Install Container Defender in a cluster
Container orchestrators provide native capabilities for deploying agents, such as Defender, to every node in the cluster.
Prisma Cloud leverages these capabilities to install Defender.
The process for deploying Container Defender to a cluster can be found in the dedicated orchestrator-specific install guides.
If you wish to automate the defenders deployment process to a cluster, or you don’t have kubectl access to your cluster (or oc access for OpenShift), you can deploy Defender DaemonSets directly from the Console UI.
This Defender install flow doesn’t let you manually configure a cluster name.
Cluster names let you segment your views of the environment.
For most cases, this shouldn’t be a problem because if you’re deploying to a managed cluster, then Prisma Cloud retrieves the cluster name directly from the cloud provider.
If you must manually specify a name, deploy your Defenders from
Manage > Defenders > Deploy > DaemonSet
or use twistcli.Deploy Defender DaemonSet using kubeconfig
Prerequisites:
- You’ve created a kubeconfig credential for your cluster so that Prisma Cloud can access it to deploy the Defender DaemonSet.
Deployment process:
- Log into Prisma Cloud Console.
- Go toManage > Defenders > Manage.
- ClickDaemonSets.
- For each cluster in the table, clickActions > Deploy.The table shows a count of deployed Defenders and their version number.