Skip to content

design-proposals: network flow observability for cozyplane - #65

Open
lfneosequentia (lfinmauritius) wants to merge 1 commit into
cozystack:mainfrom
lfinmauritius:proposal/cozyplane-flow-observability
Open

design-proposals: network flow observability for cozyplane#65
lfneosequentia (lfinmauritius) wants to merge 1 commit into
cozystack:mainfrom
lfinmauritius:proposal/cozyplane-flow-observability

Conversation

@lfinmauritius

Copy link
Copy Markdown

What

Adds a design proposal: network flow observability for cozyplane — Hubble-parity L3/L4 flow verdicts, reasons, distribution metrics, and DNS metrics for the cozyplane networking variant.

Why

A cluster running the cozyplane variant has no Cilium and no Hubble (cozyplane replaces kube-ovn + Cilium + kube-proxy). Today its datapath exposes only four aggregate counters; two of the most important drop sites are silent, and the anti-spoof drop is indistinguishable from a policy deny. This proposal fills that gap: per-flow events with a verdict and a reason (which SecurityGroup / NetworkPolicy / isolation rule), an operator CLI (flowctl observe), bounded-cardinality Prometheus series scrapable by Prometheus and VictoriaMetrics, and DNS metrics from the resolver cozyplane already runs.

Operator-only, off by default (matching Cozystack's Hubble-disabled-by-default posture), bounded cardinality, byte-identical datapath behaviour when disabled.

Scope

  • Deliberately stops at L4 — HTTP/Kafka/gRPC L7 stays with Cilium/Hubble (the kubeovn-cilium variant), which cozyplane never coexists with.
  • Complementary to distributed-tracing (OTLP app spans, different layer) and coroot-ebpf-observability (service-map/profiling platform) — neither can see cozyplane's policy verdicts, which live only in the CNI datapath.

Requesting feedback.

Hubble-parity L3/L4 flow verdicts, reasons, distribution metrics and DNS metrics for the cozyplane networking variant, which ships without Cilium/Hubble. Operator-only, off by default, bounded cardinality.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Loïc Fontaine <lfinmauritius@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Aug 25, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 32a08b11-d041-4ba9-956d-96840443fa74


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant