Linux Deployment for OTserver and OTserver Otter
Linux prerequisites
Use a dedicated scanner account, a selected physical interface, and either root or CAP_NET_RAW for Linux AF_PACKET discovery. Keep scan output and executable-adjacent otter.json in a restricted directory because the config may contain SNMP, OPC UA, and upload credentials.
Install or build the scanner
Download the archive for your architecture from a tested Otter release: otserver-otter-linux-x86_64.tar.gz for x86-64 Linux or otserver-otter-linux-aarch64.tar.gz for supported 64-bit Raspberry Pi systems. Extract it into a dedicated scanner directory. Release binaries can run ./otserver-otter --version, doctor, and interfaces from that directory.
To build from source, install Rust and Git, then clone the scanner repository. The commands below use the source-build executable path:
| |
Linux scan
Replace the example target, interface, and source MAC with the authorized network and the actual values reported by interfaces. For a downloaded release, replace ./target/release/otserver-otter with ./otserver-otter.
| |
Linux uses a native AF_PACKET raw socket for PROFINET and needs root or CAP_NET_RAW. Disable protocols individually with flags such as --no-profinet or --no-snmp; there is no --read-only switch because read-only behavior is the scanner’s design boundary.
Tagged releases include a headless AArch64 build for Raspberry Pi 3, 4, 5, and Zero 2 W on 64-bit Raspberry Pi OS Bookworm or newer. Install libssl3; for a native CLI-only build, run cargo build --locked --release --no-default-features.
For unattended operation, use the systemd service and timer example. It grants CAP_NET_RAW to a dedicated service account and keeps a stable working directory for otter.json and relative output paths.
Verify the result
Validate the export before importing it:
| |
Exit code 0 means every configured scan completed, 2 means at least one valid output is partial, and 1 means a configuration, scan, validation, or upload failed. Array configurations continue sequentially after individual failures.
Configure a weekly plant scan or review the protocol requests.