Zero-knowledge encryption for the monitor-agent

How the install script seals exporter addresses and passwords to a key that never leaves your host, what happens if you lose device.key, and how a second agent reuses the same file.

Published 2026-08-186 min readSecuritymonitor-agentZero knowledge
On this page
  1. How it works
  2. Lost device.key
  3. Secondary agents

How it works

The install script generates an RSA-2048 key on the agent host, uploads only the public key, and keeps device.key mode 600 next to docker-compose. site-main wraps exporter URLs and passwords with RSA-OAEP + AES-256-GCM. GET /api/agent/config returns ciphertext; only the agent unseals it.

Lost device.key

There is no recovery. On the install or profile card, confirm LOST_KEY to clear the registered public key, then re-enter exporter addresses and credentials. Never paste the private key into the dashboard or support chat.

Secondary agents

Copy device.key from the primary host and re-run the installer with AGENT_DEVICE_KEY_FILE pointing at that file. A second generated key is rejected (HTTP 409).

Zero-knowledge encryption for the monitor-agent — ELK Utilities