mirror of
https://github.com/SigNoz/signoz.git
synced 2026-09-22 19:30:43 +01:00
81afa641a2ebb9376d3aba2cecdfd49ba3efcfac
261 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
57268e50b4 |
fix: mark v2 notification channel secrets as password format (#12873)
Some checks failed
build-staging / prepare (push) Has been cancelled
build-staging / js-build (push) Has been cancelled
build-staging / go-build (push) Has been cancelled
build-staging / staging (push) Has been cancelled
cacheci / tests (push) Has been cancelled
Release Drafter / update_release_draft (push) Has been cancelled
#### Description - Tag the secret fields of the v2 notification channel specs with `format:"password"` so the OpenAPI schema hints UIs to obscure them. - Credentials: webhook `password`/`bearerToken`, PagerDuty `routingKey`, Opsgenie/JSM Ops `apiKey`, Jira `apiToken`, incident.io `token`. - Token-bearing URLs the code already models as `SecretURL`: Slack `apiUrl`, webhook `url`, MS Teams/Google Chat `webhookUrl`. - Regenerate `docs/api/openapi.yml` and the frontend client (separate commits). |
||
|
|
9c886be120 |
chore(querybuilder): compile every signal through one storage contract (#12802)
The semantic convention family as first call citizen revealed that the
current state of the query builder needs a bit refactoring for long term
maintenance.
The `FieldMapper` and `ConditionBuilder` are now one abstraction
`Storage`.
A storage now answers
- what the compiler cannot know i.e one read per field key (the bare
SQL, the membership present or absent, what an absent row reads, and
whether the read keeps its type or filters only).
- the fallback for a key metadata does not report
- its traits
- and one Condition compilation part.
And we introduce a new type to use in the system, `Resolved`
```
// Resolved is what resolution produces for one key: its meanings, and how
// they came to be. It is the only thing the compilers receive. Compile it
// with the operator and value it was resolved with.
type Resolved struct {
Key *telemetrytypes.TelemetryFieldKey
Fields []*telemetrytypes.LogicalField
// FromFallback: the fields came from the storage's fallback, not from
// metadata matches.
FromFallback bool
// Ambiguous: the matches held several interpretations.
Ambiguous bool
// Skipped: the storage contributes nothing for this key.
Skipped bool
Warnings []string
}
```
The prepared SQL has no changes, where it changed, it specifically made
the expression better by removing the redundant part.
- The prepared SQL remains identical with this refactoring
- No changes to integration tests
Assisted-by: Claude Fable 5.1
|
||
|
|
c8e9e362f7 |
feat: add spec for text panel (#12711)
Some checks failed
build-staging / prepare (push) Has been cancelled
cacheci / tests (push) Has been cancelled
Release Drafter / update_release_draft (push) Has been cancelled
build-staging / js-build (push) Has been cancelled
build-staging / go-build (push) Has been cancelled
build-staging / staging (push) Has been cancelled
#### Description Add a new plugin schema for text panel. This also adds a check on the query count. If the panel is text, then number of queries should be zero, otherwise it should be 1. Frontend changes to be built on top of this #### Issues closed by this PR Closes https://github.com/SigNoz/pulse-pod/issues/303 Closes https://github.com/SigNoz/pulse-pod/issues/221 --------- Co-authored-by: Abhi kumar <ahrefabhi@gmail.com> |
||
|
|
4175f84815 |
feat: add remaining v2 notification channel apis (#12786)
Some checks failed
build-staging / prepare (push) Has been cancelled
build-staging / js-build (push) Has been cancelled
build-staging / go-build (push) Has been cancelled
build-staging / staging (push) Has been cancelled
cacheci / tests (push) Has been cancelled
Release Drafter / update_release_draft (push) Has been cancelled
<!--A few plain bullets saying what changed and why, for a reviewer skimming it - not a wall of text, not a restatement of the diff, not generated boilerplate.--> #### Description Create v2 API already added, this PR adds get, update, list, delete, and test APIs. List API adds sorting, filtering, and pagination. <!--Reference issues using `Closes #issue-number` to enable automatic closure on merge. --> #### Issues closed by this PR Closes https://github.com/SigNoz/pulse-pod/issues/330 Closes https://github.com/SigNoz/pulse-pod/issues/237 |
||
|
|
fd032291f9 |
feat: add heatmap support in query (#12764)
<!--A few plain bullets saying what changed and why, for a reviewer skimming it - not a wall of text, not a restatement of the diff, not generated boilerplate.--> #### Description Heatmap support here is only for metrics (except exponential histograms) via all three query types: builder, clickhouse and promql. Logs and traces can be plugged in into this later. <!--Reference issues using `Closes #issue-number` to enable automatic closure on merge. --> #### Issues closed by this PR Closes https://github.com/SigNoz/pulse-pod/issues/311 |
||
|
|
c41899f2eb |
feat: support ai trace alerts (#12783)
#### Description - Add the `AI_TRACES_BASED_ALERT` alert type so alerts can be built with the AI explorer's `builder_ai_query`. - Treat AI trace queries like trace queries for new-series filtering and related links. - Related links for AI alerts open the AI observability explorer and tag the shared query as `builder_ai_query`, so `trace.*` aggregate fields in the filter resolve. Existing logs and traces links are unchanged. - Rule history timeline and top-contributor responses gain `relatedAITracesLink`; AI alerts populate it and leave `relatedTracesLink` empty so the frontend can route without checking the alert type. <!--Reference issues using `Closes #issue-number` to enable automatic closure on merge. --> #### Issues closed by this PR Closes https://github.com/SigNoz/engineering-pod/issues/6021 #### Additional Information Notifications keep the existing `related_traces` annotation, now carrying the AI explorer URL, so every channel and `$trace.url` template keeps working. |
||
|
|
a6346183e8 |
feat(traces-qb): read span attributes from the JSON column (evolution-gated) (#12715)
#### Description Enables the v5 traces query builder to read span attributes from the native `attributes` `JSON(max_dynamic_paths=0)` column, alongside the legacy `attributes_string/number/bool` maps, which will get deprecated over time once the dual ingestion can be stopped. - **Evolution-gated rollout.** A key resolves to the JSON column only once its column-evolution set names `attributes`; with no such entry it resolves to the Map column exactly as before. - **Negative operators** - In currently live system, records with missing keys for number/bool types are included in the negative operator queries while string data type is not included. So we are preserving the same be - Data-type-unspecified attribute keys keep the existing `CandidateKeys`/synthesis path (no branch-flip of the most common query shape) - will be fixed in https://github.com/SigNoz/engineering-pod/issues/6018 Part of https://github.com/SigNoz/engineering-pod/issues/5878 #### Additional Information First of a stacked series. Using json in span listing and other module like waterfall, flamegraph will be follow up changes tracked in https://github.com/SigNoz/engineering-pod/issues/5967 --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
8e00c04056 |
refactor(qb): quote field names with the ClickHouse quoting helpers (#12593)
#### Description
- Every user-controlled field name that reaches generated SQL goes
through the new `pkg/clickhousesql` package (`Identifier`,
`StringLiteral`, `Literal`, `LikePattern`): map reads and `mapContains`,
JSON sub-column paths and the JSON body access plan, labels, fingerprint
labels, materialized column names, select aliases, group-by and order-by
references, the legacy string-body JSONPath, and the raw SQL in the
trace funnel, trace detail and infra monitoring modules. Filter
expressions built from request or telemetry values use
`querybuilder.FilterStringLiteral`. The same package now also renders
dashboard variable values in the querier, LIKE patterns in the metadata
store and label lists in the PromQL transpiler, which each had their own
escaping.
- A `$` followed by a digit, `{` or `?` is written as `\x24`, which
ClickHouse decodes in identifiers and literals. Those are the forms the
tools react to: go-sqlbuilder resolves `$0` in a compiled fragment to
its own WHERE clause and recurses until the stack overflows, and
clickhouse-go rejects a query mixing `$<digits>` with `?` arguments. Any
other `$` stays literal, so materialized column names keep their `$$`
and render exactly as before; a key like `http.2xx` becomes ``
`attribute_string_http$\x242xx` `` instead of failing in the driver.
- Compiled sqlbuilder fragments (Select, GroupBy, OrderBy, raw Where
text) are wrapped with `sqlbuilder.Escape`; the metrics builder escapes
its compiled time-series subquery, which is compiled a second time when
joined.
- The raw statement validator (`ErrIfStatementIsNotValid`,
`LogIfStatementIsNotValid`) moves from
`pkg/querybuilder/clickhouse_sql.go` to
`pkg/clickhousesql/statement.go`. Its `Code*` identifiers drop the
`ClickHouseSQL` prefix; the code strings are unchanged.
- Unit tests round-trip the helpers over hostile names and drive them
through the modules' raw SQL;
`tests/integration/tests/queriercommon/08_field_name_quoting.py` and
`querier_json_body/07_field_name_quoting.py` query such names through
the logs, traces and metrics builders against a real ClickHouse.
#### Additional Information
- `docs/contributing/go/clickhousesql.md` documents the quoting
functions, where `sqlbuilder.Escape` belongs, the `$` rule and the
statement validator; `.claude/rules/go-contrib.md` points at it.
- `pkg/clickhousesql` is a leaf package so `telemetrytypes` (JSON access
plan) and `querybuilder` share one implementation without a cycle.
- For names without special characters the generated SQL is byte
identical.
- Not covered here: the legacy v3/v4 query_range builders and the
`pkg/query-service/utils` quoting helpers (`QuoteEscapedString`,
`QuoteEscapedStringForContains`, `ClickHouseFormattedValue`,
`AddBackTickToFormatTag`), the collector's `JSONSubColumnIndexExpr`, and
aggregation arguments naming a key that contains a backtick (rejected by
the SQL parser, a 500 as before).
🤖 Generated with [Claude Code](https://claude.com/claude-code)
|
||
|
|
1419e03ec1 |
feat(apiserver): add tls support to http server (#12830)
#### Description
- Adds optional TLS to `pkg/http/server`, exposed under `apiserver.tls`:
`enabled`, `cert_file`, `key_file`, `min_version` ("1.2" or "1.3").
- When enabled, the apiserver loads the key pair at startup and serves
HTTPS via `ListenAndServeTLS`; disabled by default, no behavior change
otherwise.
- Env: `SIGNOZ_APISERVER_TLS_ENABLED`,
`SIGNOZ_APISERVER_TLS_CERT__FILE`, `SIGNOZ_APISERVER_TLS_KEY__FILE`,
`SIGNOZ_APISERVER_TLS_MIN__VERSION`.
- Adds `.claude/rules/go-test.md`; the new http server tests follow it.
- Part of SigNoz/platform-pod#2302 — covers the apiserver HTTP piece
only.
|
||
|
|
c9ae10b1c0 |
feat(apiserver): move apiserver to registry and make it configurable (#12493)
Some checks failed
build-staging / prepare (push) Has been cancelled
build-staging / js-build (push) Has been cancelled
build-staging / go-build (push) Has been cancelled
build-staging / staging (push) Has been cancelled
cacheci / tests (push) Has been cancelled
Release Drafter / update_release_draft (push) Has been cancelled
#### Description - Make server port configurable so multiple instances can be started for agentic development and testing. - Add `make go-stop` to make it easier to restart server by agents. It does a graceful stop to allow the Prometheus metrics exporter port to shutdown otherwise that port remain occupied. - Add make target for generating the OpenAPI specs. - Documents the above in `docs/contributing/development.md` under "How do I run more than one instance?", including `make go-stop` in the basic backend flow. --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
861380dc65 |
feat: add create v2 api for notification channels (#12638)
<!--A few plain bullets saying what changed and why, for a reviewer
skimming it - not a wall of text, not a restatement of the diff, not
generated boilerplate.-->
#### Description
This PR adds one endpoint, `POST /api/v2/notification_channels`, whose
typed `{name, displayName, config:{kind, spec}}` body replaces v1's
pass-through Alertmanager receiver JSON. v1 routes are deliberately
untouched, so the diff is near-purely additive.
List/get/update/delete/test come in the next PR.
<!--Reference issues using `Closes #issue-number` to enable automatic
closure on merge. -->
#### Issues closed by this PR
Closes https://github.com/SigNoz/pulse-pod/issues/296
<!--Anything reviewers should keep in mind while reviewing -->
Eventually references (rules, routing policies) migrate onto
internal_name, freeing name to become a user-editable display name. But
that will happen post rules migration so that all rules are on v2
<!--Please delete paragraphs that you did not use before submitting.-->
|
||
|
|
0f36cb9334 |
feat(subscription): add subscription endpoints with resource authz (#12767)
#### Description - Adds a `subscription` domain: `POST`, `PUT`, and `GET /api/v1/subscriptions`, wired with `CheckResources` + `ResourceDef`s on the `subscription` metaresource (`create`, `list` + `update`, `read`). Community gets a noop implementation; enterprise talks to Zeus. - Migration `125_add_subscription_tuples` backfills the admin subscription tuples for existing organizations. - The legacy `/api/v1/checkout`, `/api/v1/billing`, and `/api/v1/portal` routes are untouched; they are deleted once the frontend has moved. #### Additional Information Part of SigNoz/platform-pod#3091. |
||
|
|
7faab60ea7 |
feat(authz): enable FGA for ingestion keys and limits (#12626)
#### Description - Moves all ingestion key and limit routes from the legacy `EditAccess` gate to `CheckResources` + `ResourceDef`s (kinds `ingestion-key` / `ingestion-limit`) with scoped security schemes. - Limit create checks `create` on the limit plus `attach` on the parent key; limit delete checks `delete` plus `detach`, resolving the parent key via the new upstream get-limit call. - Grants `attach`/`detach` on `ingestion-key` to the admin and editor managed roles; migration 120 backfills all ingestion tuples for existing organizations and refreshes the managed roles' `transaction_groups`. Stacked on #12625. #### Issues closed by this PR Closes SigNoz/platform-pod#2651 #### Additional Information - Wiremock fixtures now use UUID key/limit IDs — the metaresource FGA selector only accepts UUIDs. - Delete requests make one extra upstream GET (parent-key resolution) before the authz verdict, mirroring the serviceaccount extractor pattern. |
||
|
|
a75442f31e |
fix: add quick filters v2 api to support TelemetryFieldKey (#12698)
Some checks failed
build-staging / staging (push) Has been cancelled
build-staging / prepare (push) Has been cancelled
build-staging / js-build (push) Has been cancelled
build-staging / go-build (push) Has been cancelled
cacheci / tests (push) Has been cancelled
Release Drafter / update_release_draft (push) Has been cancelled
#### Description The old API didn't support telemetryFieldKey, so adding a new v2 API to support it. This PR * Migrates old data to the new one. * Existing API's now internally stores it in the new struct so that they don't break the UI. <!--Reference issues using `Closes #issue-number` to enable automatic closure on merge. --> #### Issues closed by this PR Closes https://github.com/SigNoz/engineering-pod/issues/5947 ## Additional details * the old api is safe with new field as it is just a subset of it. |
||
|
|
52588c4582 |
fix: support for related values in ai field values (#12716)
#### Description Adds support for related values in ai observability field values. <!--Reference issues using `Closes #issue-number` to enable automatic closure on merge. --> #### Issues closed by this PR Closes https://github.com/SigNoz/engineering-pod/issues/5975 |
||
|
|
b3b547f34a |
feat(gateway): add first-class ingestion limit APIs (#12625)
#### Description
- Adds first-class ingestion limit APIs under
`/api/v2/gateway/ingestion_limits`: create (`keyId` in body), get,
update, and delete by `{limitId}`. Get proxies the new upstream `GET
/v1/workspaces/me/limits/{limitID}`.
- Adds key read APIs: `GET /api/v2/gateway/ingestion_keys/{keyId}` (key
by id — upstream does not embed limits here) and `GET
/api/v2/gateway/ingestion_keys/{keyId}/limits` (limits for a key, with
current-period usage metrics).
- Marks the existing limit routes (`POST
/ingestion_keys/{keyId}/limits`, `PATCH/DELETE
/ingestion_keys/limits/{limitId}`) as deprecated; they keep working
unchanged.
- Renames the old create body to `DeprecatedPostableIngestionKeyLimit`;
`PostableIngestionKeyLimit` is now the first-class body carrying
`keyId`. Handlers decode via `binding.JSON` and the create response is
`types.Identifiable`.
Part of SigNoz/platform-pod#2651.
#### Additional Information
- OpenAPI spec and the generated frontend client are regenerated; the UI
stays on the deprecated routes for now.
- Requires the upstream get-by-id endpoints from
SigNoz/opentelemetry-gateway#96 (merged and deployed).
|
||
|
|
e84a61d43f |
feat(alert-channel-integrations): incidentio channel integration (#12644)
## Description Adds **incident.io** as a native alert notification channel, using incident.io's HTTP alert source (Alert Events V2 API) - A channel is configured with the alert source's **URL + token**; title and description templates are prefilled with the same defaults as Jira/JSM. - Alerts fire and auto-resolve in incident.io; the description is markdown (incident.io renders it natively) and carries the usual deep links — **View in SigNoz, related logs, related traces**. - All rule labels (severity, team, custom labels) are sent as **metadata**, so users can map them to incident.io attributes and route/escalate on them. Notes and decisions for the reviewer (full details in the [discussion ticket and doc](https://github.com/SigNoz/pulse-pod/issues/171)): - **Dedup:** one incident.io alert per notification group, keyed by the group key hash (same identity Jira uses). A resolve targets the same key; re-fires after resolve correctly open a fresh alert — no key rotation needed. - **Repeat notifications are no-ops on incident.io** (it drops duplicate firing events) — unlike Jira, we cannot append updated values to an open alert; operators click through to SigNoz for current values. - **Limits:** description capped client-side under incident.io's documented 512 KB payload limit; retries only on 429/5xx (documented limit: 120 events/min per source). - **Channel-level metadata:** optional key-value pairs on the channel config, merged into every event's metadata on top of the alert's labels (channel wins on key clash — Opsgenie precedent). Values are template-expanded; a value that fails to expand is sent raw with a warning logged, so delivery never breaks on a bad template. - Upstream alertmanager ships its own basic incident.io notifier — our config **shadows it** so the SigNoz notifier (templates, dedup, metadata) handles delivery. - Frontend (channel form) follows in a stacked PR. ## Issues closed by this PR Closes SigNoz/pulse-pod#172 --------- Co-authored-by: Naman Verma <naman.verma@signoz.io> |
||
|
|
afb1eb4a41 |
feat(licensing): add v4 license endpoints with resource authz (#12731)
Some checks failed
build-staging / prepare (push) Has been cancelled
build-staging / js-build (push) Has been cancelled
build-staging / go-build (push) Has been cancelled
build-staging / staging (push) Has been cancelled
cacheci / tests (push) Has been cancelled
Release Drafter / update_release_draft (push) Has been cancelled
#### Description - Adds strongly typed `/api/v4/licenses` endpoints on the apiserver with OpenAPI definitions: activate, list, get, refresh, delete, and `GET /api/v4/licenses/active`. - Wires resource authz (`license:create/list/read/update/delete`) via `CheckResources`; `GET /active` is `OpenAccess` and never includes the license key — the key is returned only by the FGA-gated get-by-id, so orgs can grant `license:read` selectively. Migration 118 backfills license tuples for existing orgs. - Delete is allowed only for non-cloud licenses; licenses managed by SigNoz Cloud are rejected. - v4 responses are camelCase with lowercase enum values; v3 routes and stored license data are unchanged. #### Issues closed by this PR Closes https://github.com/SigNoz/platform-pod/issues/3076 |
||
|
|
160a1b018c |
feat(alert-channel-integrations): jira + jsm ops channel backend (#12478)
#### Description Adds two Atlassian alert channels. Backend only — frontend is #12488; channels are created via the API. **Jira issues — `jira_configs`** - A firing alert creates a Jira Cloud issue; when the alert resolves, the issue is transitioned to done. A re-fire within 3 days reopens the same issue instead of creating a new one. 3 days is default but can be edited via frontend form. - The issue body is rich **Atlassian Document Format (ADF)**: a status panel, the rendered alert description, and deep-links back to SigNoz. - Re-fires keep the issue in sync (summary and description are refreshed), and every notification after the first — re-fire, resolve, reopen — also posts a **comment** carrying the same rich ADF snapshot, so the issue holds a full lifecycle timeline. - Per-rule custom notification templates (title/body) are honored, same as every other channel; multi-alert custom bodies render as divider-separated sections. - Auth is Atlassian email + API token; Atlassian **service accounts** also work (routed via the `api.atlassian.com` gateway automatically — the cloud id is resolved server-side and client-supplied values are ignored). Jira Cloud only. **JSM Ops alerts — `jsmops_configs`** - A firing alert opens a JSM Operations alert (the ex-Opsgenie alert product); resolve **closes** it. A fire after close opens a fresh alert — there is no reopen window. - Re-fires dedupe into the same alert and increment its count. The alert description keeps the first-fire snapshot; the value-over-time story lives in the notes. - Every fire and the resolve appends a **note** to the alert. JSM Ops notes support **plain text only** (they render neither HTML nor markdown), so notes use a new plain-text renderer with links flattened to `text (url)`. - The alert description supports JSM's **HTML subset**, rendered from the same markdown templates. - Auth is the JSM integration API key. No region/site config needed. **Also in this PR** - Unit tests for both config types, both notifiers, and the new ADF + plain-text renderers. - OpenAPI spec regenerated (adds `jsmops_configs`). #### Issues closed by this PR Closes SigNoz/pulse-pod#168 · Discussion: SigNoz/pulse-pod#169 #### Screenshots / Screen Recordings Jira alert issue: <img width="1171" height="739" alt="Screenshot 2026-08-18 at 12 49 31 PM" src="https://github.com/user-attachments/assets/1ec74757-5d4d-4534-a5ca-13bed07cce72" /> Jira issue comments as a timeline: <img width="1034" height="746" alt="Screenshot 2026-08-18 at 12 50 32 PM" src="https://github.com/user-attachments/assets/09afb687-b62b-4eb3-86ab-39489e38513e" /> JSM Ops alerts page look: <img width="1317" height="460" alt="Screenshot 2026-08-18 at 12 52 29 PM" src="https://github.com/user-attachments/assets/dd5a60b5-ea6c-49b7-afde-f3b2c72b178a" /> JSM Ops alerts main body + comment timeline ( comments only support plain text today ) : <img width="1323" height="784" alt="Screenshot 2026-08-18 at 12 53 10 PM" src="https://github.com/user-attachments/assets/871fb91c-307a-4c67-b2c4-bc9548506cbc" /> #### Additional Information Notes for reviewers: - Jira shadows upstream Alertmanager's `jira_configs` so our notifier handles it instead of upstream's; this needs a small dedupe in `PostableChannel.JSONSchema()` and leaves every other channel type untouched. - JSM Ops reuses the existing Opsgenie notifier; all new behaviour sits behind a single `advancedFeatures` flag, so plain Opsgenie is unchanged when it's off. - `send_resolved` defaults off for both channels, so resolve-time behaviour (Jira transition, JSM close + resolved note) needs it set on the channel; the frontend will send it on by default. - Notes are best-effort: a permanently-failed note (e.g. the first-fire note racing JSM's asynchronous alert create) is dropped with a warning instead of failing the whole notification. Nothing is lost — that first datapoint is already in the alert body; retryable failures (429) still retry. --------- Co-authored-by: Naman Verma <naman.verma@signoz.io> |
||
|
|
7eb610287e |
feat: system dashboards (#12620)
#### Description Adding support for system dashboards. * as of now updates are only through new versions in the file. * user cannot update the dashboard * For now kept the dashboard content empty and will raise it separately. Closes https://github.com/SigNoz/engineering-pod/issues/4501 |
||
|
|
4d015a927e |
perf(clickhouseprometheusv2): skip the series lookup for statically named transpiled units (#12728)
Some checks failed
build-staging / prepare (push) Has been cancelled
build-staging / js-build (push) Has been cancelled
build-staging / go-build (push) Has been cancelled
build-staging / staging (push) Has been cancelled
cacheci / tests (push) Has been cancelled
Release Drafter / update_release_draft (push) Has been cancelled
## Description <img width="1420" height="516" alt="image" src="https://github.com/user-attachments/assets/cc536314-71d2-4750-b394-d53c41ac7d91" /> the un-needed query contributed to this data read to query service, which had a purpose in earlier dev cycle but not longer needed. |
||
|
|
abebea532b |
feat(prometheus): add the Prometheus query API under a /prometheus prefix (#12093)
#### Description
- Adds `GET|POST /prometheus/api/v1/query_range` and
`/prometheus/api/v1/query` (`pkg/prometheus/promapi`), following the
Prometheus HTTP API contract: float-unix or RFC3339 times, float-seconds
or duration-string durations, the `{status, data, errorType, error,
warnings, infos}` envelope with Prometheus' status codes, and the
11,000-point cap.
- The `/prometheus` prefix works as a drop-in Prometheus base URL:
Grafana's Prometheus data source, promtool, and the PromQL compliance
tester append `/api/v1/*` to a base URL, so they can point at SigNoz
unmodified. Same layout as Mimir/Cortex.
- Wired through `signoz.Handlers` (`prometheus.Handler` interface,
constructed in `NewHandlers`) like the other domain handlers.
- Range queries serve through the `RangeExecutor` capability when the
provider has it, so a clickhousev2-serving deployment transpiles through
these endpoints too.
- New `promapiconformance` integration suite: the frozen promqltest
corpus replayed against these endpoints with `prometheus::provider:
clickhousev2` — the two paths nothing else exercises (v2 as serving
provider, and this API surface). Instant cases go through `/query` with
a real `time` parameter. The `instant-coarse` corpus variants are
skipped — they exist only to encode instant evals as coarse ranges for
the v5 API, and their transpiled coarse-step serving is already covered
and ledgered by promqlconformance's clickhousev2 leg — so this suite
asserts zero divergences with no ledger of its own.
- Purely additive: the existing `GET /api/v1/query_range` and `GET
/api/v1/query` handlers are untouched. `openapi.yml` is generated and
these mux-registered routes are outside the generator, so their
documentation is the upstream Prometheus API contract they follow.
#### Additional Information
Final slice of the clickhouseprometheusv2 stack (#12323, #12324, #12325
— merged). Legacy endpoint removal, if ever, is a separate change after
usage drains.
|
||
|
|
5069bf80b0 |
feat(authz): enable FGA for deployment hosts (#12699)
Some checks failed
build-staging / prepare (push) Has been cancelled
cacheci / tests (push) Has been cancelled
Release Drafter / update_release_draft (push) Has been cancelled
build-staging / js-build (push) Has been cancelled
build-staging / go-build (push) Has been cancelled
build-staging / staging (push) Has been cancelled
#### Description - Deployment host routes (`GET`/`PUT /api/v2/zeus/hosts`) now use `CheckResources` + `ResourceDef` instead of the coarse `ViewAccess`/`AdminAccess` gates — per-resource FGA checks on enterprise, role gate on community. - New `deployment-host` metaresource kind with `list`/`update` verbs — the GET returns the deployment's host collection and the PUT upserts the single editable host. Admins get `list`+`update`, editors and viewers get `list`, preserving current behavior. - Migration `118_add_deployment_host_tuples` backfills the tuples for existing organizations and re-syncs the stored managed-role transaction groups; new organizations get both from the registry at bootstrap. - Regenerated OpenAPI spec and transaction-groups schema: the operations advertise `deployment-host:list`/`deployment-host:update` scopes instead of `VIEWER`/`ADMIN`. - Added `deploymenthost/01_authz.py` covering managed-role gating, custom-role `list`/`update` grants, and rejection of verbs the resource does not support. #### Issues closed by this PR Closes SigNoz/platform-pod#2652 |
||
|
|
1b8155fea9 |
chore(featureflag): make features endpoint open access (#12704)
#### Description - Changes `GET /api/v1/features` from `ViewAccess` to `OpenAccess` in both editions so every authenticated user, including those on custom roles, can read feature flags. - Feature flags describe the org's plan, not the caller's privileges, and the frontend needs them to boot. With #12700 making the active license readable by every authenticated user, the flags must be readable too — otherwise custom-role users load the license but hang on the flags fetch. - Applies the same change to the flagger endpoint `GET /api/v2/features` so the v2 client behaves identically when the frontend migrates to it. #### Issues closed by this PR Closes: https://github.com/SigNoz/platform-pod/issues/2653 |
||
|
|
dac406eb93 |
feat: add support for quering scope fields in traces (#10920)
### 📄 Summary Add support for instrumentation scope for traces. PR on collector - https://github.com/SigNoz/signoz-otel-collector/pull/811 #### Screenshots / Screen Recordings (if applicable) <img width="468" height="298" alt="image" src="https://github.com/user-attachments/assets/03335ca3-a1c5-428b-9bfa-cd1796f735df" /> #### Issues closed by this PR https://github.com/SigNoz/signoz/issues/5319 |
||
|
|
02c5555a48 |
fix: add ai_observability to saved views (#12675)
Some checks failed
build-staging / prepare (push) Has been cancelled
build-staging / js-build (push) Has been cancelled
build-staging / go-build (push) Has been cancelled
build-staging / staging (push) Has been cancelled
cacheci / tests (push) Has been cancelled
Release Drafter / update_release_draft (push) Has been cancelled
#### Description * adds `ai_observability` to saved view for ai explorer <!--Reference issues using `Closes #issue-number` to enable automatic closure on merge. --> #### Issues closed by this PR Closes https://github.com/SigNoz/engineering-pod/issues/5955 |
||
|
|
a8c04cb563 |
test(alerts): add e2e for alerts (#12349)
