Skip to main content

DeaconGuard

Find vulnerable packages and signs of compromise on your Linux machines, from one self-hosted dashboard.

1Install the server — the dashboard
curl -fsSL https://get.deaconguard.io | sh -
2Enroll each machine to scan — copy this line, with its one-time token, from the dashboard
curl -fsSL https://get.deaconguard.io | DEACONGUARD_TOKEN=deaconguard1.… sh -

Built for people who run Linux servers

Official advisories

Installed packages and the running kernel are checked against each distribution’s own security data: Ubuntu OVAL, the Debian Security Tracker, Red Hat OVAL and Amazon Linux ALAS.

More than packages

Optional checks verify system files against the package manager, look for malware and compromise indicators, review security configuration, and run the host’s ClamAV.

Agents with no open ports

Agents connect out to your server over HTTPS and trust only its certificate. Scanned machines need no inbound ports and no internet access.

Read-only and predictable

Every command DeaconGuard runs on a machine is a fixed, read-only string in its source. It never installs software or changes the system it scans.

Honest results

A skipped, partial or failed check is never shown as clean, and missing advisory data is never reported as zero vulnerabilities.

Signed, self-hosted, open source

One Go binary under the MIT license. You run the server; your data stays with you. Every release is signed with Sigstore.

How it works

1

Install the server

One command installs the package, creates the first dashboard account and starts the HTTPS dashboard on port 8443.

2

Enroll machines

The dashboard gives you a one-line command with a single-use token. Run it on each machine to install and enroll the agent.

3

Scan and review

Start scans from the dashboard or the CLI. The server evaluates each machine’s packages against current advisories and keeps the history.

Supported distributions

Ubuntu 18.04 – 26.04 LTS · Debian 12 and 13 · Red Hat Enterprise Linux 8 and 9 · Amazon Linux 2023 — on amd64 and arm64.

What each distribution’s data covers →