Skip to content

Migrate DD_API_KEY to dd-sts in coverage workflow - #400

Merged
gh-worker-dd-mergequeue-cf854d[bot] merged 1 commit into
masterfrom
nicolas.schweitzer/dd-sts
Sep 3, 2026
Merged

gh-worker-dd-mergequeue-cf854d[bot] merged 1 commit into
masterfrom
nicolas.schweitzer/dd-sts

Conversation

@chouetz

@chouetz chouetz commented Aug 20, 2026 •

Copy link
Copy Markdown
Member

https://datadoghq.atlassian.net/browse/ACIX-1817

Summary

  • Replaces the static DD_API_KEY secret with short-lived credentials obtained via dd-sts-action
  • Adds permissions: id-token: write to the coverage job so the runner can federate OIDC tokens
  • The corresponding policy (datadog-go-coverage-upload) has been created in dd-source under domains/seceng/sit/apps/apis/dd-sts/config/policies/us1.ddbuild.io/

Test plan

  • Confirm the dd-source policy PR is merged and deployed (check mosaic) see https://github.com/ddoghq/dd-source/pull/62067
  • Verify the coverage job passes after this PR is merged
  • If a 403 is returned by the Datadog API, reach out to #sdlc-security to add the required scope to the dd-sts service account

🤖 Generated with Claude Code

@chouetz
chouetz marked this pull request as ready for review August 20, 2026 16:02
@chouetz
chouetz requested a review from a team as a code owner August 20, 2026 16:02

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a57d87b505

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/datadog-go.yaml
@atanzu

atanzu commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

Hi @chouetz , could you please address this comment before merging?

Replace the static DD_API_KEY secret with short-lived credentials from
dd-sts-action, using the datadog-go-coverage-upload policy.
@chouetz
chouetz force-pushed the nicolas.schweitzer/dd-sts branch from a57d87b to 6123b48 Compare August 25, 2026 07:24
@chouetz

chouetz commented Aug 25, 2026

Copy link
Copy Markdown
Member Author

Hi @chouetz , could you please address this comment before merging?

@atanzu done, thanks for the check!

@datadog-datadog-prod-us1

datadog-datadog-prod-us1 Bot commented Sep 3, 2026 •

Copy link
Copy Markdown

Pipelines  Code Coverage

🎯 Code Coverage (details)
• Patch Coverage: 100.00%
• Overall Coverage: 84.95% (-0.10%)

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 6123b48 | Docs | View more details | Give us feedback!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants