Files
substrate/manifests
Da Huang 1ec75f9578 manifests: wire OTLP exporter settings into the egress ext-proc (#1460)
The egress ext-proc container never received the shared OTLP exporter
settings: unlike every other control plane component, its Deployment did
not consume ate-otel-config via envFrom, so OTEL_EXPORTER_OTLP_ENDPOINT
was unset and the OTel SDK fell back to localhost:4317, where nothing
listens. Every egress metric and span was silently dropped, with the SDK
logging an export-failure warning every ~20s — on a live GKE install
this was the largest warn/error source in the cluster, and the
registry-listed ext_proc instruments simply did not exist in GMP for the
egress gateway.

Give the ext-proc the same envFrom, POD_UID, and
OTEL_RESOURCE_ATTRIBUTES wiring the ingress router has, in both the
plain and sdsmint egress manifests. --otlp-collector-address stays
explicitly empty: that flag only controls Envoy-side tracing, and a span
per CONNECT tunnel is dataplane-volume noise; the comment now says so
instead of leaving the empty value looking accidental. Also add
atenet-egress to the consumer list in the ate-otel-config header
comment.

Verified on a live install: after applying the env change the SDK
export-failure warnings stop and target_info for the egress deployment
appears in Managed Prometheus.

Fixes #1459

> It's a good idea to open an issue first for discussion.

- [ ] Tests pass
- [ ] Appropriate changes to documentation are included in the PR
2026-09-03 19:49:31 -04:00
..