Add bounded privacy-aware Prometheus diagnostics - #13
Merged
Conversation
YangYuS8
marked this pull request as ready for review
July 16, 2026 07:58
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
/api/v1client without adding third-party dependenciesprometheus_server_infofor bounded build and runtime diagnosticsprometheus_target_listfor bounded active-target health summariesprometheus_metric_snapshotfor constrained instant metric snapshotsQuery boundary
prometheus_metric_snapshotdoes not accept arbitrary PromQL. OpsPilot generates the expression from:sum,avg,min,max, orcountaggregationRegular expressions, range vectors, subqueries, offsets, functions, arbitrary labels, arbitrary paths, and user-supplied PromQL are not interfaces. Metric queries use Prometheus's URL-encoded POST form so matcher values do not appear in request URLs.
Configuration and transport safety
OPSPILOT_PROMETHEUS_ALLOW_HTTP=truePrivacy boundary
Raw Prometheus API data is never returned. The projection omits:
Target errors are represented by
error_present. API warnings and infos are represented by counts only. Metric labels are restricted tojob,instance,cluster,namespace,pod,container,node,service, andendpoint.Bounds and response validation
Validation
go mod tidywith no module-file changesgofmtgo vet ./...go test -race -coverprofile=coverage.out ./...go build ./cmd/opspilot