## Pull Request --- ### 📄 Summary > Why does this change exist? > What problem does it solve, and why is this the right approach? This adds a bunch of E2E tests for alerts, to test v1/v2 create and edit, and also tests for alert history. This started as tests only for history but decided to just add tests for everything, while creating them, I found two bugs inside alerts, so they already helping us before even landing :) The changes in the UI are only to add testIds, no change in logic (and no fix for the incidents) | Scope | Before (`main`) | After (this branch) | Delta | |---|---:|---:|---:| | Alerts E2E tests | 2 | 191 | **+189** | | Alerts E2E spec files | 1 | 31 | +30 | | Whole E2E suite | 141 | 330 | **+189** | #### Alerts page shell (7) | File | Test | Status | |---|---|---| | `page.spec.ts` | AL-01 all four top-level tabs render | | | `page.spec.ts` | AL-02 default tab is Alert Rules | | | `page.spec.ts` | AL-03 tab switch writes ?tab= and clears subTab | | | `page.spec.ts` | AL-04 Configuration deep-link | | | `page.spec.ts` | AL-05 Triggered Alerts tab smoke | | | `page.spec.ts` | AL-06 Notification Channels tab smoke | | | `page.spec.ts` | AL-07 tab state survives reload | | #### Alert rules list (19) | File | Test | Status | |---|---|---| | `list/columns.spec.ts` | LR-01 renders all default columns (Status, Alert Name, Severity, Labels, Actions) | | | `list/columns.spec.ts` | LR-02 shows empty state when no rules exist | skipped | | `list/columns.spec.ts` | LR-10 column selector hides and shows a column | | | `list/navigation.spec.ts` | LR-11 row click opens the overview page | | | `list/navigation.spec.ts` | LR-12 ctrl/cmd-click opens the overview in a new tab | | | `list/navigation.spec.ts` | LR-13 actions menu Edit and Edit in New Tab navigate correctly | | | `list/navigation.spec.ts` | LR-17 New Alert button navigates to alert creation | | | `list/navigation.spec.ts` | LR-18 shows ErrorEmptyState when list fails to load | skipped | | `list/pagination-sort.spec.ts` | LR-07 navigates between pages | | | `list/pagination-sort.spec.ts` | LR-08 changes page size | | | `list/pagination-sort.spec.ts` | LR-09 sorts by column header click | | | `list/row-actions.spec.ts` | LR-14 Disable then Enable toggles the rule state | | | `list/row-actions.spec.ts` | LR-15 Clone creates a copy and shows success toast | | | `list/row-actions.spec.ts` | LR-16 Delete removes the rule and shows success toast | | | `list/search.spec.ts` | LR-03 filters by name | | | `list/search.spec.ts` | LR-04 filters by severity and by label | | | `list/search.spec.ts` | LR-05 shows no-results state with clear button | | | `list/search.spec.ts` | LR-06 resets pagination when searching | | | `list/search.spec.ts` | LR-19 state and severity filters intersect, they do not union | | #### Create alert (52) | File | Test | Status | |---|---|---| | `create/edge.spec.ts` | CE-04 a server-side rejection opens the error modal and keeps the draft | | | `create/edge.spec.ts` | CE-07 none of the four builder mounts logs a console error | | | `create/edge.spec.ts` | CE-09 the v2 Discard button is clickable | skipped | | `create/prefill.spec.ts` | CD-01 a compositeQuery alone selects the alert type | | | `create/prefill.spec.ts` | CD-02 thresholds prefill from JSON, and a malformed value falls back | | | `create/prefill.spec.ts` | CD-03 matchType and compareOp aliases normalise to the enum | | | `create/prefill.spec.ts` | CD-04 ruleName and yAxisUnit apply once and never stomp an edit | | | `create/prefill.spec.ts` | CD-05 evaluationWindowPreset=meter switches to the cumulative daily window | | | `create/prefill.spec.ts` | CD-06 URL prefill is ignored in edit mode | | | `create/shell.spec.ts` | CS-01 bare /alerts/new lists exactly the expected alert-type cards | | | `create/shell.spec.ts` | CS-02 picking a card writes both params and mounts the v2 builder | | | `create/shell.spec.ts` | CS-03 the anomaly card rewrites the rule type, not the alert type | conditional | | `create/shell.spec.ts` | CS-04 modifier-clicking a card opens the builder in a new tab | | | `create/shell.spec.ts` | CS-05 breadcrumb gains a third crumb after a type is picked | | | `create/shell.spec.ts` | CS-06 create renders inside the Alert Rules tab and leaving drops subTab/search | | | `create/shell.spec.ts` | CS-07 showClassicCreateAlertsPage=true renders the v1 form instead | | | `create/shell.spec.ts` | CS-08 Switch to Classic Experience replaces history, so Back does not return to v2 | | | `create/v1.spec.ts` | CV1-01 the classic form renders its steps and the create-mode labels | | | `create/v1.spec.ts` | CV1-02 the rendered severity is the default from the rule, not the select | | | `create/v1.spec.ts` | CV1-03 one keystroke in the name field is enough to enable Save | | | `create/v1.spec.ts` | CV1-04 Save stays disabled until the channel configuration resolves | | | `create/v1.spec.ts` | CV1-05 broadcast-to-all saves the rule with the broadcast flag | skipped | | `create/v1.spec.ts` | CV1-06 a cleared threshold is coerced to 0, so the required-threshold branch is dead | | | `create/v1.spec.ts` | CV1-07 cancelling the confirm dialog does not save | | | `create/v1.spec.ts` | CV1-08 the happy path posts the v1 body shape to the shared endpoint | | | `create/v1.spec.ts` | CV1-09 CV1-10 description, labels and severity all land in the payload | | | `create/v1.spec.ts` | CV1-11 test notification skips the dialog and reports no matching data | | | `create/v1.spec.ts` | CV1-12 with no channels the form is a dead end | | | `create/v1.spec.ts` | CV1-13 Cancel leaves the form without saving | | | `create/v1.spec.ts` | CE-05 an empty PromQL expression is rejected behind the dialog | | | `create/v1.spec.ts` | CE-06 an empty ClickHouse query is rejected behind the dialog | | | `create/v1.spec.ts` | CV1-14 the condition sentence keeps its selections | | | `create/v2.spec.ts` | CV2-01 initial state: one critical threshold, both actions gated | | | `create/v2.spec.ts` | CV2-02 the save tooltip walks from the name gate to the channel gate | | | `create/v2.spec.ts` | CV2-03 clearing a threshold label re-gates the save | | | `create/v2.spec.ts` | CV2-04 a label added in the header survives the save round-trip | | | `create/v2.spec.ts` | CV2-05 a rejected label key surfaces as a notification, not an inline message | | | `create/v2.spec.ts` | CV2-06 CV2-07 the operator and match-type selects offer the documented options | | | `create/v2.spec.ts` | CV2-08 the operator is rule-wide: one change reaches every threshold | | | `create/v2.spec.ts` | CV2-09 CV2-10 added thresholds take preset tiers, and the first cannot be removed | | | `create/v2.spec.ts` | CV2-11 a channel on one threshold is not enough — the validator loops all of them | | | `create/v2.spec.ts` | CV2-12 the unit select is disabled while the query has no y-axis unit | | | `create/v2.spec.ts` | CV2-13 the recovery threshold control is never rendered | | | `create/v2.spec.ts` | CV2-14 CV2-15 the evaluation window and cadence reach the payload | | | `create/v2.spec.ts` | CV2-18 with no channels the dropdown offers only a way to create one | | | `create/v2.spec.ts` | CV2-19 routing policies unlock the save with zero channels | | | `create/v2.spec.ts` | CV2-16 the group-by select is disabled until the query groups by something | | | `create/v2.spec.ts` | CV2-17 repeat notifications enable their inputs and reach the payload | | | `create/v2.spec.ts` | CV2-20 happy-path save posts the v2 shape and lands on the list | | | `create/v2.spec.ts` | CV2-21 test notification reports that a non-firing rule matched nothing | | | `create/v2.spec.ts` | CV2-22 discard leaves without posting and resets the form | | | `create/v2.spec.ts` | CV2-23 every footer button is disabled while the save is in flight | | #### Edit alert (22) | File | Test | Status | |---|---|---| | `edit/edge.spec.ts` | CE-03 an unknown ruleId shows AlertNotFound on both entry URLs | | | `edit/edge.spec.ts` | CE-03b /alerts/edit with no ruleId also lands on AlertNotFound | | | `edit/v1.spec.ts` | EV1-01 the classic form renders in edit mode inside the details shell | | | `edit/v1.spec.ts` | EV1-02 every seeded field prefills the form | | | `edit/v1.spec.ts` | EV1-03 preferredChannels decide which channel control is prefilled | | | `edit/v1.spec.ts` | EV1-04 the happy-path update PUTs the v1 body and keeps unrelated params | | | `edit/v1.spec.ts` | EV1-05 Discard leaves without a PUT and without changing the rule | | | `edit/v1.spec.ts` | EV1-06 the header title and the form name field agree | | | `edit/v1.spec.ts` | EV1-07 /alerts/edit redirects for a v1 rule exactly as it does for v2 | | | `edit/v1.spec.ts` | EV1-08 editing a v1 rule never migrates it to the v2 schema | | | `edit/v2.spec.ts` | EV2-01 the v2 editor renders inside the details shell | | | `edit/v2.spec.ts` | EV2-02 name and labels prefill from the rule | | | `edit/v2.spec.ts` | EV2-03 both thresholds prefill, and the sentence reads spec[0] | | | `edit/v2.spec.ts` | EV2-04 the recovery threshold control never renders | | | `edit/v2.spec.ts` | EV2-05 the evaluation window prefills, and a non-preset value collapses to custom | | | `edit/v2.spec.ts` | EV2-06 repeat notifications prefill from the seeded renotify block | | | `edit/v2.spec.ts` | EV2-07 alertOnAbsent prefills the advanced options | | | `edit/v2.spec.ts` | EV2-08 the evaluation cadence always reads back in default mode | | | `edit/v2.spec.ts` | EV2-09 changing a threshold PUTs the rule and the change survives a reload | | | `edit/v2.spec.ts` | EV2-10 the footer save is what persists a rename made on the Overview tab | | | `edit/v2.spec.ts` | EV2-11 Discard leaves without a PUT and without touching the rule | | | `edit/v2.spec.ts` | EV2-12 /alerts/edit is a legacy alias that redirects into the details shell | | #### Alert details (15) | File | Test | Status | |---|---|---| | `details/actions.spec.ts` | AD-06 enable/disable toggle changes the rule state | | | `details/actions.spec.ts` | AD-07 Duplicate creates a copy and navigates to overview | | | `details/actions.spec.ts` | AD-08 Delete removes the rule and returns to the list | | | `details/chrome.spec.ts` | AD-09 copy-link button copies the current URL to clipboard | conditional | | `details/chrome.spec.ts` | AD-10 breadcrumb navigates back to the alert list | | | `details/chrome.spec.ts` | AD-13 document title updates to show the rule name | | | `details/header.spec.ts` | AD-01 v2 header shows editable name input without Rename menu item | | | `details/header.spec.ts` | AD-02 v1 header shows static title with state, severity and labels | | | `details/not-found.spec.ts` | AD-11 invalid ruleId shows AlertNotFound page | | | `details/not-found.spec.ts` | AD-12 missing ruleId on overview shows AlertNotFound page | | | `details/rename.spec.ts` | AD-03 v1 rename via modal updates the rule name | | | `details/rename.spec.ts` | AD-04 v2 inline rename saves via Overview footer button | | | `details/tabs.spec.ts` | AD-05 Overview/History tabs preserve ruleId and relativeTime | | | `details/tabs.spec.ts` | AD-05b switching to History tab discards other history params | | | `details/threshold-persistence.spec.ts` | TC-02 edit page displays the saved threshold value | | #### Alert history (75) | File | Test | Status | |---|---|---| | `history/cross-cutting.spec.ts` | AX-01 full deep-link with all params is honoured in one load | | | `history/cross-cutting.spec.ts` | AX-02 page reload preserves all history params | | | `history/cross-cutting.spec.ts` | AX-03 browser back/forward restores correct