Skip to content

DataDog: CDAP to manage sensitive permissions groups. - #623

Merged
mianava merged 4 commits into
mainfrom
ddpermissions
Oct 7, 2026
Merged

mianava merged 4 commits into
mainfrom
ddpermissions

Conversation

@mianava

@mianava mianava commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

🎫 Ticket

https://jira.cms.gov/browse/...

🛠 Changes

Adds permissions for managing datadog groups to alert based on sensitive data ingestion.

ℹ️ Context

These changes were made as our permissions were insufficient.

🧪 Validation

Validated by applying locally.

@mianava
mianava marked this pull request as ready for review October 5, 2026 17:18
@mianava
mianava requested a review from a team as a code owner October 5, 2026 17:18
@mianava
mianava enabled auto-merge (squash) October 5, 2026 20:26
@Santoshkumarpuppala

Copy link
Copy Markdown

This adds data_scanner_write, but the key still has no read scope for the scanner. The provider's group Read lists groups through ListScanningGroups (v4.24.0, which CI installs), and Datadog's API spec gates that endpoint on data_scanner_read alone. The create apply never lists, so it passes; the next refresh or plan of 502-datadog-config should then fail on that call. Adding data_scanner_read to line 7 would cover it. Read from the provider source and the spec, not run.

synthetics_manager = var.synthetics_manager ? ["synthetics_read", "synthetics_write", "synthetics_global_variable_read", "synthetics_global_variable_write", "synthetics_private_location_read"] : []
users_manager = var.users_manager ? ["user_access_manage", "user_access_read", "teams_manage"] : []
org_config_manager = var.org_config_manager ? ["monitor_config_policy_write", "create_webhooks"] : []
org_config_manager = var.org_config_manager ? ["monitor_config_policy_write", "create_webhooks", "data_scanner_write"] : []

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the keys might also need "data_scanner_read" to read the IDs of the standard rules.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Oh looks like @Santoshkumarpuppala already noticed that.

Comment thread terraform/modules/datadog_application_key/main.tf Outdated
@mianava
mianava merged commit 3850253 into main Oct 7, 2026
5 checks passed
@mianava
mianava deleted the ddpermissions branch October 7, 2026 16:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants