Skip to content

LinearB On-Prem Agent v5.0.3

Released 2026-10-01.

This release removes several bundled components that a default install never used — the Fluent Bit log collector, the Redis Sentinel and exporter images, and the MinIO strategy-migrator Job — and replaces the collector with documented extension points for running your own. It also lets the agent run on clusters that do not grant cluster-scoped permissions, adds an opt-in check of the LinearB endpoint's TLS certificate, and stops the scheduler from logging job payloads that can contain integration credentials. If any of the removed settings are still in your values file, the upgrade now stops with an error naming the setting, so please read Action required first.

Action required

  • Remove settings for components that no longer exist before upgrading. The chart now fails the install, with a message naming the key and its replacement, when any of these is still set:

    Setting Fails when
    global.installFluentBit set to true
    redis.sentinel.enabled, redis.metrics.enabled set to true
    infra.minio.strategyMigrator present at all, including enabled: false
    rabbitmq.volumePermissions.enabled, redis.volumePermissions.enabled, redis.sysctl.enabled set to true

    Items 5–8 of the v5 upgrade guide show exactly what to delete. A leftover fluent-bit: block on its own only produces a warning. - If you enabled the bundled Fluent Bit collector, the agent no longer collects or retains its own logs. Every service already logs structured JSON to stdout, so any log collector your cluster runs picks them up without agent-side configuration. The new Log collection guide has complete Fluent Bit and OpenTelemetry Collector examples. Logs the old collector wrote are left behind under logs/ on the minio-pvc volume, which is the volume MinIO stores its data on; delete them once you no longer need them. - If you sync with Argo CD using server-side apply and relied on infra.minio.strategyMigrator to switch MinIO to the Recreate strategy, that step is now a one-time manual check-and-delete before you sync. See MinIO update strategy migration. Plain helm upgrade is not affected.

New features

  • Run without cluster-scoped PriorityClasses. On clusters where the installer cannot create cluster-level objects, set global.priorityClasses.enabled: false, together with the four keys that clear the priority class from the bundled MinIO, RabbitMQ and Redis charts (the chart refuses to render if any of them is left set). local-values.yaml.template has both blocks, commented out. The prerequisites guide now lists every cluster-scoped resource an install creates and what each one depends on.
  • Optional verification of the LinearB endpoint's TLS certificate. Set global.VERIFY_UPSTREAM_TLS: true to make the forward proxy reject an endpoint whose certificate is not trusted, instead of relaying its response. This turns a misrouted corporate proxy into a clear 502 with a certificate error in the forward-proxy log, rather than a confusing application error. It is off by default, so upgrading changes nothing. A private corporate CA must first be added through CUSTOM_ROOT_CERTIFICATES. See Verifying the LinearB endpoint's certificate.
  • Chart extension points for your own tooling. Every agent pod now carries the label app.kubernetes.io/part-of: on-prem-agent, a stable selector for log collectors that does not change with the release name. global.commonLabels adds your own labels to every pod, and a top-level extraObjects list deploys extra manifests (a collector, a NetworkPolicy) as part of the same release.

Bug fixes

  • A missing PriorityClass no longer stops collection silently. Kubernetes checks the class only when a pod is admitted, so if the agent's classes were absent, or deleted after install, every new job pod was refused while the jobs themselves looked healthy. The scheduler now checks that a class exists before using it, and starts the job without a priority class (logging a warning) when it does not. The diagnostics guide lists the is forbidden: no PriorityClass with name error.
  • The corporate-proxy guide no longer states that TLS is always tunnelled through to LinearB. That is true for connect mode, but not for transparent mode against a proxy that terminates TLS.
  • The bundled ingress-nginx controller's image tag now matches the version actually deployed (v1.12.4). The image was already pulled by digest, so running clusters are unaffected.
  • The integrations guide now gives the Bitbucket Server webhook URL: <webhook endpoint>/hooks/bitbucket_server?integration_id=<integration_id>.

Improvements

  • AI tool integrations (Claude, Claude Admin, Codex and Cursor) now pace their requests and honour the provider's Retry-After header when rate limited, instead of failing the collection.
  • Codex usage cost is now derived from token counts, with per-model pricing for the fast tier.
  • GitLab reads are retried on transient server errors instead of aborting the collection.
  • Pull request collection saves its progress and continues in a follow-up job, instead of having to finish in a single run.
  • The time a GitHub pull request became ready for review is now taken from GitHub directly.
  • Azure Boards integrations can authenticate with OAuth2.
  • GitHub Issues collection can treat repositories as projects.
  • SonarQube Cloud pull request comments in the current layout are parsed correctly, with each measure read from its own badge.
  • Shallow clones can widen their history window per repository when one is too narrow.
  • The prerequisites guide states that the third-party images (ingress-nginx, MinIO, RabbitMQ, Redis, socat, Datadog) are served from the same registry as the agent images, under image-dependencies/.

Security and dependency updates

  • Improved sanitization for scheduler and agent poller logs.
  • pip is removed from every Python runtime image. Dependencies are installed at build time and nothing runs pip at runtime. This clears the setuptools findings that scanners reported from pip's bundled metadata (CVE-2025-47273, CVE-2026-23949, CVE-2026-59890); none of the affected code was present in the images.
  • The forward proxy is now built on a hardened NGINX 1.30.5 base image, with its Alpine packages upgraded at build time.
  • PyJWT updated to 2.14.0, urllib3 to 2.8.0 or later, Flask to 3.1.3 and click to 8.5.0.
  • rapidfuzz in agent-api updated to 3.0.0. The previous version could not build its compiled extension on Python 3.11 and had been running as pure Python.
  • Datadog agent and cluster agent updated to 7.83.3 (image tags only; the Datadog chart version is unchanged, so no values change is required).
  • Redis updated to 8.2.10.

Fewer images to mirror

If you mirror the agent's images into your own registry, nine third-party images are no longer used and can be dropped from your mirror: fluent-bit, configmap-reload, busybox, redis-sentinel, redis-exporter, kube-state-metrics, kubectl, os-shell and sysctl. Kube-state metrics are served by the Datadog Cluster Agent.

Component versions

Component Version
Linta v4.7.20.1
Sensors v4.6.1.1
PM Connectors v2.7.2.1
gitStream 0.3.1517
Redis 8.2.10
Datadog Agent 7.83.3
Datadog Cluster Agent 7.83.3