Skip to content

Migrate API key to environment secrets - #12126

Merged
gh-worker-dd-mergequeue-cf854d[bot] merged 1 commit into
masterfrom
bbujon/ci
Aug 3, 2026
Merged

Migrate API key to environment secrets#12126
gh-worker-dd-mergequeue-cf854d[bot] merged 1 commit into
masterfrom
bbujon/ci

Conversation

@PerfectSlayer

@PerfectSlayer PerfectSlayer commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

What Does This Do

This PR moves the DD API key to a protected environment.

Motivation

SDLC recommendations

Additional Notes

Contributor Checklist

Jira ticket: APMLP-1687

@PerfectSlayer
PerfectSlayer requested a review from a team as a code owner August 3, 2026 07:13
@PerfectSlayer PerfectSlayer added tag: no release notes Changes to exclude from release notes comp: tooling Build & Tooling labels Aug 3, 2026
@PerfectSlayer
PerfectSlayer requested review from bric3 and removed request for a team August 3, 2026 07:13
@PerfectSlayer PerfectSlayer added the tag: security Security related changes label Aug 3, 2026

@datadog-prod-us1-4 datadog-prod-us1-4 Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Datadog Autotest: PASS

More details

The change only scopes the Trivy job to protected-main-env while preserving its existing Datadog secret expression and leaving CodeQL unchanged. YAML parsing, trigger coverage, environment scope, and secret-resolution scenarios passed; environment protection rules could not be independently read because the repository API returned 403.

Was this helpful? React 👍 or 👎

📊 Validated against 4 scenarios · Open Bits AI session

🤖 Datadog Autotest · Commit 14a5f53 · What is Autotest? · @DataDog review to ask questions · Any feedback? Reach out in #autotest

@datadog-prod-us1-4

datadog-prod-us1-4 Bot commented Aug 3, 2026

Copy link
Copy Markdown

🎯 Code Coverage (details)
Patch Coverage: 100.00%
Overall Coverage: 57.89% (-0.04%)

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 14a5f53 | Docs | Datadog PR Page | Give us feedback!

@dd-octo-sts

dd-octo-sts Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

🟢 Java Benchmark SLOs — All performance SLOs passed

Suite Status
Startup 🟢 pass

SLO thresholds are defined here based on automatically generated metrics. A warning is raised when results are within 5% of the threshold.

PR vs. master results
Scenario Candidate master Δ (95% CI of mean)
startup:insecure-bank:iast:Agent 13.89 s 13.99 s [-1.4%; -0.1%] (maybe better)
startup:insecure-bank:tracing:Agent 12.97 s 12.96 s [-0.7%; +0.8%] (no difference)
startup:petclinic:appsec:Agent 16.96 s 16.77 s [+0.1%; +2.2%] (maybe worse)
startup:petclinic:iast:Agent 17.03 s 16.98 s [-0.6%; +1.2%] (no difference)
startup:petclinic:profiling:Agent 16.77 s 16.86 s [-1.4%; +0.4%] (no difference)
startup:petclinic:sca:Agent 16.73 s 16.63 s [-0.3%; +1.5%] (no difference)
startup:petclinic:tracing:Agent 15.69 s 16.10 s [-6.7%; +1.5%] (no difference)

Commit: 14a5f531 · CI Pipeline · Benchmarking Platform UI


Load and DaCapo benchmarks can be triggered manually in the GitLab pipeline. Results will appear in the Benchmarking Platform UI after completion.

@mhdatie
mhdatie requested review from a team and mhdatie and removed request for a team and bric3 August 3, 2026 12:29
@PerfectSlayer PerfectSlayer added tag: no release notes Changes to exclude from release notes and removed tag: no release notes Changes to exclude from release notes labels Aug 3, 2026
@PerfectSlayer

Copy link
Copy Markdown
Contributor Author

/merge

@gh-worker-devflow-routing-ef8351

gh-worker-devflow-routing-ef8351 Bot commented Aug 3, 2026

Copy link
Copy Markdown

View all feedbacks in Devflow UI.

2026-08-03 12:52:12 UTC ℹ️ Start processing command /merge


2026-08-03 12:52:15 UTC ❌ MergeQueue

PR already in the queue with status in_progress

@sarahchen6

Copy link
Copy Markdown
Contributor

/merge

@gh-worker-devflow-routing-ef8351

gh-worker-devflow-routing-ef8351 Bot commented Aug 3, 2026

Copy link
Copy Markdown

View all feedbacks in Devflow UI.

2026-08-03 13:21:35 UTC ℹ️ Start processing command /merge


2026-08-03 13:21:39 UTC ℹ️ MergeQueue: pull request added to the queue

The expected merge time in master is approximately 1h (p90).


2026-08-03 14:14:30 UTC ℹ️ MergeQueue: This merge request was merged

@PerfectSlayer

Copy link
Copy Markdown
Contributor Author

In fact, you can add the PR to MQ using DDCI UI… But you got no feedback. So I guess it was in queue but stuck…
In short, no idea what's happening and going to spend hours on trying to get a 2l change merged that's not even related to GitLab 😮‍💨

@sarahchen6

Copy link
Copy Markdown
Contributor

Hm I didn't know you could add a PR to MQ directly from DDCI UI... Maybe that somehow caused a double add to the MQ and the error from above "PR already in the queue with status in_progress" despite there being nothing in the MQ.

@PerfectSlayer

Copy link
Copy Markdown
Contributor Author

Yes, I did comment "/merge" to try to get the status and it failed as already in queue. Let's wait for Today and check later if it moved 🤷

@gh-worker-dd-mergequeue-cf854d
gh-worker-dd-mergequeue-cf854d Bot merged commit 464ce1a into master Aug 3, 2026
591 of 601 checks passed
@gh-worker-dd-mergequeue-cf854d
gh-worker-dd-mergequeue-cf854d Bot deleted the bbujon/ci branch August 3, 2026 14:14
@github-actions github-actions Bot added this to the 1.65.0 milestone Aug 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comp: tooling Build & Tooling tag: no release notes Changes to exclude from release notes tag: security Security related changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants