-server service on port 8443, and prints the dashboard's addresses and the certificate's fingerprint. Running it again keeps the existing accounts and settings.
The certificate
On its first start the server creates a self-signed certificate in /var/lib/deaconguard/tls/. Browsers warn about it once; check that the fingerprint matches the one setup printed.
Agents don't depend on that warning: every enrollment token carries the certificate's fingerprint, and agents trust only that certificate. See Architecture.
Setup options
These options work with deaconguard setup server, and the install script passes them on.
| Option | Use |
|---|---|
--listen ADDRESS:PORT | Listen elsewhere than 0.0.0.0:8443. |
--tls-cert FILE --tls-key FILE | Use your own certificate. Use absolute paths; the deaconguard user must be able to read both files. Agents enrolled earlier keep working when the new certificate is trusted by their system for the server's name; otherwise enroll them again. |
--admin-user NAME --admin-password-file FILE | Create the first account without prompts, for automation. Delete the file afterwards. |
Setup saves these in /etc/systemd/system/deaconguard-server.service.d/10-setup.conf, so package upgrades keep them.
Accounts
Manage dashboard accounts as the deaconguard user:
sudo -u deaconguard deaconguard user add alice
sudo -u deaconguard deaconguard user passwd alice
sudo -u deaconguard deaconguard user list
sudo -u deaconguard deaconguard user remove alice
Every account is an administrator. Changing a password or removing an account signs it out everywhere.
Built-in protections
- Failed sign-ins and enrollments are rate-limited per address.
- Sessions last 12 hours.
- The Audit log page records sign-ins, tokens, enrollments, scans and removals.
Running without systemd
deaconguard serve --listen 0.0.0.0:8443
Any address other than loopback turns on HTTPS and sign-in. Create an account first with deaconguard user add.