Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
68 commits
Select commit Hold shift + click to select a range
c6515fd
adaptive_export: production AE — streaming export + write-integrity
Jun 8, 2026
390ee45
adaptive_export: ADAPTIVE_PASSTHROUGH firehose loop
entlein Jun 8, 2026
9535139
ci: dx-image workflow — build + publish dx-daemon to ghcr
entlein Jun 9, 2026
4ab9d07
Revert ci: dx-image workflow — wrong repo
entlein Jun 9, 2026
6139e3b
adaptive_export: unit-normalize trigger watermark cursor + load-test …
Jun 16, 2026
fd80e5f
e2e_test/adaptive_export_loadtest: AE fixture-isolation load-test har…
Jun 16, 2026
1001f6d
e2e_test/adaptive_export_loadtest: document AE implied contracts (C1-…
Jun 16, 2026
4e62453
adaptive_export_loadtest: C15 write-duration contract + DX-steering d…
Jun 16, 2026
746421f
adaptive_export/trigger: update test SQL substrings for multiIf norma…
entlein Jun 16, 2026
808a3ea
adaptive_export_loadtest: exp_control uses real now_s event_time (no …
Jun 16, 2026
9798a69
adaptive_export: ADAPTIVE_RECONCILE per-pull write-fidelity instrument
Jun 17, 2026
519bff5
harness: exp_pipeline_reconcile — skip empty-key rows (0 rows != LOSS 1)
Jun 17, 2026
3f6f409
harness: log4shell_fire.sh — reliably fire + restart the log4j-chain …
Jun 17, 2026
239e032
harness: log4shell_fire.sh — detection-signal framing (Cyber Verifica…
Jun 17, 2026
10ad397
adaptive_export(passthrough): precompiled + concurrent firehose, drop…
Jun 17, 2026
f4fe5c4
adaptive_export: bazel BUILD deps for internal/reconcile + pxl compil…
Jun 17, 2026
ee2dcfb
adaptive_export(pxl): raise Pixie 10k result cap via #px:set query flag
Jun 17, 2026
0fa7eb8
adaptive_export/sink: content_type silent-drop contract suite
entlein Jun 9, 2026
1102ce5
adaptive_export_loadtest: DX-steered-vs-ALL datavolume reduction harness
Jun 17, 2026
fed1c6e
adaptive_export_loadtest: deep AE NFR benchmark harness
Jun 18, 2026
7532c87
adaptive_export_loadtest: fix DX-reduction dead-arm (clear stale stee…
Jun 18, 2026
0094ec7
nfr harness: fix lag (dateDiff) + drop racy broker-pct completeness
Jun 18, 2026
e59180a
dx-reduction harness: report ROWS reduction (primary) + bytes (second…
Jun 18, 2026
84eac90
ae deployment: add memory limit (1Gi) + raise cpu limit to 1 core
Jun 18, 2026
00aeaf3
ae bootstrap: separate the secret from the re-applied infra bundle
Jun 18, 2026
d8192aa
dx-reduction harness: fire BOTH attack stages so DX steers the backend
Jun 18, 2026
61ef494
adaptive_export: rename whitelist→allowlist across streaming path + a…
Jun 18, 2026
9feda72
ae(clickhouse): create forensic_db.dx_attack_graph at boot
Jun 18, 2026
2c7cfcf
ae(clickhouse): dx_attack_graph numeric cols Int64/Float64 (px-readable)
Jun 18, 2026
48b100e
adaptive_export(streaming): add #px:set max_output_rows cap flag to s…
Jun 18, 2026
8e7f1c6
ae(clickhouse): create dx_attack_graph_malicious view at boot
Jun 19, 2026
39a2f12
ae(control): /dx/attack_graph ingest endpoint -> ClickHouse
Jun 19, 2026
3b1d484
adaptive_export: convention pass — consolidate CH HTTP, drop dead cod…
entlein Jun 20, 2026
e9c1331
adaptive_export: restore executable bits on harness scripts (post-hea…
entlein Jun 20, 2026
15ee7a3
adaptive_export: lint pass + restore @px load prefix in cmd/BUILD.bazel
entlein Jun 20, 2026
31febbe
adaptive_export: address user review #2 #4 #6 + 4 outstanding CodeRab…
entlein Jun 20, 2026
fdfb451
test(harness): consolidate to one run-picture + e2e CI workflow
Jun 21, 2026
dc644c3
revert(bazel): drop stray buildifier attribute-reorder in stirling co…
Jun 21, 2026
fcab916
ci: fix run-genfiles + run-container-lint on PR 53
entlein Jun 21, 2026
3094068
ci: apply gazelle's actual kwarg order to stirling container_images
entlein Jun 21, 2026
19e84ad
ci: fix container-lint Errors on e2e workflow + new harness scripts
entlein Jun 21, 2026
e0a19dd
ci: silence 6 SHELLCHECK Warnings to clear container-lint exit code
entlein Jun 21, 2026
e6a6237
feat(ae-control): bearer-JWT auth + input validation (CodeRabbit foll…
Jun 21, 2026
714c1fb
fix(ae): remaining CodeRabbit Majors (#53 followup)
Jun 21, 2026
dfdc465
fix(ae-trigger): escape a PollLimit-saturated watermark boundary (fro…
Jun 22, 2026
decf2ae
feat(ae-control): TLS on the control surface (CONTROL_TLS) (#71)
entlein Jun 23, 2026
0c65751
Merge remote-tracking branch 'origin/main' into ae-followup-auth
Jun 23, 2026
e187dc3
test(ae-trigger): differential oracle vs naive reference (incremental…
entlein Jun 24, 2026
0fd9c3f
ci: fix vizier-release Build Release runner label (oracle-16cpu → ora…
entlein Jun 24, 2026
cb81ecd
ci: fix merge-conflict regressions from main pickup (runner labels, u…
entlein Jun 24, 2026
c2642da
fix(ae): address 13 CodeRabbit Go-code findings on PR 68
entlein Jun 24, 2026
7f43c51
ci: carve out private/cockpit + terraform/credentials/cockpit from fi…
entlein Jun 24, 2026
c579e48
Revert "ci: carve out private/cockpit + terraform/credentials/cockpit…
entlein Jun 24, 2026
d94624a
ci: rename private/{cockpit,skaffold_cloud.yaml} so filename-linter a…
entlein Jun 24, 2026
ae41131
terraform: drop fork IaC from PR 68 — belongs on main, not this PR
Jun 28, 2026
6d10b07
fork-infra: drop cockpit, .sops.yaml, e2e workflow from PR 68
Jun 28, 2026
55123ea
Merge remote-tracking branch 'origin/main' into ae-followup-auth
Jul 16, 2026
8340d84
adaptive_export: drop out-of-scope bazel/ui.bzl (fork UI-build fix be…
Jul 16, 2026
0954731
adaptive_export_loadtest: replace shell harness with a Go TDD suite (…
Jul 16, 2026
1de6755
adaptive_export_loadtest: drop the arbitrary reduction-threshold assert
Jul 16, 2026
3624b30
adaptive_export: standardize event_time on nanoseconds (schema + load…
Jul 16, 2026
940ea2c
adaptive_export_loadtest: add evidence.sh (stack integration + nanos …
Jul 16, 2026
e0ef748
adaptive_export_loadtest/suite: commit go.sum (reproducible testify b…
Jul 16, 2026
2886012
adaptive_export_loadtest: test EVERY forensic_db timestamp is nanosec…
Jul 16, 2026
daf881d
adaptive_export_loadtest: drop evidence.sh (the Go schema + reproduci…
Jul 16, 2026
2eb1e6d
adaptive_export_loadtest: java-poc disease calibration (real e2e)
Jul 16, 2026
be04314
test(e2e): single pixie-native command to deploy the non-Pixie stack
Jul 17, 2026
1288ea9
test(e2e): confusion matrix + all-pod KPIs; robust stage4 + CH retry
Jul 17, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .bazelignore
Original file line number Diff line number Diff line change
Expand Up @@ -6,3 +6,7 @@ third_party/threadstacks
tools/chef/nodes
# To keep third party dependencies separate, privy is intentional setup as a separate bazel workspace
src/datagen/pii/privy

# adaptive_export_loadtest generator is a docker-built test tool (see its README);
# build-agent to replace with a bazel target. Until then, keep it out of gazelle.
src/e2e_test/adaptive_export_loadtest/tools/loadgen
4 changes: 2 additions & 2 deletions .github/workflows/cli_release.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ jobs:
image-base-name: "dev_image_with_extras"
build-release:
name: Build Release
runs-on: oracle-16cpu-64gb-x86-64
runs-on: oracle-vm-16cpu-64gb-x86-64
needs: get-dev-image
permissions:
contents: read
Expand Down Expand Up @@ -209,7 +209,7 @@ jobs:
update-gh-artifacts-manifest:
if: |
always() && needs.create-github-release.result == 'success'
runs-on: oracle-8cpu-32gb-x86-64
runs-on: oracle-vm-16cpu-64gb-x86-64
needs: [get-dev-image, create-github-release]
container:
image: ${{ needs.get-dev-image.outputs.image-with-tag }}
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/cloud_release.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ jobs:
image-base-name: "dev_image_with_extras"
build-release:
name: Build Release
runs-on: oracle-16cpu-64gb-x86-64
runs-on: oracle-vm-16cpu-64gb-x86-64
needs: get-dev-image
permissions:
contents: read
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/mirror_demos.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ jobs:
permissions:
contents: read
packages: write
runs-on: oracle-16cpu-64gb-x86-64
runs-on: oracle-vm-16cpu-64gb-x86-64
Comment thread
entlein marked this conversation as resolved.
steps:
- uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v2
with:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/mirror_deps.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ jobs:
permissions:
contents: read
packages: write
runs-on: oracle-16cpu-64gb-x86-64
runs-on: oracle-vm-16cpu-64gb-x86-64
steps:
- uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v2
with:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/mirror_releases.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ jobs:
permissions:
contents: read
packages: write
runs-on: oracle-16cpu-64gb-x86-64
runs-on: oracle-vm-16cpu-64gb-x86-64
steps:
- uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v2
with:
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/operator_release.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ jobs:
image-base-name: "dev_image_with_extras"
build-release:
name: Build Release
runs-on: oracle-16cpu-64gb-x86-64
runs-on: oracle-vm-16cpu-64gb-x86-64
needs: get-dev-image
permissions:
contents: read
Expand Down Expand Up @@ -140,7 +140,7 @@ jobs:
git commit -s -m "Release Helm chart ${VERSION}"
git push origin "gh-pages"
update-gh-artifacts-manifest:
runs-on: oracle-8cpu-32gb-x86-64
runs-on: oracle-vm-16cpu-64gb-x86-64
needs: [get-dev-image, create-github-release]
container:
image: ${{ needs.get-dev-image.outputs.image-with-tag }}
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/perf_common.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ jobs:
ref: ${{ inputs.ref }}
generate-perf-matrix:
needs: get-dev-image-with-extras
runs-on: oracle-16cpu-64gb-x86-64
runs-on: oracle-vm-16cpu-64gb-x86-64
container:
image: ${{ needs.get-dev-image-with-extras.outputs.image-with-tag }}
outputs:
Expand All @@ -57,7 +57,7 @@ jobs:
echo "matrix=${matrix}" >> $GITHUB_OUTPUT
run-perf-eval:
needs: [get-dev-image-with-extras, generate-perf-matrix]
runs-on: oracle-16cpu-64gb-x86-64
runs-on: oracle-vm-16cpu-64gb-x86-64
container:
image: ${{ needs.get-dev-image-with-extras.outputs.image-with-tag }}
strategy:
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/vizier_release.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ jobs:
image-base-name: "dev_image_with_extras"
build-release:
name: Build Release
runs-on: oracle-16cpu-64gb-x86-64
runs-on: oracle-vm-16cpu-64gb-x86-64
needs: get-dev-image
permissions:
contents: read
Expand Down Expand Up @@ -140,7 +140,7 @@ jobs:
git commit -s -m "Release Helm chart Vizier ${VERSION}"
git push origin "gh-pages"
update-gh-artifacts-manifest:
runs-on: oracle-8cpu-32gb-x86-64
runs-on: oracle-vm-16cpu-64gb-x86-64
needs: [get-dev-image, create-github-release]
container:
image: ${{ needs.get-dev-image.outputs.image-with-tag }}
Expand Down
11 changes: 11 additions & 0 deletions k8s/vizier/bootstrap/adaptive_export_deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -88,13 +88,24 @@ spec:
# value: "changeme-ingest"
# - name: CLICKHOUSE_DATABASE
# value: "forensic_db"
# TLS for the control surface (CONTROL_TLS=true). server.crt/key from the
# same service-tls-certs secret the broker/PEM use; without this the dx
# bearer JWT crosses the CNI in cleartext. Harmless when control is off.
volumeMounts:
- name: certs
mountPath: /certs
readOnly: true
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
seccompProfile:
type: RuntimeDefault
volumes:
- name: certs
secret:
secretName: service-tls-certs
securityContext:
runAsUser: 10100
runAsGroup: 10100
Expand Down
14 changes: 14 additions & 0 deletions src/api/go/pxapi/opts.go
Original file line number Diff line number Diff line change
Expand Up @@ -82,3 +82,17 @@ func WithDirectCredsInsecure() ClientOption {
c.insecureDirect = true
}
}

// WithDirectTLSSkipVerify is the secure-by-default option for direct (standalone /
// node-local PEM) connections: the transport IS TLS-encrypted, but the server cert
// is not chain/hostname-verified. Use this instead of WithDirectCredsInsecure when
// the direct endpoint serves TLS with a self-signed / service cert whose SAN does
// not match the node IP (e.g. vizier-pem's direct-query port served with
// service-tls-certs, dialed at HOST_IP). Unlike WithDisableTLSVerification it does
// NOT require a "cluster.local" address, so it works for the node-IP direct dial.
// Bearer creds (the minted JWT) therefore ride an encrypted channel, never plaintext.
func WithDirectTLSSkipVerify() ClientOption {
return func(c *Client) {
c.disableTLSVerification = true
}
}
4 changes: 2 additions & 2 deletions src/e2e_test/adaptive_export_loadtest/CONTRACTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ flowchart TD
PROT["http/dns/pgsql/conn_stats/...<br/>plain MergeTree (NO dedup)"]
end

VEC -->|"C1 ⚠️ event_time UNIT = seconds<br/>C2 ⚠️ hostname = k8s node name"| KL
VEC -->|"C1 event_time UNIT = nanoseconds<br/>C2 ⚠️ hostname = k8s node name"| KL
KL -->|"C3 🔴 event_time monotone ≥ watermark<br/>C4 ⚠️ boundary dedup by content fp"| TRG
TRG --> CTL
CTL -->|"C5 ⚠️ anomaly_hash = f(pid,comm,pod,ns) only"| ATTR
Expand All @@ -56,7 +56,7 @@ flowchart LR

| # | Contract (implied) | Enforced? | Status / fix |
|---|---|---|---|
| C1 | `kubescape_logs.event_time` is unix **seconds** (one unit end-to-end) | trigger auto-detects s/ms/ns; DDL `toDateTime()` assumes seconds | 🔴 **F8 root** — see C3; AE-2 standardize+normalize |
| C1 | `kubescape_logs.event_time` is unix **nanoseconds** (one unit end-to-end) | ✅ DDL converts with `fromUnixTimestamp64Nano`; trigger keeps magnitude-normalization as a defensive net | Vector emits ns; DDL + harness aligned to ns (was the F1/F8 seconds-vs-ns root) |
| C2 | `hostname` = the k8s **node** name (AE polls `WHERE hostname=node`) | ❌ convention only | ⚠️ fixtures must use a real node, else no AE ever reads them |
| C3 | every new anomaly's `event_time` ≥ current watermark (monotone) | ❌ strict HWM filter | 🔴 **F8** — a larger-unit / out-of-order / future row poisons the HWM → all later rows silently dropped. **Fix (PR #53):** normalize cursor to nanos (`chNormEventTimeNanos`); AE-9: ingest-order cursor / bounded-lookback+dedup + below-watermark metric |
| C4 | rows sharing `event_time` at the boundary are deduped by content fingerprint | ✅ `seenAtBoundary` | ok |
Expand Down
123 changes: 62 additions & 61 deletions src/e2e_test/adaptive_export_loadtest/README.md
Original file line number Diff line number Diff line change
@@ -1,72 +1,73 @@
# adaptive_export_loadtest
# Adaptive Export (AE) load-test suite

Load-test + e2e harness for **adaptive_export (AE)** and the dx-steered SOC chain.
There are exactly **two ways to test**, by design — pick by what you're proving:
A table-driven Go test suite for the AE write surface. Each experiment is a
**fixture** (curated input); each measurement is a named **KPI** asserted with
`testify/require`; one runner drives them against a deployed AE image on a rig.

| family | needs a live SOC stack? | proves | entry point |
|---|---|---|---|
| **A. Fixture-isolation** | No (just ClickHouse) | AE's write behaviour is *deterministic* — injected `kubescape_logs` → exact `forensic_db` rows, across many reps | `harness/run.sh` |
| **B. Live-attack e2e** | Yes (Pixie + kubescape + CH + AE + dx) | the real chain: attack → detection → DX-steered data-volume reduction → no-loss → NFR | `harness/poc_fire.sh` → `exp_matrix.sh` → `nfr.sh` → `exp_row_reconcile.sh` |
It replaces the former shell harness (`harness/*.sh` + `stats.py`) — the
experiments, the measurement scripts, and the reproducibility statistic are now
Go fixtures, KPI helpers, and asserts under `suite/`.

`event_time` is unix **SECONDS** end-to-end (the unit the soc Vector kubescape sink emits and the CH DDL TTL/PARTITION assume). Fixtures use seconds.

---

## A. Fixture-isolation (offline AE proof — no Pixie)

Injects *controlled* `kubescape_logs` trigger rows (real kubescape is **not** deployed) and a *counted* traffic band, then asserts exactly how much AE writes — so write behaviour is measured deterministically instead of lost in infra noise.

```sh
export KUBECONFIG=<kubeconfig> # or run lab-side with CH_NO_PF=1
bash harness/run.sh # full suite: ae_config → E1..E4,E6 → E5
EXP=E1 REPS=20 OUT=/tmp/E1.csv bash harness/exp_control.sh # one experiment
EXP=E8 TICKS=25 INTERVAL=3 bash harness/exp_e8.sh # sustained same-pod (F8 reproducer)
```
Exact reproducibility ⇔ `harness/stats.py` reports every `*_act` metric with one distinct value (std=0).

**Scripts:** `run.sh` (orchestrator) · `lib.sh` (CH/kubectl helpers) · `inject.sh` (HTTP INSERT of kubescape_logs) · `ae_config.sh` (AE single-shot load-test mode) · `exp_control.sh` (E1–E4,E6) · `exp_e5.sh` (data-plane volume) · `exp_e8.sh` (sustained same-pod / F8) · `stats.py` (reproducibility verdict).

## B. Live-attack e2e (the real chain, on a deployed stack)

Run on a SOC stack (Pixie vizier Healthy + kubescape netStreaming + CH `forensic_db` + AE + dx). Order:
## Layout

```sh
export KUBECONFIG=<kubeconfig>
# 1. generate the attack signal (idempotent; verifies LDAP egress before returning)
bash harness/poc_fire.sh
# 2. data-volume reduction MATRIX — ALL (firehose) vs DX (steered) × {poc,argocd,react2argo}
CONDITIONS="poc:on react2argo:on" REPS=5 bash harness/exp_matrix.sh
# 3. NFR — throughput, AE+dx memory under load, verdict/query latency
bash harness/nfr.sh
# 4. no-loss — deterministic PEM↔ClickHouse row-level reconciliation for the DX arm
bash harness/exp_row_reconcile.sh
| Path | What |
|------|------|
| `suite/harness.go` | primitives: ClickHouse-over-HTTP client, kubescape-row injector, control-surface reads, kubectl helpers |
| `suite/fixtures.go` | the experiment table (control-plane reproducibility cases) + the per-rep runner |
| `suite/kpi.go` | KPI asserts: `RequireReproducible`, `RequireReconcile`, `RequireExact` |
| `suite/suite_test.go` | the tests: control-plane reproducibility (live), data-plane reconcile + volume reduction (staged) |
| `tools/loadgen/` | the counted signal generator (nested Go module) for the data-plane KPIs |
| `k8s/` | sinks + generator pod templates |
| `CONTRACTS.md` | the C1–C15 AE implied-contract register |
| `fixtures/EXPERIMENTS.md` | the experiment catalog + expected outputs |
| `FINDINGS_AND_BACKLOG.md` | observed contract violations + backlog |

## KPIs

| KPI | Asserts | Was |
|-----|---------|-----|
| **Reproducibility** | a metric is one distinct value across all reps (std = 0) | `stats.py` |
| **Reconcile** | read == wrote == ClickHouse, per protocol table (no loss) | `exp_row_reconcile.sh` |
| **Reduction** | firehose→steered volume delta — measured & logged, not gated | `exp_matrix.sh` |
| **NFR / WriteDuration** | throughput/mem/latency; window stays open until `t_end` (C15) | `nfr.sh` / `exp_e8.sh` |

## Running

The suite is **live-only**: it drives a deployed AE image, so `go test ./...`
skips unless enabled. Run it on the rig's dev-machine (which has Go + kubectl):

```bash
cd suite && go mod tidy # first run only, resolves testify
AELOAD_LIVE=1 \
AELOAD_CH_URL=http://<clickhouse>:8123 \
AELOAD_CH_WUSER=ingest_writer AELOAD_CH_WPASS=<pass> \
KUBECONFIG=/path/to/kubeconfig \
go test -v -run TestControlPlaneReproducibility ./...
```

**Scripts:** `poc_fire.sh` (attack-signal generator, bob#140-hardened) · `exp_matrix.sh` (reduction matrix, the canonical ALL-vs-DX runner) · `nfr.sh` (throughput/mem/latency) · `exp_row_reconcile.sh` (no-loss).

> The DX arm needs the load-gen pods bound to a **benign User SBoB** (`kubescape.io/managed-by: User`, `rulePolicies.R0002.processAllowed`) or benign noise gets steered and contaminates the reduction — see `biz/PoC/poc/datavolume/denoise_sbobs/`.

---
Environment:

## Layout
```
fixtures/EXPERIMENTS.md curated kubescape_logs data-set catalog + expected outputs
harness/ the two families above
k8s/ isolated sinks + per-rep generator pod (no probes)
tools/loadgen/ cleanloadgen + httpsink Go sources + Dockerfile
```
Go unit/e2e tests for AE live with the service: `src/vizier/services/adaptive_export/internal/{trigger,e2e}/*_test.go`.
| Var | Default | Meaning |
|-----|---------|---------|
| `AELOAD_LIVE` | — | must be `1` to run (else skip) |
| `AELOAD_CH_URL` | `http://127.0.0.1:8123` | ClickHouse HTTP endpoint (port-forward or in-cluster svc) |
| `AELOAD_CH_USER` / `_PASS` | default user | read credentials |
| `AELOAD_CH_WUSER` / `_WPASS` | `ingest_writer` | ingest (write) credentials |
| `AELOAD_AE_NS` / `_DS` | `pl` / `adaptive-export` | AE namespace + DaemonSet |
| `AELOAD_NODE` | first node | the node whose hostname AE polls |

See `CONTRACTS.md` (AE implied contracts) and `FINDINGS_AND_BACKLOG.md` (reproduced findings incl. the F8 watermark-poison bug).
The data-plane reconcile and volume-reduction tests are staged (they need the
counted signal generator / a lab-owned signal) and skip with a reason until
`AELOAD_DATAPLANE=1` / `AELOAD_REDUCTION=1` wire them in.

## Validation status (honest)
## Vocabulary

| Experiment | Plane | Status |
|---|---|---|
| E1 single / E2 dedup / E3 fan-out / E4 boundary / E6 restart-idempotency | control | ✅ exactly reproducible (std=0) on a live rig |
| E8 sustained same-pod | control | ✅ reproduced the F8 "writes-stop" bug + recovery |
| E5 volume / E8 data-mode | data | ⏳ authored; pending live validation |
| Live poc reduction / NFR / no-loss (family B) | data | ✅ validated (aeprod19 + pemdq10 + dx): #33 prefetch verdict 212→18ms; reduction ALL→DX ≫ measured |
Fixtures carry no CVE identifiers and no adversarial verbs. The control plane is
pure kubescape-metadata bookkeeping, so its fixtures are named by the property
under test. Live incident signals (data-plane / reduction) are emitted by the SOC
lab under its own naming (`java-poc`, `pathogen-ns`, `disease-*`, `Specimen`) and
triggered here through a lab hook — no payload literals live in this tree.

## Removed (consolidation 2026-06)
Redundant variants folded into the canonical scripts above — deleted: `ae_vs_all.sh`, `vrun.sh`, `exp_poc_reps.sh`, `exp_datavolume_extreme.sh`, `exp_dx_steering_reduction.sh` (→ `exp_matrix.sh`); `exp_ae_nfr_benchmark.sh` (→ `nfr.sh`); `exp_pipeline_reconcile.sh` (→ `exp_row_reconcile.sh`); `exp_dx_validate.sh` (→ `exp_matrix.sh`); `deploy_ae.sh`, `build_gen_image.sh` (superseded by the live stack / kit).
**External wire stays literal** and is never renamed: kubescape RuleIDs (`R0001`,
`R0010`, …), Kubernetes API keywords, ClickHouse column/table names, and the
`forensic_db` schema.
36 changes: 36 additions & 0 deletions src/e2e_test/adaptive_export_loadtest/skaffold.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
# Single pixie-native command to stand up the whole NON-Pixie e2e environment:
#
# skaffold deploy -m e2e-nonpixie
#
# It pulls each component's Skaffold from that component's golden-source repo, so
# there is exactly ONE source of truth per component — no manifests duplicated
# into the pixie tree:
#
# - k8sstormcenter/soc (skaffold.yaml, module soc-stack) = the stack:
# ClickHouse -> kubescape -> vector (+ forensic_db schema, dx delivery)
# - k8sstormcenter/bob (example/java-poc/skaffold.yaml, module java-poc-apps) =
# the sample apps: SBoBs -> workloads (java-poc chain + pathogen)
#
# Deploy order is: SOC stack first, then the bob apps (SBoBs before workloads).
# Pixie itself (the `pl` namespace: vizier + adaptive_export) is deployed by
# Pixie's OWN native Skaffold and overlaid on top — it is intentionally NOT here.
#
# k3s only for now. The suite's EnsureE2EStack() helper (suite/deploy.go) invokes
# this, and can point at local checkouts via AELOAD_SOC_DIR / AELOAD_BOB_DIR.
apiVersion: skaffold/v4beta11
kind: Config
metadata:
name: e2e-nonpixie
requires:
- git:
repo: https://github.com/k8sstormcenter/soc
path: skaffold.yaml
ref: main
configs:
- soc-stack
- git:
repo: https://github.com/k8sstormcenter/bob
path: example/java-poc/skaffold.yaml
ref: main
configs:
- java-poc-apps
Loading
Loading