2.0.x), installed with a Helm chart into the ankra namespace. Whether the platform upgrades a cluster’s agent for you depends on the auto-upgrade settings described in Upgrading the Agent.
The agent requires cluster-admin permissions to manage all Kubernetes resources and deploy add-ons.
What the Agent Does
- Resource browsing - lists and watches Deployments, Pods, Services and other resource types for the portal, CLI and AI.
- Pod logs - streams container logs to Ankra.
- Deployments - installs and upgrades your Stacks’ add-ons and manifests with the native Helm engine (the default) or through ArgoCD. See Deployment Engines.
- kubectl access - proxies authenticated
kubectlrequests to the cluster API server with no inbound ports. See Accessing Clusters with kubectl. - Fleet map reporting - optionally reports the cluster’s public egress IP so it appears on the Dashboard world map.
Installation
When you import a cluster, Ankra generates a Helm install command with a unique token. It looks like this:Verify Installation
Check the agent is running:Cluster States
Every cluster carries one status badge, shown on the clusters list, in the cluster’s sidebar and in the activity drawer. It combines whether the agent is connected with the health of what runs on the cluster:
The activity drawer lists the reasons behind a Needs Attention badge. A real failure always wins: a cluster that is provisioning, awaiting connection or stopped still shows Needs Attention if an operation failed or a resource is failing.
While the agent is offline, the cluster’s workloads keep running, but Ankra cannot deploy to the cluster or show live resources and logs. Its configuration and history stay available. To bring it back, see Agent Not Connecting.
Configuration Reference
Required Settings
Using an Existing Secret
For production environments, store the token in a Kubernetes secret:Performance Tuning
For large clusters (1000+ resources), adjust these settings:
Example for large clusters:
Fleet world map (public IP reporting)
To place an imported cluster on the Dashboard world map when it has no recognisable cloud region, let the agent report its public egress IP on check-in:public_ip.lookup_url, default https://api.ipify.org) and reports the result. Leave it disabled (the default) for air-gapped clusters or where egress IP lookups are undesirable.
All Helm Values
The complete value list - connection, workers, watch tuning, public IP reporting, image, security contexts, scheduling, and metrics - lives in the Agent Helm Values reference.The agent runs as a non-root container by default (
runAsNonRoot: true, UID/GID 1000, readOnlyRootFilesystem: true, all Linux capabilities dropped, seccompProfile: RuntimeDefault). Because the root filesystem is read-only, the chart mounts writable emptyDir volumes for /tmp, ~/.cache, and ~/.config via writable_volumes.enabled (default true). Don’t lower these security settings unless you are running a custom image.Advanced tuning via extra_env
Less-common knobs are set as environment variables through extra_env:
Architecture
The agent uses a NATS-based architecture for real-time communication: Key features:- Outbound connections only - The agent initiates all connections, no inbound ports required
- Real-time streaming - Resource data streams efficiently using pagination
- Automatic reconnection - Handles network interruptions gracefully
- kubectl proxy - Forwards authenticated
kubectlrequests (includingwatch,logs -f, andexec) from the platform to the cluster API server, so you can reach private clusters without inbound access. See Accessing Clusters with kubectl. - Health monitoring - Exposes
/livezand/readyzendpoints on port 8080
Network Requirements
The agent requires outbound connectivity to:
No inbound ports need to be opened on your cluster.
Upgrading the Agent
New agent releases are published on the2.0.x version track. When auto-upgrade is on, the platform rolls clusters forward to the latest published version, a few clusters at a time. You can still trigger an upgrade yourself at any time.
- Organisations created since 7 September 2026 have Auto-upgrade Agents on by default. Older organisations turn it on in Organisation Settings → General.
- A single cluster can opt out with Disable Auto-upgrade in its own settings.
From the Platform
In the cluster’s Settings → General, click Upgrade to v<version>. The agent will self-upgrade using Helm.Manually
Troubleshooting
Agent Not Connecting
-
Check agent pods are running:
-
View agent logs:
-
Verify network connectivity:
-
Check the token is set:
Common Issues
Health Checks
The agent exposes health endpoints:Uninstalling
To remove the agent from your cluster:Security
RBAC Requirements
The agent requires cluster-admin permissions to:- Browse all Kubernetes resources
- Deploy Helm charts and manifests
- Manage add-ons via the native Helm engine or ArgoCD
- Stream pod logs and proxy authenticated
kubectlrequests
ClusterRoleBinding with the necessary permissions.
Token Security
- Tokens are unique per cluster
- Tokens can be revoked by deleting the cluster from Ankra
- Store tokens in Kubernetes secrets (not in Helm values) for production