Start here
Connect a server
Connect a server and the service keeps every scan, so you can see each server’s grade without logging in to it.
Tested. kiyesi connect and the agent run against the real service, worker and database in the build pipeline for every change.
Get a server token
Section titled “Get a server token”Each server has its own token, which starts with ksv_. A token can only send this server’s results: it cannot read anything back. Until the dashboard arrives in the next release, whoever runs the service creates it:
pnpm --filter @kiyesi/api admin add-server <team-id> checkout-api-prodThe token is shown once. The service keeps only a hash of it.
Connect
Section titled “Connect”On the server:
sudo kiyesi connect --token ksv_...This checks the token with the service at api.kiyesi.dev, saves it to /etc/kiyesi/token where only root can read it, and starts the kiyesi system service. The first results arrive within a minute.
What runs from then on
Section titled “What runs from then on”The service scans every 15 minutes and sends a heartbeat every minute, over HTTPS only. It opens no port and accepts no incoming connection. Every value is masked before it is sent.
It runs with hard limits: at most 20% of one CPU and 64 MB of memory, a read-only view of the system apart from its own folder, and no way to gain more privileges. If the service cannot be reached, results wait on disk and are sent when it returns.
Stop sending
Section titled “Stop sending”sudo systemctl disable --now kiyesiTo send again, start it with sudo systemctl enable --now kiyesi. If a token is revoked, the agent keeps results on disk and says so in journalctl -u kiyesi; run kiyesi connect with a new token.