Skip to content

fix: drop FastAPI OTLP export, audit SCIM writes - #789

Merged
catinspace-au merged 1 commit into
mainfrom
fix/otlp-and-scim-audit
Oct 10, 2026
Merged

catinspace-au merged 1 commit into
mainfrom
fix/otlp-and-scim-audit

Conversation

@catinspace-au

Copy link
Copy Markdown
Contributor

Two fixes, both found on the 2.2.1-rc.2 deploy.

Engine OTLP export failing every minute

FastAPI 0.142 added its own OpenTelemetry setup. At startup it reads OTEL_EXPORTER_OTLP_ENDPOINT, assumes http/protobuf whatever the port, and adds a span, metric and log exporter beside the gRPC ones scalo already built. The charts point every app at the collector's gRPC port 4317, so those HTTP/1.1 posts get an HTTP/2 SETTINGS frame back (BadStatusLine('\x00\x00\x06\x04...'), then ConnectionResetError(104)) and fail with "Failed to export metrics batch due to timeout". The engine and the KEDA shim both do it. The hunt runner has no FastAPI app and logs none of it. scalo's own exporters were fine the whole time: the live engine logs readers=[otlp(grpc)->...:4317].

  • The engine API and the KEDA shim pass telemetry={"auto_configure": False} (one constant, dfe_engine/fastapi_telemetry.py). FastAPI's request telemetry still records into scalo's providers and goes out on scalo's gRPC exporters.
  • fastapi floor moves to the locked 0.142.2, since 0.141 rejects the argument.
  • 2.2.0 has it too: it pins engine v1.22.14, which already locks fastapi 0.142.2 (fix: rebuild for GA on scalo 2.31.1 and dfe-schemas 0.2.9 #743).
  • test_otlp_export_env.py puts a real listener on the endpoint the chart env names and asserts the engine API and the shim send it nothing. With the fix reverted it catches /v1/traces and /v1/metrics posts from both apps.

SCIM writes left no audit trail

The SCIM routes create, update and delete accounts and groups for an IdP and wrote no audit event. Every mutating SCIM route now emits the same auth.account.* / auth.group.* event the admin routes do (#787), with details.via = "scim" so an IdP push reads apart from an admin's.

  • Users: POST created, PUT updated, PATCH updated (only when active changes), DELETE deleted.
  • Groups: POST created, PUT updated (who joined, who left), PATCH updated (only when membership changes), DELETE deleted.
  • test_scim_change_audit.py follows test_admin_change_audit.py: one event per write, right name, actor and target, no password or hash in it, and nothing for a no-op PATCH or a refused create.

FastAPI 0.142 added its own OpenTelemetry setup. At startup it reads OTEL_EXPORTER_OTLP_ENDPOINT, assumes http/protobuf whatever the port, and adds a span, metric and log exporter beside the gRPC ones scalo already built. The charts point every app at the collector's gRPC port 4317, so each of those HTTP/1.1 posts got an HTTP/2 SETTINGS frame back and failed: "Failed to export metrics batch due to timeout" every minute on the engine and the KEDA shim. scalo's own exporters were never the problem.

The engine API and the KEDA shim now pass telemetry={"auto_configure": False}. FastAPI's request telemetry still records, into scalo's providers, and leaves on scalo's gRPC exporters only. The fastapi floor moves to the locked 0.142.2, because 0.141 rejects the argument.

The SCIM routes create, update and delete accounts and groups for an IdP and wrote no audit event for any of it. Every mutating SCIM route now emits the same auth.account.* or auth.group.* event the admin routes do, with details.via set to "scim" so an IdP push reads apart from an admin's. A PATCH that changes nothing emits nothing.
@catinspace-au
catinspace-au merged commit 8d254f4 into main Oct 10, 2026
20 checks passed
@catinspace-au
catinspace-au deleted the fix/otlp-and-scim-audit branch October 10, 2026 09:03
@github-actions

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant