Skip to content

kyverno: add container-based config discovery support - #24511

Draft
vitkyrka wants to merge 1 commit into
vwhitchurch/argo_workflows-discoveryfrom
vwhitchurch/kyverno-discovery
Draft

kyverno: add container-based config discovery support#24511
vitkyrka wants to merge 1 commit into
vwhitchurch/argo_workflows-discoveryfrom
vwhitchurch/kyverno-discovery

Conversation

@vitkyrka

@vitkyrka vitkyrka commented Jul 10, 2026

Copy link
Copy Markdown
Contributor

What does this PR do?

Adds container-based config discovery support to kyverno.

Discovery finds the Kyverno controller metrics endpoints using named Kubernetes ports (metrics-port and metrics) instead of a numeric port hint.

The ad_identifiers targets somewhat generic image names (background-controller, etc.) so we use a CEL selector to narrow those to Kyverno images.

The E2E coverage validates that Kubernetes Autodiscovery finds the four Kyverno controller instances and that generated discovery candidates can probe a Kyverno controller without destabilizing it.

Motivation

https://datadoghq.atlassian.net/browse/DSCVR-527

Review checklist (to be filled by reviewers)

  • Feature or bugfix MUST have appropriate tests (unit, integration, e2e)
  • Add qa/required if this PR needs QA validation, or qa/skip-qa if it does not. Exactly one of the two is required.
  • If you need to backport this PR to another branch, you can add the backport/<branch-name> label to the PR and it will automatically open a backport PR once this one is merged

@vitkyrka vitkyrka added the qa/skip-qa Automatically skip this PR for the next QA label Jul 10, 2026 — with ddtool CLI
vitkyrka added a commit that referenced this pull request Jul 10, 2026
Also renames the inherited keda-discovery changelog entries (24459.added
in keda/ and datadog_checks_dev/) to this PR's number, since the
Check PR changelog CI job flags them as belonging to a different PR
while this branch is based on the unmerged vwhitchurch/keda-discovery
branch.

Environment: Datadog workspace

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@datadog-datadog-us1-prod

datadog-datadog-us1-prod Bot commented Jul 10, 2026

Copy link
Copy Markdown

Tests  Code Coverage

🎉 All green!

🧪 All tests passed
❄️ No new flaky tests detected

🎯 Code Coverage (details)
Patch Coverage: 50.00%
Overall Coverage: 81.48% (+11.59%)

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 3c32b04 | Docs | Datadog PR Page | Give us feedback!

@vitkyrka
vitkyrka changed the base branch from master to vwhitchurch/keda-discovery July 10, 2026 22:07
@vitkyrka
vitkyrka changed the base branch from vwhitchurch/keda-discovery to graphite-base/24511 July 16, 2026 08:50
@vitkyrka
vitkyrka force-pushed the vwhitchurch/kyverno-discovery branch from 23cd8fa to a1920d3 Compare July 16, 2026 08:50
@vitkyrka
vitkyrka force-pushed the graphite-base/24511 branch from 2c0dc75 to 50cc010 Compare July 16, 2026 08:50
@vitkyrka
vitkyrka changed the base branch from graphite-base/24511 to master July 16, 2026 08:50

vitkyrka commented Jul 16, 2026

Copy link
Copy Markdown
Contributor Author

Warning

This pull request is not mergeable via GitHub because a downstack PR is open. Once all requirements are satisfied, merge this PR as a stack on Graphite.
Learn more

This stack of pull requests is managed by Graphite. Learn more about stacking.

@vitkyrka
vitkyrka changed the base branch from master to graphite-base/24511 July 16, 2026 08:51
@vitkyrka
vitkyrka force-pushed the vwhitchurch/kyverno-discovery branch from a1920d3 to f156b2d Compare July 16, 2026 08:51
@vitkyrka
vitkyrka changed the base branch from graphite-base/24511 to vwhitchurch/argo_workflows-discovery July 16, 2026 08:51
Scopes discovery to the kyverno-admission-controller (image
ghcr.io/kyverno/kyverno, port 8000), the integration's namesake
component. The background/cleanup/reports controllers use distinct
images and are not yet covered.

Environment: Datadog workspace

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@vitkyrka
vitkyrka force-pushed the vwhitchurch/kyverno-discovery branch from f156b2d to 3c32b04 Compare July 16, 2026 08:55
@dd-octo-sts

dd-octo-sts Bot commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

Validation Report

Validation Description Status
license-headers Validate Python files have proper license headers
models Validate configuration data models match spec.yaml

Run ddev validate all changed --fix to attempt to auto-fix supported validations.

Passed validations (19)
Validation Description Status
agent-reqs Verify check versions match the Agent requirements file
ci Validate CI configuration and code coverage settings
codeowners Validate every integration has a CODEOWNERS entry
config Validate default configuration files against spec.yaml
dep Verify dependency pins are consistent and Agent-compatible
http Validate integrations use the HTTP wrapper correctly
imports Validate check imports do not use deprecated modules
integration-style Validate check code style conventions
jmx-metrics Validate JMX metrics definition files and config
labeler Validate PR labeler config matches integration directories
legacy-signature Validate no integration uses the legacy Agent check signature
licenses Validate third-party license attribution list
metadata Validate metadata.csv metric definitions
openmetrics Validate OpenMetrics integrations disable the metric limit
package Validate Python package metadata and naming
qa-label Validate the pull request declares whether it needs QA for the next Agent release
readmes Validate README files have required sections
saved-views Validate saved view JSON file structure and fields
version Validate version consistency between package and changelog

View full run

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant