Patches the embedded MIT krb5 library so NegoEx GSS token parsing rejects truncated headers and missing extension vectors instead of reading past the buffer, and bumps pip to 26.2.1 in the embedded Python distribution. Adds Fleet-managed upgrades and rollback for Windows FIPS Agents, plus fixes for Kueue pod tag loss after restart and Cluster Agent namespace metadata collection when on-demand instrumentation is enabled.
Datadog Agent
npx @buildinternet/releases get datadog-agent-releasesUpdates golang.org/x/crypto to v0.56.0. Core Check changes are listed in the 7.84.1 tag on integrations-core, and the Cluster Agent is pinned to datadog-agent v7.84.1.
On Linux, the Datadog process manager (dd-procmgrd) becomes a first-class service manager and the default when its binary ships, replacing per-payload systemd units for the OpenTelemetry Collector. The logs Agent now sends at a fixed concurrency of logs_config.pipelines times 10 instead of scaling dynamically with intake latency, which may open more simultaneous connections to the logs intake.
Fixed missing log source configuration fields in public inventory metadata, including Windows Event Log queries, processing options, auto-multiline settings, and maximum message size.
Fixed the Agent Data Plane pre-flight configuration being built from the fully resolved Agent configuration, which caused it to send metrics and the API key to datadoghq.com instead of the configured site. Network Path collector filters set via DD_NETWORK_PATH_COLLECTOR_FILTERS are now parsed and applied correctly, GPU constant metrics report on a configurable gpu.static_metrics_reporting_interval, and Single Step Instrumentation now accepts OTEL_-prefixed tracer config environment variables.
Fixed a bug that billed fast network path tests to customers, and released the containerd view snapshot and lease taken for container image SBOM scans even when the scan is cancelled or times out. Also fixed Cluster Agent graceful shutdown to release the Kubernetes leader-election lock before exiting, and the fleet installer daemon now reports DDOT process state.
Adds a Data Security provider that triggers one-off PostgreSQL scans via Remote Configuration, plus a preflight mode for the Agent Data Plane that runs once at startup to surface environment-specific issues. Also adds span-derived primary tags to DDOT span metrics, ConfigMap collection to the Kubernetes Orchestrator, and several other features and fixes.
The Dynamic Instrumentation proxy no longer drops payloads — this was accidentally removing existing workload-specific configs. Also fixed a system-probe upgrade regression that prevented clean upgrade.
With infrastructure_mode: end_user_device, the logon_duration feature now turns on automatically, no longer requiring a separate logon_duration.enabled: true setting; explicit configuration can still override. Also upgraded the embedded Python to 3.13.15, built with Go 1.26.6, raised the messagepack span meta_struct allocation limit to 10MiB, and disabled GPU parallel collection by default to avoid NVML concurrency bugs.
Fixed a kernel panic on multi-GPU nodes with Hopper/Blackwell GPUs, and prevented explicit DDAGENTUSER_KEEP_RIGHTS or DDAGENTUSER_NAME install arguments from being silently overridden by stale fallback values on Fleet Automation-triggered Windows installs/upgrades.
Automatic multi-line log detection is now enabled by default, aggregating stack traces and JSON blobs into single log entries. The legacy viper-based config backend is removed, and the default EVP track for AI usage changes to eudm-intake with desktop monitoring disabled by default.
Fixed an issue where the DDAGENTUSER_KEEP_RIGHTS opt-out was not preserved when the Agent was upgraded through Fleet Automation, causing SeDeny*LogonRight assignments to be reapplied. Also fixed Remote Configuration processing timed-out client requests.
Metrics now use the Datadog v3 intake by default for Datadog destinations. Custom endpoints and reverse proxies continue using v2; the use_v3_api.series.enabled flag controls the behavior. On macOS, the Agent GUI no longer steals focus from the active application.
New reflector-based Kubernetes event collection path, enabled via event_collection_mode: watch. Agents now built with Go 1.26.5.
Metrics now use the Datadog v3 intake by default, reducing outbound bandwidth from Agents to Datadog. On Linux, the agent process manager systemd units were renamed from datadog-agent-procmgrd.service to datadog-agent-procmgr.service; custom automation referencing the old unit names must be updated. The DDOT feature gate exporter.datadogexporter.metricremappingdisabled has been removed and replaced with exporter.datadogexporter.DisableAllMetricRemapping, and the unsupported agent status py subcommand has been removed.
Added more traces during SSI installation on Linux hosts to improve observability. This release also includes the usual Core Checks updates.
Fixed a bug where DatadogPodAutoscaler burstable mode could leave CPU limits on a random subset of pods when the Cluster Agent runs in HA mode, and fixed Private Action Runner self-enrollment failing silently on hosts without direct internet access when a proxy is configured.
Fixed a confused-deputy vulnerability in the Cluster Agent's AppSec ingress-nginx admission mutator where a pod's --configmap argument was trusted verbatim, allowing pod-create permissions in one namespace to affect ConfigMaps in others. Also fixed container log collection stopping silently for low-volume containers, and CIS Docker rules are no longer evaluated on Kubernetes nodes using non-Docker CRI runtimes, avoiding false positives on GKE Container-Optimized OS.
The Datadog Agent's embedded Python has been upgraded from 3.13.13 to 3.13.14.
The APM trace agent on Linux now starts lazily when data is sent to its listeners, reducing resource usage. New features include AI usage support on Windows, a restricted service monitoring mode for visualizing service maps without USM billing, NCCL metrics collection for GPU workloads, and support for OTLP delta sum metrics with rate conversion.


