Install, configure and operate Sentinel with verifiable procedures for Linux servers, web applications and WordPress.
Current documentationUpdated September 10, 2026Agent · WAF · WordPress
/
Press / to search
01 · OVERVIEW
One control plane, protection close to the workload
Sentinel coordinates detection, policy and reporting from a central panel while enforcement remains on the server or inside WordPress. This keeps operational control visible and avoids treating the dashboard as the only security boundary.
01
Agent
Collects supported security signals, reports health and applies local server controls.
02
Control plane
Associates systems, policies, versions and events without replacing host-level safeguards.
03
Protection layers
WAF, firewall, threat intelligence, monitoring and WordPress modules work at different points.
02 · GETTING STARTED
From an empty record to a connected server
1
Create the server
Open Servers → Add server in the panel and use a stable, recognisable name.
2
Copy the generated command
Use the command produced for that specific record. Its API key must not be reused on other machines.
3
Run it with administrative privileges
Execute it on the target server, then confirm that the service starts and completes its connection check.
4
Validate the inventory
Hostname, addresses, installed version and last heartbeat in the panel must match the server you changed.
03 · PREPARATION
Requirements and pre-flight checks
Operating system
Use a supported Linux distribution and a maintained package manager. Check the current compatibility page before deployment.
Access
Root or sudo access, a second recovery channel and known administrative IPs or networks.
Connectivity
Working DNS, synchronised time, HTTPS access to the repository and outbound TLS to the endpoint shown by the panel.
Recovery
A tested backup and a recorded rollback plan before modifying proxy or firewall rules.
04 · LINUX AGENT
Install the Sentinel agent
Prefer the command displayed by the panel: it already contains the dedicated credential and current endpoint. The example below contains placeholders only.
The main file is /etc/sentinel/agent.yaml. Back it up before editing, preserve YAML indentation and never paste its API key into a ticket or public log.
After any change, run sudo sentinel-agent --check before restarting the service.
06 · LOCAL ENFORCEMENT
Firewall and Fail2Ban interoperability
Sentinel keeps its own chain and block set so its decisions remain identifiable. The integration can read supported Fail2Ban bans and share Sentinel indicators towards Fail2Ban without allowing Fail2Ban to overwrite Sentinel’s source of truth.
Fail2BanLocal bans read by Sentinel
→
SentinelNormalises and reports indicators
→
FleetEligible blocks reach connected agents
07 · RELEASES
Update without losing local configuration
The panel can request an update from connected agents that support remote jobs. If the job cannot run, use the manual procedure directly on the server.
Confirm the installed version, the active service, the new heartbeat and the latest log entries after every update.
08 · WEB APPLICATION FIREWALL
Move from Observe to Block deliberately
OBSERVE
Measure first
Records which rules would trigger without interrupting requests. Use representative traffic to identify narrow exceptions.
BLOCK
Enforce after validation
Rejects requests that match active policy. Enable per domain and monitor 403 responses and critical user journeys.
The WAF protects only traffic routed through its listener. Enabling a module does not automatically change the Nginx, Apache or hosting-panel upstream.
09 · WORDPRESS
Connect and protect a WordPress site
1
Register the exact public URL
Protocol, subdomain and any subdirectory form part of the site identity.
2
Generate the one-time token
Use it only for its matching site and do not include it in screenshots.
3
Install the panel package
Upload the ZIP in WordPress, activate Sentinel Security and complete the connection.
4
Review defaults
Start in Observe, inspect dashboards and events, then enable stricter controls module by module.
WAF, Login Shield, antispam, malware scanning, integrity checks and reversible quarantine cover different risks. The plugin complements updates, backups and server hardening; it does not replace them.
Check the service, DNS, clock, host:port endpoint, TLS validation and the dedicated API key.
No WAF events
Confirm that the domain’s live traffic actually crosses the configured WAF listener.
SSH watcher does not start
Verify the configured authentication source on the distribution; do not create a fake empty log as a workaround.
Update job fails
Read the job log, verify APT metadata and use the panel’s manual command directly on that server.
11 · SAFE OPERATIONS
Share evidence, never credentials
A useful support request includes hostname, distribution, agent or plugin version, timestamp with time zone, the action performed and relevant log lines. Remove API keys, enrolment tokens, cookies, personal data and unrelated addresses before sending it.