Cluster Sensor 1.8.0

October 01, 2026

This release adds crash loop detection to suppress events from containers stuck in CrashLoopBackOff and lets you store your Customer ID and Activation ID as Kubernetes secrets.

New Feature

Introduced Crash Loop Detection: Event Suppression for CrashLoopBackOff Containers

What's New for You

You can now suppress repetitive events from containers stuck in a CrashLoopBackOff state, reducing event noise while keeping relevant security signals visible.

The Cluster Sensor now detects containers in the CrashLoopBackOff state and suppresses the repetitive events they generate. Containers experiencing crash loops can generate a continuous stream of identical events, which can overwhelm normal traffic, increase processing overhead, and obscure relevant security signals.

The Cluster Sensor filters these repetitive events while preserving the initial failure context. When the container recovers and becomes healthy, the Cluster sensor automatically resumes normal event processing.

You can enable this feature using the following flag in the values.yaml file located at:
qualys-tc > charts > cluster-sensor. 

Parameter Description Default Value Required
clusterSensor.podFilter.crashLoopPodFilter.enabled Enables the crash loop pod filter to filter out pod events for containers stuck in the crash loop state. false No

Enhancement

Customer ID and Activation ID as Kubernetes Secrets

What's New for You

You can now store your Customer ID and Activation ID as Kubernetes secrets instead of plain text, keeping sensitive credentials out of Helm values files and deployment configurations.

The Helm charts for the Cluster Sensor now support specifying the Customer ID and Activation ID as Kubernetes secrets, rather than plain text values. This reduces the exposure of sensitive credentials in Helm values files and deployment configurations.

To enable this feature, use the following parameters
--set global.credentialsSecret.create=true
--set global.credentialsSecret.name="Secret Name"

To use this approach, create a Kubernetes secret that contains the following predefined key names and provide the secret name in the Helm chart. To know about qualys-tc Helm chart, refer to CS Sensor 1.45 Release Notes > Unified Helm Chart (qualys-tc 2.11.1) Updates.

Passing the Customer ID and Activation ID as plain text continues to work. When plain-text values are provided, the Helm chart automatically creates the Kubernetes secret.