The agent
What the Serversinc agent runs, what it can access, and how it talks to Serversinc.
Every managed server runs the Serversinc agent. It is the only component on the machine that Serversinc talks to. Metrics, container state, deployments, backups, commands, and hardening changes all pass through it.
The agent is open source: github.com/serversinc/agent.
How it runs
Section titled “How it runs”The agent runs as a Docker container:
| Setting | Value |
|---|---|
| Image | ghcr.io/serversinc/agent |
| User | root |
| Flags | --privileged --pid host --restart unless-stopped |
| Name | agent |
| Mounts | /var/run/docker.sock, and /root/agent |
/root/agent holds .env and agent_public_key.pem.
The env file holds SERVER_ID, CORE_URL, and SECRET_KEY. The PEM file is
the public key the agent uses to verify requests from Serversinc.
Imported and provisioned servers use the same install scripts. Both install
Docker if it is missing and start the managed reverse proxy on ports 80 and
443. The import script also adds a Serversinc public key to root’s
~/.ssh/authorized_keys.
Permissions
Section titled “Permissions”The agent has root-equivalent access to the host for the following:
- Docker: build images, create and replace containers, manage networks and volumes, and read logs.
- Host: server commands,
ufw,sshd_config, Fail2Ban, and package installs.
Treat access to a Serversinc organisation as root access to every server in it. Anyone who can run a command, deploy an application with a bind mount, or restore a volume can change the host.
How it talks to Serversinc
Section titled “How it talks to Serversinc”Traffic flows both ways:
- Agent → Serversinc. Reports and operation results over HTTPS, authenticated with the per-server secret key.
- Serversinc → agent. Requests over HTTPS on port 443, signed as an Ed25519
JWT that expires after five minutes. The agent checks the signature with
agent_public_key.pem.
The server must allow outbound HTTPS to api.serversinc.io and inbound TCP 443.
Inbound TCP 80 is needed for Let’s Encrypt HTTP-01 challenges on the agent
hostname and application domains.
What it does
Section titled “What it does”Reports
Section titled “Reports”| Report | Interval | Content |
|---|---|---|
| Heartbeat | 5 minutes | CPU utilisation and load, memory, disk, network, uptime |
| Docker events | As they happen | Container, image, network, and volume lifecycle events |
| State checks | Daily | Root SSH login, automatic updates, firewall, Fail2Ban, time sync |
| Operation results | On completion | Build, deployment, backup, and restore status |
A server is marked offline when no heartbeat arrives for 12 minutes. The agent may still be running; see When something stops reporting.
Acts on request
Section titled “Acts on request”- Builds and deployments. Clones GitHub repositories, builds images, pulls registry images, and performs recreate or rolling container swaps.
- Containers. Start, stop, restart, remove, read logs, and exec.
- Images, networks, and volumes. Create, inspect, prune, and remove.
- Commands. Runs manual and scheduled commands on the host with a two-minute timeout.
- Hardening. Toggles root SSH login,
ufw, Fail2Ban, and automatic updates, and opens or closes firewall ports. - Packages. Installs host packages that a hardening action needs.
- Backups and restores. Dumps databases and archives volumes to your storage provider, and restores them.
Updates
Section titled “Updates”The agent updates itself. The heartbeat response names a target version and image. When it differs from the running version, the agent pulls the image, starts the new version beside itself, and the new container checks its own health before it replaces the old one. If the new version fails that check, the old agent keeps running.
Remove the agent
Section titled “Remove the agent”Disconnecting a server deletes its Serversinc records and DNS hostname. It does not touch the machine. To remove Serversinc from the host:
docker rm -f agentrm -rf /root/agentOn an imported server, also remove the Serversinc key from
/root/.ssh/authorized_keys. Leave the reverse proxy running if other
containers still serve traffic through it.