Workload security
Connect a self-managed Linux host
Register a VPS, dedicated server, or on-premises Linux host in Secorvia and verify agent-based container discovery.
Reviewed
Before you start
Use a Linux x86-64 or arm64 host with outbound HTTPS to your Secorvia instance. Container collection needs Docker socket access and Trivy for local image scanning; Docker socket access is root-equivalent.
Add the host and choose capabilities
Open Self-Managed Hosts → Add Self-Managed Host. Enter Host Name, choose at least one Capability, and optionally set Environment. No cloud account is required. Only registered capabilities are authorized by the credential.
Copy the one-time credential
Store Agent Credential immediately. The host discovers its hostname, OS, architecture, and runtime when it connects. Use a recognizable name such as an environment and location so the team can identify the machine later.
Follow the generated installation instructions
Run the app’s installation command on the target Linux host as instructed. It installs the architecture-appropriate binary, verifies its checksum, creates a service account, stores the credential in a root-only file, and installs the systemd service. Use the exact deployment URL and credential shown to you.
Enable local image collection
For Container Security, complete the displayed Trivy installation and Docker-access steps. Review the Docker socket access implications before granting access. The host scans locally and uploads SBOMs rather than sending image contents to Secorvia.
Verify heartbeat and discovery
Use Check status and logs. Open Host Detail and review Last Seen, Last Inventory, Containers, and Images. Expected log messages include an accepted heartbeat and inventory counts. Move into Container Security to review image findings.
Where you are now
A registered host reports its enabled capabilities and discovered container inventory without requiring a cloud account.
WHEN SOMETHING LOOKS OFF
A few things to check
No containers discovered
Check Docker is running, the agent can read its socket, and Container Security is enabled for this host.
The host stopped after credential rotation
Update the agent environment file and restart the service. Rotation invalidates the prior credential immediately.
PUT IT INTO PRACTICE
Make your next move in Secorvia.
Open the app and follow along with your own organization.