Skip to content

Replace long-lived DD_CI_VIS_API_KEY by short-lived credentials via dd-sts-action - #357

Open
xlamorlette-datadog wants to merge 3 commits into
mainfrom
xlamorlette/remove-dd-ci-vis-api-key
Open

Replace long-lived DD_CI_VIS_API_KEY by short-lived credentials via dd-sts-action#357
xlamorlette-datadog wants to merge 3 commits into
mainfrom
xlamorlette/remove-dd-ci-vis-api-key

Conversation

@xlamorlette-datadog

@xlamorlette-datadog xlamorlette-datadog commented Aug 20, 2026

Copy link
Copy Markdown
Collaborator

Description

Migrate the long-lived DD_CI_VIS_API_KEY secret to short-lived credentials from dd-sts.

This is done with a new local composite action, .github/actions/dd-sts-credentials, which uses DataDog/dd-sts-action.

Additional Notes

By the way, small amendment in agents intsructions.

Jira ticket: IDMPL-808 [C++ Tracer] [CI] Remove DD_CI_VIS_API_KEY secret

@pr-commenter

pr-commenter Bot commented Aug 20, 2026

Copy link
Copy Markdown

Benchmarks

Benchmark execution time: 2026-08-20 11:34:32

Comparing candidate commit f9fa899 in PR branch xlamorlette/remove-dd-ci-vis-api-key with baseline commit 765983d in branch main.

Found 0 performance improvements and 0 performance regressions! Performance is the same for 8 metrics, 0 unstable metrics.

Explanation

This is an A/B test comparing a candidate commit's performance against that of a baseline commit. Performance changes are noted in the tables below as:

  • 🟩 = significantly better candidate vs. baseline
  • 🟥 = significantly worse candidate vs. baseline

We compute a confidence interval (CI) over the relative difference of means between metrics from the candidate and baseline commits, considering the baseline as the reference.

If the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD), the change is considered significant.

Feel free to reach out to #apm-benchmarking-platform on Slack if you have any questions.

More details about the CI and significant changes

You can imagine this CI as a range of values that is likely to contain the true difference of means between the candidate and baseline commits.

CIs of the difference of means are often centered around 0%, because often changes are not that big:

---------------------------------(------|---^--------)-------------------------------->
                              -0.6%    0%  0.3%     +1.2%
                                 |          |        |
         lower bound of the CI --'          |        |
sample mean (center of the CI) -------------'        |
         upper bound of the CI ----------------------'

As described above, a change is considered significant if the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD).

For instance, for an execution time metric, this confidence interval indicates a significantly worse performance:

----------------------------------------|---------|---(---------^---------)---------->
                                       0%        1%  1.3%      2.2%      3.1%
                                                  |   |         |         |
       significant impact threshold --------------'   |         |         |
                      lower bound of CI --------------'         |         |
       sample mean (center of the CI) --------------------------'         |
                      upper bound of CI ----------------------------------'

@xlamorlette-datadog
xlamorlette-datadog marked this pull request as ready for review August 20, 2026 12:00
@xlamorlette-datadog
xlamorlette-datadog requested review from a team as code owners August 20, 2026 12:00
@xlamorlette-datadog
xlamorlette-datadog requested review from cataphract and removed request for a team August 20, 2026 12:00
@xlamorlette-datadog xlamorlette-datadog changed the title Replace DD_CI_VIS_API_KEY secret by dd-sts-action Replace long-lived DD_CI_VIS_API_KEY by short-lived credentials via dd-sts-action Aug 20, 2026
Comment thread CLAUDE.md

@zacharycmontoya zacharycmontoya Aug 20, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The @AGENTS.md is needed rather than AGENTS.md so Claude can in-line the contents of the AGENTS.md file. What you have might work, but the @ is the best practice for inlining

Suggested change
@AGENTS.md

@zacharycmontoya zacharycmontoya left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants