fix(orchestrator): overwrite envID in sandbox logs too - #2679
Conversation
PR SummaryLow Risk Overview Reviewed by Cursor Bugbot for commit 54d367f. Bugbot is set up for automated code reviews on this repo. Configure here. |
❌ 9 Tests Failed:
View the full list of 19 ❄️ flaky test(s)
To view more test analytics, go to the Test Analytics Dashboard |
There was a problem hiding this comment.
Code Review
This pull request updates the log handling logic to support Newline Delimited JSON (NDJSON), allowing the injection of authoritative sandbox, environment, and team identifiers into each log entry. Review feedback identifies a critical risk of a nil-pointer panic when unmarshaling null JSON values and a correctness issue regarding the requirement for trailing newlines in the NDJSON specification.
d6a9174 to
125ff0f
Compare
125ff0f to
1755c64
Compare
1755c64 to
4cadfe3
Compare
The /logs handler already overwrites instanceID and teamID from the authoritative sandbox map; envID was the only identity field still trusted from the envd payload. Take it from sbx.Runtime.TemplateID too so envd doesn't need to be trusted for any of them.
4cadfe3 to
54d367f
Compare
Adds a byte-bounded log queue so the exporter can't grow without bound when the collector is unreachable. - 8 MiB total queue cap with drop-oldest whole entries (JSON envelopes stay intact); 192 KiB per-line ingestion cap under [Loki's 256 KiB \`max_line_size\`](https://grafana.com/docs/loki/latest/configure/#limits_config) default. - MMDS opts swapped via \`atomic.Pointer\` instead of pointer + RWMutex. - HTTP keepalives disabled on the exporter and the MMDS poll client so a pause/resume that changes endpoints doesn't reuse half-dead connections. ID injection and the send loop are unchanged; wire-compatible with the current orchestrator handler — no deploy-order dependency on #2679.
The `/logs` handler already overwrites `instanceID` and `teamID` from the authoritative sandbox map; `envID` was the only identity field still trusted from the envd payload. Take it from `sbx.Runtime.TemplateID` too so envd doesn't need to be trusted for any of them.
Minimal change; the wire format (single-JSON POST) and existing `validatePayloadSandboxID` are unchanged.