Skip to content

feat(compat): add serverless-compat inventory reporter (SVLS-9604) - #161

Open
nina9753 wants to merge 4 commits into
nina.rei/SVLS-9604/compat-inventory-gcpfrom
nina.rei/SVLS-9604/compat-inventory
Open

nina9753 wants to merge 4 commits into
nina.rei/SVLS-9604/compat-inventory-gcpfrom
nina.rei/SVLS-9604/compat-inventory

Conversation

@nina9753

@nina9753 nina9753 commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds the serverless_compat_agent inventory reporter to the shared Compat mini-agent so Azure Functions and GCP Gen1 Cloud Functions appear in Fleet Automation.

  • Startup report fires immediately; periodic reports every 30 minutes
  • Stable process UUID reused across all reports from the same process
  • Bounded retry (3 attempts, exponential backoff) for 429/5xx/transport errors; other 4xx responses are not retried
  • Azure and GCP identity collection is separated from payload construction and transport
  • Newer Gen1 runtimes that expose K_SERVICE and FUNCTION_TARGET remain supported; Gen2 uses the serverless-init sidecar path
  • Lambda and Azure Spring Apps are explicitly skipped
  • Published compat version is embedded during the build; runtime DD_SERVERLESS_COMPAT_VERSION remains the highest-precedence override
  • DD_SERVERLESS_COMPAT_RUNTIME and DD_SERVERLESS_COMPAT_RUNTIME_VERSION override platform-derived runtime metadata
  • UUID is top-level only; platform_version and hostname are intentionally absent
  • GCP metadata-server fallback completes Gen1 identity when region or project is absent from environment variables
  • Reporter failures are contained and never block mini-agent startup or request handling

Stack

  1. feat(compat): add Azure inventory payload core #175 — Azure identity and core payload
  2. feat(compat): add GCP inventory collection #176 — GCP inventory collection
  3. feat(compat): add serverless-compat inventory reporter (SVLS-9604) #161 — reporter, transport, and compat integration (this PR)

This PR is based on #176 and remains the end-to-end-testable top of the stack. Its original URL, comments, and review history are preserved.

Testing

  • cargo test --package datadog-serverless-compat-inventory --locked --offline
  • cargo test --package datadog-serverless-compat --locked --offline
  • cargo clippy --package datadog-serverless-compat-inventory --package datadog-serverless-compat --all-targets --locked --offline -- -D warnings
  • rustfmt and git diff --check

What is not here

No deploy scripts, test logs, or npm binaries; those stay local or on the prototype branch (nina/svls-9604-inventory-payload).

Related

@nina9753
nina9753 marked this pull request as ready for review September 4, 2026 14:24
Copilot AI lite review requested due to automatic review settings September 4, 2026 14:24
@nina9753
nina9753 requested review from a team as code owners September 4, 2026 14:24
@nina9753
nina9753 requested review from duncanpharvey and litianningdatadog and removed request for a team September 4, 2026 14:24
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 4, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-04T14:28:40.954414Z d22f64d Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d22f64d660

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/datadog-serverless-compat/src/inventory.rs Outdated
Comment thread crates/datadog-serverless-compat/src/inventory.rs Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

There are correctness and operability issues in the new inventory reporter (retry attempt semantics vs PR description, inaccurate attempt logging, and several silent error-swallowing/log-level concerns) that should be addressed before approval.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Adds a new background “inventory reporter” to the datadog-serverless-compat mini-agent so supported serverless compat workloads (Azure Functions + GCP Gen1 Cloud Functions) can periodically emit an inventory payload to the Datadog metadata intake for Fleet Automation visibility.

Changes:

  • Spawns a background Tokio task at startup to run the inventory reporter (gated via DD_SERVERLESS_COMPAT_INVENTORY_ENABLED=true).
  • Introduces inventory.rs to build workload identity + payload and send it with bounded retry and optional GCP metadata-server fallback.
  • Adds new crate dependencies needed for payload generation and process UUIDs (serde, serde_json, uuid, and Tokio time).
File summaries
File Description
crates/datadog-serverless-compat/src/main.rs Spawns the inventory reporter task during agent startup.
crates/datadog-serverless-compat/src/inventory.rs Implements inventory gating, identity derivation, payload construction, and send/retry logic + unit tests.
crates/datadog-serverless-compat/Cargo.toml Adds dependencies and enables Tokio time feature to support reporting.
Cargo.lock Updates lockfile for newly added dependencies.
Review details

