Repository navigation
fix(traces): receive OTLP on local Docker bridges - #488
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Docker bridge containers cannot send OTLP to an ordinary host Edge because its traces receiver only listens on loopback, despite the UI describing Docker bridge support. Keep the loopback receivers and add listeners on the IPv4/IPv6 addresses of every local Docker bridge, discovered through the local Docker Unix socket during the existing supervisor reconcile cycle.
Preflight each newly added listener and skip only occupied address/protocol pairs, retaining localhost and other working listeners. Preserve endpoints already owned by the running Collector. If a port is taken after the probe and startup fails, restore the base receivers and retry available bridges on the next reconcile.
Explicit
grpc_endpointandhttp_endpointsettings override discovery for their respective protocols. Kubernetes gateways and OBI collectors keep their existing configuration. Update the UI text, runbook, and APM ADR to describe the implemented behavior.Validation
Passed regression tests for per-protocol conflict filtering, preserving active listeners, clearing stale ownership after crashes, and retrying released ports.
Passed real Collector 0.157.0 tests in an isolated Linux container for ports occupied before discovery and a deterministic port takeover after probing. Localhost accepted empty OTLP HTTP requests for traces, metrics, and logs after fallback; bridge ingestion recovered after releasing the port.
Passed affected-package race tests:
go test -race ./internal/edgeagent/plugins/traces ./internal/edgeagent/plugins ./internal/edgeagent/plugins/autoapm.Passed Linux ARM64 traces and
cmd/ongrid-edgetest binaries in Linux containers; passed the Linux AMD64 Edge build.Passed configuration validation with OTel Collector Contrib 0.157.0, including multiple bridge receivers, IPv6, and traces/logs/metrics pipelines.
Passed isolated live Linux tests: OTLP gRPC and HTTP requests from localhost, a default bridge container, and custom bridge containers over IPv4 and IPv6. A non-bridge host address refused the connection. Test containers and the temporary bridge were removed.
Passed all six
EdgeDetailtests,npm run build, changed-file ESLint, andgit diff --check.Full
go test -p 2 ./...on macOS fails on existing Linux-only build constraints incmd/ongrid-edgeandinternal/manager/biz/aiops/tools, plus the unchangedupgrademachinedestination case-variant test on this filesystem. Linux CI provides the full supported-platform gate.Full frontend lint reports existing errors in unchanged files (
chat.ts,packetCaptures.ts,MessageBubble.tsx, andSkillRun.tsx).make arch-lintcould not run becausego-arch-lintis not installed. Browser screenshots were not run for this text-only UI update.Risk and rollback
This intentionally allows OTLP ingestion on local Docker bridge addresses. Bridge binding provides no source authentication; hosts with untrusted containers or routed bridge access should restrict traffic with a firewall. Docker socket access uses existing permissions and is not granted automatically. Missing Docker or discovery errors retain loopback defaults, with errors logged; there is no automatic wildcard fallback.
Occupied bridge endpoints are logged and skipped per protocol, then retried on the normal reconcile cycle. A startup race can briefly interrupt ingestion while the Collector falls back to its base receivers (loopback by default, with explicit endpoints preserved).
Bridge address changes are picked up on the normal reconcile cycle (typically within 60 seconds) and can briefly interrupt ingestion while the Collector restarts. The discovery path applies only to ordinary Linux hosts, not Docker Desktop host bridges. No dependencies or database schema changes are included.
To restore loopback-only behavior, explicitly set both
grpc_endpoint: 127.0.0.1:4317andhttp_endpoint: 127.0.0.1:4318, or revert this commit and roll back the Edge binary.Author confirmation