Kentik has joined Infoblox! Read the blog post

UA Backup and Restore

Prev Next

This article covers two methods for backing up and restoring a Universal Agent: a full directory backup recommended for most users, and an identity-only backup for infrastructure-as-code environments.

Back Up and Restore a Universal Agent

Each Universal Agent maintains a unique identity based on a cryptographic keypair. Preserving this identity is crucial for disaster recovery or when migrating the agent to a new host machine (VM). By restoring the agent's identity, you ensure that the Kentik platform recognizes the agent as the same entity, retaining its configuration and history without requiring re-authorization.

There are two methods for backing up the agent:

  1. Full Directory Backup (Recommended): Backs up the entire binary and configuration state.

  2. Identity-Only Backup (Advanced): Backs up only the specific key files required to recover the agent's identity.

This method involves archiving the entire /opt/kentik directory and is the simplest approach and is recommended for most users to back up and restore a Universal Agent.

Backup

  1. Ensure the agent is authorized and functioning.

  2. Create a backup of the entire /opt/kentik directory. You can use standard Linux tools such as  tar, rsync, or snapshotting tools to secure this directory.

Restore

To restore a failed agent or migrate to a new VM:

  1. Restore the /opt/kentik directory from your backup to the new host.

  2. Execute the agent repair command to fix permissions, recreate systemd service files, and start the service:

sudo /opt/kentik/bin/kagent repair

Note: This restore process works even when the new host has a different hostname or IP address.

Method 2: Identity-Only Backup (Advanced)

This method is useful for Infrastructure as Code (IaC) environments where you prefer to install a fresh Universal Agent binary but inject the previous agent's identity.

Backup

Locate and safely store the following two key files, which constitute the agent's identity:

  • /opt/kentik/components/kagent/current/conf/keys/private_key.pem

  • /opt/kentik/components/kagent/current/conf/keys/public_key.pem

Restore

To recover the agent state on a new or rebuilt host/VM:

  1. Install the Agent: Perform a fresh installation of the Kentik Universal Agent on the new host using the standard installation script or package.

  2. Stop the Agent: Ensure the service is stopped before swapping keys.

sudo systemctl stop kagent
  1. Restore the key files: Copy your backed-up private_key.pem and public_key.pem files to the target directory, overwriting any auto-generated keys:

    /opt/kentik/components/kagent/current/conf/keys/

  2. Restart the Agent: Once restarted, the agent will reconnect to the Kentik platform using the restored identity.

sudo systemctl restart kagent