Support matrix
The matrices on this page detail the compatible deployment types for application protocols. The matrices also cover Aembit features such as Client Workload Identifiers, Agent Controller Trust Providers, Agent Proxy Trust Providers, and Conditional Access. The matrices list the operating systems for VMs that Aembit supports. The CLI Support section includes the operating systems and Access Policy features that the Aembit CLI supports. The SDK support section covers Trust Providers by language.
Aembit Edge supports multiple types of deployments:
-
Kubernetes
-
AWS Elastic Container Service (ECS) Fargate
-
Virtual Machines (Linux, Windows, Docker-compose)
-
AWS Lambda (function, container)
-
Virtual Appliance (VMware)
| Icon | Meaning |
|---|---|
| ✅ | Supported |
| ❌ | Not supported |
| ⚪️ | Not applicable |
Application protocols
Section titled “Application protocols”| Application Protocols | Kubernetes | AWS EKS Fargate | AWS ECS Fargate | Virtual Machine (Linux) | Virtual Machine (Windows) | Virtual Appliance | Docker-compose on VMs | AWS Lambda |
|---|---|---|---|---|---|---|---|---|
| HTTP 1.1 | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
| Postgres 3.0 | ✅ | ❌ | ❌ | ✅ | ❌ | ❌ | ✅ | ❌ |
| MySQL 10 | ✅ | ❌ | ❌ | ✅ | ❌ | ❌ | ✅ | ❌ |
| Redis RESP2 | ✅ | ❌ | ❌ | ✅ | ❌ | ❌ | ✅ | ❌ |
| Redis RESP3 | ✅ | ❌ | ❌ | ✅ | ❌ | ❌ | ✅ | ❌ |
| Snowflake SDK (HTTP-based) | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
| Snowflake REST API (HTTP-based) | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
| Amazon Redshift 3.0 | ✅ | ❌ | ❌ | ✅ | ❌ | ❌ | ✅ | ❌ |
| Oracle Database | ✅* | ❌ | ❌ | ✅ | ❌ | ❌ | ✅ | ❌ |
* Oracle Database on Kubernetes requires transparent steering configured for the Oracle database host.
Client Workload Identifiers
Section titled “Client Workload Identifiers”| Client Workload Identifiers | Kubernetes | AWS EKS Fargate | AWS ECS Fargate | Virtual Machine (Linux) | Virtual Machine (Windows) | Virtual Appliance | Docker-compose on VMs | AWS Lambda |
|---|---|---|---|---|---|---|---|---|
| Aembit Client ID | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ✅ | ✅ |
| AWS Account ID | ❌ | ❌ | ❌ | ✅* | ✅* | ❌ | ✅* | ❌ |
| AWS EC2 Instance ID | ❌ | ⚪️ | ⚪️ | ✅* | ✅* | ❌ | ✅* | ❌ |
| AWS ECS Task Family | ⚪️ | ⚪️ | ✅ | ⚪️ | ⚪️ | ⚪️ | ⚪️ | ⚪️ |
| AWS Region | ❌ | ❌ | ❌ | ✅* | ✅* | ❌ | ✅* | ❌ |
| AWS Subscription ID | ❌ | ❌ | ❌ | ✅* | ✅* | ❌ | ✅* | ❌ |
| AWS VM ID | ❌ | ❌ | ❌ | ✅* | ✅* | ❌ | ✅* | ⚪️ |
| Hostname | ❌ | ❌ | ❌ | ✅ | ✅ | ❌ | ✅ | ❌ |
| Kubernetes Pod name | ✅ | ✅ | ⚪️ | ⚪️ | ⚪️ | ⚪️ | ⚪️ | ⚪️ |
| Kubernetes Pod name prefix | ✅ | ✅ | ⚪️ | ⚪️ | ⚪️ | ⚪️ | ⚪️ | ⚪️ |
| Process Command Line ** | ❌ | ❌ | ❌ | ✅ | ❌ | ❌ | ❌ | ❌ |
| Process Name ** | ❌ | ❌ | ❌ | ✅ | ❌ | ❌ | ❌ | ❌ |
| Process Path ** | ❌ | ❌ | ❌ | ✅ | ❌ | ❌ | ❌ | ❌ |
| Process User Name ** | ❌ | ❌ | ❌ | ✅ | ❌ | ❌ | ❌ | ❌ |
| Source IP | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ |
| AWS Lambda ARN | ⚪️ | ⚪️ | ⚪️ | ⚪️ | ⚪️ | ⚪️ | ⚪️ | ✅ |
* These Client Workload identifiers are available for their respective cloud platforms only.
** Before using process-based identifiers, you must enable them in Agent Proxy first. See Process Command Line, Process Name, Process Path, and Process User Name for details
Agent Controller Trust Providers
Section titled “Agent Controller Trust Providers”| Trust Providers | Kubernetes | AWS EKS Fargate | AWS ECS Fargate | Virtual Machine | Virtual Appliance | Docker-compose on VMs | AWS Lambda |
|---|---|---|---|---|---|---|---|
| AWS Role | ❌ | ❌ | ✅ | ❌ | ❌ | ⚪️ | ⚪️ |
| AWS Metadata Service | ✅* | ❌ | ❌ | ✅* | ❌ | ⚪️ | ⚪️ |
| Azure Instance Metadata Service | ✅* | ⚪️ | ⚪️ | ✅* | ❌ | ⚪️ | ⚪️ |
| GCP Identity Token | ✅* | ⚪️ | ⚪️ | ✅* | ❌ | ⚪️ | ⚪️ |
| Kubernetes Service Account | ✅ | ✅ | ⚪️ | ⚪️ | ⚪️ | ⚪️ | ⚪️ |
| Kerberos | ⚪️ | ⚪️ | ⚪️ | ⚪️ | ⚪️ | ⚪️ | ⚪️ |
* Aembit tailors the Trust Providers available in Kubernetes and VM environments specifically for their respective cloud platforms.
Agent Proxy Trust Providers
Section titled “Agent Proxy Trust Providers”| Trust Providers | Kubernetes | AWS EKS Fargate | AWS ECS Fargate | Virtual Machine (Linux) | Virtual Machine (Windows) | Virtual Appliance | Docker-compose on VMs | AWS Lambda |
|---|---|---|---|---|---|---|---|---|
| AWS Role | ❌ | ❌ | ✅ | ✅** | ✅** | ❌ | ❌ | ✅ |
| AWS Metadata Service | ✅* | ❌ | ❌ | ✅* | ✅* | ❌ | ✅* | ❌ |
| Azure Instance Metadata Service | ✅* | ⚪️ | ⚪️ | ✅* | ✅* | ❌ | ✅* | ⚪️ |
| GCP Identity Token | ⚪️ | ⚪️ | ⚪️ | ❌ | ❌ | ❌ | ❌ | ⚪️ |
| Kubernetes Service Account | ✅ | ✅ | ⚪️ | ⚪️ | ⚪️ | ⚪️ | ⚪️ | ⚪️ |
| Kerberos | ❌ | ❌ | ❌ | ✅ | ✅ | ❌ | ✅ | ⚪️ |
* Aembit tailors the Trust Providers available in Kubernetes and VM environments specifically for their respective cloud platforms.
** The AWS Role Trust Provider supports only EC2 instances with an attached IAM role.
Conditional Access
Section titled “Conditional Access”| Access Conditions | Kubernetes | AWS EKS Fargate | AWS ECS Fargate | Virtual Machine (Linux) | Virtual Machine (Windows) | Virtual Appliance | Docker-compose on VMs | AWS Lambda |
|---|---|---|---|---|---|---|---|---|
| CrowdStrike | ❌ | ❌ | ❌ | ✅ | ✅ | ❌ | ✅ | ❌ |
| Wiz | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ✅ |
| Time | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
| GeoIP | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
Supported operating systems for VMs
Section titled “Supported operating systems for VMs”The following sections contain the operating system versions that Aembit Agent Proxy and Agent Controller support on VMs
Linux distributions
Section titled “Linux distributions”| Linux Distribution | Version |
|---|---|
| Ubuntu | 20.04 |
| Ubuntu | 22.04 |
| Ubuntu | 24.04 |
| Red Hat | 8.6 |
| Red Hat | 8.9 |
| Red Hat | 9.3 |
Windows editions
Section titled “Windows editions”| Windows Edition | Version |
|---|---|
| Windows Server | 2019 |
| Windows Server | 2022 |
CLI support
Section titled “CLI support”CLI operating system support
Section titled “CLI operating system support”You can use the Aembit CLI with the following operating system versions:
Linux distributions
Section titled “Linux distributions”| Linux Distribution | Version |
|---|---|
| Ubuntu | 22.04 |
| Red Hat | 9.3 |
Windows editions
Section titled “Windows editions”| Windows Edition | Version |
|---|---|
| Windows | 10 |
| Windows Server | 2019 |
| Windows Server | 2022 |
CLI CI/CD runner support
Section titled “CLI CI/CD runner support”The Aembit CLI is compatible with the following CI/CD runners:
GitHub-hosted runners
Section titled “GitHub-hosted runners”For more information, see GitHub runners documentation.
| GitHub Runner |
|---|
ubuntu-latest |
windows-latest |
GitLab-hosted runners
Section titled “GitLab-hosted runners”For more information, see GitLab runners documentation.
| GitLab Runner |
|---|
saas-linux-small-amd64 |
saas-linux-medium-amd64 |
saas-linux-large-amd64 |
saas-linux-small-arm64 |
saas-linux-medium-arm64 |
saas-linux-large-arm64 |
saas-windows-medium-amd64 |
CLI deployment model support
Section titled “CLI deployment model support”The Aembit CLI supports the following deployment models:
- GitHub Actions
- GitLab Jobs
- Jenkins Pipelines
- Environments that provide OIDC tokens. See OIDC ID Token Trust Provider for more info.
CLI Client Workload Identifiers
Section titled “CLI Client Workload Identifiers”The Aembit CLI supports the following Client Workload Identifiers:
CLI Trust Providers
Section titled “CLI Trust Providers”The Aembit CLI supports the following Trust Providers:
- AWS Metadata Service Trust Provider
- AWS Role Trust Provider
- GitHub Trust Provider
- GitLab Trust Provider
- Kubernetes Service Account Trust Provider
- OIDC ID Token Trust Provider
CLI Access Conditions
Section titled “CLI Access Conditions”The Aembit CLI supports the following Access Conditions:
SDK support
Section titled “SDK support”Edge SDK Trust Providers
Section titled “Edge SDK Trust Providers”The Edge SDK is available for TypeScript and Python, and the available Trust Providers differ between the two languages. This table lists every Trust Provider type the Edge API accepts and shows SDK support for each by language.
* The Azure Instance Metadata Service provider is available in the TypeScript SDK, but Edge API support for that flow is still in progress.