The TrustGuard image is published to the NeuralTrust container registry.
Pulling it requires a registry key, which NeuralTrust issues with an enterprise
offer — contact NeuralTrust to get one. See Container images for pulling
directly or mirroring into your own registry.
trustguard-data-plane (port 8081) and dataagent-trustguard.
1
Prepare the namespace and chart sources
Do step 1 of the Hybrid install to
create the namespace and the image pull Secret, then get the chart sources
so
values-trustguard.yaml.example is on disk.2
Create the TrustGuard in the console
Create a private TrustGuard in TrustGuard → Agent Security. Take the
CONFIG_SYNC_TOKEN and the DataAgent enrollment JWT from the wizard output —
see Console setup.3
Create the two Secrets
4
Install
Put the cluster-specific values in their own file:Then install with the TrustGuard slice, which turns on
values-cluster.yaml
global.products.trustguard and wires the two Secrets:trustguard.<domain>; it
needs no inbound rule from NeuralTrust, and only
trustguard-configsync.neuraltrust.ai, databridge.neuraltrust.ai, and the
telemetry host for your region need egress.