[ACTP] add bootstrap-par-control command - #54870
Conversation
Go Package Import DifferencesBaseline: cf25466
|
This comment has been minimized.
This comment has been minimized.
Files inventory check summaryFile checks results against ancestor cf25466b: Results for datadog-agent_7.84.0~devel.git.565.9b723a6.pipeline.133819696-1_amd64.deb:No change detected Results for datadog-iot-agent_7.84.0~devel.git.565.9b723a6.pipeline.133819696-1_amd64.deb:No change detected |
6c22069 to
cd87d21
Compare
66e117b to
e323571
Compare
Static quality checks✅ Please find below the results from static quality gates Successful checksInfo
17 successful checks with minimal change (< 2 KiB)
|
cd87d21 to
6ba350e
Compare
1a16146 to
6b010be
Compare
6ba350e to
481cfaf
Compare
Regression DetectorRegression Detector ResultsMetrics dashboard Baseline: cf25466 Optimization Goals: ✅ No significant changes detected
|
| perf | experiment | goal | Δ mean % | Δ mean % CI | trials | links |
|---|---|---|---|---|---|---|
| ➖ | quality_gate_logs | % cpu utilization | +3.09 | [+2.20, +3.98] | 1 | Logs bounds checks dashboard |
| ➖ | dsd_uds_10mb_3k_timestamped_contexts_memory | memory utilization | +0.31 | [+0.10, +0.52] | 1 | Logs |
| ➖ | quality_gate_security_mean_fs_load | memory utilization | +0.27 | [+0.23, +0.31] | 1 | Logs bounds checks dashboard |
| ➖ | dsd_uds_10mb_3k_timestamped_contexts_cpu | % cpu utilization | +0.17 | [-0.07, +0.41] | 1 | Logs |
| ➖ | quality_gate_idle_all_features | memory utilization | +0.08 | [+0.04, +0.11] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_security_no_fs_load | memory utilization | +0.07 | [-0.01, +0.15] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_security_idle | memory utilization | +0.02 | [-0.04, +0.07] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_private_action_runner | memory utilization | -0.30 | [-0.42, -0.18] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_idle | memory utilization | -0.38 | [-0.43, -0.34] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_metrics_logs | memory utilization | -0.41 | [-0.63, -0.18] | 1 | Logs bounds checks dashboard |
Bounds Checks: ✅ Passed
| perf | experiment | bounds_check_name | replicates_passed | observed_value | links |
|---|---|---|---|---|---|
| ✅ | quality_gate_idle | intake_connections | 10/10 | 4 = 4 | bounds checks dashboard |
| ✅ | quality_gate_idle | memory_usage | 10/10 | 172.65MiB ≤ 179MiB | bounds checks dashboard |
| ✅ | quality_gate_idle | total_bytes_received | 10/10 | 745.41KiB ≤ 819.20KiB | bounds checks dashboard |
| ✅ | quality_gate_idle_all_features | intake_connections | 10/10 | 4 = 4 | bounds checks dashboard |
| ✅ | quality_gate_idle_all_features | memory_usage | 10/10 | 514.16MiB ≤ 537MiB | bounds checks dashboard |
| ✅ | quality_gate_idle_all_features | total_bytes_received | 10/10 | 1.14MiB ≤ 1.25MiB | bounds checks dashboard |
| ✅ | quality_gate_logs | intake_connections | 10/10 | 18 ≤ 40 | bounds checks dashboard |
| ✅ | quality_gate_logs | memory_usage | 10/10 | 213.49MiB ≤ 220MiB | bounds checks dashboard |
| ✅ | quality_gate_logs | missed_bytes | 10/10 | 0B = 0B | bounds checks dashboard |
| ✅ | quality_gate_logs | total_bytes_received | 10/10 | 263.54MiB ≤ 292MiB | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | cpu_usage | 10/10 | 373.68 ≤ 2000 | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | intake_connections | 10/10 | 20 ≤ 40 | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | memory_usage | 10/10 | 415.04MiB ≤ 455MiB | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | missed_bytes | 10/10 | 0B = 0B | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | total_bytes_received | 10/10 | 0.94GiB ≤ 1.04GiB | bounds checks dashboard |
| ✅ | quality_gate_private_action_runner | memory_usage | 10/10 | 73.11MiB ≤ 75MiB | bounds checks dashboard |
| ✅ | quality_gate_security_idle | cpu_usage | 10/10 | 29.71 ≤ 100 | bounds checks dashboard |
| ✅ | quality_gate_security_idle | memory_usage | 10/10 | 325.78MiB ≤ 355MiB | bounds checks dashboard |
| ✅ | quality_gate_security_mean_fs_load | cpu_usage | 10/10 | 62.60 ≤ 200 | bounds checks dashboard |
| ✅ | quality_gate_security_mean_fs_load | memory_usage | 10/10 | 302.22MiB ≤ 335MiB | bounds checks dashboard |
| ✅ | quality_gate_security_no_fs_load | cpu_usage | 10/10 | 22.09 ≤ 100 | bounds checks dashboard |
| ✅ | quality_gate_security_no_fs_load | memory_usage | 10/10 | 307.35MiB ≤ 345MiB | bounds checks dashboard |
Explanation
Confidence level: 90.00%
Effect size tolerance: |Δ mean %| ≥ 5.00%
Performance changes are noted in the perf column of each table:
- ✅ = significantly better comparison variant performance
- ❌ = significantly worse comparison variant performance
- ➖ = no significant change in performance
A regression test is an A/B test of target performance in a repeatable rig, where "performance" is measured as "comparison variant minus baseline variant" for an optimization goal (e.g., ingress throughput). Due to intrinsic variability in measuring that goal, we can only estimate its mean value for each experiment; we report uncertainty in that value as a 90.00% confidence interval denoted "Δ mean % CI".
For each experiment, we decide whether a change in performance is a "regression" -- a change worth investigating further -- if all of the following criteria are true:
-
Its estimated |Δ mean %| ≥ 5.00%, indicating the change is big enough to merit a closer look.
-
Its 90.00% confidence interval "Δ mean % CI" does not contain zero, indicating that if our statistical model is accurate, there is at least a 90.00% chance there is a difference in performance between baseline and comparison variants.
-
Its configuration does not mark it "erratic".
CI Pass/Fail Decision
✅ Passed. All Quality Gates passed.
- quality_gate_security_no_fs_load, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_no_fs_load, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_idle, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_idle, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_idle, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check missed_bytes: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_idle_all_features, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_idle_all_features, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_idle_all_features, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_security_idle, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_idle, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_private_action_runner, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_mean_fs_load, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_mean_fs_load, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check missed_bytes: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
6b010be to
00a3402
Compare
481cfaf to
9960c56
Compare
00a3402 to
ea55c73
Compare
9c657ce to
50ccce5
Compare
ea55c73 to
690bb57
Compare
50ccce5 to
f7b495c
Compare
690bb57 to
c2aaa60
Compare
f7b495c to
787ec32
Compare
01b23ab to
f821eba
Compare
6e4b0d0 to
29fbee2
Compare
c785c41 to
fb58e03
Compare
29fbee2 to
5d08287
Compare
fb58e03 to
4fdaf12
Compare
5d08287 to
efcffd4
Compare
672b028 to
d6f8b60
Compare
d6f8b60 to
3c1138d
Compare
4673145 to
725764e
Compare
eff670d to
e53fe05
Compare
0075a35 to
f1e6a0d
Compare
b43a153 to
48eda5c
Compare
f1e6a0d to
8bdfbbc
Compare
48eda5c to
9a8d25c
Compare
Make Go the single configuration authority for Private Action Runner split mode. `privateactionrunner bootstrap-par-control` loads the canonical Agent configuration, ensures enrollment, and emits the resolved control-plane configuration as one PAR_CONTROL_CONFIG= prefixed JSON line, so par-control no longer has to independently load or merge Agent configuration. When split mode is disabled the command returns the launch gate and log level and exits successfully, without hostname lookup, identity access, enrollment, or FIPS rejection. When split mode is active it rejects FIPS mode rather than silently consuming FIPS-transformed endpoints; a Gov site is not rejected on its own. OPMS endpoint selection moves to a shared Config.OPMSEndpointURL helper used by both the Go OPMS client and this command, so the Go and Rust runners cannot diverge again, including under the fakeintake test switch. Durations are emitted with explicit _milliseconds units, and the payload is never included in an error because it carries the runner private key and may carry proxy credentials.
What does this PR do?
Adds
privateactionrunner bootstrap-par-control, making Go the configuration and identity authority for split mode.The command loads canonical Agent configuration and secrets, ensures enrollment, derives the PAR runtime configuration, and emits one
PAR_CONTROL_CONFIG=JSON line forpar-control. Split mode rejects FIPS, and OPMS endpoint selection is shared with the Go runner.The payload can contain private keys and proxy credentials, so it is never logged or included in errors.
Validation
Stack base: #55401. Followed by #54590.