Offline agent packages
The third way to install an agent, for a host that has no route to download anything: download a package, carry it to the host (USB, an SMB share, scp) and install it there. Nothing is downloaded during the install.
| Method | When to use it |
|---|---|
| Install command | The host can reach this server: run one command on it. |
| Remote deployment | This server can log in to the hosts over SSH or WinRM and installs for you. |
| Offline package | The host cannot download anything. |
What is in a package
One archive per target: Linux x86-64 and Linux ARM64 as .tar.gz, Windows x64 as .zip. Inside one folder:
| File | What it is |
|---|---|
lawliet-agent-<os>-<arch> | The compiled agent this server serves, checked by the server before it is packed |
install_linux.sh or install_windows.ps1 | The installer this server serves |
lawliet-enrol.conf | The server address and an enrolment code with its expiry |
server-ca.pem | The server certificate, for a server with a self-signed certificate |
README.txt | The checks and the install commands |
SHA256SUMS | The SHA-256 of every other file |
A package never carries the server's enrolment secret. It carries an enrolment code made for it, which lets up to the chosen number of hosts enrol until it expires, and nothing else. Treat the package like a password until it expires, and delete it when you are done.
Making one
In the console
Agents > Install agent > Offline package: pick the target, a label, how many days the code is valid (default 7, at most 30), how many hosts it may enrol (default 50, at most 1000) and the address the hosts reach this server at. For a self-signed server the package carries the certificate the server serves, so there is nothing to paste.
Making a package needs the Deploy agents permission and a second signature. The approver sees the target, the number of hosts, the days, the address and the certificate. Once approved, Create package shows the enrolment code once, the package SHA-256 (note it down) and a download link. The link works once and for 15 minutes; a package nobody downloads is removed within the hour, and packages are never part of a backup.
On the server
sudo ./lawliet agent-package --os linux --arch amd64 --hosts 50 --days 7 --label "Plant floor"
sudo ./lawliet agent-package --os windows --hosts 20 --days 3 --label "Branch office"
It writes the package into the install directory (readable by root only; --out DIR for another place) and prints the package SHA-256, the certificate's subject and fingerprint, and the commands for the host. The code is recorded in the audit trail with the user who ran the command, and can be revoked in the console like any other.
Installing it
Step 0, on a trusted machine: compare the archive's SHA-256 (sha256sum <file>, or Get-FileHash -Algorithm SHA256 <file> on Windows) with the package SHA-256 the console or the CLI showed. Do not install it if they differ.
Linux, as root:
tar xzf lawliet-agent-linux-amd64-offline-<n>.tar.gz
sudo bash lawliet-agent-linux-amd64/install_linux.sh --offline-package lawliet-agent-linux-amd64
Windows, in Windows PowerShell as Administrator:
Expand-Archive .\lawliet-agent-windows-amd64-offline-<n>.zip -DestinationPath C:\LawlietPackage
cd C:\LawlietPackage\lawliet-agent-windows-amd64
powershell -NoProfile -ExecutionPolicy Bypass -File .\install_windows.ps1 -OfflinePackage .
The installer copies the package into a private folder, checks every file against SHA256SUMS, and refuses a package where anything does not match, a file is missing, or the archive holds a link or a path outside the package. It refuses a package for another CPU or operating system. Then it installs the agent, trusts the package's certificate, and starts the agent with the enrolment code. Once the agent has enrolled, the code is removed from the agent's configuration.
The checksum list travels inside the package, so a match proves the copy is complete and undamaged; step 0 is what proves nobody changed it on the way.
If the host cannot reach the server yet, the agent is installed anyway and keeps trying to enrol; it enrols once the server is reachable, as long as the code is still valid. After the code expires the server refuses it: make a new package and install it over the old one.
Codes: uses, expiry, revoking
The Enrolment codes list shows each code's label, target, uses, expiry, status (active, expired, exhausted, revoked) and the last host that enrolled with it. A use is counted only when a host enrols. Revoke stops a code at once and removes its package from the server; hosts already enrolled are not affected.
An enrolment code never takes over an agent already on record: a host whose earlier agent is still listed is refused with 409 until the old agent is deleted in the console. Every code made, every package download, every host that enrolled with a code and every revoke is in the audit trail.

