Install the host agent (acp-host-agent) on every WarehousePG (WHPG) cluster node to enable privileged operations on behalf of WEM. These operations include editing pg_hba.conf through the HBA Editor tab, running cluster management actions, taking and restoring backups, and collecting host metrics and logs through the node's OTel Collector, all without direct shell access to cluster hosts.
Note
WEM's internal job-execution engine runs on the same host as WEM. Before installing the host agent, complete Installing and configuring WEM.
Downloading and installing the host agent
Run these steps from the coordinator as gpadmin.
On the coordinator, download the host agent package and its
edb-otelcoldependency from the EDB repository:export EDB_SUBSCRIPTION_TOKEN=<your-token> export EDB_REPO=gpsupp curl -1sSLf "https://downloads.enterprisedb.com/$EDB_SUBSCRIPTION_TOKEN/$EDB_REPO/setup.rpm.sh" | sudo -E bash sudo dnf download edb-acp-host-agent edb-otelcol
The host agent depends on
edb-otelcol, so download both packages. Installing both.rpmfiles together on each host letsdnfresolve that dependency locally, without needing the EDB repository configured on every node.On the coordinator, create a file
all_hosts, which lists all hosts in the WHPG cluster. For example:cdw scdw sdw1 sdw2 sdw3
From the coordinator, transfer both downloaded packages to every host in the cluster. Use the
gpsyncutility on WarehousePG 7, or thegpscputility on WarehousePG 6:gpsync -f all_hosts edb-acp-host-agent-*.rpm edb-otelcol-*.rpm =:/tmp
gpscp -f all_hosts edb-acp-host-agent-*.rpm edb-otelcol-*.rpm =:/tmp
From the coordinator, use
gpsshto install both packages together on every host:gpssh -f all_hosts -u gpadmin -e "sudo dnf install -y /tmp/edb-acp-host-agent-*.rpm /tmp/edb-otelcol-*.rpm"
On every node, set
WEM_CONNECT_ADDRESSin/etc/edb/acp-host-agent/acp-host-agent.confto WEM's IPv4 address and listen port plus 1 (default 8081):WEM_HOST=<wem-host-ipv4> gpssh -f all_hosts -u gpadmin -e \ "sudo sed -i 's/^WEM_CONNECT_ADDRESS=.*/WEM_CONNECT_ADDRESS=${WEM_HOST}:8081/' \ /etc/edb/acp-host-agent/acp-host-agent.conf"
For the full variable reference, including agent identity and logging, see Host agent configuration.
Enable and start the host agent service on every node:
gpssh -f all_hosts -u gpadmin -e "sudo systemctl enable --now acp-host-agent"
Verify each agent self-registered and is waiting for approval:
gpssh -f all_hosts -u gpadmin -e "sudo cat /var/log/edb/acp-host-agent/acp-host-agent.log"
Expected output includes:
INFO self-registration succeeded task_queues=coordinator-tasks INFO starting host-agent agent_id=... connect_address=... task_queues=coordinator-tasks INFO awaiting TLS material — an admin must approve this agent in wem agent_id=...
An agent stays in this pending state, repeating the last line, until an Admin approves it. It doesn't reach a running state on its own.
Open WEM in a browser, log in with admin credentials, navigate to Management > Host Agents, select the pending agents, and choose Approve from the quick actions. You can confirm you're approving the agent you expect by comparing its Verification Token against the join token on the host (cat /etc/edb/acp-host-agent/join-token).
Note
Permission to approve host agent access is disabled by default, even for the Admin profile. To grant this permission, see Defining role-based access control.
Once approved, each agent picks up its TLS material and starts its worker within moments. Verify this on any node:
gpssh -f all_hosts -u gpadmin -e "sudo tail -5 /var/log/edb/acp-host-agent/acp-host-agent.log"
Expected output includes:
INFO handlers registered task_kinds=[file.pull, file.push, otel.service.start, ...] INFO connecting to Temporal connect_address=... task_queues=coordinator-tasks INFO worker running task_queue=coordinator-tasks
WEM pushes the OTel configuration to the host agent and WEM's internal certificate authority issues the agent a short-lived certificate. Every subsequent connection between that agent and WEM authenticates with mutual TLS (mTLS). WEM renews the certificate automatically, with a 24-hour grace window that lets an agent that was briefly offline recover its certificate without Admin intervention.
Next steps
Your installation is complete. See Getting started with WEM.