Status: Supported. Use the Local Executor where your topology or policy requires local presence. For reachable EKS environments the Cloud Executor is preferred — nothing to install, and nothing in your cluster holds a credential. The Local Executor is never required for autonomy, and installing ChangeGuard Edge (the optional evidence collector) is not a prerequisite for either.
executor package as the Cloud Executor, inside your cluster, under a service account you scope. It speaks the same protocol (permit-v1), verifies the same signed Permits, consumes each one exactly once with ChangeGuard before writing, records the pre-state, applies exactly the signed patch with the field manager changeguard-executor, and reports under the Permit and attempt id.
Installing it
Open the environment in Connected environments → Execution and choose Install Local Executor. ChangeGuard generates a complete manifest for this environment only:- a dedicated namespace, ServiceAccount, Secret and Deployment, all named
changeguard-local-executor-<environment-instance>; - a ClusterRole of the same name that only defines
get,listandpatchon Deployments, StatefulSets and DaemonSets; - a RoleBinding of the same name in each namespace you chose — and nowhere else;
- a new agent credential for the Executor, embedded in the manifest and shown once.
kubectl delete -f of the file removes this environment’s Executor and nothing else. A cluster can safely carry several environments’ Executors side by side.
What it may and may not do
An Executor installed before per-environment names, or one that does not speak
permit-v1, is served nothing and the environment reads Local Executor · upgrade required. Reinstall it from the Execution section; the old objects can then be removed by deleting exactly its own Deployment, ServiceAccount, credential Secret and bindings, and revoking its API key. Never delete a namespace the evidence collector shares.
Stopping it
Scale the Deployment to zero or delete the manifest, revoke its API key, shrink its RoleBindings, or disable execution for the environment in ChangeGuard. Queued work simply holds; nothing executes without a consumed Permit, and a silent attempt is recorded as unreported and fails to a human — it is never assumed to have worked.Cloud Executor
The preferred Executor for reachable EKS environments.
Execution authority and least privilege
The identity model behind both Executors.