Skip to main content

Install

ChangeGuard is operator-managed, and the Helm chart is the single install artifact — it deploys the operator, the read-only data collector, and all five scanners. There is no standalone agent.

Key Values

GitOps, OCI, and air-gapped installs

ChangeGuard discovers GitOps state by reading it directly from the Kubernetes API inside the cluster — no ArgoCD or Flux API token is required. Turn discovery on with:
See ArgoCD Integration and Flux CD Integration for details. The chart is also published as an OCI artifact. To install from the registry — or to run fully air-gapped by mirroring the chart and images and repointing them with a single value:

Verify before installing

The chart, the operator and agent images, and a CycloneDX SBOM for each are signed with cosign (backed by AWS KMS). Verify any artifact against the published key before installing:

Upgrade