Skip to content
StatusTick

Monitors

Private agents

Run a StatusTick agent inside your network to monitor internal services: install, network requirements, what leaves your network, and the security model.

A private agent is a small StatusTick process that runs inside your network. It checks services that are not on the internet, such as internal APIs, admin tools, databases and intranets, and sends the results to StatusTick.

Private locations and agents

  • A private location is a named place in your organization, for example "Frankfurt office" or "prod-vpc". Monitors choose it like a public region.
  • An agent is one running process in a private location. Run two or more in one location for redundancy; they share the checks and take over from each other.

Install

  1. In StatusTick, open Settings → Private locations and add a location.
  2. Copy the token. It is shown once.
  3. Start the agent on any host with Docker:
docker run -d --name statustick-agent --restart unless-stopped \
  -e STATUSTICK_TOKEN="<your location token>" \
  ghcr.io/statustick/agent:1

The location shows Online within a minute. Add monitors and choose the private location.

With Docker Compose:

services:
  statustick-agent:
    image: ghcr.io/statustick/agent:1
    restart: unless-stopped
    environment:
      STATUSTICK_TOKEN: ${STATUSTICK_TOKEN}

The image runs on amd64 and arm64, so a Raspberry Pi works too.

Network requirements

Direction What Port
Outbound HTTPS to StatusTick 443
Inbound Nothing —

No VPN, no inbound port and no IP allowlisting are needed. If your network uses an HTTP proxy, set HTTPS_PROXY. If it inspects TLS with its own CA, mount the CA file and set NODE_EXTRA_CA_CERTS.

What leaves your network

Only check results:

  • status (up, degraded, down),
  • timings (DNS, connect, TLS, total),
  • the HTTP status code,
  • a short error text.

Response bodies, headers and cookies never leave your network. Keyword checks send only whether the keyword matched.

Security model

  • Outbound only. StatusTick never connects to the agent.
  • Tokens. Each location has its own token. StatusTick stores only a hash. Rotate or revoke it in the dashboard; a revoked agent stops within a minute.
  • Isolation. An agent only receives checks for its own organization and location.
  • Your limits. Set STATUSTICK_ALLOW (for example 10.0.0.0/8,*.corp.example) and the agent refuses any target outside the list. The list lives on your side.
  • Agent down is not service down. If all agents in a location stop, the location shows Offline, admins get one notice, and its monitors do not open outage incidents.

Troubleshooting

Run the built-in check:

docker run --rm -e STATUSTICK_TOKEN="<token>" ghcr.io/statustick/agent:1 doctor

It tests DNS, the connection to StatusTick, TLS, proxy settings and the token, and tells you what to fix.

Last updated 28 Sept 2026

All docs