Repository navigation
Conversation
✅ Deploy Preview for calico-docs-preview-next ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
✅ Deploy Preview succeeded!Built without sensitive environment variables
To edit notification comments on pull requests, go to your Netlify project configuration. |
There was a problem hiding this comment.
🟡 Changes recommended
The upgrade-guide uninstall instructions hard-code a specific “upgrade-from” manifest version without clearly marking it as an example, which can mislead users upgrading from other versions.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
Documents the removal of the Calico Enterprise license agent in the upcoming 3.24 release line by updating release notes, platform-specific upgrade guidance, and adding redirects for the removed metrics page.
Changes:
- Added release-notes entries calling out license agent removal and an upgrade note that points to cleanup steps.
- Updated Kubernetes (Helm + Operator) and OpenShift upgrade guides with license-agent uninstall/cleanup instructions and a pointer to license metrics documentation.
- Added redirects from the removed license-agent metrics page to the license options page for
latestand3.24.
File summaries
| File | Description |
|---|---|
| static/_redirects | Adds redirects for the removed license-agent metrics page. |
| calico-enterprise/release-notes/index.mdx | Adds deprecated/removed note and upgrade note about license agent removal. |
| calico-enterprise/getting-started/upgrading/upgrading-enterprise/openshift-upgrade.mdx | Documents OpenShift-specific uninstall/cleanup steps for the removed license agent. |
| calico-enterprise/getting-started/upgrading/upgrading-enterprise/kubernetes-upgrade-tsee/operator.mdx | Documents operator-based upgrade uninstall/cleanup steps for the removed license agent. |
| calico-enterprise/getting-started/upgrading/upgrading-enterprise/kubernetes-upgrade-tsee/helm.mdx | Documents Helm-based upgrade uninstall/cleanup steps for the removed license agent. |
Review details
- Files reviewed: 5/5 changed files
- Comments generated: 4
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
f51c254 to
04d91ac
Compare
04d91ac to
8ec2a04
Compare
There was a problem hiding this comment.
🟡 Changes recommended
The manual fallback cleanup steps don’t account for older license-agent NetworkPolicy naming (allow-tigera tier), which can leave resources behind for users upgrading from pre-v3.23 installs without the original manifest.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Review details
- Files reviewed: 5/5 changed files
- Comments generated: 3
- Review effort level: Lite
There was a problem hiding this comment.
🟡 Changes recommended
The release-note and upgrade-guide updates are only applied to unversioned “Next” docs, while the Calico Enterprise 3.24 content users will read is served from calico-enterprise_versioned_docs/version-3.24-2/ and currently lacks these updates.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Review details
- Files reviewed: 5/5 changed files
- Comments generated: 4
- Review effort level: Lite
8ec2a04 to
9181a9b
Compare
There was a problem hiding this comment.
🟡 Changes recommended
The manual cleanup commands may miss older license-agent NetworkPolicy variants (pre-3.23 tier naming), making the uninstall guidance incomplete for some upgrade paths.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Review details
- Files reviewed: 5/5 changed files
- Comments generated: 3
- Review effort level: Lite
9181a9b to
e52be43
Compare
There was a problem hiding this comment.
🟢 Approval recommended
The changes are limited to documentation/redirect updates and the identified issues are minor formatting consistency nits with straightforward fixes.
Review details
Suppressed comments (3)
calico-enterprise/getting-started/upgrading/upgrading-enterprise/kubernetes-upgrade-tsee/operator.mdx:92
- This command block also lacks a language tag; consider changing the opening fence to ```bash for consistency with other blocks in this file.
**calico-enterprise/getting-started/upgrading/upgrading-enterprise/kubernetes-upgrade-tsee/helm.mdx:69**
* This second command block fence should also specify a language (```bash) for consistent formatting with the rest of the page.
calico-enterprise/getting-started/upgrading/upgrading-enterprise/openshift-upgrade.mdx:102
- This second command block fence should also specify a language (```bash) to match the rest of the upgrade guide’s command examples.
- **Files reviewed:** 5/5 changed files
- **Comments generated:** 3
- **Review effort level:** Lite
</details>
e52be43 to
9174846
Compare
9174846 to
96a89ad
Compare
There was a problem hiding this comment.
🟢 Approval recommended
The documentation updates are consistent across release notes, upgrade paths, and redirects, and the internal links/targets resolve to existing docs pages.
Review details
- Files reviewed: 5/5 changed files
- Comments generated: 0 new
- Review effort level: Lite
|
|
||
| ::: | ||
|
|
||
| ### License agent |
There was a problem hiding this comment.
Maybe clarify i the title that it has been removed.
In the paragraph, please direct them towards the operator metrics in calico-enterprise/operations/monitor/metrics/operator-metrics.mdx
There was a problem hiding this comment.
changed the title to License agent removed and updated the link to point to operator metrics instead of license metrics.
