Skip to content

Install without a package manager

For a host where the package isn’t an option, the agent also comes as two static binaries, which you download and verify yourself. They are the current stable build, at https://get.updawg.net/agent/latest/: x86_64 builds at the top, arm64 builds in aarch64/. They run on any supported distribution.

The package is the better choice wherever apt or dnf exists.

Terminal window
mkdir updawg && cd updawg
base=https://get.updawg.net/agent/latest
arch=$(uname -m); case $arch in aarch64|arm64) dir=aarch64/ ;; *) dir= ;; esac
for f in SHA256SUMS "${dir}updawgd" "${dir}updawgctl" updawgd.service; do
curl -fsSL --create-dirs -o "$f" "$base/$f"
done
sha256sum --check --ignore-missing SHA256SUMS

Every line must say OK. --ignore-missing because SHA256SUMS also lists the other architecture’s files and install.sh.

Terminal window
sudo install -m 0755 "${dir}updawgd" "${dir}updawgctl" /usr/local/bin/
sudo install -m 0644 updawgd.service /etc/systemd/system/updawgd.service
sudo install -d -m 0755 /etc/updawg

Then write /etc/updawg/agent.toml. The one the installer writes is:

server = "https://agents.updawg.net"
mode = "managed"
[permissions]
allow = ["refresh", "preflight", "apply_patch", "dist_upgrade", "reboot", "snapshot", "self_update"]
deny = []

Every kind in allow still has to be approved and signed by your organization before the agent will do it. Take a kind out to keep this host from ever doing it, or set mode = "observe" for a host that must only report.

Terminal window
sudo UPDAWG_TOKEN=enr_... /usr/local/bin/updawgctl enroll
sudo systemctl daemon-reload
sudo systemctl enable --now updawgd.service

Nothing updates these binaries on its own schedule. Your organization proposes an update in the portal, or turns on automatic updates, and the agent swaps its own binaries after checking them against a manifest signed with the release key. See updating the agent.