Skip to content

[SVLS-9300] add instrumentation configuration flags for ecs-fargate instrument - #2465

Merged
ojproductions merged 3 commits into
onzia/ecs-instrument-command-02from
onzia/ecs-instrument-command-03
Sep 25, 2026
Merged

ojproductions merged 3 commits into
onzia/ecs-instrument-command-02from
onzia/ecs-instrument-command-03

Conversation

@ojproductions

Copy link
Copy Markdown
Contributor

What and why?

Adds the flags that decide how an instrumented task reports to Datadog. Without them the
command produces telemetry that is hard to slice: everything lands under the task
definition family with no environment or version to correlate against.

How?

Unified service tagging (--service, --env, --version, --extra-tags) is written
three ways, so the same task is named identically wherever it shows up:

  • as DD_SERVICE, DD_ENV, DD_VERSION, and DD_TAGS on every container, which is
    what the tracers send;
  • as com.datadoghq.tags.* Docker labels on the application containers, which is what
    the Agent reads to tag the metrics it collects about them from the outside. The Agent
    container is deliberately left unlabelled, so it does not report its own resource usage
    under your service;
  • as tags on the revision itself.

An explicit flag overrides what a container already declares; the task definition family
is only a fallback, and DD_SERVICE, DD_TRACE_ENABLED, and DD_LOGS_INJECTION are
filled in only when the container has not made a choice itself.

Also the product toggles the tracers read (--tracing, --log-level, --appsec,
--llmobs, --env-vars) and the source code integration. Its Git tags are resolved even
on a dry run so the diff shows the DD_TAGS a real run would write, while the metadata
upload — a write to Datadog — is skipped.

Review checklist

  • Feature or bugfix MUST have appropriate tests (unit, integration)

@ojproductions
ojproductions requested review from a team as code owners August 21, 2026 20:37
@ojproductions
ojproductions requested a review from nina9753 August 21, 2026 20:37
@ojproductions
ojproductions changed the base branch from master to onzia/ecs-instrument-command-02 August 21, 2026 20:37
@datadog-official

datadog-official Bot commented Aug 21, 2026 •

Copy link
Copy Markdown

Tests

✅ All CI checks and tests passed.

🎉 All green!

🧪 All tests passed
❄️ No new flaky tests detected

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: ac06b03 | Docs | View more details | Give us feedback!

@ojproductions ojproductions changed the title Onzia/ecs instrument command 03 [SVLS-9300] add instrumentation configuration flags for ecs-fargate instrument Aug 21, 2026
@ojproductions ojproductions added serverless Related to [aas, cloud-run, lambda, stepfunctions, ecs-fargate] enhancement New feature or request labels Aug 21, 2026
@ava-silver

Copy link
Copy Markdown
Collaborator

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5c3513235a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

[ECS_FARGATE_ENV_VAR]: 'true',
[SITE_ENV_VAR]: settings.site,
// The Agent's own trace intake, which is a separate switch from the tracers' `DD_TRACE_ENABLED`.
[DD_APM_ENABLED_ENV_VAR]: String(settings.tracing ?? true),

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Keep the Agent intake enabled for LLM Observability

When --tracing false is combined with --llmobs, this sets DD_APM_ENABLED=false on the sidecar while the application is configured with DD_LLMOBS_AGENTLESS_ENABLED=false, explicitly requiring the sidecar to forward its LLM Observability payloads. The resulting task cannot deliver those payloads; either keep the Agent intake enabled when an Agent-backed product is selected or reject this option combination.

Useful? React with 👍 / 👎.

Comment on lines +435 to +436
const appEnvironment = getAppContainerEnvVars(settings, family)
const appLabels = getUstDockerLabels(settings, family)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Derive labels from each container's effective service

When an application container already declares DD_SERVICE but has no Datadog service Docker label, getAppContainerEnvVars() preserves that value while getUstDockerLabels() independently defaults the label to the task family. For example, a container with DD_SERVICE=checkout in family my-app is registered with com.datadoghq.tags.service=my-app, so its traces and Agent-collected container metrics are assigned to different services. Derive the default label from the container's effective DD_SERVICE, or avoid adding the family label when the container has chosen its own service.