table state | | | `history/cross-cutting.spec.ts` | AX-04 no unhandled console errors across full history session | | | `history/cross-cutting.spec.ts` | AX-05 no request storm on mount (exactly one call per endpoint) | | | `history/cross-cutting.spec.ts` | AX-06 v1 and v2 schema rules both render history correctly | | | `history/cross-cutting.spec.ts` | AX-07 no legacy v1 history API calls during full session | | | `history/cross-cutting.spec.ts` | AX-08 history API endpoints carry expected params | | | `history/empty-and-errors.spec.ts` | AE-01 invalid filter expression shows syntax error and recovers on fix | | | `history/empty-and-errors.spec.ts` | AE-02 empty filter_keys response still mounts editor (no suggestions) | | | `history/empty-and-errors.spec.ts` | AE-02b bogus ruleId never reaches history APIs (shows AlertNotFound) | | | `history/empty-and-errors.spec.ts` | AE-03 rule with no history renders empty state (not error) | | | `history/empty-and-errors.spec.ts` | AE-04 time range with no data renders empty state | | | `history/empty-and-errors.spec.ts` | AE-05 time-range change resets pagination to first page | | | `history/empty-and-errors.spec.ts` | AE-06 absurd time range (90d) still renders | | | `history/empty-and-errors.spec.ts` | AE-07 disabled rule history is still readable | | | `history/empty-and-errors.spec.ts` | AE-08 deleted rule shows AlertNotFound on revisit | | | `history/expression-filter.spec.ts` | AF-06 key suggestions load on page load | | | `history/expression-filter.spec.ts` | AF-07 value suggestions fetch from filter_values endpoint | | | `history/expression-filter.spec.ts` | AF-08 value suggestions filter client-side as user types | | | `history/expression-filter.spec.ts` | AF-09 running equality expression filters the table | | | `history/expression-filter.spec.ts` | AF-10 running expression resets pagination to first page | | | `history/expression-filter.spec.ts` | AF-11 Run button re-fetches unchanged expression | | | `history/expression-filter.spec.ts` | AF-12 in-flight query can be cancelled | | | `history/expression-filter.spec.ts` | AF-13 threshold.name and severity keys filter correctly | | | `history/expression-filter.spec.ts` | AF-14 unknown key returns 200 with zero rows (not 500) | | | `history/expression-filter.spec.ts` | AF-15 expression is lost on Overview→History round-trip (known bug) | | | `history/expression-filter.spec.ts` | AF-16 expression and state filter compose in request | | | `history/expression-filter.spec.ts` | AF-17 clearing expression restores full unfiltered list | | | `history/state-filter.spec.ts` | AF-01 All filter sends no state param in request | | | `history/state-filter.spec.ts` | AF-02 Fired filter sends state=firing in request | | | `history/state-filter.spec.ts` | AF-03 Resolved filter shows empty for rule with no resolutions | | | `history/state-filter.spec.ts` | AF-03b Resolved filter shows rows for rule with resolutions | | | `history/state-filter.spec.ts` | AF-04 deep-link ?timelineFilter=FIRED starts on Fired tab | | | `history/state-filter.spec.ts` | AF-05 changing state filter resets pagination to first page | | | `history/statistics.spec.ts` | AS-01 Total Triggered card shows the firing count | | | `history/statistics.spec.ts` | AS-02 Avg. Resolution Time card shows "No Resolutions." when none exist | | | `history/statistics.spec.ts` | AS-03 empty stats card never renders a sparkline | | | `history/statistics.spec.ts` | AS-03b sparkline present with a multi-point series | skipped | | `history/statistics.spec.ts` | AS-04 change-vs-past indicator shows "no previous data" when unavailable | | | `history/statistics.spec.ts` | AS-09 stats update when time range changes | | | `history/statistics.spec.ts` | AS-11 Avg. Resolution Time shows formatted duration when resolutions exist | | | `history/statistics.spec.ts` | AS-12 Total Triggered counts only firing rows (not resolved) | | | `history/timeline-graph.spec.ts` | AT-03 renders canvas with two segments (inactive→firing) | | | `history/timeline-graph.spec.ts` | AT-03b renders canvas with three segments (inactive→firing→inactive) | | | `history/timeline-graph.spec.ts` | AT-19 handles nodata state without console errors | | | `history/timeline-pagination.spec.ts` | AT-06 next page sends cursor and shows different rows | | | `history/timeline-pagination.spec.ts` | AT-07 prev page drops the cursor from request | | | `history/timeline-pagination.spec.ts` | AT-08 pagination buttons disable at first and last page | | | `history/timeline-pagination.spec.ts` | AT-09 browser back after paging returns to previous page | | | `history/timeline-pagination.spec.ts` | AT-10 deep-link ?page=2 loads second page directly | | | `history/timeline-pagination.spec.ts` | AT-11 default sort order is ascending | | | `history/timeline-pagination.spec.ts` | AT-12 sorting toggles order and resets to first page | | | `history/timeline-pagination.spec.ts` | AT-13 single page disables both pagination buttons | | | `history/timeline-pagination.spec.ts` | AT-21 all pages together cover the complete row set | | | `history/timeline-table.spec.ts` | AT-01 timeline section renders all chrome elements | | | `history/timeline-table.spec.ts` | AT-02 Top 5 Contributors tab is disabled with Coming Soon indicator | | | `history/timeline-table.spec.ts` | AT-04 table rows display state, labels and formatted timestamp | | | `history/timeline-table.spec.ts` | AT-05 footer shows correct row range | | | `history/timeline-table.spec.ts` | AT-14 row click does not navigate away | | | `history/timeline-table.spec.ts` | AT-15 row actions link navigates to logs explorer | | | `history/timeline-table.spec.ts` | AT-15b row actions link navigates to traces explorer | | | `history/timeline-table.spec.ts` | AT-16 metrics rule rows show disabled action (no related links) | | | `history/timeline-table.spec.ts` | AT-17 CREATED AT column respects app timezone setting | | | `history/timeline-table.spec.ts` | AT-18 state cell renders Firing, Resolved, and No Data correctly | | | `history/timeline-table.spec.ts` | AT-18b pending/recovering states render blank (coverage gap) | skipped | | `history/timeline-table.spec.ts` | AT-18c disabled state renders as "Muted" (coverage gap) | skipped | | `history/timeline-table.spec.ts` | AT-20 time-range boundaries inclusive/exclusive (coverage gap) | skipped | | `history/top-contributors.spec.ts` | AS-05 card displays max 3 rows with count ratios | | | `history/top-contributors.spec.ts` | AS-13 contributor bar width is the count as a percentage of the total | | | `history/top-contributors.spec.ts` | AS-06 "View all" button only appears when more than 3 contributors | | | `history/top-contributors.spec.ts` | AS-07 View-all drawer shows paginated list of all contributors | | | `history/top-contributors.spec.ts` | AS-07b drawer opens from deep link with ?viewAllTopContributors=true | | | `history/top-contributors.spec.ts` | AS-08 View-all click adds ?viewAllTopContributors=true to URL | | | `history/top-contributors.spec.ts` | AS-10 contributor rows show related-logs link for logs-based rules | | #### Notification channels (1) | File | Test | Status | |---|---|---| | `channels/edit.spec.ts` | NC-01 an edited recipient persists after reload | | #### Skipped tests | Test | File | Kind | Reason | |---|---|---|---| | the v2 Discard button is clickable | `create/edge.spec.ts` | hard `test.skip(` | Real bug: the button is not clickable. Test written, left ready to flip. | | broadcast-to-all saves the rule with the broadcast flag | `create/v1.spec.ts` | hard `test.skip(` | Real bug: the broadcast flag is not persisted. | | sparkline present with a multi-point series | `history/statistics.spec.ts` | `test.skip(true)` | Flaky by construction: the sparkline only renders with more than one data point, and whether the seeded ~2-minute window lands in one stats bucket or two depends on where it falls relative to the bucket boundary. | | pending/recovering states render blank | `history/timeline-table.spec.ts` | `test.skip(true)` | Unreachable: `pending` and `recovering` are transient states, and no fixture can reliably catch a rule mid-transition. | | disabled state renders as "Muted" | `history/timeline-table.spec.ts` | `test.skip(true)` | Unreachable: a `disabled` history row is policy-driven, and disabling a rule appends no row (verified). | | time-range boundaries inclusive/exclusive | `history/timeline-table.spec.ts` | `test.skip(true)` | Unreachable: asserting a row exactly at `start` and one at `start-1ms` means controlling row timestamps, but evaluation times are whatever the ruler chose. | | the anomaly card rewrites the rule type, not the alert type | `create/shell.spec.ts` | conditional | Runs only where the `ANOMALY_DETECTION` feature flag is active; it is off on this stack. | | copy-link button copies the current URL to clipboard | `details/chrome.spec.ts` | conditional | Runs on Chromium only — Playwright grants `clipboard-read` nowhere else. | #### Issues closed by this PR > Reference issues using `Closes #issue-number` to enable automatic closure on merge. Closes https://github.com/SigNoz/engineering-pod/issues/4917 --- ### ✅ Change Type _Select all that apply_ - [ ] ✨ Feature - [ ] 🐛 Bug fix - [ ] ♻️ Refactor - [ ] 🛠️ Infra / Tooling - [x] 🧪 Test-only --- ### ⚠️ Risk & Impact Assessment > What could break? How do we recover? - Blast radius: Alerts - Potential regressions: None, only test ids - Rollback plan: Find and fix the issue specifically --- ### 📝 Changelog > Fill only if this affects users, APIs, UI, or documented behavior > Use **N/A** for internal or non-user-facing changes | Field | Value | |------|-------| | Deployment Type | Cloud / OSS / Enterprise | | Change Type | Maintenance | | Description | We added more E2E tests for Alerts page. | --- ### 📋 Checklist - [x] Tests added or explicitly not required - [ ] Manually tested - [ ] Breaking changes documented - [ ] Backward compatibility considered |
||
|
|
dca6aa497d |
chore(serviceaccount): remove deprecated nested role endpoints (#12591)
Some checks failed
build-staging / prepare (push) Has been cancelled
build-staging / js-build (push) Has been cancelled
build-staging / go-build (push) Has been cancelled
build-staging / staging (push) Has been cancelled
cacheci / tests (push) Has been cancelled
Release Drafter / update_release_draft (push) Has been cancelled
#### Description
- Removes the deprecated `POST /api/v1/service_accounts/{id}/roles` and
`DELETE /api/v1/service_accounts/{id}/roles/{rid}` routes, their HTTP
handlers, and the `DeprecatedPostableServiceAccountRole` type, now that
all consumers use `/api/v1/service_account_roles`.
- Keeps the `GET /api/v1/service_accounts/{id}/roles` listing endpoint.
- Regenerates `docs/api/openapi.yml` and the frontend client.
#### Issues closed by this PR
Closes SigNoz/platform-pod#2919
#### Additional Information
- Final step of the migration; the frontend (#12589) and
integration-test (#12590) consumer moves are already merged.
|
||
|
|
bb47550c01 |
feat(authz): enable FGA for auth domains (#12588)
#### Description - Auth domain routes (`/api/v2/auth_domains`) now use `CheckResources` + `ResourceDef` instead of the coarse `AdminAccess` gate — per-resource FGA checks on enterprise, admin role gate on community. - Create and update also check `attach` on the roles the request's `roleMapping` will grant at SSO login (mapped roles + default role, `signoz-viewer` when unset, `role:*` when `useRoleAttribute` is on); update additionally checks `detach` on the roles the stored mapping was granting, since a `PUT` replaces the mapping. - Migration `117_add_auth_domain_tuples` backfills the admin `auth-domain` tuples for existing organizations and re-syncs the stored managed-role transaction groups; new organizations get both from the registry at bootstrap. - Regenerated OpenAPI spec: the auth-domain operations advertise `auth-domain:*` and `role:attach`/`role:detach` scopes instead of `ADMIN`. - Added `callbackauthn/05_authz.py` covering managed-role gating, custom-role wildcard/instance grants, and the role-mapping attach/detach checks. #### Issues closed by this PR Closes SigNoz/platform-pod#2649 |
||
|
|
edb63ae7be |
feat[ai-011y]: fields API for ai query builder (#12140)
Some checks failed
build-staging / prepare (push) Has been cancelled
build-staging / js-build (push) Has been cancelled
build-staging / go-build (push) Has been cancelled
build-staging / staging (push) Has been cancelled
cacheci / tests (push) Has been cancelled
Release Drafter / update_release_draft (push) Has been cancelled
## Pull Request --- ### 📄 Summary - Add a `type` param to `/api/v1/fields/keys`; for type=builder_ai_query (flag-gated) the metadata store returns the per-trace aggregate columns (llm_call_count, input_tokens, …) as trace-context keys — they're computed at query time, never ingested, so the attribute scan can't serve them. - Split `TraceColumn.Orderable` into `Orderable + Filterable`: ORDER BY uses orderable, the trace-level filter validates against filterable, and the API only returns keys that are both. `last_activity_time` is order-only and now rejected in filters with a targeted error.** - UI note: last_activity_time should be added to client-side list (it's the default sort). #### Issues closed by this PR Part of https://github.com/SigNoz/engineering-pod/issues/5714 --- ### ✅ Change Type _Select all that apply_ - [x] ✨ Feature - [ ] 🐛 Bug fix - [ ] ♻️ Refactor - [ ] 🛠️ Infra / Tooling - [ ] 🧪 Test-only --- ### 🧪 Testing Strategy > How was this change validated? - Tests added/updated: ✅ - Manual verification: ✅ - Edge cases covered: ✅ --- ### ⚠️ Risk & Impact Assessment > What could break? How do we recover? - Blast radius: None - Potential regressions: - Rollback plan: |
||
|
|
5b3b2865d1 |
fix(authtypes): restructure auth domain payload into a kind/spec envelope (#12472)
#### Description
- Moves the endpoints to `/api/v2/auth_domains` and removes the
`/api/v1/domains` routes — the request/response shapes changed, so they
live behind new paths instead of breaking v1 in place.
- Restructures the auth domain payload: `config` is now a `{kind, spec}`
discriminated envelope (same pattern as `RuleThresholdData` /
`EvaluationEnvelope`), replacing the old `ssoType` discriminator with
`samlConfig` / `googleAuthConfig` / `oidcConfig` sibling fields;
`ssoEnabled` and `roleMapping` move to the root as `enabled` and
`roleMapping`.
- Renames the provider kind `google_auth` → `google`, and the SAML keys
to metadata-consistent ones: `samlEntity` → `entityId`, `samlIdp` →
`location`, `samlCert` → `certificate`.
- Migrates the persisted documents too: a new sqlmigration rewrites
`auth_domain.data` into `{enabled, config: {kind, spec}, roleMapping}`,
so all legacy-shape code (storable twins, `google_auth` translation,
per-kind conversion switches) is deleted; the remaining per-kind wiring
lives in a single variant registry that `UnmarshalJSON`,
`JSONSchemaOneOf` and the discriminator mapping derive from.
- `AuthDomain` exposes the domain shape (`Enabled()`, `Kind()`,
`Config()`, `RoleMapping()`, typed spec accessors) instead of the
persisted document; `config` presence is enforced explicitly on
Postable/Updatable (the old PUT path never enforced it and could poison
a row).
- Secret fields (`clientSecret`, `serviceAccountJson`) are `format:
password` in the schema, and `GoogleConfig` loses the unused
`redirectURI` (the migration strips it from persisted documents).
- Frontend: regenerated client is a clean discriminated union; both
directions of the envelope↔form translation live in
`CreateEdit.utils.ts` with an explicit kind→provider mapping (no
cross-enum casts).
- The generated OpenAPI spec carries a real `discriminator`; the
kind/spec envelope pattern itself is documented generically in #12494,
and this PR only keeps the auth domain worked example in `types.md` in
step with the refactored types.
- Updates the google authn integration tests (#12486) to the new API,
and adds parametrized POST→GET roundtrip cases pinning the response
contract per kind (server-side defaulting, role-name normalization, null
maps) plus enforcement-toggle update coverage.
#### Issues closed by this PR
Closes SigNoz/platform-pod#2268
#### Additional Information
- Breaking change: `/api/v1/domains` is gone; the resource is now
`/api/v2/auth_domains` with the new shape. Login and SSO callback flows
are behaviorally unchanged, and existing rows are migrated in place at
startup.
- The `AuthNProvider` rename also surfaces in `/api/v2/sessions/context`
responses (`provider: "google"`) — the login page only consumes the
callback `url` — and in the reported stats key, which changes from
`authdomain.google_auth.count` to `authdomain.google.count`.
- Verified: `make go-test`, Go lint, frontend jest suites for
AuthDomain, `pnpm build`, `pnpm tsgo --noEmit`, and the full
`callbackauthn` domain suites (17 tests: roundtrip pins, the enforcement
toggle, and the google E2E flows) against a container rebuilt from this
branch — including a live run of the data migration over legacy-format
rows.
|
||
|
|
52a9a893c2 |
chore(user): remove deprecated user endpoints (#12530)
#### Description
- Removes the deprecated user endpoints that now have v2 replacements:
- `POST /api/v1/invite`, `GET /api/v1/user`, `GET
/api/v1/getResetPasswordToken/{id}`, `POST /api/v1/resetPassword`
- `POST /api/v2/users/{id}/roles` and `DELETE
/api/v2/users/{id}/roles/{roleId}`, superseded by `/api/v2/user_roles`
- `GET /api/v1/user/me` stays registered but returns 501 pointing at
`GET /api/v2/users/me`, following the v1 dashboard endpoints.
- Drops the handlers, module methods and types that only existed to
serve them (`DeprecatedUser`, the `user_invite` types, `PostableRole`).
- Moves the four remaining `*_cleanup` teardown tests off `DELETE
/api/v2/users/{id}/roles/{roleId}` onto `DELETE
/api/v2/user_roles/{id}`. Removal is keyed by the `user_role` entry id,
so they read it from `GET /api/v2/users/{id}` — that endpoint is not
deprecated and its other uses are untouched.
- Regenerates `docs/api/openapi.yml` and the frontend client. No
hand-written frontend code referenced the removed operations.
#### Issues closed by this PR
Closes: https://github.com/SigNoz/platform-pod/issues/2667
#### Additional Information
- `/api/v1/user/me` is a stub rather than a deletion because an
unregistered `/api/*` path falls through to the SPA catch-all and
answers 200 with `index.html`, which older mcp reads as a successful
response — a 501 fails loudly instead.
|
||
|
|
2616885d22 |
feat: adding mysql GCP service (#12514)
<!--A few plain bullets saying what changed and why, for a reviewer skimming it - not a wall of text, not a restatement of the diff, not generated boilerplate.--> #### Description - Adding GCP integration MySQL service - Related fix: adding formula to convert CPU utilization fraction into percentage for Postgres dashboard <!--Reference issues using `Closes #issue-number` to enable automatic closure on merge. --> #### Issues closed by this PR https://github.com/SigNoz/platform-pod/issues/2942 |
||
|
|
5bf6fd9192 |
fix(savedview): handle old invalid data in specs (#12477)
## Summary
- Handle malformed selectedFields in the extradata in the migration and
new migration to fix in the already migrated cases.
- Restructure saved-view create/update/get payloads so
`schemaVersion`/`spec` are top-level (unwrapping the old `data`
nesting), matching how dashboards and rules shape their wire types.
- Publish `schemaVersion` as an `enum: [v2]`
- Make `display` and `selectedFields` optional in the OpenAPI schema
- Declare `409` on `CreateSavedView`
- Require `minItems: 1` on `queries`
New API contract in [below
comment](https://github.com/SigNoz/signoz/pull/12477#issuecomment-5230041074),
follow up on https://github.com/SigNoz/signoz/pull/12342
Closes https://github.com/SigNoz/engineering-pod/issues/4651
Notes to reviewer:
- Please pay attention to the last case in above linked comment for
partial display field updates.
- Still assuming that [migration
046](
|
||
|
|
f44d6c7c84 |
docs(contributing): document the kind/spec envelope for sum types (#12494)
#### Description - Documents the kind/spec envelope pattern for sum types in `docs/contributing/go/types.md`: the envelope shape, why it goes at the point of variance rather than the resource root, the tagging-style rationale (adjacently tagged vs internally tagged vs sibling optional fields), the validating `UnmarshalJSON`, the OpenAPI variant structs, and the data-migration-vs-storable-twin trade-off for legacy persisted shapes. - Examples are generic (`FooConfig` with `bar`/`baz` kinds), with `RuleThresholdData`, `EvaluationEnvelope` and the dashboard plugins as the in-tree references. - Cross-links from `handler.md`'s "`oneOf` with a discriminator" section, which keeps owning the schema mechanics. |
||
|
|
db5f4b4cd5 |
feat(user): add v2 reset password endpoint (#12489)
#### Description - `POST /api/v1/resetPassword` was the last password endpoint with no v2 equivalent. Adds `POST /api/v2/factor_password/reset`, next to the existing `/factor_password/forgot`, so the whole recovery flow lives under one namespace. - v1 keeps working and is now marked deprecated. Both routes share the same handler, so behaviour is identical. - A malformed request body now returns a structured 400 instead of a 500. This applies to v1 too, since the handler is shared. #### Issues closed by this PR Contributes to SigNoz/platform-pod#2667 #### Additional Information - The generated frontend client is included because CI re-runs `pnpm generate:api` and fails on drift. The UI still calls v1; moving it to the new `useResetPassword` hook is a separate PR to keep review ownership split. - Not fixed here: a reset doesn't revoke existing sessions, though a voluntary password change does. Worth its own ticket. |
||
|
|
2a2b393146 |
chore(user): remove the deprecated user by id endpoints (#12474)
#### Description
- Removes `GET`, `PUT` and `DELETE /api/v1/user/{id}` — all deprecated
and superseded by `/api/v2/users/{id}`, which the frontend already uses.
- Drops the dead code this leaves behind: the `SelfAccess` middleware
and `Claims.IsSelfAccess` (no callers left), the deprecated update
setters, and three `DeprecatedUser` helpers.
- Points the integration tests that deleted users at `DELETE
/api/v2/users/{id}`.
#### Issues closed by this PR
Contributes to SigNoz/platform-pod#2667
#### Additional Information
- Behaviour change: the removed `GET`/`PUT` were `SelfAccess`, the v2
equivalents are `AdminAccess`. Self-serve reads and updates go through
`/api/v2/users/me`, which is what the UI already calls — but worth a
second pair of eyes.
- `DELETE /api/v1/user/{id}` was the most widely reached of the three.
Please confirm nothing external (zeus) still calls it before merging.
- OpenAPI spec and the generated frontend client are regenerated, not
hand-edited.
|
||
|
|
b904aca1a8 |
chore(user): remove the deprecated bulk invite endpoint (#12473)
#### Description - Removes `POST /api/v1/invite/bulk` — already deprecated, superseded by `POST /api/v1/invite`, and no callers left. - `Setter.CreateBulkInvite` stays; `CreateInvite` still delegates to it for the single-invite case. #### Issues closed by this PR Contributes to SigNoz/platform-pod#2667 #### Additional Information - OpenAPI spec and the generated frontend client are regenerated, not hand-edited. - The `integrationci / fmtlint` failure here is not from this PR — `make py-lint` is broken on `main`. Fixed separately in #12475; this PR needs that merged (or a rebase on it) to go green. - First of three PRs splitting a v1 user-API cleanup. The other two also regenerate the spec and generated client, so whichever merges second needs the generators re-run. |
||
|
|
85bf5ce644 |
feat(infra-monitoring): filter by pod status (#12278)
## Pull Request --- ### 📄 Summary Adds a `filterByPodStatus` secondary filter to the v2 infra-monitoring list APIs (pods, nodes, namespaces, clusters, deployments, statefulsets, jobs, daemonsets). Pod status is a derived kubectl-style value (`k8s.pod.phase` + status reasons, resolved via `argMax`), not a real label, so it can't go through the normal query-builder filter. This PR resolves the full-scope status keyset up-front and intersects it with the metadata + ranked groups, keeping `total` and pagination correct. - Multi-select: the field is an array, pushed down as `WHERE lower(display_status) IN (...)` (OR within status, AND with the attribute filter). - When the optional status metrics were never ingested, the endpoint returns a non-blocking warning + empty page instead of silently filtering everything out. #### Screenshots / Screen Recordings (if applicable) N/A — backend + generated FE API types only; the UI is a separate change. #### Issues closed by this PR Part of SigNoz/engineering-pod#5778. --- ### ✅ Change Type - [x] ✨ Feature - [ ] 🐛 Bug fix - [x] ♻️ Refactor - [ ] 🛠️ Infra / Tooling - [ ] 🧪 Test-only --- ### 🐛 Bug Context N/A — not a bug fix. --- ### 🧪 Testing Strategy - Tests added/updated: - Unit test for the status push-down (`applyPodStatusFilter`, built with go-sqlbuilder). - Integration tests across all 8 entity APIs: list mode, grouped mode, validation, missing-metric warning, and multi-select union. - Manual verification: smoke-tested against staging data (single, multi, and grouped filters). - Edge cases covered: missing status metric → warning + empty; grouped mode keeps a group if ≥1 pod matches; multi-select returns the union of the selected statuses. --- ### ⚠️ Risk & Impact Assessment - Blast radius: v2 infra-monitoring list endpoints only. - Potential regressions: none when the filter is unset (empty = off, fully additive). When set, an extra status query runs; it is gated behind the filter being present. - Rollback plan: revert the PR — no schema or data migrations involved. --- ### 📝 Changelog | Field | Value | |------|-------| | Deployment Type | OSS, Cloud, Enterprise | | Change Type | Feature | | Description | v2 infra-monitoring lists can now be filtered by pod status (multi-select). | --- ### 📋 Checklist - [x] Tests added or explicitly not required - [x] Manually tested - [x] Breaking changes documented - [x] Backward compatibility considered --- ## 👀 Notes for Reviewers - `filterByPodStatus` is optional and additive — no change to existing responses when omitted. - The status keyset is resolved once at full scope, then intersected — this is what keeps `total`/pagination correct despite status being a post-aggregation value. - OpenAPI spec + FE API types are regenerated (scalar → array); no hand-written FE. |
||
|
|
e08ef01170 |
refactor(savedview): restructure api and storage to spec based (#12342)
## Summary
- Saved views now persist a versioned, typed spec (`schemaVersion` +
`spec{compositeQuery, selectedFields, display}`) instead of a bare
composite-query blob plus an opaque, frontend-owned `extraData` string
-- mirroring the pattern dashboards already use for their v2/perses
schema.
- `/api/v1/explorer/views` keeps working exactly as before: a thin
conversion layer translates to/from the legacy wire format, including
folding `extraData`'s ad hoc JSON into the typed spec and back for
backward compatibility.
- A one-time migration rewrites existing rows into the new shape and
drops the now-unused `extra_data`/`category`/`tags` columns.
### Scaffolding decisions
- Using v2 for new handlers instead of renaming old handlers to
something else for these reasons - keep the diff minimum for easier
reviews, avoiding any git history or last updated at change in old route
registration.
- Keeping the conversion to old saved view type in handler itself rather
than `savedviewtypes` package to keep it un-exported and not let them be
available anywhere else to be used. It also enables `savedviewtypes` to
be independent on query-service models.
- Modified the existing handler and it's interface to include the v2
methods instead of adding another handlerV2 since apiserver already had
handler wired in, so don't want to pass on 2 version simultaneously.
### Breaking change
- Any unknown key in the `ExtraData` will be rejected and dropped
silently in the old APIs and give error in new version.
- If there was any way to add tag or category in saved view earlier,
that data will be lost.
- Old APIs will not support the old QB request payload, only v5 format
is supported.
---
Closes SigNoz/engineering-pod#4651
Alternative discarded https://github.com/SigNoz/signoz/pull/12208
---------
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
|
||
|
|
5c0dfe2ad1 |
feat(promql): transpile allowlisted query shapes to ClickHouse grid statements (#12325)
> **Stack** (review in order; each PR's diff is against its predecessor): > 1. #12323 `v2-read-path` — v2 native read path (leaf package) > 2. #12324 `v2-wiring` — wiring, shadow/pin rollout machinery, dual-leg conformance > 3. #12325 `v2-transpiler` — PromQL→ClickHouse transpiler + classification golden > 4. #12093 `issue-4293` — the /prometheus API move (breaking slice, last) ### What The performance half of the v2 provider: an allowlist compiler (`classify`/`rewrite`) that evaluates proven PromQL shapes entirely inside ClickHouse on the `timeSeries*ToGrid` aggregate functions (CH ≥ 25.6), so one row per output series comes back instead of every raw sample. Everything not provably equivalent falls back to the engine over the PR-1 querier; a transpilable subtree under a non-transpilable node runs hybrid (subtree materialized as synthetic series, engine on top). `TryExecuteRange` slots into the PR-2 serve/shadow paths (until now engine-only) through the new `prometheus.RangeExecutor` capability interface — the provider stays unexported and pkg/querier keeps holding `prometheus.Prometheus`; providers without the capability (v1) simply never transpile. The capability folds into the main interface once v1 is removed. Highlights (docs/contributing/prometheus.md carries the full correctness story): - Range functions map to verified grid aggregates; `increase` is `rate × range` exactly (same extrapolated delta, factor algebra). - Instant selectors reproduce stale-marker shadowing with a three-aggregate compare — skipping stale rows in WHERE would resurrect the sample the marker buried. - `*_over_time` at range = k·step aggregates whole step buckets (`groupArrayInsertAt` + slide) — no per-window fan-out, no prefix-sum differencing. - **Window-sliver filtering** (the headline perf commit, folded here): when the window is narrower than the step, only window/step of the timeline can influence any grid point; a lattice predicate in WHERE cuts the aggregate's input by the coverage ratio — measured 74s/28GiB → 16s/4.3GiB on a 36k-series 1w rate, and a 2.67B-sample case that exceeded 150GiB now completes in 19s/17GiB. Over sliver-filtered rows the last-style gates lift (instant selectors and `last_over_time` transpile at window < step), and disjoint-window `*_over_time` forms drop the divisibility gate. - Scalar-op pipelines apply in Go, slot by slot — same float64 ops, same order the AST dictates. Two guards land with it: - **Classification golden** (`classification_golden_test.go` + `testdata/classification_golden.json`): freezes the route (full/hybrid(n)/fallback + reason) of every conformance-corpus expression, one line each — 317 expressions: 132 full, 39 hybrid, 146 fallback. The test also requires each expression to route the same on every corpus grid; if a classifier change ever makes the route grid-dependent, the test fails and the key must grow. Routing is its own correctness surface — silently falling back costs the pushdown, silently transpiling an unproven shape risks wrong numbers; both now show up in review as a golden diff, with the corpus suite's v2 leg judging the numbers. - **Workload coverage reporter** (`TestClassifyCorpus`, env-gated): classifies a JSON-lines corpus of real dashboard/alert queries and buckets fallbacks by reason, to steer future allowlist work. **What the dual-leg suite caught on its first transpiled run** (evidence the PR-2 guard works, worth stating in review): - The classifier read a duration expression's offset (`x offset step()`) as zero and transpiled it — offset expressions parse *without* the experimental-parser flag, so they reach production. 20 corpus cases served silently wrong numbers. Fixed by refusing `OriginalOffsetExpr` / `RangeExpr` / `StepExpr` at classification (engine evaluates them exactly); regression cases added, golden regenerated (30 routings flipped to fallback). - Name-drop assembly treated temporally-disjoint same-labelset twins as separate series: `-{job="api"}` spanning `http_requests`/`http_errors` returned a 400 the engine would not raise, and hybrid `-metric_a or -metric_b` returned duplicate `{}` series. The engine's actual rule is: assemble the matrix by labelset, merging elements that never share an evaluation timestamp; error only on a same-timestamp conflict. Both the full-plan path (`mergeSameLabelsetSeries`) and the hybrid post-strip path (`mergeMatrixByLabelset`) now reproduce it, with unit tests pinning the corpus scenarios. - 12 remaining divergences, all one class, recorded in `known_divergences_v2.json` with causes: the engine aggregates with Kahan compensated summation (sum, sum_over_time) and an overflow-free incremental mean (avg); ClickHouse's `sumForEach`/`avgForEach`/`arraySum` are naive, so ±1e100 cancellation returns 0/residue and near-max-float64 `avg` overflows to ±Inf. Burn-down note: `sumKahanForEach` for the cancellation class; the overflow class needs an incremental-mean aggregate ClickHouse doesn't have. ### Alternatives considered and discarded - **General PromQL→SQL translation.** An allowlist inverts the failure mode: an overlooked construct becomes a fallback instead of a wrong number. Every shape on the list was validated slot-for-slot against the vendored engine on live data before entering it. - **ClickHouse's own PromQL dialect** (ClickHouse#57545, `dialect='promql'`). Emits the same grid functions, but currently covers only rate/irate/delta/idelta/last_over_time, has no fallback engine, and ties us to their TimeSeries table engine. We use the same primitives with our own classifier and our own exactness gates. - **Prefix-sum differencing for `*_over_time` windows.** Large-minus-large cancellation drifts past the shadow tolerance on counter-sized values; direct per-slot combination of at most W bucket partials adds the way the engine adds. - **Fanning each sample into every window that covers it.** Multiplies rows by W — billions of rows for a long range over a short step; the bucketed form's row count is series × buckets, the size of the output. - **Handling staleness by filtering stale rows in WHERE (instant units).** Resurrects the older real sample the marker was written to bury; hence the last-overall vs last-non-stale timestamp comparison. - **Transpiling @-modifier and default-resolution subqueries.** Their evaluation grid depends on server runtime settings the transpiler cannot see; they stay on the (exact) engine path. ### Test plan - `go test ./pkg/prometheus/clickhouseprometheusv2` — transpiler unit tests (SQL forms, classification, scalar ops, subquery grids), golden. - `pytest integration/tests/promqlconformance/` — the v2 leg now exercises transpiled serving for every routable corpus case; ledger unchanged (empty). 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: Pandey <vibhupandey28@gmail.com> |
||
|
|
e42e42ee71 |
feat: enable FGA for dashboards and their public config (#12408)
* feat: enable FGA for dashboards and their public config * test: add integration test for dashboard FGA * fix: fix permissions for public dashboards, pinning, views * fix: allow viewers to manage views * fix: remove edits to the public dashboard line |
||
|
|
816ae7760e |
feat: QB support for llm trace list and span list (#12027)
Some checks failed
build-staging / prepare (push) Has been cancelled
build-staging / js-build (push) Has been cancelled
build-staging / go-build (push) Has been cancelled
build-staging / staging (push) Has been cancelled
cacheci / tests (push) Has been cancelled
Release Drafter / update_release_draft (push) Has been cancelled
* feat: support llm trace list and span list * fix: take perf into consideration * fix: more tests * fix: more cleanup * fix: cleanup and more tests * fix: add resource fingerprint cte * fix: edge cases and correct cost key * fix: update integration test * fix: update openapi * fix: address comments * fix: address comments * fix: fix tests * fix: add back the flag in metadata * fix: remove source and change to builder ai query * fix: updated openapi * fix: minor cleanup * fix: refactor as requested * fix: address comments * fix: address comments * fix: remove tracefield. explicit rejection * fix: remove comment * fix: remove accidentally added file * fix: add NewFactory * fix: refactor integration tests * fix: address comment * fix: use assert * fix: use assert and condense comments |
||
|
|
089f9eb4c6 |
chore: add api to retry migration for a dashboard (#12387)
* chore: add api to retry migration for a dashboard * feat(dashboard): add retry migration action for legacy dashboards The legacy-dashboard dialog only offered the dashboard ID and a link to support. Now that the v1->v2 migration can be re-run on demand, let an editor trigger it from there and fall back to support only if it still fails. Retrying needs edit access (the endpoint is EDITOR-gated), so viewers keep the ID-and-support dialog unchanged. --------- Co-authored-by: Ashwin Bhatkal <ashwin96@gmail.com> |
||
|
|
5917f9fe31 |
perf(tests): cache go and pnpm stores across integration image builds (#12366)
* perf(tests): cache go and pnpm stores across integration image builds Add BuildKit cache mounts for GOCACHE/GOMODCACHE and the pnpm store to the integration Dockerfiles, and build the image via the docker CLI (docker-py, used by testcontainers' DockerImage, does not support BuildKit). Embed the go build command directly so Makefile changes do not invalidate the build layer, and pin HOME/GOCACHE/GOMODCACHE/PNPM_HOME explicitly so cache-mount targets match tool defaults by contract. The with-web node stage fetches dependencies from the lockfile before the source copy, so frontend edits only re-run the offline install and build. * feat(tests): add --clean flag to prune buildkit cache mounts The go and pnpm caches introduced for the integration image build survive --teardown since they belong to the docker builder, not to any container. --clean runs docker builder prune with a type=exec.cachemount filter at session start, forcing the next image build to start cold. Documented in the integration testing guide. * feat(tests): add --rebuild flag to refresh the signoz container under --reuse --reuse keeps the running signoz container, so backend source changes are never picked up without tearing down the whole stack. --rebuild deletes the cached signoz container and recreates it from the current sources (an incremental image build), while databases, mocks and migrations stay reused. Requires --reuse; combining with --teardown or --clean is a usage error. * chore(tests): prune comments to non-obvious constraints * docs(tests): make py-test-setup rebuild signoz and audit the integration guide py-test-setup now passes --rebuild so re-running it after backend changes transparently swaps in a signoz container built from the current sources. The integration guide documents the iteration loop and fixes stale content: option defaults (clickhouse 25.12.5, schema migrator v0.144.6), the nonexistent --zookeeper-version option, Zookeeper vs ClickHouse Keeper, the e2e doc path, and the lint toolchain (ruff). * docs(tests): wire --rebuild into the e2e setup flow The e2e bootstrap shares the signoz fixture, so --rebuild already applies; with --with-web it also picks up frontend changes since the image bakes the built frontend in. The setup command now passes --rebuild, and the guide documents the iteration loop, the --rebuild/--clean flags, ClickHouse Keeper instead of Zookeeper, and the corrected integration doc path. * docs(tests): qualify --rebuild workflow for suites with custom signoz variants make py-test-setup only rebuilds the default signoz instance; suites that create their own via create_signoz(cache_key=...) keep a separately cached container. Passing --rebuild on the suite run itself rebuilds every variant that run instantiates. * docs(tests): describe --clean behaviour instead of its exact command Keeps the docs from drifting if the prune invocation behind --clean changes. |
||
|
|
052255abf5 |
feat(prometheus): add clickhouseprometheusv2 native read path (#12323)
Second-generation ClickHouse-backed Prometheus provider: the stock engine evaluates over a native storage.Querier instead of the v1 remote-read adapter. Per-selector fetch windows, last-sample-per-step reduction for subquery-free instant selectors (gated on prometheus.QueryTraits), identical-labelset merge, per-type __name__ matchers and anchored regexes, inclusive series-lookup bounds for the exporter's hour-floored registration rows. Not wired: no factory registration, no config selection, nothing serves from this package yet. Fetch budgets (series/sample ceilings) are deliberately left out for now and will come separately. Co-authored-by: Claude Fable 5 <noreply@anthropic.com> |
||
|
|
24390d7192 |
fix(ruletypes): expose above_or_equal and below_or_equal in CompareOperator enum (#12360)
* fix(ruletypes): expose above_or_equal and below_or_equal in CompareOperator enum The operators are accepted by Validate(), normalized, evaluated and returned by the rules API, but were commented out of Enum(), so the generated OpenAPI spec (and clients generated from it, e.g. terraform-provider-signoz) rejected rules the server itself creates. * fix(alerts): support above_or_equal and below_or_equal operators in CreateAlertV2 Adds the two inclusive operators to the v2 alert form: selectable in the threshold operator dropdown, normalized from all backend aliases (5/6, above_or_eq/below_or_eq, >=/<=), rendered with their symbols in threshold rows and match-type tooltips, and prefilled losslessly from dashboard panel thresholds instead of collapsing onto the strict variants. The v1 form is left untouched. |
||
|
|
bad3850117 |
feat: adding cloud storage service for GCP integration (#12341)
* feat: adding gcp memorystore redis service * refactor: updating dashboard title * refactor: extending width of uptime gauge panel * refactor: updating cpu utilization panel * refactor: updating dashboard panel to use rate function instead of hack * feat: adding compute engine service * refactor: updating dashboard panels to use rate aggregation * fix: correct typo and unit in compute engine dashboard * refactor: migrating dashboard to v6 * feat: adding gcp gke service * chore: generating openapi spec * refactor: updating icon in dashboard JSON * feat: adding gcp cloud storage service * refactor: updating dashboard and integration config * refactor: updating cloud storage icon |
||
|
|
5a8ca9573c |
feat: adding gcp gke service (#12319)
* feat: adding gcp memorystore redis service * refactor: updating dashboard title * refactor: extending width of uptime gauge panel * refactor: updating cpu utilization panel * refactor: updating dashboard panel to use rate function instead of hack * feat: adding compute engine service * refactor: updating dashboard panels to use rate aggregation * fix: correct typo and unit in compute engine dashboard * refactor: migrating dashboard to v6 * feat: adding gcp gke service * chore: generating openapi spec * refactor: updating icon in dashboard JSON |
||
|
|
0703fbf961 |
feat: adding compute engine service in GCP integration (#12166)
* feat: adding gcp memorystore redis service * refactor: updating dashboard title * refactor: extending width of uptime gauge panel * refactor: updating cpu utilization panel * refactor: updating dashboard panel to use rate function instead of hack * feat: adding compute engine service * refactor: updating dashboard panels to use rate aggregation * fix: correct typo and unit in compute engine dashboard * refactor: migrating dashboard to v6 |