Huntress — Managed EDR
Purpose
Managed EDR (Endpoint Detection and Response) platform that protects systems by detecting malicious footholds used by attackers.
Entry Point
- Main file: huntress.nix
- Upstream: Huntress Managed EDR
Options
services.huntress.accountKeyFile
| Type | string |
The account key for the Huntress agent.
services.huntress.enable
| Type | boolean |
| Default | false |
| Example | true |
Whether to enable Huntress service.
services.huntress.organisationKeyFile
| Type | string |
The organisation key for the Huntress agent.
services.huntress.package
| Type | package |
| Default | <derivation huntress-0.14.74> |
The Huntress package to use.
Architecture / Services / Scope
The module runs a single huntress-agent systemd service as root. The agent configuration is generated at /etc/huntress/agent_config.yaml during the service’s preStart phase: a default configuration is written on first start, after which the account and organisation keys are merged in using yaml-merge.
Secrets
accountKeyFile— Huntress account key, loaded into the service via systemdLoadCredential.organisationKeyFile— Huntress organisation key, loaded into the service via systemdLoadCredential.
Operational Notes / Assumptions
- Both keys are validated during
preStart; the service fails to start if either is empty. - The merged configuration persists across restarts in
/etc/huntress/agent_config.yaml.
Usage Example
{ config, ... }: {
services.huntress = {
enable = true;
accountKeyFile = config.sops.secrets.huntress_account_key.path;
organisationKeyFile = config.sops.secrets.huntress_org_key.path;
};
}