Skip to content

Install on Amazon Linux 2023

For Amazon Linux 2023, on x86_64 and aarch64. Or use the one-liner.

Terminal window
sudo tee /etc/yum.repos.d/updawg.repo > /dev/null <<'REPO'
[updawg]
name=Updawg
baseurl=https://pkg.updawg.net/rpm/stable
enabled=1
repo_gpgcheck=1
gpgcheck=0
gpgkey=https://pkg.updawg.net/updawg.asc
REPO

repo_gpgcheck=1 makes dnf check the signature on the repository’s metadata, which fixes the SHA-256 of every package in it. gpgcheck=0 because the packages themselves carry no signature of their own: the signed metadata is what vouches for them. Replace stable with beta for every build as soon as it passes its tests.

Terminal window
sudo dnf install updawg-agent

dnf asks once whether to import the repository’s key. Accept it only if the fingerprint it shows is 4FFF 29A6 2F24 ACF3 E043 76EE DFD5 B8C2 CBCF 67C5.

Terminal window
sudo UPDAWG_TOKEN=enr_... updawgctl enroll
sudo systemctl restart updawgd

The package starts updawgd, which waits while the host is not enrolled; the restart is what makes it pick up the identity enroll wrote. sudo updawgctl status shows where it stands.

Path What
/usr/bin/updawgd, /usr/bin/updawgctl The agent and its command line
/usr/lib/systemd/system/updawgd.service The service, enabled and started on install
/etc/updawg/agent.toml Its configuration — %config(noreplace), so an upgrade never replaces your edits
/var/lib/updawg/ Its identity and state, written on enrolment

Upgrades arrive with your ordinary dnf upgrade, and restart the service only if it was running.

Amazon Linux 2023 pins every host to the release it was built from, so dnf finds nothing newer until somebody moves it. The agent reports that pin, and the portal shows such a host as pinned rather than up to date — and as pinned, behind when a newer release is on offer. See dnf check-release-update.