Skip to content

tekton: add container-based config discovery support#24526

Draft
vitkyrka wants to merge 8 commits into
vwhitchurch/keda-discoveryfrom
vwhitchurch/tekton-discovery
Draft

tekton: add container-based config discovery support#24526
vitkyrka wants to merge 8 commits into
vwhitchurch/keda-discoveryfrom
vwhitchurch/tekton-discovery

Conversation

@vitkyrka

Copy link
Copy Markdown
Contributor

What does this PR do?

Adds container-based config discovery support to tekton.

Known gap: the Triggers Controller's metrics endpoint (triggers_controller_endpoint, port 9000) is not covered by this PR. Its Deployment declares no containerPort on the pod spec at all — the port is only exposed via a separately-created Kubernetes Service object (confirmed both in the upstream tektoncd/triggers release manifests and on a live cluster via kubectl get pod -o yaml). The Agent's Kubelet-based Autodiscovery derives candidate ports from a pod's own declared container ports, so it never sees this port — the same class of limitation documented for Calico's own discovery attempt. Only the Pipelines Controller (port 9090, which does declare a containerPort named metrics) is covered here.

AD identifier: Tekton's official release images are built with ko and published under content-hash-suffixed names (e.g. ghcr.io/tektoncd/pipeline/controller-10a3e32792f33651396d02b6855a6e36) rather than a human-readable short name. This hash is stable across releases — confirmed identical between the tektoncd/pipeline v1.0.0 and v1.14.0 GitHub release manifests — and is the exact image every real deployment applying the standard release YAML runs, so it's used verbatim as the ad_identifiers value.

Base branch note: this branch is based on the not-yet-merged vwhitchurch/keda-discovery branch, which adds the shared Kubernetes-discovery E2E helpers (datadog_checks_dev/datadog_checks/dev/kube_discovery.py) this PR depends on. The diff against master therefore also includes keda's own discovery changes; rebase onto master once that branch merges.

Port selection rationale: Port 9090 is the Pipelines Controller's official documented default Prometheus metrics port.

Motivation

https://datadoghq.atlassian.net/browse/DSCVR-609

Review checklist (to be filled by reviewers)

  • Feature or bugfix MUST have appropriate tests (unit, integration, e2e)
  • Add qa/required if this PR needs QA validation, or qa/skip-qa if it does not. Exactly one of the two is required.
  • If you need to backport this PR to another branch, you can add the backport/<branch-name> label to the PR and it will automatically open a backport PR once this one is merged

vitkyrka and others added 7 commits July 9, 2026 13:15
Add a discovery strategy and auto_conf.yaml for the keda-operator-metrics-apiserver
component so the Agent's Kubernetes Autodiscovery listener can automatically
generate an openmetrics_endpoint configuration for it.

Environment: Datadog workspace

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Environment: Datadog workspace

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Adds datadog_checks_dev/datadog_checks/dev/kube_discovery.py, a new module
providing Kubelet-Autodiscovery e2e test helpers. It deploys a sleeping,
RBAC-scoped Agent pod inside the integration's existing kind cluster and
execs `agent check` into it, so config-discovery can be exercised via real
Kubelet Autodiscovery without a full long-running in-cluster Agent.

Wires keda's conftest.py/test_e2e.py up to the new helpers, restoring
keda's previously-dropped test_e2e_discovery and adding
test_e2e_discovery_all_candidates.

Environment: Datadog workspace

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Environment: Datadog workspace

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
env test/env stop re-run the dd_environment fixture body to reach kind_run's
teardown, but KUBECONFIG isn't guaranteed to resolve to a live cluster at that
point. setup_discovery_agent()/save_kube_discovery_state() were running
unconditionally, so env stop tried to kubectl apply against a stale/empty
kubeconfig and errored (harmlessly, since kind_run's own teardown still ran,
but noisily). Gate both on set_up_env(), matching how KindUp/ComposeFileUp/
PortForwardUp already behave. Verified via a real start/test/stop cycle
against keda's kind cluster.

Environment: Datadog workspace

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Some checks (e.g. kubevirt_api) need RBAC beyond the base discovery
agent's minimal ClusterRole to make their Kubernetes API calls -
discovery-generated candidates have no way to supply kube_config_dict,
so the check falls back to in-cluster credentials, which need a
CRD-provided view role (e.g. kubevirt.io:view) bound to the agent's
service account. extra_cluster_roles lets a per-integration E2E fixture
bind additional, already-existing ClusterRoles for exactly this case.

Backward compatible: keyword-only, defaults to an empty tuple, so
every existing setup_discovery_agent() call is unaffected.

Environment: Datadog workspace

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Adds a from_ports discovery strategy scoped to the Pipelines Controller
(port 9090, ad_identifiers matched on its ko-published image name), wires
setup_discovery_agent()/save_kube_discovery_state() into the kind-based E2E
fixture, and adds test_e2e_discovery/test_e2e_discovery_all_candidates. The
Triggers Controller's metrics port isn't covered since it has no
containerPort declared on its pod spec, only a Service port.

Environment: Datadog workspace

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@vitkyrka vitkyrka added the qa/skip-qa Automatically skip this PR for the next QA label Jul 11, 2026 — with ddtool CLI
Environment: Datadog workspace

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@dd-octo-sts

dd-octo-sts Bot commented Jul 11, 2026

Copy link
Copy Markdown
Contributor

Validation Report

All 21 validations passed.

Show details
Validation Description Status
agent-reqs Verify check versions match the Agent requirements file
ci Validate CI configuration and code coverage settings
codeowners Validate every integration has a CODEOWNERS entry
config Validate default configuration files against spec.yaml
dep Verify dependency pins are consistent and Agent-compatible
http Validate integrations use the HTTP wrapper correctly
imports Validate check imports do not use deprecated modules
integration-style Validate check code style conventions
jmx-metrics Validate JMX metrics definition files and config
labeler Validate PR labeler config matches integration directories
legacy-signature Validate no integration uses the legacy Agent check signature
license-headers Validate Python files have proper license headers
licenses Validate third-party license attribution list
metadata Validate metadata.csv metric definitions
models Validate configuration data models match spec.yaml
openmetrics Validate OpenMetrics integrations disable the metric limit
package Validate Python package metadata and naming
qa-label Validate the pull request declares whether it needs QA for the next Agent release
readmes Validate README files have required sections
saved-views Validate saved view JSON file structure and fields
version Validate version consistency between package and changelog

View full run

@datadog-prod-us1-5

Copy link
Copy Markdown

Tests  Code Coverage

🎉 All green!

🧪 All tests passed
❄️ No new flaky tests detected

🎯 Code Coverage (details)
Patch Coverage: 33.33%
Overall Coverage: 71.01% (-17.39%)

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 9435620 | Docs | Datadog PR Page | Give us feedback!

@vitkyrka
vitkyrka force-pushed the vwhitchurch/keda-discovery branch 3 times, most recently from d43155c to ade09a4 Compare July 17, 2026 13:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation integration/tekton qa/skip-qa Automatically skip this PR for the next QA

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant