UpdatesExplore the release notes

Learn · Lesson 4 of 7 · 4 min

Enroll machines without a browser

A server or CI runner can join without anyone opening a browser. A node auth key carries its enrollment settings and tags.

01 / CREATE A KEY

Decide how the machine should join.

Open Keys → Node Auth Keys. Here’s an example for short-lived CI runners.

ci-runner-keyExample
Ready for your pipelineci
Expires in
30 days
Reusable
On · used by multiple runners
Ephemeral
On · removed on disconnect
Auto approve
On · no approval queue

The key is shown once. Save it in your secret manager.

02 / ADD TO YOUR WORKFLOW

Two commands. No browser.

Inject the saved key as BG_AUTH_KEY in your job environment, then run:

baseguard login --auth-key "$BG_AUTH_KEY"
baseguard connect
03 / USE YOUR EXISTING RULES

The runner arrives with its tag.

Runner joinsExample
ci-runner-01ci
ci
Your allow rule
registry

The key assigns the tag. Your network rules determine what the runner can reach.

For persistent servers, leave Ephemeral off. For a fleet sharing one key, enable Reusable.

A few useful details

Defaults. Reusable and Ephemeral are off by default. Node Auto Approve is on. An expiry of 0 means the key never expires.

Single-use keys. A consumed key cannot enroll a second machine. Use a reusable key when multiple machines share the enrollment workflow.

Expiration. Expired keys cannot enroll machines. Rotate the secret before the key expires.

Ephemeral nodes. When the node disconnects, its entry and name are removed. Use this for temporary jobs.

Your automation can join on its own.

Next, give your private services names people can remember.