Skip to content

op-batcher: expose enclave Prometheus metrics via enclaver ingress - #536

Open
jjeangal wants to merge 10 commits into
espresso/batcherfrom
espresso/enclave-metrics
Open

jjeangal wants to merge 10 commits into
espresso/batcherfrom
espresso/enclave-metrics

Conversation

@jjeangal

@jjeangal jjeangal commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Follow-up to #527. Ports the "expose Prometheus :7300 via enclaver ingress" work into the op repo (Asana: Setup Prometheus Metrics / Chaos Testnet).

What

  • op-batcher/enclave-tools/enclaver.go: add a MetricsPort = 7300 ingress entry to the enclaver manifest so enclaver bridges the metrics port out of the enclave.
  • op-batcher/enclave-entrypoint.bash: launch op-batcher with --metrics.enabled --metrics.addr=0.0.0.0 --metrics.port=7300 (skipped if the caller already set metrics). Binding to 0.0.0.0 is required — op-service has a TODO: Switch to 127.0.0.1 default that would otherwise break ingress — and is guarded so it won't duplicate caller-provided flags.

Not included (lives in tee-image-builder)

The parent-side tcp<->vsock bridge that exposes 7300 on the host, same split as the 8337/8338 ports.

Base

Stacked on espresso/tee-images (#527) since that branch introduces the enclave tooling and isn't merged yet.

🤖 Generated with Claude Code


shenkeyao and others added 8 commits September 11, 2026 12:10
Add a :7300 ingress port to the enclaver manifest and launch op-batcher
with metrics enabled on 0.0.0.0:7300 so the enclaver ingress can bridge
Prometheus metrics out of the Nitro enclave to the parent.

The parent-side bridge (tcp<->vsock) lives in EspressoSystems/tee-image-builder.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 0433510f2b

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread op-batcher/enclave-entrypoint.bash Outdated
# localhost, or the ingress cannot reach the endpoint. Skip if the caller already set it.
metrics_already_set=false
for arg in "${all_args[@]}"; do
case "$arg" in --metrics.enabled*) metrics_already_set=true; break;; esac

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Keep caller-enabled metrics compatible with ingress

When a caller supplies --metrics.enabled together with a custom --metrics.port or --metrics.addr, this check suppresses all of the ingress-compatible defaults. The manifest still exposes only port 7300, while initMetricsServer binds the caller-supplied address and port, so for example --metrics.enabled --metrics.port=9000 leaves the parent-side 7300 bridge with no listener; a loopback address has the same issue. Inject the address/port independently or reject configurations that cannot be reached through the fixed ingress.

Useful? React with 👍 / 👎.

@jcortejoso
jcortejoso self-requested a review October 7, 2026 14:39
Comment thread op-batcher/enclave-entrypoint.bash Outdated
Comment on lines +241 to +246
for arg in "${all_args[@]}"; do
case "$arg" in --metrics.enabled*) metrics_already_set=true; break;; esac
done
if ! $metrics_already_set; then
all_args+=(--metrics.enabled --metrics.addr=0.0.0.0 --metrics.port=7300)
fi

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this can be confusing in some cases. If someone passes --metrics.enabled --metrics.port=9000, we skip the defaults and the batcher ends up on a port the manifest doesn't bridge, so scrapes just fail quietly. The other way round, --metrics.port=9000 on its own gets overridden by the appended 7300. Since the cli takes the last value, I think we can drop the loop and just order the args:

all_args=(--metrics.enabled --metrics.addr=0.0.0.0 "${filtered_args[@]}" "${url_args[@]}" --metrics.port=7300)

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fair points!

Review on #536: the previous "skip if caller set --metrics.enabled" guard
let a caller-supplied --metrics.port/addr bind somewhere the enclaver ingress
(fixed at 7300) doesn't bridge, so scrapes failed silently. Drop the guard and
append enabled/addr/port last so they win via urfave/cli's last-value-wins,
guaranteeing the batcher always serves on 0.0.0.0:7300.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-08T19:06:13.600594Z 40106ea New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Base automatically changed from espresso/tee-images to espresso/batcher October 9, 2026 20:57

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants