Skip to content

[ACTP] wire split runner ownership - #54594

Draft
embeaken wants to merge 1 commit into
ilya/par-control-orchestrationfrom
ilya/par-control-runner-wiring
Draft

[ACTP] wire split runner ownership#54594
embeaken wants to merge 1 commit into
ilya/par-control-orchestrationfrom
ilya/par-control-runner-wiring

Conversation

@embeaken

@embeaken embeaken commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

What does this PR do?

Makes the monolithic Go runner stand down when split mode is enabled on supported Linux and Windows host installations.

Containers and unsupported platforms keep the monolithic runner because they do not yet launch the complete replacement topology. This preserves the invariant that exactly one runner polls OPMS without disabling the only available runner.

Validation

  • bazel test //comp/privateactionrunner/impl:impl_test

Tests cover Linux and Windows hosts, containers, and unsupported platforms.

Stack 8 of 9; based on #54593 and followed by #54529.

@dd-octo-sts

dd-octo-sts Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

Go Package Import Differences

Baseline: 296059f
Comparison: 6a43ffd

binaryosarchchange
agentlinuxamd64
+9, -0
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/def
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/fx
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/impl
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/adapters/constants
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/libs/connection
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/libs/privateconnection
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/signingkeys
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/types
+github.com/DataDog/datadog-agent/pkg/proto/pbgo/privateactionrunner/privateactions
agentlinuxarm64
+9, -0
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/def
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/fx
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/impl
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/adapters/constants
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/libs/connection
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/libs/privateconnection
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/signingkeys
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/types
+github.com/DataDog/datadog-agent/pkg/proto/pbgo/privateactionrunner/privateactions
agentwindowsamd64
+9, -0
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/def
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/fx
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/impl
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/adapters/constants
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/libs/connection
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/libs/privateconnection
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/signingkeys
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/types
+github.com/DataDog/datadog-agent/pkg/proto/pbgo/privateactionrunner/privateactions
agentdarwinamd64
+9, -0
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/def
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/fx
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/impl
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/adapters/constants
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/libs/connection
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/libs/privateconnection
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/signingkeys
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/types
+github.com/DataDog/datadog-agent/pkg/proto/pbgo/privateactionrunner/privateactions
agentdarwinarm64
+9, -0
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/def
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/fx
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/impl
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/adapters/constants
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/libs/connection
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/libs/privateconnection
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/signingkeys
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/types
+github.com/DataDog/datadog-agent/pkg/proto/pbgo/privateactionrunner/privateactions
agentaixppc64
+9, -0
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/def
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/fx
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/impl
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/adapters/constants
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/libs/connection
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/libs/privateconnection
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/signingkeys
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/types
+github.com/DataDog/datadog-agent/pkg/proto/pbgo/privateactionrunner/privateactions
iot-agentlinuxamd64
+9, -0
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/def
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/fx
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/impl
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/adapters/constants
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/libs/connection
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/libs/privateconnection
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/signingkeys
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/types
+github.com/DataDog/datadog-agent/pkg/proto/pbgo/privateactionrunner/privateactions
iot-agentlinuxarm64
+9, -0
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/def
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/fx
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/impl
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/adapters/constants
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/libs/connection
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/libs/privateconnection
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/signingkeys
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/types
+github.com/DataDog/datadog-agent/pkg/proto/pbgo/privateactionrunner/privateactions
heroku-agentlinuxamd64
+9, -0
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/def
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/fx
+github.com/DataDog/datadog-agent/comp/privateactionrunner/signingkeys/impl
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/adapters/constants
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/libs/connection
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/libs/privateconnection
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/signingkeys
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/types
+github.com/DataDog/datadog-agent/pkg/proto/pbgo/privateactionrunner/privateactions
cluster-agentlinuxamd64
+1, -0
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/signingkeys
cluster-agentlinuxarm64
+1, -0
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/signingkeys
privateactionrunnerlinuxamd64
+3, -0
+github.com/DataDog/datadog-agent/cmd/privateactionrunner/subcommands/bootstrapparcontrol
+github.com/DataDog/datadog-agent/cmd/privateactionrunner/subcommands/identity
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/signingkeys
privateactionrunnerlinuxarm64
+3, -0
+github.com/DataDog/datadog-agent/cmd/privateactionrunner/subcommands/bootstrapparcontrol
+github.com/DataDog/datadog-agent/cmd/privateactionrunner/subcommands/identity
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/signingkeys
privateactionrunnerwindowsamd64
+3, -0
+github.com/DataDog/datadog-agent/cmd/privateactionrunner/subcommands/bootstrapparcontrol
+github.com/DataDog/datadog-agent/cmd/privateactionrunner/subcommands/identity
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/signingkeys
privateactionrunnerdarwinamd64
+3, -0
+github.com/DataDog/datadog-agent/cmd/privateactionrunner/subcommands/bootstrapparcontrol
+github.com/DataDog/datadog-agent/cmd/privateactionrunner/subcommands/identity
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/signingkeys
privateactionrunnerdarwinarm64
+3, -0
+github.com/DataDog/datadog-agent/cmd/privateactionrunner/subcommands/bootstrapparcontrol
+github.com/DataDog/datadog-agent/cmd/privateactionrunner/subcommands/identity
+github.com/DataDog/datadog-agent/pkg/privateactionrunner/signingkeys

@embeaken
embeaken force-pushed the ilya/par-control-runner-wiring branch from 0b5d53f to ac1c717 Compare August 7, 2026 18:32
@embeaken
embeaken force-pushed the ilya/par-control-orchestration branch from a8be707 to 082615f Compare August 7, 2026 18:32
@datadog-datadog-us1-prod

datadog-datadog-us1-prod Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

🎯 Code Coverage (details)
Patch Coverage: 57.14%
Overall Coverage: 52.66% (-0.00%)

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 6a43ffd | Docs | View more details | Give us feedback!

@github-actions github-actions Bot added the medium review PR review might take time label Aug 7, 2026
@dd-octo-sts

dd-octo-sts Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

Files inventory check summary

File checks results against ancestor 296059ff:

Results for datadog-agent_7.84.0~devel.git.460.6a43ffd.pipeline.132944293-1_amd64.deb:

No change detected

Results for datadog-iot-agent_7.84.0~devel.git.460.6a43ffd.pipeline.132944293-1_amd64.deb:

No change detected

@dd-octo-sts

dd-octo-sts Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

Static quality checks

❌ Please find below the results from static quality gates
Comparison made with ancestor 296059f
📊 Static Quality Gates Dashboard
🔗 SQG Job

Error

Quality gate Change Size (prev → curr → max)
agent_rpm_arm64 (on disk) +297.08 KiB (0.04% increase, -1133.88% of buffer) 737.104 → 737.395 → 737.130
agent_suse_arm64 (on disk) +297.08 KiB (0.04% increase, -1133.88% of buffer) 737.104 → 737.395 → 737.130
docker_agent_arm64 (on disk) +297.01 KiB (0.04% increase, -163.03% of buffer) 820.712 → 821.002 → 820.890
docker_agent_jmx_amd64 (on disk) +304.41 KiB (0.03% increase, -122.84% of buffer) 1010.658 → 1010.955 → 1010.900
Gate failure full details
Quality gate Error type Error message
agent_rpm_arm64 AbsoluteLimitExceeded static_quality_gate_agent_rpm_arm64 failed!
Disk size 737.4 MB exceeds limit of 737.1 MB by 270.9 KB
agent_suse_arm64 AbsoluteLimitExceeded static_quality_gate_agent_suse_arm64 failed!
Disk size 737.4 MB exceeds limit of 737.1 MB by 270.9 KB
docker_agent_arm64 AbsoluteLimitExceeded static_quality_gate_docker_agent_arm64 failed!
Disk size 821.0 MB exceeds limit of 820.9 MB by 114.8 KB
docker_agent_jmx_amd64 AbsoluteLimitExceeded static_quality_gate_docker_agent_jmx_amd64 failed!
Disk size 1011.0 MB exceeds limit of 1010.9 MB by 56.6 KB

Static quality gate failures prevent this PR from merging!
You can check the static quality gates runbooks page for guidance and tools. Please either fix the size violation or request an exception.

Successful checks

Info

Quality gate Change Size (prev → curr → max)
agent_deb_amd64 +312.46 KiB (0.04% increase, -8.92% of buffer) 761.181 → 761.486 → 764.600
agent_deb_amd64_fips +256.18 KiB (0.04% increase, -13.11% of buffer) 713.931 → 714.182 → 715.840
agent_heroku_amd64 +128.75 KiB (0.04% increase, -2.03% of buffer) 312.896 → 313.021 → 319.080
agent_msi +268.7 KiB (0.04% increase, -1.99% of buffer) 647.835 → 648.097 → 661.050
agent_rpm_amd64 +312.46 KiB (0.04% increase, -8.96% of buffer) 761.165 → 761.470 → 764.570
agent_rpm_amd64_fips +256.18 KiB (0.04% increase, -13.00% of buffer) 713.915 → 714.165 → 715.840
agent_rpm_arm64_fips +248.73 KiB (0.04% increase, -35.42% of buffer) 693.134 → 693.377 → 693.820
agent_suse_amd64 +312.46 KiB (0.04% increase, -8.96% of buffer) 761.165 → 761.470 → 764.570
agent_suse_amd64_fips +256.18 KiB (0.04% increase, -13.00% of buffer) 713.915 → 714.165 → 715.840
agent_suse_arm64_fips +248.73 KiB (0.04% increase, -35.42% of buffer) 693.134 → 693.377 → 693.820
docker_agent_amd64 +304.4 KiB (0.04% increase, -78.32% of buffer) 819.760 → 820.058 → 820.140
docker_agent_jmx_arm64 +297.01 KiB (0.03% increase, -94.20% of buffer) 1000.262 → 1000.552 → 1000.570
docker_cluster_agent_amd64 +20.16 KiB (0.01% increase, -2.78% of buffer) 211.422 → 211.442 → 212.130
docker_cluster_agent_arm64 +64.15 KiB (0.03% increase, -8.22% of buffer) 224.458 → 224.520 → 225.220
docker_dogstatsd_amd64 +8.06 KiB (0.02% increase, -0.86% of buffer) 39.522 → 39.530 → 40.440
docker_host_profiler_amd64 +20.62 KiB (0.01% increase, -0.19% of buffer) 306.843 → 306.863 → 317.700
docker_host_profiler_arm64 +3.06 KiB (0.00% increase, -0.03% of buffer) 318.121 → 318.123 → 328.970
dogstatsd_deb_amd64 +4.06 KiB (0.01% increase, -0.42% of buffer) 30.267 → 30.271 → 31.210
dogstatsd_deb_arm64 +4.06 KiB (0.01% increase, -0.31% of buffer) 28.294 → 28.298 → 29.590
dogstatsd_rpm_amd64 +4.06 KiB (0.01% increase, -0.42% of buffer) 30.267 → 30.271 → 31.210
dogstatsd_suse_amd64 +4.06 KiB (0.01% increase, -0.42% of buffer) 30.267 → 30.271 → 31.210
iot_agent_deb_amd64 +80.66 KiB (0.17% increase, -7.90% of buffer) 46.553 → 46.632 → 47.550
iot_agent_deb_arm64 +76.62 KiB (0.17% increase, -7.38% of buffer) 43.206 → 43.281 → 44.220
iot_agent_deb_armhf +84.4 KiB (0.19% increase, -8.08% of buffer) 44.000 → 44.083 → 45.020
iot_agent_rpm_amd64 +80.66 KiB (0.17% increase, -7.91% of buffer) 46.554 → 46.633 → 47.550
iot_agent_suse_amd64 +80.66 KiB (0.17% increase, -7.90% of buffer) 46.553 → 46.632 → 47.550
3 successful checks with minimal change (< 2 KiB)
Quality gate Current Size
docker_cws_instrumentation_amd64 7.443 MiB
docker_cws_instrumentation_arm64 6.877 MiB
docker_dogstatsd_arm64 37.623 MiB

@embeaken
embeaken force-pushed the ilya/par-control-orchestration branch from 082615f to 3292a06 Compare August 7, 2026 20:39
@embeaken
embeaken force-pushed the ilya/par-control-runner-wiring branch from ac1c717 to 5bb09ad Compare August 7, 2026 20:39
@embeaken
embeaken force-pushed the ilya/par-control-orchestration branch from 3292a06 to 940c82e Compare August 7, 2026 20:57
@embeaken
embeaken force-pushed the ilya/par-control-runner-wiring branch from 5bb09ad to 492099e Compare August 7, 2026 20:57
@cit-pr-commenter-54b7da

cit-pr-commenter-54b7da Bot commented Aug 7, 2026

Copy link
Copy Markdown

Regression Detector

Regression Detector Results

Metrics dashboard
Target profiles
Job ID: 2394ccdb-b78c-4e29-b859-cd881e7f9d0b

Baseline: c45db9e
Comparison: 6a43ffd
Diff

Optimization Goals: ✅ No significant changes detected

Fine details of change detection per experiment

perf experiment goal Δ mean % Δ mean % CI trials links
dsd_uds_10mb_3k_timestamped_contexts_cpu % cpu utilization +2.49 [+2.20, +2.77] 1 Logs
dsd_uds_10mb_3k_timestamped_contexts_memory memory utilization +1.71 [+1.49, +1.93] 1 Logs
quality_gate_security_idle memory utilization +0.41 [+0.36, +0.46] 1 Logs bounds checks dashboard
quality_gate_idle_all_features memory utilization +0.30 [+0.26, +0.33] 1 Logs bounds checks dashboard
quality_gate_security_no_fs_load memory utilization +0.29 [+0.21, +0.37] 1 Logs bounds checks dashboard
quality_gate_idle memory utilization +0.25 [+0.21, +0.29] 1 Logs bounds checks dashboard
quality_gate_metrics_logs memory utilization -0.07 [-0.30, +0.16] 1 Logs bounds checks dashboard
quality_gate_security_mean_fs_load memory utilization -0.21 [-0.24, -0.17] 1 Logs bounds checks dashboard
quality_gate_private_action_runner memory utilization -0.42 [-0.55, -0.30] 1 Logs bounds checks dashboard
quality_gate_logs % cpu utilization -1.70 [-2.57, -0.83] 1 Logs bounds checks dashboard

Bounds Checks: ✅ Passed

perf experiment bounds_check_name replicates_passed observed_value links
quality_gate_idle intake_connections 10/10 4 = 4 bounds checks dashboard
quality_gate_idle memory_usage 10/10 173.98MiB ≤ 178MiB bounds checks dashboard
quality_gate_idle total_bytes_received 10/10 747.54KiB ≤ 819.20KiB bounds checks dashboard
quality_gate_idle_all_features intake_connections 10/10 4 = 4 bounds checks dashboard
quality_gate_idle_all_features memory_usage 10/10 519.90MiB ≤ 538MiB bounds checks dashboard
quality_gate_idle_all_features total_bytes_received 10/10 1.14MiB ≤ 1.25MiB bounds checks dashboard
quality_gate_logs intake_connections 10/10 19 ≤ 40 bounds checks dashboard
quality_gate_logs memory_usage 10/10 211.08MiB ≤ 229MiB bounds checks dashboard
quality_gate_logs missed_bytes 10/10 0B = 0B bounds checks dashboard
quality_gate_logs total_bytes_received 10/10 263.42MiB ≤ 292MiB bounds checks dashboard
quality_gate_metrics_logs cpu_usage 10/10 419.42 ≤ 2000 bounds checks dashboard
quality_gate_metrics_logs intake_connections 10/10 19 ≤ 40 bounds checks dashboard
quality_gate_metrics_logs memory_usage 10/10 418.78MiB ≤ 453MiB bounds checks dashboard
quality_gate_metrics_logs missed_bytes 10/10 0B = 0B bounds checks dashboard
quality_gate_metrics_logs total_bytes_received 10/10 0.94GiB ≤ 1.04GiB bounds checks dashboard
quality_gate_private_action_runner memory_usage 10/10 71.50MiB ≤ 76MiB bounds checks dashboard
quality_gate_security_idle cpu_usage 10/10 29.43 ≤ 100 bounds checks dashboard
quality_gate_security_idle memory_usage 10/10 325.36MiB ≤ 335MiB bounds checks dashboard
quality_gate_security_mean_fs_load cpu_usage 10/10 86.96 ≤ 200 bounds checks dashboard
quality_gate_security_mean_fs_load memory_usage 10/10 303.69MiB ≤ 314MiB bounds checks dashboard
quality_gate_security_no_fs_load cpu_usage 10/10 22.06 ≤ 100 bounds checks dashboard
quality_gate_security_no_fs_load memory_usage 10/10 312.03MiB ≤ 343MiB bounds checks dashboard

Explanation

Confidence level: 90.00%
Effect size tolerance: |Δ mean %| ≥ 5.00%

Performance changes are noted in the perf column of each table:

  • ✅ = significantly better comparison variant performance
  • ❌ = significantly worse comparison variant performance
  • ➖ = no significant change in performance

A regression test is an A/B test of target performance in a repeatable rig, where "performance" is measured as "comparison variant minus baseline variant" for an optimization goal (e.g., ingress throughput). Due to intrinsic variability in measuring that goal, we can only estimate its mean value for each experiment; we report uncertainty in that value as a 90.00% confidence interval denoted "Δ mean % CI".

For each experiment, we decide whether a change in performance is a "regression" -- a change worth investigating further -- if all of the following criteria are true:

  1. Its estimated |Δ mean %| ≥ 5.00%, indicating the change is big enough to merit a closer look.

  2. Its 90.00% confidence interval "Δ mean % CI" does not contain zero, indicating that if our statistical model is accurate, there is at least a 90.00% chance there is a difference in performance between baseline and comparison variants.

  3. Its configuration does not mark it "erratic".

CI Pass/Fail Decision

Passed. All Quality Gates passed.

  • quality_gate_security_mean_fs_load, bounds check memory_usage: 10/10 replicas passed. Gate passed.
  • quality_gate_security_mean_fs_load, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
  • quality_gate_security_no_fs_load, bounds check memory_usage: 10/10 replicas passed. Gate passed.
  • quality_gate_security_no_fs_load, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
  • quality_gate_metrics_logs, bounds check missed_bytes: 10/10 replicas passed. Gate passed.
  • quality_gate_metrics_logs, bounds check memory_usage: 10/10 replicas passed. Gate passed.
  • quality_gate_metrics_logs, bounds check intake_connections: 10/10 replicas passed. Gate passed.
  • quality_gate_metrics_logs, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
  • quality_gate_metrics_logs, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
  • quality_gate_security_idle, bounds check memory_usage: 10/10 replicas passed. Gate passed.
  • quality_gate_security_idle, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
  • quality_gate_idle, bounds check intake_connections: 10/10 replicas passed. Gate passed.
  • quality_gate_idle, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
  • quality_gate_idle, bounds check memory_usage: 10/10 replicas passed. Gate passed.
  • quality_gate_idle_all_features, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
  • quality_gate_idle_all_features, bounds check intake_connections: 10/10 replicas passed. Gate passed.
  • quality_gate_idle_all_features, bounds check memory_usage: 10/10 replicas passed. Gate passed.
  • quality_gate_logs, bounds check missed_bytes: 10/10 replicas passed. Gate passed.
  • quality_gate_logs, bounds check intake_connections: 10/10 replicas passed. Gate passed.
  • quality_gate_logs, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
  • quality_gate_logs, bounds check memory_usage: 10/10 replicas passed. Gate passed.
  • quality_gate_private_action_runner, bounds check memory_usage: 10/10 replicas passed. Gate passed.

@embeaken
embeaken force-pushed the ilya/par-control-runner-wiring branch from 492099e to da8c7bf Compare August 10, 2026 15:09
@embeaken
embeaken force-pushed the ilya/par-control-orchestration branch 2 times, most recently from a984166 to f85a738 Compare August 10, 2026 15:22
@embeaken
embeaken force-pushed the ilya/par-control-runner-wiring branch from da8c7bf to a63285f Compare August 10, 2026 15:22
@embeaken
embeaken force-pushed the ilya/par-control-orchestration branch from f85a738 to 984a3fd Compare August 10, 2026 16:13
@embeaken
embeaken force-pushed the ilya/par-control-runner-wiring branch from a63285f to f1fbdb7 Compare August 10, 2026 16:14
@embeaken
embeaken force-pushed the ilya/par-control-orchestration branch from 984a3fd to eb67245 Compare August 10, 2026 17:12
@embeaken
embeaken force-pushed the ilya/par-control-runner-wiring branch 3 times, most recently from eb4762e to 461e8cc Compare August 10, 2026 18:22
@embeaken
embeaken force-pushed the ilya/par-control-orchestration branch from 349cba4 to 8aac9cd Compare August 10, 2026 18:22
@embeaken
embeaken force-pushed the ilya/par-control-orchestration branch from 86614f2 to ac84aa8 Compare August 12, 2026 18:46
@embeaken
embeaken force-pushed the ilya/par-control-runner-wiring branch from 6be08a7 to 097c253 Compare August 12, 2026 18:46
@embeaken
embeaken force-pushed the ilya/par-control-orchestration branch from ac84aa8 to 3f91e32 Compare August 12, 2026 19:26
@embeaken
embeaken force-pushed the ilya/par-control-runner-wiring branch from 097c253 to 88505c9 Compare August 12, 2026 19:27
@embeaken
embeaken force-pushed the ilya/par-control-orchestration branch from 3f91e32 to c68c4c6 Compare August 13, 2026 14:30
@embeaken
embeaken force-pushed the ilya/par-control-runner-wiring branch from 88505c9 to e600be5 Compare August 13, 2026 14:30
@embeaken
embeaken force-pushed the ilya/par-control-orchestration branch from c68c4c6 to 9cfc7d0 Compare August 13, 2026 16:27
@embeaken
embeaken force-pushed the ilya/par-control-runner-wiring branch 2 times, most recently from 153e792 to 462d772 Compare August 13, 2026 16:30
@embeaken
embeaken force-pushed the ilya/par-control-orchestration branch from 9cfc7d0 to 1aa18da Compare August 13, 2026 16:30
@embeaken
embeaken force-pushed the ilya/par-control-runner-wiring branch from 462d772 to d20641e Compare August 13, 2026 17:00
@embeaken
embeaken force-pushed the ilya/par-control-orchestration branch 2 times, most recently from 665dbfb to f4cfc0a Compare August 13, 2026 18:37
@embeaken
embeaken force-pushed the ilya/par-control-runner-wiring branch from d20641e to bc0df09 Compare August 13, 2026 18:37
@embeaken
embeaken force-pushed the ilya/par-control-orchestration branch from f4cfc0a to 49d6ce1 Compare August 13, 2026 19:11
@embeaken
embeaken force-pushed the ilya/par-control-runner-wiring branch 2 times, most recently from 4e01196 to 74672da Compare August 13, 2026 19:20
@embeaken
embeaken force-pushed the ilya/par-control-orchestration branch 2 times, most recently from 3763e5e to 1cdd762 Compare August 13, 2026 19:37
@embeaken
embeaken force-pushed the ilya/par-control-runner-wiring branch from 74672da to 52591c4 Compare August 13, 2026 19:37
@embeaken
embeaken force-pushed the ilya/par-control-orchestration branch from 1cdd762 to c139a60 Compare August 13, 2026 22:37
@embeaken
embeaken force-pushed the ilya/par-control-runner-wiring branch from 52591c4 to 2b10f25 Compare August 13, 2026 22:39
@embeaken
embeaken force-pushed the ilya/par-control-orchestration branch from c139a60 to 42177f2 Compare August 13, 2026 23:04
@embeaken
embeaken force-pushed the ilya/par-control-runner-wiring branch from 2b10f25 to ab31efc Compare August 13, 2026 23:05
@embeaken
embeaken force-pushed the ilya/par-control-orchestration branch from 42177f2 to 4359fe9 Compare August 13, 2026 23:11
@embeaken
embeaken force-pushed the ilya/par-control-runner-wiring branch 2 times, most recently from e283b71 to eb754fe Compare August 13, 2026 23:48
@embeaken
embeaken force-pushed the ilya/par-control-orchestration branch from 4359fe9 to 1c989c7 Compare August 13, 2026 23:48
@dd-octo-sts

dd-octo-sts Bot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Gitlab CI Configuration Changes

Modified Jobs

new-e2e-privateactionrunner
  new-e2e-privateactionrunner:
    after_script:
    - CODECOV_TOKEN=$($CI_PROJECT_DIR/tools/ci/fetch_secret.sh $CODECOV token) || exit
      $?; export CODECOV_TOKEN
    - $CI_PROJECT_DIR/tools/ci/junit_upload.sh "junit-${CI_JOB_ID}.tgz" "$E2E_RESULT_JSON"
    - "if [ -d \"$E2E_COVERAGE_OUT_DIR\" ]; then\n  dda inv -- -e coverage.process-e2e-coverage-folders\
      \ $E2E_COVERAGE_OUT_DIR\n  dda inv -- -e dyntest.compute-and-upload-job-index\
      \ --bucket-uri $S3_PERMANENT_ARTIFACTS_URI --coverage-folder $E2E_COVERAGE_OUT_DIR\
      \ --commit-sha $CI_COMMIT_SHA --job-id $CI_JOB_ID\nfi\n"
    - "if [ -d \"$E2E_COVERAGE_OUT_DIR\" ]; then\n  DD_API_KEY=$($CI_PROJECT_DIR/tools/ci/fetch_secret.sh\
      \ $AGENT_API_KEY_ORG2 token) || exit $?; export DD_API_KEY\n  for coverage in\
      \ \"$E2E_COVERAGE_OUT_DIR\"/*/coverage.txt; do\n    datadog-ci coverage upload\
      \ --format=go-coverprofile \"$coverage\" || true\n  done\nfi\n"
    artifacts:
      expire_in: 2 weeks
      paths:
      - $E2E_OUTPUT_DIR
      - $E2E_RESULT_JSON
      - junit-*.tgz
      - $E2E_COVERAGE_OUT_DIR
      reports:
        annotations:
        - $EXTERNAL_LINKS_PATH
      when: always
    before_script:
    - mkdir -p $GOPATH/pkg/mod/cache && zstd -dc modcache_e2e.tar.zst | tar xf - -C
      $GOPATH/pkg/mod/cache
    - rm -f modcache_e2e.tar.zst
    - mkdir -p ~/.pulumi && zstd -dc pulumi_plugins.tar.zst | tar xf - -C ~/.pulumi
    - rm -f pulumi_plugins.tar.zst
    - "go_bin=\"$(go env GOBIN)\"\nif [ -z \"$go_bin\" ]; then\n  go_bin=\"$(go env\
      \ GOPATH)/bin\"\nfi\nmkdir -p \"$go_bin\" \"$GOPATH/pkg/mod/cache\"\nzstd -dc\
      \ go_tools_bin.tar.zst | tar xf - -C \"$go_bin\"\nzstd -dc modcache_tools.tar.zst\
      \ | tar xf - -C \"$GOPATH/pkg/mod/cache\"\n"
    - rm -f go_tools_bin.tar.zst modcache_tools.tar.zst
    - export PATH=$PATH:$go_bin
    - mkdir -p ~/.aws
    - "if [ -n \"$E2E_USE_AWS_PROFILE\" ]; then\n  echo Using agent-qa-ci aws profile\n\
      \  $CI_PROJECT_DIR/tools/ci/fetch_secret.sh $AGENT_QA_E2E profile >> ~/.aws/config\
      \ || exit $?\n  # Now all `aws` commands target the agent-qa profile\n  export\
      \ AWS_PROFILE=agent-qa-ci\nelse\n  # Assume role to fetch only once credentials\
      \ and avoid rate limits\n  echo Assuming ddbuild-agent-ci role\n  roleoutput=\"\
      $(aws sts assume-role --role-arn arn:aws:iam::669783387624:role/ddbuild-agent-ci\
      \ --external-id ddbuild-agent-ci --role-session-name RoleSession)\"\n  export\
      \ AWS_ACCESS_KEY_ID=\"$(echo \"$roleoutput\" | jq -r '.Credentials.AccessKeyId')\"\
      \n  export AWS_SECRET_ACCESS_KEY=\"$(echo \"$roleoutput\" | jq -r '.Credentials.SecretAccessKey')\"\
      \n  export AWS_SESSION_TOKEN=\"$(echo \"$roleoutput\" | jq -r '.Credentials.SessionToken')\"\
      \nfi\n"
    - $CI_PROJECT_DIR/tools/ci/fetch_secret.sh $AGENT_QA_E2E ssh_public_key_rsa > $E2E_AWS_PUBLIC_KEY_PATH
      || exit $?
    - touch $E2E_AWS_PRIVATE_KEY_PATH && chmod 600 $E2E_AWS_PRIVATE_KEY_PATH && $CI_PROJECT_DIR/tools/ci/fetch_secret.sh
      $AGENT_QA_E2E ssh_key_rsa > $E2E_AWS_PRIVATE_KEY_PATH || exit $?
    - $CI_PROJECT_DIR/tools/ci/fetch_secret.sh $AGENT_QA_E2E ssh_public_key_rsa > $E2E_AZURE_PUBLIC_KEY_PATH
      || exit $?
    - touch $E2E_AZURE_PRIVATE_KEY_PATH && chmod 600 $E2E_AZURE_PRIVATE_KEY_PATH &&
      $CI_PROJECT_DIR/tools/ci/fetch_secret.sh $AGENT_QA_E2E ssh_key_rsa > $E2E_AZURE_PRIVATE_KEY_PATH
      || exit $?
    - $CI_PROJECT_DIR/tools/ci/fetch_secret.sh $AGENT_QA_E2E ssh_public_key_rsa > $E2E_GCP_PUBLIC_KEY_PATH
      || exit $?
    - touch $E2E_GCP_PRIVATE_KEY_PATH && chmod 600 $E2E_GCP_PRIVATE_KEY_PATH && $CI_PROJECT_DIR/tools/ci/fetch_secret.sh
      $AGENT_QA_E2E ssh_key_rsa > $E2E_GCP_PRIVATE_KEY_PATH || exit $?
    - pulumi login "s3://dd-pulumi-state?region=us-east-1&awssdk=v2&profile=$AWS_PROFILE"
    - ARM_CLIENT_ID=$($CI_PROJECT_DIR/tools/ci/fetch_secret.sh $E2E_AZURE client_id)
      || exit $?; export ARM_CLIENT_ID
    - ARM_CLIENT_SECRET=$($CI_PROJECT_DIR/tools/ci/fetch_secret.sh $E2E_AZURE token)
      || exit $?; export ARM_CLIENT_SECRET
    - ARM_TENANT_ID=$($CI_PROJECT_DIR/tools/ci/fetch_secret.sh $E2E_AZURE tenant_id)
      || exit $?; export ARM_TENANT_ID
    - ARM_SUBSCRIPTION_ID=$($CI_PROJECT_DIR/tools/ci/fetch_secret.sh $E2E_AZURE subscription_id)
      || exit $?; export ARM_SUBSCRIPTION_ID
    - $CI_PROJECT_DIR/tools/ci/fetch_secret.sh $E2E_GCP credentials_json > ~/gcp-credentials.json
      || exit $?
    - export GOOGLE_APPLICATION_CREDENTIALS=~/gcp-credentials.json
    - 'gcp_acr_key=$($CI_PROJECT_DIR/tools/ci/fetch_secret.sh $E2E_GCP credentials_acr_readonly)
      || exit $?
  
      export E2E_GCP_IMAGE_PULL_PASSWORD="b64=$(printf ''%s'' "$gcp_acr_key" | base64
      -w 0)"
  
      '
    - dda inv -- -e gitlab.generate-ci-visibility-links --output=$EXTERNAL_LINKS_PATH
    - export DD_ENV=nativetest
    - export DD_CIVISIBILITY_ENABLED=true
    - export DD_CIVISIBILITY_AGENTLESS_ENABLED=true
    - export DD_CIVISIBILITY_FLAKY_RETRY_ENABLED=false
    - export DD_TAGS="gitlab.pipeline_source:${CI_PIPELINE_SOURCE}"
    - DD_API_KEY=$($CI_PROJECT_DIR/tools/ci/fetch_secret.sh $AGENT_API_KEY_ORG2 token)
      || exit $?; export DD_API_KEY
    - export WINDOWS_DDNPM_DRIVER=${WINDOWS_DDNPM_DRIVER:-$(dda inv release.get-release-json-value
      "dependencies::WINDOWS_DDNPM_DRIVER" --no-worktree)}
    - export WINDOWS_DDPROCMON_DRIVER=${WINDOWS_DDPROCMON_DRIVER:-$(dda inv release.get-release-json-value
      "dependencies::WINDOWS_DDPROCMON_DRIVER" --no-worktree)}
    cache:
    - key:
        files:
        - .bazelversion
        prefix: bazelversion-$CI_RUNNER_DESCRIPTION
      paths:
      - .cache/bazelisk
      - .cache/bazel/*/install
      policy: pull$BAZEL_CACHE_POLICY_SUFFIX
      when: on_success
    - key:
        files:
        - MODULE.bazel.lock
        prefix: bazel-$CI_JOB_NAME
      paths:
      - .cache/bazel/*/cache
      - .cache/go
      - .cache/ms-go
      - .cache/pip
      policy: pull$BAZEL_CACHE_POLICY_SUFFIX
      when: on_success
    id_tokens:
      BUILDBARN_ID_TOKEN:
        aud: buildbarn.us1.ddbuild.io
    image: registry.ddbuild.io/ci/datadog-agent-buildimages/linux$CI_IMAGE_LINUX_SUFFIX:$CI_IMAGE_LINUX
    needs:
    - go_e2e_deps
    - artifacts: false
      job: go_e2e_test_binaries
    - go_tools_deps
    - job: new-e2e-base-coverage
      optional: true
    - job: publish_fakeintake
      optional: true
    - job: publish_fakeintake_pinned
      optional: true
    - agent_deb-x64-a7
    - qa_agent_linux
    - qa_dca
    rules:
    - if: $RUN_E2E_TESTS == "off"
      when: never
    - if: $CI_COMMIT_BRANCH =~ /^mq-working-branch-/
      when: never
    - if: $RUN_E2E_TESTS == "off"
      when: never
    - if: $CI_COMMIT_BRANCH =~ /^mq-working-branch-/
      when: never
    - changes:
        compare_to: $COMPARE_TO_BRANCH
        paths:
        - test/fakeintake/cmd/server/**/*.go
        - test/fakeintake/server/**/*.go
        - test/fakeintake/aggregator/**/*.go
        - test/fakeintake/api/**/*.go
        - test/fakeintake/go.mod
        - test/fakeintake/go.sum
        - test/fakeintake/Dockerfile
        - test/fakeintake/version/VERSION
        - .gitlab/build/binary_build/fakeintake.yml
        - .gitlab/deploy/container_build/fakeintake.yml
        - .gitlab/deploy/dev_container_deploy/fakeintake.yml
      variables:
        E2E_FAKEINTAKE_IMAGE_OVERRIDE: public.ecr.aws/datadog/fakeintake:v$CI_COMMIT_SHORT_SHA
      when: on_success
    - if: $RUN_E2E_TESTS == "on"
      when: on_success
    - if: $CI_COMMIT_BRANCH == "main"
      when: on_success
    - if: $CI_COMMIT_BRANCH =~ /^[0-9]+\.[0-9]+\.x$/
      when: on_success
    - if: $CI_COMMIT_TAG =~ /^[0-9]+\.[0-9]+\.[0-9]+-rc\.[0-9]+$/
      when: on_success
    - changes:
        compare_to: $COMPARE_TO_BRANCH
        paths:
        - test/fakeintake/**/*
        - .gitlab/build/binary_build/fakeintake.yml
        - .gitlab/deploy/container_build/fakeintake.yml
        - .gitlab/deploy/dev_container_deploy/fakeintake.yml
      when: on_success
    - changes:
        compare_to: $COMPARE_TO_BRANCH
        paths:
        - .gitlab/test/e2e/e2e.yml
        - test/e2e-framework/**/*
        - test/new-e2e/go.mod
        - flakes.yaml
        - release.json
    - changes:
        compare_to: $COMPARE_TO_BRANCH
        paths:
        - cmd/privateactionrunner/**/*
        - comp/privateactionrunner/**/*
        - pkg/privateactionrunner/**/*
        - pkg/config/setup/privateactionrunner.go
        - pkg/proto/datadog/privateactionrunner/**/*
        - pkg/proto/pbgo/privateactionrunner/**/*
        - test/new-e2e/tests/privateactionrunner/**/*
      when: on_success
    - if: $CI_COMMIT_BRANCH =~ /^mq-working-branch-/
      when: never
    - allow_failure: true
      when: manual
    script:
    - export IS_DEV_BRANCH="$(dda inv -- -e pipeline.is-dev-branch)"
    - DYNAMIC_TESTS_BREAKGLASS=$($CI_PROJECT_DIR/tools/ci/fetch_secret.sh $DYNAMIC_TESTS_BREAKGLASS
      value) || exit $?; export DYNAMIC_TESTS_BREAKGLASS
    - "if [ \"$DYNAMIC_TESTS_BREAKGLASS\" == \"true\" ] || [ \"$IS_DEV_BRANCH\" == \"\
      false\" ] || [ \"$RUN_E2E_TESTS\" == \"on\" ]; then\n  export DYNAMIC_TESTS_FLAG=\"\
      \"\nfi\n"
    - export E2E_IMAGE_PULL_PASSWORD=$(aws ecr get-login-password),$E2E_GCP_IMAGE_PULL_PASSWORD
    - dda inv -- -e new-e2e-tests.run $DYNAMIC_TESTS_FLAG $PRE_BUILT_BINARIES_FLAG $MAX_RETRIES_FLAG
      --local-package $CI_PROJECT_DIR/$OMNIBUS_BASE_DIR --result-json $E2E_RESULT_JSON
      --targets $TARGETS --junit-tar junit-${CI_JOB_ID}.tgz ${EXTRA_PARAMS} --test-washer
      --logs-folder=$E2E_OUTPUT_DIR/logs --logs-post-processing --logs-post-processing-test-depth=$E2E_LOGS_PROCESSING_TEST_DEPTH
    stage: e2e
    tags:
    - arch:amd64
    - specific:true
    variables:
      BAZELISK_HOME: $XDG_CACHE_HOME/bazelisk
      DYNAMIC_TESTS_FLAG: --impacted
      E2E_AWS_PRIVATE_KEY_PATH: /tmp/agent-qa-aws-ssh-key
      E2E_AWS_PUBLIC_KEY_PATH: /tmp/agent-qa-aws-ssh-key.pub
      E2E_AZURE_PRIVATE_KEY_PATH: /tmp/agent-qa-azure-ssh-key
      E2E_AZURE_PUBLIC_KEY_PATH: /tmp/agent-qa-azure-ssh-key.pub
      E2E_COMMIT_SHA: $CI_COMMIT_SHORT_SHA
      E2E_COVERAGE_OUT_DIR: $CI_PROJECT_DIR/coverage
      E2E_GCP_PRIVATE_KEY_PATH: /tmp/agent-qa-gcp-ssh-key
      E2E_GCP_PUBLIC_KEY_PATH: /tmp/agent-qa-gcp-ssh-key.pub
      E2E_IMAGE_PULL_REGISTRY: 669783387624.dkr.ecr.us-east-1.amazonaws.com,us-central1-docker.pkg.dev
      E2E_IMAGE_PULL_USERNAME: AWS,_json_key
      E2E_KEY_PAIR_NAME: datadog-agent-ci-rsa
      E2E_LOGS_PROCESSING_TEST_DEPTH: 1
      E2E_OUTPUT_DIR: $CI_PROJECT_DIR/e2e-output
      E2E_PIPELINE_ID: $CI_PIPELINE_ID
      E2E_PREBUILD_S3_URI: $S3_PERMANENT_ARTIFACTS_URI/e2e-pre-build/$CI_PIPELINE_ID
      E2E_RESULT_JSON: $CI_PROJECT_DIR/e2e_test_output.json
      E2E_SKIP_WINDOWS: $SKIP_WINDOWS
      E2E_USE_AWS_PROFILE: 'true'
      EXTERNAL_LINKS_PATH: external_links_$CI_JOB_ID.json
+     EXTRA_PARAMS: --skip "Windows"
      FLAKY_PATTERNS_CONFIG: $CI_PROJECT_DIR/flaky-patterns-runtime.yaml
      GIT_DEPTH: 0
      GIT_STRATEGY: clone
      KUBERNETES_CPU_REQUEST: 6
      KUBERNETES_MEMORY_LIMIT: 16Gi
      KUBERNETES_MEMORY_REQUEST: 12Gi
      MAX_RETRIES_FLAG: ''
      PRE_BUILT_BINARIES_FLAG: --use-prebuilt-binaries
      REMOTE_STACK_CLEANING: 'true'
      SHOULD_RUN_IN_FLAKES_FINDER: 'true'
      TARGETS: ./tests/privateactionrunner
      TEAM: action-platform
      XDG_CACHE_HOME: $CI_PROJECT_DIR/.cache

Added Jobs

new-e2e-privateactionrunner-windows
new-e2e-privateactionrunner-windows:
  after_script:
  - CODECOV_TOKEN=$($CI_PROJECT_DIR/tools/ci/fetch_secret.sh $CODECOV token) || exit
    $?; export CODECOV_TOKEN
  - $CI_PROJECT_DIR/tools/ci/junit_upload.sh "junit-${CI_JOB_ID}.tgz" "$E2E_RESULT_JSON"
  - "if [ -d \"$E2E_COVERAGE_OUT_DIR\" ]; then\n  dda inv -- -e coverage.process-e2e-coverage-folders\
    \ $E2E_COVERAGE_OUT_DIR\n  dda inv -- -e dyntest.compute-and-upload-job-index\
    \ --bucket-uri $S3_PERMANENT_ARTIFACTS_URI --coverage-folder $E2E_COVERAGE_OUT_DIR\
    \ --commit-sha $CI_COMMIT_SHA --job-id $CI_JOB_ID\nfi\n"
  - "if [ -d \"$E2E_COVERAGE_OUT_DIR\" ]; then\n  DD_API_KEY=$($CI_PROJECT_DIR/tools/ci/fetch_secret.sh\
    \ $AGENT_API_KEY_ORG2 token) || exit $?; export DD_API_KEY\n  for coverage in\
    \ \"$E2E_COVERAGE_OUT_DIR\"/*/coverage.txt; do\n    datadog-ci coverage upload\
    \ --format=go-coverprofile \"$coverage\" || true\n  done\nfi\n"
  artifacts:
    expire_in: 2 weeks
    paths:
    - $E2E_OUTPUT_DIR
    - $E2E_RESULT_JSON
    - junit-*.tgz
    - $E2E_COVERAGE_OUT_DIR
    reports:
      annotations:
      - $EXTERNAL_LINKS_PATH
    when: always
  before_script:
  - mkdir -p $GOPATH/pkg/mod/cache && zstd -dc modcache_e2e.tar.zst | tar xf - -C
    $GOPATH/pkg/mod/cache
  - rm -f modcache_e2e.tar.zst
  - mkdir -p ~/.pulumi && zstd -dc pulumi_plugins.tar.zst | tar xf - -C ~/.pulumi
  - rm -f pulumi_plugins.tar.zst
  - "go_bin=\"$(go env GOBIN)\"\nif [ -z \"$go_bin\" ]; then\n  go_bin=\"$(go env\
    \ GOPATH)/bin\"\nfi\nmkdir -p \"$go_bin\" \"$GOPATH/pkg/mod/cache\"\nzstd -dc\
    \ go_tools_bin.tar.zst | tar xf - -C \"$go_bin\"\nzstd -dc modcache_tools.tar.zst\
    \ | tar xf - -C \"$GOPATH/pkg/mod/cache\"\n"
  - rm -f go_tools_bin.tar.zst modcache_tools.tar.zst
  - export PATH=$PATH:$go_bin
  - mkdir -p ~/.aws
  - "if [ -n \"$E2E_USE_AWS_PROFILE\" ]; then\n  echo Using agent-qa-ci aws profile\n\
    \  $CI_PROJECT_DIR/tools/ci/fetch_secret.sh $AGENT_QA_E2E profile >> ~/.aws/config\
    \ || exit $?\n  # Now all `aws` commands target the agent-qa profile\n  export\
    \ AWS_PROFILE=agent-qa-ci\nelse\n  # Assume role to fetch only once credentials\
    \ and avoid rate limits\n  echo Assuming ddbuild-agent-ci role\n  roleoutput=\"\
    $(aws sts assume-role --role-arn arn:aws:iam::669783387624:role/ddbuild-agent-ci\
    \ --external-id ddbuild-agent-ci --role-session-name RoleSession)\"\n  export\
    \ AWS_ACCESS_KEY_ID=\"$(echo \"$roleoutput\" | jq -r '.Credentials.AccessKeyId')\"\
    \n  export AWS_SECRET_ACCESS_KEY=\"$(echo \"$roleoutput\" | jq -r '.Credentials.SecretAccessKey')\"\
    \n  export AWS_SESSION_TOKEN=\"$(echo \"$roleoutput\" | jq -r '.Credentials.SessionToken')\"\
    \nfi\n"
  - $CI_PROJECT_DIR/tools/ci/fetch_secret.sh $AGENT_QA_E2E ssh_public_key_rsa > $E2E_AWS_PUBLIC_KEY_PATH
    || exit $?
  - touch $E2E_AWS_PRIVATE_KEY_PATH && chmod 600 $E2E_AWS_PRIVATE_KEY_PATH && $CI_PROJECT_DIR/tools/ci/fetch_secret.sh
    $AGENT_QA_E2E ssh_key_rsa > $E2E_AWS_PRIVATE_KEY_PATH || exit $?
  - $CI_PROJECT_DIR/tools/ci/fetch_secret.sh $AGENT_QA_E2E ssh_public_key_rsa > $E2E_AZURE_PUBLIC_KEY_PATH
    || exit $?
  - touch $E2E_AZURE_PRIVATE_KEY_PATH && chmod 600 $E2E_AZURE_PRIVATE_KEY_PATH &&
    $CI_PROJECT_DIR/tools/ci/fetch_secret.sh $AGENT_QA_E2E ssh_key_rsa > $E2E_AZURE_PRIVATE_KEY_PATH
    || exit $?
  - $CI_PROJECT_DIR/tools/ci/fetch_secret.sh $AGENT_QA_E2E ssh_public_key_rsa > $E2E_GCP_PUBLIC_KEY_PATH
    || exit $?
  - touch $E2E_GCP_PRIVATE_KEY_PATH && chmod 600 $E2E_GCP_PRIVATE_KEY_PATH && $CI_PROJECT_DIR/tools/ci/fetch_secret.sh
    $AGENT_QA_E2E ssh_key_rsa > $E2E_GCP_PRIVATE_KEY_PATH || exit $?
  - pulumi login "s3://dd-pulumi-state?region=us-east-1&awssdk=v2&profile=$AWS_PROFILE"
  - ARM_CLIENT_ID=$($CI_PROJECT_DIR/tools/ci/fetch_secret.sh $E2E_AZURE client_id)
    || exit $?; export ARM_CLIENT_ID
  - ARM_CLIENT_SECRET=$($CI_PROJECT_DIR/tools/ci/fetch_secret.sh $E2E_AZURE token)
    || exit $?; export ARM_CLIENT_SECRET
  - ARM_TENANT_ID=$($CI_PROJECT_DIR/tools/ci/fetch_secret.sh $E2E_AZURE tenant_id)
    || exit $?; export ARM_TENANT_ID
  - ARM_SUBSCRIPTION_ID=$($CI_PROJECT_DIR/tools/ci/fetch_secret.sh $E2E_AZURE subscription_id)
    || exit $?; export ARM_SUBSCRIPTION_ID
  - $CI_PROJECT_DIR/tools/ci/fetch_secret.sh $E2E_GCP credentials_json > ~/gcp-credentials.json
    || exit $?
  - export GOOGLE_APPLICATION_CREDENTIALS=~/gcp-credentials.json
  - 'gcp_acr_key=$($CI_PROJECT_DIR/tools/ci/fetch_secret.sh $E2E_GCP credentials_acr_readonly)
    || exit $?

    export E2E_GCP_IMAGE_PULL_PASSWORD="b64=$(printf ''%s'' "$gcp_acr_key" | base64
    -w 0)"

