Server agent and check locations
Install, update and remove the agent that collects your servers' CPU, RAM, disk and network metrics, and the check location that checks monitors from other places.
On this page
Bekci's program can run on other servers in two different roles. They are separate records in the panel and don't show up on each other's screens:
| Server agent | Check location | |
|---|---|---|
| What it does | Sends the CPU, RAM, disk, network, temperature and Docker container metrics of the server it runs on, once a minute | Checks the monitors assigned to it from its own location and sends the results |
| In the panel | Servers → Add server | Settings → Check locations → New check location |
| Install methods | Docker, Linux (systemd), Windows | Docker |
| Supported systems | Linux amd64 and arm64, Windows amd64 | Linux amd64 and arm64 |
The agent uses no database. If it can't reach the main server (your Bekci panel), it holds its results and sends them once the connection is back.
Before you start#
BASE_URLmust be right. The install command takes the address the agent connects to fromBASE_URL. If the panel is athttps://bekci.example.com,BASE_URLmust be that too (how to set it).- HTTPS is recommended. By default the agent refuses to connect to an unencrypted (
http://) address; if the panel useshttp://, the install command adds that permission (PROBE_ALLOW_INSECURE=1) itself, but the token then travels over the network unencrypted. - The server you install the agent on must be able to reach your panel's address (an outgoing HTTPS connection is enough; you don't need to open any incoming port for the agent).
Install the server agent#
- In the panel, click Add server on the Servers page.
- Enter a Server name that will appear in the list and in notifications (e.g. “Web server Frankfurt”) and click Create.
- Choose the Docker, Native (systemd) or Windows tab under Install method and copy the command.
- Run the command on the server you want to watch, as described below.
Docker
For Linux servers with Docker. The command spans several lines and starts with sh <<'UPTIME_KURULUM'. Connect to the terminal as root and paste the whole command. If you aren't root, change the first line to sudo sh <<'UPTIME_KURULUM'.
The command:
- Creates
/etc/uptime-agent.envreadable only by root (mode 600) and writes the token into it. The token never appears on any command line (inpsoutput). - Starts a container named
uptime-agent. The container sees the server's disks and/proc,/sysinformation read-only, all Linux capabilities are dropped and memory is limited to 256 MB. - Downloads the program once, verifies it against the SHA-256 digest in the command and keeps it in the
uptime-agent-binvolume.
Linux (systemd)
For Linux servers without Docker (the Native (systemd) tab). Connect to the terminal as root and paste the whole command; if you aren't root, change the first line to sudo sh <<'UPTIME_KURULUM'.
The command:
- Downloads the program for the server's architecture (
x86_64oraarch64), verifies it with SHA-256 and saves it as/usr/local/bin/uptime. - Writes the token to
/etc/uptime-agent.env, readable only by root. - Creates a systemd service named
uptime-agent(/etc/systemd/system/uptime-agent.service), enables it at boot and starts it.
Windows
For Windows servers (Windows amd64).
- Search for PowerShell in the Start menu, right-click it and choose Run as administrator.
- Paste the one-line command you copied from the Windows tab in the panel and press Enter.
The command:
- Downloads the program, verifies it with SHA-256 and installs it as
C:\Program Files\Uptime\uptime.exe. - Writes the token to
C:\Program Files\Uptime\agent.env. Only SYSTEM and Administrators can access this folder. - Installs a service named
uptime-agentthat starts automatically with Windows and restarts itself on failure.
On Windows the load average is an approximation (derived from the processor queue); temperature and Docker containers aren't collected.
Install a check location#
A check location checks your monitors from another city or network too. That way you can tell whether an outage is seen from one place only or from everywhere.
- Under Settings → Check locations, click New check location.
- Give it a short name describing the place (e.g. “Frankfurt”) and save.
- Run the command shown on the server that will be the check location (it needs Docker), as root, pasting the whole command. It creates
/etc/uptime-probe.envand a container nameduptime-probe. - Close the window with I've copied it, close.
- On a monitor's edit page, select this check location under Locations and choose the Outage rule: down when any location, the majority of locations or all locations fail.
Files the install creates#
| Install | Program | Token (settings file) | Service / container |
|---|---|---|---|
| Server agent, Docker | uptime-agent-bin volume | /etc/uptime-agent.env | uptime-agent container |
| Server agent, systemd | /usr/local/bin/uptime | /etc/uptime-agent.env | uptime-agent service |
| Server agent, Windows | C:\Program Files\Uptime\uptime.exe | C:\Program Files\Uptime\agent.env | uptime-agent service |
| Check location, Docker | uptime-probe-bin volume | /etc/uptime-probe.env | uptime-probe container |
Updating#
The agent does not update itself: the program is downloaded and verified once, and the same program is used on every restart. That way, even if the server running your panel is compromised, no new program lands on your servers by itself. To update your agents after updating Bekci:
Get the current install command from the panel. Since the token is only shown once, this regenerates it (the old token stops working immediately):
- Server agent: on the server's page, Install command → Regenerate token and show command.
- Check location: in the Settings → Check locations list, Regenerate token in the row's menu.
For Docker installs, remove the old one first:
terminaldocker rm -f uptime-agent; docker volume rm uptime-agent-bin # server agent docker rm -f uptime-probe; docker volume rm uptime-probe-bin # check locationRun the new command. For systemd and Windows installs there's nothing to remove; the command replaces the program and the service.
Removing#
First delete the server or check location in the panel (its token stops working). Then, on the server where the agent runs:
Docker — server agent
docker rm -f uptime-agent
docker volume rm uptime-agent-bin
rm -f /etc/uptime-agent.envDocker — check location
docker rm -f uptime-probe
docker volume rm uptime-probe-bin
rm -f /etc/uptime-probe.envLinux (systemd)
systemctl disable --now uptime-agent
rm -f /etc/systemd/system/uptime-agent.service /usr/local/bin/uptime /etc/uptime-agent.env
systemctl daemon-reloadWindows
In a PowerShell opened as administrator:
& "$env:ProgramFiles\Uptime\uptime.exe" service uninstall
Remove-Item -Recurse -Force "$env:ProgramFiles\Uptime"The first line stops and deletes the service and removes the settings file (token) and the Event Log source; the second line deletes the program and its logs.
IP lock#
For new agents Lock to IP is on by default: the IP address of the agent's first connection is recorded (the full address for IPv4, the /64 block for IPv6), and requests from any other address are refused afterwards. Even if the token is stolen, it can't be used from another machine.
If the server's IP address changes (e.g. you moved the server), reset the lock; the next connection records the new address:
- Server agent: on the server's page, Settings → Reset lock.
- Check location: in the Settings → Check locations list, Edit in the row's menu → Reset lock.
You can turn the lock off entirely in the same place (the Lock to IP switch). If you suspect the token leaked, regenerate it and run the install command again (the update steps).
Troubleshooting#
Logs: on Docker docker logs uptime-agent (for a check location uptime-probe), on systemd journalctl -u uptime-agent, on Windows C:\Program Files\Uptime\agent.log. The agent's log messages are in Turkish; the table gives their meaning.
| What you see in the log or the panel | Cause and fix |
|---|---|
ana sunucu isteği reddetti: ajan devre dışı veya başka bir IP'ye kilitli (status 403) — “the main server refused: the agent is disabled or locked to another IP” | The server's IP changed or the agent is disabled in the panel. Reset the IP lock or enable the agent again. |
ana sunucu token'ı reddetti (status 401) — “the main server rejected the token” | The token is invalid (the server was deleted or the token regenerated). Get a new command from the panel and run it. |
Program özeti uyuşmuyor: kurulum komutunu panelden yenileyin — “program checksum mismatch: get a fresh install command from the panel” | The command is from an older version; Bekci has been updated. Get the current command from the panel; on Docker remove the container and the volume first (updating). |
| “The agent can’t read host metrics” in the panel | The agent runs in Docker without the server's /proc and /sys mounts. Use the command from the panel exactly as given, in full. |
PROBE_SERVER https olmalı; şifrelenmemiş http için PROBE_ALLOW_INSECURE=1 gerekir — “PROBE_SERVER must be https; unencrypted http needs PROBE_ALLOW_INSECURE=1” | The panel is at an http:// address. Put the panel behind HTTPS or add PROBE_ALLOW_INSECURE=1 to the settings file. |
ana sunucuya ulaşılamıyor, tekrar denenecek — “can't reach the main server, will retry” | The agent can't reach the panel's address. Check BASE_URL, DNS and outgoing connections from the agent's server (e.g. curl -sI https://bekci.example.com/healthz). |
| “Docker wasn’t found or the agent can’t access the Docker socket” in the panel | Container data isn't collected; that's normal if there's no Docker. If there is, make sure the /var/run/docker.sock mount from the command is in place. |
Something missing or wrong on this page? Report it on GitHub or email [email protected]