elastic / elastic/integrations

[Agentless] README Still Marks Agentless as Beta While Manifest has `release: ga`

Open
#20,751 5 comments 0 reactions 1 assignee Claimed by @moxarth-rathod View on GitHub
agentless documentation enhancement Team:SDE-Crest Team:Security-Service Integrations
Dominant language
Handlebars
Stars
333
Forks
647
Avg merge
2d 18h
Merged PRs (30d)
182

Description

## Summary

Many Integrations have promoted agentless to GA in the package manifest (`deployment_modes.agentless.release: ga`), but the published README still describes agentless as a beta feature.

This is a documentation-only mismatch. Fleet/Kibana will treat agentless as GA from the manifest, while docs still say it is beta and not covered by the GA support SLA.

## Example

**Manifest** (`packages/wiz/manifest.yml`):

```yaml
deployment_modes:
agentless:
enabled: true
release: ga
```

**README** (`packages/wiz/_dev/build/docs/README.md`):

> Agentless deployments are only supported in Elastic Serverless and Elastic Cloud environments. This functionality is in beta and is subject to change. Beta features are not subject to the support SLA of official GA features.

## Expected

README text should match the agentless `release` value in the manifest:

- `release: ga` → no beta disclaimer
- `release: beta` → keep the beta disclaimer

Suggested GA wording (already used by packages such as `google_secops` and `kolide`):

> Agentless deployments are only supported in Elastic Serverless and Elastic Cloud environments. Agentless deployments provide a means to ingest data while avoiding the orchestration, management, and maintenance needs associated with standard ingest infrastructure. Using an agentless deployment makes manual agent deployment unnecessary, allowing you to focus on your data instead of the agent that collects it.
>
> For more information, refer to [Agentless integrations](https://www.elastic.co/guide/en/serverless/current/security-agentless-integrations.html) and [Agentless integrations FAQ](https://www.elastic.co/guide/en/serverless/current/agentless-integration-troubleshooting.html).

## Proposed fix

For each affected package:

1. Update `_dev/build/docs/README.md` (source of truth; `docs/README.md` is generated).
2. Remove the beta / “not subject to the support SLA of official GA features” sentence.
3. Prefer the GA wording above. While doing so, replace leftover **“Elastic Managed deployments”** wording with **“Agentless deployments”** (36 of the packages below still use the older name).
4. Patch-bump the package and add a changelog entry (docs-only).

## Affected integrations (117)

All currently have `release: ga` in the manifest and a beta disclaimer in README.

| Package | Title |
|---|---|
| `abnormal_security` | Abnormal AI |
| `admin_by_request_epm` | Admin By Request EPM |
| `airlock_digital` | Airlock Digital |
| `armis` | Armis |
| `atlassian_bitbucket` | Atlassian Bitbucket |
| `atlassian_confluence` | Atlassian Confluence |
| `atlassian_jira` | Atlassian Jira |
| `auth0` | Auth0 |
| `authentik` | authentik |
| `beyondinsight_password_safe` | BeyondInsight and Password Safe |
| `beyondtrust_epm` | BeyondTrust EPM |
| `beyondtrust_pra` | BeyondTrust PRA |
| `bitdefender` | BitDefender |
| `bitsight` | Bitsight |
| `bitwarden` | Bitwarden |
| `blacklens` | blacklens.io |
| `box_events` | Box Events |
| `carbon_black_cloud` | VMware Carbon Black Cloud |
| `checkpoint_email` | Check Point Harmony Email & Collaboration |
| `checkpoint_harmony_endpoint` | Check Point Harmony Endpoint |
| `cisa_kevs` | CISA Known Exploited Vulnerabilities |
| `cisco_duo` | Cisco Duo |
| `cisco_secure_endpoint` | Cisco Secure Endpoint |
| `claroty_ctd` | Claroty CTD |
| `claroty_xdome` | Claroty xDome |
| `cloudflare` | Cloudflare |
| `cyberark_epm` | CyberArk EPM |
| `cybereason` | Cybereason |
| `cyera` | Cyera |
| `darktrace` | Darktrace |
| `digital_guardian` | Digital Guardian |
| `elastic_security` | Elastic Security |
| `entro` | Entro |
| `eset_protect` | ESET PROTECT |
| `extrahop` | ExtraHop |
| `first_epss` | First EPSS |
| `forgerock` | ForgeRock |
| `google_scc` | Google Security Command Center |
| `ibm_qradar` | IBM QRadar |
| `imperva_cloud_waf` | Imperva Cloud WAF |
| `infoblox_bloxone_ddi` | Infoblox BloxOne DDI |
| `ironscales` | IRONSCALES |
| `island_browser` | Island Browser |
| `jamf_pro` | Jamf Pro |
| `jumpcloud` | JumpCloud |
| `jupiter_one` | JupiterOne |
| `lastpass` | LastPass |
| `lumos` | Lumos |
| `menlo` | Menlo Security |
| `microsoft_defender_cloud` | Microsoft Defender for Cloud |
| `microsoft_defender_endpoint` | Microsoft Defender for Endpoint |
| `microsoft_exchange_online_message_trace` | Microsoft Exchange Online Message Trace |
| `microsoft_sentinel` | Microsoft Sentinel |
| `mimecast` | Mimecast |
| `miniflux` | Miniflux RSS reader |
| `neon_cyber` | Neon Cyber |
| `nextron_thor` | Nextron THOR Cloud |
| `nozomi_networks` | Nozomi Networks |
| `o365` | Microsoft Office 365 |
| `panw_cortex_xdr` | Palo Alto Cortex XDR |
| `ping_one` | PingOne |
| `prisma_cloud` | Palo Alto Prisma Cloud |
| `proofpoint_itm` | Proofpoint ITM |
| `proofpoint_tap` | Proofpoint TAP |
| `qualys_gav` | Qualys Global AssetView |
| `qualys_vmdr` | Qualys VMDR |
| `qualys_was` | Qualys Web Application Scanning (WAS) |
| `rapid7_insightvm` | Rapid7 InsightVM |
| `sailpoint_identity_sc` | Sailpoint Identity Security Cloud |
| `sentinel_one` | SentinelOne |
| `servicenow` | ServiceNow |
| `slack` | Slack Logs |
| `snyk` | Snyk |
| `sophos_central` | Sophos Central |
| `splunk` | Splunk |
| `spycloud` | SpyCloud Enterprise Protection |
| `sublime_security` | Sublime Security |
| `swimlane` | Swimlane Turbine |
| `symantec_endpoint_security` | Symantec Endpoint Security |
| `sysdig` | Sysdig |
| `tenable_io` | Tenable Vulnerability Management |
| `tenable_ot_security` | Tenable OT Security |
| `tenable_sc` | Tenable Security Center |
| `ti_anomali` | Anomali ThreatStream |
| `ti_anyrun` | ANY.RUN Threat Intelligence Feeds |
| `ti_cif3` | Collective Intelligence Framework v3 |
| `ti_crowdstrike` | CrowdStrike Falcon Intelligence |
| `ti_custom` | Custom Threat Intelligence |
| `ti_cybersixgill` | Cybersixgill |
| `ti_cyware_intel_exchange` | Cyware Intel Exchange |
| `ti_domaintools` | DomainTools Feeds |
| `ti_eclecticiq` | EclecticIQ |
| `ti_eset` | ESET Threat Intelligence |
| `ti_flashpoint` | Flashpoint |
| `ti_google_threat_intelligence` | Google Threat Intelligence |
| `ti_greynoise` | GreyNoise |
| `ti_maltiverse` | Maltiverse |
| `ti_mandiant_advantage` | Mandiant Advantage |
| `ti_misp` | MISP |
| `ti_opencti` | OpenCTI |
| `ti_otx` | AlienVault OTX |
| `ti_rapid7_threat_command` | Rapid7 Threat Command |
| `ti_recordedfuture` | Recorded Future |
| `ti_threatconnect` | ThreatConnect |
| `ti_threatq` | ThreatQuotient |
| `tines` | Tines |
| `trellix_epo_cloud` | Trellix ePO Cloud |
| `trend_micro_vision_one` | TrendAI Vision One |
| `vectra_rux` | Vectra RUX |
| `withsecure_elements` | WithSecure Elements |
| `wiz` | Wiz |
| `workday` | Workday |
| `xm_cyber` | XM Cyber |
| `zerofox` | ZeroFox |
| `zeronetworks` | Zero Networks |
| `zoom` | Zoom |
| `zscaler_zia` | Zscaler Internet Access |

## Already consistent (GA + no beta disclaimer)

These already have `release: ga` and README without the beta disclaimer, and can be used as references:

`aws_securityhub`, `axonius`, `cloud_security_posture`, `doppel`, `elastic_connectors`, `google_secops`, `proofpoint_essentials`, `ti_socradar_taxii`

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.