96a89ad to
7f248c0
Compare
7f248c0 to
71e9304
Compare
There was a problem hiding this comment.
🟢 Approval recommended
The changes are documentation/redirect updates with verified internal links/anchors and consistent redirect paths for the configured version routing.
Review details
- Files reviewed: 5/5 changed files
- Comments generated: 0 new
- Review effort level: Lite
71e9304 to
f321690
Compare
There was a problem hiding this comment.
🟡 Changes recommended
There are a few documentation accuracy/convention inconsistencies (release version string and OpenShift kubectl vs oc) that should be corrected before merge.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Review details
Suppressed comments (1)
calico-enterprise/getting-started/upgrading/upgrading-enterprise/openshift-upgrade.mdx:107
- This OpenShift upgrade guide otherwise uses
oc(for example lateroc apply ...), but these cleanup commands usekubectl. For consistency with the rest of the doc, consider usingocfor these deletions as well.
kubectl delete servicemonitor calico-lic-monitor -n tigera-prometheus --ignore-not-found
kubectl delete networkpolicies.projectcalico.org calico-system.tigera-license-agent-access -n tigera-license-agent --ignore-not-found
kubectl delete networkpolicies.projectcalico.org allow-tigera.tigera-license-agent-access -n tigera-license-agent --ignore-not-found
kubectl delete clusterrole,clusterrolebinding tigera-license-agent --ignore-not-found
kubectl delete namespace tigera-license-agent --ignore-not-found
- Files reviewed: 5/5 changed files
- Comments generated: 4
- Review effort level: Lite
There was a problem hiding this comment.
🟡 Changes recommended
The OpenShift upgrade instructions introduce kubectl commands in a guide that otherwise consistently uses oc, which is inconsistent for the target platform.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Review details
Suppressed comments (1)
calico-enterprise/getting-started/upgrading/upgrading-enterprise/openshift-upgrade.mdx:96
- This OpenShift-specific upgrade guide uses
ocelsewhere, but the new license-agent removal steps usekubectl, which is inconsistent and may be confusing for OpenShift users. Useocfor these commands in this guide.
The license agent has been removed in $[prodname] v3.24.0-3. If you previously installed
it, uninstall it using the manifest from the version you are upgrading
**from** — it is still available at its versioned URL. For example, if upgrading from v3.23.2:
```bash
- Files reviewed: 5/5 changed files
- Comments generated: 1
- Review effort level: Lite
f321690 to
a05baed
Compare
There was a problem hiding this comment.
🟡 Changes recommended
The release-notes “platform-specific steps” link currently points to a DocCardList index rather than directly to the license-agent removal instructions.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Review details
- Files reviewed: 5/5 changed files
- Comments generated: 1
- Review effort level: Lite
The license agent is removed in Calico Enterprise 3.24.0-3.0 and is no longer maintained. No license-agent image is published for this release or later. - Release notes: add a "Deprecated and removed features" entry, plus an "Upgrade notes" subsection pointing to the platform-specific cleanup steps. - Upgrade guides (helm, operator, openshift): document how to uninstall the agent, preferring the versioned manifest from the release being upgraded from, with a manual resource cleanup fallback. Each links to the license metrics documentation. - Redirects: point the removed license-agent metrics page at the license options page for the latest and 3.24 paths. These are non-forced 301s, so they stay dormant while 3.23 remains latest and activate once 3.24.0-3.0 ships.
a05baed to
a35c64d
Compare
There was a problem hiding this comment.
🔵 Needs a closer look
The upgrade guides’ version string (v3.24.0-3) is inconsistent with the PR’s stated release identifier (3.24.0-3.0) and should be aligned to avoid reader confusion.
Review details
Suppressed comments (3)
calico-enterprise/getting-started/upgrading/upgrading-enterprise/kubernetes-upgrade-tsee/operator.mdx:82
- The PR description/title refer to version
3.24.0-3.0, but this section saysv3.24.0-3, which is inconsistent and could confuse readers looking for the exact release/build identifier.
The license agent has been removed in $[prodname] v3.24.0-3. If you previously installed
calico-enterprise/getting-started/upgrading/upgrading-enterprise/kubernetes-upgrade-tsee/helm.mdx:59
- The PR description/title refer to version
3.24.0-3.0, but this section saysv3.24.0-3, which is inconsistent and could confuse readers looking for the exact release/build identifier.
The license agent has been removed in $[prodname] v3.24.0-3. If you previously installed
calico-enterprise/getting-started/upgrading/upgrading-enterprise/openshift-upgrade.mdx:92
- The PR description/title refer to version
3.24.0-3.0, but this section saysv3.24.0-3, which is inconsistent and could confuse readers looking for the exact release/build identifier.
The license agent has been removed in $[prodname] v3.24.0-3. If you previously installed
- Files reviewed: 5/5 changed files
- Comments generated: 0 new
- Review effort level: Lite
ctauchen
left a comment
There was a problem hiding this comment.
Thanks for this. I have a few questions and suggestions.
I'm making changes to how we document these upgrade-related procedures (mostly for breaking changes, but also this). I'm still working through the structure, but it's likely to result in an "Upgrade notes" page that includes all the things people need to consider before upgrading.
If it's all right with you, I'll repurpose the material here and include it with that work. After I check details about the license agent changes.
| kubectl delete -f https://downloads.tigera.io/ee/v3.23.2/manifests/licenseagent.yaml | ||
| ``` | ||
|
|
||
| If you no longer have that manifest: |
There was a problem hiding this comment.
This seems to be a second, perhaps unnecessary method. We know that we host manifests for all published versions. So can't we just rely on the manifest being available?
There was a problem hiding this comment.
fair enough. I tried to be helpful to user but if it is too much explanation, I am okay with dropping this section and only refer them to find the correct manifest to do the uninstall.
| ```bash | ||
| kubectl delete -f https://downloads.tigera.io/ee/v3.23.2/manifests/licenseagent.yaml | ||
| ``` |
There was a problem hiding this comment.
What does this procedure look like for Helm installations?
There was a problem hiding this comment.
installing license agent is not part of the default installation, it comes as an additional step and therefore not included in the helm installations as well. the instructions to install license agent for reference: https://docs.tigera.io/calico-enterprise/3.21/operations/monitor/metrics/license-agent
|
|
||
| ### License agent removed | ||
|
|
||
| The license agent has been removed in $[prodname] v3.24.0-3. If you previously installed |
There was a problem hiding this comment.
If you previously installed it
Under what circumstances would a CE users NOT have installed it? It seems to me that this applies to everyone using Calico Enterprise. Or is there a way to have a license without the agent?
There was a problem hiding this comment.
The license agent has no operational role in the cluster. It runs as a standalone Deployment whose only job is to read the LicenseKey and expose Prometheus gauges — it does not gate, enforce or enable any feature. A Calico Enterprise cluster without it is fully functional; the only difference is those metrics.
Its replacement is already running on every cluster installed from our manifests. tigera-operator exports tigera_operator_license_expiry_timestamp_seconds and tigera_operator_license_valid, both labelled by package, and ships PrometheusRule alerts on them — LicenseExpiringWarning at 30 days and LicenseExpiringCritical at 7 days or when the license is invalid. The agent shipped no alerts, so this is more coverage than before, not less.
The one real impact is on users whose dashboards or alerts reference the agent's metric names; those need repointing at the operator metrics.
|
|
||
| $[prodname] creates a default-deny for the calico-system namespace. If you deploy workloads into the calico-system namespace, you must create policy that allows the required traffic for your workloads prior to upgrade. | ||
|
|
||
| ### License agent removed |
There was a problem hiding this comment.
Some general questions:
- What happens if you don't remove the license agent?
- Does it make a difference when I do this? Before or after an upgrade? I'm guessing we do this first, then perform the upgrade.
- I presume that this removal step needs to remain in the CE docs until 3.27, when it will no longer apply because we will stop supporting upgrades from 3.24. Is that right?
- Is this just cleanup, or does this constitute a breaking change?
There was a problem hiding this comment.
1. What happens if you don't remove it?
It keeps running and keeps exporting its metrics. Nothing in the release manages it — the operator doesn't reconcile it, nothing upgrades or removes it — so it becomes an orphan: not built, not tested, not patched. CVEs accumulate in an image that never gets rebuilt.
2. Before or after the upgrade?
Either works.
3. Keep the note until 3.27?
That's correct. When 3.24 is the oldest supported cluster, we are not supporting this upgrade path anymore.
4. Cleanup or breaking change?
No functionality breaks — license validity is still observable via the operator metrics. But it's a user-visible removal, not silent cleanup: the manifest URL will 404, and dashboards or alerts on the agent's metric names need repointing. Should be a deprecation/removal in the release notes.
|
@ti-afra One last check: Is there anything that a user needs to do to maintain the function of the license? I assume that we're just changing the system that deals with licenses, and that everything should continue to work as before with no special procedures. Is that right? |
Correct — no user action needed. Licensing itself is unchanged: the LicenseKey resource, enforcement, and renewal all work exactly as before. The license agent never took part in any of that; it only exported metrics. The only change is which metrics report license expiry. |
Of course — please structure it however works best for the docs. One clarification: are you taking everything from this PR, or just the release note and upgrade note? And will you close this PR when that's merged? |

The license agent is removed in Calico Enterprise 3.24.0-3.0 and is no longer maintained. No license-agent image is published for this release or later.