Download and install the sidecar
Get the AAC Sidecar container from Docker Hub. The repository page includes the image tags, pull instructions and the public operating guide. Use a released version, then choose how to run it beside your agent.
docker pull docker.io/cascadeauth/aac-sidecar:v0.4.4
docker run --rm docker.io/cascadeauth/aac-sidecar:v0.4.4 -version
The version command confirms the downloaded executable; it does not start a configured sidecar. Next, follow one of these paths:
- First AAC example: start the AAC journey. Docker Compose runs both agents, their sidecars and trust anchor publishers.
- Your existing agent environment: prepare the configuration and place the sidecar beside your workload. Use the CLI guide to prepare tenant and agent material.
- A host process instead of a container: install the standalone binary below.
Standalone binary for Linux or macOS
The same Docker Hub repository distributes a bundle containing binaries for
linux_amd64, linux_arm64, darwin_amd64 and darwin_arm64, with the
configuration template, license and operating documentation.
Install ORAS to download the bundle:
mkdir aac-sidecar-v0.4.4
cd aac-sidecar-v0.4.4
oras pull docker.io/cascadeauth/aac-sidecar:v0.4.4-bundle
Choose the archive matching your operating system and CPU. On Ubuntu, if
uname -m returns aarch64, select linux_arm64; Apple Silicon uses
darwin_arm64. If you need to check signatures or checksums before extraction,
use the release verification procedure.
version=v0.4.4
platform=linux_amd64 # choose the matching platform listed above
install_root="${HOME}/.local/lib/aac-sidecar/releases/${version}"
mkdir -p "${install_root}" "${HOME}/.local/bin"
tar -xzf "aac-sidecar_${version}_${platform}.tar.gz" -C "${install_root}"
ln -sfn "${install_root}/aac-sidecar" "${HOME}/.local/bin/aac-sidecar"
"${HOME}/.local/bin/aac-sidecar" -version
Run the executable with the configuration prepared for your agent:
"${HOME}/.local/bin/aac-sidecar" -config /absolute/path/to/sidecar-config.yaml
The sidecar and agent must share their loopback network environment, and the
configured credentials, trust material and state paths must be available.
Configure for your environment and
operate the sidecar explain these requirements and
readiness checks. A managed service runs as a dedicated non-root account;
a developer installation can stay under your home directory.
An operator-managed installation under /opt/aac/sidecar/releases/<version>
may be root-owned, but its service process must still run as the non-root
account. Keep developer installations in a user-writable directory.
Other AAC components
The installation hub connects the rest of the stack: AAC CLI on PyPI, trust anchor publisher on PyPI or GHCR, and aac-invoke-auth on PyPI. Each package page includes its installation and usage documentation.
For an additional audit, see artifact signatures, checksums and provenance.