SENTINELDOCS Dashboard →

SENTINEL TECHNICAL CENTRE

Documentation.

Install, configure and operate Sentinel with verifiable procedures for Linux servers, web applications and WordPress.

Current documentationUpdated September 10, 2026Agent · WAF · WordPress

Press / to search

One control plane, protection close to the workload

Sentinel coordinates detection, policy and reporting from a central panel while enforcement remains on the server or inside WordPress. This keeps operational control visible and avoids treating the dashboard as the only security boundary.

01

Agent

Collects supported security signals, reports health and applies local server controls.

02

Control plane

Associates systems, policies, versions and events without replacing host-level safeguards.

03

Protection layers

WAF, firewall, threat intelligence, monitoring and WordPress modules work at different points.

From an empty record to a connected server

  1. 1

    Create the server

    Open Servers → Add server in the panel and use a stable, recognisable name.

  2. 2

    Copy the generated command

    Use the command produced for that specific record. Its API key must not be reused on other machines.

  3. 3

    Run it with administrative privileges

    Execute it on the target server, then confirm that the service starts and completes its connection check.

  4. 4

    Validate the inventory

    Hostname, addresses, installed version and last heartbeat in the panel must match the server you changed.

Requirements and pre-flight checks

Operating system

Use a supported Linux distribution and a maintained package manager. Check the current compatibility page before deployment.

Access

Root or sudo access, a second recovery channel and known administrative IPs or networks.

Connectivity

Working DNS, synchronised time, HTTPS access to the repository and outbound TLS to the endpoint shown by the panel.

Recovery

A tested backup and a recorded rollback plan before modifying proxy or firewall rules.

Install the Sentinel agent

Prefer the command displayed by the panel: it already contains the dedicated credential and current endpoint. The example below contains placeholders only.

Shell · example
curl -fsSL https://sentinel.gtechgroup.it/apt/install-agent.sh | \
  sudo bash -s -- \
  --api-key "<PANEL_GENERATED_API_KEY>" \
  --server sentinel.gtechgroup.it:9090 \
  --yes

Configuration, secrets and allowlists

The main file is /etc/sentinel/agent.yaml. Back it up before editing, preserve YAML indentation and never paste its API key into a ticket or public log.

YAML · minimal example
agent:
  server_url: "sentinel.gtechgroup.it:9090"
  api_key: "<PANEL_GENERATED_API_KEY>"

tls:
  enabled: true
  skip_verify: false

blocker:
  backend: "auto"
  chain: "SENTINEL"
  whitelist_entries:
    - "<ADMIN_IP_OR_NETWORK>"

After any change, run sudo sentinel-agent --check before restarting the service.

Firewall and Fail2Ban interoperability

Sentinel keeps its own chain and block set so its decisions remain identifiable. The integration can read supported Fail2Ban bans and share Sentinel indicators towards Fail2Ban without allowing Fail2Ban to overwrite Sentinel’s source of truth.

Fail2BanLocal bans read by Sentinel
→
SentinelNormalises and reports indicators
→
FleetEligible blocks reach connected agents

Update without losing local configuration

The panel can request an update from connected agents that support remote jobs. If the job cannot run, use the manual procedure directly on the server.

Shell · manual update
sudo apt-get update
sudo apt-get install --only-upgrade sentinel-agent \
  -o Dpkg::Options::=--force-confold
sudo systemctl restart sentinel-agent
sudo sentinel-agent --check

Confirm the installed version, the active service, the new heartbeat and the latest log entries after every update.

Move from Observe to Block deliberately

OBSERVE

Measure first

Records which rules would trigger without interrupting requests. Use representative traffic to identify narrow exceptions.

BLOCK

Enforce after validation

Rejects requests that match active policy. Enable per domain and monitor 403 responses and critical user journeys.

The WAF protects only traffic routed through its listener. Enabling a module does not automatically change the Nginx, Apache or hosting-panel upstream.

Connect and protect a WordPress site

  1. 1

    Register the exact public URL

    Protocol, subdomain and any subdirectory form part of the site identity.

  2. 2

    Generate the one-time token

    Use it only for its matching site and do not include it in screenshots.

  3. 3

    Install the panel package

    Upload the ZIP in WordPress, activate Sentinel Security and complete the connection.

  4. 4

    Review defaults

    Start in Observe, inspect dashboards and events, then enable stricter controls module by module.

WAF, Login Shield, antispam, malware scanning, integrity checks and reversible quarantine cover different risks. The plugin complements updates, backups and server hardening; it does not replace them.

Explore every WordPress module →

A repeatable diagnostic sequence

Validate configuration and connectionStart here; do not launch a second agent process.
sudo sentinel-agent --check
Read the installed versionCompare it with the server detail in the panel.
sentinel-agent --version
Check the systemd unitLook for active status and repeated restarts.
sudo systemctl status sentinel-agent --no-pager
Read recent messagesPrioritise errors after the most recent start.
sudo journalctl -u sentinel-agent -n 100 --no-pager

Server appears offline

Check the service, DNS, clock, host:port endpoint, TLS validation and the dedicated API key.

No WAF events

Confirm that the domain’s live traffic actually crosses the configured WAF listener.

SSH watcher does not start

Verify the configured authentication source on the distribution; do not create a fake empty log as a workaround.

Update job fails

Read the job log, verify APT metadata and use the panel’s manual command directly on that server.

Share evidence, never credentials

A useful support request includes hostname, distribution, agent or plugin version, timestamp with time zone, the action performed and relevant log lines. Remove API keys, enrolment tokens, cookies, personal data and unrelated addresses before sending it.