Workload security

Connect a self-managed Linux host

Register a VPS, dedicated server, or on-premises Linux host in Secorvia and verify agent-based container discovery.

Reviewed

Before you start

Use a Linux x86-64 or arm64 host with outbound HTTPS to your Secorvia instance. Container collection needs Docker socket access and Trivy for local image scanning; Docker socket access is root-equivalent.

Add the host and choose capabilities

Open Self-Managed Hosts → Add Self-Managed Host. Enter Host Name, choose at least one Capability, and optionally set Environment. No cloud account is required. Only registered capabilities are authorized by the credential.

Copy the one-time credential

Store Agent Credential immediately. The host discovers its hostname, OS, architecture, and runtime when it connects. Use a recognizable name such as an environment and location so the team can identify the machine later.

Follow the generated installation instructions

Run the app’s installation command on the target Linux host as instructed. It installs the architecture-appropriate binary, verifies its checksum, creates a service account, stores the credential in a root-only file, and installs the systemd service. Use the exact deployment URL and credential shown to you.

Enable local image collection

For Container Security, complete the displayed Trivy installation and Docker-access steps. Review the Docker socket access implications before granting access. The host scans locally and uploads SBOMs rather than sending image contents to Secorvia.

Verify heartbeat and discovery

Use Check status and logs. Open Host Detail and review Last Seen, Last Inventory, Containers, and Images. Expected log messages include an accepted heartbeat and inventory counts. Move into Container Security to review image findings.

Where you are now

A registered host reports its enabled capabilities and discovered container inventory without requiring a cloud account.

WHEN SOMETHING LOOKS OFF

A few things to check

No containers discovered

Check Docker is running, the agent can read its socket, and Container Security is enabled for this host.

The host stopped after credential rotation

Update the agent environment file and restart the service. Rotation invalidates the prior credential immediately.

PUT IT INTO PRACTICE

Make your next move in Secorvia.

Open the app and follow along with your own organization.

Open Secorvia