# Support matrix

> Supported features for each deployment type

The matrices on this page detail the compatible deployment types for [application protocols](#application-protocols). The matrices also cover Aembit features such as [Client Workload Identifiers](#client-workload-identifiers), [Agent Controller Trust Providers](#agent-controller-trust-providers), [Agent Proxy Trust Providers](#agent-proxy-trust-providers), and [Conditional Access](#conditional-access). The matrices list the [operating systems for VMs](#supported-operating-systems-for-vms) that Aembit supports. The [CLI Support](#cli-support) section includes the operating systems and Access Policy features that the Aembit CLI supports. The [SDK support](#sdk-support) section covers Trust Providers by language.

Aembit Edge supports multiple types of deployments:

* Kubernetes

* AWS Elastic Container Service (ECS) Fargate

* Virtual Machines (Linux, Windows, Docker-compose)

* AWS Lambda (function, container)

* Virtual Appliance (VMware)

> **For Linux Virtual Machines**
>
> Aembit supports Client Workloads running directly on the VM or within Docker-compose on the VM. Aembit collects different data from applications running in Docker-compose compared to those running directly on the VM.

## Key

| Icon | Meaning        |
| ---- | -------------- |
| ✅    | Supported      |
| ❌    | Not supported  |
| ⚪️   | Not applicable |

## Application protocols

| Application Protocols           | Kubernetes | AWS EKS Fargate | AWS ECS Fargate | Virtual Machine (Linux) | Virtual Machine (Windows) | Virtual Appliance | Docker-compose on VMs | AWS Lambda |
| ------------------------------- | ---------- | --------------- | --------------- | ----------------------- | ------------------------- | ----------------- | --------------------- | ---------- |
| HTTP 1.1                        | ✅          | ✅               | ✅               | ✅                       | ✅                         | ✅                 | ✅                     | ✅          |
| Postgres 3.0                    | ✅          | ❌               | ❌               | ✅                       | ❌                         | ❌                 | ✅                     | ❌          |
| MySQL 10                        | ✅          | ❌               | ❌               | ✅                       | ❌                         | ❌                 | ✅                     | ❌          |
| Redis RESP2                     | ✅          | ❌               | ❌               | ✅                       | ❌                         | ❌                 | ✅                     | ❌          |
| Redis RESP3                     | ✅          | ❌               | ❌               | ✅                       | ❌                         | ❌                 | ✅                     | ❌          |
| Snowflake SDK (HTTP-based)      | ✅          | ✅               | ✅               | ✅                       | ✅                         | ✅                 | ✅                     | ✅          |
| Snowflake REST API (HTTP-based) | ✅          | ✅               | ✅               | ✅                       | ✅                         | ✅                 | ✅                     | ✅          |
| Amazon Redshift 3.0             | ✅          | ❌               | ❌               | ✅                       | ❌                         | ❌                 | ✅                     | ❌          |
| Oracle Database                 | ✅\*        | ❌               | ❌               | ✅                       | ❌                         | ❌                 | ✅                     | ❌          |

> \* *Oracle Database on Kubernetes requires [transparent steering](/user-guide/deploy-install/advanced-options/agent-proxy/selective-transparent-steering/) configured for the Oracle database host.*

## Client Workload Identifiers

| Client Workload Identifiers | Kubernetes | AWS EKS Fargate | AWS ECS Fargate | Virtual Machine (Linux) | Virtual Machine (Windows) | Virtual Appliance | Docker-compose on VMs | AWS Lambda |
| --------------------------- | ---------- | --------------- | --------------- | ----------------------- | ------------------------- | ----------------- | --------------------- | ---------- |
| Aembit Client ID            | ✅          | ✅               | ✅               | ✅                       | ✅                         | ❌                 | ✅                     | ✅          |
| AWS Account ID              | ❌          | ❌               | ❌               | ✅\*                     | ✅\*                       | ❌                 | ✅\*                   | ❌          |
| AWS EC2 Instance ID         | ❌          | ⚪️              | ⚪️              | ✅\*                     | ✅\*                       | ❌                 | ✅\*                   | ❌          |
| AWS ECS Task Family         | ⚪️         | ⚪️              | ✅               | ⚪️                      | ⚪️                        | ⚪️                | ⚪️                    | ⚪️         |
| AWS Region                  | ❌          | ❌               | ❌               | ✅\*                     | ✅\*                       | ❌                 | ✅\*                   | ❌          |
| AWS Subscription ID         | ❌          | ❌               | ❌               | ✅\*                     | ✅\*                       | ❌                 | ✅\*                   | ❌          |
| AWS VM ID                   | ❌          | ❌               | ❌               | ✅\*                     | ✅\*                       | ❌                 | ✅\*                   | ⚪️         |
| Hostname                    | ❌          | ❌               | ❌               | ✅                       | ✅                         | ❌                 | ✅                     | ❌          |
| Kubernetes Pod name         | ✅          | ✅               | ⚪️              | ⚪️                      | ⚪️                        | ⚪️                | ⚪️                    | ⚪️         |
| Kubernetes Pod name prefix  | ✅          | ✅               | ⚪️              | ⚪️                      | ⚪️                        | ⚪️                | ⚪️                    | ⚪️         |
| Process Command Line \*\*   | ❌          | ❌               | ❌               | ✅                       | ❌                         | ❌                 | ❌                     | ❌          |
| Process Name \*\*           | ❌          | ❌               | ❌               | ✅                       | ❌                         | ❌                 | ❌                     | ❌          |
| Process Path \*\*           | ❌          | ❌               | ❌               | ✅                       | ❌                         | ❌                 | ❌                     | ❌          |
| Process User Name \*\*      | ❌          | ❌               | ❌               | ✅                       | ❌                         | ❌                 | ❌                     | ❌          |
| Source IP                   | ✅          | ✅               | ✅               | ✅                       | ✅                         | ✅                 | ✅                     | ❌          |
| AWS Lambda ARN              | ⚪️         | ⚪️              | ⚪️              | ⚪️                      | ⚪️                        | ⚪️                | ⚪️                    | ✅          |

> \* *These Client Workload identifiers are available for their respective cloud platforms only*.\
> \*\* *Before using process-based identifiers, you must enable them in Agent Proxy first.* *See [Process Command Line](/user-guide/access-policies/client-workloads/identification/process-command-line), [Process Name](/user-guide/access-policies/client-workloads/identification/process-name), [Process Path](/user-guide/access-policies/client-workloads/identification/process-path), and [Process User Name](/user-guide/access-policies/client-workloads/identification/process-user-name) for details*

## Agent Controller Trust Providers

| Trust Providers                 | Kubernetes | AWS EKS Fargate | AWS ECS Fargate | Virtual Machine | Virtual Appliance | Docker-compose on VMs | AWS Lambda |
| ------------------------------- | ---------- | --------------- | --------------- | --------------- | ----------------- | --------------------- | ---------- |
| AWS Role                        | ❌          | ❌               | ✅               | ❌               | ❌                 | ⚪️                    | ⚪️         |
| AWS Metadata Service            | ✅\*        | ❌               | ❌               | ✅\*             | ❌                 | ⚪️                    | ⚪️         |
| Azure Instance Metadata Service | ✅\*        | ⚪️              | ⚪️              | ✅\*             | ❌                 | ⚪️                    | ⚪️         |
| GCP Identity Token              | ✅\*        | ⚪️              | ⚪️              | ✅\*             | ❌                 | ⚪️                    | ⚪️         |
| Kubernetes Service Account      | ✅          | ✅               | ⚪️              | ⚪️              | ⚪️                | ⚪️                    | ⚪️         |
| Kerberos                        | ⚪️         | ⚪️              | ⚪️              | ⚪️              | ⚪️                | ⚪️                    | ⚪️         |

> \* *Aembit tailors the Trust Providers available in Kubernetes and VM environments specifically for their respective cloud platforms*.

## Agent Proxy Trust Providers

| Trust Providers                 | Kubernetes | AWS EKS Fargate | AWS ECS Fargate | Virtual Machine (Linux) | Virtual Machine (Windows) | Virtual Appliance | Docker-compose on VMs | AWS Lambda |
| ------------------------------- | ---------- | --------------- | --------------- | ----------------------- | ------------------------- | ----------------- | --------------------- | ---------- |
| AWS Role                        | ❌          | ❌               | ✅               | ✅\*\*                   | ✅\*\*                     | ❌                 | ❌                     | ✅          |
| AWS Metadata Service            | ✅\*        | ❌               | ❌               | ✅\*                     | ✅\*                       | ❌                 | ✅\*                   | ❌          |
| Azure Instance Metadata Service | ✅\*        | ⚪️              | ⚪️              | ✅\*                     | ✅\*                       | ❌                 | ✅\*                   | ⚪️         |
| GCP Identity Token              | ⚪️         | ⚪️              | ⚪️              | ❌                       | ❌                         | ❌                 | ❌                     | ⚪️         |
| Kubernetes Service Account      | ✅          | ✅               | ⚪️              | ⚪️                      | ⚪️                        | ⚪️                | ⚪️                    | ⚪️         |
| Kerberos                        | ❌          | ❌               | ❌               | ✅                       | ✅                         | ❌                 | ✅                     | ⚪️         |

> \* *Aembit tailors the Trust Providers available in Kubernetes and VM environments specifically for their respective cloud platforms*.\
> \*\* *The AWS Role Trust Provider supports only EC2 instances with an attached IAM role*.

## Conditional Access

| Access Conditions | Kubernetes | AWS EKS Fargate | AWS ECS Fargate | Virtual Machine (Linux) | Virtual Machine (Windows) | Virtual Appliance | Docker-compose on VMs | AWS Lambda |
| ----------------- | ---------- | --------------- | --------------- | ----------------------- | ------------------------- | ----------------- | --------------------- | ---------- |
| CrowdStrike       | ❌          | ❌               | ❌               | ✅                       | ✅                         | ❌                 | ✅                     | ❌          |
| Wiz               | ✅          | ✅               | ❌               | ❌                       | ❌                         | ❌                 | ❌                     | ✅          |
| Time              | ✅          | ✅               | ✅               | ✅                       | ✅                         | ✅                 | ✅                     | ✅          |
| GeoIP             | ✅          | ✅               | ✅               | ✅                       | ✅                         | ✅                 | ✅                     | ✅          |

## Supported operating systems for VMs

The following sections contain the operating system versions that Aembit Agent Proxy and Agent Controller support on VMs

### Linux distributions

| Linux Distribution | Version |
| ------------------ | ------- |
| Ubuntu             | 20.04   |
| Ubuntu             | 22.04   |
| Ubuntu             | 24.04   |
| Red Hat            | 8.6     |
| Red Hat            | 8.9     |
| Red Hat            | 9.3     |

### Windows editions

| Windows Edition | Version |
| --------------- | ------- |
| Windows Server  | 2019    |
| Windows Server  | 2022    |

## CLI support

### CLI operating system support

You can use the Aembit CLI with the following operating system versions:

#### Linux distributions

| Linux Distribution | Version |
| ------------------ | ------- |
| Ubuntu             | 22.04   |
| Red Hat            | 9.3     |

#### Windows editions

| Windows Edition | Version |
| --------------- | ------- |
| Windows         | 10      |
| Windows Server  | 2019    |
| Windows Server  | 2022    |

### CLI CI/CD runner support

The Aembit CLI is compatible with the following CI/CD runners:

#### GitHub-hosted runners

For more information, see [GitHub runners documentation](https://docs.github.com/en/actions/using-github-hosted-runners/about-github-hosted-runners).

| GitHub Runner    |
| ---------------- |
| `ubuntu-latest`  |
| `windows-latest` |

#### GitLab-hosted runners

For more information, see [GitLab runners documentation](https://docs.gitlab.com/runner/).

| GitLab Runner               |
| --------------------------- |
| `saas-linux-small-amd64`    |
| `saas-linux-medium-amd64`   |
| `saas-linux-large-amd64`    |
| `saas-linux-small-arm64`    |
| `saas-linux-medium-arm64`   |
| `saas-linux-large-arm64`    |
| `saas-windows-medium-amd64` |

### CLI deployment model support

The Aembit CLI supports the following deployment models:

* [GitHub Actions](/user-guide/deploy-install/ci-cd/github/github-edge-cli)
* [GitLab Jobs](/user-guide/deploy-install/ci-cd/gitlab/gitlab-jobs-cli)
* [Jenkins Pipelines](/user-guide/deploy-install/ci-cd/jenkins-pipelines)
* Environments that provide OIDC tokens. See [OIDC ID Token Trust Provider](/user-guide/access-policies/trust-providers/oidc-id-token-trust-provider) for more info.

### CLI Client Workload Identifiers

The Aembit CLI supports the following Client Workload Identifiers:

* [Aembit Client ID](/user-guide/access-policies/client-workloads/identification/aembit-client-id)

### CLI Trust Providers

The Aembit CLI supports the following Trust Providers:

* [AWS Metadata Service Trust Provider](/user-guide/access-policies/trust-providers/aws-metadata-service-trust-provider)
* [AWS Role Trust Provider](/user-guide/access-policies/trust-providers/aws-role-trust-provider)
* [GitHub Trust Provider](/user-guide/access-policies/trust-providers/github-trust-provider)
* [GitLab Trust Provider](/user-guide/access-policies/trust-providers/gitlab-trust-provider)
* [Kubernetes Service Account Trust Provider](/user-guide/access-policies/trust-providers/kubernetes-service-account-trust-provider)
* [OIDC ID Token Trust Provider](/user-guide/access-policies/trust-providers/oidc-id-token-trust-provider)

### CLI Access Conditions

The Aembit CLI supports the following Access Conditions:

* [GeoIP](/user-guide/access-policies/access-conditions/aembit-geoip)
* [Time](/user-guide/access-policies/access-conditions/aembit-time-condition)
* [CrowdStrike](/user-guide/access-policies/access-conditions/crowdstrike)

## SDK support

### Edge SDK Trust Providers

The [Edge SDK](/dev-guide/sdk/edge/) is available for TypeScript and Python, and the available Trust Providers differ between the two languages. This table lists every Trust Provider type the Edge API accepts and shows SDK support for each by language.

| Trust Providers                                                                                                                     | TypeScript | Python |
| ----------------------------------------------------------------------------------------------------------------------------------- | ---------- | ------ |
| [AWS Metadata Service Trust Provider](/user-guide/access-policies/trust-providers/aws-metadata-service-trust-provider)              | ✅          | ❌      |
| [AWS Role Trust Provider](/user-guide/access-policies/trust-providers/aws-role-trust-provider)                                      | ✅          | ✅      |
| [Azure Instance Metadata Service Trust Provider](/user-guide/access-policies/trust-providers/azure-metadata-service-trust-provider) | ✅\*        | ❌      |
| [GCP Identity Token Trust Provider](/user-guide/access-policies/trust-providers/gcp-identity-token-trust-provider)                  | ✅          | ❌      |
| [GitHub Trust Provider](/user-guide/access-policies/trust-providers/github-trust-provider)                                          | ✅          | ✅      |
| [GitLab Trust Provider](/user-guide/access-policies/trust-providers/gitlab-trust-provider)                                          | ❌          | ✅      |
| [OIDC ID Token Trust Provider](/user-guide/access-policies/trust-providers/oidc-id-token-trust-provider)                            | ✅          | ❌      |
| [Terraform Cloud Trust Provider](/user-guide/access-policies/trust-providers/terraform-cloud-identity-token-trust-provider)         | ❌          | ✅      |
| [Kubernetes Service Account Trust Provider](/user-guide/access-policies/trust-providers/kubernetes-service-account-trust-provider)  | ❌          | ❌      |

> \* *The Azure Instance Metadata Service provider is available in the TypeScript SDK, but Edge API support for that flow is still in progress.*