LinearB On-Prem Agent v5.0.3
Released 2026-10-01.
This release removes several bundled components that a default install never used — the Fluent Bit log collector, the Redis Sentinel and exporter images, and the MinIO strategy-migrator Job — and replaces the collector with documented extension points for running your own. It also lets the agent run on clusters that do not grant cluster-scoped permissions, adds an opt-in check of the LinearB endpoint's TLS certificate, and stops the scheduler from logging job payloads that can contain integration credentials. If any of the removed settings are still in your values file, the upgrade now stops with an error naming the setting, so please read Action required first.
Action required
-
Remove settings for components that no longer exist before upgrading. The chart now fails the install, with a message naming the key and its replacement, when any of these is still set:
Setting Fails when global.installFluentBitset to trueredis.sentinel.enabled,redis.metrics.enabledset to trueinfra.minio.strategyMigratorpresent at all, including enabled: falserabbitmq.volumePermissions.enabled,redis.volumePermissions.enabled,redis.sysctl.enabledset to trueItems 5–8 of the v5 upgrade guide show exactly what to delete. A leftover
fluent-bit:block on its own only produces a warning. - If you enabled the bundled Fluent Bit collector, the agent no longer collects or retains its own logs. Every service already logs structured JSON to stdout, so any log collector your cluster runs picks them up without agent-side configuration. The new Log collection guide has complete Fluent Bit and OpenTelemetry Collector examples. Logs the old collector wrote are left behind underlogs/on theminio-pvcvolume, which is the volume MinIO stores its data on; delete them once you no longer need them. - If you sync with Argo CD using server-side apply and relied oninfra.minio.strategyMigratorto switch MinIO to theRecreatestrategy, that step is now a one-time manual check-and-delete before you sync. See MinIO update strategy migration. Plainhelm upgradeis not affected.
New features
- Run without cluster-scoped PriorityClasses. On clusters where the installer cannot create cluster-level objects, set
global.priorityClasses.enabled: false, together with the four keys that clear the priority class from the bundled MinIO, RabbitMQ and Redis charts (the chart refuses to render if any of them is left set).local-values.yaml.templatehas both blocks, commented out. The prerequisites guide now lists every cluster-scoped resource an install creates and what each one depends on. - Optional verification of the LinearB endpoint's TLS certificate. Set
global.VERIFY_UPSTREAM_TLS: trueto make the forward proxy reject an endpoint whose certificate is not trusted, instead of relaying its response. This turns a misrouted corporate proxy into a clear502with a certificate error in the forward-proxy log, rather than a confusing application error. It is off by default, so upgrading changes nothing. A private corporate CA must first be added throughCUSTOM_ROOT_CERTIFICATES. See Verifying the LinearB endpoint's certificate. - Chart extension points for your own tooling. Every agent pod now carries the label
app.kubernetes.io/part-of: on-prem-agent, a stable selector for log collectors that does not change with the release name.global.commonLabelsadds your own labels to every pod, and a top-levelextraObjectslist deploys extra manifests (a collector, a NetworkPolicy) as part of the same release.
Bug fixes
- A missing PriorityClass no longer stops collection silently. Kubernetes checks the class only when a pod is admitted, so if the agent's classes were absent, or deleted after install, every new job pod was refused while the jobs themselves looked healthy. The scheduler now checks that a class exists before using it, and starts the job without a priority class (logging a warning) when it does not. The diagnostics guide lists the
is forbidden: no PriorityClass with nameerror. - The corporate-proxy guide no longer states that TLS is always tunnelled through to LinearB. That is true for
connectmode, but not fortransparentmode against a proxy that terminates TLS. - The bundled ingress-nginx controller's image tag now matches the version actually deployed (
v1.12.4). The image was already pulled by digest, so running clusters are unaffected. - The integrations guide now gives the Bitbucket Server webhook URL:
<webhook endpoint>/hooks/bitbucket_server?integration_id=<integration_id>.
Improvements
- AI tool integrations (Claude, Claude Admin, Codex and Cursor) now pace their requests and honour the provider's
Retry-Afterheader when rate limited, instead of failing the collection. - Codex usage cost is now derived from token counts, with per-model pricing for the fast tier.
- GitLab reads are retried on transient server errors instead of aborting the collection.
- Pull request collection saves its progress and continues in a follow-up job, instead of having to finish in a single run.
- The time a GitHub pull request became ready for review is now taken from GitHub directly.
- Azure Boards integrations can authenticate with OAuth2.
- GitHub Issues collection can treat repositories as projects.
- SonarQube Cloud pull request comments in the current layout are parsed correctly, with each measure read from its own badge.
- Shallow clones can widen their history window per repository when one is too narrow.
- The prerequisites guide states that the third-party images (ingress-nginx, MinIO, RabbitMQ, Redis, socat, Datadog) are served from the same registry as the agent images, under
image-dependencies/.
Security and dependency updates
- Improved sanitization for scheduler and agent poller logs.
pipis removed from every Python runtime image. Dependencies are installed at build time and nothing runs pip at runtime. This clears the setuptools findings that scanners reported from pip's bundled metadata (CVE-2025-47273, CVE-2026-23949, CVE-2026-59890); none of the affected code was present in the images.- The forward proxy is now built on a hardened NGINX 1.30.5 base image, with its Alpine packages upgraded at build time.
- PyJWT updated to 2.14.0, urllib3 to 2.8.0 or later, Flask to 3.1.3 and click to 8.5.0.
- rapidfuzz in
agent-apiupdated to 3.0.0. The previous version could not build its compiled extension on Python 3.11 and had been running as pure Python. - Datadog agent and cluster agent updated to 7.83.3 (image tags only; the Datadog chart version is unchanged, so no values change is required).
- Redis updated to 8.2.10.
Fewer images to mirror
If you mirror the agent's images into your own registry, nine third-party images are no longer used and can be dropped from your mirror: fluent-bit, configmap-reload, busybox, redis-sentinel, redis-exporter, kube-state-metrics, kubectl, os-shell and sysctl. Kube-state metrics are served by the Datadog Cluster Agent.
Component versions
| Component | Version |
|---|---|
| Linta | v4.7.20.1 |
| Sensors | v4.6.1.1 |
| PM Connectors | v2.7.2.1 |
| gitStream | 0.3.1517 |
| Redis | 8.2.10 |
| Datadog Agent | 7.83.3 |
| Datadog Cluster Agent | 7.83.3 |