[ACTP] add ensure-enrollment command to PAR binary - #54870
Conversation
Go Package Import DifferencesBaseline: d473f2a
|
|
🎯 Code Coverage (details) 🔗 Commit SHA: c1e1143 | Docs | View more details | Give us feedback! |
Files inventory check summaryFile checks results against ancestor d473f2ae: Results for datadog-agent_7.84.0~devel.git.286.c1e1143.pipeline.131727366-1_amd64.deb:No change detected Results for datadog-iot-agent_7.84.0~devel.git.286.c1e1143.pipeline.131727366-1_amd64.deb:No change detected |
6c22069 to
cd87d21
Compare
66e117b to
e323571
Compare
Static quality checks✅ Please find below the results from static quality gates Successful checksInfo
17 successful checks with minimal change (< 2 KiB)
|
cd87d21 to
6ba350e
Compare
1a16146 to
6b010be
Compare
6ba350e to
481cfaf
Compare
Regression DetectorRegression Detector ResultsMetrics dashboard Baseline: 83ec016 Optimization Goals: ✅ No significant changes detected
|
| perf | experiment | goal | Δ mean % | Δ mean % CI | trials | links |
|---|---|---|---|---|---|---|
| ➖ | quality_gate_private_action_runner | memory utilization | +0.70 | [+0.57, +0.82] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_metrics_logs | memory utilization | +0.31 | [+0.08, +0.55] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_security_idle | memory utilization | +0.21 | [+0.16, +0.26] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_security_no_fs_load | memory utilization | +0.13 | [+0.04, +0.21] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_security_mean_fs_load | memory utilization | +0.09 | [+0.06, +0.13] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_idle | memory utilization | -0.18 | [-0.22, -0.14] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_idle_all_features | memory utilization | -0.31 | [-0.34, -0.27] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_logs | % cpu utilization | -4.66 | [-5.51, -3.80] | 1 | Logs bounds checks dashboard |
Bounds Checks: ✅ Passed
| perf | experiment | bounds_check_name | replicates_passed | observed_value | links |
|---|---|---|---|---|---|
| ✅ | quality_gate_idle | intake_connections | 10/10 | 4 = 4 | bounds checks dashboard |
| ✅ | quality_gate_idle | memory_usage | 10/10 | 172.98MiB ≤ 178MiB | bounds checks dashboard |
| ✅ | quality_gate_idle | total_bytes_received | 10/10 | 746.60KiB ≤ 819.20KiB | bounds checks dashboard |
| ✅ | quality_gate_idle_all_features | intake_connections | 10/10 | 4 = 4 | bounds checks dashboard |
| ✅ | quality_gate_idle_all_features | memory_usage | 10/10 | 515.90MiB ≤ 538MiB | bounds checks dashboard |
| ✅ | quality_gate_idle_all_features | total_bytes_received | 10/10 | 1.15MiB ≤ 1.25MiB | bounds checks dashboard |
| ✅ | quality_gate_logs | intake_connections | 10/10 | 16 ≤ 40 | bounds checks dashboard |
| ✅ | quality_gate_logs | memory_usage | 10/10 | 211.39MiB ≤ 229MiB | bounds checks dashboard |
| ✅ | quality_gate_logs | missed_bytes | 10/10 | 0B = 0B | bounds checks dashboard |
| ✅ | quality_gate_logs | total_bytes_received | 10/10 | 263.43MiB ≤ 292MiB | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | cpu_usage | 10/10 | 427.77 ≤ 2000 | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | intake_connections | 10/10 | 20 ≤ 40 | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | memory_usage | 10/10 | 427.59MiB ≤ 439MiB | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | missed_bytes | 10/10 | 0B = 0B | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | total_bytes_received | 10/10 | 0.94GiB ≤ 1.04GiB | bounds checks dashboard |
| ✅ | quality_gate_private_action_runner | memory_usage | 10/10 | 71.80MiB ≤ 76MiB | bounds checks dashboard |
| ✅ | quality_gate_security_idle | cpu_usage | 10/10 | 34.06 ≤ 100 | bounds checks dashboard |
| ✅ | quality_gate_security_idle | memory_usage | 10/10 | 328.24MiB ≤ 335MiB | bounds checks dashboard |
| ✅ | quality_gate_security_mean_fs_load | cpu_usage | 10/10 | 62.02 ≤ 200 | bounds checks dashboard |
| ✅ | quality_gate_security_mean_fs_load | memory_usage | 10/10 | 301.72MiB ≤ 314MiB | bounds checks dashboard |
| ✅ | quality_gate_security_no_fs_load | cpu_usage | 10/10 | 24.67 ≤ 100 | bounds checks dashboard |
| ✅ | quality_gate_security_no_fs_load | memory_usage | 10/10 | 313.35MiB ≤ 343MiB | bounds checks dashboard |
Explanation
Confidence level: 90.00%
Effect size tolerance: |Δ mean %| ≥ 5.00%
Performance changes are noted in the perf column of each table:
- ✅ = significantly better comparison variant performance
- ❌ = significantly worse comparison variant performance
- ➖ = no significant change in performance
A regression test is an A/B test of target performance in a repeatable rig, where "performance" is measured as "comparison variant minus baseline variant" for an optimization goal (e.g., ingress throughput). Due to intrinsic variability in measuring that goal, we can only estimate its mean value for each experiment; we report uncertainty in that value as a 90.00% confidence interval denoted "Δ mean % CI".
For each experiment, we decide whether a change in performance is a "regression" -- a change worth investigating further -- if all of the following criteria are true:
-
Its estimated |Δ mean %| ≥ 5.00%, indicating the change is big enough to merit a closer look.
-
Its 90.00% confidence interval "Δ mean % CI" does not contain zero, indicating that if our statistical model is accurate, there is at least a 90.00% chance there is a difference in performance between baseline and comparison variants.
-
Its configuration does not mark it "erratic".
CI Pass/Fail Decision
✅ Passed. All Quality Gates passed.
- quality_gate_metrics_logs, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check missed_bytes: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_idle, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_idle, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_idle, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check missed_bytes: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_private_action_runner, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_idle_all_features, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_idle_all_features, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_idle_all_features, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_mean_fs_load, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_mean_fs_load, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_idle, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_idle, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_no_fs_load, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_no_fs_load, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
6b010be to
00a3402
Compare
481cfaf to
9960c56
Compare
00a3402 to
ea55c73
Compare
9c657ce to
50ccce5
Compare
ea55c73 to
690bb57
Compare
50ccce5 to
f7b495c
Compare
690bb57 to
c2aaa60
Compare
f7b495c to
787ec32
Compare
01b23ab to
f821eba
Compare
d34ebc0 to
606784f
Compare
e0cd96c to
6e4b0d0
Compare
606784f to
85b0ed7
Compare
6e4b0d0 to
29fbee2
Compare
c785c41 to
fb58e03
Compare
29fbee2 to
5d08287
Compare
fb58e03 to
4fdaf12
Compare
5d08287 to
efcffd4
Compare
672b028 to
d6f8b60
Compare
d6f8b60 to
3c1138d
Compare
The recordingLogger fake implemented the whole log.Component surface for a single test whose only exercised log line is a constant string, so it could not detect a private-key leak. Key redaction is still covered by the invalid configured private key case, which asserts the error does not echo the key.
A truncated or malformed identity file could keep ensure-enrollment failing until it was deleted by hand, since persistIdentityToFile writes in place and a crash mid-write leaves partial JSON behind. Content-level damage is now marked with ErrIdentityCorrupt and treated as unusable: ensure-enrollment warns, discards it, and continues to the configured identity or self-enrollment, removing the file when a configured identity takes over so par-control cannot pick it up again. I/O and K8s secret failures still abort, because they may be transient and re-enrolling would register a second runner for the same host.
getRunnerConfig hard-failed on any GetIdentityFromPreviousEnrollment error, so the monolithic runner stayed wedged on a corrupt identity file while split mode recovered from it. Treat ErrIdentityCorrupt as an absent identity there too, and keep aborting on I/O failures.
3c1138d to
c1e1143
Compare
What does this PR do?
Adds
privateactionrunner ensure-enrollment, a CLI command that will be used whenpar-controlstarts. It:It also shares enrollment-and-persistence logic with
rotate-identity.This was done to reuse enrollment Go code without reimplementing it in Rust.
Validation
bazel test //cmd/privateactionrunner/subcommands/ensureenrollment:ensureenrollment_testbazel test //cmd/privateactionrunner/subcommands/rotateidentity:rotateidentity_test