Skip to content

Add DROP, SAMPLE, ROUTE and metrics rules to the sandbox runbook - #9

Open
PRIYAM232 wants to merge 1 commit into
mainfrom
docs/sandbox-more-rule-types
Open

PRIYAM232 wants to merge 1 commit into
mainfrom
docs/sandbox-more-rule-types

Conversation

@PRIYAM232

Copy link
Copy Markdown
Owner

What

Adds step 6 to deploy/sandbox/README.md: four more rules that cover the paths the step 4 REDACT/THROTTLE rules don't.

# Rule Covers
5 drop-debug-logs: DROP LOGS log.severity EQUALS DEBUG DROP on logs, the log.severity virtual field
6 sample-initech-traces: SAMPLE TRACES tenant_id EQUALS initech, rate 0.25 trace-consistent SAMPLE
7 route-acme-logs-cold: ROUTE LOGS tenant_id EQUALS acme → cold-storage ROUTE, which reroutes without counting as a drop
8 drop-cache-miss-metric: DROP METRICS metric.name EQUALS search.cache.misses the metrics signal, the metric.name virtual field

For each rule, the section gives the expected ruleset updated line, how the rule behaves, a pass check (PromQL, or a docker logs one-liner), and a reference-run table of measured values.

It also:

  • notes at the top of Going further that its examples assume only the step 4 rules (step 6 holds globex at 0)
  • adds troubleshooting for a mistyped ROUTE destination and for SAMPLE on LOGS being ignored

Why

Step 4 exercises REDACT and THROTTLE only, and the seeded rules are span DROP/SAMPLE rules that match nothing the load generator emits. Before launch, every action and every signal should have a demo someone can reproduce.

How the numbers were produced

  • Where: a separate sandbox from origin/main, with the 3 seeded rules and the 4 step-4 rules in place.
  • How the rules got in: inserted straight into PolicyRule, the same row the dashboard's Create rule action writes. The UI click path wasn't exercised for these four.
  • What matched: every value in the reference table was measured, and each matches what the code predicts.
    • Sync: 4.6s to rules_total 11 / traces 5 / logs 5 / metrics 1 / ignored 0.
    • Rule 5: globex 50 → 0, drop fraction 0.88 → 0.98.
    • Rule 6: initech 60 → 15 traces/min with all 3 spans each, spans dropped 2.29/s.
    • Rule 7: acme 5 → 0 at the backend, 25 routed records per 5s on debug/cold, logs dropped exactly 500/s.
    • Rule 8: metrics dropped 0.20/s, search_cache_misses_total stale while payments_requests_total keeps updating.
    • Proxy: RestartCount stayed at 0.

Docs only; no code or config changes.

🤖 Generated with Claude Code

Step 4 exercises REDACT and THROTTLE only, and the seeded rules are span DROP/SAMPLE rules that match nothing the load generator emits. The new step 6 adds four rules: DROP on logs by log.severity, trace-consistent SAMPLE for one tenant, ROUTE to cold-storage (which reroutes without counting as a drop), and DROP on a metric by metric.name. Each comes with its expected ruleset line, a pass check, and a reference run of measured values.

Also notes that the Going further examples assume only the step 4 rules, and adds troubleshooting for a mistyped ROUTE destination and for SAMPLE on LOGS being ignored.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant