Enterprise early access is open. Request access

Docs Setup Install with Helm

Install with Helm

Install the private release into a validated Kubernetes cluster, choose a storage backend, and enable the modules your deployment requires.

Before you begin#

  • Kubernetes 1.27 or later, with cluster-admin rights to install CustomResourceDefinitions.
  • Helm 3.
  • The versioned release bundle and image-registry access supplied during onboarding.

Verify and extract the versioned chart before using a profile:

sha256sum --check SHA256SUMS
tar -xzf agentfleet-<version>.tgz

Install the CustomResourceDefinitions#

CRDs install separately from the chart so that upgrading the control plane never rewrites your API types by surprise.

kubectl apply -f crds/
Verify
kubectl get crd | grep agentfleet.io

Install the chart#

Start from a profile rather than raw defaults. A profile is an opinionated set of values for a situation; anything in it can still be overridden.

helm install agentfleet ./agentfleet \
  --namespace agentfleet-system --create-namespace \
  -f agentfleet/profiles/enterprise-baseline.yaml \
  -f agentfleet-images.values.json
helm install agentfleet ./agentfleet \
  --namespace agentfleet-system --create-namespace
helm template agentfleet ./agentfleet \
  --namespace agentfleet-system \
  -f agentfleet/profiles/enterprise-baseline.yaml \
  -f agentfleet-images.values.json
Policy is default-deny

Profiles that enforce policy ship no allow rules, so the control plane denies every request until you author them. That is deliberate — a chart must not ship someone else's authorization policy. See Write a policy that allows traffic.

Choose a storage backend#

Registry, approval, context, and Console sessions each keep state. In-memory storage is the default and is fine for evaluation; it loses everything on restart and cannot run more than one replica.

For anything durable, point each module at PostgreSQL using a Secret that holds its DSN:

kubectl create secret generic agentfleet-registry-postgres \
  --namespace agentfleet-system \
  --from-literal=dsn='postgres://user:password@host:5432/agentfleet?sslmode=require'
helm upgrade agentfleet ./agentfleet \
  --namespace agentfleet-system --reuse-values \
  --set registry.storage.type=postgres \
  --set registry.storage.postgres.existingSecret=agentfleet-registry-postgres
Migrations run themselves

The chart runs a migration Job as a pre-install and pre-upgrade hook. Migrations are transactional, take an advisory lock, and are checksummed, so a partially applied or edited migration history fails loudly instead of drifting.

Every storage key is listed in the generated Helm values reference.

Upgrade#

helm upgrade agentfleet ./agentfleet \
  --namespace agentfleet-system --reuse-values

Apply any new CRDs first — Helm does not upgrade CRDs installed outside the chart:

kubectl apply -f crds/

Uninstall#

helm uninstall agentfleet --namespace agentfleet-system

CRDs and their resources are left in place so that uninstalling the control plane never deletes your agent definitions. Remove them explicitly when you mean to:

kubectl delete -f crds/

Next#