Sign inSign up

docker/sbx-kit-dynatrace:latest

Multi-platform
Manifest digest

sha256:00c49f4e58b7b9cdf9692ace144b3309f52600ee758fc6c3922eab0a76079a5c

Last pushed

9 days by cdupuis

Type

Sandbox Kit

Manifest digest

sha256:00c49f4e58b7b9cdf9692ace144b3309f52600ee758fc6c3922eab0a76079a5c

yaml
schemaVersion: "3"
displayName: Dynatrace (SaaS, Remote MCP)
description: 'Wires an agent to a Dynatrace SaaS environment through the official hosted Dynatrace Remote MCP server (no server install): query problems, vulnerabilities, entities, logs, and run DQL against Grail. The kit holds no token; store it once with `sbx secret set dynatrace` and the sbx proxy injects it as a Bearer token on requests to *.apps.dynatrace.com.'
sourceUrl: https://github.com/dynatrace-oss/dynatrace-mcp
version: 1.0.0
licenses:
    - Apache-2.0
kind: mixin
capabilities:
    - type: com.docker.sandbox/network-policy@1
      config:
        install:
            allow:
                - pypi.org
                - files.pythonhosted.org
        runtime:
            allow:
                - '*.apps.dynatrace.com'
    - type: com.docker.sandbox/credential@1
      config:
        apiKey:
            inject:
                - domain: '*.apps.dynatrace.com'
                  format: Bearer %s
                  header: Authorization
        phase: runtime
        service: dynatrace
      description: Dynatrace platform token for Remote MCP and Grail DQL; requires the storage read scopes used by the runbooks
    - type: com.docker.sandbox/lifecycle@1
      config:
        files:
            - content: |
                {
                  "mcpServers": {
                    "dynatrace": {
                      "type": "http",
                      "url": "${{ kit.args.environment }}/platform-reserved/mcp-gateway/v0.1/servers/dynatrace-mcp/mcp",
                      "headers": {
                        "Authorization": "Bearer inject-me"
                      }
                    }
                  }
                }
              description: Portable Remote MCP definition for any agent that reads an mcpServers block; the proxy replaces its placeholder Authorization value
              mode: "0644"
              overwrite: false
              path: /home/agent/.dynatrace/mcp.json
        install:
            - command: pip install --break-system-packages 'requests>=2.31,<3'
              description: Install the requests library used by the DQL runbooks
              env:
                - HTTP_PROXY
                - HTTPS_PROXY
              user: "1000"
        startup:
            - command:
                - sh
                - -c
                - 'command -v claude >/dev/null 2>&1 || exit 0; case "$DT_ENVIRONMENT" in *YOUR-ENV*) exit 0 ;; esac; claude mcp add --transport http dynatrace "$DT_ENVIRONMENT/platform-reserved/mcp-gateway/v0.1/servers/dynatrace-mcp/mcp" --header "Authorization: Bearer inject-me" >/dev/null 2>&1 || true'
              description: Register the Dynatrace Remote MCP server with the Claude agent (best-effort; no-op elsewhere)
              env:
                - DT_ENVIRONMENT
              user: "1000"
    - type: com.docker.sandbox/agent-context@1
      config:
        contentFile: /usr/share/sandbox/kit/dynatrace/dynatrace-context.md
args:
    environment:
        default: https://YOUR-ENV.apps.dynatrace.com
        description: Your Dynatrace SaaS (Gen3 "apps") environment URL, for example https://abc12345.apps.dynatrace.com. Use the "apps" URL, not the classic *.live.dynatrace.com. Left at the default, the kit installs but the Remote MCP registration and the runbooks stay inert until you set a real URL.
        pattern: ^https://[A-Za-z0-9-]+\.apps\.dynatrace\.com/?$
        env: DT_ENVIRONMENT