Install agent
Install the DataNivra agent in your environment
The agent is the only DataNivra component that reads your data. It runs inside your network, needs outbound HTTPS only, and opens no inbound port. You install and run it yourself from the signed release files below; the release status above names the current version.
Latest release: 0.3.0 (published 2026-10-07)
Image (pin this digest): ghcr.io/manuelbomi/datanivra-agent@sha256:13590eaa85d789385f124b5c5a54446fc7561d1510b7893705d8d9a4816e882c
Before you install
- Create an account and organization (see how to start).
- In the console, open Install agent to create a one-time enrollment token. It is short-lived and single-use; store it as a file or secret, never in shell history, and never share it.
- Allow outbound HTTPS (443) from the agent host to the control plane, your registry and your secret store. No inbound rule is needed.
Install methods
| Method | Download | Requirements | Runbook |
|---|---|---|---|
| Docker (one command) | datanivra-agent-docker-0.3.0.tar.gz | One Linux host with Docker; outbound HTTPS (443) only. | docs/runbooks/deploy-agent-docker.md |
| Docker Compose | datanivra-agent-docker-compose-0.3.0.tar.gz | One Linux host with Docker Compose; outbound HTTPS (443) only. | docs/runbooks/deploy-agent-docker.md |
| Kubernetes (Helm) | datanivra-agent-0.3.0.tgz | Kubernetes >= 1.25 (chart kubeVersion); manifests validated against 1.29. | docs/runbooks/deploy-agent-kubernetes.md |
| Kubernetes without Helm (kustomize) | datanivra-agent-kubernetes-generic-0.3.0.tar.gz | Kubernetes >= 1.25 with kustomize. | docs/runbooks/deploy-agent-kubernetes.md |
| Customer Azure VNet (Terraform) | datanivra-agent-azure-customer-vnet-0.3.0.tar.gz | Your Azure subscription and VNet; Terraform; Key Vault for secrets. | docs/runbooks/deploy-agent-azure.md |
| Customer AWS VPC (Terraform, ECS Fargate) | datanivra-agent-aws-customer-vpc-0.3.0.tar.gz | Your AWS account and VPC; Terraform >= 1.6; Secrets Manager for secrets. | docs/runbooks/deploy-agent-aws.md |
Docker, one command
Put the enrollment token in a tmpfs secrets directory readable only by uid 10001, then start the hardened container (read-only root filesystem, no capabilities, no published port). Nothing but Docker and the public image is needed; the console's Install agent page prints the same command with your control-plane address filled in:
sudo install -d -m 0700 -o 10001 -g 10001 /run/datanivra-secrets
# Paste the one-time enrollment token at the prompt (input is hidden, nothing is saved)
read -rsp 'Enrollment token: ' DATANIVRA_ENROLLMENT_TOKEN && echo
printf %s "$DATANIVRA_ENROLLMENT_TOKEN" | sudo install -m 0600 -o 10001 -g 10001 /dev/stdin /run/datanivra-secrets/enrollment-token
unset DATANIVRA_ENROLLMENT_TOKEN
docker run -d --name datanivra-agent --restart unless-stopped \
--read-only --tmpfs /tmp --cap-drop ALL --security-opt no-new-privileges:true \
-e DATANIVRA_AGENT_CONTROL_PLANE_URL=https://<your-control-plane-api> \
-e DATANIVRA_AGENT_AGENT_NAME=<agent-name> \
-e DATANIVRA_AGENT_SECRETS_DIR=/etc/datanivra/secrets \
-e DATANIVRA_AGENT_ENROLLMENT_TOKEN_REF=file://enrollment-token \
-v /run/datanivra-secrets:/etc/datanivra/secrets:ro \
-v datanivra-agent-state:/var/lib/datanivra-agent \
ghcr.io/manuelbomi/datanivra-agent@sha256:13590eaa85d789385f124b5c5a54446fc7561d1510b7893705d8d9a4816e882cBehind a proxy set HTTPS_PROXY / NO_PROXY; with a TLS-inspecting proxy set CA_BUNDLE (Compose and Helm: DATANIVRA_AGENT_CA_BUNDLE).
Windows: the agent is a Linux container. On Windows, use Docker Desktop with the WSL 2 backend and run these commands in a WSL terminal (for example Ubuntu), not in PowerShell or the Command Prompt.
Docker Compose
Download and extract the Compose package, then follow the README.md in its directory (enrollment token file, .env from .env.example, docker compose up -d):
curl -fsSLO https://www.datanivra.com/downloads/agent/0.3.0/datanivra-agent-docker-compose-0.3.0.tar.gz
tar -xzf datanivra-agent-docker-compose-0.3.0.tar.gz
cd datanivra-agent-docker-compose-0.3.0/infra/agent-packages/docker-compose
# Now follow README.md in this directoryKubernetes (Helm)
helm install datanivra-agent https://www.datanivra.com/downloads/agent/0.3.0/datanivra-agent-0.3.0.tgz \
--set image.repository=ghcr.io/manuelbomi/datanivra-agent \
--set image.digest=sha256:13590eaa85d789385f124b5c5a54446fc7561d1510b7893705d8d9a4816e882cThe same chart is published as a signed OCI artifact:
helm install datanivra-agent oci://ghcr.io/manuelbomi/charts/datanivra-agent --version 0.3.0 \
--set image.repository=ghcr.io/manuelbomi/datanivra-agent \
--set image.digest=sha256:13590eaa85d789385f124b5c5a54446fc7561d1510b7893705d8d9a4816e882cThe chart runs a single-replica StatefulSet (one agent identity per volume) and reads secrets as mounted Kubernetes Secrets. The Kubernetes manifests without Helm and the Terraform modules for your own Azure VNet and AWS VPC are in the packages listed above; each package explains its steps in a README.md, and the documentation package holds the runbooks.
Download files
Every file of agent release 0.3.0 except the per-platform SBOM and provenance documents, which are attached to the image instead (see below). Download the files you need, then check them against the signed checksum list before you use them:
| File | SHA-256 |
|---|---|
| datanivra-agent-0.3.0-helm-values.yaml | 470b9567e287139c10379b00b1a1ed766d24c8f2687dbda6382cc1e3d04836e1 |
| datanivra-agent-0.3.0.tgz | b63bcd91f616d38dfc274e3919ecccc9e06754714cd58dc5db6982d62b443ee4 |
| datanivra-agent-aws-customer-vpc-0.3.0.tar.gz | c4ad1aaf3012bac953320963192a852117e67703c145e29c7efb9d74f83a760a |
| datanivra-agent-azure-customer-vnet-0.3.0.tar.gz | 02d7dbf681594750a8c543e7cc09b87bd1d64908d0ab7dae2f556e0a22158db6 |
| datanivra-agent-docker-0.3.0.tar.gz | 61b1da460989e0ed22bcf35e412f72f520a088b69fd132a9a559a74e6f4f9a0b |
| datanivra-agent-docker-compose-0.3.0.tar.gz | 818d661016e18645592f4d93adad69b9b58a5bd586d5fb56090ee5b4a4ddfa8a |
| datanivra-agent-docs-0.3.0.tar.gz | 9c5f316a5c8dae5dd550ecf66204932567ff9e6d064af55bc997b31133d5d37e |
| datanivra-agent-kubernetes-generic-0.3.0.tar.gz | 920315dad59d878fe4267c39f4636af7ea12c6f73caafdbe833895c2df5013c0 |
| RELEASE_NOTES.md | 5be834f6d8fe9be96fa44481b407f665f18bf2f14d0994b975fa3224ef4d8898 |
| release-manifest.json | 694c313ba1b091d0f21817d3b8ef009fd95d88011aeac7a30f59d3153c586237 |
| SHA256SUMS | Checksum list (verify it with the bundle below) |
| SHA256SUMS.cosign.bundle | Sigstore signature bundle of SHA256SUMS |
curl -fsSLO https://www.datanivra.com/downloads/agent/0.3.0/SHA256SUMS
curl -fsSLO https://www.datanivra.com/downloads/agent/0.3.0/SHA256SUMS.cosign.bundle
curl -fsSLO https://www.datanivra.com/downloads/agent/0.3.0/datanivra-agent-docker-compose-0.3.0.tar.gz
cosign verify-blob --bundle SHA256SUMS.cosign.bundle \
--certificate-identity 'https://github.com/manuelbomi/datanivra-platform/.github/workflows/release-agent.yml@refs/tags/agent-v0.3.0' \
--certificate-oidc-issuer 'https://token.actions.githubusercontent.com' SHA256SUMS
sha256sum -c --ignore-missing SHA256SUMScosign verify-blob proves that SHA256SUMS was signed by the DataNivra release workflow for this version; sha256sum then checks every file you downloaded (--ignore-missing skips the ones you did not).
Supported platforms
| Platform | Status | Note |
|---|---|---|
linux/amd64 | Built | Built, signed and published by the release workflow (agent 0.3.0). |
linux/arm64 | Built | Built, signed and published by the release workflow (agent 0.3.0). |
Verify before you run it
Always deploy by digest, never by tag, and verify the keyless Sigstore signature made by the DataNivra release workflow:
cosign verify ghcr.io/manuelbomi/datanivra-agent@sha256:13590eaa85d789385f124b5c5a54446fc7561d1510b7893705d8d9a4816e882c \
--certificate-identity 'https://github.com/manuelbomi/datanivra-platform/.github/workflows/release-agent.yml@refs/tags/agent-v0.3.0' \
--certificate-oidc-issuer 'https://token.actions.githubusercontent.com'The image carries a BuildKit SBOM and provenance attestation. Inspect them with:
docker buildx imagetools inspect ghcr.io/manuelbomi/datanivra-agent@sha256:13590eaa85d789385f124b5c5a54446fc7561d1510b7893705d8d9a4816e882c --format '{{ json .SBOM }}'
docker buildx imagetools inspect ghcr.io/manuelbomi/datanivra-agent@sha256:13590eaa85d789385f124b5c5a54446fc7561d1510b7893705d8d9a4816e882c --format '{{ json .Provenance }}'The checksums of the release files, including the SBOM and provenance documents, are listed in SHA256SUMS (see Download files).
In Kubernetes, enforce the same identity with an admission policy (for example Sigstore policy-controller or Kyverno image verification).
Build from source
The image is built from agent/runtime/Dockerfile at the repository root. The source repository is private today, so building from source requires repository access from DataNivra:
docker build -f agent/runtime/Dockerfile -t datanivra-agent:local .
docker run --rm \
-e DATANIVRA_AGENT_CONTROL_PLANE_URL=https://<your-control-plane-api> \
datanivra-agent:local checkdatanivra-agent check validates configuration and prints non-secret settings. See the agent installation guide, the support center if something does not connect, and how to verify the agent's network behaviour yourself.