Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.

Use the following instructions to enable Misconfigurations and Vulnerability Management.

Collecting events using Cloud Security affects your billing. For more information, see Datadog Pricing.

Prerequisites

Note: SBOM collection is not compatible with the image streaming feature in Google Kubernetes Engine (GKE). To disable it, see the Disable Image streaming section of the GKE docs.

Installation

  1. Add the following to the spec section of the datadog-agent.yaml file:

    # datadog-agent.yaml file
    apiVersion: datadoghq.com/v2alpha1
    kind: DatadogAgent
    metadata:
      name: datadog
    spec:
      features:
        # Enables Misconfigurations
        cspm:
          enabled: true
          hostBenchmarks:
            enabled: true
    
        # Enables Software Bill of Materials (SBOM) collection
        sbom:
          enabled: true
    
          # Enables Container Vulnerability Management
          containerImage:
            enabled: true
            # Enables scanning of application libraries in addition to OS packages (Agent 7.70+)
            analyzers: ["os", "languages"]
    
          # Enables Host Vulnerability Management
          host:
            enabled: true
            # Enables scanning of application libraries in addition to OS packages (Agent 7.70+)
            analyzers: ["os", "languages"]
    
          # Enables runtime package prioritization (Preview, Agent 7.79+)
          # See Runtime Package Prioritization section below.
          enrichment:
            usage:
              enabled: true
    
  2. Apply the changes and restart the Agent.

  1. Add the following to the datadog section of the datadog-values.yaml file:

    # datadog-values.yaml file
    datadog:
      securityAgent:
        # Enables Misconfigurations
        compliance:
          enabled: true
          host_benchmarks:
            enabled: true
    
      # Enables Software Bill of Materials (SBOM) collection
      sbom:
        # Enables Container Vulnerability Management
        containerImage:
          enabled: true
          # Enables scanning of application libraries in addition to OS packages (Agent 7.70+)
          analyzers: ["os", "languages"]
    
        # Enables Host Vulnerability Management
        host:
          enabled: true
          # Enables scanning of application libraries in addition to OS packages (Agent 7.70+)
          analyzers: ["os", "languages"]
    
        # Enables runtime package prioritization (Preview, Agent 7.79+)
        # See Runtime Package Prioritization section below.
        enrichment:
          usage:
            enabled: true
    
  2. Restart the Agent.

  1. Add the following environment variables to every Agent container in the daemonset.yaml file, including agent, security-agent, and system-probe. These variables enable Misconfigurations, Vulnerability Management, mount-based container image scanning, and runtime package prioritization.

    - name: DD_COMPLIANCE_CONFIG_ENABLED
      value: "true"
    - name: DD_COMPLIANCE_CONFIG_HOST_BENCHMARKS_ENABLED
      value: "true"
    - name: DD_SBOM_ENABLED
      value: "true"
    - name: DD_SBOM_CONTAINER_IMAGE_ENABLED
      value: "true"
    - name: DD_SBOM_HOST_ENABLED
      value: "true"
    - name: DD_SBOM_CONTAINER_IMAGE_USE_MOUNT
      value: "true"
    - name: DD_SBOM_ENRICHMENT_USAGE_ENABLED
      value: "true"
    - name: HOST_ROOT
      value: /host/root
    

    If your DaemonSet mounts the host root at a different path, set HOST_ROOT to that mount path in each Agent container.

  2. Set hostPID: true in the pod spec and add the following securityContext to the agent container. These settings are required for mount-based container image scanning with DD_SBOM_CONTAINER_IMAGE_USE_MOUNT=true.

      # Source: datadog/templates/daemonset.yaml
      apiVersion: apps/v1
      kind: DaemonSet
      [...]
      spec:
        [...]
        template:
          [...]
          spec:
            hostPID: true
            containers:
            [...]
              - name: agent
                [...]
                securityContext:
                  capabilities:
                    add:
                      - SYS_ADMIN
                  readOnlyRootFilesystem: true
                  appArmorProfile:
                    type: Unconfined
    
  3. Restart the Agent.

Note: enrichment.usage.enabled: true is in Preview and requires Datadog Agent 7.79.0 or later. From 7.79.0, runtime package prioritization runs independently of Workload Protection and does not affect its usage. See the Runtime Package Prioritization section for more details.

Note: The languages analyzer requires Datadog Agent 7.70 or later. When enabled, it detects vulnerabilities in application libraries managed by the package managers below, in addition to OS packages. When the analyzers field is omitted, Datadog only scans OS packages for container images.

Supported application library package managers

The languages analyzer covers the following package ecosystems:

EcosystemPackage manager/format
RubyBundler, GemSpec
RustCargo, Rust binary
PHPComposer
JavaJar, Maven (pom.xml), Gradle lock, Sbt lock
JavaScriptnpm (package-lock.json), Yarn, pnpm, Node package
.NETNuGet, .NET Core, PackagesProps
PythonPython package (egg), pip, Pipenv, Poetry, uv, Conda package, Conda environment
GoGo binary, Go modules
C/C++Conan lock
Swift / Objective-CCocoaPods, Swift
DartPubSpec lock
ElixirMix lock
JuliaJulia

Runtime Package Prioritization (Preview)

Runtime package prioritization identifies which packages in a container image are used at runtime, so you can prioritize vulnerabilities in code that runs over vulnerabilities in packages that are installed but never executed.

When enabled, the Agent uses eBPF to observe file access on your workloads and adds these signals to vulnerability findings for that image:

SignalWhat it tells you
Package is runningThe package’s files were observed being accessed by a running process.
Accessed by root processThe package was accessed by a process running as root (UID 0).
SUID binary presentThe package contains a binary with the SUID bit set, which can enable privilege escalation.

Package is running feeds the Reachability dimension of the Runtime Prioritization Engine. To query these signals directly, see Filter findings by runtime signals.

Requirements:

  • Datadog Agent 7.79.0 or later. On Kubernetes, use 7.81.0 or later for the most complete signal coverage.
  • Linux only (eBPF dependency).
  • Applies to operating system packages in container image vulnerability findings.

Note: Use Datadog Agent 7.79.0 or later. Earlier Agent versions enable this feature through Workload Protection and can affect its usage. From 7.79.0, runtime package prioritization runs independently and does not affect its usage.

Add the enrichment block to the sbom section of your datadog-agent.yaml file:

spec:
  features:
    sbom:
      enabled: true
      containerImage:
        enabled: true
      # Enables runtime package prioritization (Preview, Agent 7.79+)
      enrichment:
        usage:
          enabled: true

Apply the changes and restart the Agent.

Add the enrichment block to the sbom section of your datadog-values.yaml file:

datadog:
  sbom:
    containerImage:
      enabled: true
    # Enables runtime package prioritization (Preview, Agent 7.79+)
    enrichment:
      usage:
        enabled: true

Restart the Agent.

Set hostPID: true in the pod spec, and add the following environment variables to every Agent container in your daemonset.yaml file, including agent, security-agent, and system-probe:

# Pod spec
hostPID: true

# Add to each Agent container's env section.
- name: DD_SBOM_ENABLED
  value: "true"
- name: DD_SBOM_CONTAINER_IMAGE_ENABLED
  value: "true"
- name: DD_SBOM_ENRICHMENT_USAGE_ENABLED
  value: "true"

Restart the Agent.