LawlietLAWLIET
Book a demo

Agents

A small service on each monitored host. It connects out to your Lawliet server on a heartbeat and never listens on a port.

Supported systems

PlatformRuns asStatus
Linux: Ubuntu 22.04 and 24.04, Debian 11 and 12, RHEL and Rocky 8 and 9systemd serviceField-tested
WindowsScheduled task as SYSTEMSupported
macOSlaunchd serviceSupported

The Linux agent needs Python 3.10 or newer.

What an agent does

Enrolling a host

Run ./lawliet token on the server, or open Environment, Install agent in the console, and copy the command for the platform.

# Linux, as root
curl -sSL https://your-server/api/v1/agents/download/linux | sudo bash -s -- \
  --server https://your-server --token <enrolment-token>

# Windows, PowerShell as Administrator
Invoke-WebRequest https://your-server/api/v1/agents/download/windows -OutFile install.ps1
.\install.ps1 -Server https://your-server -Token <enrolment-token>

# macOS
curl -sSL https://your-server/api/v1/agents/download/macos | sudo bash -s -- \
  --server https://your-server --token <enrolment-token>

Using a self-signed certificate? Each host has to trust it. ./lawliet tls --export writes the certificate to copy to your hosts.

How commands reach a host

Commands wait in a queue on the server. On its next heartbeat the agent collects them, checks each one's HMAC-SHA256 signature and timestamp, and runs it. A command older than ten minutes, or more than a minute in the future, is refused. This is why time sync matters on both ends.

Agent upgrades

Agents can upgrade themselves to a release signed with an Ed25519 key that we hold offline. An agent refuses any release without a valid signature. Automatic upgrade is off by default.