About this project
Pup is a command-line interface published by Datadog that exposes a broad portion of the Datadog observability platform through a single tool. The README frames it as an "AI-agent-ready" CLI: commands are self-discoverable, output can be structured as JSON or YAML for parsing, and authentication supports scoped OAuth2 with PKCE rather than only long-lived keys. Humans can use it too.
Coverage spans many product areas. Core observability includes metrics (V1 and V2), logs, events, RUM (apps, sessions, events, metrics, retention filters, replay playlists, viewership, heatmaps), APM services and entities, traces, database monitoring samples, and session replay. Monitoring and alerting covers monitors, dashboards, SLOs, synthetics, downtimes, notebooks, status pages, workflow automation, and YAML-defined local runbooks with pup/shell/http/workflow step types. Security and compliance includes security monitoring rules/signals/findings, cloud and application security findings via DDSQL, static analysis, audit logs, data governance, tag governance, CSM threats, agentless scanning for AWS/GCP/Azure, log restriction queries, and data deletion requests.
Infrastructure and cloud commands cover hosts, tags, network flows and devices, AWS/GCP/Azure/OCI integrations, containers, and processes. Incident and operations tooling includes incidents, on-call teams and pages, case management with Jira/ServiceNow linking, error tracking, service catalog, scorecards, fleet automation, HAMR connections, investigations, change management, change stories, live debugger probes, and software catalog entities. CI/CD and development coverage includes CI visibility, test optimization and flaky tests, DORA metrics, code coverage summaries, and deployment gates. Organization and access commands handle users, organizations, API keys, app keys, and AuthN mappings. Platform and configuration areas include usage metering, cost management and Cloud Cost Management, product analytics, third-party integrations, feature flags, Kafka data streams (experimental), restricted datasets, observability pipelines, LLM observability, reference tables, miscellaneous endpoints, and App Builder.
Installation options are Homebrew via the datadog-labs/pack tap, building from source with Cargo, or downloading pre-built binaries from releases. Authentication supports three methods in priority order: a stateless bearer token via DD_ACCESS_TOKEN, OAuth2 tokens obtained through `pup auth login`, and API keys via DD_API_KEY and DD_APP_KEY. OAuth2 uses browser-based login with automatic token refresh and requires Dynamic Client Registration on the Datadog site. Multiple sites and orgs can be stored as separate named sessions and selected with --org or DD_ORG; site resolution follows DD_SITE, then the recorded session site, then datadoghq.com. Tokens are stored in the platform secure store (macOS Keychain, Linux Secret Service, Windows Credential Manager) with a file-based fallback under ~/.config/pup/ using 0600 permissions, overridable via DD_TOKEN_STORAGE or config.
Example usage shown in the README includes `pup monitors list --tags="team:api-platform"`, `pup logs search --query="status:error" --from="1h"`, and `pup metrics query --query="avg:system.cpu.user{*}"`. A canonical command reference lives in docs/COMMANDS.md, and `pup --help` or `pup agent schema` provides the live command list. Some areas are noted as not yet implemented, such as profiling, powerpacks, roles listing, and IP allowlist. The project is Apache 2.0 licensed and written in Rust.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.