Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Huntress — Managed EDR

Purpose

Managed EDR (Endpoint Detection and Response) platform that protects systems by detecting malicious footholds used by attackers.

Entry Point

Options

services.huntress.accountKeyFile

Typestring

The account key for the Huntress agent.


services.huntress.enable

Typeboolean
Defaultfalse
Exampletrue

Whether to enable Huntress service.


services.huntress.organisationKeyFile

Typestring

The organisation key for the Huntress agent.


services.huntress.package

Typepackage
Default<derivation huntress-0.14.74>

The Huntress package to use.


Architecture / Services / Scope

The module runs a single huntress-agent systemd service as root. The agent configuration is generated at /etc/huntress/agent_config.yaml during the service’s preStart phase: a default configuration is written on first start, after which the account and organisation keys are merged in using yaml-merge.

Secrets

  • accountKeyFile — Huntress account key, loaded into the service via systemd LoadCredential.
  • organisationKeyFile — Huntress organisation key, loaded into the service via systemd LoadCredential.

Operational Notes / Assumptions

  • Both keys are validated during preStart; the service fails to start if either is empty.
  • The merged configuration persists across restarts in /etc/huntress/agent_config.yaml.

Usage Example

{ config, ... }: {
  services.huntress = {
    enable = true;
    accountKeyFile = config.sops.secrets.huntress_account_key.path;
    organisationKeyFile = config.sops.secrets.huntress_org_key.path;
  };
}

References