forked from pixie-io/pixie
-
Notifications
You must be signed in to change notification settings - Fork 2
AE control auth + CodeRabbit #53 followup #68
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
68 commits
Select commit
Hold shift + click to select a range
c6515fd
adaptive_export: production AE — streaming export + write-integrity
390ee45
adaptive_export: ADAPTIVE_PASSTHROUGH firehose loop
entlein 9535139
ci: dx-image workflow — build + publish dx-daemon to ghcr
entlein 4ab9d07
Revert ci: dx-image workflow — wrong repo
entlein 6139e3b
adaptive_export: unit-normalize trigger watermark cursor + load-test …
fd80e5f
e2e_test/adaptive_export_loadtest: AE fixture-isolation load-test har…
1001f6d
e2e_test/adaptive_export_loadtest: document AE implied contracts (C1-…
4e62453
adaptive_export_loadtest: C15 write-duration contract + DX-steering d…
746421f
adaptive_export/trigger: update test SQL substrings for multiIf norma…
entlein 808a3ea
adaptive_export_loadtest: exp_control uses real now_s event_time (no …
9798a69
adaptive_export: ADAPTIVE_RECONCILE per-pull write-fidelity instrument
519bff5
harness: exp_pipeline_reconcile — skip empty-key rows (0 rows != LOSS 1)
3f6f409
harness: log4shell_fire.sh — reliably fire + restart the log4j-chain …
239e032
harness: log4shell_fire.sh — detection-signal framing (Cyber Verifica…
10ad397
adaptive_export(passthrough): precompiled + concurrent firehose, drop…
f4fe5c4
adaptive_export: bazel BUILD deps for internal/reconcile + pxl compil…
ee2dcfb
adaptive_export(pxl): raise Pixie 10k result cap via #px:set query flag
0fa7eb8
adaptive_export/sink: content_type silent-drop contract suite
entlein 1102ce5
adaptive_export_loadtest: DX-steered-vs-ALL datavolume reduction harness
fed1c6e
adaptive_export_loadtest: deep AE NFR benchmark harness
7532c87
adaptive_export_loadtest: fix DX-reduction dead-arm (clear stale stee…
0094ec7
nfr harness: fix lag (dateDiff) + drop racy broker-pct completeness
e59180a
dx-reduction harness: report ROWS reduction (primary) + bytes (second…
84eac90
ae deployment: add memory limit (1Gi) + raise cpu limit to 1 core
00aeaf3
ae bootstrap: separate the secret from the re-applied infra bundle
d8192aa
dx-reduction harness: fire BOTH attack stages so DX steers the backend
61ef494
adaptive_export: rename whitelist→allowlist across streaming path + a…
9feda72
ae(clickhouse): create forensic_db.dx_attack_graph at boot
2c7cfcf
ae(clickhouse): dx_attack_graph numeric cols Int64/Float64 (px-readable)
48b100e
adaptive_export(streaming): add #px:set max_output_rows cap flag to s…
8e7f1c6
ae(clickhouse): create dx_attack_graph_malicious view at boot
39a2f12
ae(control): /dx/attack_graph ingest endpoint -> ClickHouse
3b1d484
adaptive_export: convention pass — consolidate CH HTTP, drop dead cod…
entlein e9c1331
adaptive_export: restore executable bits on harness scripts (post-hea…
entlein 15ee7a3
adaptive_export: lint pass + restore @px load prefix in cmd/BUILD.bazel
entlein 31febbe
adaptive_export: address user review #2 #4 #6 + 4 outstanding CodeRab…
entlein fdfb451
test(harness): consolidate to one run-picture + e2e CI workflow
dc644c3
revert(bazel): drop stray buildifier attribute-reorder in stirling co…
fcab916
ci: fix run-genfiles + run-container-lint on PR 53
entlein 3094068
ci: apply gazelle's actual kwarg order to stirling container_images
entlein 19e84ad
ci: fix container-lint Errors on e2e workflow + new harness scripts
entlein e0a19dd
ci: silence 6 SHELLCHECK Warnings to clear container-lint exit code
entlein e6a6237
feat(ae-control): bearer-JWT auth + input validation (CodeRabbit foll…
714c1fb
fix(ae): remaining CodeRabbit Majors (#53 followup)
dfdc465
fix(ae-trigger): escape a PollLimit-saturated watermark boundary (fro…
decf2ae
feat(ae-control): TLS on the control surface (CONTROL_TLS) (#71)
entlein 0c65751
Merge remote-tracking branch 'origin/main' into ae-followup-auth
e187dc3
test(ae-trigger): differential oracle vs naive reference (incremental…
entlein 0fd9c3f
ci: fix vizier-release Build Release runner label (oracle-16cpu → ora…
entlein cb81ecd
ci: fix merge-conflict regressions from main pickup (runner labels, u…
entlein c2642da
fix(ae): address 13 CodeRabbit Go-code findings on PR 68
entlein 7f43c51
ci: carve out private/cockpit + terraform/credentials/cockpit from fi…
entlein c579e48
Revert "ci: carve out private/cockpit + terraform/credentials/cockpit…
entlein d94624a
ci: rename private/{cockpit,skaffold_cloud.yaml} so filename-linter a…
entlein ae41131
terraform: drop fork IaC from PR 68 — belongs on main, not this PR
6d10b07
fork-infra: drop cockpit, .sops.yaml, e2e workflow from PR 68
55123ea
Merge remote-tracking branch 'origin/main' into ae-followup-auth
8340d84
adaptive_export: drop out-of-scope bazel/ui.bzl (fork UI-build fix be…
0954731
adaptive_export_loadtest: replace shell harness with a Go TDD suite (…
1de6755
adaptive_export_loadtest: drop the arbitrary reduction-threshold assert
3624b30
adaptive_export: standardize event_time on nanoseconds (schema + load…
940ea2c
adaptive_export_loadtest: add evidence.sh (stack integration + nanos …
e0ef748
adaptive_export_loadtest/suite: commit go.sum (reproducible testify b…
2886012
adaptive_export_loadtest: test EVERY forensic_db timestamp is nanosec…
daf881d
adaptive_export_loadtest: drop evidence.sh (the Go schema + reproduci…
2eb1e6d
adaptive_export_loadtest: java-poc disease calibration (real e2e)
be04314
test(e2e): single pixie-native command to deploy the non-Pixie stack
1288ea9
test(e2e): confusion matrix + all-pod KPIs; robust stage4 + CH retry
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Some comments aren't visible on the classic Files Changed page.
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,72 +1,73 @@ | ||
| # adaptive_export_loadtest | ||
| # Adaptive Export (AE) load-test suite | ||
|
|
||
| Load-test + e2e harness for **adaptive_export (AE)** and the dx-steered SOC chain. | ||
| There are exactly **two ways to test**, by design — pick by what you're proving: | ||
| A table-driven Go test suite for the AE write surface. Each experiment is a | ||
| **fixture** (curated input); each measurement is a named **KPI** asserted with | ||
| `testify/require`; one runner drives them against a deployed AE image on a rig. | ||
|
|
||
| | family | needs a live SOC stack? | proves | entry point | | ||
| |---|---|---|---| | ||
| | **A. Fixture-isolation** | No (just ClickHouse) | AE's write behaviour is *deterministic* — injected `kubescape_logs` → exact `forensic_db` rows, across many reps | `harness/run.sh` | | ||
| | **B. Live-attack e2e** | Yes (Pixie + kubescape + CH + AE + dx) | the real chain: attack → detection → DX-steered data-volume reduction → no-loss → NFR | `harness/poc_fire.sh` → `exp_matrix.sh` → `nfr.sh` → `exp_row_reconcile.sh` | | ||
| It replaces the former shell harness (`harness/*.sh` + `stats.py`) — the | ||
| experiments, the measurement scripts, and the reproducibility statistic are now | ||
| Go fixtures, KPI helpers, and asserts under `suite/`. | ||
|
|
||
| `event_time` is unix **SECONDS** end-to-end (the unit the soc Vector kubescape sink emits and the CH DDL TTL/PARTITION assume). Fixtures use seconds. | ||
|
|
||
| --- | ||
|
|
||
| ## A. Fixture-isolation (offline AE proof — no Pixie) | ||
|
|
||
| Injects *controlled* `kubescape_logs` trigger rows (real kubescape is **not** deployed) and a *counted* traffic band, then asserts exactly how much AE writes — so write behaviour is measured deterministically instead of lost in infra noise. | ||
|
|
||
| ```sh | ||
| export KUBECONFIG=<kubeconfig> # or run lab-side with CH_NO_PF=1 | ||
| bash harness/run.sh # full suite: ae_config → E1..E4,E6 → E5 | ||
| EXP=E1 REPS=20 OUT=/tmp/E1.csv bash harness/exp_control.sh # one experiment | ||
| EXP=E8 TICKS=25 INTERVAL=3 bash harness/exp_e8.sh # sustained same-pod (F8 reproducer) | ||
| ``` | ||
| Exact reproducibility ⇔ `harness/stats.py` reports every `*_act` metric with one distinct value (std=0). | ||
|
|
||
| **Scripts:** `run.sh` (orchestrator) · `lib.sh` (CH/kubectl helpers) · `inject.sh` (HTTP INSERT of kubescape_logs) · `ae_config.sh` (AE single-shot load-test mode) · `exp_control.sh` (E1–E4,E6) · `exp_e5.sh` (data-plane volume) · `exp_e8.sh` (sustained same-pod / F8) · `stats.py` (reproducibility verdict). | ||
|
|
||
| ## B. Live-attack e2e (the real chain, on a deployed stack) | ||
|
|
||
| Run on a SOC stack (Pixie vizier Healthy + kubescape netStreaming + CH `forensic_db` + AE + dx). Order: | ||
| ## Layout | ||
|
|
||
| ```sh | ||
| export KUBECONFIG=<kubeconfig> | ||
| # 1. generate the attack signal (idempotent; verifies LDAP egress before returning) | ||
| bash harness/poc_fire.sh | ||
| # 2. data-volume reduction MATRIX — ALL (firehose) vs DX (steered) × {poc,argocd,react2argo} | ||
| CONDITIONS="poc:on react2argo:on" REPS=5 bash harness/exp_matrix.sh | ||
| # 3. NFR — throughput, AE+dx memory under load, verdict/query latency | ||
| bash harness/nfr.sh | ||
| # 4. no-loss — deterministic PEM↔ClickHouse row-level reconciliation for the DX arm | ||
| bash harness/exp_row_reconcile.sh | ||
| | Path | What | | ||
| |------|------| | ||
| | `suite/harness.go` | primitives: ClickHouse-over-HTTP client, kubescape-row injector, control-surface reads, kubectl helpers | | ||
| | `suite/fixtures.go` | the experiment table (control-plane reproducibility cases) + the per-rep runner | | ||
| | `suite/kpi.go` | KPI asserts: `RequireReproducible`, `RequireReconcile`, `RequireExact` | | ||
| | `suite/suite_test.go` | the tests: control-plane reproducibility (live), data-plane reconcile + volume reduction (staged) | | ||
| | `tools/loadgen/` | the counted signal generator (nested Go module) for the data-plane KPIs | | ||
| | `k8s/` | sinks + generator pod templates | | ||
| | `CONTRACTS.md` | the C1–C15 AE implied-contract register | | ||
| | `fixtures/EXPERIMENTS.md` | the experiment catalog + expected outputs | | ||
| | `FINDINGS_AND_BACKLOG.md` | observed contract violations + backlog | | ||
|
|
||
| ## KPIs | ||
|
|
||
| | KPI | Asserts | Was | | ||
| |-----|---------|-----| | ||
| | **Reproducibility** | a metric is one distinct value across all reps (std = 0) | `stats.py` | | ||
| | **Reconcile** | read == wrote == ClickHouse, per protocol table (no loss) | `exp_row_reconcile.sh` | | ||
| | **Reduction** | firehose→steered volume delta — measured & logged, not gated | `exp_matrix.sh` | | ||
| | **NFR / WriteDuration** | throughput/mem/latency; window stays open until `t_end` (C15) | `nfr.sh` / `exp_e8.sh` | | ||
|
|
||
| ## Running | ||
|
|
||
| The suite is **live-only**: it drives a deployed AE image, so `go test ./...` | ||
| skips unless enabled. Run it on the rig's dev-machine (which has Go + kubectl): | ||
|
|
||
| ```bash | ||
| cd suite && go mod tidy # first run only, resolves testify | ||
| AELOAD_LIVE=1 \ | ||
| AELOAD_CH_URL=http://<clickhouse>:8123 \ | ||
| AELOAD_CH_WUSER=ingest_writer AELOAD_CH_WPASS=<pass> \ | ||
| KUBECONFIG=/path/to/kubeconfig \ | ||
| go test -v -run TestControlPlaneReproducibility ./... | ||
| ``` | ||
|
|
||
| **Scripts:** `poc_fire.sh` (attack-signal generator, bob#140-hardened) · `exp_matrix.sh` (reduction matrix, the canonical ALL-vs-DX runner) · `nfr.sh` (throughput/mem/latency) · `exp_row_reconcile.sh` (no-loss). | ||
|
|
||
| > The DX arm needs the load-gen pods bound to a **benign User SBoB** (`kubescape.io/managed-by: User`, `rulePolicies.R0002.processAllowed`) or benign noise gets steered and contaminates the reduction — see `biz/PoC/poc/datavolume/denoise_sbobs/`. | ||
|
|
||
| --- | ||
| Environment: | ||
|
|
||
| ## Layout | ||
| ``` | ||
| fixtures/EXPERIMENTS.md curated kubescape_logs data-set catalog + expected outputs | ||
| harness/ the two families above | ||
| k8s/ isolated sinks + per-rep generator pod (no probes) | ||
| tools/loadgen/ cleanloadgen + httpsink Go sources + Dockerfile | ||
| ``` | ||
| Go unit/e2e tests for AE live with the service: `src/vizier/services/adaptive_export/internal/{trigger,e2e}/*_test.go`. | ||
| | Var | Default | Meaning | | ||
| |-----|---------|---------| | ||
| | `AELOAD_LIVE` | — | must be `1` to run (else skip) | | ||
| | `AELOAD_CH_URL` | `http://127.0.0.1:8123` | ClickHouse HTTP endpoint (port-forward or in-cluster svc) | | ||
| | `AELOAD_CH_USER` / `_PASS` | default user | read credentials | | ||
| | `AELOAD_CH_WUSER` / `_WPASS` | `ingest_writer` | ingest (write) credentials | | ||
| | `AELOAD_AE_NS` / `_DS` | `pl` / `adaptive-export` | AE namespace + DaemonSet | | ||
| | `AELOAD_NODE` | first node | the node whose hostname AE polls | | ||
|
|
||
| See `CONTRACTS.md` (AE implied contracts) and `FINDINGS_AND_BACKLOG.md` (reproduced findings incl. the F8 watermark-poison bug). | ||
| The data-plane reconcile and volume-reduction tests are staged (they need the | ||
| counted signal generator / a lab-owned signal) and skip with a reason until | ||
| `AELOAD_DATAPLANE=1` / `AELOAD_REDUCTION=1` wire them in. | ||
|
|
||
| ## Validation status (honest) | ||
| ## Vocabulary | ||
|
|
||
| | Experiment | Plane | Status | | ||
| |---|---|---| | ||
| | E1 single / E2 dedup / E3 fan-out / E4 boundary / E6 restart-idempotency | control | ✅ exactly reproducible (std=0) on a live rig | | ||
| | E8 sustained same-pod | control | ✅ reproduced the F8 "writes-stop" bug + recovery | | ||
| | E5 volume / E8 data-mode | data | ⏳ authored; pending live validation | | ||
| | Live poc reduction / NFR / no-loss (family B) | data | ✅ validated (aeprod19 + pemdq10 + dx): #33 prefetch verdict 212→18ms; reduction ALL→DX ≫ measured | | ||
| Fixtures carry no CVE identifiers and no adversarial verbs. The control plane is | ||
| pure kubescape-metadata bookkeeping, so its fixtures are named by the property | ||
| under test. Live incident signals (data-plane / reduction) are emitted by the SOC | ||
| lab under its own naming (`java-poc`, `pathogen-ns`, `disease-*`, `Specimen`) and | ||
| triggered here through a lab hook — no payload literals live in this tree. | ||
|
|
||
| ## Removed (consolidation 2026-06) | ||
| Redundant variants folded into the canonical scripts above — deleted: `ae_vs_all.sh`, `vrun.sh`, `exp_poc_reps.sh`, `exp_datavolume_extreme.sh`, `exp_dx_steering_reduction.sh` (→ `exp_matrix.sh`); `exp_ae_nfr_benchmark.sh` (→ `nfr.sh`); `exp_pipeline_reconcile.sh` (→ `exp_row_reconcile.sh`); `exp_dx_validate.sh` (→ `exp_matrix.sh`); `deploy_ae.sh`, `build_gen_image.sh` (superseded by the live stack / kit). | ||
| **External wire stays literal** and is never renamed: kubescape RuleIDs (`R0001`, | ||
| `R0010`, …), Kubernetes API keywords, ClickHouse column/table names, and the | ||
| `forensic_db` schema. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,36 @@ | ||
| # Single pixie-native command to stand up the whole NON-Pixie e2e environment: | ||
| # | ||
| # skaffold deploy -m e2e-nonpixie | ||
| # | ||
| # It pulls each component's Skaffold from that component's golden-source repo, so | ||
| # there is exactly ONE source of truth per component — no manifests duplicated | ||
| # into the pixie tree: | ||
| # | ||
| # - k8sstormcenter/soc (skaffold.yaml, module soc-stack) = the stack: | ||
| # ClickHouse -> kubescape -> vector (+ forensic_db schema, dx delivery) | ||
| # - k8sstormcenter/bob (example/java-poc/skaffold.yaml, module java-poc-apps) = | ||
| # the sample apps: SBoBs -> workloads (java-poc chain + pathogen) | ||
| # | ||
| # Deploy order is: SOC stack first, then the bob apps (SBoBs before workloads). | ||
| # Pixie itself (the `pl` namespace: vizier + adaptive_export) is deployed by | ||
| # Pixie's OWN native Skaffold and overlaid on top — it is intentionally NOT here. | ||
| # | ||
| # k3s only for now. The suite's EnsureE2EStack() helper (suite/deploy.go) invokes | ||
| # this, and can point at local checkouts via AELOAD_SOC_DIR / AELOAD_BOB_DIR. | ||
| apiVersion: skaffold/v4beta11 | ||
| kind: Config | ||
| metadata: | ||
| name: e2e-nonpixie | ||
| requires: | ||
| - git: | ||
| repo: https://github.com/k8sstormcenter/soc | ||
| path: skaffold.yaml | ||
| ref: main | ||
| configs: | ||
| - soc-stack | ||
| - git: | ||
| repo: https://github.com/k8sstormcenter/bob | ||
| path: example/java-poc/skaffold.yaml | ||
| ref: main | ||
| configs: | ||
| - java-poc-apps |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.