Wires an agent to a Dynatrace SaaS environment through the official hosted Dynatrace Remote MCP s...
124
Wires an agent to a Dynatrace SaaS environment through the official hosted Dynatrace Remote MCP server (no server install): query problems, vulnerabilities, entities, logs, and run DQL against Grail. The kit holds no token; store it once with `sbx secret set dynatrace` and the sbx proxy injects it as a Bearer token on requests to *.apps.dynatrace.com.
| Name | Required | Default | Description |
|---|---|---|---|
environment | Optional | https://YOUR-ENV.apps.dynatrace.com | Your Dynatrace SaaS (Gen3 "apps") environment URL, for example https://abc12345.apps.dynatrace.com. Use the "apps" URL, not the classic *.live.dynatrace.com. Left at the default, the kit installs but the Remote MCP registration and the runbooks stay inert until you set a real URL. |
| Type | Required | Description | |
|---|---|---|---|
com.docker.sandbox/network-policy@1 | Required | — | |
com.docker.sandbox/credential@1 | Required | Dynatrace platform token for Remote MCP and Grail DQL; requires the storage read scopes used by the runbooks | |
com.docker.sandbox/lifecycle@1 | Required | — | |
com.docker.sandbox/agent-context@1 | Required | — | |
sbx run <agent> --kit docker/sbx-kit-dynatrace:latestRun the following command to install sbx on your machine.
brew install docker/tap/sbxwinget install Docker.sbxNote
Experimental: Sandbox Kit v3This kit uses the experimental Sandbox Kit specification, specifically v3. The format and runtime behavior may change before v3 is stable.
A mixin kit that wires an agent to a Dynatrace SaaS environment through the official hosted Dynatrace Remote MCP server (nothing is installed in the sandbox): list problems, security vulnerabilities and exceptions, find entities, and run DQL against Grail. The kit holds no token; it is stored on the host and injected by the sbx proxy on the wire.
Pairs with any base agent. For the built-in claude agent the Remote MCP server is registered automatically at startup; other agents can import the portable ~/.dynatrace/mcp.json the kit writes.
https://abc12345.apps.dynatrace.com.Store the token once on the host (the kit declares the dynatrace credential, so no --host wiring is needed):
sbx secret set dynatrace
Pass your environment URL with --kit-arg dynatrace.environment=...:
sbx run --kit "docker.io/docker/sbx-kit-dynatrace:latest" --kit-arg dynatrace.environment=https://abc12345.apps.dynatrace.com claude
Or target this repo directly over git, or a local clone:
sbx run --kit "git+https://github.com/docker/sbx-kits-contrib.git#dir=dynatrace" --kit-arg dynatrace.environment=https://abc12345.apps.dynatrace.com claude
sbx run --kit ./dynatrace/ --kit-arg dynatrace.environment=https://abc12345.apps.dynatrace.com claude
Left at its default, the kit still installs, but the Remote MCP registration and the runbooks stay inert until dynatrace.environment is a real URL.
The kit declares a dynatrace credential with one inject rule for *.apps.dynatrace.com (the host that serves both the Remote MCP gateway and the Grail DQL API). dynatrace is a custom service, so the token is never exported into the container: sbx only sets SBX_CRED_DYNATRACE_MODE, and requests leave the sandbox carrying a placeholder Authorization: Bearer inject-me header that the proxy overwrites with your real token on the wire. The real token never touches the sandbox filesystem or environment.
For quick scripting without the MCP server, ~/runbooks/ ships small requests-based scripts that hit the Grail DQL API directly:
python3 ~/runbooks/run_dql.py 'fetch dt.davis.problems | limit 10'
python3 ~/runbooks/dynatrace_report.py
They read DT_ENVIRONMENT (set from the dynatrace.environment arg) and default the token to the inject-me placeholder the proxy overwrites.
The v3 descriptor is dynatrace.yaml, its runbook overlay recipe is dynatrace.dockerfile, and agent guidance lives in dynatrace-context.md.
sbx secret rm --service dynatrace
Pulls:
57
Last week