Forward for Dynatrace converts observed application dependencies into governed network intent and modeled path evidence. Application, network, and change teams can validate the same business-critical relationships before and after a change while Dynatrace and Forward remain authoritative for their respective data.
Release channel:
0.13.4enterprise preview for controlled evaluation and non-production use. The release is delivered as one immutable Dynatrace app archive with checksums, an SBOM, and GitHub attestations.
| Team | Outcome |
|---|---|
| Application and SRE | Convert current service relationships into network validation scope without manually recreating flows. |
| Network engineering | Add application context to Forward path analysis, intent checks, and pre/post-change assurance. |
| Change management | Gate execution and closeout on current application health and modeled network evidence. |
| Security and platform | Enforce least privilege, explicit write approval, bounded data exchange, and independently verifiable releases. |
flowchart LR
DT["Dynatrace<br/>spans, OneAgent network flows, Workflow, Guardian"]
APP["Forward for Dynatrace<br/>UI, app functions, actions, settings"]
FWD["Forward<br/>snapshots, paths, NQE, intent checks"]
DT -->|observed dependencies and health| APP
APP -->|sanitized modeled-network evidence| DT
APP -->|HTTPS API requests through a Vault-backed connection| FWD
FWD -->|host resolution, path results, check state| APP
The Dynatrace app is the only installable component. Forward communication is direct HTTPS API traffic from Dynatrace app functions through a tenant-managed Credential Vault reference. The integration requires no Forward-side service, container, agent, package, or browser-held credential.
- Discover current service-to-service relationships from distributed traces, plus infrastructure-centric connections from OneAgent network connection monitoring when applications are not instrumented.
- Normalize application, environment, endpoint, protocol, port, owner, and evidence-time metadata through a tenant-owned discovery profile.
- Resolve endpoints and evaluate modeled paths against the latest processed Forward snapshot.
- Build deterministic intent-check plans with create, update, unchanged, stale, collision, and mapping counts.
- Create missing checks and update changed managed checks only after exact Network Admin approval.
- Keep stale checks report-only; synchronization has no implicit delete path.
- Run allowlisted Forward Library NQEs or reviewed arbitrary NQEs according to the selected Forward access profile.
- Correlate Forward reachability with Dynatrace Site Reliability Guardian results while preserving each platform's source-of-truth boundary.
Each connection binds one Forward network and one declared access profile. A more privileged credential never upgrades a plan-only request.
| Forward profile | Evidence access | Intent-check behavior |
|---|---|---|
| Read Only | Modeled state, checks, paths, and approved Library NQEs by ID | Plan only; no writes |
| Network Operator | Read Only plus arbitrary NQE execution permitted by Forward RBAC | Plan only; no writes |
| Network Admin | Full evidence plus managed intent-check reconciliation | Exact-approved create and update only |
Network Admin apply requires the immutable plan digest, the same processed snapshot, explicit mutation budgets, exact approval of every changed managed source key, zero ownership collisions, and successful post-write readback.
- Forward credentials are stored only in a dedicated APP_ENGINE-scoped Dynatrace Credential Vault entry. App settings retain its entity ID; only app functions resolve the secret at invocation time.
- Forward API targets require HTTPS, the exact
/apiroot, and tenant outbound-host approval. - Requests use strict schemas, timeouts, bounded retries, response-size limits, concurrency limits, and mutation budgets.
- Plans bind the network, snapshot, access profile, managed identities, and canonical check fingerprints.
- Unmanaged checks are never adopted by name; partial failure stops the apply and requires a new plan.
- Browser and Workflow results exclude credentials, authorization headers, raw authenticated errors, complete inventory, and detailed path topology.
- Every release contains an app archive, CycloneDX SBOM, SHA-256 checksums, optional detached signature, and GitHub artifact attestations.
See Architecture, RBAC, Data handling, Threat model, and Security policy for the complete control boundary.
- Dynatrace SaaS with AppEngine and Workflow enabled.
- Permission to install custom apps, manage app settings and Credential Vault entries, and approve the Forward API host under Settings > General > External requests.
- A dedicated, auditable Forward service identity and a network with a processed snapshot. Start with Read Only.
- Node.js 24 and an authenticated GitHub CLI for the supplied verification and installation tooling.
The /secure path below is an example. Use an operator-owned directory with permissions appropriate for release
evidence in your environment.
export RELEASE_TAG=v0.13.4
mkdir -p "/secure/forward-dynatrace/${RELEASE_TAG}"
cd "/secure/forward-dynatrace/${RELEASE_TAG}"
gh release download "${RELEASE_TAG}" \
--repo forwardnetworks/forward-dynatrace
sha256sum -c SHA256SUMS
gh attestation verify "forward-dynatrace-app-${RELEASE_TAG}.zip" \
--repo forwardnetworks/forward-dynatraceUse the installer from the same immutable tag. Keep OAuth values in the environment or an approved secret manager; never place them on a shared command line, in source control, or in Workflow JSON.
git clone https://github.com/forwardnetworks/forward-dynatrace.git
cd forward-dynatrace
git checkout "${RELEASE_TAG}"
npm ci
export DT_APP_OAUTH_CLIENT_ID=<protected-client-id>
export DT_APP_OAUTH_CLIENT_SECRET=<protected-client-secret>
npm run dynatrace:release:install -- \
--environment-url https://<environment-id>.apps.dynatrace.com/ \
--archive "/secure/forward-dynatrace/${RELEASE_TAG}/forward-dynatrace-app-${RELEASE_TAG}.zip" \
--checksums "/secure/forward-dynatrace/${RELEASE_TAG}/SHA256SUMS"The installer verifies checksum membership, archive identity, required app functions, settings schemas, and Workflow actions before upload, then waits for the exact version to become ready in the AppEngine Registry.
For upgrades, rollback, signed-app identity, and tenant scopes, see the installation guide.
- Approve the exact Forward API hostname in Dynatrace external requests.
- Create one or more Dependency discovery profiles using the matching reviewed distributed-trace or OneAgent network-flow DQL template and an explicit freshness window.
- Store the dedicated Forward service identity as an APP_ENGINE-scoped username/password entry in Dynatrace Credential Vault.
- Create a Forward API connection with the exact
/apiURL, network ID, Credential Vault entity ID, and declared access profile. - Open Apps > Forward, select the discovery profile, and confirm current dependency and mapping evidence.
- Add Synchronize Forward intent checks to an on-demand Workflow and begin with
operation: planunder Read Only. - Add Network Admin apply only after approval ownership, budgets, and post-change closeout policy are established.
In v0.13.x the network ID is entered manually; Credential Vault stores authentication and does not populate a dynamic network list. Private or internal-CA Forward endpoints require EdgeConnect with the CA configured for verified TLS. The app does not provide a certificate-verification bypass. See the installation limitations.
The enterprise evaluation guide provides a complete click-by-click acceptance sequence.
A normal change-assurance cycle is:
- Refresh current Dynatrace dependencies and select the latest processed Forward snapshot.
- Run a plan and review mapping gaps, modeled-path results, collisions, reconciliation counts, and the plan digest.
- Approve and apply only the exact Network Admin plan when writes are required.
- Collect a post-change Forward snapshot and rerun the same evidence scope.
- Run the associated Site Reliability Guardian validation.
- Close the change only when the required Forward and Dynatrace objectives pass.
See the workflow guide, operations runbook, and Site Reliability Guardian integration.
GitHub releases publish exactly one Dynatrace app archive plus verification evidence. The project does not publish a container image, operating-system package, Python package, or Forward-side runtime. Published tags are immutable; any change requires a new version.
See Release process, Release provenance, Compatibility policy, and Release communication.
npm ci
npm run ci
npm run startNode.js 24 is the supported development runtime. npm run ci validates schemas, security controls, Workflow and
Guardian assets, 1,000-relationship scale behavior, 100 repeat reconciliation cycles, release integrity, linting,
builds, and the installable archive.
Repository layout:
api/ Dynatrace app functions
actions/ Workflow actions, widgets, and connection contracts
ui/ Dynatrace application UI
lib/ discovery, evidence, identity, and access policy
schemas/ API payload and evidence contracts
deploy/ Workflow, DQL, dashboard, and Guardian assets
scripts/ validation, packaging, installation, and release tooling
docs/ architecture, security, operations, and integration guides
See Contributing, Support, Ownership, and the documentation index.

