Repository navigation
otel-profiles: linux-host and mysql verified in Docker - #56
Merged
Merged
Conversation
…in-one:2.39.1 ships Read in clickhouse/clickstack-all-in-one:2.39.1 (otelcol-hyperdx 0.155.0), not from docs: - Receivers: /otelcontribcol components lists docker_stats, file_log, fluent_forward, host_metrics, k8s_cluster, kubelet_stats, nop, otlp, datadog and prometheus. filelog, fluentforward, hostmetrics and kubeletstats are accepted as aliases (validate --config); dockerstats and k8scluster are rejected; there is no statsd. Corrected in CONVENTIONS rule 4, otel-profiles README and the virt-vsphere README, both languages. - Rule 1: the all-in-one image always runs the OpAMP supervisor path (/etc/local/entry.base.sh exports OPAMP_SERVER_URL); agent.config_files is config.yaml then $CUSTOM_OTELCOL_CONFIG_FILE, with the OpAMP remote config merged after. The standalone branch in /otel-entrypoint.sh is not taken. - Rule 3: clickhouse and otlp/hyperdx are injected at runtime by the API (opampController.js), not defined in /etc/otelcol-contrib/config.yaml. - Rule 2: ClickStack's pipelines are bare traces and metrics plus named logs/in, logs/out-default and logs/out-rrweb; the rule itself is unchanged. - _base/README: the "standalone as well as supervisor" sentence now says what was read and what was not (the Cloud-side collector). No Verified line is written: bin/verify.sh has not run end to end yet (#52). Refs #52 Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…ted; vsphere targets otlp/hyperdx Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… on ClickStack 2.39.1 First end-to-end run of bin/verify.sh (#52). Layers 1 and 2 passed; layer 3 printed "searchable via HyperDX (1 rows)" for 200 stored rows. Cause, read from the running 2.39.1 API: - POST /api/v2/search with the lucene field `verify.run_id` returns {"message":"UNKNOWN_IDENTIFIER: ... `verify.run_id` ..."}; a resource attribute is addressed as `ResourceAttributes.verify.run_id`. - The script counted len(d.get('data', d)): for an error object that is the number of keys, so any error read as "1 rows" and passed. Now the lucene field is `ResourceAttributes.verify.run_id`, only a `data` list counts, and a response without one is a FAIL that prints the server's message. What the layer checks (rows found through the HyperDX search for this run_id, more than zero) is unchanged. With N=3, the old script passed with "1 rows", a copy with the old field name now fails with the UNKNOWN_IDENTIFIER message, and the fixed script passes with "3 rows". Full run, N=200: emitted 200, stored 200, searchable 200. README: the Verified on line, both languages (ClickStack 2.39.1, ClickHouse 26.8.7.19 from SELECT version(), telemetrygen v0.155.0). Refs #52 Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
linux-host (#53) - custom.config.yaml accepts both syslog formats: RFC 3164 (Ubuntu 22.04's rsyslog default) and ISO 8601 (Ubuntu 24.04's), one time_parser each. - Verified line (Docker only: Docker Desktop VM metrics, rsyslog in ubuntu:noble-20260911 and ubuntu:jammy-20260901.2); the docker run example names 2.39.1. mysql (#54) - custom.config.yaml: a filter operator drops mysqld's three-line slow-log header, which is written at every start and made verify.sql query 4 return unparsed_slow_lines = 5. Verified line added. - Prerequisites corrected: SHOW REPLICA STATUS needs REPLICATION CLIENT; the sidecar health port must be set when it runs next to _base. - metrics.md and a sidecar.config.yaml comment: db.system.name at v0.155.0 is an attribute of two disabled log events only. Fixture (_base/docker-compose.otel-verify.yml, _base/otel-verify/) - one volume at /hostfs/var/log, written by rsyslog in two Ubuntu releases and by MySQL 8.4.11; README section in both languages. sidecar/docker-compose.yml: CLICKSTACK_API_KEY falls back to HYPERDX_INGESTION_KEY; the health port is SIDECAR_HEALTH_PORT (default 13133). CONVENTIONS.md rule 4, both languages: each receiver alias logs a deprecation warning when the collector starts. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #53
