Skip to main content
Status: Supported. Use the Local Executor where your topology or policy requires local presence. For reachable EKS environments the Cloud Executor is preferred — nothing to install, and nothing in your cluster holds a credential. The Local Executor is never required for autonomy, and installing ChangeGuard Edge (the optional evidence collector) is not a prerequisite for either.
The Local Executor runs the same executor package as the Cloud Executor, inside your cluster, under a service account you scope. It speaks the same protocol (permit-v1), verifies the same signed Permits, consumes each one exactly once with ChangeGuard before writing, records the pre-state, applies exactly the signed patch with the field manager changeguard-executor, and reports under the Permit and attempt id.

Installing it

Open the environment in Connected environments → Execution and choose Install Local Executor. ChangeGuard generates a complete manifest for this environment only:
  • a dedicated namespace, ServiceAccount, Secret and Deployment, all named changeguard-local-executor-<environment-instance>;
  • a ClusterRole of the same name that only defines get, list and patch on Deployments, StatefulSets and DaemonSets;
  • a RoleBinding of the same name in each namespace you chose — and nowhere else;
  • a new agent credential for the Executor, embedded in the manifest and shown once.
Apply it with your own credentials:
Applying it is the grant. Nothing in ChangeGuard can give itself write access. Then click Verify execution access in the Execution section: the Executor proves it holds the verbs it needs in your namespaces and not the ones it must never have, and verifies a signed probe Permit — without reading or changing any workload. Every object the install creates carries the environment’s instance label and annotation, so regenerating the install updates this environment’s Executor in place, another environment’s install never touches it, and kubectl delete -f of the file removes this environment’s Executor and nothing else. A cluster can safely carry several environments’ Executors side by side.

What it may and may not do

An Executor installed before per-environment names, or one that does not speak permit-v1, is served nothing and the environment reads Local Executor · upgrade required. Reinstall it from the Execution section; the old objects can then be removed by deleting exactly its own Deployment, ServiceAccount, credential Secret and bindings, and revoking its API key. Never delete a namespace the evidence collector shares.

Stopping it

Scale the Deployment to zero or delete the manifest, revoke its API key, shrink its RoleBindings, or disable execution for the environment in ChangeGuard. Queued work simply holds; nothing executes without a consumed Permit, and a silent attempt is recorded as unreported and fails to a human — it is never assumed to have worked.

Cloud Executor

The preferred Executor for reachable EKS environments.

Execution authority and least privilege

The identity model behind both Executors.