Repository navigation
Conversation
Expose quota_stats through AdminServer with a default-empty exact-path JSON allowlist. Sample existing quota records without subtree traversal or write-path changes, report unavailable data explicitly, and cover validation, concurrent changes and restart behavior. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This was referenced Sep 28, 2026
Retain upstream SPIFFE authorization and quota statistics as an independent feature branch. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
arkmish
marked this pull request as ready for review
October 8, 2026 05:28
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Expose recorded namespace quota usage and limits for monitoring without recursively scanning the live data tree or changing quota enforcement.
The new AdminServer command is:
Requests require an exact match in
zookeeper.quotaStats.allowedNamespaces, a strictly validated JSON array that defaults to[]./zookeeperpaths are rejected.availableandreasonfields.The allowlist limits which paths can be disclosed; it does not replace AdminServer access controls. Sampling remains non-atomic and may reflect accounting lag.
Tests
Validated
CommandsTest,DataTreeTest,ServerMetricsTest, andZooKeeperQuotaTestusing Maven on JDK 11 with Java 8 API targeting:Coverage includes exact JSON/null semantics, strict path/allowlist validation, numeric bounds, missing and malformed quota records, no ancestor substitution, bounded read-only access, concurrent changes, namespace removal, and server restarts.
Changes that Break Backward Compatibility (Optional)
No client protocol, ACL decision, persistence-format, quota-enforcement, or write-accounting change. The command is default-deny and supplies no production namespace approvals.
available=truemeans the required metadata was readable and valid for the sample. It does not establish freshness, atomic consistency, safe capacity, or an approved operational budget.Documentation (Optional)
Updated
zookeeper-docs/src/main/resources/markdown/zookeeperAdmin.mdwith configuration syntax, command examples, response/error schemas, and sampling limitations.🤖 Generated with GitHub Copilot CLI