Skip to content

Add new TLS field for mTLS support for server based sources#36998

Open
tessneau wants to merge 1 commit into
masterfrom
tessneau/add-new-mtls-field-for-multiple-sources
Open

Add new TLS field for mTLS support for server based sources#36998
tessneau wants to merge 1 commit into
masterfrom
tessneau/add-new-mtls-field-for-multiple-sources

Conversation

@tessneau
Copy link
Copy Markdown
Member

@tessneau tessneau commented May 26, 2026

What does this PR do? What is the motivation?

We've addded support for mTLS by adding a new boolean tls field tls.verify_certifcate to most server based sources: fluent (fluentbit and fluentd), http_server, logstash, opentelemetry, socket, splunk_hec, splunk_tcp, syslog (rsyslog and syslog-ng).

This new field was already released in OPW v 2.16.0.

Client based sources do not need this for establishing mTLS and certain server based sources which do not yet support TLS in general are not included either.

Merge instructions

Merge readiness:

  • Ready for merge

For Datadog employees:

Your branch name MUST follow the <name>/<description> convention and include the forward slash (/). Without this format, your pull request will not pass CI, the GitLab pipeline will not run, and you won't get a branch preview. Getting a branch preview makes it easier for us to check any issues with your PR, such as broken links.

If your branch doesn't follow this format, rename it or create a new branch and PR.

[6/5/2025] Merge queue has been disabled on the documentation repo. If you have write access to the repo, the PR has been reviewed by a Documentation team member, and all of the required checks have passed, you can use the Squash and Merge button to merge the PR. If you don't have write access, or you need help, reach out in the #documentation channel in Slack.

AI assistance

Additional notes

@github-actions github-actions Bot added the Architecture Everything related to the Doc backend label May 26, 2026
@tessneau tessneau force-pushed the tessneau/add-new-mtls-field-for-multiple-sources branch from a9a11fc to 95e24a4 Compare May 26, 2026 16:42
@tessneau tessneau marked this pull request as ready for review May 26, 2026 17:06
@tessneau tessneau requested a review from a team as a code owner May 26, 2026 17:06
@maycmlee maycmlee added the editorial review Waiting on a more in-depth review label May 26, 2026
Copy link
Copy Markdown
Contributor

@maycmlee maycmlee left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just a couple of small suggestions!

@@ -0,0 +1 @@
Optionally, after you enable TLS, toggle **Verify certificate** to require connecting clients to present a valid client certificate. This enforces mutual TLS (mTLS), where the Worker verifies the identity of each connecting client.
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Optionally, after you enable TLS, toggle **Verify certificate** to require connecting clients to present a valid client certificate. This enforces mutual TLS (mTLS), where the Worker verifies the identity of each connecting client.
-(Optional) Toggle **Verify certificate** to require connecting clients to present a valid client certificate. This enforces mutual TLS (mTLS), where the Worker verifies the identity of each connecting client.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Architecture Everything related to the Doc backend editorial review Waiting on a more in-depth review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants