Skip to main content

What the installer puts on a host

The installer writes to four places on a host: one binary directory, one library directory, one configuration directory and one data directory, plus the systemd units that run the connector and its plugins. This page lists all of it, with the owner and mode of each path, so a host can be audited against it. The install runbook describes the order the installer works in. A Wazuh Cloud environment is not installed this way and has none of these paths.

Paths​

PathOwner and modeWhat lives thereWho reads it
/usr/local/bin/fleet-connectorroot, 0755The connector binary.systemd, and an operator running a command.
/usr/local/bin/fleet-connector.prevroot, 0755The previous binary, kept after an update for a rollback. Only an update creates it.The confirm step and fleet-connector rollback.
/usr/local/lib/fleet-connector/core/<version>/root, 0755One directory per connector version the host has installed.fleet-connector rollback --to and fleet-connector status.
/usr/local/lib/fleet-connector/plugins/<service>/<version>/root, 0755One directory per plugin version the host has installed.The plugin unit, through current.
/usr/local/lib/fleet-connector/plugins/<service>/currentroot, symlinkPoints at the plugin version that runs. It is the one answer to what is installed, and it is removed when the plugin is.The plugin unit, the connector and the reconciler.
/usr/local/lib/fleet-connector/fleet-connector-confirm.shroot, 0755The confirm step, a POSIX shell script.fleet-connector-confirm.service.
/etc/fleet-connector/connector.yamlroot, 0600The connector configuration. See Connector configuration.The connector.
/etc/fleet-connector/plugins/root, 0755Created empty. The machine owner's directory for one file per plugin, <service>.yaml, of which the connector reads a single key, exec. See Connector services.The connector and the reconciler, read only.
/var/lib/fleet-connector/root, 0711The identity: connector_id at 0644, cert.pem and key.pem at 0600, and ca.pem, the public certificate the connector trusts the gateway by.The connector.
/var/lib/fleet-connector/discovered-login.jsonroot, 0600The Wazuh login the installer found on the host, when it found one. See The Wazuh login the installer finds.The connector, which copies it into the files of each service installed through Fleet.
/var/lib/fleet-connector/plugins/root, 0711One state directory per plugin, and the connector's own notes on each, which only root writes.The connector and the reconciler.
/var/lib/fleet-connector/plugins/<service>/fleet-plugin-<service>, 0750The plugin's state directory.The plugin, and the connector.
/var/lib/fleet-connector/upgrade/root, 0700Staged downloads, the requests the daemon leaves for the reconciler, and the results and markers of every swap.The connector, the reconciler and the confirm step.

The data directory and its plugins/ directory are 0711 rather than 0700. A plugin runs as its own unprivileged user and has to pass through both to reach its own state directory. 0711 allows that and does not allow listing either directory. The connector's key is 0600 and owned by root, and a plugin's token is 0600 and owned by that plugin alone. The reconciler puts the data directory back to 0711 if it finds it without that bit, because at 0700 a plugin starts, reads nothing and reports nothing.

Inside a plugin's state directory​

FileOwner and modeWritten by
targets.json and targets.yamlroot, group of the plugin, 0640The connector. The host's name and platform, the plugin generation, and any error in the machine owner's file for that plugin. It also carries the Wazuh login the installer found on the host, when one was found, and no other credential.
envroot, group of the plugin, 0640The connector. Two identifiers the unit loads before it starts.
bind/ and bind/token.jsonfleet-plugin-<service>, 0700 and 0600The connector, once per token its service sends. Owned by the plugin because the plugin deletes the token once it has enrolled with it.
credentials.jsonfleet-plugin-<service>, 0600The plugin. The Wazuh login it works with and where that login came from, the installer or its own service. The name is the one the plugin contract recommends.
identity/fleet-plugin-<service>The plugin. The identity its own service issued when it enrolled.
status.jsonThe pluginThe plugin. The connector reads it and reports it to Fleet.

Removing a plugin empties its state directory, so every file in the table goes with it and the directory itself stays. Disallowing a service keeps all of them.

Units​

Seven unit files go to /etc/systemd/system/:

  • fleet-connector.service, enabled and started by the installer.
  • fleet-connector-reconcile.path and fleet-connector-reconcile.timer, enabled by the installer, and the fleet-connector-reconcile.service they start.
  • fleet-connector-confirm.timer and fleet-connector-confirm.service. The timer is never enabled. The reconciler starts it for each swap.
  • fleet-plugin@.service, the template for every plugin. An instance is enabled only when Fleet asks the host for that plugin.

A directory fleet-plugin@<service>.service.d/ with the file 50-fleet-exec.conf exists only while the machine owner's own /etc/fleet-connector/plugins/<service>.yaml allows that plugin to run as root. Its content is fixed in the connector binary, and it is removed with the setting. See Connector logs for what each unit writes.

System users​

The installer creates fleet-plugin-mobius, fleet-plugin-pharos and fleet-plugin-vesper, each a system account with a group of the same name, whose home is its state directory, which the installer does not create. It creates them whether or not a plugin is ever installed, because the connector writes files a plugin reads before that plugin's unit has ever started, and their owner has to exist first. An account for any other service is created by the reconciler the first time that plugin is prepared.

What a plugin can read​

The plugin unit runs as fleet-plugin-<service>, with no capabilities, a read-only view of the system, no access to home directories and a private /tmp. Its state directory is the only place it can write. Its own targets.json, env and token are readable to it. Another plugin's state directory is not, because it belongs to another user at 0750. The connector's key, certificate and connector.yaml are not either, because they are 0600 and owned by root. What a plugin reads beyond that is its own service's to document.

Hosts installed by an older build​

A host installed before the connector's paths moved may hold a config at /etc/mobius/connector.yaml and an identity at /var/lib/mobius-connector. The installer copies the config to /etc/fleet-connector/connector.yaml and leaves the original in place. It copies the identity into /var/lib/fleet-connector and removes the old directory. When a Wazuh Mobius connector is installed on the same host both paths belong to it, and the installer touches neither.

What uninstalling keeps and removes​

Without a flagWith --purge
PluginsStopped and disabled firstStopped and disabled first
Binary, .prev, units, exec drop-ins, confirm scriptRemovedRemoved
/var/lib/fleet-connectorKept, except discovered-login.jsonRemoved
/etc/fleet-connectorKeptRemoved
/usr/local/lib/fleet-connector and its versionsKeptRemoved
The fleet-plugin-<service> usersKeptRemoved
/etc/mobius/connector.yaml and /var/lib/mobius-connectorKeptRemoved, unless a Wazuh Mobius connector is installed

The commands are in the command reference.