    '
  - dda inv -- -e gitlab.generate-ci-visibility-links --output=$EXTERNAL_LINKS_PATH
  - export DD_ENV=nativetest
  - export DD_CIVISIBILITY_ENABLED=true
  - export DD_CIVISIBILITY_AGENTLESS_ENABLED=true
  - export DD_CIVISIBILITY_FLAKY_RETRY_ENABLED=false
  - export DD_TAGS="gitlab.pipeline_source:${CI_PIPELINE_SOURCE}"
  - DD_API_KEY=$($CI_PROJECT_DIR/tools/ci/fetch_secret.sh $AGENT_API_KEY_ORG2 token)
    || exit $?; export DD_API_KEY
  - export WINDOWS_DDNPM_DRIVER=${WINDOWS_DDNPM_DRIVER:-$(dda inv release.get-release-json-value
    "dependencies::WINDOWS_DDNPM_DRIVER" --no-worktree)}
  - export WINDOWS_DDPROCMON_DRIVER=${WINDOWS_DDPROCMON_DRIVER:-$(dda inv release.get-release-json-value
    "dependencies::WINDOWS_DDPROCMON_DRIVER" --no-worktree)}
  cache:
  - key:
      files:
      - .bazelversion
      prefix: bazelversion-$CI_RUNNER_DESCRIPTION
    paths:
    - .cache/bazelisk
    - .cache/bazel/*/install
    policy: pull$BAZEL_CACHE_POLICY_SUFFIX
    when: on_success
  - key:
      files:
      - MODULE.bazel.lock
      prefix: bazel-$CI_JOB_NAME
    paths:
    - .cache/bazel/*/cache
    - .cache/go
    - .cache/ms-go
    - .cache/pip
    policy: pull$BAZEL_CACHE_POLICY_SUFFIX
    when: on_success
  id_tokens:
    BUILDBARN_ID_TOKEN:
      aud: buildbarn.us1.ddbuild.io
  image: registry.ddbuild.io/ci/datadog-agent-buildimages/linux$CI_IMAGE_LINUX_SUFFIX:$CI_IMAGE_LINUX
  needs:
  - go_e2e_deps
  - artifacts: false
    job: go_e2e_test_binaries
  - go_tools_deps
  - job: new-e2e-base-coverage
    optional: true
  - job: publish_fakeintake
    optional: true
  - job: publish_fakeintake_pinned
    optional: true
  - windows_msi_and_bosh_zip_x64-a7
  - windows_msi_and_bosh_zip_x64-a7-fips
  rules:
  - if: $RUN_E2E_TESTS == "off"
    when: never
  - if: $CI_COMMIT_BRANCH =~ /^mq-working-branch-/
    when: never
  - if: $RUN_E2E_TESTS == "off"
    when: never
  - if: $CI_COMMIT_BRANCH =~ /^mq-working-branch-/
    when: never
  - changes:
      compare_to: $COMPARE_TO_BRANCH
      paths:
      - test/fakeintake/cmd/server/**/*.go
      - test/fakeintake/server/**/*.go
      - test/fakeintake/aggregator/**/*.go
      - test/fakeintake/api/**/*.go
      - test/fakeintake/go.mod
      - test/fakeintake/go.sum
      - test/fakeintake/Dockerfile
      - test/fakeintake/version/VERSION
      - .gitlab/build/binary_build/fakeintake.yml
      - .gitlab/deploy/container_build/fakeintake.yml
      - .gitlab/deploy/dev_container_deploy/fakeintake.yml
    variables:
      E2E_FAKEINTAKE_IMAGE_OVERRIDE: public.ecr.aws/datadog/fakeintake:v$CI_COMMIT_SHORT_SHA
    when: on_success
  - if: $RUN_E2E_TESTS == "on"
    when: on_success
  - if: $CI_COMMIT_BRANCH == "main"
    when: on_success
  - if: $CI_COMMIT_BRANCH =~ /^[0-9]+\.[0-9]+\.x$/
    when: on_success
  - if: $CI_COMMIT_TAG =~ /^[0-9]+\.[0-9]+\.[0-9]+-rc\.[0-9]+$/
    when: on_success
  - changes:
      compare_to: $COMPARE_TO_BRANCH
      paths:
      - test/fakeintake/**/*
      - .gitlab/build/binary_build/fakeintake.yml
      - .gitlab/deploy/container_build/fakeintake.yml
      - .gitlab/deploy/dev_container_deploy/fakeintake.yml
    when: on_success
  - changes:
      compare_to: $COMPARE_TO_BRANCH
      paths:
      - .gitlab/test/e2e/e2e.yml
      - test/e2e-framework/**/*
      - test/new-e2e/go.mod
      - flakes.yaml
      - release.json
  - changes:
      compare_to: $COMPARE_TO_BRANCH
      paths:
      - cmd/privateactionrunner/**/*
      - comp/privateactionrunner/**/*
      - pkg/privateactionrunner/**/*
      - pkg/config/setup/privateactionrunner.go
      - pkg/proto/datadog/privateactionrunner/**/*
      - pkg/proto/pbgo/privateactionrunner/**/*
      - test/new-e2e/tests/privateactionrunner/**/*
    when: on_success
  - if: $CI_COMMIT_BRANCH =~ /^mq-working-branch-/
    when: never
  - allow_failure: true
    when: manual
  script:
  - export IS_DEV_BRANCH="$(dda inv -- -e pipeline.is-dev-branch)"
  - DYNAMIC_TESTS_BREAKGLASS=$($CI_PROJECT_DIR/tools/ci/fetch_secret.sh $DYNAMIC_TESTS_BREAKGLASS
    value) || exit $?; export DYNAMIC_TESTS_BREAKGLASS
  - "if [ \"$DYNAMIC_TESTS_BREAKGLASS\" == \"true\" ] || [ \"$IS_DEV_BRANCH\" == \"\
    false\" ] || [ \"$RUN_E2E_TESTS\" == \"on\" ]; then\n  export DYNAMIC_TESTS_FLAG=\"\
    \"\nfi\n"
  - export E2E_IMAGE_PULL_PASSWORD=$(aws ecr get-login-password),$E2E_GCP_IMAGE_PULL_PASSWORD
  - dda inv -- -e new-e2e-tests.run $DYNAMIC_TESTS_FLAG $PRE_BUILT_BINARIES_FLAG $MAX_RETRIES_FLAG
    --local-package $CI_PROJECT_DIR/$OMNIBUS_BASE_DIR --result-json $E2E_RESULT_JSON
    --targets $TARGETS --junit-tar junit-${CI_JOB_ID}.tgz ${EXTRA_PARAMS} --test-washer
    --logs-folder=$E2E_OUTPUT_DIR/logs --logs-post-processing --logs-post-processing-test-depth=$E2E_LOGS_PROCESSING_TEST_DEPTH
  stage: e2e
  tags:
  - arch:amd64
  - specific:true
  variables:
    BAZELISK_HOME: $XDG_CACHE_HOME/bazelisk
    DYNAMIC_TESTS_FLAG: --impacted
    E2E_AWS_PRIVATE_KEY_PATH: /tmp/agent-qa-aws-ssh-key
    E2E_AWS_PUBLIC_KEY_PATH: /tmp/agent-qa-aws-ssh-key.pub
    E2E_AZURE_PRIVATE_KEY_PATH: /tmp/agent-qa-azure-ssh-key
    E2E_AZURE_PUBLIC_KEY_PATH: /tmp/agent-qa-azure-ssh-key.pub
    E2E_COMMIT_SHA: $CI_COMMIT_SHORT_SHA
    E2E_COVERAGE_OUT_DIR: $CI_PROJECT_DIR/coverage
    E2E_GCP_PRIVATE_KEY_PATH: /tmp/agent-qa-gcp-ssh-key
    E2E_GCP_PUBLIC_KEY_PATH: /tmp/agent-qa-gcp-ssh-key.pub
    E2E_IMAGE_PULL_REGISTRY: 669783387624.dkr.ecr.us-east-1.amazonaws.com,us-central1-docker.pkg.dev
    E2E_IMAGE_PULL_USERNAME: AWS,_json_key
    E2E_KEY_PAIR_NAME: datadog-agent-ci-rsa
    E2E_LOGS_PROCESSING_TEST_DEPTH: 1
    E2E_OUTPUT_DIR: $CI_PROJECT_DIR/e2e-output
    E2E_PIPELINE_ID: $CI_PIPELINE_ID
    E2E_PREBUILD_S3_URI: $S3_PERMANENT_ARTIFACTS_URI/e2e-pre-build/$CI_PIPELINE_ID
    E2E_RESULT_JSON: $CI_PROJECT_DIR/e2e_test_output.json
    E2E_SKIP_WINDOWS: $SKIP_WINDOWS
    E2E_USE_AWS_PROFILE: 'true'
    EXTERNAL_LINKS_PATH: external_links_$CI_JOB_ID.json
    EXTRA_PARAMS: --run "Windows"
    FLAKY_PATTERNS_CONFIG: $CI_PROJECT_DIR/flaky-patterns-runtime.yaml
    GIT_DEPTH: 0
    GIT_STRATEGY: clone
    KUBERNETES_CPU_REQUEST: 6
    KUBERNETES_MEMORY_LIMIT: 16Gi
    KUBERNETES_MEMORY_REQUEST: 12Gi
    MAX_RETRIES_FLAG: ''
    PRE_BUILT_BINARIES_FLAG: --use-prebuilt-binaries
    REMOTE_STACK_CLEANING: 'true'
    SHOULD_RUN_IN_FLAKES_FINDER: 'true'
    TARGETS: ./tests/privateactionrunner
    TEAM: action-platform
    XDG_CACHE_HOME: $CI_PROJECT_DIR/.cache

Changes Summary

Removed Modified Added Renamed
0 1 1 0

ℹ️ Diff available in the job log.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant