Skip to content

Add DD_NO_SECURITY_AGENT_INSTALL - #457

Open
lebauce wants to merge 1 commit into
DataDog:mainfrom
lebauce:lebauce/no-security-agent
Open

lebauce wants to merge 1 commit into
DataDog:mainfrom
lebauce:lebauce/no-security-agent

Conversation

@lebauce

@lebauce lebauce commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Lets CWS and CSPM run in system-probe instead of the security agent.

With DD_NO_SECURITY_AGENT_INSTALL set:

  • DD_RUNTIME_SECURITY_CONFIG_ENABLED=true → system-probe.yaml gets runtime_security_config: {enabled: true, direct_send_from_system_probe: true}.
  • DD_COMPLIANCE_CONFIG_ENABLED=true → datadog.yaml gets compliance_config: {enabled: true, run_in_system_probe: true}.
  • security-agent.yaml is never created. If it already exists, it gets both runtime_security_config.direct_send_from_system_probe and compliance_config.run_in_system_probe: the datadog-agent-security service starts as soon as that file exists, so the security agent needs to read those to know it has nothing to do and stop.

manage_security_config takes the new flag as an argument, so both paths stay in one place. Also reported in the install telemetry as no_security_agent.

Covered by unit tests and a new TestInstallNoSecurityAgentSuite e2e suite (picked up by the existing catch-all e2e jobs).

@lebauce
lebauce requested a review from a team as a code owner September 22, 2026 15:41
@lebauce
lebauce requested a review from dd-valdugay September 22, 2026 15:41
Run CWS and CSPM without the security agent:

- DD_RUNTIME_SECURITY_CONFIG_ENABLED=true enables runtime security in
  system-probe.yaml with direct_send_from_system_probe, and leaves
  security-agent.yaml alone.
- DD_COMPLIANCE_CONFIG_ENABLED=true enables compliance_config with
  run_in_system_probe in datadog.yaml. An existing security-agent.yaml
  gets direct_send_from_system_probe so it stops sending CWS events,
  but it is never created.
@lebauce
lebauce force-pushed the lebauce/no-security-agent branch from 50bfd34 to b6b7b45 Compare September 23, 2026 09:52
@datadog-prod-us1-4

datadog-prod-us1-4 Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Pipelines  Tests

✨ Unblock PR with BitsAI

❌ Errors

Your PR has failed checks. Please review the issues below and take necessary action before merging.

🚦 1 Pipeline job failed

DataDog/agent-linux-install-script | Amazon_Linux_2023_amd64.SIM: [test-app-php-container-83] — 🔧 Needs a code fix, caused by this PR

View more details · View in GitLab

ℹ️ Info

No other issues found (see more)

🧪 All tests passed
❄️ No new flaky tests detected

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: b6b7b45 | Docs | View more details | Give us feedback!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant