September 25
Agent Control v1.25.1
Bug fixes
- On-host: the OpAMP compression for the verify client is disabled so that the server can read the
execution.modeattribute
Security updates
- Updated rust crate nr-auth to v0.6.0
- Updated rust crate config to 0.15.26
- Updated rust crate thiserror to 2.0.21
For a detailed description of changes, see the release notes.
September 18
Agent Control v1.25.0
New features
- Linux: added Debian 13 (trixie) as a supported/published platform.
- Linux: removed the legacy on-host folder migration pre-v1.2.0 from
newrelic-agent-control-cli - Variants support has been removed in favor of the "governance" flow server side
- Regex-based remote config validation has been removed in favor of the "governance" flow server side.
Bug fixes
- On-host: fixed a spurious
error-level log"cannot forward agent control event"emitted on every clean shutdown; the status server bridge now exits only via an explicit stop signal, closed channels are silently disabled rather than causing an exit, and publisher lifetimes are extended to keep channels open until the stop signal fires. - Linux:
uninstall.shnow usesapt-get purgeinstead ofapt-get remove, preventing a dpkg state inconsistency that caused reinstallation to fail, the service could not start because thesystemd-env.confconffile was not recreated by the package manager. - Windows: the uninstall script now warns instead of silently succeeding when the install or runtime-data directory cannot be removed (e.g. Windows Explorer has it open), and preserves the script itself so it can be re-run once the lock is released.
- On-host: filesystem entries under
filesystem:/shared_filesystem:are now written to disk in alphabetical order and fsynced after each write, making the write order deterministic. - On-host: self-update no longer deletes the downloaded package's binary when replacing the running binary, fixing rollback and same-version reinstall after a self-update.
- On-host: fixed a spurious
Error reading the log directory/files: No such file or directorymessage printed to stderr the first time Agent Control's or a sub-agent's log directory is created. - On-host: executable output and lifecycle logs are no longer misleadingly tagged with the
start_agentspan for the entire lifetime of agent processes and supervisors, they carry the explicit fields instead. - On exit, the process-terminated log line (success or error) is no longer dropped from the log file: it used to be emitted after the file logger had already shut down, so it only ever reached
journalctl/stderr.
Security updates
- Update rustls
- Updated rust crate reqwest to 0.13.5
- Updated rust crate encoding_rs to 0.8.41
- Updated alpine/helm to v4.3.0
- Updated rust crate toml to 1.1.6
- Updated rust crate clap to 4.6.7
- Updated rust crate jsonwebtoken to 11.1.0
- Updated rust crate opamp-client to v0.1.0
- Updated rust crate cfg-if to 1.0.5
- Updated rust crate syn to 3.0.6
- Updated rust crate serde-saphyr to 1.3.0
- Updated rust crate nr-auth to v0.5.3
For a detailed description of changes, see the release notes.
September 8
Agent Control v1.24.0
New features
- Renamed the
secrets_providersconfig key tovalue_providers, the old key is kept for backwards compatibility. - OnHost: added support for RedHat 10
- K8s: add a new
nr-kubecmvalue provider to resolve variables from Kubernetes ConfigMaps. chart_values.globalis still supported in agentTypes, but deprecated. You can still configure globals viachart_values.[chart-name].global- Linux: added
uninstall.shscript bundled in the package that auto-detects the package manager (apt, yum, zypper) and removesnewrelic-agent-control.
Bug fixes
- On-host: the eBPF agent now writes its status log under the AC managed filesystem directory instead of
/etc/newrelic-ebpf-agent. - On-host: fix false "already running" startup error when a stale PID file held a PID reused by an unrelated process.
- Suppress
Healthreporting (OpAMP and status server) for sub-agents whose agent type defines nohealth:block, including on initial supervisor start failure. - On-host: when an agent type is upgraded to a new version, stale filesystem entries declared by the old version are now removed via a diff instead of a full agent directory wipe; the sub-agent's OpAMP instance ID is preserved across version bumps.
- K8s: when a sub-agent type is upgraded to a new version, the OpAMP instance ID is now preserved across the upgrade; previously the fleet-data ConfigMap was deleted on every type change regardless of whether the agent name changed, causing a new instance ID to be generated on the next start.
- Linux:
postremovescript now correctly removesnewrelic-agent-controldirectories on any uninstall (not only onapt purge), and targets the right paths (/etc/newrelic-agent-control,/var/lib/newrelic-agent-control,/var/run/newrelic-infra) instead of the old infra-agent ones. - On-host: the service now retries indefinitely on failure (20 s delay) instead of stopping after 5 rapid restarts; applies to both the Linux systemd unit and the Windows SCM failure actions.
Security updates
- Updated rust crate nr-auth to v0.5.2
- Updated rust crate opamp-client to v0.0.42
- Updated rust crate flate2 to 1.1.10
- Updated rust crate rcgen to 0.14.10
- Updated rust crate serde-saphyr to 1.2.0
- Updated alpine/kubectl to v1.37.0
- Updated rust crate aws-lc-rs to 1.18.1
- Updated rust crate toml to 1.1.5
- Updated rust to v1.98.1
- Updated rust crate windows-link to 0.100.0
- Updated rust crate windows-registry to 0.100.0
- Updated rust crate syn to 3.0.5
- Updated rust crate crossbeam to 0.8.5
- Updated rust crate rstest to 0.27.0
- Updated rust crate encoding_rs to 0.8.40
For a detailed description of changes, see the release notes.
August 25
Agent Control v1.23.0
New features
- Add support for variables override through
variable.agentConfigsyntax in Remote Configuration keys. - Add support for a single entry of a
string_mapvariable override throughvariable.agentConfig.<variable>:<map-key>syntax in Remote Configuration keys. - On-host infrastructure agent type (linux): expose the
nri-dockerintegration configuration through a newconfig_dockervariable. - Agent type: enforce variable name format to
[A-Za-z0-9_-]starting with a letter and maximum length of 64 characters. - On-Host: enable self-update capability by default. Self updates are only executed when commanded by Fleet Control.
Bug fixes
- K8s supervisor: force a Flux reconciliation on stalled HelmReleases (e.g. after exhausting install/upgrade retries) when a new remote config arrives and restarts the sub-agent supervisor.
- On-host: report the actual last failure (launch error or non-zero exit) in the
lastErrorMessageof the unhealthy status once the restart policy is exceeded, instead of the generic "Restart policy exceeded" message. - On-host: persist fluent-bit's home directory (
fb.db) across infra-agent package updates instead of storing it in the replaced package directory
Security updates
- Updated rust crate either to 1.18.0
- Updated rust to v1.98.0
- Updated rust crate actix-web to 4.15.0
- Updated alpine/kubectl to v1.36.4
- Updated rust crate syn to 3.0.4
For a detailed description of changes, see the release notes.
August 18
Agent Control v1.22.0
New features
- On-host: enforce a 2400 MiB hard memory limit on the Agent Control process tree (AC + all child agents) via systemd
MemoryMaxon Linux.
Bug fixes
- Linux: prevent systemd service disable after RPM package update
Security updates
- Updated rust crate futures to 0.3.34
- Updated alpine/helm to v4.2.4
- Updated rust crate serde-saphyr to 1.1.0
For a detailed description of changes, see the release notes.
August 11
Agent Control v1.21.0
New features
- Windows filesystem: Removed unused code and use higher-level APIs for Windows interaction.
- Reports the
com.newrelic.remoteAgentTypeRepoReachableOpAMP custom capability when the configured Agent Type OCI repository is reachable at startup. - On-host: added nri-flex agentType.
Bug fixes
- Windows: fixed files under Agent Control's managed directories being left with permissions it could not use. Managed directories now use an inheritable Administrators ACE, and Agent Control tries to repair ACEs on startup.
Security updates
- Updated rust crate http to 1.5.0
- Updated rust crate clap to 4.6.6
- Updated rust crate serde-saphyr to 1.0.1
- Updated rust crate base64 to 0.23.1
- Updated rust crate aws-lc-rs to 1.18.0
- Updated rust crate thiserror to 2.0.20
- Updated rust crate async-trait to 0.1.92
- Updated rust crate actix-web to 4.14.1
- Updated rust crate rcgen to 0.14.9
For a detailed description of changes, see the release notes.
July 29
Agent Control v1.20.0
New features
- Kubernetes:
--release-nameis now optional onuninstall-agent-control; omitting it skips deleting the release's own HelmRelease/HelmRepository CRs. - On-host: added nri-apache and nri-nginx agentTypes.
- On-host: added nri-postgresql agentType.
- On-host: added nri-mysql agentType.
- On-host: added nri-memcached Agent Type.
- Log files rotated have now 30 days of retention.
- Added
agent-type validate --file <path>subcommand tonewrelic-agent-control-cliandnewrelic-agent-control-k8s-clifor schema-level validation of agent type definition files. - Extended
agent-type validatewith semantic validation: every${nr-var:X}reference indeploymentmust have a matchingvariablesdeclaration. - Enable cache for remote Agent Type registry
Security updates
- Updated rust crate kube to 4.2.0
- Updated rust crate rustls-pki-types to 1.15.1
- Updated rust crate base64 to 0.23.0
- Updated rust crate either to 1.17.0
- Updated rust crate jsonwebtoken to v11
- Updated rust crate serial_test to v4
- Updated rust crate schemars to 1.2.2
- Updated alpine/kubectl to v1.36.3
- Updated rust crate toml to 1.1.4
For a detailed description of changes, see the release notes.
July 23
Agent Control v1.19.1
Bug fixes
- On-host: the infra agentType has been fixed removing nri-flex binary copy.
Security updates
- Updated rust crate clap to 4.6.4
- Updated rust crate tokio to 1.53.1
- Updated rust crate glob to 0.3.4
- Updated rust crate tokio-stream to 0.1.19
- Updated rust crate syn to 3.0.3
For a detailed description of changes, see the release notes.
July 20
Agent Control v1.19.0
New features
- On-host and Kubernetes: When an agent's type is bumped via a live remote config update, Agent Control now reconciles both per-agent and shared filesystems, deleting paths declared by the old type that no longer appear in any active agent's declarations. Co-owned shared paths still claimed by another active agent are preserved. On Kubernetes, k8s objects annotated with the old type are garbage-collected while new-type resources are left intact.
- Adds
oci-utilsCLI totest/crates/oci-test-utilsfor pushing agent packages and agent type definitions to OCI registries from the command line (dev/test tooling; not published). - On-host agent-type parsing now validates
reported_version_package: It must reference a declared package, and is required when more than one package is defined. Invalid configurations are rejected at parse time with a descriptive error. Thisreported_version_packagedetermines which version is reported asagent.version. - Adds support for
copy_from_filefor on-host "in-agent" filesystem. - Adds support for
shared_filesystemin on-host agent types. It includes a single-owner rule: Two agents claiming the same path in the shared-filesystem are invalid and reported as Failed. - On-host self-update: Skip sub-agent reconciliation when a self-update is in progress. When a single remote config both bumps the Agent Control version and changes a sub-agent's
agent_type, the changed sub-agent is no longer recreated moments before the process restarts; the new config is stored and re-applied cleanly by the restarted process, avoiding a redundant sub-agent restart and telemetry gap. - On-host: Added support for nri-redis agentType for both Linux and Windows.
- On-host health config: Replaced the flat
health.http:/health.file:fields with an explicitchecks:list. Each entry is discriminated bykind:(Process,Http, orFile). The previously implicit supervised-process health check is now declared askind: Process. An omitted or emptychecks:list disables health reporting entirely. - On-host filesystem entries (
file/dir) now always survive sub-agent stop, restart, and config-apply. A straypersistent:key in existing agent-type YAML is ignored rather than rejected.
Bug fixes
- Added identifying attributes for each package specified in the agentType as
package.version.<id>. - RPM packages now restore
local_config.yamlfrom the.rpmsavebackup left by a prior uninstall.
Security updates
- Updated rust crate bytes to 1.12.1
- Updated rust crate regex to 1.13.1
- Updated rust to v1.97.1
- Updated alpine/helm to v4.2.3
- Updated rust crate toml to 1.1.3
- Updated rust crate syn to v3
- Updated rust crate clap to 4.6.2
- Updated rust crate tokio to 1.53.0
- Updated rust crate aws-lc-rs to 1.17.3
- Updated rust crate thiserror to 2.0.19
- Updated rust crate serde to 1.0.229
- Updated rust crate async-trait to 0.1.91
- Updated rust crate futures to 0.3.33
- Updated rust crate quote to 1.0.47
- Updated rust crate serde_json to 1.0.151
For a detailed description of changes, see the release notes.
July 6
Agent Control v1.18.0
Features
- Added exponential backoff and jitter retries to OCI artifact fetches using a new
BackoffPolicy(configured underself_update.download_retry), replacing the previouswith_retries(usize, Duration)API. - Added post-download script support for OCI packages.
- Hardened service restart policies on Linux and Windows platforms (implementing
systemdrate limiting: maximum of 5 restarts within 60 seconds) to prevent crash-looping from saturating CPU capacity. - Added support for retrieving remote agent type definitions directly from OCI registries.
- Configured agent type definitions to tolerate unknown fields to ensure forward compatibility.
- Added support for creating on-host agents without defining a health check, which disables health reporting for that agent.
- Streamlined version tracking for on-host agents by deriving versions directly from OCI package metadata. This eliminates command-based version checking and removes the need for the
deployment.versionconfiguration in agent type definitions. - Replaced the
filesystemconfiguration in on-host agent type definitions with an explicit, recursive, tagged-kind tree structure where every entry declareskind: file | dir | dir_content_from_mapanddirentries nest usingentries:. - Introduced a
persistentflag (default value is set tofalse) for on-host filesystem entries; ephemeral entries are deleted when a sub-agent stops, while persistent entries remain until the agent is removed from thefleet.Reconciliationacross writes is driven by a.ac-managed-paths.jsonmanifest (reserved filename — agent types must not declare it) so paths Agent Control no longer owns are deleted while sub-agent-created files are preserved. - Introduced the
shared-filesystem-dirvariable for agent type configurations. - Extended the internal
fscrate to support file copy operations. - Removed the filesystem manifest-based prune mechanism; Agent Control no longer deletes previously-declared paths dropped by subsequent configurations; agent-managed files are now reclaimed only when the agent is removed from the fleet.
Fixes
- Fixed an on-host self-update issue where pushing an empty
version: ""string from Fleet Control incorrectly triggered an image pull of the:latestOCI tag. It now correctly treats an empty string as a no-op (), matching the behavior of an absent version field.
For a detailed description of changes, see the release notes.