Skip to content

feat(telemetry): report AppSec state at startup - #426

Open
e-n-0 wants to merge 2 commits into
masterfrom
flavien.darche/appsec-telemetry-product-state
Open

e-n-0 wants to merge 2 commits into
masterfrom
flavien.darche/appsec-telemetry-product-state

Conversation

@e-n-0

@e-n-0 e-n-0 commented Sep 2, 2026 •

Copy link
Copy Markdown
Member

Summary

  • register the AppSec product in app-started telemetry for WAF-enabled builds
  • report the state owned by security::Library and the nginx module version
  • clear stale active state when AppSec is explicitly disabled

Dependency

Depends on DataDog/dd-trace-cpp#366, which fixes serialization of registered telemetry products.

Validation

  • WAF-enabled CMake build of the changed objects
  • unit_tests: passed
  • native NGINX telemetry capture with AppSec disabled: enabled=false, version=1.22.0
  • native NGINX telemetry capture with AppSec enabled: enabled=true, version=1.22.0
  • clangd diagnostics: clean

@datadog-prod-us1-3

datadog-prod-us1-3 Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

Tests

✅ All CI checks and tests passed.

🎉 All green!

🧪 All tests passed
❄️ No new flaky tests detected

🎯 Code Coverage (details)
• Patch Coverage: 100.00%
• Overall Coverage: 69.33% (+0.04%)

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: c1f1e7a | Docs | View more details | Give us feedback!

@e-n-0
e-n-0 force-pushed the flavien.darche/appsec-telemetry-product-state branch from fda30f7 to c1f1e7a Compare October 2, 2026 14:56
@e-n-0
e-n-0 marked this pull request as ready for review October 2, 2026 15:24
@e-n-0
e-n-0 requested review from a team as code owners October 2, 2026 15:25

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c1f1e7a7ec

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread src/tracing_library.cpp
Comment thread src/security/library.cpp

if (conf.enable_status() ==
FinalizedConfigSettings::enable_status::DISABLED) {
Library::set_active(false);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks like the default of active_ should be false instead

Comment thread src/tracing_library.cpp
Comment on lines +126 to +131
datadog::telemetry::Product{datadog::telemetry::Product::Name::appsec,
security::Library::active(),
datadog_semver_nginx_mod,
{},
{},
{}});

@cataphract cataphract Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this what you really want? By this time, this will have been run:

set_active(status == ENABLED)

if status is UNSPECIFIED, it will report false. But aftwerwards RC may enable it. So this will report false for everyone using RC to activate/deactive appsec via RC.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants