Skip to content

fix(traces): receive OTLP on local Docker bridges - #488

Merged
youzi-1122 merged 2 commits into
mainfrom
fix/traces-docker-bridge-listeners
Oct 9, 2026
Merged

youzi-1122 merged 2 commits into
mainfrom
fix/traces-docker-bridge-listeners

Conversation

@youzi-1122

@youzi-1122 youzi-1122 commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Summary

Docker bridge containers cannot send OTLP to an ordinary host Edge because its traces receiver only listens on loopback, despite the UI describing Docker bridge support. Keep the loopback receivers and add listeners on the IPv4/IPv6 addresses of every local Docker bridge, discovered through the local Docker Unix socket during the existing supervisor reconcile cycle.

Preflight each newly added listener and skip only occupied address/protocol pairs, retaining localhost and other working listeners. Preserve endpoints already owned by the running Collector. If a port is taken after the probe and startup fails, restore the base receivers and retry available bridges on the next reconcile.

Explicit grpc_endpoint and http_endpoint settings override discovery for their respective protocols. Kubernetes gateways and OBI collectors keep their existing configuration. Update the UI text, runbook, and APM ADR to describe the implemented behavior.

Validation

  • Passed regression tests for per-protocol conflict filtering, preserving active listeners, clearing stale ownership after crashes, and retrying released ports.

  • Passed real Collector 0.157.0 tests in an isolated Linux container for ports occupied before discovery and a deterministic port takeover after probing. Localhost accepted empty OTLP HTTP requests for traces, metrics, and logs after fallback; bridge ingestion recovered after releasing the port.

  • Passed affected-package race tests: go test -race ./internal/edgeagent/plugins/traces ./internal/edgeagent/plugins ./internal/edgeagent/plugins/autoapm.

  • Passed Linux ARM64 traces and cmd/ongrid-edge test binaries in Linux containers; passed the Linux AMD64 Edge build.

  • Passed configuration validation with OTel Collector Contrib 0.157.0, including multiple bridge receivers, IPv6, and traces/logs/metrics pipelines.

  • Passed isolated live Linux tests: OTLP gRPC and HTTP requests from localhost, a default bridge container, and custom bridge containers over IPv4 and IPv6. A non-bridge host address refused the connection. Test containers and the temporary bridge were removed.

  • Passed all six EdgeDetail tests, npm run build, changed-file ESLint, and git diff --check.

  • Full go test -p 2 ./... on macOS fails on existing Linux-only build constraints in cmd/ongrid-edge and internal/manager/biz/aiops/tools, plus the unchanged upgrademachine destination case-variant test on this filesystem. Linux CI provides the full supported-platform gate.

  • Full frontend lint reports existing errors in unchanged files (chat.ts, packetCaptures.ts, MessageBubble.tsx, and SkillRun.tsx). make arch-lint could not run because go-arch-lint is not installed. Browser screenshots were not run for this text-only UI update.

Risk and rollback

This intentionally allows OTLP ingestion on local Docker bridge addresses. Bridge binding provides no source authentication; hosts with untrusted containers or routed bridge access should restrict traffic with a firewall. Docker socket access uses existing permissions and is not granted automatically. Missing Docker or discovery errors retain loopback defaults, with errors logged; there is no automatic wildcard fallback.

Occupied bridge endpoints are logged and skipped per protocol, then retried on the normal reconcile cycle. A startup race can briefly interrupt ingestion while the Collector falls back to its base receivers (loopback by default, with explicit endpoints preserved).

Bridge address changes are picked up on the normal reconcile cycle (typically within 60 seconds) and can briefly interrupt ingestion while the Collector restarts. The discovery path applies only to ordinary Linux hosts, not Docker Desktop host bridges. No dependencies or database schema changes are included.

To restore loopback-only behavior, explicitly set both grpc_endpoint: 127.0.0.1:4317 and http_endpoint: 127.0.0.1:4318, or revert this commit and roll back the Edge binary.

Author confirmation

@youzi-1122
youzi-1122 requested a review from singchia as a code owner October 9, 2026 09:31
@youzi-1122
youzi-1122 merged commit 97d4274 into main Oct 9, 2026
12 checks passed
@youzi-1122
youzi-1122 deleted the fix/traces-docker-bridge-listeners branch October 9, 2026 10:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant