From b6b7b456a1c7dac47d2daa5666aee9c131b8a466 Mon Sep 17 00:00:00 2001 From: Sylvain Baubeau Date: Tue, 22 Sep 2026 17:40:02 +0200 Subject: [PATCH] Add DD_NO_SECURITY_AGENT_INSTALL Run CWS and CSPM without the security agent: - DD_RUNTIME_SECURITY_CONFIG_ENABLED=true enables runtime security in system-probe.yaml with direct_send_from_system_probe, and leaves security-agent.yaml alone. - DD_COMPLIANCE_CONFIG_ENABLED=true enables compliance_config with run_in_system_probe in datadog.yaml. An existing security-agent.yaml gets direct_send_from_system_probe so it stops sending CWS events, but it is never created. --- README.md | 1 + install_script.sh.template | 71 +++++++++++++++- test/e2e/install_no_security_agent_test.go | 94 ++++++++++++++++++++++ unit_tests/test_install_script.sh | 93 +++++++++++++++++++++ 4 files changed, 257 insertions(+), 2 deletions(-) create mode 100644 test/e2e/install_no_security_agent_test.go diff --git a/README.md b/README.md index 33ff9624..d71e47d6 100644 --- a/README.md +++ b/README.md @@ -36,6 +36,7 @@ The install script allows installation of different flavors of the Agent binarie |`DD_SYSTEM_PROBE_ENSURE_CONFIG`|Create the system probe configuration file from a template if it does not already exist.| |`DD_RUNTIME_SECURITY_CONFIG_ENABLED`|If set to `true`, ensure creation of security Agent and system probe configuration file (if they don't already exist), and enable Cloud Workload Security (CWS).| |`DD_COMPLIANCE_CONFIG_ENABLED`|If set to `true`, ensures the creation of a security Agent configuration file if one doesn't already exist, and enables Cloud Security Posture Management (CSPM).| +|`DD_NO_SECURITY_AGENT_INSTALL`|Set to any value to run Cloud Workload Security (CWS) and Cloud Security Posture Management (CSPM) in the system probe instead of the security Agent. With `DD_RUNTIME_SECURITY_CONFIG_ENABLED=true`, CWS is enabled in the system probe configuration file, which also sends the events directly. With `DD_COMPLIANCE_CONFIG_ENABLED=true`, CSPM is enabled in the Agent configuration file and runs in the system probe. The security Agent configuration file is never created, but if it already exists it is updated to tell the security Agent that CWS and CSPM run in the system probe, so that it stops. These settings are applied even when the configuration files are kept from a previous installation.| |`DD_DISCOVERY_ENABLED`|If set to `true`, and a system probe configuration file does not already exist, creates a system probe configuration file and enables Service Discovery. |`DD_PRIVILEGED_LOGS_ENABLED`|If set to `true`, and a system probe configuration file does not already exist, creates a system probe configuration file and enables Privileged Logs. |`DD_SYSTEM_PROBE_SERVICE_MONITORING_ENABLED`|If set to `true`, and a system probe configuration file does not already exist, creates a system probe configuration file and enables Universal Service Monitoring (USM). diff --git a/install_script.sh.template b/install_script.sh.template index ba045b35..f854d358 100644 --- a/install_script.sh.template +++ b/install_script.sh.template @@ -923,6 +923,11 @@ if [ -n "$DD_NO_AGENT_INSTALL" ]; then no_agent=true fi +no_security_agent= +if [ -n "$DD_NO_SECURITY_AGENT_INSTALL" ]; then + no_security_agent=true +fi + infrastructure_mode= if [ -n "$DD_INFRASTRUCTURE_MODE" ]; then infrastructure_mode=$DD_INFRASTRUCTURE_MODE @@ -2275,13 +2280,68 @@ function update_par(){ ${par_config} EOF } +function set_config_option(){ + local sudo_cmd="$1" + local config_file="$2" + local section="$3" + local option="$4" + local value="$5" + if ! $sudo_cmd grep -q "^$section:" "$config_file"; then + printf "\033[34m\n* Setting $section.$option to $value in $config_file\n\033[0m\n" + $sudo_cmd sh -c "cat >> '$config_file'" < /dev/null + manage_security_config "sudo" $security_agent_config_file true true true + sudo test -e $security_agent_config_file + assertEquals 1 $? +} +testNoSecurityAgentFullInstall(){ + # What the install script does on a fresh install with CWS and CSPM enabled + sudo rm $security_agent_config_file $system_probe_config_file 2> /dev/null + sudo cp ${config_file}.example $config_file + manage_security_config "sudo" $security_agent_config_file true true true + manage_system_probe_config "sudo" $system_probe_config_file true false "" false + run_security_in_system_probe "sudo" $config_file $security_agent_config_file $system_probe_config_file true + yamllint -c "$yaml_config" --no-warnings $config_file + assertEquals 0 $? + yamllint -c "$yaml_config" --no-warnings $system_probe_config_file + assertEquals 0 $? + assertEquals "$(sudo yq eval '.compliance_config.enabled' $config_file)" "true" + assertEquals "$(sudo yq eval '.compliance_config.run_in_system_probe' $config_file)" "true" + assertEquals "$(sudo yq eval '.runtime_security_config.enabled' $system_probe_config_file)" "true" + assertEquals "$(sudo yq eval '.runtime_security_config.direct_send_from_system_probe' $system_probe_config_file)" "true" + sudo test -e $security_agent_config_file + assertEquals 1 $? +} +testSecurityAgentSystemProbeNoDirectSend(){ + sudo rm $system_probe_config_file 2> /dev/null + manage_system_probe_config "sudo" $system_probe_config_file true false "" false + yamllint -c "$yaml_config" --no-warnings $system_probe_config_file + assertEquals 0 $? + assertEquals "$(sudo yq eval '.runtime_security_config.enabled' $system_probe_config_file)" "true" + assertEquals "$(sudo yq eval '.runtime_security_config.direct_send_from_system_probe' $system_probe_config_file)" "null" +} + +### Run security in system-probe +testRunSecurityInSystemProbeExistingSecurityAgentConfig(){ + # A security Agent configuration file kept from a previous installation must tell the security + # Agent that both CWS and CSPM run in system-probe + sudo cp ${security_agent_config_file}.example $security_agent_config_file + sudo cp ${config_file}.example $config_file + sudo rm $system_probe_config_file 2> /dev/null + run_security_in_system_probe "sudo" $config_file $security_agent_config_file $system_probe_config_file false + yamllint -c "$yaml_config" --no-warnings $security_agent_config_file + assertEquals 0 $? + assertEquals "$(sudo yq eval '.runtime_security_config.direct_send_from_system_probe' $security_agent_config_file)" "true" + assertEquals "$(sudo yq eval '.compliance_config.run_in_system_probe' $security_agent_config_file)" "true" + assertEquals "$(sudo yq eval '.runtime_security_config.enabled' $security_agent_config_file)" "null" + assertEquals "$(sudo yq eval '.compliance_config.enabled' $security_agent_config_file)" "null" + # CSPM is not enabled, the Agent configuration file must not be updated + assertEquals "$(sudo yq eval '.compliance_config' $config_file)" "null" +} +testRunSecurityInSystemProbeKeptConfiguration(){ + # CWS and CSPM enabled by a previous installation must now run in system-probe + printf 'apm_config:\n enabled: true\n' | sudo tee $config_file > /dev/null + printf 'runtime_security_config:\n enabled: true\n' | sudo tee $system_probe_config_file > /dev/null + printf 'runtime_security_config:\n enabled: true\ncompliance_config:\n enabled: true\n' | sudo tee $security_agent_config_file > /dev/null + run_security_in_system_probe "sudo" $config_file $security_agent_config_file $system_probe_config_file true + yamllint -c "$yaml_config" --no-warnings $config_file + assertEquals 0 $? + # compliance_config must be added even though the Agent configuration file was kept + assertEquals "$(sudo yq eval '.compliance_config.enabled' $config_file)" "true" + assertEquals "$(sudo yq eval '.compliance_config.run_in_system_probe' $config_file)" "true" + assertEquals "$(sudo yq eval '.apm_config.enabled' $config_file)" "true" + assertEquals "$(sudo yq eval '.runtime_security_config.direct_send_from_system_probe' $system_probe_config_file)" "true" + assertEquals "$(sudo yq eval '.runtime_security_config.enabled' $system_probe_config_file)" "true" + assertEquals "$(sudo yq eval '.runtime_security_config.direct_send_from_system_probe' $security_agent_config_file)" "true" + assertEquals "$(sudo yq eval '.compliance_config.run_in_system_probe' $security_agent_config_file)" "true" + # Running it again must not add the options a second time + run_security_in_system_probe "sudo" $config_file $security_agent_config_file $system_probe_config_file true + assertEquals 1 "$(sudo grep -c "direct_send_from_system_probe" $security_agent_config_file)" + assertEquals 1 "$(sudo grep -c "run_in_system_probe" $security_agent_config_file)" + assertEquals 1 "$(sudo grep -c "run_in_system_probe" $config_file)" +} +testRunSecurityInSystemProbeComplianceAlreadyEnabled(){ + # CSPM enabled by a previous installation must run in system-probe, even when + # DD_COMPLIANCE_CONFIG_ENABLED is not set again + printf 'compliance_config:\n enabled: true\n' | sudo tee $config_file > /dev/null + sudo rm $security_agent_config_file $system_probe_config_file 2> /dev/null + run_security_in_system_probe "sudo" $config_file $security_agent_config_file $system_probe_config_file false + assertEquals "$(sudo yq eval '.compliance_config.enabled' $config_file)" "true" + assertEquals "$(sudo yq eval '.compliance_config.run_in_system_probe' $config_file)" "true" +} +testRunSecurityInSystemProbeCreatesNothing(){ + sudo rm $security_agent_config_file $system_probe_config_file $config_file 2> /dev/null + run_security_in_system_probe "sudo" $config_file $security_agent_config_file $system_probe_config_file true + sudo test -e $security_agent_config_file + assertEquals 1 $? + sudo test -e $system_probe_config_file + assertEquals 1 $? + sudo test -e $config_file + assertEquals 1 $? +} + ### Test logs config process collect all function testLogsConfigProcessCollectAll() { sudo rm $config_file 2> /dev/null