Agent
Prelude
Released on: 2026-09-30
- Please refer to the 7.84.0 tag on integrations-core for the list of changes on the Core Checks
Upgrade Notes
-
On Linux, the Datadog process manager (
dd-procmgrd) is now a first-class service manager alongside systemd, upstart and sysvinit, and it is the default when thedd-procmgrdbinary ships with the Agent. The OpenTelemetry Collector distribution is supervised throughprocesses.dand thedatadog-agent-ddotsystemd unit is no longer installed.Each service manager now installs its own self-consistent set of units, so a host runs either the
dd-procmgrdsupervision path or the per-payload systemd units, never a mix of the two. -
Linux Agent packages no longer include the static archive
/opt/datadog-agent/embedded/lib/libpcap.a. This affects users whose custom integrations or build scripts link directly against that archive. Before upgrading, check for references to this path and instead install the platform's libpcap development package or provide a separate libpcap build. The libpcap headers under/opt/datadog-agent/embedded/includeremain available. -
The
com.datadoghq.remoteaction.agentPrivate Action Runner bundle (Preview) has been renamed tocom.datadoghq.remoteaction.datadogagent. -
The logs Agent now sends log payloads at a fixed higher concurrency by default instead of scaling the number of concurrent senders dynamically with intake latency (the previous "RTT fairness" behavior). This improves throughput for high-latency and high-volume workloads without manual tuning.
The Agent now uses a static send concurrency of
logs_config.pipelinesx 10 (for example, 40 concurrent senders on a host with the default 4 pipelines).Connection impact — please review before upgrading: because the Agent now runs more senders concurrently by default, it may open more simultaneous connections to the logs intake (up to the static concurrency above). If you need to limit connections — for example behind a proxy or on a connection-constrained network — set
logs_config.batch_max_concurrent_sendto a lower value (1keeps a single sender per pipeline).
New Features
- Data security PostgreSQL scans can now connect over TLS. The instance option
sslacceptsdisable,allow,preferandrequire. Theverify-caandverify-fullmodes are not supported yet, as server certificates are not validated. - Data security PostgreSQL scans now support the
verify-caandverify-fullSSL modes, and send a client certificate and key on TLS connections whenssl_certandssl_keyare set. - On Linux and macOS, the Agent now reports an Agent Health issue when the log file tailer loses log data because a file was rotated before the tailer finished reading it. The issue is reported once per host and covers every affected log source, reporting the total bytes lost and rotations involved over the last 24 hours together with a breakdown per source and service. Loss recorded before an Agent restart is not carried across the restart.
- On macOS, the
thermalcheck now reports hardware temperatures and the system thermal pressure level. It submitssystem.thermal.temperature.cpu,system.thermal.temperature.gpu,system.thermal.temperature.ssdandsystem.thermal.temperature.batteryin degrees Celsius, along withsystem.thermal.pressure_level(0 nominal, 1 moderate, 2 heavy, 3 trapping, 4 sleeping) tagged with the level name. Both Apple Silicon and Intel Macs are supported. Sensors that the host does not expose are omitted rather than reported as zero, so the set of available metrics varies by hardware model. - OTLP ingestion: Adds a new
otlp_config.metrics.infra_attributes.as_tagsoption. When enabled, custom tagger-derived tags (for example, tags configured viakubernetesResourcesLabelsAsTags/kubernetesResourcesAnnotationsAsTags) are promoted so they survive the metrics translator's allowlist and are emitted as metric tags for OTLP metrics ingested directly by the Agent. Without it, custom tags that are not known Datadog or OpenTelemetry conventions are dropped. Default behavior is unchanged. - DDOT: The
infraattributesprocessor now supports a newmetrics_attributes_as_tagsoption for the metrics pipeline. When enabled, custom tagger-derived tags (for example, tags configured viakubernetesResourcesLabelsAsTags/kubernetesResourcesAnnotationsAsTags) are promoted so they survive the metrics translator's allowlist and are emitted as metric tags. Default behavior is unchanged. - Rshell privileged helper process is introduced and allows specific, allow-listed commands to run with elevated privileges. This is enabled with private_action_runner: enabled: true restricted_shell: privileged: enabled: true it requires
seccompandlandlockand is linux-only. - Added the
device_tags_sourceoption to the SNMP check, controlling where the device tags on metrics come from.resource(default) sends only the device resource tag and lets the backend attach the device tags from the metadata payload.agenthas the Agent attach the device tags to every metric and omits the resource tag, so no backend enrichment happens.bothsends the device tags and the resource tag. Has no effect whencollect_device_metadatais disabled.
Enhancement Notes
- The Datadog installer's setup script now accepts a
DD_LOG_LEVELenvironment variable to set thelog_leveloption indatadog.yamlat install time. On Windows, the Agent MSI installer also exposes aDD_LOG_LEVELproperty and passes it through to the Datadog installer. - Network Path Synthetic tests now report an NDM
namespaceon emitted paths. By default the Agent uses its configurednetwork_devices.namespace(matching thenetwork_pathintegration); individual tests can override it via anamespacefield in their configuration. Previously synthetic paths were always emitted with an empty namespace. - Adds
data_plane.preflight_mode_duration, which sets how long the Agent Data Plane (ADP) pre-flight leaves ADP running. It defaults to90sand is clamped to that as a minimum, so it can only extend the window: a shorter one stops ADP while its startup is still in progress and reports a healthy host as a failure. It is intended for benchmarking harnesses that need ADP resident for the whole of a fixed-length run; on a real host the setting to reach for remainsdata_plane.preflight_mode. - APM : The trace-agent EVP proxy now forwards the
DD-EVP-ORIGINandDD-EVP-ORIGIN-VERSIONrequest headers to Event Platform intake. Previously these headers were stripped by the proxy allowlist, so server SDK metadata (SDK name and version) was lost at the Agent even when the SDK sent it. Values are forwarded unchanged; the Agent does not synthesize defaults for requests that omit them. - APM : Use the OpenTelemetry
url.templateattribute in HTTP client resource names when available, while retaining method-only resource names as the fallback. - APM: Add
apm_config.traces_send_to_main_endpoint(DD_APM_TRACES_SEND_TO_MAIN_ENDPOINT, defaulttrue). This setting is for internal use, and we expect to remove it in a future version. When set tofalse, the trace-agent trace and stats writers stop sending to the main endpoint (api_key+apm_config.apm_dd_url) and forward traces and APM stats only toapm_config.additional_endpoints. The main endpoint's API key is still used by the other trace-agent proxies, and the configuration is rejected when no additional endpoint would remain. This is the traces/stats counterpart ofapm_config.profiling_send_to_main_endpoint. - APM : Add support for installing APM injection on AMD64 systems that also run 32-bit binaries. 32-bit executables run without injection, while supported 64-bit executables continue to be instrumented.
- Agents are now built with Go
1.26.6. - Agents are now built with Go
1.26.7. - The DDOT configuration converter now reuses a user-defined
pprof,zpages,health_checkorddflareextension that was declared underextensionsbut not wired intoservice.extensions, instead of adding a default<name>/dd-autoconfiguredcopy. This matches the behavior already in place for thedatadoganddogtelextensions, so a user's custom extension configuration is honored even when they forget to add it to the service's extension list. - The Datadog Distribution of the OpenTelemetry Collector (DDOT) now sends series metrics to Datadog using the v3 metrics intake, reducing metrics egress bandwidth. This aligns DDOT with the core Agent: series follow the
use_v3_api.series.enabledsetting, whose default (datadog_only) uses the v3 intake for Datadog destinations while other destinations continue to use the v2 intake. To keep using the v2 intake, setuse_v3_api.series.enabledtofalse(or theDD_USE_V3_API_SERIES_ENABLEDenvironment variable). - DogStatsD diagnostic commands (
dogstatsd-stats,dogstatsd-capture,dogstatsd-replay,dogstatsd top, anddogstatsd dump-contexts) now print a clear error message and exit when invoked against the Core Agent while the Agent Data Plane is configured to handle DogStatsD traffic. In that mode the Core Agent's DogStatsD pipeline is dormant and the commands would silently produce empty or misleading results. Use the equivalent commands through theagent-data-planebinary instead. - Added retry-with-backoff to startup of the External Metrics Provider. The Cluster Agent now retries the external metrics server setup on transient APIServer failures instead of failing on the first attempt.
- gpum: Add
gpu.legacy_sm_activeconfig toggle. When enabled on GPM-capable NVIDIA GPUs,gpu.sm_activereports the GPM SM utilization value whilegpu.sm_utilizationremains available. - gpu: add
gpu_nvlink_capableandgpu_nvlink_versiontags to GPU metrics, to allow filtering GPUs that have NVLink enabled and the version supported. - Health Platform: the
health_platform.issues_detectedtelemetry counter is now also tagged withseverity, in addition to the existingissue_typetag. This allows filtering or grouping detected health issues by their severity level. - Tag Kubernetes Job events emitted by the
kubernetes_apiservercheck withkube_cronjobwhen the Job's name matches the pattern generated by a CronJob, similar to the tagging already applied to Pod events. agent statusnow reports why a file matched by a log configuration is not being tailed when its fingerprint cannot be used, under the log source that matched it. The most common cause is a file that holds less data thanlogs_config.fingerprint_config.count, for instance right after a log rotation replaced it with a smaller file, and the message names the setting to change. This previously showed up only as a shortfall in theN files tailed out of M files matchingline, with no explanation.- The Logs Agent now logs a warning when a file matched by a log configuration is not tailed because its fingerprint cannot be used, which previously happened without any log line at any level. The most common cause is a file that holds less data than
logs_config.fingerprint_config.count, for instance right after a log rotation replaced it with a smaller file. The warning reports the path, the current size of the file and how much data fingerprinting requires, and distinguishes a file that is simply too short from a file whose fingerprint could not be computed at all. It is emitted once when the file starts being skipped rather than once per check, and a closing message is logged when it stops being skipped, whether the file started being tailed again or was never tailed at all, so the collection gap can be measured from the Agent log alone. - The logon duration event on Windows now breaks each boot Group Policy pass down into the individual client-side extension invocations that ran during it, reporting the offset, duration, and outcome of each along with the Group Policy objects that fed it. The breakdown appears as a new
group_policy_detailsblock in the event'scustomattributes, split intocomputeranduserarrays. - Notable Events on macOS now reports the cause of the previous shutdown on Apple silicon: the Agent classifies the power management unit's boot-fault record after each boot and emits a
System shutdown faultevent when the previous shutdown was caused by a power fault, a processor crash signal, a watchdog timeout, a hardware fault or a thermal fault. The event reports the fault classification and the underlying fault tokens, and is emitted at most once per boot. - The Private Action Runner can now validate MongoDB connections
- The Network Configuration Management (NCM) check now emits a
datadog.ncm.check_failuremetric, tagged with the failure reason, whenever the check encounters an error. - Network Config Management (NCM) local configuration store is now bounded by the network_devices.config_management.store.min_configs_per_device, network_devices.config_management.store.max_configs_per_device, and network_devices.config_management.store.max_raw_config_store_bytes configurations. Once these limits are exceeded, the least-recently-used configs are evicted. min_configs_per_device and max_configs_per_device is floored at 2. min_configs_per_device and max_configs_per_device are hard limits and will be enforced even if the size of the database file is greater than or less than max_raw_config_store_bytes. Default values are as follows: min_configs_per_device = 3, max_configs_per_device = 50, max_raw_config_store_bytes = 2000000000. Updates to store configurations become active upon agent restart.
- The Datadog Distribution of OpenTelemetry (DDOT) Collector now compresses all telemetry signals with
zstd, providing a consistent compression algorithm across metrics, logs, and traces. Metrics and logs default tozstdlevel 3 and the level is configurable through theserializer_zstd_compressor_levelandlogs_config.zstd_compression_levelsettings. Previously, metrics were compressed withzliband traces withgzip. - OTLP ingest and DDOT: Logs received through the OTLP receiver now map the instrumentation scope name and version to
otel.scope.nameandotel.scope.version. Incomingotel.library.name/otel.library.versionattributes (the deprecated OpenTelemetry predecessors) are remapped to the canonicalotel.scope.*keys. - Private Action Runner: the
api_key_only_enrollmentsetting now defaults totrue. Runners now enroll using only an API key by default, without requiring an application key. Your API key need to have "Private Action Runner" scoped enabled. - Add opt-in PAR split mode support to the containerized Agent.
- Enables PAR action execution on-demand to significantly reduce idle memory usage. This is opt-in behind
private_action_runner.split_enabledand is currently available on Linux host deployments. - Private Action Runner: add the
private_action_runner.restricted_shell.disable_detailed_telemetrysetting. When set totrue, it suppresses the raw command text and effective sandbox configuration that rshell attaches to its "run" telemetry span for eachrunCommand/runRemediationCommandinvocation. The setting defaults tofalse; other rshell telemetry (exit code, timing, command counts) is unaffected. - Adds support for on-demand PAR action execution to Windows host deployments.
- Data Observability: Extended the
queryactionscomponent to support SQL Server in addition to PostgreSQL. The component now schedulesdata_observability.queriesforsqlservercheck instances and correctly resolves Azure SQL Database instances by requiring both host and database equality, preventing cross-database payload injection. - Autodiscovery now reports the check configuration keys it ignores when several annotation or label formats are set on the same entity. Only the format with the highest priority is applied (
checks, thencheck_nameswithinit_configsandinstances, then the legacyservice-discovery.datadoghq.comprefix), and the others used to be discarded silently. The ignored keys are now listed in the Autodiscovery section of theagent statusoutput. - The SSI
injection-metadatatelemetry payload now supports an optional, free-formmetadatafield for carryingresult_class-dependent data. - Bumped the Security Agent policies to v0.84.0
- APM: Reduce allocations when decoding v0.4 traces by interning strings directly from the incoming payload instead of allocating a string for every value already present in the string table.
- APM: Reserve room for the trailing end-of-body read when buffering an incoming trace payload, avoiding a reallocation and copy of the buffer.
- A small sample of sketch metric flushes (0.1% by default) is now additionally sent to a v3beta metrics intake endpoint to validate the upcoming v3 metrics protocol. Shadow traffic is only sent for agents configured against the
datadoghq.com(US1) site. To opt out, setserializer_experimental_use_v3_api.sketches.shadow_sample_rateto0. - The Agent now logs a warning instead of an informational message when it finds a Docker, CRI or PodResources socket that exists but cannot be reached. On Unix this condition is only reported when opening the socket fails with a permission error, so it means the Agent user lacks access to the socket. Because these messages are emitted while the configuration is still loading, they were previously discarded on Agents running with
log_levelset towarnor above.
Deprecation Notes
- Remove system-probe module-restart CLI command.
Security Notes
- Data security PostgreSQL scans now open connections as read-only, as a first layer of protection against accidental writes.
- The Datadog flare extension (
ddflare) in DDOT no longer serves its endpoint, by defaulthttps://localhost:7777, without authentication. - Update agent-payload to v5.0.209 to remove the legacy zstd_0 dependency.
Bug Fixes
- Autodiscovery: a negative index in the
%%port_<index>%%template variable (for example%%port_-1%%) no longer crashes the Agent. Negative indexes are now resolved Python-style,-1being the last port,-2the second to last, and so on, wrapping around the list of ports so that indexes beyond the number of ports still resolve. - The file-based secret backend now rejects directory paths passed as a secret name. On AIX, reading a directory with
os.ReadFilereturns raw directory bytes instead of an error, which could cause a directory's contents to be returned as a secret value. - APM: Raise the messagepack decoder allocation limit for the span
meta_structfield to 10MiB, so largemeta_structentries (as written by LLM Observability) are no longer rejected by the package-wide 500,000 element limit. Other span fields keep the lower limit. - APM peer-tag aggregation now refreshes derived tag keys when Remote Configuration changes semantic registry mappings without changing the producer-declared content hash.
- Add the origin product source to distribution metrics originating from checks.
- Clarify the Process Component status when Service Discovery is enabled without Live Process collection. The enabled checks now report
service_discoveryinstead ofprocessandrtprocessin this configuration. - CSM Misconfigurations: a Kubernetes configuration file the Agent may not read is now reported with its content left out. An unreadable kubelet kubeconfig used to parse into an empty one, matching a kubeconfig that really names no cluster, and the managed environment detection concluded from it that an EKS, GKE or AKS node was unmanaged. The detection now sees an absent kubeconfig, and the payload says as much. The ownership and permissions of an unreadable file are reported too, so the benchmarks that check them see the real mode.
- CSM Misconfigurations: the Kubernetes node configuration collected for the CIS Kubernetes benchmarks now assumes the
KubeletConfigurationdefaults for a kubelet started with--config, and folds in the drop-ins of--config-dir. Kubernetes keeps the historical command line defaults of--read-only-port,--anonymous-authand--authorization-modefor a kubelet started on flags alone, and the Agent applied them in both cases. A node whose configuration file left those settings out was therefore reported with a read-only port on10255, anonymous authentication enabled and anAlwaysAllowauthorization mode, while the kubelet was really running with the read-only port disabled, anonymous authentication disabled andWebhookauthorization. OpenShift and kubeadm both leavereadOnlyPortout of their rendered configuration, so their nodes failed the "kubelet read-only port should be disabled" rule with the port closed. - CWS: fix a regression where the process context updates carried by an event (
setuid,setgid,capset, login UID and IMDS security credentials) were applied before the event was evaluated, preventing rules from matching on the process state that preceded the event. - Data Observability query actions now match PostgreSQL checks by their resolved database identifier. Queries now run when the identifier uses an agent hostname override or a
database_identifiertemplate. - Fixed DDOT being unable to reach the core Agent in containerized deployments that do not pass
--core-config(Docker, ECS, and ECS Fargate). Without a core config path the connection failed withx509: certificate signed by unknown authority. The OTel Agent now falls back to the defaultdatadog.yamllocation when it exists and the collector is not running in standalone mode. - Fixed a bug in the trace-agent DogStatsD proxy endpoints (
/dogstatsd/v1/proxyand/dogstatsd/v2/proxy) where a request body was split into all of its newline-separated payloads at once, so a body containing many newlines used several times its own size in memory. The body is now scanned one payload at a time, empty payloads are skipped, and the number of payloads relayed per request is capped. - The Agent no longer shows the content of check config files on its local expvar page. This includes the configuration of JMX checks. The content is still sent to Datadog and still included in the flare.
- The metric filter list (
metric_filterlist) now matches on the normalized metric name instead of the raw submitted name. Metric names are normalized by the Datadog intake on ingest, so a metric submitted asmy metric-nameis stored and displayed asmy_metric_name. Previously a filter list entry using the normalized name that users see in Datadog would fail to match such a metric, and the metric was submitted anyway. Filter list entries themselves are matched as written, so they should be the metric name as it appears in Datadog. - Kubernetes orchestrator: Prevent unchanged clusters from being repeatedly reported as updated when the node listing order changes.
- CWS: Network events are now attributed to the correct process when the same address and port are reused across different network namespaces.
- Fix the default
query_timeoutfor the Oracle check from 20,000 seconds to 20 seconds. - Fixed a bug in container image reporting where image references whose registry host included a port (for example
myregistry.local:5000/foo/bar:1.2.3) were split on the first colon instead of the tag separator. This caused theimage_nameandimage_tagtags, as well as the values shown in the Container Images view, to be incorrect for such images. The repo and tag are now parsed using the last colon following the last slash, matching standard image reference rules. Relatedly, the registry of images whose reference has a registry host followed by a single path component (for examplelocalhost:5000/serviceorregistry.k8s.io/pause) is now reported in the Container Images view instead of being left empty. - Fixes Agent installs and upgrades failing to create any systemd unit files on hosts whose kernel does not support ambient capabilities (kernel older than 4.3). On those hosts the installer selects the
-nocapsystemd unit templates, but those templates were never compiled into the installer binary, so unit generation failed withfailed to write stable units: open tmpl/gen/debrpm-nocap/datadog-agent.service: file does not existand the host was left with no Datadog units at all. Because the package manager scriptlet ignores this failure, the install appeared to succeed whilesystemctl start datadog-agentreportedUnit not found. This affected both the classic DEB/RPM install path and Fleet Automation remote upgrades and configuration experiments, which use the equivalentoci-nocaptemplates. - Fix container log corruption when partial records from stdout and stderr are interleaved. The Agent now reconstructs partial CRI and Docker JSON-file records independently for each stream.
- Cluster Agent (KSM check): fix a collision when collecting custom resource metrics for two custom resources that share the same
Kindand plural name but belong to different API groups (for exampleProjectin bothartifactory.example.comandsonarqube.example.com). Previously the resources shared a single API client, causing repeatedUnexpected watch event object gvkerrors and mixed, incorrect metric counts. Custom resource clients are now keyed by their fully-qualified GroupVersionResource. - NCM check frequency will no longer default to a negative number; config values expressed as integers instead of durations (e.g. "5" instead of "30s" or "10m") will be parsed as seconds instead of nanoseconds.
- DDOT: fix
DD_SITEbeing ignored whenapi.siteis absent from the Datadog exporter config. Telemetry was silently sent toapi.datadoghq.cominstead of the site configured viaDD_SITEordatadog.site. - Fix an issue on Windows where uninstalling the Agent could fail if the configuration directory (
C:\ProgramData\Datadogby default) had already been removed before running the uninstall. - On Windows, the
wlancheck no longer panics on hosts wherewlanapi.dllis unavailable. The library ships with theWireless-Networkingfeature, which is not installed by default on Windows Server. Such hosts are now reported as having no active Wi-Fi interface. - Fix an issue where the Agent logged a spurious error about Workloadmeta collectors not being ready on every startup in environments where no container runtime or orchestrator is detected, such as container sidecars.
- Flare archive filenames now include a process ID and counter suffix (
datadog-agent-<timestamp>-<pid>-<counter>-<loglevel>.zip), preventing two archives created by the same Agent process at the same second from overwriting each other. - Fleet Installer: Fix an issue where the installer's telemetry client repeatedly logged
failed to send telemetry payloadwarnings with404 Not Founderrors on GovCloud sites (ddog-gov.com), since no instrumentation telemetry intake exists there. Telemetry is now disabled outright for GovCloud sites, matching the existing behavior of the Agent's own resident telemetry. - HA Agent: a Remote Config document on the
HA_AGENTproduct that belongs to thecomp/workloadbalancingcomponent (identified by an explicittypefield) is now skipped instead of being processed as an invalid HA Agent document. If every document in an update batch turns out to belong tocomp/workloadbalancing, HA Agent resets its state toUnknownrather than keeping a stale Active/Standby state. - Fix Private Action Runner startup delays when signing keys are already available from Remote Config.
- Fix an Agent IPC client socket leak when a local service accepts a TLS connection but never completes the handshake.
- KSM core check: Fixed a bug where the
kubernetes_state.configmap.countmetric could stop being reported. ConfigMaps are collected using a metadata-only Kubernetes client, and the conversion of watch events into ConfigMap objects was dropping annotations, including thek8s.io/initial-events-endbookmark annotation used by newer versions of client-go's watch-list feature to signal that the initial list has finished syncing. Without that signal, the underlying reflector would wait indefinitely and the metric would never be reported. - Windows: Fix the logon duration event reporting
boot_timelineandgroup_policy_detailsentries out of chronological order. A milestone that ran while the machine sat at the login screen, such as Computer Group Policy on a domain-joined host, could render after milestones that actually followed it. - Add new
bind_hostconfiguration option to TCP and UDP log listeners. - Normalize Windows device tags to use forward-slash paths, preventing duplicate disk and IO metric device tags.
- Fixed a standalone DDOT (
DD_OTEL_STANDALONE=true) failing to start when configured without a Datadog exporter, for example when the standalone DDOT is used to forward telemetry to a separate gateway layer via an OTLP exporter instead. - Agent OTLP Ingest no longer attaches the OpenTelemetry
debugexporterby default. Thedebugexporteris now attached only when theotlp_config.debugsection is explicitly configured. Declaring the section without a verbosity uses the default verbosity (basic), while settingotlp_config.debug.verbosity(orDD_OTLP_CONFIG_DEBUG_VERBOSITY) tobasic,normal, ordetailedselects the verbosity. Setting it tononeleaves the exporter detached. - The deprecated
process_config.enabledsetting no longer overridesprocess_config.container_collection.enabledandprocess_config.process_collection.enabledwhen those are configured directly, whether through the configuration file, an environment variable, or any higher-precedence source. Previously, settingDD_PROCESS_CONFIG_ENABLED=falsetogether withDD_PROCESS_CONFIG_CONTAINER_COLLECTION_ENABLED=falseleft container collection enabled.process_config.enabledstill applies to whichever of the two settings is left unset, so configurations that only use the deprecated setting are unaffected. - Autodiscovery now retries check configurations that failed secret resolution when
secret_refresh_intervalis enabled, allowing checks to recover after a transient secret backend outage without restarting the Agent. - Fix a crash of the Agent process when a Python check raises an exception whose message contains a Unicode lone surrogate.
- Runtime usage enrichment keeps container image SBOM components that share a name and a version. Trivy reports one component per install location, so a library version pinned by two lockfiles appears twice, and the merge kept only the first, leaving the dependency graph referencing a component the payload had lost. Components are deduplicated by their CycloneDX bom-ref, which is what identifies one.
- Fixed container image SBOMs being reported as in use after their last container had stopped. On Kubernetes nodes, an image that had run a container once kept that flag until the Agent was restarted.
- The runtime usage properties merged onto container image SBOMs (
LastSeenRunning,HasSetSuidBitandRunningAsRoot) now reach OS packages alone. The system-probe report is matched to components by name and version, so a language package sharing an OS package's name and version took the timestamp and flags of the OS package that had run. Components whose purl places them outside the dpkg, rpm and apk databases are left out of the match. - The runtime usage properties merged onto container image SBOMs (
LastSeenRunning,HasSetSuidBitandRunningAsRoot) are now set on OS packages alone. The runtime scanner reads the dpkg, rpm and apk databases, so language packages (npm, pypi, golang and others), the image's operating-system component and the per-lockfile application components stay out of its scope. The absence of a property marks a component out of scope, where aLastSeenRunningof0states that the package was watched and found idle. - Fixed
sbom.container_image.use_spread_refreshernever refreshing container image SBOMs on hosts with fewer than ten images, and refreshing them more slowly thanperiodic_refresh_secondson other hosts. - Fixed the Agent crashing when the stored SBOM of a container image could not be uncompressed. The image is now skipped instead.
- ECS Fargate: skip EC2 IMDS instance-type lookups. The Agent no longer periodically queries
169.254.169.254/latest/meta-data/instance-typeon Fargate (where IMDS is unavailable), which removes recurring INFO log noise in CloudWatch. - SNMP: Fix the detection of profiles using the legacy Python metric syntax. The detection result is now cached along with the profiles, so every check instance is consistently handed over to the Python loader instead of only the first instance to be configured. Previously the remaining instances silently kept using the Core loader.
- SNMP: The error reported when a legacy profile forces the fallback to the Python loader now names the profiles using the legacy syntax.
- Stop the Agent from attempting to reach a Kubelet when running as a Cluster Checks Runner. Cluster Checks Runners are Deployment replicas, not DaemonSets, so they never have a locally-reachable Kubelet, since a CCR doesn't correspond to any one node. This removes the recurring
Impossible to reach Kubelet through HTTPSwarning logged by Cluster Checks Runner pods. There is no change in behavior on the node Agent or Cluster Agent. - Auto multi-line detection no longer concatenates consecutive IIS W3C extended-format access log entries. A client IPv4 address next to the leading timestamp was being scored as part of that timestamp, which dropped the match to the detection threshold so each single-line record was treated as a continuation of the previous one. IPv4 addresses are now recognized as their own token and no longer interfere with timestamp detection.
- Fixed a crash in the trace-agent when processing a v0.7 payload whose trace chunk omits the
tagsfield and whose spans carry a_dd.p.dmtag. Promoting the decision maker to the chunk level no longer writes to an uninitialized map. - APM: Fix several trace-agent debug/error log messages that printed incorrect info due to format-string bugs.
Other Notes
- Agent Data Plane has been bumped to version 1.6.0. See the Agent Data Plane 1.6.0 release notes.
- Agent Data Plane has been bumped to version 1.6.1. See the Agent Data Plane 1.6.1 release notes.
- Added origin mapping for the Cisco Catalyst Center integration.
- Extended the delegated authentication (Workload Identity Federation) component so it can write a resolved API key into a map- or list-shaped
additional_endpointsconfiguration value, replacing a placeholderDELA(...)directive. This is internal foundation work; no Agent subsystem readsDELA(...)directives yet, so this does not enable any user-facing behavior on its own. - Added origin mapping for the Kueue and External Secrets integrations.
- The
batteryandwlancheck configurations are no longer shipped in the Linux and AIX packages. Both checks can only collect on macOS and Windows, so on other platforms their configuration only mattered wheninfrastructure_modewas set toend_user_device, where it scheduled a check that could never report data. macOS and Windows packages are unchanged. - Add metric origin mapping for the thermal integration.
Datadog Cluster Agent
Prelude
Released on: 2026-09-30 Pinned to datadog-agent v7.84.0: CHANGELOG.
Upgrade Notes
DD_INSTRUMENTATION_INSTALL_TYPE=k8s_single_stepand SSI defaults (for exampleDD_TRACE_ENABLED) apply only when a target or policy matches the pod, not merely because the namespace could match some rule. Pods that only have library annotations and do not match a target or policy usek8s_lib_injection.
New Features
DatadogInstrumentationchecks and logs configurations can now target StrimziStrimziPodSetworkloads.- Add AppSec injection support for GKE managed Gateways (EXTERNAL mode only). The Cluster Agent now detects GKE managed Gateways whose
spec.gatewayClassNameis in an allowlist of external-managed GatewayClass names (gke-l7-global-external-managed,gke-l7-regional-external-managed) and creates oneGCPTrafficExtension(networking.gke.io/v1) per Gateway to route edge traffic through a user-deployed Datadog AppSec callout service. SIDECAR mode is not supported because managed GKE has no in-cluster Envoy data plane. The callout Deployment, Service, and HealthCheckPolicy must be deployed by the user following the public GKE service-extensions documentation. Cluster-agent RBAC forgcptrafficextensions.networking.gke.io(get/list/watch/create/delete) is required. The GatewayClass allowlist is configurable viaappsec.proxy.gke.gateway_classes. Multi-cluster GatewayClasses (names ending in-mc) are always skipped, including when added to that allowlist, because they require anet.gke.ioServiceImportcallout backend that the Cluster Agent does not create. EachGCPTrafficExtensionis owned by its Gateway via an owner reference, so Kubernetes garbage-collects it even if the Cluster Agent misses the Gateway deletion event.
Enhancement Notes
- Adds Cluster Agent telemetry for the
DatadogInstrumentationcontroller, including the number of resources it tracks and reconciliation outcomes for checks and logs. - Added the
datadog.cluster_agent.autoscaling.workload.objective.targetgauge, which exposes the target value configured in aDatadogPodAutoscalerspec.objectives. The metric is tagged withobjective_type(pod_resource,container_resourceorcustom_query),value_type(utilizationorabsolute_value),objective_index(the 0-based position inspec.objectivesthat keeps each objective a distinct timeseries), and, for resource objectives,resource_nameandkube_container_name. - Collect NVIDIA Dynamo custom resources by default.
- Collect KubeRay
RayCluster,RayCronJob,RayJob, andRayServicecustom resources by default. - Single Step Instrumentation now evaluates local targeting (Helm, Operator, or
datadog.yaml) before Remote Config policies. Local targets keep first-match-wins order. Remote Config policies use last-match-wins: the last matching policy applies, so a catch-all can be listed first and exceptions after. A workload that matches a local target is not overridden by a remote deny. - Single Step Instrumentation now decides SSI versus local library injection from whether a configuration target or remote-config policy matched the pod, instead of a namespace-level eligibility approximation. Library annotations still short-circuit target selection for library versions and tracer configs (existing GA precedence).
Security Notes
- The Cluster Agent's admission controller webhook now enforces a size limit on incoming request bodies and validates the request content type before reading the body.
- The Cluster Agent no longer exposes the Go
pprofprofiling andexpvardebug endpoints on its metrics port (metrics_port, default5000) to remote callers. These/debug/endpoints were previously served on all network interfaces without authentication; they are now restricted to loopback callers, and requests originating from any other address receive a404. The/metricsendpoint is unchanged and remains reachable off-host so the node Agent can continue to scrape Cluster Agent telemetry. Local tooling such as the Cluster Agent flare, which connects over loopback, is unaffected.
Bug Fixes
- Fixed an issue where the
DatadogPodAutoscalercontroller could silently drop a status update after an HTTP 409 (Conflict) caused by a staleresourceVersionread from the informer cache. The reconcile now requeues on such a conflict so a subsequent pass retries the update with a refreshed object. - Ensure Kubernetes endpoint check annotations take precedence over
DatadogInstrumentationconfigurations that target the same Service and integration. This prevents duplicate endpoint checks and restores the CR-backed check when the overriding annotation is removed. - Fix an issue on AKS clusters where the Cluster Agent and the AKS admission enforcer would repeatedly overwrite each other's changes to the
datadog-webhookMutatingWebhookConfiguration/ValidatingWebhookConfigurationobjects, causingthe object has been modifiederrors to be logged in a loop. This affected admission controller features whose webhook rule did not otherwise restrict which namespaces it applies to (for example theDatadogInstrumentationCRD validating webhook), even whenadmission_controller.add_aks_selectors(DD_ADMISSION_CONTROLLER_ADD_AKS_SELECTORS) was enabled. - Fix a crash in the
kubernetes_state_corecheck (Cluster Agent or Cluster Check Runner) that occurred when using a wildcard entry ("*") inkubernetes_namespace_annotations_as_tagsor the equivalentkubernetes_resources_annotations_as_tagsnamespace configuration, on any namespace without annotations. - Fixed an issue where the Cluster Agent could schedule Prometheus Scrape OpenMetrics checks against Kubernetes services even when the autodiscovery configuration included
kubernetes_container_names. The Cluster Agent now skips service and endpoint Prometheus Scrape scheduling for configurations that setkubernetes_container_names; scraping discovered by node Agents remains as is. - Fix a Cluster Agent API bug that could log spurious
superfluous response.WriteHeader callwarnings. The internal telemetry wrapper now correctly tracks the response status when a handler writes the response body before explicitly setting the status code. - Restore continuous
kubernetes_state.endpoint.address_availableandkubernetes_state.endpoint.address_not_readyreporting (including0for the opposite ready state). After the kube-state-metrics v2.18 bump, each metric was only emitted for addresses in that state, so healthy endpoints no longer reportedaddress_not_ready=0and fully unready endpoints no longer reportedaddress_available=0.