Repository navigation
v1.4.0
Documentation: https://jmrp.io/docs/mikroscope/, in English and
Spanish: installing it,
what it costs the router, and
where it stands: what has
run on hardware and what has not.
Which file do I need?
Two different programs are published here, and they run on two different
machines. Read the table before downloading anything.
| I want to… | Download | Runs on |
|---|---|---|
| Install and use mikroscope (the usual case) | mikroscope_1.4.0_<os>_<arch>.tar.gz — or .zip on Windows |
your own computer, not the router |
| Let the router fetch the agent | nothing: mikroscope install --remote-image jmrplens/mikroscope-agent:1.4.0 |
the router pulls it itself |
| Side-load the agent image | one mikroscope-agent-<arch>.tar from the table below |
uploaded to the router |
| Run the agent outside a container | mikroscope-agent_1.4.0_linux_<arch>.tar.gz |
wherever you unpack it |
The CLI archive is picked by the operating system and CPU of the
machine you type commands on: linux_x86_64 for an ordinary PC or server,
darwin_arm64 for an Apple-silicon Mac, windows_x86_64 for Windows.
Nothing about it depends on the router.
The agent image tar is picked by the router's architecture, and only
matters if you install with --agent-tar:
| Your MikroTik | /system/resource architecture-name |
Agent image tar |
|---|---|---|
| RB5009, CCR2004, hAP ax³, most 64-bit ARM boards | arm64 |
mikroscope-agent-arm64.tar |
| hEX Refresh / hEX S (2025), any EN7562CT board | arm |
mikroscope-agent-armv5.tar |
| Other 32-bit ARM boards (hAP ac², hAP ax², …) | arm |
mikroscope-agent-armv7.tar or the v5 one |
| CHR, x86 RouterOS | x86_64 |
mikroscope-agent-amd64.tar |
MikroTik's container package exists for arm, arm64 and x86 only, and its
documentation states that "for devices with EN7562CT CPU like the hEX
Refresh, only arm32v5 container images are supported" — an ARMv5 image runs
on every 32-bit ARM MikroTik ships, an ARMv7 one does not run on those. If you are not sure which 32-bit board you have,
take the v5 tar. --remote-image avoids the question entirely: the
image index carries all four platforms and the router picks its own.
Run mikroscope doctor --router user@<address> first; it reads the
architecture off the device and says which of these it wants.
Agent image: jmrplens/mikroscope-agent:1.4.0 on Docker Hub
and ghcr.io/jmrplens/mikroscope-agent:1.4.0
(linux/amd64, linux/arm64, linux/arm/v7, linux/arm/v5). --remote-image
sends RouterOS the whole reference, registry host included
(registry-1.docker.io/jmrplens/mikroscope-agent:1.4.0 for Docker
Hub), so the device-wide /container/config registry-url does not decide
the pull, needs no setting and is never changed (doctor, and upgrade
before it removes anything, read it only to warn about a registry
username), and no registry login is needed. On the reference RB5009
(RouterOS 7.24.4, 2026-09-24) the host inside remote-image= overrode
registry-url, and Docker Hub served the image with no registry username
set. Not tried: a whole install or upgrade in this form (the references
were given to RouterOS by hand), a router at its factory registry-url,
other RouterOS versions, an anonymous GHCR pull by RouterOS, and which
credential RouterOS presents to a host named only in remote-image=.
doctor warns when /container/config holds a username meant for another
registry than the one the image comes from.
Verify the checksums (keyless, no key to fetch); checksums.txt also
covers the agent image tars:
cosign verify-blob \
--certificate-identity-regexp 'https://github.com/jmrplens/mikroscope/.github/workflows/release.yml@refs/tags/.*' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
--bundle checksums.txt.sigstore.json \
checksums.txt
sha256sum --ignore-missing -c checksums.txt
Full changelog: https://github.com/jmrplens/mikroscope/blob/v1.4.0/CHANGELOG.md