Skip to content

fix: move to scalo 2.14.1 and turn PGO and BOLT on for GA - #106

Merged
catinspace-au merged 2 commits into
mainfrom
fix/ga-scalo-2-14
Oct 6, 2026
Merged

catinspace-au merged 2 commits into
mainfrom
fix/ga-scalo-2-14

Conversation

@catinspace-au

Copy link
Copy Markdown
Contributor

GA rebuild of dfe-transform-vector on scalo 2.14.1, with PGO and BOLT back on and a final dependency pass. Two commits: the migration (proved on 2.14.0), then the deps pass, which takes scalo 2.14.1 and cel 0.14.5. 2.14.1's generated Dockerfile, chart, schema and generate-artefacts output are byte-identical to 2.14.0's.

What moved

  • scalo 2.14.0 writes no vendor, licence, copyright or group prefix of its own, so the app names them: HyperI vendor, io.hyperi label namespace, BUSL-1.1, the copyright line.
  • Derived consumer groups keep dfe- through KafkaSource::with_group_prefix("dfe-"). integration::config::dfe_source_derives_topics_and_cg and dfe_source_with_pipeline_name_uses_pipeline_in_cg pin dfe-transform-vector-syslog and dfe-transform-vector-syslog-enriched. On 2.14.0 without the prefix they fail with transform-vector-syslog / transform-vector-syslog-enriched. With it they pass.
  • build.skip_optimize is gone, so the release channel runs PGO and BOLT again (workload_cmd: bash scripts/pgo-workload.sh, 300 s).
  • config/defaults.yaml gives generate-artefacts the ArgoCD repo URL and namespace dfe.
  • ci.yml passes optimize-tier through on dispatch, matching dfe-receiver.
  • The osv-scanner ignore for GHSA-w9wp-h8wv-79jx now names the real blocker (metrics-exporter-opentelemetry 0.2.1 requires opentelemetry ^0.31) and the live tracker, Move the OpenTelemetry stack off 0.31 once metrics-exporter-opentelemetry publishes scalo-rs#281.

GA fixes

  • RESEARCH.md deleted, with its links in README.md and docs/architecture.md. It described an internal architecture this repo no longer has.
  • docs/DESIGN.md no longer promises a dlq config. There is none: a record no retry gets through is dropped and counted in pipeline_dead_letters_dropped_total. The DLQ feature itself stays open as DLQ via Vector-native reroute_dropped sink: the DESIGN.md dlq config was never built #46 (post-ga).
  • README "What tends to bite" said the repo ships no secret marker. The schema has carried one since password was schema'd as SensitiveString. The row now says that is how a field gets x-scalo-secret.

Regenerated

  • Dockerfile: only the scalo header's regenerate line changes. Licence, copyright, vendor and io.hyperi.* labels are byte-identical.
  • docs/config-schema.{json,yaml}: x-scalo-secret beside x-dfe-secret.
  • chart/templates/deployment.yaml (hand-fixed, so carried across by hand): checksum/secret, automountServiceAccountToken: false, the projected service-account volume. chart/values.yaml takes two generator comment updates. Every non-hand-fixed chart file already matched the generator.

Dependencies

  • Lock takes the newest compatible of everything. Floors raised: tokio 1.53.2, clap 4.6.7, thiserror 2.0.21, tokio-test 0.4.6. This covers Renovate fix(deps): update rust-dependencies #76.
  • Held: testcontainers 0.28 (testcontainers-modules 0.15.0, the newest, requires 0.27).
  • No release in over a year: figment, dotenvy, serde_yaml_ng (all three also in scalo's graph) and prometheus-parse (app only, no maintained drop-in).
  • cargo tree -d: one cel. Every remaining duplicate (base64, hashbrown, rand, reqwest 0.12/0.13, syn, toml_edit, ...) is transitive through scalo or testcontainers.

Left as is

  • chart/values.yaml keeps config.source.group_id: dfe-transform-vector-default. Dropping it changes the stock group to dfe-transform-vector, and renders the KEDA trigger with an empty consumerGroup. Stock instances would still share one group, under a new name.

Proof (local, rustc 1.99.0, docker unreachable)

  • cargo nextest run: 346 passed, 9 skipped (all #[ignore], Vector binary or live Kafka). Three Docker tests return early locally and run in CI.
  • cargo clippy --all-targets --all-features -- -D warnings: clean.
  • hyperi-ci check --quick: "Detected language: rust", markdownlint "9 file(s) clean", osv-scanner passed, "quality complete".
  • osv-scanner on the bare lock finds exactly GHSA-w9wp-h8wv-79jx, so the .hyperi-ci.yaml ignore is what passes it.
  • Optimize probe: build.skip_optimize resolved=False, channel=release, allocator=jemalloc, lto=fat, pgo=on, bolt=on.
  • generate-artefacts: argocd-application.yaml repoURL https://github.com/hyperi-io/dfe-transform-vector, path: chart, namespace dfe.

scalo 2.14.0 writes no vendor, licence, copyright or group prefix of its own, so the app names them. The OCI labels carry the HyperI vendor, the io.hyperi namespace, BUSL-1.1 and the copyright line, as before.

Derived consumer groups keep their dfe- prefix through KafkaSource::with_group_prefix. The integration tests pinning dfe-transform-vector-syslog and dfe-transform-vector-syslog-enriched fail on 2.14.0 without it and pass with it.

PGO and BOLT are back on: build.skip_optimize is gone.

config/defaults.yaml gives generate-artefacts the ArgoCD repo URL and the dfe namespace. The hand-fixed chart Deployment takes the generator's checksum/secret annotation and its projected service-account volume with token automount off. The Dockerfile header and config schema are regenerated.

ci.yml passes optimize-tier through on dispatch, as the other apps do. The osv-scanner reason names the real blocker and the live scalo-rs tracker.

RESEARCH.md goes, with its two links: it described an internal architecture this repo no longer has. DESIGN.md stops promising a dlq config the app never had, and the README secret-marker row says how the marker gets onto a field. The 25 markdownlint warnings left in DESIGN.md, MIGRATION.md, README.md and SECURITY.md are cleared.
scalo moves to 2.14.1, which brings cel 0.14.5, the one cel line the suite now shares. Its generated Dockerfile, chart, config schema and generate-artefacts output are byte-identical to 2.14.0's.

Cargo.lock takes the newest compatible release of every crate. The floors move to what the lock now holds for tokio 1.53.2, clap 4.6.7, thiserror 2.0.21 and tokio-test 0.4.6, and the thiserror 1.x copy leaves the graph.

testcontainers stays on 0.27: testcontainers-modules 0.15.0, the newest, requires it.

figment, dotenvy, serde_yaml_ng and prometheus-parse have had no release in over a year. scalo depends on the first three as well, and no maintained drop-in replaces prometheus-parse, so each stays.

The Kafka test broker is already apache/kafka 4.3.1 on the JVM image, pinned by digest.

No open Dependabot alert. Code scanning is not enabled on this repo.
@catinspace-au
catinspace-au merged commit 72f5b95 into main Oct 6, 2026
21 checks passed
@catinspace-au
catinspace-au deleted the fix/ga-scalo-2-14 branch October 6, 2026 03:49
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant