> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Set Up AgentGuard

> Connect your AWS account and Kubernetes cluster so that AgentGuard can discover your AI workloads. This setup is the prerequisite for both levels of AgentGuard visibility.

This guide describes how to connect your AWS account and Kubernetes workloads to
AgentGuard so that it can discover your AI workloads.

<Note> AgentGuard phase one supports AWS only. Support for additional clouds is planned for the future.</Note>

After completing the setup, you can configure either level of visibility as per your requirements:

* [Get Basic Visibility Without a Gateway](/docs/cloud/security/agentguard/getting-started/agentguard-without-gateway)
* [Get Deep Visibility and Enforcement With a Gateway](/docs/cloud/security/agentguard/getting-started/agentguard-with-gateway)

## AgentGuard Setup Overview

The AgentGuard setup workflow is as follows:

<Frame title="AgentGuard Setup Workflow">
  <img src="https://mintcdn.com/aviatrix-14b37c43/viuzwLiPfKgpTD5k/docs/cloud/images/agentguard-setup-workflow.png?fit=max&auto=format&n=viuzwLiPfKgpTD5k&q=85&s=d45b29b85dcd6f76d8a5a0b9436ab5bf" alt="AgentGuard Setup Workflow" width="2388" height="1114" data-path="docs/cloud/images/agentguard-setup-workflow.png" />
</Frame>

1. *Set up AgentGuard* - Connect your Cloud account and Kubernetes cluster so that AgentGuard can discover your AI workloads.
2. *Configure the level of visibility* - Configure the level of visibility as per your requirements:
   * **[Without a gateway](/docs/cloud/security/agentguard/getting-started/agentguard-without-gateway)**
     provides an inventory of every AI workload, a classification by vendor, and a
     risk level for each workload, with no changes to your network.
   * **[With a gateway](/docs/cloud/security/agentguard/getting-started/agentguard-with-gateway)**
     adds full-detail AI traffic analysis and rule enforcement.

You get the deeper visibility and enforcement with a gateway when you require detailed traffic analysis and enforcement.
<Info>You can add a gateway at any time for deeper visibility and enforcement.</Info>

## Steps to Set Up AgentGuard

The following steps set up AgentGuard by onboarding your Cloud accounts and Kubernetes clusters so that AgentGuard can discover your AI workloads.

### Prerequisites

* Access to Aviatrix Cloud Console at
  [console.cloud.aviatrix.com](https://console.cloud.aviatrix.com).
* An AWS account that you can onboard with an IAM role.
* The read-only IAM permissions listed in the
  [AWS permissions](#aws-permissions-read-only) section.

  <Note>
    AgentGuard phase one supports AWS only. Support for additional clouds is planned for the future.
  </Note>

### Step 1: Onboard Your AWS Account

Onboarding connects your AWS account so that AgentGuard can discover your AI
workloads. AgentGuard requires read-only access only.

<Frame title="Onboard Your AWS Account">
  <img src="https://mintcdn.com/aviatrix-14b37c43/viuzwLiPfKgpTD5k/docs/cloud/images/agentguard-onboard-aws-account.png?fit=max&auto=format&n=viuzwLiPfKgpTD5k&q=85&s=a90d69221caa3b6c79e4dbec363a39ec" alt="Onboard Your AWS Account" width="5120" height="2880" data-path="docs/cloud/images/agentguard-onboard-aws-account.png" />
</Frame>

<Steps>
  <Step title="Open the onboarding workflow">
    From the Aviatrix Cloud Console, navigate to **Cloud Resources > Cloud Accounts > +
    Cloud Account**.
  </Step>

  <Step title="Launch the CloudFormation template">
    Enter an **Account Name**, select **AWS**, then select **AWS IAM Role**
    and **CloudFormation Script**. Click **Launch CloudFormation** to create
    the required IAM role in your AWS account, then copy the resulting
    **AviatrixRoleAppARN** value and paste it into the **AWS Role ARN** field
    in Aviatrix. For the complete onboarding procedure, see
    [Onboard an AWS Cloud Account](/docs/cloud/platform-administration/onboard-offboard/aws-cloud-account-onboard).

    <Note>
      AgentGuard phase one supports AWS only. Support for additional clouds is planned for the future.
    </Note>
  </Step>

  <Step title="Validate and onboard">
    Click **Next**. When the **Account Onboarded** message appears, click
    **Onboard**.
  </Step>

  <Step title="Confirm the account is connected">
    Confirm that the account shows **Status = UP** with a recent last sync. Your
    VPCs and Kubernetes clusters appear automatically under **Cloud Assets**.
  </Step>
</Steps>

<Tip>
  If a required permission is missing, the validation error identifies the
  specific permission. Add it to the role and validate again.
</Tip>

### Step 2: Onboard Your Kubernetes Cluster

Complete this step if you run AI workloads on Kubernetes. Onboarding the Kubernetes cluster
enables AgentGuard to identify your pods and resolve workloads to names rather
than IP addresses.

<Frame title="Onboard Your Kubernetes Cluster">
  <img src="https://mintcdn.com/aviatrix-14b37c43/viuzwLiPfKgpTD5k/docs/cloud/images/agentguard-onboard-kubernetes-cluster.png?fit=max&auto=format&n=viuzwLiPfKgpTD5k&q=85&s=52428d19137b75ea997bcc5653c834ac" alt="Manually Onboard Cluster dialog showing cloud provider selection, cluster name, cloud account, region, VPC/VNet, network mode, and a kubeconfig file upload field" width="5120" height="2880" data-path="docs/cloud/images/agentguard-onboard-kubernetes-cluster.png" />
</Frame>

<Steps>
  <Step title="Locate the cluster">
    From the Aviatrix Cloud Console, navigate to **Cloud Assets > Kubernetes
    Clusters** and wait for your cluster to appear with **Status = Not
    Onboarded**.
  </Step>

  <Step title="Install the Aviatrix Helm chart">
    Select your cluster, then click **Onboard Cluster**. Install the Aviatrix
    Helm chart in the cluster, using the install commands shown in the dialog.
    This step is required for every onboarding method.
  </Step>

  <Step title="Choose an onboarding method and onboard">
    Choose **Terraform**, **Command Line**, or **Upload Kubeconfig File**, and
    follow the instructions shown for that method. Select the checkbox
    confirming that you installed the Helm chart (and, for Terraform or
    Command Line, that you ran the generated script), then click **Onboard**.
  </Step>

  <Step title="Verify that pods are discovered">
    Confirm that **Onboarded = Yes** and that the pod count is greater than
    zero. Open the **Pods** view and confirm that your AI client pods appear
    by name — for example, an Ollama, Claude, Bedrock, or GitHub client pod.
  </Step>
</Steps>

### AWS Permissions (Read-Only)

AgentGuard requires the following read-only permissions on the onboarded role.

| Permission | Used for |
| - | - |
| `ec2:DescribeVpcs`, `DescribeSubnets`, `DescribeInstances`, `DescribeSecurityGroups` | Discovering virtual machines and VPCs |
| `eks:ListClusters`, `DescribeCluster`, `ListNodegroups` | Discovering Kubernetes clusters |
| `ec2:DescribeFlowLogs`, `s3:GetObject` | Reading VPC flow logs for risk scoring |
| `bedrock:ListAgents`, `GetAgent` | Discovering AWS Bedrock agents (optional) |

## Troubleshooting

<AccordionGroup>
  <Accordion title="The account does not reach Status = UP">
    Confirm that the **AWS Role ARN** pasted into Aviatrix matches the
    **AviatrixRoleAppARN** value from the CloudFormation stack **Outputs**
    tab, and that the CloudFormation stack reached **CREATE\_COMPLETE**. The
    validation error identifies any missing permission.
  </Accordion>

  <Accordion title="The Kubernetes cluster does not appear">
    Confirm that the account is **UP**, then confirm that the role has the
    `eks:ListClusters` and `eks:DescribeCluster` permissions. Clusters appear
    under **Cloud Assets > Kubernetes Clusters** after the account syncs.
  </Accordion>
</AccordionGroup>

## Next Steps

Setup is complete when the account shows **Status = UP** and your workloads
appear under **Cloud Assets**. Refer to the following for the level of visibility that matches your requirements:

* [Get Basic Visibility Without a Gateway](/docs/cloud/security/agentguard/getting-started/agentguard-without-gateway)
* [Get Deep Visibility and Enforcement With a Gateway](/docs/cloud/security/agentguard/getting-started/agentguard-with-gateway)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.