datadog-labs/agent-skills/dd-apm/linux-ssi/agent-install/SKILL.md
agent-install
Install the Datadog Agent on Linux hosts via SSH with Single Step Instrumentation (SSI) enabled — SSI automatically instruments applications for APM without code changes. Only use if no agent is installed yet.
- Source repository stars
- 158
- Declared platforms
- 0
- Static risk flags
- 2
- Last source update
- 2026-08-21
- Source checked
- 2026-08-25
Decision brief
What it does: where it fits
Before doing anything else: Fully resolve all variables in Context to resolve before acting. Do not begin Step 1 until every variable has a concrete value.
Not for
- Tasks that require unconfirmed production actions or broad system permissions.
- Environments where the pinned source and install steps cannot be inspected.
Compatibility matrix
Platform support, with evidence labels
| Platform | Status | Evidence | What to check |
|---|---|---|---|
| Codex | Not declared | No explicit evidence | Portability before use |
| Claude Code | Not declared | No explicit evidence | Portability before use |
| Cursor | Not declared | No explicit evidence | Portability before use |
| Gemini CLI | Not declared | No explicit evidence | Portability before use |
Installation
Inspect first. Install second.
The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.
npx skills add https://github.com/datadog-labs/agent-skills --skill "dd-apm/linux-ssi/agent-install"Inspect the Agent Skill "agent-install" from https://github.com/datadog-labs/agent-skills/blob/47d0cf5096fed4e7191e1f8eb2b2dc69cc135f10/dd-apm/linux-ssi/agent-install/SKILL.md at commit 47d0cf5096fed4e7191e1f8eb2b2dc69cc135f10. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.
Workflow
What the source asks the agent to do
- 01
Phase 0: Load Credentials
If DDAPIKEY is already set — proceed directly to gathering infrastructure info.
If DDAPIKEY is already set — proceed directly to gathering infrastructure info.If DDAPIKEY is not set — tell the user:Please run the following in this chat to set your credentials (the ! prefix executes it in this session): - 02
Phase 1: Gather Infrastructure Info
Only do this phase if the user hasn't already provided the information. If SSH credentials are known, skip to Phase 2.
Which hosts need the agent? Get a list of IPs or hostnames.How do I SSH to them? Get the SSH user, key path, and any jump host or bastion configuration.Do any hosts already have the Datadog Agent installed? If so, skip install for those hosts and go straight to verify-ssi. - 03
Phase 2: Install the Datadog Agent with SSI
Run for each host that does not already have the agent installed.
Run for each host that does not already have the agent installed.DDAPMINSTRUMENTATIONENABLED=host causes the install script to also install datadog-apm-inject and language library packages under /opt/datadog-packages/ in one pass.If the script completes without errors — proceed to Phase 2. - 04
Phase 3: Verify the Agent is Running and Healthy
Healthy output shows: - Agent (v7.XX.X) with Status: Running - API Keys status: API Key ending with XXXX: Valid
Agent (v7.XX.X) with Status: RunningAPI Keys status: API Key ending with XXXX: ValidHealthy output shows: - Agent (v7.XX.X) with Status: Running - API Keys status: API Key ending with XXXX: Valid - 05
Phase 4: Discover Services That Need Restarting
SSI only injects into processes at startup. Existing processes keep running uninstrumented until restarted. Discover what's running so the user knows what to restart.
SSI only injects into processes at startup. Existing processes keep running uninstrumented until restarted. Discover what's running so the user knows what to restart.For each application-level listener (ignore sshd, systemd, chronyd):bash ssh -o StrictHostKeyChecking=no -i @ "
Permission review
Static risk signals and limitations
Network access
The documentation includes network, browsing, or remote request actions.
"DD_API_KEY=${DD_API_KEY} DD_SITE=${DD_SITE} DD_APM_INSTRUMENTATION_ENABLED=host bash -c \"\$(curl -L https://install.datadoghq.com/scripts/install_script_agent7.sh)\""Network access
The documentation includes network, browsing, or remote request actions.
"apt-get install -y curl 2>/dev/null || yum install -y curl"Writes files
The documentation asks the agent to create, modify, or delete local files.
Never write a raw API key into any file or chat messageEvidence record
Why each signal appears
| Signal | Value | Evidence type | Meaning |
|---|---|---|---|
| Quality score | 92/100 | Computed | Documentation, specificity, maintenance, and trust rules |
| Repository stars | 158 | Source | Repository attention, not individual Skill quality |
| Compatibility | 0 platforms | Source | Declared in the catalog source record |
| Usage guide | automated source guide | Editorial | Generated or reviewed according to the visible evidence level |
Pinned source
Provenance and original SKILL.md
- Repository
- datadog-labs/agent-skills
- Skill path
- dd-apm/linux-ssi/agent-install/SKILL.md
- Commit
- 47d0cf5096fed4e7191e1f8eb2b2dc69cc135f10
- License
- MIT
- Collected
- 2026-08-25
- Default branch
- main
View the original SKILL.md
Install Datadog Agent on Linux
Before doing anything else: Fully resolve all variables in
## Context to resolve before acting. Do not begin Step 1 until every variable has a concrete value.
Triggers
Invoke this skill when the user expresses intent to:
- Install the Datadog Agent on Linux hosts or VMs
- Set up Datadog monitoring on bare-metal or cloud Linux instances
- Prepare Linux hosts for APM onboarding
Do NOT invoke this skill if:
- The Agent is already installed on all hosts — check with
datadog-agent statusfirst - The target is a Kubernetes cluster — use
dd-apm-k8s-agent-installinstead
Phase 0: Load Credentials
[ -f environment ] && source environment
echo "DD_API_KEY set: $([ -n "${DD_API_KEY:-}" ] && echo yes || echo no)"
echo "DD_SITE: ${DD_SITE:-not set}"
If DD_API_KEY is already set — proceed directly to gathering infrastructure info.
If DD_API_KEY is not set — tell the user:
Please run the following in this chat to set your credentials (the
!prefix executes it in this session):! export DD_API_KEY=your-api-key-here ! export DD_SITE=datadoghq.com
Wait for the user to run the commands, then re-run the check above before continuing.
Phase 1: Gather Infrastructure Info
Only do this phase if the user hasn't already provided the information. If SSH credentials are known, skip to Phase 2.
Ask the user:
- Which hosts need the agent? Get a list of IPs or hostnames.
- How do I SSH to them? Get the SSH user, key path, and any jump host or bastion configuration.
- Do any hosts already have the Datadog Agent installed? If so, skip install for those hosts and go straight to
verify-ssi.
Claude runs
Verify SSH works for each host before proceeding:
ssh -o StrictHostKeyChecking=no -i <SSH_KEY> <SSH_USER>@<SSH_HOST> "hostname"
If it returns a hostname — proceed. ERROR: Connection refused or timeout — resolve connectivity before continuing.
Once SSH is confirmed, present a plan to the user before proceeding. For example:
Here's what I'm going to do:
1. Install the Datadog Agent with SSI on: <host1>, <host2>, ...
2. Verify each agent is running and healthy
3. Discover services on each host that need restarting for SSI to take effect
4. After you restart services, verify instrumentation is working
Ready to proceed?
Wait for user confirmation before starting installs.
Prerequisites
Per host — check before installing:
Claude runs
ssh -o StrictHostKeyChecking=no -i <SSH_KEY> <SSH_USER>@<SSH_HOST> \
"uname -m && cat /etc/os-release | grep -E '^(ID|VERSION_ID|PRETTY_NAME)='"
If architecture is x86_64 or aarch64, and the OS is a supported distribution (Ubuntu 16.04+, Debian 9+, RHEL/CentOS 6-9, Amazon Linux 2/2023, SUSE 12+) — proceed.
ERROR: Architecture is armv7l (32-bit ARM) or unsupported OS — stop. Datadog Agent 7 and SSI do not support this configuration.
Context to resolve before acting
| Variable | How to resolve |
|---|---|
DD_API_KEY | Check echo $DD_API_KEY first — if set, use it. Otherwise ask the user for their API key from Datadog UI: Organization Settings → API Keys. Never log or print the key. |
DD_SITE | Check echo $DD_SITE first — if set, use it. Otherwise ask the user. Default: datadoghq.com. Options: datadoghq.com, us3.datadoghq.com, us5.datadoghq.com, datadoghq.eu, ap1.datadoghq.com |
SSH_KEY | Ask the user for the path to their SSH private key, or check CLAUDE.md |
SSH_USER | Ask the user for the SSH username. Default: root |
SSH_HOST | Ask the user for the hostname or IP of the target host |
SSH_PORT | Ask the user for the SSH port. Default: 22 |
Phase 2: Install the Datadog Agent with SSI
Run for each host that does not already have the agent installed.
Claude runs
ssh -o StrictHostKeyChecking=no -i <SSH_KEY> <SSH_USER>@<SSH_HOST> \
"DD_API_KEY=${DD_API_KEY} DD_SITE=${DD_SITE} DD_APM_INSTRUMENTATION_ENABLED=host bash -c \"\$(curl -L https://install.datadoghq.com/scripts/install_script_agent7.sh)\""
DD_APM_INSTRUMENTATION_ENABLED=host causes the install script to also install datadog-apm-inject and language library packages under /opt/datadog-packages/ in one pass.
If the script completes without errors — proceed to Phase 2.
ERROR: curl: command not found:
ssh -o StrictHostKeyChecking=no -i <SSH_KEY> <SSH_USER>@<SSH_HOST> \
"apt-get install -y curl 2>/dev/null || yum install -y curl"
ERROR: Permission error — ensure the SSH user has sudo access. The install script requires root.
ERROR: Script fails with GPG key error — retry; if it persists, check the host's DNS resolution for keys.datadoghq.com.
Phase 3: Verify the Agent is Running and Healthy
Claude runs
ssh -o StrictHostKeyChecking=no -i <SSH_KEY> <SSH_USER>@<SSH_HOST> \
"sudo datadog-agent status 2>&1 | head -40"
Healthy output shows:
Agent (v7.XX.X)withStatus: RunningAPI Keys status: API Key ending with XXXX: Valid
ERROR: command not found — installation did not complete. Re-run Phase 1.
ERROR: API key invalid — update and restart:
ssh -o StrictHostKeyChecking=no -i <SSH_KEY> <SSH_USER>@<SSH_HOST> \
"sudo sed -i 's/^api_key:.*/api_key: <NEW_API_KEY>/' /etc/datadog-agent/datadog.yaml && \
(sudo systemctl restart datadog-agent 2>/dev/null || sudo service datadog-agent restart)"
ERROR: Agent service not running:
ssh -o StrictHostKeyChecking=no -i <SSH_KEY> <SSH_USER>@<SSH_HOST> \
"sudo systemctl start datadog-agent 2>/dev/null && sudo systemctl enable datadog-agent 2>/dev/null || sudo service datadog-agent start"
Verify APM inject packages are present on disk (not just registered):
ssh -o StrictHostKeyChecking=no -i <SSH_KEY> <SSH_USER>@<SSH_HOST> \
"ls /opt/datadog-packages/ && sudo datadog-installer status 2>/dev/null | grep apm | head -10"
If /opt/datadog-packages/datadog-apm-inject exists — injection is available.
ERROR: Directory missing or empty — datadog-installer status may show the package as registered while its directory is actually empty (stale registration). Reinstall:
ssh -o StrictHostKeyChecking=no -i <SSH_KEY> <SSH_USER>@<SSH_HOST> \
"sudo datadog-installer remove datadog-apm-inject && \
DD_API_KEY=${DD_API_KEY} DD_SITE=${DD_SITE} DD_APM_INSTRUMENTATION_ENABLED=host bash -c \"\$(curl -L https://install.datadoghq.com/scripts/install_script_agent7.sh)\""
Verify hostname registration — the Agent must resolve and register its hostname for the host to appear in Datadog. DNS lookup failures are common in containers and minimal VMs:
ssh -o StrictHostKeyChecking=no -i <SSH_KEY> <SSH_USER>@<SSH_HOST> \
"sudo datadog-agent status 2>&1 | grep -iE '^\s+Hostname' | head -3"
If Hostname: <some-name> is shown — hostname resolved. Record this as DD_HOSTNAME for all subsequent steps.
ERROR: Hostname: (none) or any DNS resolution error — the agent can't resolve its own FQDN. Fix by setting the hostname explicitly in datadog.yaml:
# Read the actual system hostname
ACTUAL_HOSTNAME=$(ssh -o StrictHostKeyChecking=no -i <SSH_KEY> <SSH_USER>@<SSH_HOST> "hostname")
# Append to datadog.yaml only if not already set
ssh -o StrictHostKeyChecking=no -i <SSH_KEY> <SSH_USER>@<SSH_HOST> \
"grep -q '^hostname:' /etc/datadog-agent/datadog.yaml || \
echo \"hostname: ${ACTUAL_HOSTNAME}\" | sudo tee -a /etc/datadog-agent/datadog.yaml"
# Restart the Agent
ssh -o StrictHostKeyChecking=no -i <SSH_KEY> <SSH_USER>@<SSH_HOST> \
"sudo systemctl restart datadog-agent 2>/dev/null || sudo service datadog-agent restart"
# Confirm hostname is now registered
ssh -o StrictHostKeyChecking=no -i <SSH_KEY> <SSH_USER>@<SSH_HOST> \
"sudo datadog-agent status 2>&1 | grep -iE '^\s+Hostname' | head -2"
Phase 4: Discover Services That Need Restarting
SSI only injects into processes at startup. Existing processes keep running uninstrumented until restarted. Discover what's running so the user knows what to restart.
Claude runs
ssh -o StrictHostKeyChecking=no -i <SSH_KEY> <SSH_USER>@<SSH_HOST> \
"sudo ss -lntp 2>/dev/null || sudo netstat -tlnp 2>/dev/null || cat /proc/net/tcp"
For each application-level listener (ignore sshd, systemd, chronyd):
ssh -o StrictHostKeyChecking=no -i <SSH_KEY> <SSH_USER>@<SSH_HOST> "
# Command line of the process
sudo cat /proc/<PID>/cmdline | tr '\0' ' '
# Service manager (may not be available in all environments)
sudo systemctl status <PID> 2>/dev/null | head -3 || true
# Parent process
PPID=\$(sudo awk '/PPid/ {print \$2}' /proc/<PID>/status)
sudo cat /proc/\$PPID/cmdline | tr '\0' ' '
"
Present findings to the user:
I found the following application services on <host>:
Port 8080 — PID 1234 — /usr/bin/python3 /app/server.py
Managed by: systemd unit flask-app.service
Port 3000 — PID 5678 — node /app/server.js
Managed by: supervisord
These services need to be restarted for Datadog SSI to inject into them.
Restart them however is appropriate for your environment, then let me know
and I'll verify the instrumentation.
Do not offer to restart services. Do not restart services unless the user explicitly asks.
Done
Exit when ALL of the following are true:
- Agent running on each target host (
datadog-agent statusshows Running, API key valid) -
/opt/datadog-packages/datadog-apm-injectexists on disk on each host - User has been informed which services need restarting
- User has confirmed they are ready to restart services
Automatically proceed to enable-ssi (if services need UST labels configured) or verify-ssi (if services have already been restarted) — do not ask the user for permission.
Security constraints
- Never write a raw API key into any file or chat message
- Never store
DD_API_KEYin shell history — pass it inline in the SSH command only - If the user's API key appears in any output, redact it before displaying
- Always confirm before restarting production services
Frequently asked questions
What to verify before installation and use
What does the agent-install source document cover?
Before doing anything else: Fully resolve all variables in Context to resolve before acting. Do not begin Step 1 until every variable has a concrete value.
How do I install agent-install?
The source record exposes this install command: npx skills add https://github.com/datadog-labs/agent-skills --skill "dd-apm/linux-ssi/agent-install". Inspect the command and pinned source before running it.
Which permission-related actions were detected?
Static rules flagged network, write-files in the source; the page lists the matching lines and excerpts.
Alternatives
Compare before choosing
coreyhaines31/marketingskills
ab-testing
When the user wants to plan, design, or implement an A/B test or experiment, or build a growth experimentation program. Also use when the user mentions "A/B test," "split test," "experiment," "test this change," "variant copy," "multivariate test," "hypothesis," "should I test this," "which version is better," "test two versions," "statistical significance," "how long should I run this test," "growth experiments," "experiment velocity," "experiment backlog," "ICE score," "experimentation program
garrytan/gbrain
bulk-ingestion
End-to-end discipline for turning any large data source (audio libraries, email takeouts, document corpora, chat exports, API dumps) into brain pages at scale. The lifecycle spine: SCHEMA → ACCESS → TRIAL → EVALUATE → IMPROVE → CODIFY → TEST → SKILLIFY → BULK → MONITOR. State is tracked in a durable JSON manifest (see MANIFEST-PATTERN.md) so any crash, session boundary, or subagent fan-out resumes from ground truth instead of memory.
alirezarezvani/claude-skills
app-store-optimization
App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store. Use when the user asks about ASO, app store rankings, app metadata, app titles and descriptions, app store listings, app visibility, or mobile app marketing on iOS or Android. Supports keyword research and scoring, competitor keyword analysis, metadata optimization, A/B test planning, launch checklist
dotnet/skills
migrate-vstest-to-mtp
Migrates .NET test projects from VSTest to Microsoft.Testing.Platform (MTP). Use when user asks to "migrate to MTP", "switch from VSTest", "enable Microsoft.Testing.Platform", "use MTP runner", set OutputType=Exe only for test projects in Directory.Build.props, or mentions EnableMSTestRunner, EnableNUnitRunner, or UseMicrosoftTestingPlatformRunner. USE FOR: MTP behavioral differences vs VSTest (exit code 8, zero tests discovered, --ignore-exit-code, TESTINGPLATFORM_EXITCODE_IGNORE); centralizing