User guideAgents

Install the agent on Linux

You need an enrollment token. The portal shows the commands below with your address and token filled in; copy them from there.

Run on the host:

sh
curl -fsSL https://YOUR-PORTAL/install.sh | sudo PATCHPILOT_ENROLLMENT_TOKEN='ppe_…' sh -s -- --server https://YOUR-PORTAL

The installer:

  1. downloads the agent for the host's architecture from your portal and checks its SHA-256 checksum, refusing to install on a mismatch;
  2. installs it to /opt/patchpilot/bin/patchpilot-agent;
  3. creates and starts the systemd service patchpilot-agent;
  4. waits up to 60 seconds for the host to enroll, then deletes the token from the host.

When it succeeds it prints:

text
patchpilot: enrolled; running as systemd service patchpilot-agent
patchpilot: this host appears in the portal within a minute.

The host then appears under Devices.

With a package

For hosts where software must be installed as a package, the portal also offers a .deb (x86-64) and an .rpm (x86-64):

sh
# Debian or Ubuntu
curl -fsSLO https://YOUR-PORTAL/downloads/patchpilot-agent-amd64.deb
sudo dpkg -i patchpilot-agent-amd64.deb

# RHEL family
curl -fsSLO https://YOUR-PORTAL/downloads/patchpilot-agent-x86_64.rpm
sudo rpm -i patchpilot-agent-x86_64.rpm

Then put your portal address and token in /etc/patchpilot/agent.env:

sh
PATCHPILOT_SERVER_URL=https://YOUR-PORTAL
PATCHPILOT_ENROLLMENT_TOKEN=ppe_…

and start the service:

sh
sudo systemctl enable --now patchpilot-agent

Once the host has enrolled, empty the PATCHPILOT_ENROLLMENT_TOKEN line.

Checking the agent

sh
systemctl status patchpilot-agent      # is it running?
journalctl -u patchpilot-agent -f      # follow its log

Files on the host:

Path What it is
/opt/patchpilot/bin/patchpilot-agent The agent
/etc/patchpilot/agent.env Portal address (and the token until enrollment)
/var/lib/patchpilot/state.json The host's own credential, readable by root only

If it does not enroll

Message What to do
"download failed: is … reachable from this host?" The host cannot reach your portal on port 443. Check DNS, firewall and proxy
"the agent did not enroll within 60 seconds" Check the log (journalctl -u patchpilot-agent). Usually the token has expired, reached its use limit, or the host's address or name is outside the token's allowed networks or hostnames. Enrollment attempts in the portal shows the reason
"this host is not enrolled: set PATCHPILOT_ENROLLMENT_TOKEN" The token was not passed. Copy the full command from the portal
"run as root (sudo)" Run the command with sudo

If the token required approval, the host waits under Waiting for approval on the Enrollment page until an administrator approves it.

Running the installer again

Running the same command again on an enrolled host upgrades the agent and keeps the host's identity. No token is needed for that. See Upgrade agents.

Next