Skip to content

[pull] master from DataDog:master - #1100

Merged
pull[bot] merged 18 commits into
DevKyleS:masterfrom
DataDog:master
Aug 21, 2026
Merged

[pull] master from DataDog:master#1100
pull[bot] merged 18 commits into
DevKyleS:masterfrom
DataDog:master

Conversation

@pull

@pull pull Bot commented Aug 21, 2026

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

valeryjuli and others added 18 commits August 21, 2026 15:57
* Add IaC CI setup doc

* Fix heading capitalization and variable name mismatch in IaC CI setup doc

* Apply word-list and sentence-length fixes to IaC CI setup doc

* Update from feedback on iac-setup

* Update hugo/content/en/security/code_security/iac_security/setup.md

Co-authored-by: May Lee <may.lee@datadoghq.com>

---------

Co-authored-by: May Lee <may.lee@datadoghq.com>
… event volume tuning (#39354)

* Runtime Package Prioritization: document enablement prerequisites and event volume tuning

Adds the kernel, host PID namespace, and PodSecurity prerequisites, plus
enrichment interval tuning guidance for large fleets.

Co-Authored-By: Claude <noreply@anthropic.com>

* Soften system-probe memory guidance and add a verification step

Replaces the fixed memory recommendation with monitoring guidance, and
adds a verification step to each setup page.

Co-Authored-By: Claude <noreply@anthropic.com>

* Link kernel support instead of restating a version

Points at the Workload Protection distribution list rather than naming a
kernel version on three pages.

Co-Authored-By: Claude <noreply@anthropic.com>

* Correct claims that did not hold up against Agent source

- Drops the hostPID and --pid host requirements: the real dependency is the
  host /proc mount, and hostPID is baseline Agent configuration.
- States that the setting starts system-probe, which is the actual change to
  a node's footprint.
- Corrects the verification step: the Agent status output has no SBOM section,
  the sbom check appears under Collector.
- Corrects the enrichment interval trade-off: first observations bypass the
  interval, so only repeat observations are throttled.
- Drops the claim that system-probe memory grows with image count; its caches
  are fixed size.

Co-Authored-By: Claude <noreply@anthropic.com>

* Cut repeated version and Workload Protection notes, add Docker tuning

The version requirement and the Workload Protection statement each appeared
three or four times per page, and described pre-7.79 behavior the pages tell
readers not to use. Each now appears once. Adds the enrichment interval
guidance to the Docker page for parity.

Co-Authored-By: Claude <noreply@anthropic.com>

* Name the supported package managers in the scope line

"Operating system packages" was open to interpretation. States apt/dpkg,
yum/dnf/rpm, and apk, and that application libraries and unmanaged binaries
receive no runtime signals.

Co-Authored-By: Claude <noreply@anthropic.com>

* Trim wording to match the style of neighboring setup pages

Cuts mechanism explanations, the Agent status check that reported nothing
about this feature, and redundant qualifiers. Verification now leads with
the product outcome, matching the Verify sections on other setup pages.

Co-Authored-By: Claude <noreply@anthropic.com>

* State only what the feature supports, and align the RPE page

Drops two sentences that claimed more than needed. Adds the same scope
statement to the Runtime Prioritization Engine page and aligns its Agent
version guidance with the setup pages.

Co-Authored-By: Claude <noreply@anthropic.com>

* Remove the enrichment interval tuning guidance

The default is appropriate at customer scale, raising the interval reduces
signal freshness, and the effect is not observable from the Agent. Keeps the
system-probe memory note.

Co-Authored-By: Claude <noreply@anthropic.com>

* Keep only the requirements, the version risk, and the scope

Requirements now lists actual requirements. Restores the pre-7.79 Workload
Protection caveat as a single note, states signal scope once, and drops the
procfs, system-probe, and memory lines the proven enablement path never needed.

Co-Authored-By: Claude <noreply@anthropic.com>

* Remove the pre-7.79 Workload Protection note

The pages require 7.79.0 or later, so the note described a configuration
readers are not being pointed to. Removing it avoids suggesting the legacy
path is current.

Co-Authored-By: Claude <noreply@anthropic.com>

* Apply review feedback

- Add the missing period to the version bullet on the Docker and Linux pages.
- Split the runtime signals sentence on the engine page.
- Make the Agent version formatting consistent under Get started.

Co-Authored-By: Claude <noreply@anthropic.com>

---------

Co-authored-by: Claude <noreply@anthropic.com>
* llm-obs: SDK documentation end-user feedback

* llm-obs: use dedicated Feedback data source in Analyze feedback

* Apply suggestions from code review

Co-authored-by: Eva Parish <eva.parish@datadoghq.com>

---------

Co-authored-by: Eva Parish <eva.parish@datadoghq.com>
* Clarify Session Replay masking is permanent

Distinguish Session Replay masking (permanent, values never leave the
device) from Sensitive Data Scanner masking (reversible by users with
the Data Scanner Unmask permission).

* Apply suggestions from code review

Co-authored-by: domalessi <111786334+domalessi@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: Rosa Trieu <107086888+rtrieu@users.noreply.github.com>

* Apply suggestion from @rtrieu

---------

Co-authored-by: domalessi <111786334+domalessi@users.noreply.github.com>
Co-authored-by: ci.datadog-api-spec <packages@datadoghq.com>
Co-authored-by: ci.datadog-api-spec <packages@datadoghq.com>
* Add Workflow Automation MCP Tools doc page

Documents the workflows toolset in the Datadog MCP Server: setup,
available tools (discovery, spec/action discovery, creation and
management, validation, execution, and debugging), and permissions.

* Add sidebar nav entry for Workflow Automation MCP Tools page

* Shorten sidebar label for Workflow Automation MCP Tools page

* [DOCS-15371] Align Workflow Automation MCP tools page with tools reference (#39287)

* [DOCS-15371] Align Workflow Automation MCP tools page with mcp_server/tools.md

Replace duplicated per-tool descriptions and example requests with links
to each tool's entry in the canonical mcp_server/tools.md reference,
move Permissions above Available tools, and fix minor wording issues.

* Add lifecycle context sentences to Workflow Automation MCP Tools categories

Add one sentence to each tool category under Available tools describing
what it's used for, forming a single connected example across discovery,
action lookup, creation, validation, execution, and debugging.

* Add use cases section and editorial fixes to Workflow Automation MCP Tools

Replace the per-category lifecycle sentences with a single Use cases
section, correct Bits Investigation naming, drop the non-standard
"Workflow Automations" plural, and split overlong sentences per Vale.

* Add two more tools

* Remove validation and debugging sections from mcp_tools.md

Removed sections on workflow validation and execution debugging from mcp_tools.md.

---------

Co-authored-by: Esther Kim <esther.kim@datadoghq.com>
Co-authored-by: Gabriel Margolis <gabriel.margolis@datadoghq.com>
Retention quotas can now be configured through the public API, but the
docs page only covers the in-app setup. Add a short API section pointing
to the API reference, matching the equivalent section on the retention
filters page.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* Add description frontmatter to Observability Pipelines configuration docs

* Apply suggestions from code review

Co-authored-by: May Lee <may.lee@datadoghq.com>

* Apply suggestions from code review

Co-authored-by: domalessi <111786334+domalessi@users.noreply.github.com>

* Apply suggestion from @maycmlee

---------

Co-authored-by: domalessi <111786334+domalessi@users.noreply.github.com>
* WIP

* New Toc

* Agent rules and secl guide

* req fix

* remove some

* coverage in main page

* fix link

* policy management

* add links to OOTB rules and create rule and detection

* WIP detection rule

* first change in Agent events

* WIP repond and report

* Content pack WIP

* WIP signals

* WIP 2 detection

* coverage remove old pages

* Rewrite Coverage page for reworked Workload Protection coverage map

First draft: update Coverage doc to match current product (Explorer/Map
views, group by, Pass/Error severity, policy and rule statuses with
verdicts, top widget findings). Add screenshots.

* docs: finding rules/finding explorer

* variables and actions

* fix agent events

* remove useless guides

* remove ebpfless setup

* Agent events

* rename automated response

* rename remeditation response

* signal overview

* combine response pages

* Advanced config static

* Add Workload Protection-specific threat intelligence page

* feat: update automated response doc

* Add deployment strategies section with managed deployment and deploy instantly guides

* Apply formatting normalization

* remove useless part of guide

* remove useless image

* move response rbac

* Remove advanced use cases for now

* fix nav

* last fix actions

* fix link in response

* Apply style guide and formatting fixes to Workload Protection docs (#38502)

* Improve Workload Protection agent and backend rule documentation.

Update SecL examples to full rule syntax, move backend syntax under detection rules in the nav, and document backend event schema fields for detection and finding rule queries.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Reorganize detection and finding rules documentation under a shared section.

Add a parent overview page, move detection and finding rules into a dedicated subsection, group backend syntax references there, and update internal links with aliases for the previous URLs.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix SecL examples identation

* Structural Changes for Workload Protection PR (#38623)

* Consolidate duplicate Workload Protection nav blocks

* Restore site-wide Detection Rules navigation entry

* Delete Workload Protection pages superseded by aliases

* Delete superseded Workload Protection pages and retarget inbound links

* Rename Workload Protection getting_started section to setup

* Scope eBPF-less agent docs to AWS Fargate

* Retarget broken agent_expressions and notification rules links

* Add redirects for moved and deleted Workload Protection pages

* Rename Workload Protection setup page title to Setting up Workload Protection

* Global edit of screenshots

* Edit troubleshooting

* small review and rewording

* Restructure Workload Protection overview and standardize landing page openers (#39127)

* Restructure Workload Protection overview and standardize landing page openers

* Move Use cases above How it works on the Workload Protection overview

* Rename Use cases to Beyond threat detection and consolidate policy content

* Add product purpose and Datadog platform context to Workload Protection overview

* rename eBPFLess by cws-instrumentation tracer

* add Saving resources by design and reorder eval steps

* Minor edits

---------

Co-authored-by: Theo Putegnat <theo.putegnat@datadoghq.com>

* docs: reorganize Workload Protection setup (#39216)

* Workload Protection reorg: Detect and Monitor content revisions (#39215)

* docs: refine Detect and Monitor content

* docs: use reference links for Agent Rules

* tiny changes

* Minor edits

---------

Co-authored-by: Theo Putegnat <theo.putegnat@datadoghq.com>

* Workload Protection reorg Coverage updates (#39213)

* docs: split Coverage reference and tasks

* docs: consolidate Coverage functionality

* docs: consolidate Coverage benefits

* docs: organize Coverage review tasks

* docs: simplify Coverage review order

* docs: standardize Coverage terminology

* docs: refine Coverage review guidance

* docs: align Coverage tasks with review order

* docs: preserve Coverage review guidance

* docs: finalize Coverage page structure

* Add screenshots

* docs: add Coverage page screenshots

* add dual ship guide

* Refine Workload Protection investigate and triage docs (#39256)

* Refine Workload Protection investigate and triage docs

* Rename signal actions page to Triage and Act on Security Signals

* Refine Workload Protection response docs (#39302)

* Refine Workload Protection response docs

* Complete Workload Protection response cleanup

* Fix response terminology, restore enforcement defaults and network probe config

* Tighten response intro, remove duplicated action lists, lowercase automated response in prose

* Lowercase automated response in prose and remove duplicated enforcement sentence

* Add lead-in under Response requirements heading

* Change respond report

---------

Co-authored-by: Theo Putegnat <theo.putegnat@datadoghq.com>

* Workload Protection reorg final review (#39348)

* Apply review fixes: reference-style links, Vale wording, whitespace

* Fix reference link scoping in tabs, comma and list marker consistency, rename tuning guide

* Add page descriptions, apply ui shortcode to UI labels, capitalize Explorer, drop redundant Overview headings

* Move backend rule callout into Agent rules intro and drop orphan paragraph

* Drop How to from dual shipping guide title

* Fix spacing before Manual response heading

* Workload Protection reorg: Restore images and revert dependencies (#39349)

* Restore deleted CWS images and revert requirements3.txt to master

* Use card-grid shortcodes for Workload Protection setup tiles instead of deprecated tile partials

* Restore threat_detection_pipeline_2.png at its original path for translated pages

* Addressed yoann's changes

* addressed john comments part1

* rename to wp

* Fix App and API Protection incident link

* Convert inline links to reference-style links in Workload Protection troubleshooting

* Address john comments v2

* Last minute fixes for title casing of docs

---------

Co-authored-by: gui774ume <gui774ume.fournier@gmail.com>
Co-authored-by: Theo Putegnat <theo.putegnat@datadoghq.com>
Co-authored-by: Bang NGUYEN <bang.nguyen@datadoghq.com>
Co-authored-by: Danila <danila.ivanov@datadoghq.com>
Co-authored-by: Axel Manuel <axel.manuel@datadoghq.com>
Co-authored-by: thibaud.szymczak <thibaud.szymczak@datadoghq.com>
Co-authored-by: DeForest Richards <56796055+drichards-87@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: DeForest Richards <deforest.richards@datadoghq.com>
* Align optimization validation guide with UI

* [SDTEST-3822] Incorporate github-actions' feedback

* [SDTEST-3822] Incorporate additional github-actions feedback

* [SDTEST-3822] Incorporate validation clarity feedback

* [SDTEST-3822] Address follow-up validation feedback

* [SDTEST-3822] Polish validation walkthrough

* [SDTEST-3822] Clarify validation setup and flow

* [SDTEST-3822] Remove temporal wording

* [SDTEST-3822] Refine validation guidance

* [SDTEST-3822] Improve validation walkthrough clarity

* [SDTEST-3822] Clarify validation state and filters

* [SDTEST-3822] Refine validation instructions

* [SDTEST-3822] Polish validation guidance

* [SDTEST-3822] Clarify remediation terminology

* [SDTEST-3822] Standardize validation results

* [SDTEST-3822] Surface validation workflow constraints

* [SDTEST-3822] Tighten validation wording

* [SDTEST-3822] Apply final validation review

* [SDTEST-3822] Fix validation service setup

* [SDTEST-3822] Update repository settings screenshot

* [SDTEST-3822] Clarify mitigation marker change

* [SDTEST-3822] Add post-validation guidance

* [SDTEST-3822] Clarify validation workflow

* [SDTEST-3822] Fix validation setup commit step

* [SDTEST-3822] Document quarantine policy setup

* [SDTEST-3822] Incorporate datadog-official's feedback

* [SDTEST-3822] Incorporate clreaume's feedback

* Apply suggestions from code review

Co-authored-by: Cara Reaume <35357020+clreaume@users.noreply.github.com>

* Address validation guide review feedback

* Apply suggestions from code review

Co-authored-by: Cara Reaume <35357020+clreaume@users.noreply.github.com>

* [SDTEST-3822] Restore test service explanation

---------

Co-authored-by: Cara Reaume <35357020+clreaume@users.noreply.github.com>
…upport (#39398)

* Update Browser Developer Extension docs for multi-site support

The Feature Flags tab now supports all commercial Datadog sites and
stores local overrides separately for each site.

- List the supported commercial sites in the prerequisites, and add the
  government site callout used on the client SDK pages
- Tell readers to select their site before signing in
- Document per-site override scoping and the reload banner
- Document the signed-out Clear all, and how Clear all scopes to the
  connected site when signed in
- Document the type-mismatch and flag-not-in-catalog row warnings
- Use a site placeholder in the DatadogDevtools sample

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Drop duplicate gov callout, note that the two site settings must match

The gov/gov2 callout is injected for every page under /feature_flags/
by the site_support_banner partial, so authoring one in the source
rendered it twice. The prerequisites line keeps the exclusion in text.

Also note that the site in the provider config should match the site
selected in the extension dropdown.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Update hugo/content/en/feature_flags/browser_developer_extension.md

Co-authored-by: Olivia Shoup <116908616+OliviaShoup@users.noreply.github.com>

* Update hugo/content/en/feature_flags/browser_developer_extension.md

Co-authored-by: Olivia Shoup <116908616+OliviaShoup@users.noreply.github.com>

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: Olivia Shoup <116908616+OliviaShoup@users.noreply.github.com>
Co-authored-by: webops-guacbot[bot] <214537265+webops-guacbot[bot]@users.noreply.github.com>
@pull pull Bot locked and limited conversation to collaborators Aug 21, 2026
@pull pull Bot added the ⤵️ pull label Aug 21, 2026
@pull
pull Bot merged commit ee21deb into DevKyleS:master Aug 21, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.