Skip to main content

Agent releases

Agents and connectors update themselves from releases published on the server. Admin → Agent releases manages them.

Publish a release​

In the portal, under Publish a release:

FieldMeaning
Componentagent or connector.
VersionSemantic version, e.g. 1.2.0. Each version can be released once (release_exists).
ChannelStable, or Beta (only tenants on the beta channel get it).
Rollout (%)Share of installations offered the release (0–100).
MSIThe installer, built with the release public key.
NotesRelease notes.

The MSI is uploaded to object storage as a draft. Publish checks the uploaded file's size and SHA-256 and signs the release with the server's Ed25519 key (RMM_RELEASE_SIGNING_KEY; without it: signing_key_missing). The newest published stable release also becomes the MSI behind the enrollment download links and the AD agent push.

You can raise the rollout percentage of a published release later, and delete a release: its MSI is deleted, installations already on it keep running.

From automation​

The same API is used by CI with a dedicated token (RMM_RELEASE_TOKEN), which only reaches the release endpoints:

  • .github/workflows/release.yml in entrosity-axis-agent and entrosity-axis-connector publishes tagged releases (v*).
  • .github/workflows/dev-release.yml in the same repositories publishes a dev build of the MSI on every push to main, as version 0.1.<run>-dev.<commit>.

Both publish only when the repository variable RELEASE_PUBLISH_ENABLED is true (Self-update publishing). For Entrosity's production it is on in both repositories, so every push to main of the agent or connector reaches production as a dev build.

Dev builds go to the stable channel until 1.0.0

Until v1.0.0 is tagged, dev builds are published to the stable channel with rollout 100 %, so they reach every tenant. After tagging v1.0.0, set the DEV_RELEASE_CHANNEL repository variable to beta (or change the default in the workflow) so dev builds stop reaching stable tenants.

By hand: make publish-release api=https://hub.entrosity.com/axis [product=connector] [channel=beta] [rollout=20] with RMM_RELEASE_TOKEN set (Make targets).

Download a release​

Download next to each release saves its MSI as rmm-<component>-<version>.msi (for example to install a connector by hand). Every click asks for a fresh link valid for one hour; drafts can be downloaded once their MSI is uploaded. Only global admins can download (GET /admin/agent-releases/{id}/download, not the release token), and each download is recorded in the audit log as release.download.

How updates reach devices​

An installation is offered a release when all of these hold:

  • its tenant is active, and the release is the newest published one of the tenant's channel (beta tenants also see beta releases);
  • it runs an older version;
  • its rollout bucket (a stable hash of its ID, 0–99) is below the release's rollout percentage;
  • it has no update job in flight, and was not offered this version in the last hour.

Offers are made when an agent connects and by a background job every five minutes. Local builds (version dev, or with build metadata such as 1.0.0-dev+abc) are never updated; CI dev builds (0.1.<run>-dev.<commit>) are.

RMM_MIN_AGENT_VERSION: installations older than this get the newest release at once, ignoring the rollout percentage. Set it after a security fix.

What the device does​

  1. Verifies the release's Ed25519 signature against the public key compiled into its build. A build without a key answers update_unsigned; a bad signature signature_invalid. Nothing is downloaded before the signature checks out.
  2. Downloads the MSI and verifies its size and SHA-256.
  3. Hands the install to a one-shot SYSTEM scheduled task (RMMAgentUpdate / RMMConnectorUpdate) and reports scheduled.
  4. The task installs the MSI, then a watchdog checks that the service is running and still running 60 seconds later. Otherwise it reinstalls the previous MSI (rollback).
  5. After restarting, the agent reports agent_updated or update_failed.

Adoption​

The adoption chart shows which versions are running across the installation, per component.

See Protocol → Self-update and Key rotation → Release signing key.