> ## Documentation Index
> Fetch the complete documentation index at: https://conductorone-luisinasantos-sync-coupa-v0-1-13-docs.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Set up a Datadog connector

> C1 provides identity governance for Datadog. Integrate your Datadog instance with C1 to run user access reviews (UARs) and enable just-in-time access requests.

<Tip>
  **This is an updated and improved version of the Datadog connector!** If you're setting up Datadog with C1 for the first time, you're in the right place.
</Tip>

## Capabilities

| Resource | Sync | Provision | Issue | Revoke |
| :- | :- | :- | :- | :- |
| Accounts | <Icon icon="square-check" iconType="solid" color="#c937ae" /> | <Icon icon="square-check" iconType="solid" color="#c937ae" /> | | |
| Roles | <Icon icon="square-check" iconType="solid" color="#c937ae" /> | <Icon icon="square-check" iconType="solid" color="#c937ae" /> | | |
| Teams | <Icon icon="square-check" iconType="solid" color="#c937ae" /> | <Icon icon="square-check" iconType="solid" color="#c937ae" /> | | |
| Schedules | <Icon icon="square-check" iconType="solid" color="#c937ae" />\* | | | |
| Secrets - Organization API keys | <Icon icon="square-check" iconType="solid" color="#c937ae" /> | | <Icon icon="square-check" iconType="solid" color="#c937ae" />‡ | <Icon icon="square-check" iconType="solid" color="#c937ae" />‡ |
| Secrets - Service account application keys | <Icon icon="square-check" iconType="solid" color="#c937ae" />\* | | <Icon icon="square-check" iconType="solid" color="#c937ae" />\* | <Icon icon="square-check" iconType="solid" color="#c937ae" />\*† |

[This connector can sync secrets](/product/admin/inventory) and display them on the **Inventory** page. Organization API keys and service account application keys are synced, issued, and shown as distinct secret kinds: they are two different kinds of API key, not two spellings of one, and a request names which kind it wants. Service account application keys are the default kind.

An application key can be issued and revoked through C1 when **Sync secrets** and **Sync service account application keys** are both enabled, provided the selected Datadog user is a service account. Datadog does not support an expiration date when creating an application key.

<Warning>
  Credential issuance targets a Datadog service account only. C1 re-checks at issuance time that the selected user is still a service account, and refuses to issue against a human user. The issued application key is owned by, and scoped to, that service account.

  Revoking a service account application key needs the owning service account as well as the key. C1 does not supply it today, so the connector reads it from the key's own owner record instead. A revoke is refused only when that lookup cannot name an owner either.
</Warning>

‡Organization API key issuance and revocation both require **Allow organization API key deletion**, which is off by default and is separate from **Sync secrets**. An organization API key belongs to the whole organization rather than to the person it was issued to, and it cannot be scoped, so C1 will not mint one it has no permission to revoke. With the setting off, organization API keys still sync; they simply cannot be issued or deleted.

\*Schedules and service account application keys are not enabled by default. Enable **Sync schedules** for schedules; enable **Sync secrets** *and* **Sync service account application keys** for application keys — **Sync secrets** alone syncs organization API keys only.

†Revoking a service account application key needs the owning service account as well as the key, because Datadog has no delete-by-key-id-alone form for these keys. When the request omits it, the connector looks the owner up from the key and proceeds; a key whose owner cannot be identified is refused rather than guessed at — see the note above.

### Connector actions

Connector actions are custom capabilities that extend C1 automations with app-specific operations. You can use connector actions in the [Perform connector action](/product/admin/automations-steps-reference#perform-connector-action) automation step.

| Action name | Additional fields | Description |
| - | - | - |
| enable\_user | `user_id` (string, required) | Re-enables a previously disabled Datadog user. |
| disable\_user | `user_id` (string, required) | Disables a Datadog user. Datadog has no permanent delete, so the account is retained and can be re-enabled later. |
| update\_user | `user_id` (string, required), `name` (string, optional), `email` (string, optional), `title` (string, optional) | Updates the user's display name, email and/or job title. At least one optional field must be provided. |

## Gather Datadog credentials

Configuring the connector requires you to pass in credentials generated in Datadog. Gather these credentials before you move on.

<Warning>
  A user with the **Connector Administrator** or **Super Administrator** role in C1 and the **Datadog Admin** or **Datadog standard** role in Datadog must perform this task.

  If your user has a custom Datadog role, make sure it includes **User App Keys**, **User Access Invite**, and **User Access Manage** to create, update, enable, and disable users from C1. If you enable **Sync secrets**, add **API Keys Read** to sync organization API keys. Add **Service Account Write**, which governs syncing, issuing, and revoking service account application keys, only if you also enable **Sync service account application keys**; add **Org App Keys Read** alongside it, which the revoke path uses to find the service account that owns a key when the request does not name it. Add **API Keys Write** and **API Keys Delete** only if you also enable **Allow organization API key deletion**; without that setting the connector never creates or deletes an organization API key, so those two permissions are not needed. **Service Account Write** is required, not optional, once that setting is on: a role that lacks it fails the sync rather than syncing an application-key inventory that is silently missing keys. That is why the setting is off by default — an existing install keeps syncing until the operator grants the permission.
</Warning>

### Locate your Datadog site

<Steps>
  <Step>
    Navigate to the Datadog login screen and make a note of your Datadog site. Valid Datadog sites are `datadoghq.com`, `us3.datadoghq.com`, `us5.datadoghq.com`, `datadoghq.eu`, `ddog-gov.com`, and `ap1.datadoghq.com`.
  </Step>
</Steps>

### Create an API key

<Steps>
  <Step>
    Log into your Datadog account and navigate to **User Account** > **Organizational Settings**.
  </Step>

  <Step>
    Click **API Keys** and then click **+ New Key**.
  </Step>

  <Step>
    Enter a name for your new key, such as "C1", and click **Create Key**.
  </Step>

  <Step>
    Copy and save the newly created API key.
  </Step>
</Steps>

### Create an application key

<Steps>
  <Step>
    Navigate back to **Organization Settings**.
  </Step>

  <Step>
    Click **Application Keys** and then click **+ New Key**.
  </Step>

  <Step>
    Enter a name for your new key, such as "C1", and click **Create Key**.
  </Step>

  <Step>
    Copy and save the newly created application key.
  </Step>
</Steps>

**Done.** Next, move on to the connector configuration instructions.

## Configure the Datadog connector

<Warning>
  To complete this task, you'll need:

  * The **Connector Administrator** or **Super Administrator** role in C1
  * Access to the set of Datadog credentials generated by following the instructions above
</Warning>

<Tabs>
  <Tab title="Cloud-hosted">
    **Follow these instructions to use a built-in, no-code connector hosted by C1.**

    <Steps>
      <Step>
        In C1, navigate to **Apps** > **Connectors** and click **Add connector**.
      </Step>

      <Step>
        Search for **Datadog v2** and click **Add**.
      </Step>

      <Step>
        Choose where to add the connector: **Create a new app**, or **Add to an existing app** (then select the app).

        If you're creating a new app, choose whether to link it to an application discovered from your identity provider: select **Yes** and pick the IdP application, or **No** to continue with just the connector.
      </Step>

      <Step>
        Set the connector's **Name** and, optionally, a **Description**.
      </Step>

      <Step>
        Click the pencil icon next to **Owners** to choose who can configure and manage this connector.
      </Step>

      <Step>
        Click **Add**. The connector is created and its configuration page opens.
      </Step>

      <Step>
        Find the **Settings** area of the page and click **Edit**.
      </Step>

      <Step>
        Select your Datadog site from the list.
      </Step>

      <Step>
        Paste the API key into the **API key** field.
      </Step>

      <Step>
        Paste the application key into the **Application key** field.
      </Step>

      <Step>
        **Optional.** Enable **Sync secrets** to display them on the [Inventory page](/product/admin/inventory).
      </Step>

      <Step>
        **Optional.** Enable **Sync service account application keys** to sync, issue, and revoke them. It requires the **Service Account Write** permission, and a role without it fails the whole sync, so it is off by default and **Sync secrets** alone does not turn it on.

        **Optional.** Enable **Allow organization API key deletion** to let C1 issue and revoke Datadog organization API keys. Leave it off unless you want C1 to be able to delete organization-wide keys; enabling **Sync secrets** alone does not grant this.
      </Step>

      <Step>
        **Optional.** Enable **Sync schedules**.
      </Step>

      <Step>
        Click **Save**.
      </Step>

      <Step>
        The connector's label changes to **Syncing**, followed by **Connected**. You can view the logs to ensure that information is syncing.
      </Step>
    </Steps>

    **Done.** Your Datadog connector is now pulling access data into C1.
  </Tab>

  <Tab title="Self-hosted">
    **Follow these instructions to use the Datadog connector, hosted and run in your own environment.**

    When running in service mode on Kubernetes, a self-hosted connector maintains an ongoing connection with C1, automatically syncing and uploading data at regular intervals. This data is immediately available in the C1 UI for access reviews and access requests.

    ### Resources

    * [Official download center](https://dist.conductorone.com/ConductorOne/baton-datadog): For stable binaries (Windows/Linux/macOS) and container images.

    * [GitHub repository](https://github.com/conductorone/baton-datadog): Access the source code, report issues, or contribute to the project.

    ### Step 1: Set up a new Datadog connector

    <Steps>
      <Step>
        In C1, navigate to **Apps** > **Connectors** and click **Add connector**.
      </Step>

      <Step>
        Search for **Baton** and click **Add**.
      </Step>

      <Step>
        Choose where to add the connector: **Create a new app**, or **Add to an existing app** (then select the app).

        If you're creating a new app, choose whether to link it to an application discovered from your identity provider: select **Yes** and pick the IdP application, or **No** to continue with just the connector.
      </Step>

      <Step>
        Set the connector's **Name** and, optionally, a **Description**.
      </Step>

      <Step>
        Click the pencil icon next to **Owners** to choose who can configure and manage this connector.
      </Step>

      <Step>
        Click **Add**. The connector is created and its configuration page opens.
      </Step>

      <Step>
        In the **Settings** area of the page, click **Edit**.
      </Step>

      <Step>
        Click **Rotate** to generate a new Client ID and Secret.

        Carefully copy and save these credentials. We'll use them in Step 2.
      </Step>
    </Steps>

    ### Step 2: Create Kubernetes configuration files

    Create two Kubernetes manifest files for your Datadog connector deployment:

    #### Secrets configuration

    ```yaml expandable theme={null}
    # baton-datadog-secrets.yaml
    apiVersion: v1
    kind: Secret
    metadata:
      name: baton-datadog-secrets
    type: Opaque
    stringData:
      # C1 credentials
      BATON_CLIENT_ID: <C1 client ID>
      BATON_CLIENT_SECRET: <C1 client secret>
      
      # Datadog credentials
      BATON_API_KEY: <Datadog API key>
      BATON_APP_KEY: <Datadog app key>
      BATON_SITE: <Your Datadog site ID>

      # Optional: include if you want C1 to provision access using this connector
      BATON_PROVISIONING: true

      # Optional: include if you want to sync schedule data from Datadog
      BATON_SYNC_SCHEDULES: true

      # Optional: include if you want to sync secrets (API keys) from Datadog.
      # On its own this syncs organization API keys only.
      BATON_SYNC_SECRETS: true

      # Optional: include alongside BATON_SYNC_SECRETS to sync, issue and revoke
      # service account application keys. Needs service_account_write, without
      # which sync fails, plus org_app_keys_read for revoke owner lookup.
      BATON_SYNC_SERVICE_ACCOUNT_APPLICATION_KEYS: true

      # Optional: include ONLY if you want C1 to issue and delete organization-wide
      # Datadog API keys. Syncing secrets does not grant this on its own.
      BATON_ALLOW_ORG_API_KEY_DELETION: true
    ```

    See the connector's README or run `--help` to see all available configuration flags and environment variables.

    #### Deployment configuration

    ```yaml expandable theme={null}
    # baton-datadog.yaml
    apiVersion: apps/v1
    kind: Deployment
    metadata:
      name: baton-datadog
      labels:
        app: baton-datadog
    spec:
      selector:
        matchLabels:
          app: baton-datadog
      template:
        metadata:
          labels:
            app: baton-datadog
            baton: true
            baton-app: datadog
        spec:
          containers:
          - name: baton-datadog
            image: public.ecr.aws/conductorone/baton-datadog:latest
            imagePullPolicy: IfNotPresent
            env:
            - name: BATON_HOST_ID
              value: baton-datadog
            envFrom:
            - secretRef:
                name: baton-datadog-secrets
    ```

    ### Step 3: Deploy the connector

    <Steps>
      <Step>
        Create a namespace in which to run C1 connectors (if desired), then apply the secret config and deployment config files.
      </Step>

      <Step>
        Check that the connector data uploaded correctly. In C1, click **Apps**. On the **Managed apps** tab, locate and click the name of the application you added the Datadog connector to. Datadog data should be found on the **Entitlements** and **Accounts** tabs.
      </Step>
    </Steps>

    **Done.** Your Datadog connector is now pulling access data into C1.
  </Tab>
</Tabs>
