Use this path when collectors must run inside your own cluster—for example network-restricted Databricks, Microsoft Copilot Studio, Azure Foundry, or Azure M365 Agents environments, or policies that require Kubernetes-native deployment.
Supported cluster (for example Amazon EKS or Azure AKS) in the region you select when creating the runtime
Access
kubectl configured for the target cluster; permissions to create namespaces and deploy Helm releases in the runtime namespace
Network
Outbound-only internet access from the cluster to Trust3 (Runtime Plane connects outbound; no inbound connectivity from the internet into the cluster is required for the control-plane link)