On CoreOS, run the install steps with sudo; permission errors during setup are the norm without it, not a broken machine. The agent reads its API key and target from the ignition config, so after a failed install open the rendered ignition and check MW_API_KEY and MW_TARGET for typos before anything else. Validate the key/target pair independently so you know the config values are good. Then read the agent service logs with journalctl; the first failure line distinguishes auth problems from connectivity problems.

Context: Official docs (docs.middleware.io, CoreOS agent installation): documents the CoreOS specifics: permission errors during install are fixed with sudo, and the API key and target travel through the ignition config, so a typo there breaks everything.