You can use the CLI to instrument your Azure Container Apps with Datadog. The CLI enables instrumentation by modifying existing Container App configurations to include the Datadog sidecar, which enables tracing, log collection, and custom metrics.
See the docs for language-specific application steps needed in addition to these commands.
Run datadog-ci container-app instrument to apply Datadog instrumentation to an Azure Container App. This command configures your Container App with the necessary environment variables and settings for Datadog monitoring.
# Instrument a Container App using subscription ID, resource group, and name
datadog-ci container-app instrument \
--subscription-id <subscription-id> \
--resource-group <resource-group-name> \
--name <container-app-name>
# Instrument a Container App using a full resource ID
datadog-ci container-app instrument \
--resource-id "/subscriptions/{subscriptionId}/resourceGroups/{resourceGroup}/providers/Microsoft.App/containerApps/{containerAppName}"
# Instrument multiple Container Apps using resource IDs
datadog-ci container-app instrument \
--resource-id <resource-id-1> \
--resource-id <resource-id-2>
# Instrument with configuration
datadog-ci container-app instrument \
--subscription-id <subscription-id> \
--resource-group <resource-group-name> \
--name <container-app-name> \
--service my-service \
--env prod \
--version 1.0.0
# Detect the application language and add its tracer automatically
datadog-ci container-app instrument \
--subscription-id <subscription-id> \
--resource-group <resource-group-name> \
--name <container-app-name> \
--tracing inject
# Add only the Python tracer
datadog-ci container-app instrument \
--subscription-id <subscription-id> \
--resource-group <resource-group-name> \
--name <container-app-name> \
--tracing inject \
--language python
# Dry run to preview changes
datadog-ci container-app instrument \
--subscription-id <subscription-id> \
--resource-group <resource-group-name> \
--name <container-app-name> \
--dry-runUse --tracing inject to detect the application language and add its tracer without rebuilding the application image. Add --language <language> to copy only one tracer. Supported language values are java, nodejs, csharp, python, ruby, and php. dotnet is accepted as an alias for csharp. The command copies the tracer through an init container and keeps the Datadog sidecar for trace transport.
--tracer-version and --tracer-libc require --tracing inject --language. Single-language injection uses the latest tracer version and glibc by default. Ruby injection does not support musl, and .NET tracer versions before 3.0 are not supported. Runtime support follows the APM compatibility requirements; latest can drop runtimes after they reach end of life.
Go tracers cannot be injected. Install dd-trace-go in the application image, and use --tracing manual.
Automatic instrumentation can increase cold-start delays when the app scales to zero. Automatic language detection copies a larger composite tracer image than selecting one language. For scale-to-zero workloads, install the tracer in the application image, and use --tracing manual.
For a Container App with multiple application containers, use --container-name to select one container. This differs from --name, which selects the Container App resource.
A tracer your own image installs is left alone. The command removes the startup settings it wrote, which it recognizes from the /datadog-lib and /opt/datadog-packages paths it copies tracers into. Settings a manual install shares with it, such as CORECLR_ENABLE_PROFILING, are only removed alongside one of those paths.
The following names and paths belong to this command. Every run removes them before applying what you asked for, so a tracer left by an earlier release or another tool is replaced rather than left alongside the new one. Use different names and paths for anything of your own, and the command reports when it replaces something it did not write.
| Resource | Name or path |
|---|---|
| Init container | datadog-tracer |
| Volume | datadog-tracer |
| Mount paths | /datadog-lib, /opt/datadog-packages |
Tracing defaults to manual, which uses a tracer already installed in the application image. Use --tracing disabled to turn tracing off.
You can use any nonempty --language value without --tracing inject to set DD_SOURCE for log parsing. With --tracing inject, use Java, Node.js, .NET, Python, Ruby, or PHP.
Run datadog-ci container-app uninstrument to remove Datadog instrumentation from an Azure Container App. This command reverts the Container App configuration to its pre-instrumented state by removing the Datadog sidecar and associated environment variables.
# Uninstrument a Container App using subscription ID, resource group, and name
datadog-ci container-app uninstrument \
--subscription-id <subscription-id> \
--resource-group <resource-group-name> \
--name <container-app-name>
# Uninstrument a Container App using a full resource ID
datadog-ci container-app uninstrument \
--resource-id "/subscriptions/{subscriptionId}/resourceGroups/{resourceGroup}/providers/Microsoft.App/containerApps/{containerAppName}"
# Uninstrument multiple Container Apps using resource IDs
datadog-ci container-app uninstrument \
--resource-id <resource-id-1> \
--resource-id <resource-id-2>
# Dry run to preview changes
datadog-ci container-app uninstrument \
--subscription-id <subscription-id> \
--resource-group <resource-group-name> \
--name <container-app-name> \
--dry-runYou must have valid Azure credentials configured with access to the Container Apps where you are running any datadog-ci container-app commands. The CLI uses the Azure SDK's default credential chain, which includes:
- Environment variables
- Managed Identity (when running in Azure)
- Azure CLI credentials (
az login) - Visual Studio Code credentials
- Azure PowerShell credentials
For local development, ensure you're authenticated through the Azure CLI:
az loginYou must expose these environment variables in the environment where you are running datadog-ci container-app instrument:
| Environment Variable | Description | Example |
|---|---|---|
DD_API_KEY |
Required. Datadog API Key. Sets the DD_API_KEY environment variable on your Container App. For more information about getting a Datadog API key, see the API key documentation. |
export DD_API_KEY=<API_KEY> |
DD_SITE |
Set which Datadog site to send data to. Possible values are datadoghq.com, datadoghq.eu, us3.datadoghq.com, us5.datadoghq.com, ap1.datadoghq.com, ap2.datadoghq.com, uk1.datadoghq.com, ddog-gov.com, and us2.ddog-gov.com. The default is datadoghq.com. |
export DD_SITE=datadoghq.com |
Configuration can be done using command-line arguments or a JSON configuration file (see the next section).
You can pass the following arguments to instrument to specify its behavior. Values in the configuration file override command-line arguments.
| Argument | Shorthand | Description | Default |
|---|---|---|---|
--subscription-id |
-s |
Subscription ID of the Azure subscription containing the Container App. Must be used with --resource-group and --name. |
|
--resource-group |
-g |
Name of the Azure Resource Group containing the Container App. Must be used with --subscription-id and --name. |
|
--name |
-n |
Name of the Azure Container App to instrument. Must be used with --subscription-id and --resource-group. |
|
--resource-id |
-r |
Full Azure resource ID to instrument. Can be specified multiple times. Format: /subscriptions/<subscription-id>/resourceGroups/<resource-group-name>/providers/Microsoft.App/containerApps/<container-app-name>. |
|
--env-vars |
-e |
Additional environment variables to set for the Container App. Can specify multiple variables in the format --env-vars VAR1=VALUE1 --env-vars VAR2=VALUE2. |
|
--config |
Path to the configuration file. | ||
--dry-run |
-d |
Run the command in dry-run mode, without making any changes. Preview the changes that running the command would apply. | false |
--service |
The value for the service tag. Use this to group related Container Apps belonging to similar workloads. For example, my-service. If not provided, the Container App name is used. |
||
--env or --environment |
The value for the env tag. Use this to separate your staging, development, and production environments. For example, prod. |
||
--version |
The value for the version tag. Use this to correlate spikes in latency, load, or errors to new versions. For example, 1.0.0. |
||
--sidecar-name |
(Not recommended) The name to use for the sidecar container. | datadog-sidecar |
|
--shared-volume-name |
(Not recommended) Specify a custom shared volume name. | shared-volume |
|
--shared-volume-path |
(Not recommended) Specify a custom shared volume path. | /shared-volume |
|
--logs-path |
(Not recommended) Specify a custom log file path. Must begin with the shared volume path. | /shared-volume/logs/*.log |
|
--sidecar-cpu |
The number of CPUs to allocate to the sidecar container. | 0.5 |
|
--sidecar-memory |
The amount of memory (in GiB) to allocate to the sidecar container. | 1 |
|
--sidecar-image |
Override to pin a specific version tag or to use a mirrored image from a custom registry (e.g., ACR) to avoid pull rate limits. | index.docker.io/datadog/serverless-init:latest |
|
--tracing |
Configure APM instrumentation. Use manual when the tracer is installed, inject to detect the language and add a tracer automatically, or disabled to turn tracing off. Add --language with inject to select one tracer. Defaults to manual. |
||
--language |
Set the application language for log parsing. With --tracing inject, this selects one tracer instead of detecting the language automatically. Supported injection values: java, nodejs, csharp, python, ruby, php. |
||
--tracer-version |
Set the tracer image tag. Requires --tracing inject --language. |
latest |
|
--tracer-libc |
Set the C standard library used by the application image. Requires --tracing inject --language. Possible values: "glibc", "musl". |
glibc |
|
--container-name |
Select the application container to instrument when the Container App has several. Requires --tracing inject. |
||
--source-code-integration or --sourceCodeIntegration |
Whether to enable the Datadog Source Code integration. This tags your service(s) with the Git repository and the latest commit hash of the local directory. Specify --no-source-code-integration to disable. |
true |
|
--upload-git-metadata or --uploadGitMetadata |
Whether to enable Git metadata uploading, as a part of the source code integration. Git metadata uploading is only required if you don't have the Datadog GitHub integration installed. Specify --no-upload-git-metadata to disable. |
true |
|
--extra-tags or --extraTags |
Additional tags to add to the app in the format "key1:value1,key2:value2". |
You can pass the following arguments to uninstrument to specify its behavior. These arguments override the values set in the configuration file, if any.
| Argument | Shorthand | Description | Default |
|---|---|---|---|
--subscription-id |
-s |
Subscription ID of the Azure subscription containing the Container App. Must be used with --resource-group and --name. |
|
--resource-group |
-g |
Name of the Azure Resource Group containing the Container App. Must be used with --subscription-id and --name. |
|
--name |
-n |
Name of the Azure Container App to instrument. Must be used with --subscription-id and --resource-group. |
|
--resource-id |
-r |
Full Azure resource ID to instrument. Can be specified multiple times. Format: /subscriptions/<subscription-id>/resourceGroups/<resource-group-name>/providers/Microsoft.App/containerApps/<container-app-name>. |
|
--env-vars |
-e |
Additional environment variables to set for the Container App. Can specify multiple variables in the format --env-vars VAR1=VALUE1 --env-vars VAR2=VALUE2. |
|
--config |
Path to the configuration file. | ||
--dry-run |
-d |
Run the command in dry-run mode, without making any changes. Preview the changes that running the command would apply. | false |
--sidecar-name |
The name of the sidecar container to remove. Specify if you have a different sidecar name. | datadog-sidecar |
|
--shared-volume-name |
The name of the shared volume to remove. Specify if you have a different shared volume name. | shared-volume |
Instead of supplying arguments, you can create a configuration file in your project and run the datadog-ci container-app instrument --config datadog-ci.json command. Specify the datadog-ci.json file using the --config argument, and use this configuration file structure:
{
"containerApp": {
"subscriptionId": "your-subscription-id",
"resourceGroup": "your-resource-group",
"containerAppName": "your-container-app-name",
"service": "my-service",
"environment": "prod",
"version": "1.0.0",
"logPath": "/custom-path/*.log",
"tracing": "inject",
"language": "python",
"sourceCodeIntegration": true,
"uploadGitMetadata": true,
"extraTags": "team:backend,project:api",
"envVars": ["CUSTOM_VAR1=value1", "CUSTOM_VAR2=value2"]
}
}Alternatively, you can use resource IDs:
{
"containerApp": {
"resourceIds": [
"/subscriptions/<subscription-id>/resourceGroups/<resource-group-name>/providers/Microsoft.App/containerApps/<container-app-name1>",
"/subscriptions/<subscription-id>/resourceGroups/<resource-group-name>/providers/Microsoft.App/containerApps/<container-app-name2>"
],
"service": "my-service",
"environment": "prod",
"tracing": "manual"
}
}export DD_API_KEY=<your-api-key>
export DD_SITE=datadoghq.com
datadog-ci container-app instrument \
--subscription-id 12345678-1234-1234-1234-123456789012 \
--resource-group my-resource-group \
--name my-container-appexport DD_API_KEY=<your-api-key>
datadog-ci container-app instrument \
--subscription-id 12345678-1234-1234-1234-123456789012 \
--resource-group my-resource-group \
--name my-container-app \
--service my-web-api \
--env production \
--version v2.5.0 \
--extra-tags team:platform,cost-center:engineeringexport DD_API_KEY=<your-api-key>
datadog-ci container-app instrument \
--subscription-id 12345678-1234-1234-1234-123456789012 \
--resource-group my-resource-group \
--name my-container-app \
--log-path /home/LogFiles/myapp/*.log \export DD_API_KEY=<your-api-key>
datadog-ci container-app instrument \
--subscription-id 12345678-1234-1234-1234-123456789012 \
--resource-group my-resource-group \
--name my-container-app \
--dry-runFor product feedback and questions, join the #serverless channel in the Datadog community on Slack.