Suppressed comments (3)

crates/datadog-serverless-compat/src/inventory.rs:210

  • This log message reports the 0-based loop index as an “attempt” count, so it under-reports by 1 (e.g., last attempt logs “after 2 attempts” when 3 total attempts were made). Consider logging attempt + 1 or renaming the field to retries.
                warn!(
                    "inventory: transport error after {attempt} attempts \
                     (report_reason={report_reason}, error={e})"
                );

crates/datadog-serverless-compat/src/inventory.rs:425

  • The metadata-server request transport error is dropped via .ok()?, which makes it hard to understand why region/project resolution failed (you only get a later “identity unavailable” warning). Logging the reqwest error here would make troubleshooting much easier.
        .get(&url)
        .header("Metadata-Flavor", "Google")
        .send()
        .await
        .ok()?;

crates/datadog-serverless-compat/src/inventory.rs:438

  • Reading the metadata-server response body and logging the parsed value currently uses .ok()? (drops the error) and logs the value at INFO. Consider logging the read error and lowering the value log to DEBUG to avoid leaking project IDs into INFO logs.
    let body = resp.text().await.ok()?;
    let result = parse(body.trim());
    info!("inventory: GCP metadata server {label}: {:?}", result);
    result
  • Files reviewed: 3/4 changed files
  • Comments generated: 3
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread crates/datadog-serverless-compat/src/inventory.rs Outdated
Comment thread crates/datadog-serverless-compat/src/inventory.rs Outdated
Comment thread crates/datadog-serverless-compat/src/inventory.rs Outdated
Comment thread crates/datadog-serverless-compat-inventory/src/lib.rs Outdated
Comment thread crates/datadog-serverless-compat/src/inventory.rs Outdated
Comment thread crates/datadog-serverless-compat/src/inventory.rs Outdated

// Runtime: prefer DD_SERVERLESS_COMPAT_RUNTIME (set by language package);
// fall back to FUNCTIONS_WORKER_RUNTIME injected by Azure.
let runtime = env::var("DD_SERVERLESS_COMPAT_RUNTIME")

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Where does DD_SERVERLESS_COMPAT_RUNTIME come from? Is that set in the Serverless Compatibility layer today?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is an optional handoff intended for the language package wrapping the compat binary; it is not set by this Rust binary today. When absent, the reporter uses the platform-derived runtime from AzureMetadata or the GCP runtime environment. I added a test covering the optional override behavior.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Are there plans to set this value somewhere in the future? If not, I'd remove it to reduce any complexity introduced by an unused feature.

Comment thread crates/datadog-serverless-compat/src/inventory.rs Outdated

// Runtime version: prefer DD_SERVERLESS_COMPAT_RUNTIME_VERSION (language package),
// then FUNCTIONS_WORKER_RUNTIME_VERSION, then language-specific vars.
let runtime_ver = env::var("DD_SERVERLESS_COMPAT_RUNTIME_VERSION")

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Where doesDD_SERVERLESS_COMPAT_RUNTIME_VERSION come from? Is that set in the Serverless Compatibility layer today?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Like DD_SERVERLESS_COMPAT_RUNTIME, this is an optional language-package handoff and is not set by the Rust binary itself today. If it is absent, Azure uses FUNCTIONS_WORKER_RUNTIME_VERSION through AzureMetadata, while GCP derives the language version from the platform runtime variables.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same comment as above: #161 (comment)

Comment thread crates/datadog-serverless-compat/src/inventory.rs Outdated
Comment thread crates/datadog-serverless-compat/src/inventory.rs Outdated
@nina9753
nina9753 force-pushed the nina.rei/SVLS-9604/compat-inventory branch from 5a10d29 to 4bb2152 Compare September 28, 2026 17:06
@nina9753
nina9753 force-pushed the nina.rei/SVLS-9604/compat-inventory branch from 4bb2152 to 1c5c819 Compare September 29, 2026 15:29
@nina9753
nina9753 changed the base branch from main to nina.rei/SVLS-9604/compat-inventory-gcp September 29, 2026 15:39
@nina9753
nina9753 requested a review from duncanpharvey October 1, 2026 14:07

@apiarian-datadog apiarian-datadog left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks okay, but lets make sure serverless-compat engineers look at this.

Comment thread crates/inventory/src/reporter.rs
@nina9753
nina9753 added this pull request to stack #177 October 5, 2026 20:05
@nina9753
nina9753 force-pushed the nina.rei/SVLS-9604/compat-inventory branch 2 times, most recently from 64d97d8 to 0ab5886 Compare October 6, 2026 13:20
@nina9753
nina9753 force-pushed the nina.rei/SVLS-9604/compat-inventory branch from 0ab5886 to b7d0f84 Compare October 6, 2026 15:59
Comment on lines +88 to +94
let intake_url = match build_intake_url(&self.dd_site) {
Ok(url) => url,
Err(error) => {
warn!("inventory: invalid DD_SITE, skipping {report_reason} report: {error}");
return;
}
};

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

build_intake_url should probably be build once at startup rather than on every report of telemetry from the inventory agent.

@nina9753
nina9753 force-pushed the nina.rei/SVLS-9604/compat-inventory branch from b7d0f84 to 40b65bc Compare October 7, 2026 00:34

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants