Instead of storing RAD Security Cluster API keys as Kubernetes secrets, they can be stored and retrieved from AWS Secrets Manager. Pass the Secret ID intoDocumentation Index
Fetch the complete documentation index at: https://docs.rad.security/llms.txt
Use this file to discover all available pages before exploring further.
rad.awsSecretId in the Helm Chart.
Secret Format
The Secret Manager secret must follow this JSON structure:Authentication Setup
Plugins need AWS authentication configured. Any supported authentication method can be used.IRSA (IAM Roles for Service Accounts)
IRSA requires a Role with proper OIDC permissions. Set the service account annotations in yourvalues.yaml:
EKS Pod Identity
EKS Pod Identity requires less configuration than IRSA. The following service accounts in the rad namespace need access:rad-sbomrad-guardagent-rad-k9rad-node-agentrad-syncrad-watch