Skip to content

Add allowlisted metadata-only quota telemetry - #155

Open
arkmish wants to merge 2 commits into
branch-3.6from
armishra/zk-quota-stats
Open

arkmish wants to merge 2 commits into
branch-3.6from
armishra/zk-quota-stats

Conversation

@arkmish

@arkmish arkmish commented Sep 28, 2026 •

Copy link
Copy Markdown

Description

Expose recorded namespace quota usage and limits for monitoring without recursively scanning the live data tree or changing quota enforcement.

The new AdminServer command is:

/commands/quota_stats?path=/app

Requests require an exact match in zookeeper.quotaStats.allowedNamespaces, a strictly validated JSON array that defaults to [].

  • Validate the request path and the entire allowlist before accessing the tree. Root and reserved /zookeeper paths are rejected.
  • Read only the namespace's existence and its exact existing quota-stat/limit nodes. Do not substitute an ancestor quota or recount the subtree.
  • Return schema version, path, recorded count/byte usage and limits, plus explicit available and reason fields.
  • Distinguish missing, incomplete, malformed, or changed metadata. Unavailable samples have null numeric fields; native unset limits are null, while configured zero remains zero.
  • Use standard command errors for invalid requests/configuration and avoid echoing raw invalid metadata.

The allowlist limits which paths can be disclosed; it does not replace AdminServer access controls. Sampling remains non-atomic and may reflect accounting lag.

Tests

Validated CommandsTest, DataTreeTest, ServerMetricsTest, and ZooKeeperQuotaTest using Maven on JDK 11 with Java 8 API targeting:

Tests run: 76, Failures: 0, Errors: 0, Skipped: 0
BUILD SUCCESS

Coverage includes exact JSON/null semantics, strict path/allowlist validation, numeric bounds, missing and malformed quota records, no ancestor substitution, bounded read-only access, concurrent changes, namespace removal, and server restarts.

  • Local code review completed

Changes that Break Backward Compatibility (Optional)

No client protocol, ACL decision, persistence-format, quota-enforcement, or write-accounting change. The command is default-deny and supplies no production namespace approvals.

available=true means the required metadata was readable and valid for the sample. It does not establish freshness, atomic consistency, safe capacity, or an approved operational budget.

Documentation (Optional)

Updated zookeeper-docs/src/main/resources/markdown/zookeeperAdmin.md with configuration syntax, command examples, response/error schemas, and sampling limitations.

🤖 Generated with GitHub Copilot CLI

Expose quota_stats through AdminServer with a default-empty exact-path JSON allowlist. Sample existing quota records without subtree traversal or write-path changes, report unavailable data explicitly, and cover validation, concurrent changes and restart behavior.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@arkmish arkmish added quota telemetry Namespace quota usage, limits, and bounded telemetry collection monitoring Observability, collection coverage, dashboards, and alerting labels Sep 30, 2026
Retain upstream SPIFFE authorization and quota statistics as an independent feature branch.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@arkmish
arkmish marked this pull request as ready for review October 8, 2026 05:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

monitoring Observability, collection coverage, dashboards, and alerting quota telemetry Namespace quota usage, limits, and bounded telemetry collection

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant