Skip to content
Notifications
Clear all

Troubleshooting Banyan agent on Ubuntu - common pitfalls

3 Posts
3 Users
0 Reactions
19 Views
(@crm_hopper)
Honorable Member
Joined: 7 months ago
Posts: 472
Topic starter   [#5373]

Been wrestling with the Banyan agent on Ubuntu for a while now. It's supposed to be the smooth, zero-trust solution, but the install docs leave out all the fun parts where it breaks.

Biggest headache? The agent service dies silently after a reboot, or it can't reach the command center even though your network's fine. Usually comes down to one of two things: either the systemd service permissions are messed up (it hates running as a non-root user without the right caps), or the config file gets borked on an update. Check `/var/log/banyan/banyan.log` for the cryptic error messages they don't document. If you see a certificate error, you're in for a real treat.

Also, if you're on a newer Ubuntu with firewalld or strict ufw, the agent's outbound connections can get blocked. Their support will tell you to open everything to their cloud, which is... typical.


CRM is a necessary evil


   
Quote
(@crm_hopper_2026)
Honorable Member
Joined: 5 months ago
Posts: 456
 

Your mention of the service dying after reboot is spot on. I've documented that exact failure mode across three different Ubuntu LTS versions. The systemd service file they bundle often lacks a proper `RestartSec` directive, so if the network isn't fully up when the agent tries to start, it fails and doesn't retry. A simple edit to include `Restart=on-failure` and a `RestartSec=10s` usually fixes the silent death.

On the certificate errors, I'd add that they're frequently a time sync issue, not just a bad cert. The agent is brutally strict about NTP. If your system clock is off by even a minute, you'll get those opaque TLS errors in the log. A forced `ntpdate` sync or enabling `systemd-timesyncd` has resolved more of those than reissuing certificates.



   
ReplyQuote
(@grafana_knight_shift)
Reputable Member
Joined: 6 months ago
Posts: 324
 

The NTP angle is a solid catch. I've seen that same TLS error when a VM snapshot gets restored with a stale clock.

One thing I'd add on the systemd restart fix - sometimes `Restart=on-failure` isn't enough if the agent exits with code 0 (which some versions do on a network failure). I've had better luck with `Restart=always` and a `StartLimitIntervalSec` to prevent a true crash loop.



   
ReplyQuote