Microsoft Defender for Cloud
Architecture and deployment

Deploy Defender for Containers to private clusters (Preview)

In brief

The article now explicitly describes deployment through Helm charts or an Azure Arc-enabled Kubernetes extension and names the Helm on Amazon EKS, Helm on Google Kubernetes Engine, and Azure Arc-enabled Kubernetes tabs. The publication date and documentation metadata were also updated.

What Defender admins need to know

Administrators can more quickly select the relevant installation instructions; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Deploy Defender for Containers to private clusters

This article explains how to deploy Microsoft Defender for Containers to private Kubernetes clusters by using Helm charts or an Azure Arc-enabled Kubernetes extension. Private clusters isolate Kubernetes environments from the internet and, in this context, restricted connectivityinternet, which means no direct access to the Kubernetes API server. Defender for Containers extends threat detection and security visibility to these environments, so you can maintain protection coverage while preserving private cluster network boundaries. Before you begin, review the prerequisites.

Prerequisites

Defender for Containers Helm charts are published to mcr.microsoft.com/azuredefender/microsoft-defender-for-containers. Private clusters are supported in 0.11.X chart versions. Use the following tabsHelm on Amazon EKS, Helm on Google Kubernetes Engine, or Azure Arc-enabled Kubernetes tab to install the components for your environment.

Helm on Amazon EKS