Skip to Main Content
Cloud and AIOps


This is an IBM Automation portal for Cloud Management, Technology Cost Management, Network Automation and AIOps products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).

Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.

Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

Status Future consideration
Workspace Instana
Categories Agent
Created by Guest
Created on Aug 17, 2026

Support for running Instana Agent with security restriction on kubernets for MQ only

We are looking for a solution to collect all the logs and metrics from MQ deployed on kubernetes pods. We are interested only in MQ, no other IBM products.

Our restrictions regarding deployment are:

  • Pods can't have these settings: hostNetwork: true, hostPID: true, privileged: true, hostPath mounts.

  • Pods have this security context:
    allowPrivilegeEscalation: false
    readOnlyRootFilesystem: true
    runAsUser: 1001
    runAsNonRoot: true
    privileged: false
    capabilities:
    drop:
    - ALL

  • RBAC: Rules with secrets are not permitted for ClusterRole

  • Strong preference (and possibly a requirement) for changing ClusterRole to Role as there are greater restrictions for ClusterRole which may not be allowed.

  • Images with critical and high vulnerabilities found while scanning a new image not permitted

Idea priority Urgent
  • Admin
    Henning Treu
    Aug 18, 2026

    Hi Szymon,

    thanks for providing this idea. We can adjust Instana agents privileges with our upcoming Agent 2 release.

    For this, we will review and adjust the following from the requirements list:

    • privileged: true will be addressed by our non-root agent deployment

      • the capabilities: drop: ALL setting can not be used for the agent pod. Agent will have a list of dedicated Linux kernel capabilities to perform the monitoring

      • hostNetwork and hostPID is an essential requirement for Instana agent to perform monitoring

    • host path mounts will be revisited and restricted / removed as much as possible

      • exceptions will be documented

    • ClusterRole / Role rules with secrets will be restricted to instana-agent namespace

    • ClusterRoles in general will be restricted to namespace Roles as much as possible

      • exceptions will be documented


    Please be aware that we can role out any of those modifications only with Agent 2 release. Agent 1 is not fully compatible and requires the current settings.


    Best regards

    Henning Treu - Product Manager Instana Agent