Skip to content

feat(metrics,logs): bug & auth fixes - #120

Merged
blue4209211 merged 6 commits into
mainfrom
feat/workspace-metrics-logs
Oct 8, 2026
Merged

blue4209211 merged 6 commits into
mainfrom
feat/workspace-metrics-logs

Conversation

@blue4209211

@blue4209211 blue4209211 commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Nubi's workspace runs nbctl against a proxy in llm-server, authenticated with the per-command workspace token, to fetch raw metrics and logs into files (nudgebee/nudgebee-enterprise#40463, proxy: nudgebee/nudgebee-enterprise#40619).

Changes

Config

Metrics / logs commands

  • metrics list-metrics calls metrics_list_names. metrics_list is the series query action and returned nothing without queries.
  • -o json for metrics query / logs query prints the backend results / logs unchanged, with no JSON-in-strings, even when they don't fit nbctl's types.
  • metrics query --step <duration> is sent as step_interval seconds. The request is now one $request: FetchMetricsRequest! variable.
  • Empty results are explained on stderr, e.g. No values found for log label "severity" ... (it may be a field inside log lines rather than an indexed label). Stdout stays empty (text) or [] (JSON). Behavior change: "No logs found." / "No Data" moved from stdout to stderr.
  • logs query warns on stderr when it returns exactly --limit lines, and gives the --offset for the next page.

Client

  • Authorization, cookies and X-Api-Key are written as [REDACTED] in the verbose log (nbctl_graphql.log).
  • Request timeout: --http-timeout / NUDGEBEE_HTTP_TIMEOUT (default 30s; 0 disables).

Embedding

  • NUDGEBEE_ENABLED_COMMANDS=metrics,logs removes other top-level commands. This is a convenience, not access control; the proxy enforces access.
  • The GraphQL documents of the seven metrics/logs commands are exported constants. cmd/workspace_contract_test.go pins their exact text and variables and lists the request fields the proxy allows.

Known limitation (backend, not nbctl)

--step is sent but ignored on the agent path. api-server sends action_params.steps and relay-server only checks step, so relay-server fills step from the window and the agent uses that. The fix belongs in nudgebee-enterprise (api-server prometheusActionParams should also set step).

Testing

  • make build passes (lint, go test -race ./..., build).
  • Unit tests cover:
    • the request contract for the 7 commands;
    • raw JSON pass-through, including shapes that don't fit nbctl's types;
    • --step;
    • empty-result notes in text and JSON;
    • the limit warning;
    • header redaction;
    • timeout parsing;
    • the command allowlist;
    • env-over-profile, including an empty env var.
  • Live on dev:
    • every metrics/logs command;
    • logs query paging;
    • instant, chart and failed queries;
    • an env-only run with an empty HOME, the allowlist, a 50s timeout and verbose on: the token appears neither in the log nor as an Authorization line;
    • 401 and timeout errors.
  • Nubi end-to-end: 17 conversations against dev through the llm-server proxy.

🤖 Generated with Claude Code

blue4209211 and others added 2 commits October 8, 2026 13:15
Nubi's workspace runs nbctl against a proxy in llm-server with a short-lived
token, to fetch raw metrics and logs into files (nudgebee/nudgebee-enterprise#40463).

- config: IsConfigured no longer requires username (unused for auth since
  the API key is sent directly as Bearer)
- metrics list-metrics: call metrics_list_names; metrics_list is the series
  query action and returned nothing without queries
- metrics query / logs query: -o json prints the backend results unchanged
  (no JSON-in-strings), and [] when empty; failed queries, notes and log
  suggestions go to stderr
- metrics query: --step <duration>, sent as step_interval seconds; the
  request is sent as one $request: FetchMetricsRequest! variable
- client: never write Authorization, cookies or X-Api-Key to
  nbctl_graphql.log (--verbose)
- client: per-request timeout configurable via --http-timeout /
  NUDGEBEE_HTTP_TIMEOUT (default 30s)
- NUDGEBEE_ENABLED_COMMANDS=metrics,logs removes other top-level commands
- the GraphQL documents of the seven metrics/logs commands are named
  constants, pinned by a contract test

Co-Authored-By: Claude Opus 5.5 <[email protected]>
A profile in ~/.nudgebee/config.yaml was applied with viper.Set and so
overrode env, e.g. the endpoint and token Nubi's workspace sets per command.

Co-Authored-By: Claude Opus 5.5 <[email protected]>

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces several enhancements to nbctl, including support for limiting available commands via NUDGEBEE_ENABLED_COMMANDS, custom HTTP timeouts, and credential redaction in verbose logs. It also refactors GraphQL queries into shared constants, updates configuration validation to make the username optional, and adds a comprehensive contract test suite. Feedback on the changes highlights a bug in restrictCommands where modifying the commands slice during iteration causes elements to be skipped, and suggests optimizing string(raw) == "null" checks in logs and metrics queries by checking the slice length first to avoid unnecessary memory allocations.

Comment thread cmd/root.go Outdated
Comment thread cmd/logs_query.go
Comment thread cmd/metrics_query.go
blue4209211 and others added 3 commits October 8, 2026 18:26
…; ignore empty env vars over profiles

- metrics query -o json no longer fails when results don't fit the typed
  structs (e.g. a non-string label value); decoding is only needed for text
  output and the stderr warnings
- an empty NUDGEBEE_* env var no longer masks the profile setting (viper
  ignores empty env vars, so the setting ended up blank)

Co-Authored-By: Claude Opus 5.5 <[email protected]>
- list-metrics, list-labels, list-label-values, metrics query and logs query
  say on stderr when they found nothing (with the label/metric and window),
  so an empty stdout is not mistaken for a silent failure; -o json still
  prints [] (metrics query: the results unchanged)
- logs query warns when it returned exactly --limit lines and gives the
  --offset for the next page
- contract test documents the request fields the llm-server proxy allows

Co-Authored-By: Claude Opus 5.5 <[email protected]>
@blue4209211 blue4209211 changed the title feat(metrics,logs): make nbctl usable from Nubi's workspace feat(metrics,logs): bug & auth fixes Oct 8, 2026
- metrics query / logs query -o json: when the results don't fit the typed
  structs, the count is unknown, not zero; no longer print a false
  'No data' / 'No logs found'
- instant queries say 'at <end>' instead of a window

Co-Authored-By: Claude Opus 5.5 <[email protected]>
@blue4209211
blue4209211 merged commit 5fbd13b into main Oct 8, 2026
2 checks passed
@blue4209211
blue4209211 deleted the feat/workspace-metrics-logs branch October 8, 2026 16:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants