Skip to content

feat: Ship the network metrics policy with the control plane - #504

Draft
scotwells wants to merge 1 commit into
mainfrom
feat/ship-resource-metrics-policy
Draft

scotwells wants to merge 1 commit into
mainfrom
feat/ship-resource-metrics-policy

Conversation

@scotwells

@scotwells scotwells commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The resource-metrics service publishes no Gateway, proxy, domain or network status for any project, because the operator's metric policy for those kinds sits in the repository but no bundle path deploys it.

Deployments therefore still depend on per-project kube-state-metrics exporters for these series, and in Datum's production that means 395 exporters nothing owns, with projects created since April getting no status at all.

This ships the policy with the control-plane resources alongside the operator's CRDs, so any control plane that applies them publishes the metrics. The local dev install leaves it out, since its cluster has no resource-metrics CRD.

Important

Applying the control-plane resources now requires the resource-metrics CRD on that control plane. Datum's infra must land datum-cloud/infra#6212 first so a policy's status cannot stall the apply. Staging picks this up from main builds on merge. Datum's production picks up any new release on its own, so hold the release that carries this until that health check is promoted to production.

Test plan

  • The control-plane resources render with the policy and the local dev install renders unchanged
  • In staging the policy is accepted with no invalid expressions and the control-plane apply stays Ready
  • Staging publishes Gateway, HTTPProxy and Domain series for every project that has those objects
  • Kustomize validation, lint and tests pass

Related to https://github.com/datum-cloud/infra/issues/6198

The networking-metrics ResourceMetricsPolicy describes the Gateway,
HTTPProxy, Domain, HTTPRoute and network metrics the resource-metrics
service should publish for every project, but no bundle path includes it,
so nothing deploys it. Deployments still rely on per-project
kube-state-metrics exporters for these series.

Key changes:
- Include the policy in upstream_resources, the path a control plane
  applies alongside the operator's CRDs
- Leave it out of the local dev install, whose cluster has no
  resource-metrics CRD

A control plane that applies upstream_resources now needs the
resourcemetrics.miloapis.com CRD installed first.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

1 participant