
# Secure agent

> Part of Build and extend

The Atlan Secure Agent is a lightweight, Kubernetes-based application that enables secure metadata extraction. It connects internal systems with Atlan SaaS while keeping sensitive data protected and doesn’t require inbound connectivity. Running within an organization’s controlled environment, the Secure Agent ensures compliance with security policies and automates metadata processing.

- [Install on Virtual Machine (K3s)](https://docs.atlan.com/llms/platform/secure-agent/install-secure-agent-on-virtual-machine-k3s/llms.txt): This page provides instructions for installing the Secure Agent on a virtual machine (VM) by deploying K3s in a rootless execution mode%E2%80%8B).
- [Install on AWS EKS](https://docs.atlan.com/llms/platform/secure-agent/install-secure-agent-on-aws-eks/llms.txt): This guide provides step-by-step instructions to install the Secure Agent on an Amazon Elastic Kubernetes Service (AWS EKS) cluster.
- [Configure workflow execution](https://docs.atlan.com/llms/platform/secure-agent/configure-secure-agent-for-workflow-execution/llms.txt): Learn about configure workflow execution.
- [Migrate to Self-Deployed Runtime](https://docs.atlan.com/llms/platform/secure-agent/understand-migrating-to-sdr/llms.txt): Overview of migrating from Atlan Secure Agent to Self-Deployed Runtime before the June 2026 deprecation deadline.
- [Migrate to Self-deployed runtime](https://docs.atlan.com/llms/platform/secure-agent/migrate-to-sdr/llms.txt): Step-by-step instructions to deploy Self-Deployed Runtime and migrate workflows from Secure Agent, through to decommission.
- [Secure Agent vs self-deployed runtime](https://docs.atlan.com/llms/platform/secure-agent/secure-agent-vs-sdr/llms.txt): Detailed comparison of Secure Agent and Self-Deployed Runtime architecture, security, deployment, and configuration.
- [Secure Agent to SDR configuration mapping](https://docs.atlan.com/llms/platform/secure-agent/secure-agent-config-mapping/llms.txt): Mapping table to translate Secure Agent configuration settings to their SDR equivalents, covering K3s and EKS source deployments.
- [Deployment architecture](https://docs.atlan.com/llms/platform/secure-agent/deployment-architecture/llms.txt): The Atlan Secure Agent is a Kubernetes-based application that runs within a customer's environment. It acts as a gateway between the single-tenant Atlan SaaS and external systems like Snowflake, Tableau, and other data sources. This document explains the Secure Agent's deployment architecture, key components, communication flows, and security considerations.
- [Security](https://docs.atlan.com/llms/platform/secure-agent/security/llms.txt): The Secure Agent is designed with multiple security controls to protect metadata, credentials, and communication between systems. This document outlines its security mechanisms across authentication, encryption, container security, network security, and logging and monitoring.
