* [stable/datadog] v2.0.0 cleaning and refactoring
* Remove Datadog agent deployment configuration.
* Cleanup resources labels, to fit with recommended labels.
* Cleanup useless or unused values parameters.
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* [stable/datadog] cleanup refactor RBAC resources
* each component have its own RBAC configuration (create,configuration).
* container runtime socket update values configuration simplification.
* `nameOverride` `fullnameOverride` is now optional in values.yaml
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* update stable/datadog/ci values.yaml
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* [datadog] fix linter error
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* [datadog] fix missing merge
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* refactor values.yaml
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* update value.yaml
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* Add a table with the correspondence between the v1 and v2 parameters
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* templates: enable APM by default
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* Leave apm.enabled setting but change default.
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* DD_APM_NON_LOCAL_TRAFFIC=true when apm.enabled is true
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* Enable hostPort binding 8126 by default when apm.enabled is true.
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* values: make apm.enabled default to false
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* Address PR comments.
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* refactor dogstatsd parameters
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* update after comments
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* fix dogstatsd parameters path
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* update system-probe manifest after review
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* update ci configuration and fix cluster-agent config
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* change cluster-agent probes endpoint
change the cluster-agent probes endpoint in order to be resilent if
never the datadog api is not reachable.
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* Fix several typo thanks to contributions
Include: #20460#20449
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* adding new approvers/reviewers
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* [stable/datadog] add resoures field for init-containers
Fixe: #20035
Include: #20461
Add the possibility to overwrite the resources associated to the
init-containers.
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* update after review
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* return error message if apiKey is not provided
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* Mount the directory containing the CRI socket instead of the socket itself (#5)
This is to handle the cases where the docker daemon is restarted.
In this case, the docker daemon will recreate its docker socket and,
if the container bind-mounted directly the socket, the container would
still have access to the old socket instead of the one of the new docker
daemon.
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
Co-authored-by: Lénaïc Huard <L3n41c@users.noreply.github.com>
Co-authored-by: Gabriel Aszalos <gabriel.aszalos@datadoghq.com>
* Fixes issue with trace-agent only listening on localhost
Currently the `trace-agent` only listens on `localhost` regardless whether `nonLocalTraffic` is true or not.
This fixes that by checking if `nonLocalTraffic: true` then we set the correct environment variables in the trace-agent pods
Signed-off-by: Danny Carrillo <odannycx@gmail.com>
* Update Chart.yaml
Signed-off-by: Danny Carrillo <odannycx@gmail.com>
* Update datadog-yaml-configmap.yaml
Current configuration is causing issue with enabling APM for nonlocal traffic.
Here is what it currently looks like in the containers /etc/datadog/datadog.yaml file:
apm_config:
enabled: false
apm_non_local_traffic: true# tag 6 was introduce with 6.15
Signed-off-by: Jeffrey Scelza <jeffrey.scelza@checkr.com>
* Bumping up version of Datadog Chart
Signed-off-by: Jeffrey Scelza <jeffrey.scelza@checkr.com>
Fix the usage of the `.Values.datadog.site` and `.Values.datadog.dd_url`
parameters when `.Values.daemonset.useDedicatedContainers` is activated.
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* fix syntax error in templates/datadog-yaml-configmap.yaml
Signed-off-by: Alex Jones <ajones@agari.com>
* Up chart version since new versions of the chart have been merged since PR was opened
Signed-off-by: Alex Jones <ajones@agari.com>
* [stable/datadog] allow dogstatsd port to be variable
Signed-off-by: John Pekcan <johnpekcan@gmail.com>
* need to uncomment customAgentConfig
Signed-off-by: John Pekcan <johnpekcan@gmail.com>
* leave dogstatsd port empty in values.yaml
Signed-off-by: John Pekcan <johnpekcan@gmail.com>
* spacing for comments
Signed-off-by: John Pekcan <johnpekcan@gmail.com>
* need to leave dogstatsd_port uncommented
Signed-off-by: John Pekcan <johnpekcan@gmail.com>
* taking feedback, moving var around
Signed-off-by: John Pekcan <johnpekcan@gmail.com>
* fixing camelCase, and adding env var for statsd
Signed-off-by: John Pekcan <johnpekcan@gmail.com>
* bumping version with sign off
Signed-off-by: John Pekcan <johnpekcan@gmail.com>
* relocating the param in readme
Signed-off-by: John Pekcan <johnpekcan@gmail.com>
* Datadog: remove hard coded names
* The new system-probe container and config used hard coded CongigMap
names meaning only one installation is possible per cluster and
namespace.
Signed-off-by: Matt Klich <matt@elementalvoid.com>
* bump version
Signed-off-by: David J. M. Karlsen <david@davidkarlsen.com>
The cluster name parameter has been introduced to disambiguate nodes
having the same name in different clusters.
Cluster names are, for ex., used to build hostnames and must therefore
comply with some rules.
We enforce here the same rules as the ones enforced by GKE:
https://cloud.google.com/kubernetes-engine/docs/reference/rest/v1beta1/projects.locations.clusters#Cluster.FIELDS.name
The DataDog agent itself is already checking the validity of cluster names since
DataDog/datadog-agent#4492.
The goal of this change in the helm chart is to catch issues as early as possible because
having a clear error message from helm is smarter than having to dig in the logs of
a failing agent.
Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
* [stable/datadog] Remove the seccomp profile for system-probe
The `system-probe` container currently has a specific seccomp profile.
This seccomp profile currently misses some syscalls that are necessary to
exec inside the container.
Concretely, attempting to exec inside the container produces this error:
```
$ kubectl exec -ti datadog-fswnc -c system-probe /bin/bash
shell-init: error retrieving current directory: getcwd: cannot access parent directories: Operation not permitted
bash: initialize_job_control: getpgrp failed: Operation not permitted
command terminated with exit code 1
```
If we add `setpgrp` to the seccomp profile, we get:
```
$ kubectl exec -ti datadog-kbg97 -c system-probe /bin/bash
shell-init: error retrieving current directory: getcwd: cannot access parent directories: Operation not permitted
I have no name!@datadog-kbg97:.$ exit
```
If we add `getcwd`, we get:
```
$ kubectl exec -ti datadog-7b7lf -c system-probe /bin/bash
I have no name!@datadog-7b7lf:/$ exit
```
If we add `geteuid` and `geteuid32`, we get:
```
$ kubectl exec -ti datadog-c42rb -c system-probe /bin/bash
/bin/bash: cannot set uid to -1: effective uid 0: Invalid argument
/bin/bash: cannot set gid to -1: effective gid -1: Invalid argument
bash-5.0$ exit
```
If we get `getgid` and `getgid32`, we get:
```
$ kubectl exec -ti datadog-tp4qd -c system-probe /bin/bash
/bin/bash: cannot set uid to -1: effective uid 0: Invalid argument
bash-5.0$ exit
```
etc.
If we compare the seccomp profile of `system-probe` with the
[default one](https://github.com/moby/moby/blob/4b0371fb36a958589319ab7c501ff4bc22645cfa/profiles/seccomp/default.json),
we see that a lot of syscalls that are missing are innocuous (`getcwd`) or might become useful one day (`inotify` family)
Some syscalls are added on purpose for the `system-probe` container like `bpf` or `perf_event_open` ones.
But those syscalls are part of the [default seccomp profile for containers that have the `SYS_ADMIN` capability](https://github.com/moby/moby/blob/4b0371fb36a958589319ab7c501ff4bc22645cfa/profiles/seccomp/default.json#L567-L594),
and the [`system-probe` container do have the `SYS_ADMIN` capability](https://github.com/helm/charts/blob/3907cebc7042f452506a7471f912d6d0c8380e51/stable/datadog/templates/container-system-probe.yaml#L7).
So, the `system-probe` specific seccomp profile is not necessary to have the `system-probe` container able to load eBPF programs.
Its removal has been tested on GKE, both with Ubuntu and with Container-Optimized OS
and both with docker and containerd.
Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
* Make the ad-hoc seccomp profile for system-probe an option
which is enabled by default to stick with the current behavior.
Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
* [stable/datadog] Allow use of any arbitrary seccomp profile
…for system-probe.
By default, it will create an ad-hoc one.
Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
* [stable/datadog] Add a CI test for seccomp profile override
Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
When `processAgentEnabled` is not set, trying to instantiate the datadog chart caused the following error:
```
Error: release datadog failed: DaemonSet.apps "datadog" is invalid: spec.template.spec.containers[1].volumeMounts[2].name: Not found: "passwd"
```
Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
* Update stable/datadog application to 6.13.0
* Bump the chart version to `1.33.0`
* Update the application version to `6.13.0`
* Update Kube-State-Metrics version to `1.7.2` with chart `2.2.3`
* Fix wrong indentation in kube-state-metrics parameters
* Document the possibility to overwrite KSM container resources
* Add ci/*-values.yaml files for CI validation
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* temporary remove stable/datadog/ci folder
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
* add in comment example
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
Using double-sided whitespace trimming (something like `{{- end -}}` can be
dangerous anywhere other than at the very beginning and the very end of a
template file, because it trims carriage returns. This makes it possible to
inadvertently create a manifest like the following:
```yaml
apiVersion: "rbac.authorization.k8s.io/v1"
kind: ClusterRoleBinding
metadata:
labels:
app: "datadog"
chart: "datadog-1.31.8"
release: "datadog"
heritage: "Tiller"
name: datadog
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: datadog
subjects:
- kind: ServiceAccount
name: datadog
namespace: datadog---
apiVersion: v1
kind: ServiceAccount
metadata:
labels:
app: "datadog"
chart: "datadog-1.31.8"
heritage: "Tiller"
release: "datadog"
name: datadog
---
```
Signed-off-by: Steve Huff <shuff@vecna.org>
* ensure init scripts run in correct order
Signed-off-by: Joe Hohertz <joe@viafoura.com>
* re-bump chart version
Signed-off-by: Joe Hohertz <joe@viafoura.com>