Remove packaging as a runtime dependency of opentelemetry-instrumentation-flask
Summary
opentelemetry-instrumentation-flask declares packaging >= 21.0 as a runtime
dependency, used solely to compare the installed Flask version.
Motivation: the auto-instrumentation injector
The auto-instrumentation injector (the Python auto-instrumentation shipped by the
OpenTelemetry Operator) bundles the instrumentation packages and all of their
runtime dependencies into an init container and prepends that directory to the
target application's PYTHONPATH. Every runtime dependency is therefore injected
into the user's application process, where a common library like packaging
risks version shadowing/conflicts and adds to the injected payload. Removing it
shrinks that footprint. See #4882 for the full rationale.
Where it is used
pyproject.toml: packaging >= 21.0 in dependencies.
src/opentelemetry/instrumentation/flask/__init__.py:305:
package_version.parse(flask_version) compared against 2.2.0 / 3.1.0 to
gate newer-Flask behavior.
Purpose: spec-compliant PEP 440 ordering of flask.__version__ to branch
behavior by installed Flask version.
Proposed resolution
Import the PEP 440 Version from the internal implementation added in #4882
(opentelemetry.instrumentation._packaging.version) instead of packaging, and
remove packaging from this package's dependencies.
Depends on #4882, which introduces opentelemetry.instrumentation._packaging
in opentelemetry-instrumentation (a dependency of this package).
Remove
packagingas a runtime dependency ofopentelemetry-instrumentation-flaskSummary
opentelemetry-instrumentation-flaskdeclarespackaging >= 21.0as a runtimedependency, used solely to compare the installed Flask version.
Motivation: the auto-instrumentation injector
The auto-instrumentation injector (the Python auto-instrumentation shipped by the
OpenTelemetry Operator) bundles the instrumentation packages and all of their
runtime dependencies into an init container and prepends that directory to the
target application's
PYTHONPATH. Every runtime dependency is therefore injectedinto the user's application process, where a common library like
packagingrisks version shadowing/conflicts and adds to the injected payload. Removing it
shrinks that footprint. See #4882 for the full rationale.
Where it is used
pyproject.toml:packaging >= 21.0independencies.src/opentelemetry/instrumentation/flask/__init__.py:305:package_version.parse(flask_version)compared against2.2.0/3.1.0togate newer-Flask behavior.
Purpose: spec-compliant PEP 440 ordering of
flask.__version__to branchbehavior by installed Flask version.
Proposed resolution
Import the PEP 440
Versionfrom the internal implementation added in #4882(
opentelemetry.instrumentation._packaging.version) instead ofpackaging, andremove
packagingfrom this package'sdependencies.Depends on #4882, which introduces
opentelemetry.instrumentation._packagingin
opentelemetry-instrumentation(a dependency of this package).