Agent releases
Agents and connectors update themselves from releases published on the server. Admin → Agent releases manages them.
Publish a release
In the portal, under Publish a release:
| Field | Meaning |
|---|---|
| Component | agent or connector. |
| Version | Semantic version, e.g. 1.2.0. Each version can be released once (release_exists). |
| Channel | Stable, or Beta (only tenants on the beta channel get it). |
| Rollout (%) | Share of installations offered the release (0–100). |
| MSI | The installer, built with the release public key. |
| Notes | Release notes. |
The MSI is uploaded to object storage as a draft. Publish checks
the uploaded file's size and SHA-256 and signs the release with the
server's Ed25519 key (RMM_RELEASE_SIGNING_KEY; without it:
signing_key_missing). The newest published stable release also
becomes the MSI behind the enrollment download links and the AD agent
push.
You can raise the rollout percentage of a published release later, and delete a release: its MSI is deleted, installations already on it keep running.
From automation
The same API is used by CI with a dedicated token (RMM_RELEASE_TOKEN),
which only reaches the release endpoints:
.github/workflows/release.ymlinentrosity-axis-agentandentrosity-axis-connectorpublishes tagged releases (v*)..github/workflows/dev-release.ymlin the same repositories publishes a dev build of the MSI on every push tomain, as version0.1.<run>-dev.<commit>.
Both publish only when the repository variable RELEASE_PUBLISH_ENABLED
is true (Self-update publishing).
For Entrosity's production it is on in both repositories, so every push
to main of the agent or connector reaches production as a dev build.
Until v1.0.0 is tagged, dev builds are published to the stable
channel with rollout 100 %, so they reach every tenant. After tagging
v1.0.0, set the DEV_RELEASE_CHANNEL repository variable to beta (or
change the default in the workflow) so dev builds stop reaching stable
tenants.
By hand: make publish-release api=https://hub.entrosity.com/axis [product=connector] [channel=beta] [rollout=20] with RMM_RELEASE_TOKEN
set (Make targets).
Download a release
Download next to each release saves its MSI as
rmm-<component>-<version>.msi (for example to install a connector by
hand). Every click asks for a fresh link valid for one hour; drafts can be
downloaded once their MSI is uploaded. Only global admins can download
(GET /admin/agent-releases/{id}/download, not the release token), and
each download is recorded in the audit log as release.download.
How updates reach devices
An installation is offered a release when all of these hold:
- its tenant is active, and the release is the newest published one of the tenant's channel (beta tenants also see beta releases);
- it runs an older version;
- its rollout bucket (a stable hash of its ID, 0–99) is below the release's rollout percentage;
- it has no update job in flight, and was not offered this version in the last hour.
Offers are made when an agent connects and by a background job every five
minutes. Local builds (version dev, or with build metadata such as
1.0.0-dev+abc) are never updated; CI dev builds (0.1.<run>-dev.<commit>)
are.
RMM_MIN_AGENT_VERSION: installations older than this get the newest
release at once, ignoring the rollout percentage. Set it after a security
fix.
What the device does
- Verifies the release's Ed25519 signature against the public key
compiled into its build. A build without a key answers
update_unsigned; a bad signaturesignature_invalid. Nothing is downloaded before the signature checks out. - Downloads the MSI and verifies its size and SHA-256.
- Hands the install to a one-shot SYSTEM scheduled task
(
RMMAgentUpdate/RMMConnectorUpdate) and reports scheduled. - The task installs the MSI, then a watchdog checks that the service is running and still running 60 seconds later. Otherwise it reinstalls the previous MSI (rollback).
- After restarting, the agent reports
agent_updatedorupdate_failed.
Adoption
The adoption chart shows which versions are running across the installation, per component.
See Protocol → Self-update and Key rotation → Release signing key.