mirror of
https://github.com/XRPLF/rippled.git
synced 2026-10-02 17:58:07 +00:00
docs(telemetry): Drop the remaining account-hashing claims
This commit is contained in:
@@ -27,7 +27,7 @@ include/xrpl/telemetry/ # libxrpl layer: tracing SDK wrapper
|
||||
├── DeterministicIdGenerator.h # trace_id from txHash / prevLedgerHash
|
||||
├── TraceContextPropagator.h # protobuf TraceContext inject/extract (P2P)
|
||||
├── TraceContextValidation.h # Validation of peer-supplied trace context
|
||||
├── Redaction.h # redactAccount() — unconditional address hashing
|
||||
├── Redaction.h # redactAccount() — hashing helper, applied to no span
|
||||
└── GetObjectMetricNames.h # getobject_* metric name constants
|
||||
|
||||
src/libxrpl/telemetry/
|
||||
|
||||
@@ -235,11 +235,11 @@ The authoritative collector config lives in the repo at `docker/telemetry/otel-c
|
||||
`docker/telemetry/otel-collector-config.yaml` is the base config used by the
|
||||
local stack and by CI. It carries **three** pipelines, not one:
|
||||
|
||||
| Pipeline | Receivers | Processors | Exporters |
|
||||
| --------- | ---------------------- | ---------------------------------------------------------------- | ------------------------------------------ |
|
||||
| `traces` | `otlp` | `resource/tier`, `resource/stripsdk`, `attributes/hash`, `batch` | `debug`, `otlp_grpc/tempo`, `span_metrics` |
|
||||
| `metrics` | `otlp`, `span_metrics` | `resource/tier`, `resource/stripsdk`, `batch` | `prometheus` |
|
||||
| `logs` | `file_log` | `resource/logs`, `resource/tier`, `resource/stripsdk`, `batch` | `otlp_http/loki` |
|
||||
| Pipeline | Receivers | Processors | Exporters |
|
||||
| --------- | ---------------------- | -------------------------------------------------------------- | ------------------------------------------ |
|
||||
| `traces` | `otlp` | `resource/tier`, `resource/stripsdk`, `batch` | `debug`, `otlp_grpc/tempo`, `span_metrics` |
|
||||
| `metrics` | `otlp`, `span_metrics` | `resource/tier`, `resource/stripsdk`, `batch` | `prometheus` |
|
||||
| `logs` | `file_log` | `resource/logs`, `resource/tier`, `resource/stripsdk`, `batch` | `otlp_http/loki` |
|
||||
|
||||
Component detail:
|
||||
|
||||
@@ -253,8 +253,8 @@ Component detail:
|
||||
`xrpl.network.type` only when absent); `resource/stripsdk` (drops the
|
||||
`telemetry.sdk.*` attributes); `resource/logs` (`action: upsert` on
|
||||
`service.name` and `job` — only the former becomes a Loki stream label, see
|
||||
the known issue in §5.8.5); `attributes/hash` (hashes
|
||||
`pathfind_source_account` and `pathfind_dest_account`).
|
||||
the known issue in §5.8.5). No processor hashes or drops span attributes:
|
||||
account addresses are public identifiers and are stored as emitted.
|
||||
- **Connector.** `span_metrics` with `namespace: "span"`
|
||||
(`otel-collector-config.yaml:114`) — this is why the derived RED metrics are
|
||||
`span_calls_total` / `span_duration_milliseconds_*`. The connector's own
|
||||
@@ -280,8 +280,7 @@ Component detail:
|
||||
|
||||
Deliberately absent from the base config — do not document them as present:
|
||||
no `memory_limiter`, no `tail_sampling`, no Elastic APM exporter, and no
|
||||
`tx_account` attribute rule (the hashed keys are the two `pathfind_*_account`
|
||||
ones).
|
||||
attribute hashing or redaction rule (account addresses are emitted raw).
|
||||
|
||||
### 5.5.2 Production Configuration
|
||||
|
||||
|
||||
@@ -745,7 +745,6 @@ Differences that change what you will see:
|
||||
| Pipelines | 3: `traces`, `metrics`, `logs` | 5: `traces/metrics`, `traces/store`, `metrics/local`, `metrics/cloud`, `logs` |
|
||||
| Trace sampling | none — 100% of spans reach Tempo | `tail_sampling` keeps **0.5%** (one `probabilistic` policy, `decision_wait: 10s`) on `traces/store` |
|
||||
| `debug` exporter | present on `traces` | dropped |
|
||||
| `attributes/hash` | present on `traces` | **omitted** |
|
||||
| Cloud metric labels | n/a | `transform/cloudlabels` on `metrics/cloud` only |
|
||||
|
||||
Consequences worth knowing before you debug against the cloud stack:
|
||||
@@ -756,17 +755,10 @@ Consequences worth knowing before you debug against the cloud stack:
|
||||
pipeline, so `span_*` rates stay exact while only ~1 trace in 200 is
|
||||
retrievable by trace ID. A trace you can see in a metric may not exist in
|
||||
Tempo.
|
||||
- **The same account carries a different token on each config.** No raw account
|
||||
address leaves the node: the path-finding handlers under
|
||||
`src/xrpld/rpc/handlers/orderbook/` pass both accounts through
|
||||
`redactAccount()` first, which is a prefix of the address's SHA-512Half digest
|
||||
(contract in `include/xrpl/telemetry/Redaction.h`). The base config's
|
||||
`attributes/hash` processor then hashes that token a second time; no cloud
|
||||
pipeline has it. The token is deterministic, so one account stays correlatable
|
||||
across nodes and restarts — but only within one config. A trace stored while
|
||||
the collector ran the base config must not be joined against a trace stored
|
||||
under the cloud config, because the same account appears under two different
|
||||
tokens.
|
||||
- **Account addresses read the same on both configs.** Neither config hashes
|
||||
or drops the `pathfind_*_account` or `tx_*` account attributes: an address is
|
||||
a public ledger identifier and is stored as the node emitted it, so a trace
|
||||
from the base stack joins a trace from the cloud stack by account.
|
||||
|
||||
### Step 4: Verify data reaches Grafana Cloud
|
||||
|
||||
|
||||
@@ -55,8 +55,7 @@
|
||||
* // Edge case -- an expensive value still needs a block guard,
|
||||
* // because arguments are evaluated even when the method is a no-op.
|
||||
* if constexpr (telemetry::kEnabled)
|
||||
* span.setAttribute(
|
||||
* pathfind_span::attr::sourceAccount, redactAccount(account));
|
||||
* span.setAttribute(tx_span::attr::txHash, to_string(txId));
|
||||
* @endcode
|
||||
*/
|
||||
|
||||
|
||||
Reference in New Issue
Block a user