Linux Deployment for OTserver and OTserver Otter

Linux prerequisites

Use a dedicated scanner account, a selected physical interface, and either root or CAP_NET_RAW for Linux AF_PACKET discovery. Keep scan output and executable-adjacent otter.json in a restricted directory because the config may contain SNMP, OPC UA, and upload credentials.

Install or build the scanner

Download the archive for your architecture from a tested Otter release: otserver-otter-linux-x86_64.tar.gz for x86-64 Linux or otserver-otter-linux-aarch64.tar.gz for supported 64-bit Raspberry Pi systems. Extract it into a dedicated scanner directory. Release binaries can run ./otserver-otter --version, doctor, and interfaces from that directory.

To build from source, install Rust and Git, then clone the scanner repository. The commands below use the source-build executable path:

1
2
3
4
5
6
git clone https://github.com/ruveydac/otserver-otter.git
cd otserver-otter
cargo build --locked --release
./target/release/otserver-otter --version
sudo ./target/release/otserver-otter doctor
sudo ./target/release/otserver-otter interfaces

Linux scan

Replace the example target, interface, and source MAC with the authorized network and the actual values reported by interfaces. For a downloaded release, replace ./target/release/otserver-otter with ./otserver-otter.

1
2
3
4
5
6
sudo ./target/release/otserver-otter scan \
  --target 192.168.1.0/24 \
  --interface eth0 \
  --source-mac 00:11:22:33:44:55 \
  --output ./scan.otserver.json \
  --ack-authorized

Linux uses a native AF_PACKET raw socket for PROFINET and needs root or CAP_NET_RAW. Disable protocols individually with flags such as --no-profinet or --no-snmp; there is no --read-only switch because read-only behavior is the scanner’s design boundary.

Tagged releases include a headless AArch64 build for Raspberry Pi 3, 4, 5, and Zero 2 W on 64-bit Raspberry Pi OS Bookworm or newer. Install libssl3; for a native CLI-only build, run cargo build --locked --release --no-default-features.

For unattended operation, use the systemd service and timer example. It grants CAP_NET_RAW to a dedicated service account and keeps a stable working directory for otter.json and relative output paths.

Verify the result

Validate the export before importing it:

1
./target/release/otserver-otter validate ./scan.otserver.json

Exit code 0 means every configured scan completed, 2 means at least one valid output is partial, and 1 means a configuration, scan, validation, or upload failed. Array configurations continue sequentially after individual failures.

Configure a weekly plant scan or review the protocol requests.