Skip to content

Start here

Connect a server

Connect a server and the service keeps every scan, so you can see each server’s grade without logging in to it.

Tested. kiyesi connect and the agent run against the real service, worker and database in the build pipeline for every change.

Each server has its own token, which starts with ksv_. A token can only send this server’s results: it cannot read anything back. Until the dashboard arrives in the next release, whoever runs the service creates it:

Terminal window
pnpm --filter @kiyesi/api admin add-server <team-id> checkout-api-prod

The token is shown once. The service keeps only a hash of it.

On the server:

Terminal window
sudo kiyesi connect --token ksv_...

This checks the token with the service at api.kiyesi.dev, saves it to /etc/kiyesi/token where only root can read it, and starts the kiyesi system service. The first results arrive within a minute.

The service scans every 15 minutes and sends a heartbeat every minute, over HTTPS only. It opens no port and accepts no incoming connection. Every value is masked before it is sent.

It runs with hard limits: at most 20% of one CPU and 64 MB of memory, a read-only view of the system apart from its own folder, and no way to gain more privileges. If the service cannot be reached, results wait on disk and are sent when it returns.

Terminal window
sudo systemctl disable --now kiyesi

To send again, start it with sudo systemctl enable --now kiyesi. If a token is revoked, the agent keeps results on disk and says so in journalctl -u kiyesi; run kiyesi connect with a new token.