Add a lightweight gate for prepared Agent rollouts - #54832
Conversation
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3f10665ecd
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| t.Setenv(activePathEnv, filepath.Join(dir, "trace-agent.active")) | ||
| t.Setenv(podUIDEnv, "pod-uid") | ||
|
|
||
| opts, err := parseOptions([]string{"--component", "trace-agent", "--wait-file", "/etc/datadog-agent/auth/token", "--", "trace-agent", "--config", "/etc/datadog-agent/datadog.yaml"}, io.Discard) |
There was a problem hiding this comment.
Make parse test portable on Windows
When this test target is run on Windows, main_test.go is still included because it has no Linux build tag, but this case passes a Unix-style wait-file path into parseOptions; parseOptions checks filepath.IsAbs, which rejects /etc/datadog-agent/auth/token on Windows, so the new test target fails before it reaches the unsupported-platform stubs. Use a path derived from t.TempDir() or mark the test Linux-only.
AGENTS.md reference: AGENTS.md:L177-L178
Useful? React with 👍 / 👎.
| # Copy the built OTel agent from the builder stage | ||
| COPY --from=builder /workspace/datadog-agent/bin/otel-agent/otel-agent /opt/datadog-agent/embedded/bin/otel-agent | ||
| COPY --from=builder /workspace/datadog-agent/bin/otel-agent/dist/otel-config.yaml /etc/datadog-agent/otel-config.yaml | ||
| COPY agent-rollout-gate /opt/datadog-agent/embedded/bin/agent-rollout-gate |
There was a problem hiding this comment.
Build the gate in the OTel Docker self-build path
The GitLab OTel image jobs add agent-rollout-gate to BUILD_CONTEXT, but the Dockerfile also has a self-build path where the builder clones the repo and only runs invoke otel-agent.build; in that path there is no build-context file named agent-rollout-gate, so this release-stage COPY fails before producing the standalone image. Build the gate in the builder stage and copy it from there, or make this copy conditional on the CI-prepared context.
Useful? React with 👍 / 👎.
Gitlab CI Configuration Changes
|
| Removed | Modified | Added | Renamed |
|---|---|---|---|
| 0 | 11 | 0 | 0 |
ℹ️ Diff available in the job log.
This comment has been minimized.
This comment has been minimized.
Files inventory check summaryFile checks results against ancestor 99f14942: Results for datadog-agent_7.84.0~devel.git.426.5eb946f.pipeline.132756131-1_amd64.deb:No change detected Results for datadog-iot-agent_7.84.0~devel.git.426.5eb946f.pipeline.132756131-1_amd64.deb:No change detected |
Regression DetectorRegression Detector ResultsMetrics dashboard Baseline: 99f1494 Optimization Goals: ✅ No significant changes detected
|
| perf | experiment | goal | Δ mean % | Δ mean % CI | trials | links |
|---|---|---|---|---|---|---|
| ➖ | quality_gate_idle_all_features | memory utilization | +0.54 | [+0.50, +0.58] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_metrics_logs | memory utilization | +0.50 | [+0.27, +0.72] | 1 | Logs bounds checks dashboard |
| ➖ | dsd_uds_10mb_3k_timestamped_contexts_cpu | % cpu utilization | +0.35 | [+0.10, +0.60] | 1 | Logs |
| ➖ | quality_gate_security_no_fs_load | memory utilization | +0.33 | [+0.24, +0.42] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_private_action_runner | memory utilization | +0.11 | [-0.01, +0.23] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_idle | memory utilization | +0.11 | [+0.06, +0.15] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_security_mean_fs_load | memory utilization | -0.02 | [-0.06, +0.01] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_security_idle | memory utilization | -0.25 | [-0.29, -0.20] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_logs | % cpu utilization | -0.59 | [-1.44, +0.27] | 1 | Logs bounds checks dashboard |
| ➖ | dsd_uds_10mb_3k_timestamped_contexts_memory | memory utilization | -0.77 | [-0.98, -0.56] | 1 | Logs |
Bounds Checks: ✅ Passed
| perf | experiment | bounds_check_name | replicates_passed | observed_value | links |
|---|---|---|---|---|---|
| ✅ | quality_gate_idle | intake_connections | 10/10 | 4 = 4 | bounds checks dashboard |
| ✅ | quality_gate_idle | memory_usage | 10/10 | 172.46MiB ≤ 178MiB | bounds checks dashboard |
| ✅ | quality_gate_idle | total_bytes_received | 10/10 | 747.54KiB ≤ 819.20KiB | bounds checks dashboard |
| ✅ | quality_gate_idle_all_features | intake_connections | 10/10 | 4 = 4 | bounds checks dashboard |
| ✅ | quality_gate_idle_all_features | memory_usage | 10/10 | 515.09MiB ≤ 538MiB | bounds checks dashboard |
| ✅ | quality_gate_idle_all_features | total_bytes_received | 10/10 | 1.14MiB ≤ 1.25MiB | bounds checks dashboard |
| ✅ | quality_gate_logs | intake_connections | 10/10 | 18 ≤ 40 | bounds checks dashboard |
| ✅ | quality_gate_logs | memory_usage | 10/10 | 210.99MiB ≤ 229MiB | bounds checks dashboard |
| ✅ | quality_gate_logs | missed_bytes | 10/10 | 0B = 0B | bounds checks dashboard |
| ✅ | quality_gate_logs | total_bytes_received | 10/10 | 263.37MiB ≤ 292MiB | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | cpu_usage | 10/10 | 358.24 ≤ 2000 | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | intake_connections | 10/10 | 20 ≤ 40 | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | memory_usage | 10/10 | 421.17MiB ≤ 453MiB | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | missed_bytes | 10/10 | 0B = 0B | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | total_bytes_received | 10/10 | 0.94GiB ≤ 1.04GiB | bounds checks dashboard |
| ✅ | quality_gate_private_action_runner | memory_usage | 10/10 | 72.45MiB ≤ 76MiB | bounds checks dashboard |
| ✅ | quality_gate_security_idle | cpu_usage | 10/10 | 29.05 ≤ 100 | bounds checks dashboard |
| ✅ | quality_gate_security_idle | memory_usage | 10/10 | 328.95MiB ≤ 335MiB | bounds checks dashboard |
| ✅ | quality_gate_security_mean_fs_load | cpu_usage | 10/10 | 58.07 ≤ 200 | bounds checks dashboard |
| ✅ | quality_gate_security_mean_fs_load | memory_usage | 10/10 | 298.69MiB ≤ 314MiB | bounds checks dashboard |
| ✅ | quality_gate_security_no_fs_load | cpu_usage | 10/10 | 22.09 ≤ 100 | bounds checks dashboard |
| ✅ | quality_gate_security_no_fs_load | memory_usage | 10/10 | 314.77MiB ≤ 343MiB | bounds checks dashboard |
Explanation
Confidence level: 90.00%
Effect size tolerance: |Δ mean %| ≥ 5.00%
Performance changes are noted in the perf column of each table:
- ✅ = significantly better comparison variant performance
- ❌ = significantly worse comparison variant performance
- ➖ = no significant change in performance
A regression test is an A/B test of target performance in a repeatable rig, where "performance" is measured as "comparison variant minus baseline variant" for an optimization goal (e.g., ingress throughput). Due to intrinsic variability in measuring that goal, we can only estimate its mean value for each experiment; we report uncertainty in that value as a 90.00% confidence interval denoted "Δ mean % CI".
For each experiment, we decide whether a change in performance is a "regression" -- a change worth investigating further -- if all of the following criteria are true:
-
Its estimated |Δ mean %| ≥ 5.00%, indicating the change is big enough to merit a closer look.
-
Its 90.00% confidence interval "Δ mean % CI" does not contain zero, indicating that if our statistical model is accurate, there is at least a 90.00% chance there is a difference in performance between baseline and comparison variants.
-
Its configuration does not mark it "erratic".
CI Pass/Fail Decision
✅ Passed. All Quality Gates passed.
- quality_gate_private_action_runner, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check missed_bytes: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_security_no_fs_load, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_no_fs_load, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_mean_fs_load, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_mean_fs_load, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check missed_bytes: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_idle, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_idle, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
- quality_gate_idle_all_features, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_idle_all_features, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_idle_all_features, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_idle, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_idle, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_idle, bounds check memory_usage: 10/10 replicas passed. Gate passed.
… ali.b/prepared-agent-surge
Static quality checks❌ Please find below the results from static quality gates Error
Gate failure full details
Static quality gate failures prevent this PR from merging! Successful checksInfo
16 successful checks with minimal change (< 2 KiB)
|
Why
A DaemonSet update can delete a working Agent before Kubernetes pulls and starts its replacement. A slow or failed pull can therefore leave a node without an Agent.
What does this PR do?
This PR adds an experimental Linux
agent-rollout-gatebinary to the node Agent images.The Operator starts this binary before each Agent component. The gate waits for a component-specific host lock before it starts the real process. Kubernetes can therefore pull and create a replacement Pod while the old Agent still serves. Each component changes ownership independently, so a slow
system-probeshutdown does not block the core Agent or trace Agent.The gate keeps the startup probe unsuccessful while it waits. After it gets the lock, the gate starts the Agent and forwards the original health check. An unhealthy process releases its lock after the original startup failure budget. Failure-state I/O also fails safe by terminating the active process.
The waiting gate exits on Pod termination. FIPS packages build it with the required system-crypto CGO mode; other packages keep the static build.
This mechanism does not transfer Agent queues, caches, Cluster Agent assignments, metadata, or process state.
Validation
Experimental-cluster validation starts after the three PoC PRs are reviewed.
Related PRs
Deploy the gate-capable Agent image with the ordinary rollout before you enable prepared mode.