This article covers two methods for backing up and restoring a Universal Agent: a full directory backup recommended for most users, and an identity-only backup for infrastructure-as-code environments.
Back Up and Restore a Universal Agent
Each Universal Agent maintains a unique identity based on a cryptographic keypair. Preserving this identity is crucial for disaster recovery or when migrating the agent to a new host machine (VM). By restoring the agent's identity, you ensure that the Kentik platform recognizes the agent as the same entity, retaining its configuration and history without requiring re-authorization.
There are two methods for backing up the agent:
Full Directory Backup (Recommended): Backs up the entire binary and configuration state.
Identity-Only Backup (Advanced): Backs up only the specific key files required to recover the agent's identity.
Method 1: Full Directory Backup (Recommended)
This method involves archiving the entire /opt/kentik directory and is the simplest approach and is recommended for most users to back up and restore a Universal Agent.
Backup
Ensure the agent is authorized and functioning.
Create a backup of the entire
/opt/kentikdirectory. You can use standard Linux tools such astar,rsync, or snapshotting tools to secure this directory.
Restore
To restore a failed agent or migrate to a new VM:
Restore the
/opt/kentikdirectory from your backup to the new host.Execute the agent repair command to fix permissions, recreate
systemdservice files, and start the service:
sudo /opt/kentik/bin/kagent repairNote: This restore process works even when the new host has a different hostname or IP address.
Method 2: Identity-Only Backup (Advanced)
This method is useful for Infrastructure as Code (IaC) environments where you prefer to install a fresh Universal Agent binary but inject the previous agent's identity.
Backup
Locate and safely store the following two key files, which constitute the agent's identity:
/opt/kentik/components/kagent/current/conf/keys/private_key.pem/opt/kentik/components/kagent/current/conf/keys/public_key.pem
Restore
To recover the agent state on a new or rebuilt host/VM:
Install the Agent: Perform a fresh installation of the Kentik Universal Agent on the new host using the standard installation script or package.
Stop the Agent: Ensure the service is stopped before swapping keys.
sudo systemctl stop kagentRestore the key files: Copy your backed-up
private_key.pemandpublic_key.pemfiles to the target directory, overwriting any auto-generated keys:/opt/kentik/components/kagent/current/conf/keys/Restart the Agent: Once restarted, the agent will reconnect to the Kentik platform using the restored identity.
sudo systemctl restart kagent