Dynatrace OneAgent and Kubernetes Operator: Resolving the Injection Boundary in Production
0 reputation · 06 Dec 2022, 13:44 UTC
Integration boundary
A Dynatrace OneAgent configuration that connects in a local Docker Compose setup may not connect when the same application runs under the Dynatrace Kubernetes Operator. The local path typically relies on manually set DT_API_URL and DT_API_TOKEN environment variables. The production path depends on the Operator's mutating webhook and pod annotations to inject connection variables such as DT_CONNECTION_POINT and DT_TENANT.
The unresolved decision is which injection mechanism should be authoritative when both are present or when the webhook is disabled. Operator versions around 0.9.0 changed required annotation keys, and older documentation may still reference dynatrace.com/inject. SaaS and Managed endpoints and token formats are not interchangeable, so a local token may be rejected in production even if injection succeeds. The exact annotation key and version compatibility require current verification against the deployed Operator release.
Open questions
- Does the deployed Operator version inject connection variables through the mutating webhook, or should the OneAgent continue to read manually set
DT_API_URLandDT_API_TOKEN? - Which annotation key is required for the current Operator version, and how does it interact with the webhook?
- When the webhook is unavailable, what is the supported way to supply the connection point without conflicting with Operator-managed values?