Skip to content

Repository files navigation

Forward for Dynatrace

CI Release Node.js 24 License: ISC

Forward for Dynatrace converts observed application dependencies into governed network intent and modeled path evidence. Application, network, and change teams can validate the same business-critical relationships before and after a change while Dynatrace and Forward remain authoritative for their respective data.

Release channel: 0.13.4 enterprise preview for controlled evaluation and non-production use. The release is delivered as one immutable Dynatrace app archive with checksums, an SBOM, and GitHub attestations.

Forward for Dynatrace application overview

Business Outcomes

Team Outcome
Application and SRE Convert current service relationships into network validation scope without manually recreating flows.
Network engineering Add application context to Forward path analysis, intent checks, and pre/post-change assurance.
Change management Gate execution and closeout on current application health and modeled network evidence.
Security and platform Enforce least privilege, explicit write approval, bounded data exchange, and independently verifiable releases.

How It Works

flowchart LR
  DT["Dynatrace<br/>spans, OneAgent network flows, Workflow, Guardian"]
  APP["Forward for Dynatrace<br/>UI, app functions, actions, settings"]
  FWD["Forward<br/>snapshots, paths, NQE, intent checks"]

  DT -->|observed dependencies and health| APP
  APP -->|sanitized modeled-network evidence| DT
  APP -->|HTTPS API requests through a Vault-backed connection| FWD
  FWD -->|host resolution, path results, check state| APP
Loading

The Dynatrace app is the only installable component. Forward communication is direct HTTPS API traffic from Dynatrace app functions through a tenant-managed Credential Vault reference. The integration requires no Forward-side service, container, agent, package, or browser-held credential.

Capabilities

  • Discover current service-to-service relationships from distributed traces, plus infrastructure-centric connections from OneAgent network connection monitoring when applications are not instrumented.
  • Normalize application, environment, endpoint, protocol, port, owner, and evidence-time metadata through a tenant-owned discovery profile.
  • Resolve endpoints and evaluate modeled paths against the latest processed Forward snapshot.
  • Build deterministic intent-check plans with create, update, unchanged, stale, collision, and mapping counts.
  • Create missing checks and update changed managed checks only after exact Network Admin approval.
  • Keep stale checks report-only; synchronization has no implicit delete path.
  • Run allowlisted Forward Library NQEs or reviewed arbitrary NQEs according to the selected Forward access profile.
  • Correlate Forward reachability with Dynatrace Site Reliability Guardian results while preserving each platform's source-of-truth boundary.

Access Profiles And Change Control

Each connection binds one Forward network and one declared access profile. A more privileged credential never upgrades a plan-only request.

Forward profile Evidence access Intent-check behavior
Read Only Modeled state, checks, paths, and approved Library NQEs by ID Plan only; no writes
Network Operator Read Only plus arbitrary NQE execution permitted by Forward RBAC Plan only; no writes
Network Admin Full evidence plus managed intent-check reconciliation Exact-approved create and update only

Network Admin apply requires the immutable plan digest, the same processed snapshot, explicit mutation budgets, exact approval of every changed managed source key, zero ownership collisions, and successful post-write readback.

Security And Governance

  • Forward credentials are stored only in a dedicated APP_ENGINE-scoped Dynatrace Credential Vault entry. App settings retain its entity ID; only app functions resolve the secret at invocation time.
  • Forward API targets require HTTPS, the exact /api root, and tenant outbound-host approval.
  • Requests use strict schemas, timeouts, bounded retries, response-size limits, concurrency limits, and mutation budgets.
  • Plans bind the network, snapshot, access profile, managed identities, and canonical check fingerprints.
  • Unmanaged checks are never adopted by name; partial failure stops the apply and requires a new plan.
  • Browser and Workflow results exclude credentials, authorization headers, raw authenticated errors, complete inventory, and detailed path topology.
  • Every release contains an app archive, CycloneDX SBOM, SHA-256 checksums, optional detached signature, and GitHub artifact attestations.

See Architecture, RBAC, Data handling, Threat model, and Security policy for the complete control boundary.

Install An Immutable Release

Prerequisites

  • Dynatrace SaaS with AppEngine and Workflow enabled.
  • Permission to install custom apps, manage app settings and Credential Vault entries, and approve the Forward API host under Settings > General > External requests.
  • A dedicated, auditable Forward service identity and a network with a processed snapshot. Start with Read Only.
  • Node.js 24 and an authenticated GitHub CLI for the supplied verification and installation tooling.

1. Download And Verify

The /secure path below is an example. Use an operator-owned directory with permissions appropriate for release evidence in your environment.

export RELEASE_TAG=v0.13.4
mkdir -p "/secure/forward-dynatrace/${RELEASE_TAG}"
cd "/secure/forward-dynatrace/${RELEASE_TAG}"

gh release download "${RELEASE_TAG}" \
  --repo forwardnetworks/forward-dynatrace
sha256sum -c SHA256SUMS
gh attestation verify "forward-dynatrace-app-${RELEASE_TAG}.zip" \
  --repo forwardnetworks/forward-dynatrace

2. Install The Verified Archive

Use the installer from the same immutable tag. Keep OAuth values in the environment or an approved secret manager; never place them on a shared command line, in source control, or in Workflow JSON.

git clone https://github.com/forwardnetworks/forward-dynatrace.git
cd forward-dynatrace
git checkout "${RELEASE_TAG}"
npm ci

export DT_APP_OAUTH_CLIENT_ID=<protected-client-id>
export DT_APP_OAUTH_CLIENT_SECRET=<protected-client-secret>

npm run dynatrace:release:install -- \
  --environment-url https://<environment-id>.apps.dynatrace.com/ \
  --archive "/secure/forward-dynatrace/${RELEASE_TAG}/forward-dynatrace-app-${RELEASE_TAG}.zip" \
  --checksums "/secure/forward-dynatrace/${RELEASE_TAG}/SHA256SUMS"

The installer verifies checksum membership, archive identity, required app functions, settings schemas, and Workflow actions before upload, then waits for the exact version to become ready in the AppEngine Registry.

For upgrades, rollback, signed-app identity, and tenant scopes, see the installation guide.

Configure

Dynatrace app settings for dependency discovery and Forward API connections

  1. Approve the exact Forward API hostname in Dynatrace external requests.
  2. Create one or more Dependency discovery profiles using the matching reviewed distributed-trace or OneAgent network-flow DQL template and an explicit freshness window.
  3. Store the dedicated Forward service identity as an APP_ENGINE-scoped username/password entry in Dynatrace Credential Vault.
  4. Create a Forward API connection with the exact /api URL, network ID, Credential Vault entity ID, and declared access profile.
  5. Open Apps > Forward, select the discovery profile, and confirm current dependency and mapping evidence.
  6. Add Synchronize Forward intent checks to an on-demand Workflow and begin with operation: plan under Read Only.
  7. Add Network Admin apply only after approval ownership, budgets, and post-change closeout policy are established.

In v0.13.x the network ID is entered manually; Credential Vault stores authentication and does not populate a dynamic network list. Private or internal-CA Forward endpoints require EdgeConnect with the CA configured for verified TLS. The app does not provide a certificate-verification bypass. See the installation limitations.

The enterprise evaluation guide provides a complete click-by-click acceptance sequence.

Operate

A normal change-assurance cycle is:

  1. Refresh current Dynatrace dependencies and select the latest processed Forward snapshot.
  2. Run a plan and review mapping gaps, modeled-path results, collisions, reconciliation counts, and the plan digest.
  3. Approve and apply only the exact Network Admin plan when writes are required.
  4. Collect a post-change Forward snapshot and rerun the same evidence scope.
  5. Run the associated Site Reliability Guardian validation.
  6. Close the change only when the required Forward and Dynatrace objectives pass.

See the workflow guide, operations runbook, and Site Reliability Guardian integration.

Release Integrity

GitHub releases publish exactly one Dynatrace app archive plus verification evidence. The project does not publish a container image, operating-system package, Python package, or Forward-side runtime. Published tags are immutable; any change requires a new version.

See Release process, Release provenance, Compatibility policy, and Release communication.

Development

npm ci
npm run ci
npm run start

Node.js 24 is the supported development runtime. npm run ci validates schemas, security controls, Workflow and Guardian assets, 1,000-relationship scale behavior, 100 repeat reconciliation cycles, release integrity, linting, builds, and the installable archive.

Repository layout:

api/       Dynatrace app functions
actions/   Workflow actions, widgets, and connection contracts
ui/        Dynatrace application UI
lib/       discovery, evidence, identity, and access policy
schemas/   API payload and evidence contracts
deploy/    Workflow, DQL, dashboard, and Guardian assets
scripts/   validation, packaging, installation, and release tooling
docs/      architecture, security, operations, and integration guides

See Contributing, Support, Ownership, and the documentation index.

License

ISC

About

Dynatrace app for publishing service dependency evidence into Forward

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages