What the agent is
The agent is a container you run inside your VPC, VNet, Kubernetes cluster or data centre. It hosts the connectors, the TDM engine and the industry packs, and it is the only DataNivra component that ever reads your source data.
Network requirements
- Outbound HTTPS from the agent to your DataNivra control-plane endpoint. Proxies are supported.
- No inbound ports. The control plane never connects into your network; the agent polls for work.
- Network reachability from the agent to the sources it reads (read-only) and the targets it provisions.
Identity and enrollment
- An administrator with the agent-management permission creates a one-time enrollment token in the console. It is short-lived and single-use.
- On first start the agent generates its own key pair and enrolls with that token, registering only its public key.
- From then on the agent exchanges a signed assertion for short-lived access tokens. Revoking the agent in the console takes effect at its next token exchange, heartbeat or lease request, and a revoked agent stops all work.
Secrets
Source and target credentials, and masking keys, stay in your secret store. DataNivra configuration refers to them by URI:
| Scheme | Example | Status |
|---|---|---|
env:// | env://DATANIVRA_TDM_READER_PASSWORD | Built in (names must start with an allowed prefix, DATANIVRA_ by default) |
file:// | file://reader | Built in (under the agent's secrets directory; file mode 0600 or 0400) |
k8s:// | k8s://tdm/reader-credentials | Built in (mounted Kubernetes secrets) |
azure-kv:// | azure-kv://tdm-vault/qa-db-password | Needs a provider plugin in a derived agent image, or stage the secret into a file |
aws-sm:// | aws-sm://prod/tdm/reader | Needs a provider plugin in a derived agent image, or stage the secret into a file |
vault:// | vault://secret/tdm#reader | Needs a provider plugin in a derived agent image, or stage the secret into a file |
The agent resolves these locally at run time. The resolved values never leave your environment.
Check the host: datanivra-agent doctor
Run datanivra-agent doctor where the agent runs, before or after enrollment. It checks control-plane DNS, outbound HTTPS, TLS and health, clock skew, local storage and permissions, the agent and protocol versions, and — for each --source-ref or --target-ref you pass — that the secret reference resolves, the connector ships, the source opens and its read-only proof passes, or that the target is writable. Each result has a status, a stable reason code and a link to its fix in the support center; nothing it prints contains a secret value or a row.
Failure behaviour
If the control plane is unreachable, the agent finishes or aborts in-flight work safely, never publishes uncertified output, and does not start new work without a valid lease.
Images and packages
The console's Agents page creates the enrollment token and shows copyable Docker and Kubernetes (Helm) commands. Signed, digest-pinned agent releases with checksums, an SBOM and deployment packages for Docker, Docker Compose, Kubernetes, an Azure VNet and an AWS VPC will be listed on Downloads with each release, together with the verification steps. Until the first release is published that page says so, the image is built from source, and the packages are shared with pilot customers on request.