Useful? React with 👍 / 👎.

@ojproductions
ojproductions force-pushed the onzia/ecs-instrument-command-03 branch from 5c35132 to 828a074 Compare August 27, 2026 20:12
@ojproductions
ojproductions force-pushed the onzia/ecs-instrument-command-03 branch from 2aae581 to 1d41bbb Compare September 4, 2026 21:55

@ava-silver ava-silver left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated AI Review (human curated)

The command needs a consistent desired-state model for UST, product settings, and log collection. I also noted one documentation mismatch.


const containers = taskDefinition.containerDefinitions ?? []
const borrowed = borrowedLogConfiguration(containers)
const firelens = settings.logCollection ? firelensLogConfiguration(settings) : undefined

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

When log collection is turned off, firelens becomes undefined and the existing router plus every existing awsfirelens configuration remain unchanged. The command therefore cannot converge back to its default log state, and no ECS uninstrument command exists to clean these CLI-managed artifacts. Add a cleanup path that removes the router and its routing configuration.


if (settings.service) {
managed[SERVICE_ENV_VAR] = settings.service
} else if (family) {

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Using the family as a default here preserves an existing application DD_SERVICE, but the Agent and revision tag use the family. A task with DD_SERVICE=checkout in a payments-worker family then emits traces as checkout and Agent/resource telemetry as payments-worker. Resolve UST once, then apply the same desired state to every Datadog-owned UST destination.

if (settings.tracing !== undefined) {
managed[DD_TRACE_ENABLED_ENV_VAR] = String(settings.tracing)
}
if (settings.appsec) {

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

--no-appsec resolves to false, but this add-only branch leaves an existing DD_APPSEC_ENABLED=true untouched. The same desired-state issue applies to disabling source-code integration and omitting other new settings. Resolve each setting to an enabled value or absence, then apply or remove its Datadog-owned fields consistently.

})
private envVars = Option.Array('-e,--env-vars', {
description:
'Additional environment variables to set on every container in the task. Can specify multiple variables in the format `--env-vars VAR1=VALUE1 --env-vars VAR2=VALUE2`.',

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This says every container, but with --log-collection the transform deliberately excludes datadog-log-router from envVars. Please describe this as applying to application containers and the Datadog Agent.

@ojproductions
ojproductions force-pushed the onzia/ecs-instrument-command-03 branch from bdb2fd9 to 7177257 Compare September 10, 2026 14:27
@ojproductions
ojproductions force-pushed the onzia/ecs-instrument-command-03 branch from 7177257 to 027a089 Compare September 10, 2026 14:47
@ojproductions
ojproductions force-pushed the onzia/ecs-instrument-command-03 branch 2 times, most recently from 9ceffa4 to 8a010fd Compare September 10, 2026 20:12
@ojproductions
ojproductions force-pushed the onzia/ecs-instrument-command-03 branch from 8a010fd to 15b0eae Compare September 11, 2026 14:12
@ojproductions
ojproductions force-pushed the onzia/ecs-instrument-command-03 branch from 15b0eae to d2d53ec Compare September 14, 2026 18:10
@ojproductions
ojproductions force-pushed the onzia/ecs-instrument-command-03 branch from d2d53ec to 4c7047f Compare September 15, 2026 14:58
@ojproductions
ojproductions force-pushed the onzia/ecs-instrument-command-03 branch 2 times, most recently from 00803c3 to 2742bd9 Compare September 16, 2026 20:08
@ojproductions
ojproductions force-pushed the onzia/ecs-instrument-command-03 branch from 2742bd9 to 110bddd Compare September 21, 2026 16:38
@ojproductions
ojproductions force-pushed the onzia/ecs-instrument-command-03 branch from 110bddd to ac06b03 Compare September 21, 2026 16:40
@ojproductions
ojproductions merged commit 0d270b2 into master Sep 25, 2026
36 checks passed
@ojproductions
ojproductions deleted the onzia/ecs-instrument-command-03 branch September 25, 2026 18:31
@Drarig29 Drarig29 mentioned this pull request Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request serverless Related to [aas, cloud-run, lambda, stepfunctions, ecs-fargate]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants