UpdatesExplore the release notes

API & Automation

Set it up once.
Let the next machine join.

Give your servers and build runners a way in. Your scripts handle enrollment, so you can carry on building.

Bring a CI runner or a new server onto your private network from a script. Use node auth keys to enroll and the REST API to manage what comes next.

Get Started Free

API & Automation

Reach a private registry from CI

Enroll a runner with the ci tag and allow access to your image registry.

Keep the registry private and let the runner join for the job. Its enrollment key supplies the tags; your network rules supply the access.

  • Keep the auth key in your CI secret store.
  • Ephemeral nodes are removed when they disconnect.
CI runner · build job
~ baseguard login --auth-key "$BG_AUTH_KEY"
baseguard connect
# Access the registry through your ci rule
docker pull registry.corp.internal/app:latest
# Ephemeral node is removed on disconnect

API & Automation

Connect servers on first boot

Use a reusable key in your provisioning workflow to enroll new machines.

Add enrollment to your provisioning script. Every new machine arrives with its tags, ready to follow the rules you have already defined.

  • Use a reusable key for a group of servers.
  • Set an expiration and rotate the enrollment secret.
Fleet enrollment
1Create a reusable key
fleet-enrollReusable · auto-approved · expires in 30 days
prod
2Add it to your first-boot script
baseguard login --auth-key "$BG_AUTH_KEY"baseguard connect
3New servers join with the right tags
app-server-01prodConnected
app-server-02prodConnected
app-server-03prodConnected

Each server inherits prod. Your existing tag-based rules apply as it joins.

API & Automation

Build your own operations tools

Manage nodes, tags, rules, keys, DNS and users through the REST API.

Connect network management to your own admin panel or operational scripts. Use the REST API to manage the resources your workflow needs.

  • Manage nodes, tags, rules, keys, DNS and users.
  • Use API keys for management and node auth keys for enrollment.
API · Create a network rule

Your automation creates the rule

POST/v1/acl/network
nightly-backupCreated
Backup runnersbackup
Database serversdatabase
Allow PostgreSQLTCP · 5432

The rule appears in your console and applies to matching nodes. The API and console manage the same network.

FREQUENTLY ASKED QUESTIONS

A few things you might be wondering.

Are node auth keys and API keys the same?

No. A node auth key enrolls a machine. An API key authenticates requests that manage the organization through the REST API.

What happens when a key expires?

An expired enrollment key cannot enroll another machine. Rotate automation secrets before their expiration. A single-use key also cannot be used again after it has been consumed.

Does an ephemeral runner get access to everything?

Its access is determined by your network rules, just like any other node. Configure narrowly scoped rules and remove the initial Default ACL allow-all rule to restrict it.

TRY IT ON YOUR OWN NETWORK

Connect your first two machines.

Install Baseguard, join the same organization, and put it to work.