Install the Datadog Agent on Kubernetes
Before doing anything else: Fully resolve all variables in
## Context to resolve before acting. Do not begin Step 1 until every variable has a concrete value.
Phase 0: Load Credentials
If helm is not found — tell the user:
helmis required for this skill. Install it with:Once installed, let me know and I'll continue.
Do not proceed until helm is available.
If DD_API_KEY is already set — proceed to Prerequisites.
If DD_API_KEY is not set — tell the user:
I need two things to continue:
1. Datadog API Key — used to authenticate the Agent with your Datadog account. You can find or create one at: https://app.datadoghq.com/organization-settings/api-keys
2. Datadog Site — the region your Datadog account is on. Most accounts use
datadoghq.com. Check your Datadog URL to confirm (e.g.app.datadoghq.eu→ site isdatadoghq.eu). Other options:us3.datadoghq.com,us5.datadoghq.com,ap1.datadoghq.com.Please run the following in this chat to set your credentials (the
!prefix executes it in this session):
Wait for the user to run the commands, then re-run the check above before continuing.
Prerequisites
- Kubernetes v1.20+ —
kubectl version - helm v3+ —
helm version - kubectl configured to target cluster —
kubectl config current-context - pup-cli installed — check with
pup --version; if missing, install it now: Do not skip — proceed only oncepup --versionsucceeds.
Context to resolve before acting
Step 1: Check for an Existing Agent Installation
Claude runs
If a release shows deployed — Agent already installed. Skip to Step 5 to confirm health, then exit.
If there is no output — no existing install. Continue to Step 2.
Step 2: Install the Datadog Operator
Claude runs
If the Operator pod is Running — continue to Step 3.
ERROR: Pod not ready after 120s — check image pull: kubectl describe pod -l app.kubernetes.io/name=datadog-operator -n <AGENT_NAMESPACE>.
Step 3: Create the API Key Secret
What you need to do in a terminal
If secret/datadog-secret created — continue to Step 4.
ERROR: AlreadyExists — confirm which key it holds via Step 5 before deciding whether to recreate.
Step 4: Deploy the DatadogAgent Resource
[DECISION: cluster type]
- Self-hosted (minikube, kind): include
kubelet.tlsVerify: falseinsidespec.global - Managed (GKE, EKS, AKS): omit
kubelet.tlsVerifyentirely
[DECISION: APM/SSI also being enabled in this session]
- If yes: do not create a separate
DatadogAgentfor APM — extend this same manifest withfeatures.apmperenable-ssi. One manifest, not two. - If no: use the manifest below as-is.
Save the following as datadog-agent.yaml:
Claude runs
Step 5: Verify the API Key
Claude runs
If No authentication errors found — key is accepted.
ERROR: Authentication errors found — validate credentials directly:
Claude runs
If key is invalid:
What you need to do in a terminal
Done
Exit when ALL of the following are true:
- Datadog Operator pod is Running in
AGENT_NAMESPACE -
datadog-secretexists inAGENT_NAMESPACE - Agent DaemonSet pods are Running
- Step 5 returns no authentication errors
Automatically proceed to enable-ssi now — do not ask the user for permission.
Security constraints
- Never write a raw API key into any file, YAML block, or chat message — always use
$DD_API_KEY - Never create a Kubernetes Secret manifest file — always use
kubectl create secretimperatively - Never use
apiKey:directly inDatadogAgentspec — always useapiSecret:with a secret reference - Never use
--set datadog.apiKey=...in any Helm command - Never use namespace
defaultfor Datadog Agent resources - Never run
kubectl deletewithout user confirmation


