Forcepoint Data Security Posture Management Online Help
  1. Home
  2. Deployment guide

  3. Installation

  4. Understand installation requirements

    Forcepoint products use Kubernetes under the hood, and we have very specific hardware requirements. It is crucial to meet the minimum resource requirements defined for containers, as failing to do so can lead to problems:

  5. K3S installation

    We use Kubernetes, an open-source container orchestration system to manage our applications.

  6. K3s support matrix

  • Getting started

    Forcepoint Data Security Posture Management (Forcepoint DSPM) allows organizations to locate and classify sensitive data across data stores, assess the risks associated with this data’s exposure based on its sensitivity, and implement access controls to the data.

  • Deployment guide

    • Sizing

      Server sizing indicates the utilization of Forcepoint DSPM.

    • Installation

      • Understand installation requirements

        Forcepoint products use Kubernetes under the hood, and we have very specific hardware requirements. It is crucial to meet the minimum resource requirements defined for containers, as failing to do so can lead to problems:

        • K3S installation

          We use Kubernetes, an open-source container orchestration system to manage our applications.

          • K3s support matrix

          • Network settings

            Your network should be configured to allow the following public URLs to be accessible over port 443 (HTTPS) and HTTPS traffic is bypassed (NOT intercepted):

        • Configuring a HA K3s cluster

          Our K3s HA setup consists of 4 homogeneous nodes (3 master nodes + 1 worker node) and can withstand a single-node failure with a very short failover disruption (between 3 to 6 minutes).

        • Configuring Rancher and Fleet agent to run behind an HTTP proxy

        • Install Forcepoint DSPM using Helm without Rancher

        • Install Forcepoint DSPM using Rancher

        • Air Gap Installation

        • Uploads to Rancher

          Rancher manages clusters through its control plane. Managed clusters send data to Rancher's central management servers. This includes "always-on" data, exchanged with Rancher whenever the cluster has Internet access, and "on-demand" data, which should be explicitly requested by Forcepoint Support via the Rancher UI.

      • Upgrade K3s

        This document outlines the steps to install and update K3s servers and how to deploy and backup FDC services.

      • Troubleshooting

    • Estimate hardware capacity needs

      A VM or server with the following specifications:

  • Administration guide

  • Authentication

  • Implementation

  • Integrations

  • Scan with Forcepoint DSPM

  • Glossary

  • FAQ

  • FDC- All Documents

K3s support matrix

Note: Do not use Docker as the container runtime, instead use containerd.

Note that

For more information, see the EN-2.6.5SupportMatrix-300422-0116-26 section.

Copyright © 2025 Forcepoint LLC