Prerequisites
- A Kubernetes cluster (EKS, GKE, AKS, or any CNCF-conformant cluster)
kubectlconfigured and pointing at your clusterhelm3.8+ installed — the installer is a thin wrapper around a Helm install- A ChangeGuard account (start free trial)
Step 1: Get Your API Key
After signing up, your API key is shown on the confirmation screen. You can also create keys in Settings → API Keys → Create Key.Step 2: Install the Operator
- Data collector — read-only snapshot agent pushing every 10 seconds
- KubeBench — CIS Kubernetes benchmark scanning (every 6 hours)
- Grype — container image CVE scanning (every 4 hours + on new deploys)
- Falco — runtime syscall threat detection (continuous, every node)
- Pluto — deprecated Kubernetes API detection (every 12 hours)
- Syft — software bill of materials generation (every 8 hours)
Step 3: Verify
Step 4: View Your Dashboard
Go to app.changeguard.ai and log in. Your cluster appears in the sidebar within 10 seconds, with its first CSC score. Full scan evidence (CIS, CVE, SBOM) fills in over the first scan cycle.Step 5: Gate Your Pipeline
The score becomes useful the day it can say no. Wire the validate endpoint into CI — GitHub Actions, GitLab, ArgoCD PreSync, or any shell — and risky deploys are held before they land.Install Options
The one-liner is configured with environment variables:
The operator installs into the
changeguard-system namespace. For a custom namespace, air-gapped or OCI installs, GitOps, or finer-grained values, install the Helm chart directly.