Installation Prerequisites
Before starting the installation, ensure that the Kubernetes cluster (minikube in this example) is up and running.
minikube statusIf the output is not Running, start it:
minikube startOnce the cluster is running, verify that the following tooling and network prerequisites are also in place.
Tooling Prerequisites | ||
|---|---|---|
Requirement | Commands to Check | Expected |
Cluster admin rights | kubectl auth can-i create clusterrole | yes (the injector creates cluster-scoped resources) |
Helm 3 installed | helm version --short | v3.x.x or newer |
Node architecture is known | kubectl get nodes -o jsonpath='{.items[0].status.nodeInfo.architecture}' | for example, amd64 — record this value; it is needed for the image architecture check |
The cluster must also have outbound network access to the following endpoints.
Required Outbound Access | ||
|---|---|---|
Destination | Port | Used for |
krontechnology.github.io | 443 | Downloading the Helm chart index and chart packages |
Container image registry (docker.io / krontechnology) | 443 | Pulling the Agent, aapm-service, injector, and aapm-client images |
Kron PAM server (<KRON_PAM_SERVER_ADDRESS>) | 443 | Agent registration and secret retrieval |
Image Architecture Check
The container images are not guaranteed to be published as multi-architecture manifests for every tag. If the image architecture doesn't match the node architecture, the container fails to start with exec format error and enters CrashLoopBackOff. This failure is unrelated to chart or values configuration and can't be fixed by any Helm operation. Verify the match before installing.
Node architecture
kubectl get nodes -o jsonpath='{.items[0].status.nodeInfo.architecture}'- Image architecture (minikube example)
minikube ssh -- docker pull <repository>/<image>:<tag>
minikube ssh -- docker image inspect <repository>/<image>:<tag> --format '{{.Architecture}}'Success criteria: Both commands return the same architecture value (for example amd64).
If they don't match, identify a tag that is published for the node's architecture and override the image tag at install time. For the injected client this is sidecarImage.tag, described in the injector installation section.
If an image with the same tag was previously pulled on the node, the cached copy is reused because imagePullPolicy defaults to IfNotPresent. Remove the cached image before retrying: minikube ssh -- docker rmi -f <repository>/<image>:<tag>