{"version":1,"pages":[{"id":"pCkFoeTQfWljduRHgUud","title":"Introduction","pathname":"/","siteSpaceId":"sitesp_DWi0Q","description":"Overview of LinuxGuard's Linux security monitoring agent — what it does, who it is for, and how to navigate the documentation set."},{"id":"yHCvsjq4CJSXoGOUbqIH","title":"Get Started","pathname":"/get-started/get-started","siteSpaceId":"sitesp_DWi0Q","description":"Onboarding entry point for operators evaluating LinuxGuard — quick start, prerequisites, and choose-your-deployment guidance.","breadcrumbs":[{"label":"Get Started"}]},{"id":"VBXXIgQgWCtqVuXAcC3D","title":"Quick Start","pathname":"/get-started/get-started/quick-start","siteSpaceId":"sitesp_DWi0Q","description":"Install the LinuxGuard agent and verify enrollment in five minutes on a supported Linux host.","breadcrumbs":[{"label":"Get Started"},{"label":"Get Started"}]},{"id":"VHVCS6I3F9s4LflsIFUP","title":"Install","pathname":"/install/install","siteSpaceId":"sitesp_DWi0Q","description":"Install the LinuxGuard agent on supported Linux distributions — per-distro guides, prerequisites, and container deployment.","breadcrumbs":[{"label":"Install"}]},{"id":"nb6OAGrranrEvcTbyTZG","title":"Prerequisites","pathname":"/install/install/prerequisites","siteSpaceId":"sitesp_DWi0Q","description":"Tenant account, credentials, and system prerequisites required before installing the LinuxGuard agent.","breadcrumbs":[{"label":"Install"},{"label":"Install"}]},{"id":"VOMesVwVtGY2YoIxBbc6","title":"Multi-Architecture Support","pathname":"/install/install/multi-architecture","siteSpaceId":"sitesp_DWi0Q","description":"Per-architecture capability matrix for the LinuxGuard agent — ARMv7 Degraded mode, RISC-V best-effort, and the eBPF probe gap operators must plan around.","breadcrumbs":[{"label":"Install"},{"label":"Install"}]},{"id":"aP5TKU0OoRA9ymgF6k1f","title":"Debian / Ubuntu","pathname":"/install/install/debian-ubuntu","siteSpaceId":"sitesp_DWi0Q","description":"Install the LinuxGuard agent on Debian, Ubuntu, and derivatives via the APT repository at packages.linuxguard.io.","breadcrumbs":[{"label":"Install"},{"label":"Install"}]},{"id":"DXj7iKrcjOVwxTg3Io0b","title":"RedHat / CentOS","pathname":"/install/install/redhat-centos","siteSpaceId":"sitesp_DWi0Q","description":"Install the LinuxGuard agent on RedHat Enterprise Linux, CentOS, and CentOS Stream via the DNF/YUM repository at packages.linuxguard.io.","breadcrumbs":[{"label":"Install"},{"label":"Install"}]},{"id":"XkIkDXxb8yi26fDFsvzA","title":"SUSE / openSUSE","pathname":"/install/install/suse","siteSpaceId":"sitesp_DWi0Q","description":"Install the LinuxGuard agent on SUSE Linux Enterprise Server, openSUSE Leap, and openSUSE Tumbleweed via the zypper repository.","breadcrumbs":[{"label":"Install"},{"label":"Install"}]},{"id":"3oLioTrqPHVfQ0YQJoJG","title":"Alpine Linux","pathname":"/install/install/alpine","siteSpaceId":"sitesp_DWi0Q","description":"Install the LinuxGuard agent on Alpine Linux via the APK repository — OpenRC service management and musl libc considerations.","breadcrumbs":[{"label":"Install"},{"label":"Install"}]},{"id":"L7IG2Qz935IKUYqU4oq9","title":"Container Deployment","pathname":"/install/install/container","siteSpaceId":"sitesp_DWi0Q","description":"Decision guide for deploying the LinuxGuard agent in containers — scenario matrix, anti-patterns, and per-orchestrator spokes for Docker, Podman, docker-compose, and Kubernetes.","breadcrumbs":[{"label":"Install"},{"label":"Install"}]},{"id":"efVc7G3gMHGMj97zkofc","title":"Distroless image reference","pathname":"/install/install/container/distroless","siteSpaceId":"sitesp_DWi0Q","description":"Reference for the LinuxGuard agent distroless container image — contents, exclusions, security context, host paths, PSS compatibility, RBAC, and image-signing verification.","breadcrumbs":[{"label":"Install"},{"label":"Install"},{"label":"Container Deployment"}]},{"id":"DIbJ6mKfky4cySX0DNbM","title":"Ephemeral mode","pathname":"/install/install/container/ephemeral-mode","siteSpaceId":"sitesp_DWi0Q","description":"Configure the LinuxGuard agent in ephemeral container mode — TOTP enrol, in-memory cert chain, PID 1 auto-detection, TLS cache restart semantics.","breadcrumbs":[{"label":"Install"},{"label":"Install"},{"label":"Container Deployment"}]},{"id":"VsGylijjbkUsHSXu3Z0u","title":"Kubernetes DaemonSet","pathname":"/install/install/container/kubernetes-daemonset","siteSpaceId":"sitesp_DWi0Q","description":"Kubernetes DaemonSet deployment of the LinuxGuard agent — copy-pasteable YAML with PSS profile comment, line-by-line securityContext rationale, eBPF prerequisites, and RBAC.","breadcrumbs":[{"label":"Install"},{"label":"Install"},{"label":"Container Deployment"}]},{"id":"u3BcxqeQJSK5W7PdQeLR","title":"Downward API integration","pathname":"/install/install/container/downward-api","siteSpaceId":"sitesp_DWi0Q","description":"Kubernetes Downward API integration for the LinuxGuard agent — LINUXGUARD_NODE_NAME and LINUXGUARD_POD_UID via fieldRef, workload identity derivation.","breadcrumbs":[{"label":"Install"},{"label":"Install"},{"label":"Container Deployment"}]},{"id":"zWbTv85PDcex0GnNEhGH","title":"Enrollment tokens","pathname":"/install/install/container/enrollment-tokens","siteSpaceId":"sitesp_DWi0Q","description":"TOTP enrollment token flow for the LinuxGuard agent in containers — LINUXGUARD_ENROLL_TOKEN, valueFrom.secretKeyRef pattern, token-hash tag for renewal tracking.","breadcrumbs":[{"label":"Install"},{"label":"Install"},{"label":"Container Deployment"}]},{"id":"Ra0ky2s85yFQLF5z5GN4","title":"docker-compose","pathname":"/install/install/container/docker-compose","siteSpaceId":"sitesp_DWi0Q","description":"Deploy the LinuxGuard agent with docker-compose — compose.yaml example, capabilities, host paths, restart policy, and PID 1 considerations.","breadcrumbs":[{"label":"Install"},{"label":"Install"},{"label":"Container Deployment"}]},{"id":"0AzzEIxdDIuXSU3Q2tbm","title":"Podman","pathname":"/install/install/container/podman","siteSpaceId":"sitesp_DWi0Q","description":"Deploy the LinuxGuard agent under Podman — rootless vs rootful trade-offs, systemd quadlet integration, Docker-equivalent commands.","breadcrumbs":[{"label":"Install"},{"label":"Install"},{"label":"Container Deployment"}]},{"id":"62LIFUvcZ9sMAQdNuUzQ","title":"OCI multi-arch manifest","pathname":"/install/install/oci-multi-arch-manifest","siteSpaceId":"sitesp_DWi0Q","description":"OCI multi-arch manifest for the LinuxGuard agent container image — docker manifest inspect output, supported platforms, image digest stability, and per-platform pull syntax.","breadcrumbs":[{"label":"Install"},{"label":"Install"}]},{"id":"qud3VPmIOTxUVsiL8Q3o","title":"Configure","pathname":"/configure/configure","siteSpaceId":"sitesp_DWi0Q","description":"Enroll the LinuxGuard agent to your tenant and set group, tag, and environment flags so it starts sending telemetry to the console.","breadcrumbs":[{"label":"Configure"}]},{"id":"GK3aGFMvq3KNS8yjgpwn","title":"Log Level and Rotation","pathname":"/configure/configure/log-level-rotation","siteSpaceId":"sitesp_DWi0Q","description":"LinuxGuard agent log rotation defaults, configurable knobs, and runtime log level management via config set + SIGHUP reload.","breadcrumbs":[{"label":"Configure"},{"label":"Configure"}]},{"id":"ufyhtINUEmINS89tuWmV","title":"Operate","pathname":"/operate/operate","siteSpaceId":"sitesp_DWi0Q","description":"Day-2 operations for the LinuxGuard agent — service management, log inspection, signal handling, support bundles, and uninstall.","breadcrumbs":[{"label":"Operate"}]},{"id":"Gk9h2eCcWLWkOY3ISYIh","title":"Log Management","pathname":"/operate/operate/log-management","siteSpaceId":"sitesp_DWi0Q","description":"LinuxGuard agent log management — precise redaction scope, rate limiting drop summaries, and central log collection patterns for journald, syslog, and structured JSON shipping.","breadcrumbs":[{"label":"Operate"},{"label":"Operate"}]},{"id":"9hwKk3qjP7hecr5i9jzO","title":"Support Bundles","pathname":"/operate/operate/support-bundles","siteSpaceId":"sitesp_DWi0Q","description":"Support bundle collection and upload — pre-share PII warning, per-file redaction status, 180 MB cap, presigned S3 upload flow, and decision tree for when to collect.","breadcrumbs":[{"label":"Operate"},{"label":"Operate"}]},{"id":"IZaEgr3oMyb5RNAIQCUv","title":"Uninstallation","pathname":"/operate/operate/uninstallation","siteSpaceId":"sitesp_DWi0Q","description":"Uninstall the LinuxGuard agent from a Linux host — package removal, config cleanup, and de-enrollment from your tenant.","breadcrumbs":[{"label":"Operate"},{"label":"Operate"}]},{"id":"FesnW2pNCLC8AniMRovS","title":"Deploy at Scale","pathname":"/deploy-at-scale/deploy-at-scale","siteSpaceId":"sitesp_DWi0Q","description":"Deploy the LinuxGuard agent at scale using configuration-management tools and cloud-init mechanisms across Ansible, Chef, Puppet, AWS, GCP, and Azure.","breadcrumbs":[{"label":"Deploy at Scale"}]},{"id":"WVTFwbBCDeZiIeQrfSDg","title":"Deploy with Ansible","pathname":"/deploy-at-scale/deploy-at-scale/ansible","siteSpaceId":"sitesp_DWi0Q","description":"Deploy the LinuxGuard agent to a fleet of Linux hosts using an Ansible role with Vault-encrypted credentials and idempotent enrollment.","breadcrumbs":[{"label":"Deploy at Scale"},{"label":"Deploy at Scale"}]},{"id":"uuMWIQ7EbVft0tCN6izE","title":"Deploy with Chef","pathname":"/deploy-at-scale/deploy-at-scale/chef","siteSpaceId":"sitesp_DWi0Q","description":"Deploy the LinuxGuard agent at scale using a Chef cookbook with chef-vault credentials and idempotent enroll resource.","breadcrumbs":[{"label":"Deploy at Scale"},{"label":"Deploy at Scale"}]},{"id":"HyGSLW7NaADfr0yZ72Nr","title":"Deploy with Puppet","pathname":"/deploy-at-scale/deploy-at-scale/puppet","siteSpaceId":"sitesp_DWi0Q","description":"Deploy the LinuxGuard agent at scale using a Puppet module with Hiera eyaml credentials and idempotent enroll exec.","breadcrumbs":[{"label":"Deploy at Scale"},{"label":"Deploy at Scale"}]},{"id":"w3gcbWay12Dnmx9mXrRP","title":"Deploy with AWS EC2 User-Data","pathname":"/deploy-at-scale/deploy-at-scale/aws-userdata","siteSpaceId":"sitesp_DWi0Q","description":"Provision the LinuxGuard agent on AWS EC2 instances at launch using user-data scripts and credentials from AWS Secrets Manager.","breadcrumbs":[{"label":"Deploy at Scale"},{"label":"Deploy at Scale"}]},{"id":"1F5wAOGai4Q4dhNBtVUS","title":"Deploy with GCP Startup Script","pathname":"/deploy-at-scale/deploy-at-scale/gcp-startup","siteSpaceId":"sitesp_DWi0Q","description":"Provision the LinuxGuard agent on Google Compute Engine instances using startup-script metadata, Secret Manager, and an idempotency guard.","breadcrumbs":[{"label":"Deploy at Scale"},{"label":"Deploy at Scale"}]},{"id":"78RkMNaMqjlhxvXLPiyY","title":"Deploy with Azure","pathname":"/deploy-at-scale/deploy-at-scale/azure","siteSpaceId":"sitesp_DWi0Q","description":"Provision the LinuxGuard agent on Azure Virtual Machines using cloud-init or Custom Script Extension, with Key Vault credentials via managed identity.","breadcrumbs":[{"label":"Deploy at Scale"},{"label":"Deploy at Scale"}]},{"id":"RylwmP32Wk8cg70UxkdZ","title":"Respond","pathname":"/respond/respond","siteSpaceId":"sitesp_DWi0Q","description":"Active response and SecOps integration for LinuxGuard alerts — notification rules, webhooks, syslog, and SIEM forwarding.","breadcrumbs":[{"label":"Respond"}]},{"id":"P5iO9guON9Kl2RsiwhNG","title":"Notification Rules","pathname":"/respond/respond/notification-rules","siteSpaceId":"sitesp_DWi0Q","description":"Configure notification rules in the LinuxGuard console to route signals to webhook, syslog, and Splunk HEC delivery channels.","breadcrumbs":[{"label":"Respond"},{"label":"Respond"}]},{"id":"kg9lBD3vvAoEXM6s9xvQ","title":"Webhook Integration","pathname":"/respond/respond/webhook-integration","siteSpaceId":"sitesp_DWi0Q","description":"Deliver LinuxGuard security signals to an HTTPS endpoint