The server agent
One Python file, standard library only, MIT-licensed — read it before you run it: apps/api/agent/pc-agent.py.
Install
Servers → Add server shows a one-line install with a one-time code:
curl -fsSL https://checker.example.com/api/agent/install.sh | sudo bash -s -- --enroll pce_… --all--all also installs Trivy, CrowdSec with its firewall bouncer and automatic security updates when they are missing. --trust-ip <office IP> keeps your own address out of CrowdSec and fail2ban bans. --no-logs stops error lines from container logs being sent.
Run the same command without a code to update the agent in place — the token and settings are kept.
What it reports
Every 5 minutes: load and real CPU use, memory, disks, pending and security updates, CrowdSec, containers (state, health, memory, image), Swarm services, listening ports, hardening, access (SSH keys, sudoers), signs of compromise, Docker disk usage, and error lines from container logs — scrubbed of passwords, tokens, e-mail and IP addresses before they leave. Daily: Trivy on the host and every running image.
What it never does
- open a port, or accept a command
- run anything sent from Moatline
- send log lines other than errors, or environment values
The systemd units drop every capability except reading files and cap CPU and memory. Details: server monitoring.