Skip to main content

Overview

kanari agent runs a continuous monitoring loop. On each cycle it collects metrics and either logs them locally (local mode) or sends them to the Kanari backend for persistent monitoring and alerts (API mode).
Stop with Ctrl+C or SIGTERM. The agent handles both gracefully.

Flags


API key resolution

The agent finds your API key automatically in this order:
  1. --token flag
  2. KANARI_API_KEY environment variable
  3. ~/.kanari/config — saved by kanari login ← recommended
  4. api_key in your kanari.yaml
After running kanari login, you never need to set an API key manually.

Local mode

The best way to verify what the agent collects before connecting it to the backend.
Each cycle emits structured JSON to stdout:
Pipe to jq for filtering:

API mode

API mode sends metrics to the Kanari backend on every cycle. The backend evaluates findings and sends Slack/email alerts when thresholds are breached.
On startup the agent validates the API key. If invalid, it exits immediately with a clear error.

Running as a background service

systemd

Docker

Docker Compose