using signed webhook requests with retry semantics.","breadcrumbs":[{"label":"Respond"},{"label":"Respond"}]},{"id":"vU78DlSkofrwfE1nRajn","title":"Syslog Forwarding","pathname":"/respond/respond/syslog-forwarding","siteSpaceId":"sitesp_DWi0Q","description":"Forward LinuxGuard security signals as syslog messages to a SIEM or log aggregator over TCP, UDP, or TLS transport.","breadcrumbs":[{"label":"Respond"},{"label":"Respond"}]},{"id":"DWMKcK4oikRIq5UUOBxF","title":"Splunk HEC Integration","pathname":"/respond/respond/splunk-hec-integration","siteSpaceId":"sitesp_DWi0Q","description":"Send LinuxGuard security signals to Splunk via the HTTP Event Collector with token authentication and index targeting.","breadcrumbs":[{"label":"Respond"},{"label":"Respond"}]},{"id":"lkGwmeQHwbKa9PMhTEU8","title":"Audit & Comply","pathname":"/audit-and-comply/audit-comply","siteSpaceId":"sitesp_DWi0Q","description":"Compliance mapping hub for LinuxGuard — three-tier vocabulary (Satisfies / Supports / Out of scope), framework version pin reference, scope statement template, and per-framework page template.","breadcrumbs":[{"label":"Audit & Comply"}]},{"id":"qG8P45RrMPWdAs6pAvCs","title":"PCI-DSS v4.0.1","pathname":"/audit-and-comply/audit-comply/pci-dss","siteSpaceId":"sitesp_DWi0Q","description":"PCI-DSS v4.0.1 control mapping — LinuxGuard agent and console capabilities aligned to Requirements 2, 6, 7, 8, 10, and 11 with Satisfies / Supports / Out of scope tiers.","breadcrumbs":[{"label":"Audit & Comply"},{"label":"Audit & Comply"}]},{"id":"y5j56wmQseHJnVPnFTxQ","title":"HIPAA","pathname":"/audit-and-comply/audit-comply/hipaa","siteSpaceId":"sitesp_DWi0Q","description":"HIPAA 45 CFR §164 control mapping — LinuxGuard agent and console capabilities aligned to Security Rule technical safeguards with Satisfies / Supports / Out of scope tiers.","breadcrumbs":[{"label":"Audit & Comply"},{"label":"Audit & Comply"}]},{"id":"PQ1ueTSBZiQ7xzdpS8wY","title":"SOC 2","pathname":"/audit-and-comply/audit-comply/soc2","siteSpaceId":"sitesp_DWi0Q","description":"SOC 2 TSC 2017 (rev 2022) control mapping — LinuxGuard agent and console capabilities aligned to Common Criteria and supplemental TSC categories with Satisfies / Supports / Out of scope tiers.","breadcrumbs":[{"label":"Audit & Comply"},{"label":"Audit & Comply"}]},{"id":"Ubeaam71BtXL8mJP1Kao","title":"GDPR","pathname":"/audit-and-comply/audit-comply/gdpr","siteSpaceId":"sitesp_DWi0Q","description":"GDPR Regulation (EU) 2016/679 control mapping — LinuxGuard agent and console capabilities aligned to Article 32 security of processing with IP-as-PII gotcha and Satisfies / Supports / Out of scope tie","breadcrumbs":[{"label":"Audit & Comply"},{"label":"Audit & Comply"}]},{"id":"LiGlqms5Wh5w3ALL7guE","title":"NIS2","pathname":"/audit-and-comply/audit-comply/nis2","siteSpaceId":"sitesp_DWi0Q","description":"NIS2 Directive (EU) 2022/2555 control mapping — LinuxGuard agent and console capabilities aligned to Article 21 risk management measures with member-state transposition note and Satisfies / Supports /","breadcrumbs":[{"label":"Audit & Comply"},{"label":"Audit & Comply"}]},{"id":"rlk8Y3UPRUQuQmBEJmzO","title":"DORA","pathname":"/audit-and-comply/audit-comply/dora","siteSpaceId":"sitesp_DWi0Q","description":"DORA Regulation (EU) 2022/2554 control mapping — LinuxGuard agent and console capabilities aligned to ICT risk management, incident reporting, and digital operational resilience testing with effective","breadcrumbs":[{"label":"Audit & Comply"},{"label":"Audit & Comply"}]},{"id":"ouRQPvpGursnFmpml25L","title":"EU AI Act","pathname":"/audit-and-comply/audit-comply/eu-ai-act","siteSpaceId":"sitesp_DWi0Q","description":"EU AI Act Regulation (EU) 2024/1689 control mapping — LinuxGuard host-layer telemetry for Art 12 record-keeping and Art 15 cybersecurity of high-risk AI.","breadcrumbs":[{"label":"Audit & Comply"},{"label":"Audit & Comply"}]},{"id":"uM35waCE3FlMTXcrFArl","title":"FedRAMP / StateRAMP","pathname":"/audit-and-comply/audit-comply/fedramp-stateramp","siteSpaceId":"sitesp_DWi0Q","description":"FedRAMP Rev 5 and StateRAMP control mapping — LinuxGuard agent and console capabilities aligned to NIST SP 800-53 Rev 5 control families AC, AU, CM, CP, IA, IR, SC, SI, SR with authorization-boundary","breadcrumbs":[{"label":"Audit & Comply"},{"label":"Audit & Comply"}]},{"id":"7B3Mmo0Qb2KaFslgOL9b","title":"HITRUST + FFIEC","pathname":"/audit-and-comply/audit-comply/hitrust-ffiec","siteSpaceId":"sitesp_DWi0Q","description":"HITRUST CSF v11.x and FFIEC CAT 2017 control mapping — LinuxGuard agent and console capabilities aligned to HITRUST access control, audit, incident response domains and FFIEC Domain 3 (Cybersecurity C","breadcrumbs":[{"label":"Audit & Comply"},{"label":"Audit & Comply"}]},{"id":"xCKAFGTJCVnd6jr5UuRV","title":"NIST CSF 2.0","pathname":"/audit-and-comply/audit-comply/nist-csf","siteSpaceId":"sitesp_DWi0Q","description":"NIST Cybersecurity Framework 2.0 control mapping — LinuxGuard agent and console capabilities aligned to PROTECT, DETECT, and RESPOND functions with Satisfies / Supports / Out of scope tiers.","breadcrumbs":[{"label":"Audit & Comply"},{"label":"Audit & Comply"}]},{"id":"AhgXRQaDmIjYpaZOVnfC","title":"ISO/IEC 27001:2022","pathname":"/audit-and-comply/audit-comply/iso-27001","siteSpaceId":"sitesp_DWi0Q","description":"ISO/IEC 27001:2022 control mapping — LinuxGuard agent and console capabilities aligned to Annex A Technological controls (A.8.x) with :2013 transition note and Satisfies / Supports / Out of scope tier","breadcrumbs":[{"label":"Audit & Comply"},{"label":"Audit & Comply"}]},{"id":"4Y9NOCW01XILtBQoRGIs","title":"CIS Controls v8.1","pathname":"/audit-and-comply/audit-comply/cis-controls","siteSpaceId":"sitesp_DWi0Q","description":"CIS Controls v8.1 control mapping — LinuxGuard agent and console capabilities aligned to the 18 control families with explicit separation from CIS Benchmarks and Satisfies / Supports / Out of scope ti","breadcrumbs":[{"label":"Audit & Comply"},{"label":"Audit & Comply"}]},{"id":"um8vVOnr7M1t7qdBVCOG","title":"CIS Benchmarks (Linux)","pathname":"/audit-and-comply/audit-comply/cis-benchmarks","siteSpaceId":"sitesp_DWi0Q","description":"CIS Benchmarks Linux control mapping — LinuxGuard agent and console capabilities aligned to per-distro hardening configurations with explicit separation from CIS Controls and Satisfies / Supports / Ou","breadcrumbs":[{"label":"Audit & Comply"},{"label":"Audit & Comply"}]},{"id":"MsYtwG8cad36b8Xoy4GO","title":"Reference","pathname":"/reference/reference","siteSpaceId":"sitesp_DWi0Q","description":"Cross-cutting reference lookups for LinuxGuard — agent commands, supported distributions, and the v4.0 glossary.","breadcrumbs":[{"label":"Reference"}]},{"id":"6i81gE3vIumKNaqcJaU2","title":"Agent Commands","pathname":"/reference/reference/agent-commands","siteSpaceId":"sitesp_DWi0Q","description":"Reference for the linuxguard-agent command-line interface — start, stop, status, show-config, enroll, and unenroll commands.","breadcrumbs":[{"label":"Reference"},{"label":"Reference"}]},{"id":"ByU10BSfadanarLu9SQb","title":"CLI Reference","pathname":"/reference/reference/cli","siteSpaceId":"sitesp_DWi0Q","description":"Per-command reference for the linuxguard-agent CLI — start, config, probe, and additional commands shipping in subsequent phases.","breadcrumbs":[{"label":"Reference"},{"label":"Reference"}]},{"id":"RRt3lYPhpWsEi2Q1zjGt","title":"start","pathname":"/reference/reference/cli/start","siteSpaceId":"sitesp_DWi0Q","description":"Reference for linuxguard-agent start — typical service mode and ephemeral mode flags, environment variables, signals, and exit codes.","breadcrumbs":[{"label":"Reference"},{"label":"Reference"},{"label":"CLI Reference"}]},{"id":"Ewp4fHpwWspHKb181vSC","title":"config","pathname":"/reference/reference/cli/config","siteSpaceId":"sitesp_DWi0Q","description":"Reference for linuxguard-agent config — set, get, unset, and list-keys subcommands for runtime configuration without restarting the agent.","breadcrumbs":[{"label":"Reference"},{"label":"Reference"},{"label":"CLI Reference"}]},{"id":"XgUS35q0qIYrNeZBvUwF","title":"probe","pathname":"/reference/reference/cli/probe","siteSpaceId":"sitesp_DWi0Q","description":"Reference for linuxguard-agent probe — host capability check covering kernel, BPF, fanotify, netlink, audit, and Linux capabilities.","breadcrumbs":[{"label":"Reference"},{"label":"Reference"},{"label":"CLI Reference"}]},{"id":"1odgkNV4X5UT7uS4LZxV","title":"support-bundle","pathname":"/reference/reference/cli/support-bundle","siteSpaceId":"sitesp_DWi0Q","description":"Reference for linuxguard-agent support-bundle — collect a redacted diagnostic archive locally or upload an existing bundle via a presigned S3 URL.","breadcrumbs":[{"label":"Reference"},{"label":"Reference"},{"label":"CLI Reference"}]},{"id":"PcM2BPuGOr0Nf5aePyiu","title":"enroll","pathname":"/reference/reference/cli/enroll","siteSpaceId":"sitesp_DWi0Q","description":"Reference for linuxguard-agent enroll — bind a host to a tenant using a long-lived API key, with environment / tag assignment and mTLS certificate provisioning.","breadcrumbs":[{"label":"Reference"},{"label":"Reference"},{"label":"CLI Reference"}]},{"id":"uSWcSxxvwBFvVRT3AnRA","title":"unenroll","pathname":"/reference/reference/cli/unenroll","siteSpaceId":"sitesp_DWi0Q","description":"Reference for linuxguard-agent unenroll — remove the host from its tenant binding so the agent can be enrolled into a different tenant.","breadcrumbs":[{"label":"Reference"},{"label":"Reference"},{"label":"CLI Reference"}]},{"id":"cYwcLgMVA9RgSCMN3TM0","title":"show-config","pathname":"/reference/reference/cli/show-config","siteSpaceId":"sitesp_DWi0Q","description":"Reference for linuxguard-agent show-config — print the entire current configuration as indented JSON for inspection or debugging.","breadcrumbs":[{"label":"Reference"},{"label":"Reference"},{"label":"CLI Reference"}]},{"id":"ioRda8orNW426H3Fcuce","title":"status","pathname":"/reference/reference/cli/status","siteSpaceId":"sitesp_DWi0Q","description":"Reference for linuxguard-agent status — check whether the agent process is running, by inspecting the PID file and verifying the process is alive.","breadcrumbs":[{"label":"Reference"},{"label":"Reference"},{"label":"CLI Reference"}]},{"id":"fw3fMEK1tTlBNbxcfpXo","title":"version","pathname":"/reference/reference/cli/version","siteSpaceId":"sitesp_DWi0Q","description":"Reference for linuxguard-agent --version and the build-time metadata (version string, git commit, build timestamp) the agent reports.","breadcrumbs":[{"label":"Reference"},{"label":"Reference"},{"label":"CLI Reference"}]},{"id":"K57WE0jo65JUuRZHsqoA","title":"signals","pathname":"/reference/reference/cli/signals","siteSpaceId":"sitesp_DWi0Q","description":"Signal-handling reference for the linuxguard-agent start process — SIGHUP (log-level reload + log rotation), SIGTERM (143), SIGINT (130), and the re-raise convention.","breadcrumbs":[{"label":"Reference"},{"label":"Reference"},{"label":"CLI Reference"}]},{"id":"p687nxvOuqPHHf2DiKPy","title":"env-variables","pathname":"/reference/reference/cli/env-variables","siteSpaceId":"sitesp_DWi0Q","description":"Environment-variable reference for linuxguard-agent — LINUXGUARD_ENROLL_TOKEN, LINUXGUARD_NODE_NAME, LINUXGUARD_POD_UID, and related variables used by the start command.","breadcrumbs":[{"label":"Reference"},{"label":"Reference"},{"label":"CLI Reference"}]},{"id":"R6hEyBKPhxDGbukN4Wxz","title":"exit-codes","pathname":"/reference/reference/cli/exit-codes","siteSpaceId":"sitesp_DWi0Q","description":"Exit-code reference for linuxguard-agent — universal codes (0/1/2), signal-induced 128+N codes (130 SIGINT, 143 SIGTERM), and per-command divergences.","breadcrumbs":[{"label":"Reference"},{"label":"Reference"},{"label":"CLI Reference"}]},{"id":"3bAhepxoRmegZamInU35","title":"Supported Distributions","pathname":"/reference/reference/supported-distributions","siteSpaceId":"sitesp_DWi0Q","description":"Per-architecture capability matrix and per-distribution support matrix for the LinuxGuard agent — Debian, RedHat, SUSE, Alpine across amd64, arm64, armv7, and riscv64.","breadcrumbs":[{"label":"Reference"},{"label":"Reference"}]},{"id":"m4WIQ8R9zGhvpRCrF5sU","title":"Glossary","pathname":"/reference/reference/glossary","siteSpaceId":"sitesp_DWi0Q","description":"Glossary of LinuxGuard terminology — agent, console, eBPF, enrollment, modules, compliance frameworks, and related security concepts.","breadcrumbs":[{"label":"Reference"},{"label":"Reference"}]},{"id":"pGx7K9dJzQUaWAUzNaiZ","title":"Concepts","pathname":"/concepts/concepts","siteSpaceId":"sitesp_DWi0Q","description":"Conceptual scaffolding for LinuxGuard — security architecture, active response, alerting, and the console pillars.","breadcrumbs":[{"label":"Concepts"}]},{"id":"isRjRCYTtaj2esiTPdwY","title":"Security Architecture","pathname":"/concepts/concepts/security-architecture","siteSpaceId":"sitesp_DWi0Q","description":"LinuxGuard's zero-trust, least-privilege security architecture — privilege model, eBPF monitoring, and runtime protections.","breadcrumbs":[{"label":"Concepts"},{"label":"Concepts"}]},{"id":"i33ZNAUnNOf8MYFNqfFc","title":"Active Response","pathname":"/concepts/concepts/active-response","siteSpaceId":"sitesp_DWi0Q","description":"How LinuxGuard's active-response model executes automated containment actions with triple opt-in safety and audited rollback.","breadcrumbs":[{"label":"Concepts"},{"label":"Concepts"}]},{"id":"hAm0yOsZZVHEMCK56DcA","title":"Alerting & SIEM Integration","pathname":"/concepts/concepts/alerting","siteSpaceId":"sitesp_DWi0Q","description":"How LinuxGuard routes security signals to webhook, syslog, and Splunk HEC delivery channels via notification rules.","breadcrumbs":[{"label":"Concepts"},{"label":"Concepts"}]},{"id":"iR2BOOD0eNEoXJceScFE","title":"Console","pathname":"/concepts/concepts/console","siteSpaceId":"sitesp_DWi0Q","description":"Overview of the LinuxGuard console — the v3.0 five pillars plus v4.0 expanded pillars (Baselines, Efficiency, Audit, Integrations, Posture, Notifications).","breadcrumbs":[{"label":"Concepts"},{"label":"Concepts"}]},{"id":"hTTCdV3ckAsTzdBC9ep5","title":"Dashboard","pathname":"/concepts/concepts/console/dashboard","siteSpaceId":"sitesp_DWi0Q","description":"The LinuxGuard console Dashboard — identity risk score, fleet posture, top identity risks, and findings feed.","breadcrumbs":[{"label":"Concepts"},{"label":"Concepts"},{"label":"Console"}]},{"id":"HhEgbY4XtfiOJieCeKAm","title":"Identity Intelligence","pathname":"/concepts/concepts/console/identity-intelligence","siteSpaceId":"sitesp_DWi0Q","description":"Identity Intelligence pillar in the LinuxGuard console — cross-server identity profiles, risk scoring, SSH keys, and access patterns.","breadcrumbs":[{"label":"Concepts"},{"label":"Concepts"},{"label":"Console"}]},{"id":"W9QHUtTwSpvbDlhadxqZ","title":"Zero Trust Enforcement","pathname":"/concepts/concepts/console/zero-trust-enforcement","siteSpaceId":"sitesp_DWi0Q","description":"Zero Trust Enforcement pillar in the LinuxGuard console — signals with MITRE mapping, config drift, SUDO policy, and findings.","breadcrumbs":[{"label":"Concepts"},{"label":"Concepts"},{"label":"Console"}]},{"id":"XQNEWEqZMYGRH5pc9NnW","title":"Compliance & Audit","pathname":"/concepts/concepts/console/compliance-audit","siteSpaceId":"sitesp_DWi0Q","description":"Compliance & Audit pillar in the LinuxGuard console — framework scores, history, suppressions, and audit log export.","breadcrumbs":[{"label":"Concepts"},{"label":"Concepts"},{"label":"Console"}]},{"id":"5CzvAba0UsRxM3JHVgcy","title":"Infrastructure","pathname":"/concepts/concepts/console/infrastructure","siteSpaceId":"sitesp_DWi0Q","description":"Infrastructure pillar in the LinuxGuard console — fleet inventory, efficiency and rightsizing analysis, and baseline configuration.","breadcrumbs":[{"label":"Concepts"},{"label":"Concepts"},{"label":"Console"}]},{"id":"CzTjexQge3mOu67ZgNuC","title":"What Changed","pathname":"/concepts/concepts/console/whats-changed","siteSpaceId":"sitesp_DWi0Q","description":"What Changed in the LinuxGuard console — mapping from the old flat section list to the 5-pillar model.","breadcrumbs":[{"label":"Concepts"},{"label":"Concepts"},{"label":"Console"}]},{"id":"pCHzk9G2c3H3SSMJN077","title":"Baselines","pathname":"/concepts/concepts/console/baselines","siteSpaceId":"sitesp_DWi0Q","description":"Baselines pillar in the LinuxGuard console — known-good snapshots of accounts, groups, SSH, and SUDO configuration with drift detection.","breadcrumbs":[{"label":"Concepts"},{"label":"Concepts"},{"label":"Console"}]},{"id":"EMVu4VYL5cNCwhxsBNC8","title":"Efficiency","pathname":"/concepts/concepts/console/efficiency","siteSpaceId":"sitesp_DWi0Q","description":"Efficiency pillar in the LinuxGuard console — rightsizing, storage, network IO, JVM, waste assessment, labor savings, and reports.","breadcrumbs":[{"label":"Concepts"},{"label":"Concepts"},{"label":"Console"}]},{"id":"lveQP3HzBN2Kbl4OdiJP","title":"Audit","pathname":"/concepts/concepts/console/audit","siteSpaceId":"sitesp_DWi0Q","description":"Audit pillar in the LinuxGuard console — authorizations audit and SUDO execution audit for privileged-action reconciliation.","breadcrumbs":[{"label":"Concepts"},{"label":"Concepts"},{"label":"Console"}]},{"id":"96PzKSVc2lb1s3CShpAS","title":"Compliance Expansion","pathname":"/concepts/concepts/console/compliance-expansion","siteSpaceId":"sitesp_DWi0Q","description":"Compliance Expansion pillar — frameworks browser, evidence collection, compliance history, reports, suppressions, and evidence location reference.","breadcrumbs":[{"label":"Concepts"},{"label":"Concepts"},{"label":"Console"}]},{"id":"IWJwLeV5QNEnF2xGut6G","title":"Integrations","pathname":"/concepts/concepts/console/integrations","siteSpaceId":"sitesp_DWi0Q","description":"Integrations pillar — JIRA, Microsoft Teams, Slack, Syslog, SIEM, generic webhooks, and delivery tracking from the LinuxGuard console.","breadcrumbs":[{"label":"Concepts"},{"label":"Concepts"},{"label":"Console"}]},{"id":"vzGFNaZnOFKppcSOFxwb","title":"Zero Trust Expansion","pathname":"/concepts/concepts/console/zero-trust-expansion","siteSpaceId":"sitesp_DWi0Q","description":"Zero Trust Expansion pillar — policies, findings, playbooks, active responses history, SUDO policies and executions, SELinux, and policy violations.","breadcrumbs":[{"label":"Concepts"},{"label":"Concepts"},{"label":"Console"}]},{"id":"KqGdMauflliHXd6yQXyr","title":"Posture","pathname":"/concepts/concepts/console/posture","siteSpaceId":"sitesp_DWi0Q","description":"Posture pillar — Compliance Posture, Configuration Posture, Health Posture and the rationale for consolidation under one navigation label.","breadcrumbs":[{"label":"Concepts"},{"label":"Concepts"},{"label":"Console"}]},{"id":"CuHlNjkAKf8m9oLjiXnS","title":"Notifications","pathname":"/concepts/concepts/console/notifications","siteSpaceId":"sitesp_DWi0Q","description":"Notifications pillar — notification rules, suppressions, and rule edit/new flows in the LinuxGuard console.","breadcrumbs":[{"label":"Concepts"},{"label":"Concepts"},{"label":"Console"}]},{"id":"8IFYlK2qUDEw5X4ZiYtp","title":"Troubleshooting","pathname":"/troubleshooting","siteSpaceId":"sitesp_DWi0Q","description":"Diagnose and resolve common LinuxGuard agent issues — log inspection, enrollment errors, runtime problems, and integration failures."},{"id":"C3wQ57QPVGMVgyO9PW9J","title":"Support","pathname":"/support","siteSpaceId":"sitesp_DWi0Q","description":"Contact information and help resources for LinuxGuard — 24/7 support channels, what to include in requests, and self-service routes."},{"id":"i2rK2RvhpfP0LUBIEDGd","title":"Changelog","pathname":"/changelog","siteSpaceId":"sitesp_DWi0Q","description":"Release notes and documentation change history for LinuxGuard, organized in Keep a Changelog format with semantic versioning."}]}