Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (19)
🔗 Linked repositories identifiedCodeRabbit considers these linked repositories for cross-repo context during reviews:
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe change adds opt-in OpenTelemetry configuration for Grid gateways through the operator and Helm chart. It renders Praxis telemetry settings and trace-context propagation, enables gateway exporter features, and documents credential handling and trace-linkage limits. ChangesGateway telemetry
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant NetworkAdmin
participant GridOperator
participant PraxisConfig
participant GridGateway
participant OTLPCollector
NetworkAdmin->>GridOperator: Set consumerConfig.telemetry
GridOperator->>PraxisConfig: Render root telemetry and trace_context
PraxisConfig-->>GridGateway: Supply runtime telemetry configuration
GridGateway->>OTLPCollector: Export spans through OTLP
Suggested reviewers: Merge Risk: ⚪ Minimal · up to This adds opt-in OpenTelemetry export that is off by default, so existing deployments should not change. No blocking issue was found in the supplied changes. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to Telemetry is opt-in, validated, and keeps collector credentials out of generated configuration. However, removing exporter settings can remain unapplied when routing reconciliation is skipped, leaving an old destination available after restart. Production permissions, outbound-network restrictions, and collector-credential isolation remain unverified. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Comment |
Signed-off-by: Brent Salisbury <bsalisbu@redhat.com>
Signed-off-by: Brent Salisbury <bsalisbu@redhat.com>
Signed-off-by: Brent Salisbury <bsalisbu@redhat.com>
Signed-off-by: Brent Salisbury <bsalisbu@redhat.com>
b723415 to
30a2938
Compare
What does this PR do?
Add opt-in OpenTelemetry configuration for AGN (AI Gateway Networking) gateways, so operators can export gateway HTTP and routing spans without putting collector settings or credentials in routing overlays.
grid-gatewaywith the Praxis OTLP exporter and Praxis AI routing-span features; initialize tracing at startup and hold its guard through shutdown.GatewayRef.consumerConfigand the Praxis gateway Helm chart. An omitted or empty OTLP endpoint uses the process environment; invalid sampling rates and credential-bearing endpoint URLs are rejected.Merge order: This change can merge before the Praxis framework tracing change. The normal Grid build remains on registry Praxis 0.7.1; no fork dependency is pinned. On that version, opt-in telemetry exports local HTTP and AI routing spans and forwards W3C headers, but edge and provider exported spans are not yet one linked trace. After the framework change is released, Grid must update its dependency, rebuild the gateway image, and verify exported parent IDs against that exact image before claiming cross-gateway linkage.
Which issue(s) does this relate to?
Related to #260. This PR delivers the opt-in configuration and export groundwork. Cross-gateway parentage remains an open acceptance criterion for that issue.
Checklist
git commit -s)make lint && make test && make test-integrationpasses locallymake lint,make test, andmake helm-lintpassed on a clean checkout of this branch; Helm reported 351 passes and one optional API-key runtime skip. A locked gateway image built from the same checkout, and a collector-backed check against that image confirmed local span export, routing revision attributes, and W3C header propagation. It also confirmed the documented cross-gateway linkage gap on Praxis 0.7.1. Grid has nomake test-integrationtarget.Does this introduce a breaking change?
No. Telemetry is opt-in and disabled by default. Enabling it requires a
grid-gatewayimage built with the tracing features; the chart's default Praxis AI image does not provide this Grid-specific build.Summary by CodeRabbit