Operator administration uses a root-only launcher with isolated startup configuration, a fixed local endpoint and authentication from a protected token file. Install the matching Guard binary and launcher together; sudo guard-operator requires Guard 0.8.8 or newer and preserves relative file arguments and command input.
Linux release archives include a Unix installer with read-only checks and an explicit mode for updating the binary and launcher while preserving compatible existing service units, drop-ins, identities, configuration and state. The installer leaves service activation to the operator; the deployment guide covers stopped snapshots and rollback that retains displaced databases and sidecars.