Skip to content

EV-6699: Document license agent removal in 3.24.0-3 - #3001

Open
ti-afra wants to merge 1 commit into
tigera:mainfrom
ti-afra:license-agent
Open

ti-afra wants to merge 1 commit into
tigera:mainfrom
ti-afra:license-agent

Conversation

@ti-afra

@ti-afra ti-afra commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

The license agent is removed in Calico Enterprise 3.24.0-3.0 and is no longer maintained. No license-agent image is published for this release or later.

  • Release notes: add a "Deprecated and removed features" entry, plus an "Upgrade notes" subsection pointing to the platform-specific cleanup steps.
  • Upgrade guides (helm, operator, openshift): document how to uninstall the agent, preferring the versioned manifest from the release being upgraded from, with a manual resource cleanup fallback. Each links to the license metrics documentation.
  • Redirects: point the removed license-agent metrics page at the license options page for the latest and 3.24 paths. These are non-forced 301s, so they stay dormant while 3.23 remains latest and activate once 3.24.0-3.0 ships.

Copilot AI lite review requested due to automatic review settings September 2, 2026 22:11
@ti-afra
ti-afra requested a review from a team as a code owner September 2, 2026 22:11
@netlify

netlify Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for calico-docs-preview-next ready!

Name Link
🔨 Latest commit a35c64d
🔍 Latest deploy log https://app.netlify.com/projects/calico-docs-preview-next/deploys/6a99df84ea6e610008345be5
😎 Deploy Preview https://deploy-preview-3001--calico-docs-preview-next.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@netlify

netlify Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview succeeded!

Built without sensitive environment variables

Name Link
🔨 Latest commit a35c64d
🔍 Latest deploy log https://app.netlify.com/projects/tigera/deploys/6a99df84f2405d000804d041
😎 Deploy Preview https://deploy-preview-3001--tigera.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
Lighthouse
Lighthouse
1 paths audited
Performance: 71 (🔴 down 24 from production)
Accessibility: 98 (no change from production)
Best Practices: 92 (no change from production)
SEO: 100 (no change from production)
PWA: -
View the detailed breakdown and full score reports
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The upgrade-guide uninstall instructions hard-code a specific “upgrade-from” manifest version without clearly marking it as an example, which can mislead users upgrading from other versions.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Documents the removal of the Calico Enterprise license agent in the upcoming 3.24 release line by updating release notes, platform-specific upgrade guidance, and adding redirects for the removed metrics page.

Changes:

  • Added release-notes entries calling out license agent removal and an upgrade note that points to cleanup steps.
  • Updated Kubernetes (Helm + Operator) and OpenShift upgrade guides with license-agent uninstall/cleanup instructions and a pointer to license metrics documentation.
  • Added redirects from the removed license-agent metrics page to the license options page for latest and 3.24.
File summaries
File Description
static/_redirects Adds redirects for the removed license-agent metrics page.
calico-enterprise/release-notes/index.mdx Adds deprecated/removed note and upgrade note about license agent removal.
calico-enterprise/getting-started/upgrading/upgrading-enterprise/openshift-upgrade.mdx Documents OpenShift-specific uninstall/cleanup steps for the removed license agent.
calico-enterprise/getting-started/upgrading/upgrading-enterprise/kubernetes-upgrade-tsee/operator.mdx Documents operator-based upgrade uninstall/cleanup steps for the removed license agent.
calico-enterprise/getting-started/upgrading/upgrading-enterprise/kubernetes-upgrade-tsee/helm.mdx Documents Helm-based upgrade uninstall/cleanup steps for the removed license agent.
Review details
  • Files reviewed: 5/5 changed files
  • Comments generated: 4
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread calico-enterprise/release-notes/index.mdx Outdated
Copilot AI review requested due to automatic review settings September 2, 2026 22:31

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The manual fallback cleanup steps don’t account for older license-agent NetworkPolicy naming (allow-tigera tier), which can leave resources behind for users upgrading from pre-v3.23 installs without the original manifest.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Review details
  • Files reviewed: 5/5 changed files
  • Comments generated: 3
  • Review effort level: Lite

Copilot AI review requested due to automatic review settings September 2, 2026 22:34

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The release-note and upgrade-guide updates are only applied to unversioned “Next” docs, while the Calico Enterprise 3.24 content users will read is served from calico-enterprise_versioned_docs/version-3.24-2/ and currently lacks these updates.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Review details
  • Files reviewed: 5/5 changed files
  • Comments generated: 4
  • Review effort level: Lite

Comment thread calico-enterprise/release-notes/index.mdx Outdated
Copilot AI review requested due to automatic review settings September 3, 2026 18:17

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The manual cleanup commands may miss older license-agent NetworkPolicy variants (pre-3.23 tier naming), making the uninstall guidance incomplete for some upgrade paths.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Review details
  • Files reviewed: 5/5 changed files
  • Comments generated: 3
  • Review effort level: Lite

Copilot AI review requested due to automatic review settings September 3, 2026 18:42

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The changes are limited to documentation/redirect updates and the identified issues are minor formatting consistency nits with straightforward fixes.

Review details

Suppressed comments (3)

calico-enterprise/getting-started/upgrading/upgrading-enterprise/kubernetes-upgrade-tsee/operator.mdx:92

  • This command block also lacks a language tag; consider changing the opening fence to ```bash for consistency with other blocks in this file.
**calico-enterprise/getting-started/upgrading/upgrading-enterprise/kubernetes-upgrade-tsee/helm.mdx:69**
* This second command block fence should also specify a language (```bash) for consistent formatting with the rest of the page.

calico-enterprise/getting-started/upgrading/upgrading-enterprise/openshift-upgrade.mdx:102

  • This second command block fence should also specify a language (```bash) to match the rest of the upgrade guide’s command examples.

- **Files reviewed:** 5/5 changed files
- **Comments generated:** 3
- **Review effort level:** Lite
</details>

Copilot AI review requested due to automatic review settings September 3, 2026 18:49

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

Only minor documentation nits were found (missing terminal punctuation on new link sentences).

Review details
  • Files reviewed: 5/5 changed files
  • Comments generated: 3
  • Review effort level: Lite

Copilot AI review requested due to automatic review settings September 3, 2026 18:57

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The documentation updates are consistent across release notes, upgrade paths, and redirects, and the internal links/targets resolve to existing docs pages.

Review details
  • Files reviewed: 5/5 changed files
  • Comments generated: 0 new
  • Review effort level: Lite


:::

### License agent

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe clarify i the title that it has been removed.

In the paragraph, please direct them towards the operator metrics in calico-enterprise/operations/monitor/metrics/operator-metrics.mdx

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

changed the title to License agent removed and updated the link to point to operator metrics instead of license metrics.

Copilot AI review requested due to automatic review settings September 3, 2026 19:18

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The changes are documentation/redirect updates with verified internal links/anchors and consistent redirect paths for the configured version routing.

Review details
  • Files reviewed: 5/5 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

Copilot AI review requested due to automatic review settings September 3, 2026 19:23

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

There are a few documentation accuracy/convention inconsistencies (release version string and OpenShift kubectl vs oc) that should be corrected before merge.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Review details

Suppressed comments (1)

calico-enterprise/getting-started/upgrading/upgrading-enterprise/openshift-upgrade.mdx:107

  • This OpenShift upgrade guide otherwise uses oc (for example later oc apply ...), but these cleanup commands use kubectl. For consistency with the rest of the doc, consider using oc for these deletions as well.
   kubectl delete servicemonitor calico-lic-monitor -n tigera-prometheus --ignore-not-found
   kubectl delete networkpolicies.projectcalico.org calico-system.tigera-license-agent-access -n tigera-license-agent --ignore-not-found
   kubectl delete networkpolicies.projectcalico.org allow-tigera.tigera-license-agent-access -n tigera-license-agent --ignore-not-found
   kubectl delete clusterrole,clusterrolebinding tigera-license-agent --ignore-not-found
   kubectl delete namespace tigera-license-agent --ignore-not-found
  • Files reviewed: 5/5 changed files
  • Comments generated: 4
  • Review effort level: Lite

Copilot AI review requested due to automatic review settings September 3, 2026 19:26

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The OpenShift upgrade instructions introduce kubectl commands in a guide that otherwise consistently uses oc, which is inconsistent for the target platform.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Review details

Suppressed comments (1)

calico-enterprise/getting-started/upgrading/upgrading-enterprise/openshift-upgrade.mdx:96

  • This OpenShift-specific upgrade guide uses oc elsewhere, but the new license-agent removal steps use kubectl, which is inconsistent and may be confusing for OpenShift users. Use oc for these commands in this guide.
The license agent has been removed in $[prodname] v3.24.0-3. If you previously installed
it, uninstall it using the manifest from the version you are upgrading
**from** — it is still available at its versioned URL. For example, if upgrading from v3.23.2:

   ```bash
  • Files reviewed: 5/5 changed files
  • Comments generated: 1
  • Review effort level: Lite

Comment thread static/_redirects Outdated
Copilot AI review requested due to automatic review settings September 3, 2026 19:35

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The release-notes “platform-specific steps” link currently points to a DocCardList index rather than directly to the license-agent removal instructions.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Review details
  • Files reviewed: 5/5 changed files
  • Comments generated: 1
  • Review effort level: Lite

Comment thread calico-enterprise/release-notes/index.mdx Outdated
The license agent is removed in Calico Enterprise 3.24.0-3.0 and is no longer
maintained. No license-agent image is published for this release or later.

- Release notes: add a "Deprecated and removed features" entry, plus an
  "Upgrade notes" subsection pointing to the platform-specific cleanup steps.
- Upgrade guides (helm, operator, openshift): document how to uninstall the
  agent, preferring the versioned manifest from the release being upgraded
  from, with a manual resource cleanup fallback. Each links to the license
  metrics documentation.
- Redirects: point the removed license-agent metrics page at the license
  options page for the latest and 3.24 paths. These are non-forced 301s, so
  they stay dormant while 3.23 remains latest and activate once 3.24.0-3.0 ships.
Copilot AI review requested due to automatic review settings September 3, 2026 20:58

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The upgrade guides’ version string (v3.24.0-3) is inconsistent with the PR’s stated release identifier (3.24.0-3.0) and should be aligned to avoid reader confusion.

Review details

Suppressed comments (3)

calico-enterprise/getting-started/upgrading/upgrading-enterprise/kubernetes-upgrade-tsee/operator.mdx:82

  • The PR description/title refer to version 3.24.0-3.0, but this section says v3.24.0-3, which is inconsistent and could confuse readers looking for the exact release/build identifier.
The license agent has been removed in $[prodname] v3.24.0-3. If you previously installed

calico-enterprise/getting-started/upgrading/upgrading-enterprise/kubernetes-upgrade-tsee/helm.mdx:59

  • The PR description/title refer to version 3.24.0-3.0, but this section says v3.24.0-3, which is inconsistent and could confuse readers looking for the exact release/build identifier.
The license agent has been removed in $[prodname] v3.24.0-3. If you previously installed

calico-enterprise/getting-started/upgrading/upgrading-enterprise/openshift-upgrade.mdx:92

  • The PR description/title refer to version 3.24.0-3.0, but this section says v3.24.0-3, which is inconsistent and could confuse readers looking for the exact release/build identifier.
The license agent has been removed in $[prodname] v3.24.0-3. If you previously installed
  • Files reviewed: 5/5 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

@ti-afra ti-afra changed the title EV-6699: Document license agent removal in 3.24.0-3.0 EV-6699: Document license agent removal in 3.24.0-3 Sep 3, 2026

@ctauchen ctauchen left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for this. I have a few questions and suggestions.

I'm making changes to how we document these upgrade-related procedures (mostly for breaking changes, but also this). I'm still working through the structure, but it's likely to result in an "Upgrade notes" page that includes all the things people need to consider before upgrading.

If it's all right with you, I'll repurpose the material here and include it with that work. After I check details about the license agent changes.

kubectl delete -f https://downloads.tigera.io/ee/v3.23.2/manifests/licenseagent.yaml
```

If you no longer have that manifest:

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems to be a second, perhaps unnecessary method. We know that we host manifests for all published versions. So can't we just rely on the manifest being available?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

fair enough. I tried to be helpful to user but if it is too much explanation, I am okay with dropping this section and only refer them to find the correct manifest to do the uninstall.

Comment on lines +63 to +65
```bash
kubectl delete -f https://downloads.tigera.io/ee/v3.23.2/manifests/licenseagent.yaml
```

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What does this procedure look like for Helm installations?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

installing license agent is not part of the default installation, it comes as an additional step and therefore not included in the helm installations as well. the instructions to install license agent for reference: https://docs.tigera.io/calico-enterprise/3.21/operations/monitor/metrics/license-agent


### License agent removed

The license agent has been removed in $[prodname] v3.24.0-3. If you previously installed

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If you previously installed it

Under what circumstances would a CE users NOT have installed it? It seems to me that this applies to everyone using Calico Enterprise. Or is there a way to have a license without the agent?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The license agent has no operational role in the cluster. It runs as a standalone Deployment whose only job is to read the LicenseKey and expose Prometheus gauges — it does not gate, enforce or enable any feature. A Calico Enterprise cluster without it is fully functional; the only difference is those metrics.

Its replacement is already running on every cluster installed from our manifests. tigera-operator exports tigera_operator_license_expiry_timestamp_seconds and tigera_operator_license_valid, both labelled by package, and ships PrometheusRule alerts on them — LicenseExpiringWarning at 30 days and LicenseExpiringCritical at 7 days or when the license is invalid. The agent shipped no alerts, so this is more coverage than before, not less.

The one real impact is on users whose dashboards or alerts reference the agent's metric names; those need repointing at the operator metrics.


$[prodname] creates a default-deny for the calico-system namespace. If you deploy workloads into the calico-system namespace, you must create policy that allows the required traffic for your workloads prior to upgrade.

### License agent removed

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Some general questions:

  1. What happens if you don't remove the license agent?
  2. Does it make a difference when I do this? Before or after an upgrade? I'm guessing we do this first, then perform the upgrade.
  3. I presume that this removal step needs to remain in the CE docs until 3.27, when it will no longer apply because we will stop supporting upgrades from 3.24. Is that right?
  4. Is this just cleanup, or does this constitute a breaking change?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1. What happens if you don't remove it?

It keeps running and keeps exporting its metrics. Nothing in the release manages it — the operator doesn't reconcile it, nothing upgrades or removes it — so it becomes an orphan: not built, not tested, not patched. CVEs accumulate in an image that never gets rebuilt.

2. Before or after the upgrade?

Either works.

3. Keep the note until 3.27?

That's correct. When 3.24 is the oldest supported cluster, we are not supporting this upgrade path anymore.

4. Cleanup or breaking change?

No functionality breaks — license validity is still observable via the operator metrics. But it's a user-visible removal, not silent cleanup: the manifest URL will 404, and dashboards or alerts on the agent's metric names need repointing. Should be a deprecation/removal in the release notes.

@ctauchen

Copy link
Copy Markdown
Collaborator

@ti-afra One last check: Is there anything that a user needs to do to maintain the function of the license? I assume that we're just changing the system that deals with licenses, and that everything should continue to work as before with no special procedures. Is that right?

@ti-afra

ti-afra commented Sep 15, 2026

Copy link
Copy Markdown
Contributor Author

@ti-afra One last check: Is there anything that a user needs to do to maintain the function of the license? I assume that we're just changing the system that deals with licenses, and that everything should continue to work as before with no special procedures. Is that right?

Correct — no user action needed. Licensing itself is unchanged: the LicenseKey resource, enforcement, and renewal all work exactly as before. The license agent never took part in any of that; it only exported metrics. The only change is which metrics report license expiry.

@ti-afra

ti-afra commented Sep 15, 2026

Copy link
Copy Markdown
Contributor Author

Thanks for this. I have a few questions and suggestions.

I'm making changes to how we document these upgrade-related procedures (mostly for breaking changes, but also this). I'm still working through the structure, but it's likely to result in an "Upgrade notes" page that includes all the things people need to consider before upgrading.

If it's all right with you, I'll repurpose the material here and include it with that work. After I check details about the license agent changes.

Of course — please structure it however works best for the docs.

One clarification: are you taking everything from this PR, or just the release note and upgrade note? And will you close this PR when that's merged?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants