Skip to content

Reference

What the agent reads and sends

Read this before you install. It lists everything a scan reads, and it is built from the same file the agent uses, so it cannot drift from what the agent does.

What it sends

Nothing. A scan reads the server, prints a report and saves it on the same server. It makes no network request. Sending results to a dashboard comes in a later release, only after you connect the server yourself, and this page will list every field it sends.

What it reads

22 of the 22 checks are built today. Each one reads only what is listed here. Where a check needs root, the reason is given; without root, that part is skipped and never counted as passed.

Health

Load

The 15-minute load average in /proc/loadavg and the number of CPU cores in /proc/cpuinfo.

No root needed

Memory and swap

Memory and swap totals in /proc/meminfo.

No root needed

Disk

The mounted file systems in /proc/self/mounts, and the space and inodes on each.

No root needed

Containers

Each container's state, restart count and health status, read from the Docker socket.

Root for part of itThe Docker socket can be read only by root and the docker group.

Out-of-memory kills

The kernel log for the last 24 hours, through journalctl or /var/log/kern.log.

Root for part of itOn Ubuntu the kernel log can be read only by root and the adm group.

SSL certificates

The certificates in /etc/letsencrypt/live, Caddy's certificate folders, and the certificate files named in nginx and Apache settings.

Root for part of itCertificate folders such as /etc/letsencrypt/live can be read only by root.

Backups

The age of the newest file in each backup folder named in /etc/kiyesi/config.yaml.

Root for part of itBackup folders are often readable only by root.

Pending updates

The security updates apt has waiting, from a dry run that changes nothing (apt-get -s upgrade), and the date Kiyesi first saw each one.

No root needed

Security

Open ports

The ports listening on public addresses, from /proc/net/tcp and /proc/net/tcp6, and the ports Docker publishes.

No root needed

Exposed databases

Whether MongoDB, Redis, PostgreSQL or MySQL listen on a public address or are published by Docker, and whether the firewall on this server blocks them.

Root for part of itReading the firewall rules needs root.

Docker bypassing the firewall

The ports Docker publishes on all addresses, and the ufw rules for them.

Root for part of itReading the ufw rules and the Docker socket needs root.

SSH settings

/etc/ssh/sshd_config and the files in /etc/ssh/sshd_config.d.

No root needed

Firewall

Whether ufw, firewalld or an nftables or iptables rule set is on.

Root for part of itWhen ufw and firewalld are off, reading nftables or iptables rules needs root.

Login attack protection

Whether fail2ban, sshguard or CrowdSec is running, and whether SSH allows password login.

No root needed

Secrets in files

Environment files, Compose files and shell history in the folders listed under secrets.paths in /etc/kiyesi/config.yaml. Kiyesi reports where a secret is, never its value.

Root for part of itOther users' files and /root can be read only by root.

Risky containers

Each running container's settings for privileged mode, mounted volumes and user, read from the Docker socket.

Root for part of itThe Docker socket can be read only by root and the docker group.

Known vulnerabilities

System packages and container images, checked by Trivy if it is already installed. Kiyesi never downloads Trivy or its database during a scan.

Root for part of itTrivy needs root to read every system package and the Docker socket.

Data location

Server location

The cloud provider's own details: /run/cloud-init/instance-data.json, the maker in /sys/class/dmi/id/sys_vendor, and the provider's metadata address on its local network (169.254.169.254). Nothing is sent there; the scan only reads the region.

No root needed

Database connections

The database hosts in env files, Compose files and connection settings in the folders under secrets.paths. Only the host and port are kept, never the user or password.

Root for part of itOther users' files and /root can be read only by root.

Backup destinations

The storage targets in rclone settings, restic repositories, AWS CLI settings, and the backup commands in cron jobs and scripts under secrets.paths.

Root for part of itrclone settings and cron jobs in /root and other users' folders can be read only by root.

Outside services

The log, monitoring, email and SMS services named in env files and Compose files, such as Sentry, SMTP hosts, Twilio and Termii.

Root for part of itOther users' files and /root can be read only by root.

Payment data tag

The databases listed under payment_data in /etc/kiyesi/config.yaml.

No root needed

What it sends once connected

A one-off kiyesi scan sends nothing. After kiyesi connect, the agent sends two things to the service address you gave, over HTTPS only, and accepts no incoming connection:

  • The scan report, every 15 minutes: the same grade, findings, fixes and data-location rows you see in the terminal. Host names and ports of databases and backups are sent; user names, passwords and tokens are not.
  • A heartbeat, every minute: only the time, so a server that stops reporting can be noticed.

Before anything leaves the server, every value is masked: passwords in addresses, settings whose names say they hold a secret, passwords given to tools such as mysql -p and redis-cli -a, and known token shapes all become [masked]. The service masks everything again before it stores it. Each batch has an id, so a batch sent twice is stored once.

What it writes

A scan changes nothing on the server. It writes only its own files: the report, kept as/var/lib/kiyesi/report-<date>.txt (or in ~/.local/state/kiyesi/when run without root), with the last 30 kept, and /var/lib/kiyesi/state.yaml, which records the day it first saw each waiting security update.

kiyesi connect also writes the token to /etc/kiyesi/token, readable by root only, the service address to /etc/kiyesi/agent.yaml, and the system service to/etc/systemd/system/kiyesi.service. Results that cannot be sent wait in/var/lib/kiyesi/outbox, which never grows past 20 MB: the oldest are dropped first.

The rules it keeps

  • Read-only. It never changes a file, a setting or a container. It prints the fix, and you run it.
  • Open source. The agent is public, so anyone can read what it does before installing it.
  • Local by default. A one-off scan sends nothing off the server.
  • Secrets never leave. It reports that a secret exists and where, never its value.
  • Outgoing only. It opens no port and accepts no incoming connection.
  • Easy to remove. One command uninstalls it.
  • No AI and no third parties. Findings go only to the service's own storage.

The trust rules page explains each one.