Introduce `ApmRelayConfiguration` / `ApmRelay`, which sits in front of the
trace-agent: it listens on TCP and/or a Unix domain socket where the
trace-agent normally would, handles Datadog v1.0 (ETP) trace payloads
itself, and proxies every other request to the relocated trace-agent.
- `POST /v1.0/traces` is dispatched as `Payload::Http` on the `traces`
output, with headers preserved verbatim so tracer metadata reaches the
decoder. Bodies over `max_payload_size` get 413; other body read errors
get 400. The response is an empty `200 OK` for now.
- Every other path, and every other method on `/v1.0/traces`, is forwarded
to `proxy_destination` (`http://host:port` or `unix:///path`). Requests
and responses are streamed rather than buffered, hop-by-hop headers are
dropped in both directions, and the proxy imposes no request timeout of
its own since each trace-agent route enforces its own. An unreachable
trace-agent is answered with 502.
Proxying hides the tracer's Unix domain socket peer credentials from the
trace-agent, which it uses for origin detection when a tracer sends no
container headers. A TODO marks where ADP will inject the container ID.
The relay takes plain values and states no defaults of its own. It is not
wired into the topology yet.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Summary
Stacked on #2707 (config). Adds
ApmRelay, which sits in front of the trace-agent when the experimental APM proxy is enabled:apm_config.receiver_port/receiver_socket/apm_non_local_traffic/bind_host.POST /v1.0/tracesis handled by ADP: dispatched asPayload::Httpon thetracesoutput with headers preserved verbatim, for the ETP decoder that comes later in the stack. 413 overmax_payload_size, 400 on other body read errors, empty200 OKfor now. The real response contract (rate_by_service, load shedding) is a follow-up./v1.0/traces, is reverse-proxied toproxy_destination(http://host:portorunix:///path):The proxy lives in its own
relays/apm/proxy.rs.Known gap: for tracers that send no container headers, the trace-agent derives the container ID from the UDS peer credentials. Behind the proxy, those credentials are ADP's. A TODO in
proxy.rsmarks where ADP will injectDatadog-Container-IDin a follow-up.The relay is not wired into the topology yet, so there's no user-visible change.
Change Type
How did you test this PR?
POST /v1.0/tracesis dispatched; other paths and methods are proxiedmake check-all: cleanReferences
Part of #2438: #2437 (TCP/UDS listeners; named pipe deferred), #2439 (payload size bound), #2450 (routes; everything but v1 served by the trace-agent via the proxy).
🤖 Generated with Claude Code