What the installer puts on a host
The installer writes to four places on a host: one binary directory, one library directory, one configuration directory and one data directory, plus the systemd units that run the connector and its plugins. This page lists all of it, with the owner and mode of each path, so a host can be audited against it. The install runbook describes the order the installer works in. A Wazuh Cloud environment is not installed this way and has none of these paths.
Paths
| Path | Owner and mode | What lives there | Who reads it |
|---|---|---|---|
/usr/local/bin/fleet-connector | root, 0755 | The connector binary. | systemd, and an operator running a command. |
/usr/local/bin/fleet-connector.prev | root, 0755 | The previous binary, kept after an update for a rollback. Only an update creates it. | The confirm step and fleet-connector rollback. |
/usr/local/lib/fleet-connector/core/<version>/ | root, 0755 | One directory per connector version the host has installed. | fleet-connector rollback --to and fleet-connector status. |
/usr/local/lib/fleet-connector/plugins/<service>/<version>/ | root, 0755 | One directory per plugin version the host has installed. | The plugin unit, through current. |
/usr/local/lib/fleet-connector/plugins/<service>/current | root, symlink | Points at the plugin version that runs. It is the one answer to what is installed, and it is removed when the plugin is. | The plugin unit, the connector and the reconciler. |
/usr/local/lib/fleet-connector/fleet-connector-confirm.sh | root, 0755 | The confirm step, a POSIX shell script. | fleet-connector-confirm.service. |
/etc/fleet-connector/connector.yaml | root, 0600 | The connector configuration. See Connector configuration. | The connector. |
/etc/fleet-connector/plugins/ | root, 0755 | Created empty. The machine owner's directory for one file per plugin, <service>.yaml, of which the connector reads a single key, exec. See Connector services. | The connector and the reconciler, read only. |
/var/lib/fleet-connector/ | root, 0711 | The identity: connector_id at 0644, cert.pem and key.pem at 0600, and ca.pem, the public certificate the connector trusts the gateway by. | The connector. |
/var/lib/fleet-connector/discovered-login.json | root, 0600 | The Wazuh login the installer found on the host, when it found one. See The Wazuh login the installer finds. | The connector, which copies it into the files of each service installed through Fleet. |
/var/lib/fleet-connector/plugins/ | root, 0711 | One state directory per plugin, and the connector's own notes on each, which only root writes. | The connector and the reconciler. |
/var/lib/fleet-connector/plugins/<service>/ | fleet-plugin-<service>, 0750 | The plugin's state directory. | The plugin, and the connector. |
/var/lib/fleet-connector/upgrade/ | root, 0700 | Staged downloads, the requests the daemon leaves for the reconciler, and the results and markers of every swap. | The connector, the reconciler and the confirm step. |
The data directory and its plugins/ directory are 0711 rather than 0700.
A plugin runs as its own unprivileged user and has to pass through both to reach
its own state directory. 0711 allows that and does not allow listing either
directory. The connector's key is 0600 and owned by root, and a plugin's
token is 0600 and owned by that plugin alone. The reconciler
puts the data directory back to 0711 if it finds it without that bit, because
at 0700 a plugin starts, reads nothing and reports nothing.
Inside a plugin's state directory
| File | Owner and mode | Written by |
|---|---|---|
targets.json and targets.yaml | root, group of the plugin, 0640 | The connector. The host's name and platform, the plugin generation, and any error in the machine owner's file for that plugin. It also carries the Wazuh login the installer found on the host, when one was found, and no other credential. |
env | root, group of the plugin, 0640 | The connector. Two identifiers the unit loads before it starts. |
bind/ and bind/token.json | fleet-plugin-<service>, 0700 and 0600 | The connector, once per token its service sends. Owned by the plugin because the plugin deletes the token once it has enrolled with it. |
credentials.json | fleet-plugin-<service>, 0600 | The plugin. The Wazuh login it works with and where that login came from, the installer or its own service. The name is the one the plugin contract recommends. |
identity/ | fleet-plugin-<service> | The plugin. The identity its own service issued when it enrolled. |
status.json | The plugin | The plugin. The connector reads it and reports it to Fleet. |
Removing a plugin empties its state directory, so every file in the table goes with it and the directory itself stays. Disallowing a service keeps all of them.
Units
Seven unit files go to /etc/systemd/system/:
fleet-connector.service, enabled and started by the installer.fleet-connector-reconcile.pathandfleet-connector-reconcile.timer, enabled by the installer, and thefleet-connector-reconcile.servicethey start.fleet-connector-confirm.timerandfleet-connector-confirm.service. The timer is never enabled. The reconciler starts it for each swap.fleet-plugin@.service, the template for every plugin. An instance is enabled only when Fleet asks the host for that plugin.
A directory fleet-plugin@<service>.service.d/ with the file
50-fleet-exec.conf exists only while the machine owner's own
/etc/fleet-connector/plugins/<service>.yaml allows that plugin to run as root.
Its content is fixed in the connector binary, and it is removed with the setting.
See Connector logs for what each unit writes.
System users
The installer creates fleet-plugin-mobius, fleet-plugin-pharos and
fleet-plugin-vesper, each a system account with a group of the same name,
whose home is its state directory, which the installer does not create. It creates them whether or not a plugin is ever installed,
because the connector writes files a plugin reads before that plugin's unit has
ever started, and their owner has to exist first. An account for any other
service is created by the reconciler the first time that plugin is prepared.
What a plugin can read
The plugin unit runs as fleet-plugin-<service>, with no capabilities, a
read-only view of the system, no access to home directories and a private
/tmp. Its state directory is the only place it can write. Its own
targets.json, env and token are readable to it. Another plugin's state
directory is not, because it belongs to another user at 0750. The connector's
key, certificate and connector.yaml are not either, because they are 0600
and owned by root. What a plugin reads beyond that is its own service's to
document.
Hosts installed by an older build
A host installed before the connector's paths moved may hold a config at
/etc/mobius/connector.yaml and an identity at /var/lib/mobius-connector. The
installer copies the config to /etc/fleet-connector/connector.yaml and leaves
the original in place. It copies the identity into /var/lib/fleet-connector
and removes the old directory. When a Wazuh Mobius connector is installed on the
same host both paths belong to it, and the installer touches neither.
What uninstalling keeps and removes
| Without a flag | With --purge | |
|---|---|---|
| Plugins | Stopped and disabled first | Stopped and disabled first |
Binary, .prev, units, exec drop-ins, confirm script | Removed | Removed |
/var/lib/fleet-connector | Kept, except discovered-login.json | Removed |
/etc/fleet-connector | Kept | Removed |
/usr/local/lib/fleet-connector and its versions | Kept | Removed |
The fleet-plugin-<service> users | Kept | Removed |
/etc/mobius/connector.yaml and /var/lib/mobius-connector | Kept | Removed, unless a Wazuh Mobius connector is installed |
The commands are in the command reference.