Skip to content
Serversinc Serversinc
Dashboard

The agent

What the Serversinc agent runs, what it can access, and how it talks to Serversinc.

Every managed server runs the Serversinc agent. It is the only component on the machine that Serversinc talks to. Metrics, container state, deployments, backups, commands, and hardening changes all pass through it.

The agent is open source: github.com/serversinc/agent.

The agent runs as a Docker container:

SettingValue
Imageghcr.io/serversinc/agent
Userroot
Flags--privileged --pid host --restart unless-stopped
Nameagent
Mounts/var/run/docker.sock, and /root/agent

/root/agent holds .env and agent_public_key.pem.

The env file holds SERVER_ID, CORE_URL, and SECRET_KEY. The PEM file is the public key the agent uses to verify requests from Serversinc.

Imported and provisioned servers use the same install scripts. Both install Docker if it is missing and start the managed reverse proxy on ports 80 and 443. The import script also adds a Serversinc public key to root’s ~/.ssh/authorized_keys.

The agent has root-equivalent access to the host for the following:

  • Docker: build images, create and replace containers, manage networks and volumes, and read logs.
  • Host: server commands, ufw, sshd_config, Fail2Ban, and package installs.

Treat access to a Serversinc organisation as root access to every server in it. Anyone who can run a command, deploy an application with a bind mount, or restore a volume can change the host.

Traffic flows both ways:

  • Agent → Serversinc. Reports and operation results over HTTPS, authenticated with the per-server secret key.
  • Serversinc → agent. Requests over HTTPS on port 443, signed as an Ed25519 JWT that expires after five minutes. The agent checks the signature with agent_public_key.pem.

The server must allow outbound HTTPS to api.serversinc.io and inbound TCP 443. Inbound TCP 80 is needed for Let’s Encrypt HTTP-01 challenges on the agent hostname and application domains.

ReportIntervalContent
Heartbeat5 minutesCPU utilisation and load, memory, disk, network, uptime
Docker eventsAs they happenContainer, image, network, and volume lifecycle events
State checksDailyRoot SSH login, automatic updates, firewall, Fail2Ban, time sync
Operation resultsOn completionBuild, deployment, backup, and restore status

A server is marked offline when no heartbeat arrives for 12 minutes. The agent may still be running; see When something stops reporting.

  • Builds and deployments. Clones GitHub repositories, builds images, pulls registry images, and performs recreate or rolling container swaps.
  • Containers. Start, stop, restart, remove, read logs, and exec.
  • Images, networks, and volumes. Create, inspect, prune, and remove.
  • Commands. Runs manual and scheduled commands on the host with a two-minute timeout.
  • Hardening. Toggles root SSH login, ufw, Fail2Ban, and automatic updates, and opens or closes firewall ports.
  • Packages. Installs host packages that a hardening action needs.
  • Backups and restores. Dumps databases and archives volumes to your storage provider, and restores them.

The agent updates itself. The heartbeat response names a target version and image. When it differs from the running version, the agent pulls the image, starts the new version beside itself, and the new container checks its own health before it replaces the old one. If the new version fails that check, the old agent keeps running.

Disconnecting a server deletes its Serversinc records and DNS hostname. It does not touch the machine. To remove Serversinc from the host:

Terminal window
docker rm -f agent
rm -rf /root/agent

On an imported server, also remove the Serversinc key from /root/.ssh/authorized_keys. Leave the reverse proxy running if other containers still serve traffic through it.