Install the Secrets Management Agent
The Agent is the component that registers with the Kron PAM server and provides gRPC access to other components. The parameters below control the following:
Secrets Management Agent Parameters | |
|---|---|
Parameter | Meaning |
secrets.installToken | The token used for initial registration with Kron PAM, typically single use. Obtained from the Kron PAM console under Application Token → Agent. |
secrets.address | The address (hostname/IP) of the Kron PAM server. |
config.singleconnect.agentName | The unique name under which this agent will appear in the Kron PAM console. |
config.singleconnect.sslIgnored | Set to true if the Kron PAM server's certificate is self-signed or untrusted; false is sufficient if Kron PAM has a publicly trusted certificate. |
config.singleconnect.hostnameIgnored | Set to true to skip hostname verification if the certificate hostname doesn't match the connection address. |
helm install kron-aapm-agent kron-pam/kron-aapm-agent \
--namespace ns-agent \
--create-namespace \
--set secrets.installToken="<KRON_PAM_AAPM_AGENT_INSTALLATION_TOKEN>" \
--set secrets.address="<KRON_PAM_SERVER_ADDRESS>" \
--set config.singleconnect.agentName="<AGENT_NAME>" \
--set config.singleconnect.sslIgnored=false \
--set config.singleconnect.hostnameIgnored=falseThe Installation Token is valid for a limited period. Once it expires, it can no longer be used for agent registration. Obtain a new token from the Kron PAM console if the token has expired.
Verification
Execute the following command to check the status of the installation.
kubectl get pods -n ns-agent
kubectl logs -n ns-agent deploy/kron-aapm-agent --tail=40Success criteria: Pod is 1/1 Running AND the logs show doRegisterCall result: OK followed by Ping successful....