Stop the agent from attempting to reach a Kubelet when running as a cluster checks runner - #54920
Stop the agent from attempting to reach a Kubelet when running as a cluster checks runner#54920mrdoggopat wants to merge 5 commits into
Conversation
|
🎯 Code Coverage (details) 🔗 Commit SHA: 4cb48ce | Docs | Datadog PR Page | Give us feedback! |
Files inventory check summaryFile checks results against ancestor afcc03c4: Results for datadog-agent_7.84.0~devel.git.205.4cb48ce.pipeline.131078063-1_amd64.deb:No change detected Results for datadog-iot-agent_7.84.0~devel.git.205.4cb48ce.pipeline.131078063-1_amd64.deb:No change detected |
…ostAliases" This reverts commit 66c4f62.
Regression DetectorRegression Detector ResultsMetrics dashboard Baseline: afcc03c Optimization Goals: ✅ No significant changes detected
|
| perf | experiment | goal | Δ mean % | Δ mean % CI | trials | links |
|---|---|---|---|---|---|---|
| ➖ | quality_gate_logs | % cpu utilization | +3.18 | [+2.28, +4.09] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_metrics_logs | memory utilization | +1.08 | [+0.83, +1.33] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_idle | memory utilization | +0.41 | [+0.29, +0.53] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_idle_all_features | memory utilization | +0.07 | [+0.02, +0.11] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_security_mean_fs_load | memory utilization | -0.27 | [-0.35, -0.20] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_security_idle | memory utilization | -0.30 | [-0.40, -0.19] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_private_action_runner | memory utilization | -0.30 | [-0.42, -0.19] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_security_no_fs_load | memory utilization | -0.42 | [-0.57, -0.28] | 1 | Logs bounds checks dashboard |
Bounds Checks: ✅ Passed
| perf | experiment | bounds_check_name | replicates_passed | observed_value | links |
|---|---|---|---|---|---|
| ✅ | quality_gate_idle | intake_connections | 10/10 | 4 = 4 | bounds checks dashboard |
| ✅ | quality_gate_idle | memory_usage | 10/10 | 172.59MiB ≤ 178MiB | bounds checks dashboard |
| ✅ | quality_gate_idle | total_bytes_received | 10/10 | 741.94KiB ≤ 819.20KiB | bounds checks dashboard |
| ✅ | quality_gate_idle_all_features | intake_connections | 10/10 | 4 = 4 | bounds checks dashboard |
| ✅ | quality_gate_idle_all_features | memory_usage | 10/10 | 528.13MiB ≤ 538MiB | bounds checks dashboard |
| ✅ | quality_gate_idle_all_features | total_bytes_received | 10/10 | 1.13MiB ≤ 1.25MiB | bounds checks dashboard |
| ✅ | quality_gate_logs | intake_connections | 10/10 | 17 ≤ 40 | bounds checks dashboard |
| ✅ | quality_gate_logs | memory_usage | 10/10 | 205.62MiB ≤ 229MiB | bounds checks dashboard |
| ✅ | quality_gate_logs | missed_bytes | 10/10 | 0B = 0B | bounds checks dashboard |
| ✅ | quality_gate_logs | total_bytes_received | 10/10 | 264.22MiB ≤ 292MiB | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | cpu_usage | 10/10 | 366.49 ≤ 2000 | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | intake_connections | 10/10 | 19 ≤ 40 | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | memory_usage | 10/10 | 426.05MiB ≤ 439MiB | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | missed_bytes | 10/10 | 0B = 0B | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | total_bytes_received | 10/10 | 0.94GiB ≤ 1.04GiB | bounds checks dashboard |
| ✅ | quality_gate_private_action_runner | memory_usage | 10/10 | 71.91MiB ≤ 76MiB | bounds checks dashboard |
| ✅ | quality_gate_security_idle | cpu_usage | 10/10 | 27.17 ≤ 100 | bounds checks dashboard |
| ✅ | quality_gate_security_idle | memory_usage | 10/10 | 326.71MiB ≤ 335MiB | bounds checks dashboard |
| ✅ | quality_gate_security_mean_fs_load | cpu_usage | 10/10 | 62.15 ≤ 200 | bounds checks dashboard |
| ✅ | quality_gate_security_mean_fs_load | memory_usage | 10/10 | 301.43MiB ≤ 314MiB | bounds checks dashboard |
| ✅ | quality_gate_security_no_fs_load | cpu_usage | 10/10 | 20.47 ≤ 100 | bounds checks dashboard |
| ✅ | quality_gate_security_no_fs_load | memory_usage | 10/10 | 309.54MiB ≤ 343MiB | bounds checks dashboard |
Explanation
Confidence level: 90.00%
Effect size tolerance: |Δ mean %| ≥ 5.00%
Performance changes are noted in the perf column of each table:
- ✅ = significantly better comparison variant performance
- ❌ = significantly worse comparison variant performance
- ➖ = no significant change in performance
A regression test is an A/B test of target performance in a repeatable rig, where "performance" is measured as "comparison variant minus baseline variant" for an optimization goal (e.g., ingress throughput). Due to intrinsic variability in measuring that goal, we can only estimate its mean value for each experiment; we report uncertainty in that value as a 90.00% confidence interval denoted "Δ mean % CI".
For each experiment, we decide whether a change in performance is a "regression" -- a change worth investigating further -- if all of the following criteria are true:
-
Its estimated |Δ mean %| ≥ 5.00%, indicating the change is big enough to merit a closer look.
-
Its 90.00% confidence interval "Δ mean % CI" does not contain zero, indicating that if our statistical model is accurate, there is at least a 90.00% chance there is a difference in performance between baseline and comparison variants.
-
Its configuration does not mark it "erratic".
CI Pass/Fail Decision
✅ Passed. All Quality Gates passed.
- quality_gate_security_idle, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_idle, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_idle, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_idle, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_idle, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_private_action_runner, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check missed_bytes: 10/10 replicas passed. Gate passed.
- quality_gate_security_mean_fs_load, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_mean_fs_load, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_no_fs_load, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_no_fs_load, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_idle_all_features, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_idle_all_features, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_idle_all_features, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check missed_bytes: 10/10 replicas passed. Gate passed.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 86af90636a
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
…HostAliases" This reverts commit 86af906.
Static quality checks✅ Please find below the results from static quality gates Successful checksInfo
8 successful checks with minimal change (< 2 KiB)
|
jeremy-hanna
left a comment
There was a problem hiding this comment.
👍 for agent-runtime owned files
What does this PR do?
Stops the Agent from attempting to reach a local Kubelet when running as a Cluster Checks Runner (CCR).
Cluster Checks Runners are Deployment replicas, not DaemonSets so they aren't scheduled per-node, so a CCR pod never has a locally-reachable Kubelet. Despite that, several independent code paths unconditionally called into
kubelet.GetKubeUtil()/GetKubeUtilWithRetrier(), each of which restarts the same HTTPS→HTTP fallback probe and keeps its exponential-backoff retrier alive. This PR adds ahelper.IsCLCRunner(...)guard to each of the six call sites found to trigger this:pkg/util/kubernetes/cloudprovider/cloudprovider.go-GetName(), used to populate thekube_distributionhost tag (host-tags refresh cycle, ~30 min).pkg/util/kubernetes/clustername/clustername.go-getClusterName()'s unconditional node-label lookup viahostinfo.NewNodeInfo()(same ~30 min cycle). Config-provided or cloud-provider-discovered cluster names are unaffected; only the node-label auto-discovery/override step is skipped on CCR.comp/core/workloadmeta/collectors/internal/kubelet/kubelet.goand.../kubemetadata/kubemetadata.go—Start()now returnserrors.NewDisabled(...)on CCR instead of letting workloadmeta's own candidate-retry loop (1s → 30s exponential backoff, no max elapsed time) retry it forever.comp/metadata/host/impl/hosttags/tags.go- the"kubernetes"host-tags provider is no longer registered at all on CCR (same ~30 min refresh cycle).pkg/util/containers/metrics/kubelet/collector.go- thekubeletcontainer-metrics collector's constructor now returnsprovider.ErrPermaFailon CCR, instead of getting retried forever by the metrics-provider registry's independent 2-second discovery ticker.pkg/util/cloudproviders/cloudproviders.go-GetHostAliases()'s kubelet and kubernetes host-alias detectors, which route through the shared kubelet client singleton (host-metadata refresh cycle, ~30 min, plus agent startup). Both detectors are now skipped entirely on CCR instead of hitting the kubelet retrier's exponential backoff on every refresh.Each of the six guards is independent as they sit on genuinely separate callers of the shared Kubelet retrier singleton, triggered by different subsystems and cadences (host-tags refresh, workloadmeta collector startup, and the metrics registry's ticker). Removing any single one reintroduces the warning from exactly that call path.
There is no change in behavior for the node Agent or Cluster Agent. All guards are scoped to
helper.IsCLCRunner(...).Motivation
CONS-8502
Historically, the Cluster Checks Runner has always tried to reach a local Kubelet on startup and on periodic refreshes, even though it's fundamentally incapable of reaching one (it's a Deployment replica, not a per-node DaemonSet). This was previously a
Debug-level log, so it went unnoticed. PR #51447 raised the Kubelet HTTPS-fallback log fromDebugtoWarn(first released in 7.81.0), which turned this long-standing, harmless-but-pointless probing into a recurringWARN.Describe how you validated your changes