Closes #54
Both profiles are now verified in Docker only, on the local
_base/stack: no physical or cloud Linux host, and the MySQL is a container. The Verified lines say so.What changed
linux-host/custom.config.yaml: thefilelogparser accepts two syslog shapes. Ubuntu 22.04 writes RFC 3164 (Oct 1 04:14:15 host tag[pid]: msg); Ubuntu 24.04 dropped$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormatand writes ISO 8601 (2026-10-01T04:13:39.637057+00:00 host tag[pid]: msg), which the old regex did not match at all. The regex takes eitherts, and there is onetime_parserper shape, selected byif:. The owner chose this on otel-profiles/linux-host: verify in Docker (Docker Desktop VM as the host) #53.metrics.mdLogs section updated.mysql/custom.config.yaml: afilteroperator drops mysqld's three-line slow-log header (/usr/sbin/mysqld, Version: … started with:), which mysqld writes at every start. It is not a query entry, and the restart is already inerror.log. The owner chose this on otel-profiles/mysql: verify both halves against a MySQL 8.4 container #54.verify.sqlis unchanged.metrics.mdhas one sentence on it.mysql/README.mdPrerequisites, both languages:SHOW REPLICA STATUSneedsREPLICATION CLIENT(the old text said no grant was needed). Sidecar section:SIDECAR_HEALTH_PORTmust be set when the sidecar runs on the same machine as_base.mysql/metrics.md,mysql/sidecar.config.yaml(comment):db.system.nameat v0.155.0 is an attribute of two disabled log events, not "added in a later release" (see Collector facts).sidecar/docker-compose.yml:CLICKSTACK_API_KEYfalls back toHYPERDX_INGESTION_KEY; the health port is${SIDECAR_HEALTH_PORT:-13133}(default unchanged).CONVENTIONS.mdrule 4, both languages: each receiver alias logs a deprecation warning when the collector starts. Nothing is renamed in the profiles._base/docker-compose.otel-verify.ymland_base/otel-verify/, with a_base/README.mdsection in both languages. A plaindocker compose up -ddoes not use it.Why a fixture
On Docker Desktop,
/hostfsis the VM. Its/var/logholds onlylastlog, so there is no syslog to read. A named volume can be mounted at/hostfs/var/logbut not at/hostfs/var/log/mysql(read-only file system; probed before writing the fixture). So one volume,otel-verify-logs, is mounted at/hostfs/var/log:roin ClickStack, and rsyslog (two Ubuntu releases, one after the other) and MySQL write into it. The profiles' paths and configs are unchanged. Both rsyslogs run the package's default configuration with onlyimklogoff (a container has no kernel log).Versions, and how each was read
clickstack-all-in-one:2.39.1, collector components 0.155.0componentsbuildinfoSELECT version()(also inbin/check.sh)mysql:8.4.11)SELECT VERSION(); tag from the Docker Hub API 2026-10-01otel/opentelemetry-collector-contrib:0.155.0--versiondocker version --format '{{.Server.Platform.Name}}'7.0.14-linuxkituname -rinside a containernoble-20260911=24.04, rsyslog8.2312.0-3ubuntu9.4apt-cache policy;dpkg -s rsyslogin the built image;rsyslogd -vjammy-20260901.2=jammy, rsyslog8.2112.0-2ubuntu2.5Digests (Docker Hub API, 2026-10-01; the hardware is arm64):
ubuntu:noble-20260911sha256:11dc1ccb427f0464a2369e645454c272bb0baece7357c892ba69d313b3a332cfsha256:496754492fb28b4d3049432f2ca787449331e23fb14f0dd3fffea86bf5a93eb4ubuntu:jammy-20260901.2sha256:1cc7bb38a74c0e126716646e47c0b3c5c139547d386d5ff7a64cf3ea316ca523sha256:281c5745f657873d78e5531fc5ba8575f46ab7769b94550ac99543f122679986mysql:8.4.11sha256:ca3f0494c0f1fc86eb45f5e4786a1bb9f64d2f85b562cc74a9595046f6519a42sha256:80f4933e3835f9dc4d35a28ec500d7986cb4414e6c6821c5461239cb7beb8995ClickStack's collector runs as root (
psin the container), so the 0640syslog:admand mysql files were readable.Syslog sample (the fixtures'
/var/log/syslog)Pre-validation of the parsers (credential-free)
A throwaway
docker run --rm --entrypoint /otelcontribcolof the 2.39.1 image: the profile'sfilelogblock copied byyqwith onlystart_at: beginningand the include path changed, a bind-mounted test file, adebugexporter withverbosity: detailed, no/mount, the running stack untouched. (Validating against the running collector's own configuration needs its environment; I did not do that.)linux-host, seven test lines:
unit2026-10-01T04:13:39.637057+00:00 …fixture2026-10-01T13:13:41.100000+09:00 …fixture-offset2026-10-01T04:13:42Z …(no fraction)fixture-zOct 1 04:14:15 …(RFC 3164)fixtureOct 1 04:14:21 … last message repeated 3 timeson_error: send)The same file through the pre-change profile: no
unitand Timestamp 1970 on every ISO line, jammy lines parsed.mysql
filter: a testmysql-slow.logwith the header block followed by two# Time:entries, plus anerror.logcontaining a line withVersion:mid-line. Result: exactly two slow-log records (both parsed:query_time,rows_examined, Timestamp from the entry), botherror.loglines untouched. Without the operator the same file gives three slow-log records, the first being the unparsed header with Timestamp 1970. The expressionattributes["log.file.name"] == "mysql-slow.log" and body matches "^\\S+, Version: "compiled and ran without error. The regex is written with two backslashes (\\S) because the expression's string literal unescapes them to\S.bin/check.shreceiver check (linux-host alone)bin/verify.sh linux-host(SQL comment echo trimmed; run after the noble fixture and then the jammy fixture had written for several 30 s collection intervals.)
Per fixture host (ad hoc, not added to
verify.sql): doesTimestampequal the line's ownts, rather than the ingestion time? ISO within 2 s (sample rows are exact to the microsecond); RFC 3164 exact to the second, comparingformatDateTime(Timestamp, '%b %e %H:%i:%S')withts.bin/verify.sh mysql: failing side, then passing sideFailing side, before the
filteroperator: the collector was recreated first and MySQL started after it, so the slow log was read from the top, including mysqld's own header written by each of its starts. Statement 4 of that run:An ad hoc breakdown of those rows:
parsed_slow_entries=4, unparsed_slow_lines=5, of_which_mysqld_banner=5, of_which_other=0.Passing side, with the
filteroperator.clickstackwas recreated with the rebuiltmysql linux-hostconfig; the five earlier unparsed rows are still inotel_logs(nothing was deleted) but their newest Timestamp is06:17:35, 0 of them inside the 15-minute window. Thenmysqldwas restarted while the collector was reading, andSELECT SLEEP(2),(3)and(2.5)were run asotel_monitor.grep -c 'Version:' /var/log/mysql/mysql-slow.loginside the mysql container: 3 before the restart, 4 after (a new header was written while the collector was running).Ad hoc: the header never reached
otel_logs, and the restart is inerror.log:Collector facts, at the pinned tag
mysqlis inotel/opentelemetry-collector-contrib:0.155.0components(metrics Beta, logs Development), and not in ClickStack'scomponents. Read withdocker run --rm otel/opentelemetry-collector-contrib:0.155.0 components.receiver/mysqlreceiver/metadata.yaml@v0.155.0: one resource attribute,mysql.instance.endpoint;server.address,server.portandservice.instance.idappear nowhere. Query 1'smysql.instance.endpointishost.docker.internal:3306, and the resource attribute keys on themysql.*points aredb.system.name,deploy.platform,host.name,mysql.instance.endpoint,os.type,service.name; all butmysql.instance.endpointare added by the sidecar's processors.db.system.nameappears in thatmetadata.yamlonly as an attribute of the log eventsdb.server.query_sampleanddb.server.top_query, bothenabled: falseand not used by this profile.mysql/metrics.mdand asidecar.config.yamlcomment said it was "added in a later release"; reworded.force_flush_perioddefaults to 500ms (reader.DefaultFlushPeriod = 500 * time.Millisecondinpkg/stanza/fileconsumer/internal/reader;receiver/filelogreceiver/README.md).include_file_name(default true) setslog.file.name. No change needed.filteroperator (pkg/stanza/docs/operators/filter.md,operator/transformer/filter/transformer.go@ v0.155.0): entries matchingexprare dropped;drop_ratiodefaults to 1. If the expression errors, the entry is dropped too, which is why the expression is guarded by the file name.time_parserusestime.ParseInLocationforgotime;if:takes an expr-lang expression (matchesis the regex operator, expr v1.17.8).filelog,hostmetrics,fluentforward,kubeletstatslogs"<alias>" alias is deprecated; use "<name>" insteadwhen the 2.39.1 collector starts with it;validateprints nothing. The contrib 0.155.0 sidecar logs the same forotlpandresourcedetection.Sidecar
Run the documented way from
otel-profiles/sidecar/with--env-file ../../_base/.envplus a non-secret env file (CLICKSTACK_OTLP_ENDPOINT=host.docker.internal:4317,CLICKSTACK_OTLP_INSECURE=true,MYSQL_*for theotel_monitorlocal user,SIDECAR_HEALTH_PORT=13134). The ingestion key was read from_base/.envby Compose and not copied. The interpolation was proven first with dummy env files: with onlyHYPERDX_INGESTION_KEYset the key is used, an explicitCLICKSTACK_API_KEYwins, with neither it is empty.upwith the default failed withBind for 0.0.0.0:13133 failed: port is already allocated, because_basepublishes 13133 for its own collector. HenceSIDECAR_HEALTH_PORT; the default stays 13133.otel_monitoruser was created exactly as the README says. The sidecar logged, on every 30 s scrape, at info level:Failed to fetch replica status stats … Error 1227 (42000): Access denied; you need (at least one of) the SUPER, REPLICATION CLIENT privilege(s) for this operation. The other 20mysql.*metric names still arrived. Prerequisites corrected; the grant was not added silently.grpc: addrConn.createTransport failed to connect to {Addr: "[fdc4:f303:9324::254]:4317", ServerName: "host.docker.internal:4317"} … network is unreachable(five warnings):host.docker.internalresolves to an IPv6 address that Docker Desktop's VM cannot reach. Metrics reached ClickHouse over IPv4 anyway.host.id. The sidecar logsfailed to get host IDfromresourcedetection/common, so its metrics have nohost.idresource attribute.host.nameis present.Findings worth knowing
host.nameon the linux-host metric rows is the collector container's own hostname, not the VM's:resourcedetectionruns inside the container. The values are the VM's.$RepeatedMsgReduction onturns repeated identical messages intolast message repeated N times, which has nounitand does not match the regex. The fixture'sloggerlines carry a counter so they are never repeated..shinit fragment. On a Docker Desktop bind mount the entrypoint took its "running" branch for a mode-644 file and failed withPermission denied, withrestart: unless-stoppedrestarting into a half-initialised data directory. The user is now created throughMYSQL_USER/MYSQL_PASSWORDplus a.sqlgrant, and the service isrestart: "no"./var/log/syslogaside (the two releases'syslogusers have different uids), and no lines were lost in the switch.How it was run
_base/docker-compose.ymlplus the new override,clickstack-all-in-one:2.39.1.CH_URL=http://localhost:18123 CH_USER=api CH_PASSWORD=apiforverify.sh._base/.env; none is in this PR, its commits, or any file created for it. gitleaks over the branch: no leaks.Not run
REPLICATION CLIENTgranted..env.examplenot updated: not readable by the agent.SIDECAR_HEALTH_PORTandMYSQL_MONITOR_PASSWORDare documented in compose comments and the READMEs only.aws-rds-mysql; a MySQL 5.7 variant; other Ubuntu or MySQL releases; amd64 builds of the fixture (this machine is arm64).FLUSH SLOW LOGSalso writes the header (a restart does).STATUS.md(left to the lead).Verify commands
🤖 Generated with Claude Code