Skip to content

Bound feature queries and make polling cancellable - #5

Merged
craffit merged 10 commits into
masterfrom
otel-feature-query
Oct 1, 2026
Merged

craffit merged 10 commits into
masterfrom
otel-feature-query

Conversation

@craffit

@craffit craffit commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Adds bounded, classified feature queries and cancellable polling on the merged transport foundation. HTTPS CONNECT 407 is a configuration failure; proxy 5xx remains retryable.

Client.StartPolling replaces StartFeaturesPoller; callers must migrate. The existing client constructor and Connect() remain available.

Validation: OpenAPI transport/feature race suites pass; revive reports no errors.

Tracking: https://github.com/StackVista/stackstate/issues/587

@craffit

craffit commented Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

Updated the description to explain the connection checks and request limits in plain language. No code changes.

@craffit craffit changed the title Add bounded Receiver feature queries Bound feature queries and make polling cancellable Sep 14, 2026
@craffit

craffit commented Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

Added cancellable feature polling with delayed, jittered queries and delivery of successful and failed outcomes. Tests cover slow consumers, retry accounting, repeated stop and cancellation during HTTP, backoff, interval waits and blocked output. Focused race tests, the full Go suite and CI lint pass.

@ai-collaboration-app ai-collaboration-app Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed as the root of the #587 chain (this PR → kubernetes-rbac-agent#13 → sts-opentelemetry-collector#181 → helm-charts-internal#205). Both consumers pin this exact commit, so no divergence there.

The two blockers are connectivity regressions rather than logic bugs: not following redirects and dropping proxy env vars each turn a working deployment into a fatal start, because both consumers treat Rejected/Authentication as unrecoverable. Worth settling here before the consumers adopt.

Positives worth keeping: the token is re-read per request so SA rotation works, Result deliberately retains no error or body so credentials can't leak into telemetry, and dropping the old isVerbose openapi debug removes a request/response logging path.

Comment thread pkg/openapiclient/client.go

func newTransport(opts ConnectionOptions) (http.RoundTripper, error) {
transport := http.DefaultTransport.(*http.Transport).Clone()
transport.Proxy = nil

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Blocker. Clearing Proxy drops HTTPS_PROXY/NO_PROXY, so installs that reach the Receiver through a cluster-wide proxy env var lose connectivity silently after upgrade. Fall back to http.ProxyFromEnvironment when ProxyURL is empty.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The previous transport also configured only an explicit proxy; it did not use ProxyFromEnvironment. That policy is retained and documented in a78db13. TestProxyAndRedirectBoundaries passes for explicit proxying and isolation from ambient proxy settings.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Explicit proxy handling now lives in foundation #6 (f18c955), together with the additive options constructor. This PR retains only the feature-query/poller additions above it. Proxy and transport race tests pass on e2d867b.

Comment thread pkg/openapiclient/features/features_client.go
if err != nil || values == nil {
return Malformed
}
if capability, present := values["otel-logs"]; present {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A shared client shouldn't hardcode one consumer's capability key — the RBAC agent's k8s-rbac gets no equivalent type check. Either move the expected keys into QueryOptions, or drop the check and let callers assert.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in a78db13 with copied QueryOptions.BooleanCapabilities. The HTTP matrix covers logs, RBAC, both keys and object-only queries, including malformed requested keys and preserved unrelated numeric values. Both consumers explicitly select their own key.

Comment thread pkg/openapiclient/transport.go
result.Class = contextClass(authCtx, queryCtx.Err())
break
}
delay := time.Duration(c.random() * float64(backoff))

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is full jitter, so a run of small random values retries almost immediately and the retry bound degrades to MaxAttempts back-to-back requests. A floor of backoff/2 would keep the spacing.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Full jitter is the selected retry policy, so near-zero delays are allowed. MaxAttempts and the whole-query deadline still bound requests, and Retry-After remains a minimum when present. Existing retry/deadline/cancellation tests pass; no minimum spacing is promised for retries.

@craffit

craffit commented Sep 21, 2026

Copy link
Copy Markdown
Contributor Author

Added consumer-specific boolean capability validation and compatibility documentation in a78db13. The HTTP matrix, options-copy test, race checks, full suite and gofmt pass; revive reports existing warnings only. RBAC #13 and Collector #181 consume the same pushed pseudo-version.

@craffit

craffit commented Sep 22, 2026

Copy link
Copy Markdown
Contributor Author

Step-7 handoff at a78db13: full-suite/lint CI and the refreshed focused race suite pass. All six inline threads have substantive replies.

Regarding the review summary: redirects are deliberately rejected, requiring the final Receiver URL. Explicit-only proxying predates this PR. Per-request credential rotation and bounded, redacted results remain covered. RBAC now waits through capability-query 401/403; the logs collector retains its separate startup policy.

Descriptions are updated; no new source changes. Receiver route/config tests were skipped by owner request, and live acceptance remains outstanding.

@craffit
craffit changed the base branch from master to receiver-transport September 23, 2026 09:42
@craffit

craffit commented Sep 23, 2026

Copy link
Copy Markdown
Contributor Author

Stacked on #6 with signed merge e2d867b; reviewed history is preserved. Transport and legacy-constructor compatibility live in #6; this diff retains discovery, response bounds and polling. Full tests, feature/transport race tests and lint pass. Consumer pin: v0.0.0-20260923090625-e2d867b29448.

@craffit

craffit commented Sep 23, 2026

Copy link
Copy Markdown
Contributor Author

Integration review found that the feature-response wrapper hid idle-connection cleanup. a9d2a56 forwards CloseIdleConnections and adds a real HTTP shutdown regression test. Full tests, focused race tests and lint pass; consumers are updating to the corrected revision.

…ature-query

# Conflicts:
#	pkg/openapiclient/options_test.go
@craffit

craffit commented Sep 23, 2026

Copy link
Copy Markdown
Contributor Author

Merged the #6 transport cleanup, removing CABundlePEM and using system certificate trust. Feature-query classification and polling behavior are retained. CI passed for f0ec060.

@craffit

craffit commented Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Merged A1's platform-aware system-trust test fix into this branch (3f3f517). The Linux certificate-trust subprocess test remains covered; non-Linux runs skip that Linux-specific mechanism. Focused client and feature-query race tests pass.

@craffit
craffit changed the base branch from receiver-transport to master September 29, 2026 09:17
@craffit

craffit commented Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

Merged master in signed commit 82c5cc1 and retargeted to master after #6 merged. Transport/feature race tests and current-head CI pass. Collector and RBAC now pin this revision.

@craffit
craffit marked this pull request as ready for review September 29, 2026 09:21
Comment thread pkg/openapiclient/transport.go

@LouisLotter LouisLotter left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Follow-up review of the current head. The proxy CONNECT classification needs a fix before consumers are re-pinned; the compatibility wording is a nonblocking correction.

Comment thread pkg/openapiclient/features/features_client.go
Comment thread pkg/openapiclient/features/features_poller.go
@craffit

craffit commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Fixed in f2036fa: preserve CONNECT status in a credential-safe typed error, classify 407 as configuration failure before generic transport errors, and retain bounded retries for proxy 5xx. Regression tests cover status/attempt counts and private response-text exclusion; OpenAPI race suites pass.

Also corrected the compatibility description: Client.StartPolling replaces StartFeaturesPoller; existing constructors remain available. Collector and RBAC are being re-pinned to this revision.

@craffit
craffit merged commit fd72bbd into master Oct 1, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants