Install agent

Install the DataNivra agent in your environment

The agent is the only DataNivra component that reads your data. It runs inside your network, needs outbound HTTPS only, and opens no inbound port. You install and run it yourself from the signed release files below; the release status above names the current version.

Latest release: 0.3.0 (published 2026-10-07)

Image (pin this digest): ghcr.io/manuelbomi/datanivra-agent@sha256:13590eaa85d789385f124b5c5a54446fc7561d1510b7893705d8d9a4816e882c

Download files and checksums for 0.3.0

Before you install

  1. Create an account and organization (see how to start).
  2. In the console, open Install agent to create a one-time enrollment token. It is short-lived and single-use; store it as a file or secret, never in shell history, and never share it.
  3. Allow outbound HTTPS (443) from the agent host to the control plane, your registry and your secret store. No inbound rule is needed.

Install methods

Every method runs the same signed agent image.
MethodDownloadRequirementsRunbook
Docker (one command)datanivra-agent-docker-0.3.0.tar.gzOne Linux host with Docker; outbound HTTPS (443) only.docs/runbooks/deploy-agent-docker.md
Docker Composedatanivra-agent-docker-compose-0.3.0.tar.gzOne Linux host with Docker Compose; outbound HTTPS (443) only.docs/runbooks/deploy-agent-docker.md
Kubernetes (Helm)datanivra-agent-0.3.0.tgzKubernetes >= 1.25 (chart kubeVersion); manifests validated against 1.29.docs/runbooks/deploy-agent-kubernetes.md
Kubernetes without Helm (kustomize)datanivra-agent-kubernetes-generic-0.3.0.tar.gzKubernetes >= 1.25 with kustomize.docs/runbooks/deploy-agent-kubernetes.md
Customer Azure VNet (Terraform)datanivra-agent-azure-customer-vnet-0.3.0.tar.gzYour Azure subscription and VNet; Terraform; Key Vault for secrets.docs/runbooks/deploy-agent-azure.md
Customer AWS VPC (Terraform, ECS Fargate)datanivra-agent-aws-customer-vpc-0.3.0.tar.gzYour AWS account and VPC; Terraform >= 1.6; Secrets Manager for secrets.docs/runbooks/deploy-agent-aws.md

Docker, one command

Put the enrollment token in a tmpfs secrets directory readable only by uid 10001, then start the hardened container (read-only root filesystem, no capabilities, no published port). Nothing but Docker and the public image is needed; the console's Install agent page prints the same command with your control-plane address filled in:

sudo install -d -m 0700 -o 10001 -g 10001 /run/datanivra-secrets
# Paste the one-time enrollment token at the prompt (input is hidden, nothing is saved)
read -rsp 'Enrollment token: ' DATANIVRA_ENROLLMENT_TOKEN && echo
printf %s "$DATANIVRA_ENROLLMENT_TOKEN" | sudo install -m 0600 -o 10001 -g 10001 /dev/stdin /run/datanivra-secrets/enrollment-token
unset DATANIVRA_ENROLLMENT_TOKEN
docker run -d --name datanivra-agent --restart unless-stopped \
  --read-only --tmpfs /tmp --cap-drop ALL --security-opt no-new-privileges:true \
  -e DATANIVRA_AGENT_CONTROL_PLANE_URL=https://<your-control-plane-api> \
  -e DATANIVRA_AGENT_AGENT_NAME=<agent-name> \
  -e DATANIVRA_AGENT_SECRETS_DIR=/etc/datanivra/secrets \
  -e DATANIVRA_AGENT_ENROLLMENT_TOKEN_REF=file://enrollment-token \
  -v /run/datanivra-secrets:/etc/datanivra/secrets:ro \
  -v datanivra-agent-state:/var/lib/datanivra-agent \
  ghcr.io/manuelbomi/datanivra-agent@sha256:13590eaa85d789385f124b5c5a54446fc7561d1510b7893705d8d9a4816e882c

Behind a proxy set HTTPS_PROXY / NO_PROXY; with a TLS-inspecting proxy set CA_BUNDLE (Compose and Helm: DATANIVRA_AGENT_CA_BUNDLE).

Windows: the agent is a Linux container. On Windows, use Docker Desktop with the WSL 2 backend and run these commands in a WSL terminal (for example Ubuntu), not in PowerShell or the Command Prompt.

Docker Compose

Download and extract the Compose package, then follow the README.md in its directory (enrollment token file, .env from .env.example, docker compose up -d):

curl -fsSLO https://www.datanivra.com/downloads/agent/0.3.0/datanivra-agent-docker-compose-0.3.0.tar.gz
tar -xzf datanivra-agent-docker-compose-0.3.0.tar.gz
cd datanivra-agent-docker-compose-0.3.0/infra/agent-packages/docker-compose
# Now follow README.md in this directory

Kubernetes (Helm)

helm install datanivra-agent https://www.datanivra.com/downloads/agent/0.3.0/datanivra-agent-0.3.0.tgz \
  --set image.repository=ghcr.io/manuelbomi/datanivra-agent \
  --set image.digest=sha256:13590eaa85d789385f124b5c5a54446fc7561d1510b7893705d8d9a4816e882c

The same chart is published as a signed OCI artifact:

helm install datanivra-agent oci://ghcr.io/manuelbomi/charts/datanivra-agent --version 0.3.0 \
  --set image.repository=ghcr.io/manuelbomi/datanivra-agent \
  --set image.digest=sha256:13590eaa85d789385f124b5c5a54446fc7561d1510b7893705d8d9a4816e882c

The chart runs a single-replica StatefulSet (one agent identity per volume) and reads secrets as mounted Kubernetes Secrets. The Kubernetes manifests without Helm and the Terraform modules for your own Azure VNet and AWS VPC are in the packages listed above; each package explains its steps in a README.md, and the documentation package holds the runbooks.

Download files

Every file of agent release 0.3.0 except the per-platform SBOM and provenance documents, which are attached to the image instead (see below). Download the files you need, then check them against the signed checksum list before you use them:

Files of agent release 0.3.0, served from this website.
FileSHA-256
datanivra-agent-0.3.0-helm-values.yaml470b9567e287139c10379b00b1a1ed766d24c8f2687dbda6382cc1e3d04836e1
datanivra-agent-0.3.0.tgzb63bcd91f616d38dfc274e3919ecccc9e06754714cd58dc5db6982d62b443ee4
datanivra-agent-aws-customer-vpc-0.3.0.tar.gzc4ad1aaf3012bac953320963192a852117e67703c145e29c7efb9d74f83a760a
datanivra-agent-azure-customer-vnet-0.3.0.tar.gz02d7dbf681594750a8c543e7cc09b87bd1d64908d0ab7dae2f556e0a22158db6
datanivra-agent-docker-0.3.0.tar.gz61b1da460989e0ed22bcf35e412f72f520a088b69fd132a9a559a74e6f4f9a0b
datanivra-agent-docker-compose-0.3.0.tar.gz818d661016e18645592f4d93adad69b9b58a5bd586d5fb56090ee5b4a4ddfa8a
datanivra-agent-docs-0.3.0.tar.gz9c5f316a5c8dae5dd550ecf66204932567ff9e6d064af55bc997b31133d5d37e
datanivra-agent-kubernetes-generic-0.3.0.tar.gz920315dad59d878fe4267c39f4636af7ea12c6f73caafdbe833895c2df5013c0
RELEASE_NOTES.md5be834f6d8fe9be96fa44481b407f665f18bf2f14d0994b975fa3224ef4d8898
release-manifest.json694c313ba1b091d0f21817d3b8ef009fd95d88011aeac7a30f59d3153c586237
SHA256SUMSChecksum list (verify it with the bundle below)
SHA256SUMS.cosign.bundleSigstore signature bundle of SHA256SUMS
curl -fsSLO https://www.datanivra.com/downloads/agent/0.3.0/SHA256SUMS
curl -fsSLO https://www.datanivra.com/downloads/agent/0.3.0/SHA256SUMS.cosign.bundle
curl -fsSLO https://www.datanivra.com/downloads/agent/0.3.0/datanivra-agent-docker-compose-0.3.0.tar.gz
cosign verify-blob --bundle SHA256SUMS.cosign.bundle \
  --certificate-identity 'https://github.com/manuelbomi/datanivra-platform/.github/workflows/release-agent.yml@refs/tags/agent-v0.3.0' \
  --certificate-oidc-issuer 'https://token.actions.githubusercontent.com' SHA256SUMS
sha256sum -c --ignore-missing SHA256SUMS

cosign verify-blob proves that SHA256SUMS was signed by the DataNivra release workflow for this version; sha256sum then checks every file you downloaded (--ignore-missing skips the ones you did not).

Supported platforms

Container image platforms built by the release workflow.
PlatformStatusNote
linux/amd64BuiltBuilt, signed and published by the release workflow (agent 0.3.0).
linux/arm64BuiltBuilt, signed and published by the release workflow (agent 0.3.0).

Verify before you run it

Always deploy by digest, never by tag, and verify the keyless Sigstore signature made by the DataNivra release workflow:

cosign verify ghcr.io/manuelbomi/datanivra-agent@sha256:13590eaa85d789385f124b5c5a54446fc7561d1510b7893705d8d9a4816e882c \
  --certificate-identity 'https://github.com/manuelbomi/datanivra-platform/.github/workflows/release-agent.yml@refs/tags/agent-v0.3.0' \
  --certificate-oidc-issuer 'https://token.actions.githubusercontent.com'

The image carries a BuildKit SBOM and provenance attestation. Inspect them with:

docker buildx imagetools inspect ghcr.io/manuelbomi/datanivra-agent@sha256:13590eaa85d789385f124b5c5a54446fc7561d1510b7893705d8d9a4816e882c --format '{{ json .SBOM }}'
docker buildx imagetools inspect ghcr.io/manuelbomi/datanivra-agent@sha256:13590eaa85d789385f124b5c5a54446fc7561d1510b7893705d8d9a4816e882c --format '{{ json .Provenance }}'

The checksums of the release files, including the SBOM and provenance documents, are listed in SHA256SUMS (see Download files).

In Kubernetes, enforce the same identity with an admission policy (for example Sigstore policy-controller or Kyverno image verification).

Build from source

The image is built from agent/runtime/Dockerfile at the repository root. The source repository is private today, so building from source requires repository access from DataNivra:

docker build -f agent/runtime/Dockerfile -t datanivra-agent:local .
docker run --rm \
  -e DATANIVRA_AGENT_CONTROL_PLANE_URL=https://<your-control-plane-api> \
  datanivra-agent:local check

datanivra-agent check validates configuration and prints non-secret settings. See the agent installation guide, the support center if something does not connect, and how to verify the agent's network behaviour yourself.