Skip to content

feat(health): report redacted datasource/SSH integration errors - #162

Open
PrashantBtkl wants to merge 2 commits into
mainfrom
feat/proxy-agent-integration-errors
Open

PrashantBtkl wants to merge 2 commits into
mainfrom
feat/proxy-agent-integration-errors

Conversation

@PrashantBtkl

Copy link
Copy Markdown
Contributor

Description

Adds error_class (datasource_integration_failure / ssh_integration_failure) to per-datasource entries in the health report, so the Proxy Agent tab can show why an integration is failing without logging into the host.

Errors come from failed health checks and failed proxied requests (kept up to 15 min, cleared by the next successful request). They are redacted (credentials, private keys, IPs, host:port) and truncated to 512 chars before leaving the host. Rather than scraping journald, the agent reports from its own in-process state, so it works on all platforms. Errors clear automatically once the integration recovers.

Relates to nudgebee/nudgebee-enterprise#39578 (backend/UI storage and rendering of error_class still to do).

Type of change

  • New feature (non-breaking change which adds functionality)
  • Documentation

How Has This Been Tested?

  • Unit tests (go vet and go test ./pkg/...; make validate not run)

Checklist

  • CLA signed (the CLA bot will prompt on your first PR)
  • make validate passes (fmt + lint + test)
  • Docs updated if the wire shape, config surface, or proxy module behavior changed

🤖 Generated with Claude Code

Add error_class to datasource health entries and record request-time
failures so they surface in the next health report. Errors are redacted
(credentials, keys, IPs, host:port) and truncated before leaving the host.

Refs nudgebee/nudgebee-enterprise#39578

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces integration error reporting for the proxy agent, adding error redaction, truncation, and tracking of recent request errors with a 15-minute TTL. Feedback on these changes highlights three key areas: first, string truncation in RedactError should safely handle multi-byte UTF-8 characters to prevent invalid sequences; second, a potential memory leak in Registry should be addressed by cleaning up reqErrors when datasources are removed or closed; and third, the test suite for RedactError should assert exact expected outputs to prevent tests from passing vacuously.

Comment thread pkg/proxy/errors.go
Comment thread pkg/proxy/registry.go
Comment thread pkg/proxy/errors_test.go Outdated
- only record connectivity/auth failures; ignore caller errors and
  cancelled request contexts
- clear recorded request errors on Register/Remove/CloseAll and ignore
  results for unregistered datasources
- redaction: bearer/basic, JSON-style secrets, IPv6, lookup/dial hosts,
  UTF-8-safe truncation; redact outside the lock
- add ErrorClass and redaction to the per-target ctx-error branch
- tests assert exact redacted output; add lifecycle and race coverage

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants