[ACTP] add bootstrap-par-control command to PAR binary - #54870
Conversation
Go Package Import DifferencesBaseline: 296059f
|
|
🎯 Code Coverage (details) 🔗 Commit SHA: e24de5f | Docs | View more details | Give us feedback! |
Files inventory check summaryFile checks results against ancestor 296059ff: Results for datadog-agent_7.84.0~devel.git.448.e24de5f.pipeline.132944334-1_amd64.deb:No change detected Results for datadog-iot-agent_7.84.0~devel.git.448.e24de5f.pipeline.132944334-1_amd64.deb:No change detected |
6c22069 to
cd87d21
Compare
66e117b to
e323571
Compare
Static quality checks✅ Please find below the results from static quality gates Successful checksInfo
23 successful checks with minimal change (< 2 KiB)
|
cd87d21 to
6ba350e
Compare
1a16146 to
6b010be
Compare
6ba350e to
481cfaf
Compare
Regression DetectorRegression Detector ResultsMetrics dashboard Baseline: c45db9e Optimization Goals: ✅ No significant changes detected
|
| perf | experiment | goal | Δ mean % | Δ mean % CI | trials | links |
|---|---|---|---|---|---|---|
| ➖ | dsd_uds_10mb_3k_timestamped_contexts_memory | memory utilization | +0.32 | [+0.11, +0.53] | 1 | Logs |
| ➖ | quality_gate_metrics_logs | memory utilization | +0.17 | [-0.06, +0.40] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_private_action_runner | memory utilization | +0.16 | [+0.04, +0.28] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_security_no_fs_load | memory utilization | +0.14 | [+0.05, +0.23] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_idle | memory utilization | +0.02 | [-0.03, +0.06] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_idle_all_features | memory utilization | -0.04 | [-0.08, -0.00] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_security_mean_fs_load | memory utilization | -0.09 | [-0.12, -0.05] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_security_idle | memory utilization | -0.19 | [-0.24, -0.15] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_logs | % cpu utilization | -0.61 | [-1.48, +0.27] | 1 | Logs bounds checks dashboard |
| ➖ | dsd_uds_10mb_3k_timestamped_contexts_cpu | % cpu utilization | -0.86 | [-1.10, -0.61] | 1 | Logs |
Bounds Checks: ✅ Passed
| perf | experiment | bounds_check_name | replicates_passed | observed_value | links |
|---|---|---|---|---|---|
| ✅ | quality_gate_idle | intake_connections | 10/10 | 4 = 4 | bounds checks dashboard |
| ✅ | quality_gate_idle | memory_usage | 10/10 | 172.06MiB ≤ 178MiB | bounds checks dashboard |
| ✅ | quality_gate_idle | total_bytes_received | 10/10 | 746.33KiB ≤ 819.20KiB | bounds checks dashboard |
| ✅ | quality_gate_idle_all_features | intake_connections | 10/10 | 4 = 4 | bounds checks dashboard |
| ✅ | quality_gate_idle_all_features | memory_usage | 10/10 | 532.37MiB ≤ 538MiB | bounds checks dashboard |
| ✅ | quality_gate_idle_all_features | total_bytes_received | 10/10 | 1.14MiB ≤ 1.25MiB | bounds checks dashboard |
| ✅ | quality_gate_logs | intake_connections | 10/10 | 19 ≤ 40 | bounds checks dashboard |
| ✅ | quality_gate_logs | memory_usage | 10/10 | 213.00MiB ≤ 229MiB | bounds checks dashboard |
| ✅ | quality_gate_logs | missed_bytes | 10/10 | 0B = 0B | bounds checks dashboard |
| ✅ | quality_gate_logs | total_bytes_received | 10/10 | 263.51MiB ≤ 292MiB | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | cpu_usage | 10/10 | 354.15 ≤ 2000 | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | intake_connections | 10/10 | 20 ≤ 40 | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | memory_usage | 10/10 | 405.99MiB ≤ 453MiB | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | missed_bytes | 10/10 | 0B = 0B | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | total_bytes_received | 10/10 | 0.94GiB ≤ 1.04GiB | bounds checks dashboard |
| ✅ | quality_gate_private_action_runner | memory_usage | 10/10 | 71.99MiB ≤ 76MiB | bounds checks dashboard |
| ✅ | quality_gate_security_idle | cpu_usage | 10/10 | 28.69 ≤ 100 | bounds checks dashboard |
| ✅ | quality_gate_security_idle | memory_usage | 10/10 | 326.99MiB ≤ 335MiB | bounds checks dashboard |
| ✅ | quality_gate_security_mean_fs_load | cpu_usage | 10/10 | 62.20 ≤ 200 | bounds checks dashboard |
| ✅ | quality_gate_security_mean_fs_load | memory_usage | 10/10 | 305.35MiB ≤ 314MiB | bounds checks dashboard |
| ✅ | quality_gate_security_no_fs_load | cpu_usage | 10/10 | 22.66 ≤ 100 | bounds checks dashboard |
| ✅ | quality_gate_security_no_fs_load | memory_usage | 10/10 | 310.12MiB ≤ 343MiB | bounds checks dashboard |
Explanation
Confidence level: 90.00%
Effect size tolerance: |Δ mean %| ≥ 5.00%
Performance changes are noted in the perf column of each table:
- ✅ = significantly better comparison variant performance
- ❌ = significantly worse comparison variant performance
- ➖ = no significant change in performance
A regression test is an A/B test of target performance in a repeatable rig, where "performance" is measured as "comparison variant minus baseline variant" for an optimization goal (e.g., ingress throughput). Due to intrinsic variability in measuring that goal, we can only estimate its mean value for each experiment; we report uncertainty in that value as a 90.00% confidence interval denoted "Δ mean % CI".
For each experiment, we decide whether a change in performance is a "regression" -- a change worth investigating further -- if all of the following criteria are true:
-
Its estimated |Δ mean %| ≥ 5.00%, indicating the change is big enough to merit a closer look.
-
Its 90.00% confidence interval "Δ mean % CI" does not contain zero, indicating that if our statistical model is accurate, there is at least a 90.00% chance there is a difference in performance between baseline and comparison variants.
-
Its configuration does not mark it "erratic".
CI Pass/Fail Decision
✅ Passed. All Quality Gates passed.
- quality_gate_idle, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_idle, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_idle, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_security_no_fs_load, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_no_fs_load, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_private_action_runner, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_idle, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_idle, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
- quality_gate_idle_all_features, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_idle_all_features, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_idle_all_features, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check missed_bytes: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_security_mean_fs_load, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_mean_fs_load, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check missed_bytes: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check intake_connections: 10/10 replicas passed. Gate passed.
6b010be to
00a3402
Compare
481cfaf to
9960c56
Compare
00a3402 to
ea55c73
Compare
9c657ce to
50ccce5
Compare
ea55c73 to
690bb57
Compare
50ccce5 to
f7b495c
Compare
690bb57 to
c2aaa60
Compare
f7b495c to
787ec32
Compare
01b23ab to
f821eba
Compare
6e4b0d0 to
29fbee2
Compare
c785c41 to
fb58e03
Compare
29fbee2 to
5d08287
Compare
fb58e03 to
4fdaf12
Compare
5d08287 to
efcffd4
Compare
672b028 to
d6f8b60
Compare
d6f8b60 to
3c1138d
Compare
4673145 to
725764e
Compare
eff670d to
e53fe05
Compare
0075a35 to
f1e6a0d
Compare
b43a153 to
48eda5c
Compare
f1e6a0d to
8bdfbbc
Compare
48eda5c to
9a8d25c
Compare
Make Go the single configuration authority for Private Action Runner split mode. `privateactionrunner bootstrap-par-control` loads the canonical Agent configuration, ensures enrollment, and emits the resolved control-plane configuration as one PAR_CONTROL_CONFIG= prefixed JSON line, so par-control no longer has to independently load or merge Agent configuration. When split mode is disabled the command returns the launch gate and log level and exits successfully, without hostname lookup, identity access, enrollment, or FIPS rejection. When split mode is active it rejects FIPS mode rather than silently consuming FIPS-transformed endpoints; a Gov site is not rejected on its own. OPMS endpoint selection moves to a shared Config.OPMSEndpointURL helper used by both the Go OPMS client and this command, so the Go and Rust runners cannot diverge again, including under the fakeintake test switch. Durations are emitted with explicit _milliseconds units, and the payload is never included in an error because it carries the runner private key and may carry proxy credentials.
What does this PR do?
Adds
privateactionrunner bootstrap-par-control, the commandpar-controlruns atstartup. It makes Go the single configuration authority for split mode:
config.NewAgentParams+core.Bundle(core.WithSecrets())), so precedence, secrets, endpoint selectionand Agent file-path resolution are the same ones the Go executor uses;
persisting otherwise;
PAR_CONTROL_CONFIG=prefixed JSON line on stdout.When split mode is disabled it returns only the launch gate and log level and exits
successfully, without hostname lookup, identity access, enrollment, or the FIPS
check. When split mode is active it rejects FIPS mode rather than silently
consuming FIPS-transformed endpoints; a Gov site is not rejected on its own.
OPMS endpoint selection moves into a shared
Config.OPMSEndpointURLhelper used byboth the Go OPMS client and this command, so the Go and Rust runners cannot diverge
again — including under the fakeintake test switch.
Durations are emitted with explicit
_millisecondsunits. The payload carries therunner private key and may carry proxy credentials, so it is never included in an
error.
This replaces the earlier
ensure-enrollmentcommand with no compatibility alias;the enrollment helper and its tests moved rather than being rewritten. Rust no
longer loads or merges Agent configuration — see #54590.
Motivation
par-control previously loaded and merged Agent configuration itself, in Rust. That
duplicated the Go loader and let the two runners disagree; the OPMS endpoint had
already drifted once. Making Go authoritative removes roughly 1,640 lines of Rust
configuration code and the class of bug that goes with it.
Validation
bazel test //cmd/privateactionrunner/subcommands/bootstrapparcontrol:bootstrapparcontrol_testbazel test //cmd/privateactionrunner/subcommands/rotateidentity:rotateidentity_testdda inv test --targets=./pkg/privateactionrunner/opms,./pkg/privateactionrunner/adapters/configpersisted identity and staging OPMS endpoint, and a UI-triggered
script.testConnectionproduced arunPredefinedScripttask that was verified,executed, and published successfully. The emitted payload never appeared in the
control-plane log.