Repository navigation
feat(supervisor): export OTLP traces from sandbox supervisors - #3977
Conversation
|
🌿 Preview your docs: https://nvidia-preview-pr-3977.docs.buildwithfern.com/openshell |
ebefc25 to
53a60f5
Compare
|
Sol found three things:
Sol's suggestion for the first:
|
|
That seems reasonable to me, but I'm only one-code-read's worth of familiar with this, so you might have a more efficient choice in mind. I'd address the first two. |
BlockedGitHub reports merge conflicts for this PR, so Gator cannot advance it to code review yet. Thanks @purp. I checked the current head after your comments: no new commit has been pushed since you asked for a supervisor-reachable collector endpoint and a propagation test that proves explicit parenting. Those requests remain with the author. Next action: @krishicks, resolve the merge conflicts and address those two maintainer requests in an updated commit. Gator will review the new head. Gator metadata
|
53a60f5 to
00e8e84
Compare
When the gateway exports OTLP traces, compute drivers pass the gateway's endpoint to supervisors as OPENSHELL_OTLP_ENDPOINT, along with TRACEPARENT from the operation that launched them. The Kubernetes, Docker, Podman, and VM drivers all receive the endpoint from the gateway; driver TOML cannot set it. On Podman Machine, the Podman driver points a loopback endpoint at host.containers.internal, since supervisor loopback is the VM's. The supervisor exports spans as openshell-supervisor, tagged with the sandbox ID, and flushes them before exiting. supervisor.startup joins the sandbox's creation trace and covers image policy discovery, policy load, and boundary attach, confirm, agent start, and access start. Supervisor calls to the gateway carry W3C trace context, so the gateway's server spans nest under them. Each egress connection emits supervisor.egress.connect with authorize, resolve, and dial children. These spans use DEBUG level because every outbound connection starts its own trace. OpenShell spans export at INFO, or at the sandbox log level when it is debug or trace; spans from other libraries export at INFO. Signed-off-by: Kris Hicks <khicks@nvidia.com>
00e8e84 to
f82246e
Compare
|
@purp Updated:
|
purp
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
Thanks @krishicks. I checked your update: the Podman Machine address conversion and the explicit-parent propagation tests address those two parts of @purp's feedback. Your local Podman trace check is helpful. One supported local Kubernetes path still receives an unreachable supervisor collector endpoint; I left the remaining finding on the changed line. The author can fix that path or ask a maintainer to explicitly accept deferring it to #3196. No other blocking findings arose in the full patch review.
Next state: gator:in-review. The author and maintainer should resolve the Kubernetes tracing scope before Gator dispatches the required runtime tests.
Gator metadata
- Head SHA:
f82246ee3bb0f0ee568df57f2846115ca1d0b187 - Base SHA:
be7af99ff2eacba807d82b69adb0c3d4eaa32158 - Merge base SHA:
be7af99ff2eacba807d82b69adb0c3d4eaa32158 - Patch ID:
459f587dc45ef7dccebdfe356cf4da7ed34dd2aa - Gator payload:
9 - Next state:
gator:in-review
|
Label |
purp
left a comment
There was a problem hiding this comment.
Deferral makes sense.
LGTM 🚢
Monitoring CompleteMonitoring is complete because this PR has merged. Final status: Gator's current-head review was preserved, and the PR merged after maintainer approval. I removed the active |
Summary
Sandbox supervisors now export OTLP traces to the gateway's collector, so sandbox startup, supervisor-to-gateway calls, and egress handling show up in the same trace as the gateway request that created the sandbox.
Related Issue
Partially addresses #2508
#2508 proposed relaying supervisor spans through the gateway because the supervisor ran inside the sandbox and direct export would have needed an egress policy exception. Since RFC 0012 the supervisor runs outside the workload's egress policy, so it exports directly to the collector.
Changes
OPENSHELL_OTLP_ENDPOINT, along withTRACEPARENTfrom the launching operation. Driver TOML cannot set the endpoint.openshell-supervisorwith theopenshell.sandbox.idresource attribute, and flushes them before exiting.supervisor.startupjoins the sandbox creation trace and covers image policy discovery, policy load, and boundary attach, confirm, agent start, and access start.supervisor.egress.connectwithauthorize,resolve, anddialchildren. These use DEBUG level because every outbound connection starts its own trace.docs/how-it-works/gateways/configuration.mdxnotes that the collector must be reachable from sandboxes and how to include DEBUG spans.Testing
mise run pre-commitpassesNew tests cover the OTLP span filter directives, egress span levels and parent/child structure, and trace context propagation. Traces were checked manually against a local collector with the Docker driver. The two startup spans at INFO (
boundary.confirm,access.start) have no level test; that would need running supervisor startup under a span-capturing subscriber.Checklist