Skip to main content
The ChangeGuardAgent CRD is the single configuration surface. Apply it, and the operator reconciles all components.

Minimal Example

This enables all defaults: data collection every 10s, KubeBench, Grype, Falco, Pluto, and Syft.

Security Spec

All scanners default to enabled when the security field is present.

GitOps Spec

ChangeGuard discovers GitOps state by reading custom resources directly over the Kubernetes API — no ArgoCD or Flux API token is required.
Discovered ArgoCD applications and Flux resources are pushed to ChangeGuard and persisted, so fleet and GitOps views survive backend restarts and stay consistent across replicas. See ArgoCD Integration and Flux CD Integration.

AI Spec

Status