AgentGuard phase one supports AWS only. Support for additional clouds is planned for the future.
AgentGuard Setup Overview
The AgentGuard setup workflow is as follows:
- Set up AgentGuard - Connect your Cloud account and Kubernetes cluster so that AgentGuard can discover your AI workloads.
- Configure the level of visibility - Configure the level of visibility as per your requirements:
- Without a gateway provides an inventory of every AI workload, a classification by vendor, and a risk level for each workload, with no changes to your network.
- With a gateway adds full-detail AI traffic analysis and rule enforcement.
You can add a gateway at any time for deeper visibility and enforcement.
Steps to Set Up AgentGuard
The following steps set up AgentGuard by onboarding your Cloud accounts and Kubernetes clusters so that AgentGuard can discover your AI workloads.Prerequisites
- Access to Aviatrix Cloud Console at console.cloud.aviatrix.com.
- An AWS account that you can onboard with an IAM role.
-
The read-only IAM permissions listed in the
AWS permissions section.
AgentGuard phase one supports AWS only. Support for additional clouds is planned for the future.
Step 1: Onboard Your AWS Account
Onboarding connects your AWS account so that AgentGuard can discover your AI workloads. AgentGuard requires read-only access only.
1
Open the onboarding workflow
From the Aviatrix Cloud Console, navigate to Cloud Resources > Cloud Accounts > +
Cloud Account.
2
Launch the CloudFormation template
Enter an Account Name, select AWS, then select AWS IAM Role
and CloudFormation Script. Click Launch CloudFormation to create
the required IAM role in your AWS account, then copy the resulting
AviatrixRoleAppARN value and paste it into the AWS Role ARN field
in Aviatrix. For the complete onboarding procedure, see
Onboard an AWS Cloud Account.
AgentGuard phase one supports AWS only. Support for additional clouds is planned for the future.
3
Validate and onboard
Click Next. When the Account Onboarded message appears, click
Onboard.
4
Confirm the account is connected
Confirm that the account shows Status = UP with a recent last sync. Your
VPCs and Kubernetes clusters appear automatically under Cloud Assets.
Step 2: Onboard Your Kubernetes Cluster
Complete this step if you run AI workloads on Kubernetes. Onboarding the Kubernetes cluster enables AgentGuard to identify your pods and resolve workloads to names rather than IP addresses.
1
Locate the cluster
From the Aviatrix Cloud Console, navigate to Cloud Assets > Kubernetes
Clusters and wait for your cluster to appear with Status = Not
Onboarded.
2
Install the Aviatrix Helm chart
Select your cluster, then click Onboard Cluster. Install the Aviatrix
Helm chart in the cluster, using the install commands shown in the dialog.
This step is required for every onboarding method.
3
Choose an onboarding method and onboard
Choose Terraform, Command Line, or Upload Kubeconfig File, and
follow the instructions shown for that method. Select the checkbox
confirming that you installed the Helm chart (and, for Terraform or
Command Line, that you ran the generated script), then click Onboard.
4
Verify that pods are discovered
Confirm that Onboarded = Yes and that the pod count is greater than
zero. Open the Pods view and confirm that your AI client pods appear
by name — for example, an Ollama, Claude, Bedrock, or GitHub client pod.
AWS Permissions (Read-Only)
AgentGuard requires the following read-only permissions on the onboarded role.Troubleshooting
The account does not reach Status = UP
The account does not reach Status = UP
Confirm that the AWS Role ARN pasted into Aviatrix matches the
AviatrixRoleAppARN value from the CloudFormation stack Outputs
tab, and that the CloudFormation stack reached CREATE_COMPLETE. The
validation error identifies any missing permission.
The Kubernetes cluster does not appear
The Kubernetes cluster does not appear
Confirm that the account is UP, then confirm that the role has the
eks:ListClusters and eks:DescribeCluster permissions. Clusters appear
under Cloud Assets > Kubernetes Clusters after the account syncs.