Skills
Skill 15 of 48
Verify Single Step Instrumentation (SSI) is working end-to-end on Kubernetes — SSI automatically instruments applications for APM without code changes.
2 minutes · 432 words · 17 sections
Install
npx skills add datadog-labs/agent-skills --skill verify-ssinpx skills add datadog-labs/agent-skillsThe first command installs just this skill, by the name in its SKILL.md; the second installs the whole repository.
Before doing anything else: Fully resolve all variables in
## Context to resolve before acting. Do not begin Step 1 until every variable has a concrete value.
Invoke this skill when the user expresses intent to:
Do NOT invoke this skill if:
enable-ssi firsttroubleshoot-ssienable-ssi is completepup --versionIf not found:
brew tap datadog-labs/pack
brew install pupCheck auth:
pup auth status --site <DD_SITE>If not authenticated:
pup auth login --site <DD_SITE>This opens a browser tab for OAuth. Complete the login there — Claude will continue once the command exits.
If valid token — proceed.
ERROR: No browser available — use API key fallback: export DD_APP_KEY=<your-app-key>
| Variable | How to resolve |
|---|---|
CLUSTER_NAME | Check spec.global.clusterName in datadog-agent.yaml, or kubectl config current-context |
ENV | Check tags.datadoghq.com/env label on the application Deployment |
SERVICE_NAME | Check tags.datadoghq.com/service label on the application Deployment |
kubectl get pod -l app=<APP_LABEL> -n <APP_NAMESPACE> \
-o jsonpath='{.items[0].spec.initContainers[*].name}'If the output includes datadog-lib-<language>-init and datadog-init-apm-inject — SSI init containers are injected.
ERROR: Init containers missing — pod was not restarted after SSI was enabled, or namespace targeting is not matching. Restart the pod and recheck.
DD_SITE=<DD_SITE> pup apm services list --env <ENV> --from 1hIf <SERVICE_NAME> appears in the services list with isTraced: true — continue to Step 3.
ERROR: Service missing — send some traffic to the app first, then retry:
# Port-forward and send test traffic
kubectl port-forward deployment/<DEPLOYMENT_NAME> 8099:8000 -n <APP_NAMESPACE> &
sleep 2 && for i in $(seq 1 10); do curl -s -o /dev/null http://localhost:8099/; done
sleep 30 && kill %1 2>/dev/null
DD_SITE=<DD_SITE> pup apm services list --env <ENV> --from 10mERROR: Still missing after traffic — check the agent’s trace receiver: kubectl exec -n <AGENT_NAMESPACE> <AGENT_POD> -c agent -- agent status | grep -A 10 "Receiver (previous minute)". If receiver shows 0 traces, go to troubleshoot-ssi.
Only run this step if ddTraceConfigs was explicitly configured in enable-ssi (e.g. profiling, AppSec, Data Streams). If basic SSI was set up without ddTraceConfigs, skip this step — an empty response here is expected and not a failure.
pup apm service-library-config get \
--service-name <SERVICE_NAME> \
--env <ENV>If the output shows expected environment variables matching what was configured in ddTraceConfigs — done.
If the output is empty and ddTraceConfigs was not configured — expected, not a failure.
ERROR: Config missing but ddTraceConfigs was configured — check it is present in the DatadogAgent manifest under the correct target, and that pods were restarted after the config change.
Exit when ALL of the following are true:
datadog-lib-<language>-init and datadog-init-apm-inject)pup apm services list with isTraced: trueDatadogAgentIf any check fails, go to troubleshoot-ssi.
When all steps pass, automatically proceed to onboarding-summary now — do not ask the user for permission.
kubectl delete without user confirmationVerify Single Step Instrumentation (SSI) is working end-to-end on Kubernetes — SSI automatically instruments applications for APM without code changes. Only use after enable-ssi has run.
The verbatim description from this skill’s front matter — the string an agent matches on to decide whether to load it.
main, last pushed 17 September 2026.SKILL.md, not by matching a directory convention. 11 distinct layouts observed: agent-observability/*/SKILL.md, */SKILL.md, dd-apm/k8s-ssi/*/SKILL.md, dd-apm/linux-ssi/*/SKILL.md, dd-apm/*/SKILL.md, dd-apps/*/SKILL.md, dd-audit/*/SKILL.md, dd-browser-sdk/*/SKILL.md, dd-security/csm/*/SKILL.md, dd-software-delivery/*/SKILL.md, SKILL.md (repo root).h1 and no skipped levels:/datadog-labs/agent-skills.md, and each skill at its own .md URL.