Skip to content

fix(orchestrator): overwrite envID in sandbox logs too - #2679

Merged
ValentaTomas merged 1 commit into
mainfrom
fix/orchestrator-logs-ndjson
May 16, 2026
Merged

ValentaTomas merged 1 commit into
mainfrom
fix/orchestrator-logs-ndjson

Conversation

@ValentaTomas

@ValentaTomas ValentaTomas commented May 16, 2026 •

Copy link
Copy Markdown
Member

The `/logs` handler already overwrites `instanceID` and `teamID` from the authoritative sandbox map; `envID` was the only identity field still trusted from the envd payload. Take it from `sbx.Runtime.TemplateID` too so envd doesn't need to be trusted for any of them.

Minimal change; the wire format (single-JSON POST) and existing `validatePayloadSandboxID` are unchanged.

@cla-bot cla-bot Bot added the cla-signed label May 16, 2026
@cursor

cursor Bot commented May 16, 2026 •

Copy link
Copy Markdown

PR Summary

Low Risk
Low risk: a small change to log forwarding that only replaces a client-provided identity field with a server-derived value.

Overview
The /logs handler previously trusted envID from the incoming payload, allowing spoofed environment attribution; it now overwrites envID from the sandbox runtime (TemplateID) alongside instanceID and teamID before forwarding logs.

Reviewed by Cursor Bugbot for commit 54d367f. Bugbot is set up for automated code reviews on this repo. Configure here.

@codecov

codecov Bot commented May 16, 2026 •

Copy link
Copy Markdown

❌ 9 Tests Failed:

Tests completed Failed Passed Skipped
2622 9 2613 5
View the full list of 19 ❄️ flaky test(s)
github.com/e2b-dev/infra/tests/integration/internal/tests/api/metrics::TestTeamMetrics

Flake rate in main: 71.12% (Passed 212 times, Failed 522 times)

Stack Traces | 1.41s run time
=== RUN   TestTeamMetrics
=== PAUSE TestTeamMetrics
=== CONT  TestTeamMetrics
    team_metrics_test.go:61: 
        	Error Trace:	.../api/metrics/team_metrics_test.go:61
        	Error:      	Should be true
        	Test:       	TestTeamMetrics
        	Messages:   	MaxConcurrentSandboxes should be >= 0
--- FAIL: TestTeamMetrics (1.41s)
github.com/e2b-dev/infra/tests/integration/internal/tests/api/sandboxes::TestSandboxRapidSnapshotForkChain

Flake rate in main: 55.10% (Passed 207 times, Failed 254 times)

Stack Traces | 85.6s run time
=== RUN   TestSandboxRapidSnapshotForkChain
=== PAUSE TestSandboxRapidSnapshotForkChain
=== CONT  TestSandboxRapidSnapshotForkChain
    sandbox_rapid_pause_resume_test.go:64: 
        	Error Trace:	.../api/sandboxes/snapshot_template_test.go:37
        	            				.../api/sandboxes/sandbox_rapid_pause_resume_test.go:64
        	Error:      	Not equal: 
        	            	expected: 201
        	            	actual  : 500
        	Test:       	TestSandboxRapidSnapshotForkChain
--- FAIL: TestSandboxRapidSnapshotForkChain (85.60s)
github.com/e2b-dev/infra/tests/integration/internal/tests/api/sandboxes::TestUpdateNetworkConfig

Flake rate in main: 76.63% (Passed 222 times, Failed 728 times)

Stack Traces | 34.5s run time
=== RUN   TestUpdateNetworkConfig
=== PAUSE TestUpdateNetworkConfig
=== CONT  TestUpdateNetworkConfig
Executing command curl in sandbox if7gputacnxxr70b7huue
--- FAIL: TestUpdateNetworkConfig (34.48s)
github.com/e2b-dev/infra/tests/integration/internal/tests/api/sandboxes::TestUpdateNetworkConfig/3_replace_allowed_ip

Flake rate in main: 55.10% (Passed 207 times, Failed 254 times)

Stack Traces | 0.18s run time
=== RUN   TestUpdateNetworkConfig/3_replace_allowed_ip
Executing command curl in sandbox idimfpnv1ljawdo10amar
    sandbox_network_update_test.go:328: Command [curl] output: event:{start:{pid:1325}}
    sandbox_network_update_test.go:328: 
        	Error Trace:	.../api/sandboxes/sandbox_network_out_test.go:67
        	            				.../api/sandboxes/sandbox_network_update_test.go:58
        	            				.../api/sandboxes/sandbox_network_update_test.go:328
        	Error:      	Received unexpected error:
        	            	failed to execute command curl in sandbox idimfpnv1ljawdo10amar: invalid_argument: protocol error: incomplete envelope: unexpected EOF
        	Test:       	TestUpdateNetworkConfig/3_replace_allowed_ip
        	Messages:   	https://1.1.1.1 should be reachable
--- FAIL: TestUpdateNetworkConfig/3_replace_allowed_ip (0.18s)
github.com/e2b-dev/infra/tests/integration/internal/tests/api/sandboxes::TestUpdateNetworkConfig/pause_resume_preserves_allow_internet_access_false

Flake rate in main: 77.19% (Passed 213 times, Failed 721 times)

Stack Traces | 1.78s run time
=== RUN   TestUpdateNetworkConfig/pause_resume_preserves_allow_internet_access_false
Executing command curl in sandbox if7gputacnxxr70b7huue
    sandbox_network_update_test.go:372: Command [curl] output: event:{start:{pid:1360}}
    sandbox_network_update_test.go:372: Command [curl] output: event:{end:{exit_code:35 exited:true status:"exit status 35" error:"exit status 35"}}
Executing command curl in sandbox idimfpnv1ljawdo10amar
    sandbox_network_update_test.go:372: Command [curl] output: event:{start:{pid:1361}}
    sandbox_network_update_test.go:372: Command [curl] output: event:{end:{exit_code:35 exited:true status:"exit status 35" error:"exit status 35"}}
Executing command curl in sandbox i9z6ofumjn87cfjtrcnte
    sandbox_network_update_test.go:391: Command [curl] output: event:{start:{pid:1362}}
    sandbox_network_update_test.go:391: Command [curl] output: event:{data:{stdout:"HTTP/2 302 \r\nx-content-type-options: nosniff\r\nlocation: https://dns.google/\r\ndate: Sat, 16 May 2026 08:54:41 GMT\r\ncontent-type: text/html; charset=UTF-8\r\nserver: HTTP server (unknown)\r\ncontent-length: 216\r\nx-xss-protection: 0\r\nx-frame-options: SAMEORIGIN\r\nalt-svc: h3=\":443\"; ma=2592000,h3-29=\":443\"; ma=2592000\r\n\r\n"}}
    sandbox_network_update_test.go:391: Command [curl] output: event:{end:{exited:true status:"exit status 0"}}
    sandbox_network_update_test.go:391: Command [curl] completed successfully in sandbox idimfpnv1ljawdo10amar
    sandbox_network_update_test.go:391: 
        	Error Trace:	.../api/sandboxes/sandbox_network_out_test.go:74
        	            				.../api/sandboxes/sandbox_network_update_test.go:60
        	            				.../api/sandboxes/sandbox_network_update_test.go:391
        	Error:      	An error is expected but got nil.
        	Test:       	TestUpdateNetworkConfig/pause_resume_preserves_allow_internet_access_false
        	Messages:   	https://8.8.8.8 should be blocked
--- FAIL: TestUpdateNetworkConfig/pause_resume_preserves_allow_internet_access_false (1.78s)
github.com/e2b-dev/infra/tests/integration/internal/tests/api/templates::TestTemplateBuildENV

Flake rate in main: 59.66% (Passed 211 times, Failed 312 times)

Stack Traces | 0s run time
=== RUN   TestTemplateBuildENV
=== PAUSE TestTemplateBuildENV
=== CONT  TestTemplateBuildENV
--- FAIL: TestTemplateBuildENV (0.00s)
github.com/e2b-dev/infra/tests/integration/internal/tests/api/templates::TestTemplateBuildENV/ENV_with_multiline_value

Flake rate in main: 60.23% (Passed 204 times, Failed 309 times)

Stack Traces | 23.3s run time
=== RUN   TestTemplateBuildENV/ENV_with_multiline_value
=== PAUSE TestTemplateBuildENV/ENV_with_multiline_value
=== CONT  TestTemplateBuildENV/ENV_with_multiline_value
    build_template_test.go:134: test-ubuntu-env-multiline: [info] Building template 74ewxx9byzehq7f2kghc/646823c8-9572-4595-af86-599ef9ab3995
    build_template_test.go:134: test-ubuntu-env-multiline: [info] CACHED [base] FROM ubuntu:22.04 [ffd709f131f42dfab282de47a91dd2c139e900c1c11fc574b49b517a05ef0a32]
    build_template_test.go:134: test-ubuntu-env-multiline: [info] CACHED [base] DEFAULT USER user [90bdd4afa342293c931373351bf578872dec9179214ba3e8bf9edba311466213]
    build_template_test.go:134: test-ubuntu-env-multiline: [info] [builder 1/2] ENV MULTILINE line1
        line2
        line3 [e93da3f3765f20eb6407c336b9e4e0b9321d994ec5f6cb547743a2a4070eed23]
    build_template_test.go:134: test-ubuntu-env-multiline: [info] [builder 2/2] RUN [[ $(echo "$MULTILINE" | wc -l) -eq 3 ]] || exit 1 [477610d61cdf858776262d3331809539bcbcf16f706aac18515a57337bae1786]
    build_template_test.go:134: test-ubuntu-env-multiline: [error] Build failed: failed to run command '[[ $(echo "$MULTILINE" | wc -l) -eq 3 ]] || exit 1': exit status 1
    build_template_test.go:374: Build failed: {<nil> failed to run command '[[ $(echo "$MULTILINE" | wc -l) -eq 3 ]] || exit 1': exit status 1 0xc000420d10}
--- FAIL: TestTemplateBuildENV/ENV_with_multiline_value (23.33s)
github.com/e2b-dev/infra/tests/integration/internal/tests/envd::TestBindLocalhost

Flake rate in main: 56.26% (Passed 370 times, Failed 476 times)

Stack Traces | 0s run time
=== RUN   TestBindLocalhost
=== PAUSE TestBindLocalhost
=== CONT  TestBindLocalhost
--- FAIL: TestBindLocalhost (0.00s)
github.com/e2b-dev/infra/tests/integration/internal/tests/envd::TestBindLocalhost/bind_0_0_0_0

Flake rate in main: 62.70% (Passed 210 times, Failed 353 times)

Stack Traces | 7.28s run time
=== RUN   TestBindLocalhost/bind_0_0_0_0
=== PAUSE TestBindLocalhost/bind_0_0_0_0
=== CONT  TestBindLocalhost/bind_0_0_0_0
    localhost_bind_test.go:69: Command [python] output: event:{start:{pid:1256}}
Executing command python in sandbox ia8yawkjvnbw4j9ugrwa2
    localhost_bind_test.go:90: 
        	Error Trace:	.../tests/envd/localhost_bind_test.go:90
        	Error:      	Not equal: 
        	            	expected: 200
        	            	actual  : 502
        	Test:       	TestBindLocalhost/bind_0_0_0_0
        	Messages:   	Unexpected status code 502 for bind address 0.0.0.0
--- FAIL: TestBindLocalhost/bind_0_0_0_0 (7.28s)
github.com/e2b-dev/infra/tests/integration/internal/tests/envd::TestBindLocalhost/bind_::1

Flake rate in main: 64.04% (Passed 210 times, Failed 374 times)

Stack Traces | 7.21s run time
=== RUN   TestBindLocalhost/bind_::1
=== PAUSE TestBindLocalhost/bind_::1
=== CONT  TestBindLocalhost/bind_::1
Executing command python in sandbox in5ulpbvb24w0539f51bj
    localhost_bind_test.go:69: Command [python] output: event:{start:{pid:1256}}
    localhost_bind_test.go:90: 
        	Error Trace:	.../tests/envd/localhost_bind_test.go:90
        	Error:      	Not equal: 
        	            	expected: 200
        	            	actual  : 502
        	Test:       	TestBindLocalhost/bind_::1
        	Messages:   	Unexpected status code 502 for bind address ::1
--- FAIL: TestBindLocalhost/bind_::1 (7.21s)
Executing command python in sandbox i53jnd3owpasrt9x999bh
github.com/e2b-dev/infra/tests/integration/internal/tests/envd::TestBindLocalhost/bind_localhost

Flake rate in main: 63.92% (Passed 210 times, Failed 372 times)

Stack Traces | 7.27s run time
=== RUN   TestBindLocalhost/bind_localhost
=== PAUSE TestBindLocalhost/bind_localhost
=== CONT  TestBindLocalhost/bind_localhost
    localhost_bind_test.go:69: Command [python] output: event:{start:{pid:1256}}
Executing command python in sandbox iogv6dmntpg15rcqtvgk5
    localhost_bind_test.go:90: 
        	Error Trace:	.../tests/envd/localhost_bind_test.go:90
        	Error:      	Not equal: 
        	            	expected: 200
        	            	actual  : 502
        	Test:       	TestBindLocalhost/bind_localhost
        	Messages:   	Unexpected status code 502 for bind address localhost
--- FAIL: TestBindLocalhost/bind_localhost (7.27s)
github.com/e2b-dev/infra/tests/integration/internal/tests/envd::TestListDir

Flake rate in main: 53.68% (Passed 264 times, Failed 306 times)

Stack Traces | 1.02s run time
=== RUN   TestListDir
=== PAUSE TestListDir
=== CONT  TestListDir
--- FAIL: TestListDir (1.02s)
Executing command python in sandbox iwct2lk5i4ne8zol80fy0
github.com/e2b-dev/infra/tests/integration/internal/tests/envd::TestListDir/depth_0_lists_only_root_directory

Flake rate in main: 57.58% (Passed 210 times, Failed 285 times)

Stack Traces | 0.02s run time
=== RUN   TestListDir/depth_0_lists_only_root_directory
=== PAUSE TestListDir/depth_0_lists_only_root_directory
=== CONT  TestListDir/depth_0_lists_only_root_directory
    filesystem_test.go:97: 
        	Error Trace:	.../tests/envd/filesystem_test.go:97
        	Error:      	Received unexpected error:
        	            	unavailable: 502 Bad Gateway
        	Test:       	TestListDir/depth_0_lists_only_root_directory
--- FAIL: TestListDir/depth_0_lists_only_root_directory (0.02s)
github.com/e2b-dev/infra/tests/integration/internal/tests/envd::TestListDir/depth_1_lists_root_directory

Flake rate in main: 57.58% (Passed 210 times, Failed 285 times)

Stack Traces | 0.01s run time
=== RUN   TestListDir/depth_1_lists_root_directory
=== PAUSE TestListDir/depth_1_lists_root_directory
=== CONT  TestListDir/depth_1_lists_root_directory
    filesystem_test.go:97: 
        	Error Trace:	.../tests/envd/filesystem_test.go:97
        	Error:      	Received unexpected error:
        	            	unavailable: 502 Bad Gateway
        	Test:       	TestListDir/depth_1_lists_root_directory
--- FAIL: TestListDir/depth_1_lists_root_directory (0.01s)
github.com/e2b-dev/infra/tests/integration/internal/tests/envd::TestListDir/depth_2_lists_first_level_of_subdirectories_(in_this_case_the_root_directory)

Flake rate in main: 57.58% (Passed 210 times, Failed 285 times)

Stack Traces | 0.01s run time
=== RUN   TestListDir/depth_2_lists_first_level_of_subdirectories_(in_this_case_the_root_directory)
=== PAUSE TestListDir/depth_2_lists_first_level_of_subdirectories_(in_this_case_the_root_directory)
=== CONT  TestListDir/depth_2_lists_first_level_of_subdirectories_(in_this_case_the_root_directory)
    filesystem_test.go:97: 
        	Error Trace:	.../tests/envd/filesystem_test.go:97
        	Error:      	Received unexpected error:
        	            	unavailable: 502 Bad Gateway
        	Test:       	TestListDir/depth_2_lists_first_level_of_subdirectories_(in_this_case_the_root_directory)
--- FAIL: TestListDir/depth_2_lists_first_level_of_subdirectories_(in_this_case_the_root_directory) (0.01s)
github.com/e2b-dev/infra/tests/integration/internal/tests/envd::TestListDir/depth_3_lists_all_directories_and_files

Flake rate in main: 57.58% (Passed 210 times, Failed 285 times)

Stack Traces | 0.01s run time
=== RUN   TestListDir/depth_3_lists_all_directories_and_files
=== PAUSE TestListDir/depth_3_lists_all_directories_and_files
=== CONT  TestListDir/depth_3_lists_all_directories_and_files
    filesystem_test.go:97: 
        	Error Trace:	.../tests/envd/filesystem_test.go:97
        	Error:      	Received unexpected error:
        	            	unavailable: 502 Bad Gateway
        	Test:       	TestListDir/depth_3_lists_all_directories_and_files
--- FAIL: TestListDir/depth_3_lists_all_directories_and_files (0.01s)
github.com/e2b-dev/infra/tests/integration/internal/tests/orchestrator::TestSandboxMemoryIntegrity

Flake rate in main: 66.05% (Passed 220 times, Failed 428 times)

Stack Traces | 74.2s run time
=== RUN   TestSandboxMemoryIntegrity
=== PAUSE TestSandboxMemoryIntegrity
=== CONT  TestSandboxMemoryIntegrity
    sandbox_memory_integrity_test.go:26: Build completed successfully
--- FAIL: TestSandboxMemoryIntegrity (74.20s)
github.com/e2b-dev/infra/tests/integration/internal/tests/orchestrator::TestSandboxMemoryIntegrity/tmpfs_hash

Flake rate in main: 66.77% (Passed 210 times, Failed 422 times)

Stack Traces | 30.2s run time
=== RUN   TestSandboxMemoryIntegrity/tmpfs_hash
=== PAUSE TestSandboxMemoryIntegrity/tmpfs_hash
=== CONT  TestSandboxMemoryIntegrity/tmpfs_hash
    sandbox_memory_integrity_test.go:70: Command [bash] output: event:{start:{pid:1258}}
    sandbox_memory_integrity_test.go:70: Command [bash] output: event:{data:{stdout:"Total memory: 985 MB\nUsed memory before tmpfs mount: 183 MB\nFree memory before tmpfs mount: 801 MB\nMemory to use in integrity test (80% of free, min 64MB): 640 MB\n"}}
    sandbox_memory_integrity_test.go:70: Command [bash] output: event:{data:{stderr:"640+0 records in\n640+0 records out\n671088640 bytes (671 MB, 640 MiB) copied, 3.47453 s, 193 MB/s\n\tCommand being timed: \"dd if=/dev/urandom of=/mnt/testfile bs=1M count=640\"\n\tUser time (seconds): 0.00\n\tSystem time (seconds): 3.44\n\tPercent of CPU this job got: 99%\n\tElapsed (wall clock) time (h:mm:ss or m:ss): 0:03.48\n\tAverage shared text size (kbytes): 0\n\tAverage unshared data size (kbytes): 0\n\tAverage stack size (kbytes): 0\n\tAverage total size (kbytes): 0\n\tMaximum resident set size (kbytes): 2640\n\tAverage resident set size (kbytes): 0\n\tMajor (requiring I/O) page faults: 2\n\tMinor (reclaiming a frame) page faults: 344\n\tVoluntary context switches: 3\n\tInvoluntary context switches: 18\n\tSwaps: 0\n\tFile system inputs: 176\n\tFile system outputs: 0\n\tSocket messages sent: 0\n\tSocket messages received: 0\n\tSignals delivered: 0\n\tPage size (bytes): 4096\n\tExit status: 0\n"}}
    sandbox_memory_integrity_test.go:70: Command [bash] output: event:{data:{stdout:"Used memory after tmpfs mount and file fill: 830 MB\n"}}
    sandbox_memory_integrity_test.go:70: Command [bash] output: event:{end:{exited:true status:"exit status 0"}}
    sandbox_memory_integrity_test.go:70: Command [bash] completed successfully in sandbox idi98r3s4zqf9z6sbfdj5
Executing command bash in sandbox idi98r3s4zqf9z6sbfdj5 (user: root)
    sandbox_memory_integrity_test.go:74: Command [bash] output: event:{start:{pid:1275}}
    sandbox_memory_integrity_test.go:74: Command [bash] output: event:{data:{stdout:"5dc143c7740247696aeb6ca4dd3a813c999d49a19c216519a0089f9e2b31a5ee\n"}}
    sandbox_memory_integrity_test.go:74: Command [bash] output: event:{end:{exited:true status:"exit status 0"}}
    sandbox_memory_integrity_test.go:74: Command [bash] completed successfully in sandbox idi98r3s4zqf9z6sbfdj5
Executing command bash in sandbox idi98r3s4zqf9z6sbfdj5 (user: root)
    sandbox_memory_integrity_test.go:99: Command [bash] output: event:{start:{pid:1278}}
    sandbox_memory_integrity_test.go:100: 
        	Error Trace:	.../tests/orchestrator/sandbox_memory_integrity_test.go:100
        	Error:      	Received unexpected error:
        	            	failed to execute command bash in sandbox idi98r3s4zqf9z6sbfdj5: invalid_argument: protocol error: incomplete envelope: unexpected EOF
        	Test:       	TestSandboxMemoryIntegrity/tmpfs_hash
--- FAIL: TestSandboxMemoryIntegrity/tmpfs_hash (30.25s)
github.com/e2b-dev/infra/tests/integration/internal/tests/proxies::TestSandboxWithTrafficAccessTokenAutoResumeViaProxy

Flake rate in main: 55.04% (Passed 214 times, Failed 262 times)

Stack Traces | 20.5s run time
=== RUN   TestSandboxWithTrafficAccessTokenAutoResumeViaProxy
=== PAUSE TestSandboxWithTrafficAccessTokenAutoResumeViaProxy
=== CONT  TestSandboxWithTrafficAccessTokenAutoResumeViaProxy
    traffic_access_token_test.go:263: [Status code: 502] Response body: {"sandboxId":"il7vb32rb26virqv0jf7w","message":"The sandbox is running but port is not open","port":8080,"code":502}
    traffic_access_token_test.go:263: [Status code: 502] Response body: {"sandboxId":"il7vb32rb26virqv0jf7w","message":"The sandbox is running but port is not open","port":8080,"code":502}
    traffic_access_token_test.go:263: [Status code: 502] Response body: {"sandboxId":"il7vb32rb26virqv0jf7w","message":"The sandbox is running but port is not open","port":8080,"code":502}
    traffic_access_token_test.go:292: 
        	Error Trace:	.../tests/proxies/traffic_access_token_test.go:292
        	Error:      	Received unexpected error:
        	            	Get "http://localhost:3002": context deadline exceeded (Client.Timeout exceeded while awaiting headers)
        	Test:       	TestSandboxWithTrafficAccessTokenAutoResumeViaProxy
--- FAIL: TestSandboxWithTrafficAccessTokenAutoResumeViaProxy (20.53s)

To view more test analytics, go to the Test Analytics Dashboard
📋 Got 3 mins? Take this short survey to help us improve Test Analytics.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the log handling logic to support Newline Delimited JSON (NDJSON), allowing the injection of authoritative sandbox, environment, and team identifiers into each log entry. Review feedback identifies a critical risk of a nil-pointer panic when unmarshaling null JSON values and a correctness issue regarding the requirement for trailing newlines in the NDJSON specification.

Comment thread packages/orchestrator/pkg/hyperloopserver/handlers/logs.go Outdated
Comment thread packages/orchestrator/pkg/hyperloopserver/handlers/logs.go Outdated
@ValentaTomas
ValentaTomas force-pushed the fix/orchestrator-logs-ndjson branch from d6a9174 to 125ff0f Compare May 16, 2026 08:12
@ValentaTomas ValentaTomas changed the title fix(orchestrator): handle NDJSON log batches, own all ID injection fix(orchestrator): overwrite envID in sandbox logs too May 16, 2026
@ValentaTomas
ValentaTomas force-pushed the fix/orchestrator-logs-ndjson branch from 125ff0f to 1755c64 Compare May 16, 2026 08:17
@ValentaTomas
ValentaTomas marked this pull request as ready for review May 16, 2026 08:17
@ValentaTomas
ValentaTomas enabled auto-merge (squash) May 16, 2026 08:18
@ValentaTomas
ValentaTomas force-pushed the fix/orchestrator-logs-ndjson branch from 1755c64 to 4cadfe3 Compare May 16, 2026 08:18
The /logs handler already overwrites instanceID and teamID from the
authoritative sandbox map; envID was the only identity field still
trusted from the envd payload. Take it from sbx.Runtime.TemplateID too
so envd doesn't need to be trusted for any of them.
@ValentaTomas
ValentaTomas force-pushed the fix/orchestrator-logs-ndjson branch from 4cadfe3 to 54d367f Compare May 16, 2026 08:19
@ValentaTomas
ValentaTomas merged commit 839ccc7 into main May 16, 2026
94 of 96 checks passed
@ValentaTomas
ValentaTomas deleted the fix/orchestrator-logs-ndjson branch May 16, 2026 09:04
ValentaTomas added a commit that referenced this pull request May 16, 2026
Adds a byte-bounded log queue so the exporter can't grow without bound
when the collector is unreachable.

- 8 MiB total queue cap with drop-oldest whole entries (JSON envelopes
stay intact); 192 KiB per-line ingestion cap under [Loki's 256 KiB
\`max_line_size\`](https://grafana.com/docs/loki/latest/configure/#limits_config)
default.
- MMDS opts swapped via \`atomic.Pointer\` instead of pointer + RWMutex.
- HTTP keepalives disabled on the exporter and the MMDS poll client so a
pause/resume that changes endpoints doesn't reuse half-dead connections.

ID injection and the send loop are unchanged; wire-compatible with the
current orchestrator handler — no deploy-order dependency on #2679.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants