Repository navigation
feat(metrics,logs): bug & auth fixes - #120
Merged
Merged
Conversation
Nubi's workspace runs nbctl against a proxy in llm-server with a short-lived token, to fetch raw metrics and logs into files (nudgebee/nudgebee-enterprise#40463). - config: IsConfigured no longer requires username (unused for auth since the API key is sent directly as Bearer) - metrics list-metrics: call metrics_list_names; metrics_list is the series query action and returned nothing without queries - metrics query / logs query: -o json prints the backend results unchanged (no JSON-in-strings), and [] when empty; failed queries, notes and log suggestions go to stderr - metrics query: --step <duration>, sent as step_interval seconds; the request is sent as one $request: FetchMetricsRequest! variable - client: never write Authorization, cookies or X-Api-Key to nbctl_graphql.log (--verbose) - client: per-request timeout configurable via --http-timeout / NUDGEBEE_HTTP_TIMEOUT (default 30s) - NUDGEBEE_ENABLED_COMMANDS=metrics,logs removes other top-level commands - the GraphQL documents of the seven metrics/logs commands are named constants, pinned by a contract test Co-Authored-By: Claude Opus 5.5 <[email protected]>
A profile in ~/.nudgebee/config.yaml was applied with viper.Set and so overrode env, e.g. the endpoint and token Nubi's workspace sets per command. Co-Authored-By: Claude Opus 5.5 <[email protected]>
There was a problem hiding this comment.
Code Review
This pull request introduces several enhancements to nbctl, including support for limiting available commands via NUDGEBEE_ENABLED_COMMANDS, custom HTTP timeouts, and credential redaction in verbose logs. It also refactors GraphQL queries into shared constants, updates configuration validation to make the username optional, and adds a comprehensive contract test suite. Feedback on the changes highlights a bug in restrictCommands where modifying the commands slice during iteration causes elements to be skipped, and suggests optimizing string(raw) == "null" checks in logs and metrics queries by checking the slice length first to avoid unnecessary memory allocations.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
…; ignore empty env vars over profiles - metrics query -o json no longer fails when results don't fit the typed structs (e.g. a non-string label value); decoding is only needed for text output and the stderr warnings - an empty NUDGEBEE_* env var no longer masks the profile setting (viper ignores empty env vars, so the setting ended up blank) Co-Authored-By: Claude Opus 5.5 <[email protected]>
- list-metrics, list-labels, list-label-values, metrics query and logs query say on stderr when they found nothing (with the label/metric and window), so an empty stdout is not mistaken for a silent failure; -o json still prints [] (metrics query: the results unchanged) - logs query warns when it returned exactly --limit lines and gives the --offset for the next page - contract test documents the request fields the llm-server proxy allows Co-Authored-By: Claude Opus 5.5 <[email protected]>
- metrics query / logs query -o json: when the results don't fit the typed structs, the count is unknown, not zero; no longer print a false 'No data' / 'No logs found' - instant queries say 'at <end>' instead of a window Co-Authored-By: Claude Opus 5.5 <[email protected]>
RamanKharchee
approved these changes
Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Nubi's workspace runs nbctl against a proxy in llm-server, authenticated with the per-command workspace token, to fetch raw metrics and logs into files (nudgebee/nudgebee-enterprise#40463, proxy: nudgebee/nudgebee-enterprise#40619).
Changes
Config
IsConfiguredno longer requiresusername(unused for auth since fix(auth)!: send API token directly as Bearer, drop /api/auth/token exchange #119).NUDGEBEE_*env var now wins over a profile in~/.nudgebee/config.yaml. Before, the profile overrode env.Metrics / logs commands
metrics list-metricscallsmetrics_list_names.metrics_listis the series query action and returned nothing without queries.-o jsonformetrics query/logs queryprints the backendresults/logsunchanged, with no JSON-in-strings, even when they don't fit nbctl's types.metrics query --step <duration>is sent asstep_intervalseconds. The request is now one$request: FetchMetricsRequest!variable.No values found for log label "severity" ... (it may be a field inside log lines rather than an indexed label). Stdout stays empty (text) or[](JSON). Behavior change: "No logs found." / "No Data" moved from stdout to stderr.logs querywarns on stderr when it returns exactly--limitlines, and gives the--offsetfor the next page.Client
Authorization, cookies andX-Api-Keyare written as[REDACTED]in the verbose log (nbctl_graphql.log).--http-timeout/NUDGEBEE_HTTP_TIMEOUT(default 30s;0disables).Embedding
NUDGEBEE_ENABLED_COMMANDS=metrics,logsremoves other top-level commands. This is a convenience, not access control; the proxy enforces access.cmd/workspace_contract_test.gopins their exact text and variables and lists the request fields the proxy allows.Known limitation (backend, not nbctl)
--stepis sent but ignored on the agent path. api-server sendsaction_params.stepsand relay-server only checksstep, so relay-server fillsstepfrom the window and the agent uses that. The fix belongs in nudgebee-enterprise (api-serverprometheusActionParamsshould also setstep).Testing
make buildpasses (lint,go test -race ./..., build).--step;logs querypaging;🤖 Generated with Claude Code