Skip to content

Configuration

The agent reads /etc/updawg/agent.toml when it starts. Change it and restart the service: sudo systemctl restart updawgd.

Local configuration always wins. Your organization can narrow what a host does — approve fewer changes, or none — but nothing it sends can widen what this file allows. Neither the installer nor a package upgrade ever rewrites the file once it exists.

Key Default Meaning
server — (required) Where the agent checks in: https://agents.updawg.net.
mode "managed" managed runs jobs your organization approved and signed, if [permissions] allows their kind. observe only reports: it refreshes its inventory and runs preflights, and refuses every job that would change the host, whatever is approved.

Which kinds of job this host will accept. Every job still has to be approved and signed by your organization; this is what the host will do at most.

Key Default Meaning
allow [] The kinds this host accepts. Empty accepts nothing, so a truncated file fails closed.
deny [] Kinds refused even if allowed. Deny beats allow.

The kinds:

Name Jobs it covers Changes the host
refresh Collect and upload a fresh inventory No
preflight Check whether a change would succeed, without making it No
apply_patch Install exactly the approved package versions Yes
dist_upgrade Upgrade to an approved release (Debian, Ubuntu, RHEL family) Yes
reboot Reboot Yes
snapshot Take a snapshot before a change, and roll back to one Yes
self_update Update the agent itself Yes

Examples: a host nobody may restart — take out reboot. A host that stays on its release — take out dist_upgrade, or add it to deny.

Key Default Meaning
inventory_interval "6h" How often to collect and upload a full inventory. It also uploads one after every job that changes the host, and when the service asks.
refresh_metadata "1h" How often to refresh the package manager’s metadata (apt-get update, dnf makecache).

Durations are a number and a unit: s, m, h or d.

Before a change, the agent takes a snapshot where it can, so the change can be rolled back.

Key Default Meaning
provider "auto" auto detects one at start; or snapper (btrfs), zfs, lvm (thin-provisioned), or none.
keep 3 How many of its own snapshots to keep. Older ones are removed.
min_free_mb 1024 Take no snapshot with less than this free, in MiB, where it would live: the change needs room for the old files and the new.

How the host warns people before a job reboots it. Whether it may reboot at all is reboot in [permissions].

Key Default Meaning
delay "1m" Time between the warning and the reboot. Rounded up to whole minutes, and never less than one.
message "Updawg: rebooting shortly to finish an approved update" What logged-in users see.

Checks run after every job that changes the host. A failing check marks the job failed, and halts a staged rollout before it reaches more hosts. A check that cannot run counts as failing, never as passing.

Each entry has a name, a type, and a timeout (default "5s"):

[[health_check]]
name = "nginx"
type = "systemd"
unit = "nginx.service"
[[health_check]]
name = "app answers"
type = "http"
url = "http://127.0.0.1:8080/healthz"
expect_status = 200 # the default
[[health_check]]
name = "database reachable"
type = "command"
argv = ["/usr/local/bin/check-db", "--quick"]
timeout = "10s"

command takes an argument list and runs it directly, never through a shell: there is no quoting to get wrong and nothing to inject into.

What the installer and the packages write:

server = "https://agents.updawg.net"
mode = "managed"
[permissions]
allow = ["refresh", "preflight", "apply_patch", "dist_upgrade", "reboot", "snapshot", "self_update"]
deny = []