LWMadmin Agent for Linux

Use the authenticated LWMadmin cabinet to create a new Agent and copy the generated
Linux installation command. The generated command contains the one-time enrollment
code and server URL and should be pasted unchanged on the target host.

Linux installation is root-capable by default. Ordinary remote operations run as the
dedicated lwmadmin-agent account. Explicit privilege=root requests remain blocked
until Root access is enabled for that node in the cabinet.

For an already-enrolled legacy Linux Agent, use the node card's one-time
"Prepare Agent for Root access" upgrade command. It preserves the existing device
credential and does not require re-enrollment.
