Skip to content
Probe MCP
Get Support

Deploying the probe

The probe is a single container you run on one host inside the customer LAN. It collects telemetry locally and dials home over an outbound tunnel — there are no inbound ports to open.

  • A Linux host on the LAN — ideally on the same broadcast domain (or a SPAN destination) as the gear you want to watch.
  • Docker installed.
  • Outbound internet access so the bundled cloudflared tunnel can connect. Nothing inbound needs to be reachable.

The image is a small Alpine-based container that bundles the probe binary and cloudflared, built for linux/amd64, linux/arm64, and linux/arm.

Enroll a probe in the dashboard to get a ready-to-paste docker run command. Run it on the host:

Terminal window
# Example shape — copy the real one-liner (with your activation code) from the dashboard.
docker run -d --name probe-mcp \
--network host \
-v probe-data:/var/lib/probe-mcp \
-e ACTIVATION_CODE=act_xxxxxxxx \
<image>

Two things to know about that command:

  • --network host — the probe binds its listeners (syslog, SNMP traps, sFlow) directly on the host’s network so LAN devices can reach them. This is why you don’t publish individual ports.
  • ACTIVATION_CODE — a single-use code that expires. The probe uses it exactly once, on first start, to fetch its identity, tunnel token, and shared secret from the engine; after that it never needs the code again.

The probe stores everything under /var/lib/probe-mcp — its SQLite databases, the offline upload buffer, and its persisted credentials. Mount a named volume there (as the one-liner does) so the probe keeps its identity and buffered data across restarts and image upgrades.

Within a minute the probe should show as Online in the dashboard, with its LAN IP and last heartbeat. Once it’s Online:

  1. Point your devices at it using that LAN IP.
  2. Connect Claude and ask it to list your probes.

If a probe is stuck in a pending state, or you need to redeploy on a fresh host, use New activation command on the probes list to mint a new single-use Docker command.

What the probe does and doesn’t reach out to

Section titled “What the probe does and doesn’t reach out to”

The probe makes only outbound connections: the cloudflared tunnel to the engine, plus outbound SNMP polls and (if enabled) SSH to your devices. Its local HTTP API is bound to 127.0.0.1:8080 and is reachable only through the tunnel, never exposed on the LAN. See the Security model for the full network picture.

The probe heartbeats every 60 seconds. If those stop, it’s flagged offline after 180 seconds of silence, by a sweep that runs every 5 minutes — so the dashboard can lag a failure by a few minutes. See Troubleshooting.