Documentation menu

Docs › Agent

Install the agent

Install inframole-agent on each server you want to map. You need to be a workspace admin or owner to create enrollment tokens.

Create an enrollment token

In InfraMole open Settings › Agents › New enrollment token. Give it a name (for example datacenter-1), choose how long it is valid (7 days by default) and, optionally, how many agents may use it.

The dialog then shows the token once, with ready-made install commands for Windows and Linux. One token can enroll many servers.

Check what would be sent (optional)

Before installing anything, you can download the binary (see Manual download) and print the exact report it would send. Nothing leaves the machine and nothing is installed:

.\inframole-agent.exe dry-run
./inframole-agent dry-run

Download, verify and install

Run the commands from the dialog on the server. They put the binary in a permanent location, stop if the checksum does not match, enroll the machine and install the service. They look like this:

Open PowerShell as Administrator:

$dir = "$env:ProgramFiles\InfraMole"; New-Item -ItemType Directory -Force $dir | Out-Null
Set-Location $dir
$arch = if ($env:PROCESSOR_ARCHITECTURE -eq "ARM64") { "arm64" } else { "amd64" }
$file = "inframole-agent_windows_$arch.exe"
$base = "https://github.com/InfraMole/agent/releases/latest/download"
Invoke-WebRequest "$base/$file" -OutFile inframole-agent.exe
Invoke-WebRequest "$base/SHA256SUMS" -OutFile SHA256SUMS
$expected = Get-Content SHA256SUMS | ForEach-Object { $h, $n = $_ -split '\s+\*?', 2; if ($n -eq $file) { $h } }
if (-not $expected -or (Get-FileHash inframole-agent.exe -Algorithm SHA256).Hash -ne $expected) { Remove-Item inframole-agent.exe; throw "Checksum mismatch: do not run this file." }
$env:INFRAMOLE_ENROLLMENT_TOKEN = "<token from the dialog>"
& "$dir\inframole-agent.exe" install --server https://inframole.example.com

The binary lives in C:\Program Files\InfraMole and runs as the inframole-agent Windows service (LocalSystem, automatic start). Its configuration is in C:\ProgramData\InfraMole\agent.json, readable only by SYSTEM and Administrators.

With sudo (or as root):

cd "$(mktemp -d)"
ARCH=$(uname -m | sed 's/x86_64/amd64/;s/aarch64/arm64/')
BASE=https://github.com/InfraMole/agent/releases/latest/download
curl -fsSLO "$BASE/inframole-agent_linux_$ARCH" -O "$BASE/SHA256SUMS"
sha256sum --ignore-missing -c SHA256SUMS && sudo install -m 0755 "inframole-agent_linux_$ARCH" /usr/local/bin/inframole-agent
sudo INFRAMOLE_ENROLLMENT_TOKEN=<token from the dialog> /usr/local/bin/inframole-agent install --server https://inframole.example.com

The binary lives in /usr/local/bin/inframole-agent and runs as the inframole-agent systemd unit (enabled, restarts automatically). Its configuration is in /etc/inframole/agent.json (mode 0600).

Passing the token through INFRAMOLE_ENROLLMENT_TOKEN keeps it out of the shell history and process list.

Confirm it is reporting

& "$env:ProgramFiles\InfraMole\inframole-agent.exe" status
sudo inframole-agent status

Within a minute the server appears in Settings › Agents and in the Library as Discovered. Connections become suggestions after a couple of reports.

Many servers

Use the same token everywhere (set Max agents if you want a cap), and your usual tools — GPO, Intune, Ansible, SSH loops — to run the same commands. The installation is idempotent: running it again on an enrolled machine re-enrolls it without creating a duplicate host.

Manual download

Binaries for Windows and Linux (x64 and ARM64), SHA256SUMS and its Sigstore signature are on the agent releases page. Verify by hand with:

sha256sum --ignore-missing -c SHA256SUMS

Firewalls and proxies

The agent only needs outbound HTTPS to your InfraMole address. It does not follow redirects and always verifies the server certificate (TLS 1.2+).

Behind an HTTP proxy, it uses the standard HTTPS_PROXY and NO_PROXY variables. Set them for the service:

As Administrator, set a machine-wide variable and restart the service:

[Environment]::SetEnvironmentVariable("HTTPS_PROXY", "http://proxy.example.com:3128", "Machine")
Restart-Service inframole-agent

If the service does not pick it up, restart Windows once.

sudo systemctl edit inframole-agent
# add:
# [Service]
# Environment=HTTPS_PROXY=http://proxy.example.com:3128
sudo systemctl restart inframole-agent