Skip to content

Add DD_NO_SECURITY_AGENT_INSTALL option - #459

Open
lebauce wants to merge 1 commit into
mainfrom
lebauce/no-security-agent
Open

lebauce wants to merge 1 commit into
mainfrom
lebauce/no-security-agent

Conversation

@lebauce

@lebauce lebauce commented Sep 24, 2026

Copy link
Copy Markdown
Contributor

Adds DD_NO_SECURITY_AGENT_INSTALL, to run CWS and CSPM in system-probe instead of the security agent.

When it is set:

  • DD_RUNTIME_SECURITY_CONFIG_ENABLED=true → system-probe.yaml gets
    runtime_security_config: {enabled: true, direct_send_from_system_probe: true}
  • DD_COMPLIANCE_CONFIG_ENABLED=true → datadog.yaml gets
    compliance_config: {enabled: true, run_in_system_probe: true}
  • security-agent.yaml is never created. If it already exists, it gets both
    runtime_security_config.direct_send_from_system_probe and compliance_config.run_in_system_probe:
    the datadog-agent-security service starts as soon as that file exists, so the security agent
    needs to read those to know it has nothing to do and stop.

These settings are applied after the configuration files have been written, outside of the
"keeping old configuration file" block, otherwise nothing would happen when reinstalling over an
existing datadog.yaml. A datadog.yaml kept from a previous installation that has CSPM enabled
also gets run_in_system_probe, so compliance doesn't silently stop running.

Everything is idempotent: running the script again reports the options as already set and changes
nothing. set_config_option only looks for an option inside its own section, since names like
enabled are used all over the configuration files.

Also reported in the install telemetry as no_security_agent.

Test

Unit tests for the new functions, and a new TestInstallNoSecurityAgentSuite e2e suite covering a
fresh install (picked up by the existing catch-all e2e jobs).

Manually, in a container: install with CWS + CSPM, uninstall, reinstall with
DD_NO_SECURITY_AGENT_INSTALL=true → the three files get the expected settings, pass yamllint and
keep their ownership; a third run changes nothing.

Run CWS and CSPM without the security agent:

- DD_RUNTIME_SECURITY_CONFIG_ENABLED=true enables runtime security in
  system-probe.yaml with direct_send_from_system_probe, and leaves
  security-agent.yaml alone.
- DD_COMPLIANCE_CONFIG_ENABLED=true enables compliance_config with
  run_in_system_probe in datadog.yaml. An existing security-agent.yaml
  gets direct_send_from_system_probe so it stops sending CWS events,
  but it is never created.
@lebauce
lebauce requested a review from a team as a code owner September 24, 2026 15:44
@lebauce
lebauce requested a review from arbll September 24, 2026 15:44

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b6b7b456a1

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment on lines +2299 to +2301
if $sudo_cmd sed -n "/^$section:/,/^[^[:space:]#]/p" "$config_file" | grep -qE "^[[:space:]]+$option:"; then
printf "\033[34m\n* $section.$option is already set in $config_file, skipping the update.\n\033[0m\n"
return

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Force migration flags to true

When a retained configuration already contains any of these keys with false (for example, compliance_config.enabled: false in datadog.yaml or direct_send_from_system_probe: false in system-probe.yaml), this presence-only check skips the requested update. Consequently, DD_NO_SECURITY_AGENT_INSTALL=true DD_COMPLIANCE_CONFIG_ENABLED=true can leave CSPM disabled or leave CWS sending through the security Agent, despite the migration option explicitly requesting that they run in system-probe. Update the existing value when it conflicts with the required true value rather than treating every pre-existing key as idempotent success.

Useful? React with 👍 / 👎.

@datadog-prod-us1-3

datadog-prod-us1-3 Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Pipelines  Tests

✨ Unblock PR with BitsAI

❌ Errors

Your PR has failed checks. Please review the issues below and take necessary action before merging.

🚦 1 Pipeline job failed

DataDog/agent-linux-install-script | Amazon_Linux_2023_amd64.SIM: [test-app-php-container-83] — 🔧 Needs a code fix, caused by this PR

View more details · View in GitLab

ℹ️ Info

No other issues found (see more)

🧪 All tests passed
❄️ No new flaky tests detected

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: b6b7b45 | Docs | View more details | Give us feedback!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant