tekton: add container-based config discovery support#24526
Draft
vitkyrka wants to merge 8 commits into
Draft
Conversation
Add a discovery strategy and auto_conf.yaml for the keda-operator-metrics-apiserver component so the Agent's Kubernetes Autodiscovery listener can automatically generate an openmetrics_endpoint configuration for it. Environment: Datadog workspace Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Environment: Datadog workspace Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Adds datadog_checks_dev/datadog_checks/dev/kube_discovery.py, a new module providing Kubelet-Autodiscovery e2e test helpers. It deploys a sleeping, RBAC-scoped Agent pod inside the integration's existing kind cluster and execs `agent check` into it, so config-discovery can be exercised via real Kubelet Autodiscovery without a full long-running in-cluster Agent. Wires keda's conftest.py/test_e2e.py up to the new helpers, restoring keda's previously-dropped test_e2e_discovery and adding test_e2e_discovery_all_candidates. Environment: Datadog workspace Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Environment: Datadog workspace Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
env test/env stop re-run the dd_environment fixture body to reach kind_run's teardown, but KUBECONFIG isn't guaranteed to resolve to a live cluster at that point. setup_discovery_agent()/save_kube_discovery_state() were running unconditionally, so env stop tried to kubectl apply against a stale/empty kubeconfig and errored (harmlessly, since kind_run's own teardown still ran, but noisily). Gate both on set_up_env(), matching how KindUp/ComposeFileUp/ PortForwardUp already behave. Verified via a real start/test/stop cycle against keda's kind cluster. Environment: Datadog workspace Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Some checks (e.g. kubevirt_api) need RBAC beyond the base discovery agent's minimal ClusterRole to make their Kubernetes API calls - discovery-generated candidates have no way to supply kube_config_dict, so the check falls back to in-cluster credentials, which need a CRD-provided view role (e.g. kubevirt.io:view) bound to the agent's service account. extra_cluster_roles lets a per-integration E2E fixture bind additional, already-existing ClusterRoles for exactly this case. Backward compatible: keyword-only, defaults to an empty tuple, so every existing setup_discovery_agent() call is unaffected. Environment: Datadog workspace Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Adds a from_ports discovery strategy scoped to the Pipelines Controller (port 9090, ad_identifiers matched on its ko-published image name), wires setup_discovery_agent()/save_kube_discovery_state() into the kind-based E2E fixture, and adds test_e2e_discovery/test_e2e_discovery_all_candidates. The Triggers Controller's metrics port isn't covered since it has no containerPort declared on its pod spec, only a Service port. Environment: Datadog workspace Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Environment: Datadog workspace Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Contributor
Validation ReportAll 21 validations passed. Show details
|
🎉 All green!🧪 All tests passed 🎯 Code Coverage (details) 🔗 Commit SHA: 9435620 | Docs | Datadog PR Page | Give us feedback! |
vitkyrka
force-pushed
the
vwhitchurch/keda-discovery
branch
3 times, most recently
from
July 17, 2026 13:53
d43155c to
ade09a4
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this PR do?
Adds container-based config discovery support to tekton.
Known gap: the Triggers Controller's metrics endpoint (
triggers_controller_endpoint, port 9000) is not covered by this PR. Its Deployment declares nocontainerPorton the pod spec at all — the port is only exposed via a separately-created KubernetesServiceobject (confirmed both in the upstreamtektoncd/triggersrelease manifests and on a live cluster viakubectl get pod -o yaml). The Agent's Kubelet-based Autodiscovery derives candidate ports from a pod's own declared container ports, so it never sees this port — the same class of limitation documented for Calico's own discovery attempt. Only the Pipelines Controller (port 9090, which does declare acontainerPortnamedmetrics) is covered here.AD identifier: Tekton's official release images are built with
koand published under content-hash-suffixed names (e.g.ghcr.io/tektoncd/pipeline/controller-10a3e32792f33651396d02b6855a6e36) rather than a human-readable short name. This hash is stable across releases — confirmed identical between thetektoncd/pipelinev1.0.0andv1.14.0GitHub release manifests — and is the exact image every real deployment applying the standard release YAML runs, so it's used verbatim as thead_identifiersvalue.Base branch note: this branch is based on the not-yet-merged
vwhitchurch/keda-discoverybranch, which adds the shared Kubernetes-discovery E2E helpers (datadog_checks_dev/datadog_checks/dev/kube_discovery.py) this PR depends on. The diff againstmastertherefore also includes keda's own discovery changes; rebase ontomasteronce that branch merges.Port selection rationale: Port 9090 is the Pipelines Controller's official documented default Prometheus metrics port.
Motivation
https://datadoghq.atlassian.net/browse/DSCVR-609
Review checklist (to be filled by reviewers)
qa/requiredif this PR needs QA validation, orqa/skip-qaif it does not. Exactly one of the two is required.backport/<branch-name>label to the PR and it will automatically open a backport PR once this one is merged