Skip to content

Add self-report metrics step to CI workflow - #3199

Merged
bobymicroby merged 9 commits into
redis:masterfrom
bobymicroby:report-perf-metrics
Mar 17, 2026
Merged

bobymicroby merged 9 commits into
redis:masterfrom
bobymicroby:report-perf-metrics

Conversation

@bobymicroby

@bobymicroby bobymicroby commented Mar 17, 2026 •

Copy link
Copy Markdown
Member

Note

Medium Risk
Adds a new CI step that exports test metrics to an external OTLP endpoint using a repository secret; main risk is misconfigured secrets/egress or unintended data exposure from CI.

Overview
Adds a "Self Report Metrics" step to the Tests GitHub Actions workflow to publish JUnit results as OpenTelemetry metrics via redis-developer/cae-otel-ci-visibility@v1.0.2.

The step is gated to run only on pushes and on same-repo PRs, and sends metrics to a Grafana OTLP endpoint using the SELF_CHECK_OTEL_AUTHORIZATION_TOKEN secret (with OTEL_EXPORTER_OTLP_PROTOCOL set to http/protobuf).

Written by Cursor Bugbot for commit 8fc4071. This will update automatically on new commits. Configure here.

@jit-ci

jit-ci Bot commented Mar 17, 2026

Copy link
Copy Markdown

Hi, I’m Jit, a friendly security platform designed to help developers build secure applications from day zero with an MVS (Minimal viable security) mindset.

In case there are security findings, they will be communicated to you as a comment inside the PR.

Hope you’ll enjoy using Jit.

Questions? Comments? Want to learn more? Get in touch with us.

Comment thread .github/workflows/tests.yml Outdated
junit-xml-folder: 'junit-results'
service-name: 'node-redis'
service-namespace: 'redis'
service-version: 'master'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hardcoded service-version ignores non-master branches

Medium Severity

service-version is hardcoded to 'master', but this workflow triggers on pushes and PRs to master, v4.0, and v5 branches. Metrics reported from v4.0 or v5 branches will be incorrectly attributed to master, making it impossible to distinguish metrics by branch. This likely needs a dynamic value like ${{ github.ref_name }}.

Fix in Cursor Fix in Web

Comment thread .github/workflows/tests.yml Outdated
'{"Authorization": "Basic ${{
secrets.SELF_CHECK_OTEL_AUTHORIZATION_TOKEN}}"}'
env:
OTEL_EXPORTER_OTLP_PROTOCOL: 'http/protobuf' No newline at end of file

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Metrics step skipped on test failures

Medium Severity

The "Self Report Metrics" step lacks an if: always() condition, so it only runs when all previous steps (including "Run Tests") succeed. Since the purpose of CI visibility is to track test outcomes — especially failures — this step will silently be skipped in the most valuable reporting scenario.

Fix in Cursor Fix in Web

Comment thread .github/workflows/tests.yml Outdated
Comment thread .github/workflows/tests.yml Outdated
Comment thread .github/workflows/tests.yml Outdated
Comment thread .github/workflows/tests.yml
Comment thread .github/workflows/tests.yml Outdated

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

There are 3 total unresolved issues (including 2 from previous reviews).

Fix All in Cursor

otlp-headers: "Authorization=Basic ${{secrets.SELF_CHECK_OTEL_AUTHORIZATION_TOKEN}}"
env:
OTEL_EXPORTER_OTLP_PROTOCOL: "http/protobuf"
ACTIONS_STEP_DEBUG: "true"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Missing continue-on-error on non-critical metrics step

Medium Severity

The new Self Report Metrics step lacks continue-on-error: true. Since this is a non-critical observability step, any failure (OTLP endpoint outage, expired secret, network issue) will cause the entire CI job to be marked as failed — even when all tests actually passed. This could block PRs and pushes across all 12 matrix combinations whenever the telemetry backend is unavailable.

Fix in Cursor Fix in Web

@nkaradzhov nkaradzhov left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor's comment seems legit, otherwise, looks good

@bobymicroby

Copy link
Copy Markdown
Member Author

@nkaradzhov The comment is legit, but if we do that we will never know that the step is failing. I kinda prefer it to err so we fix it on time.

@bobymicroby
bobymicroby merged commit 750527f into redis:master Mar 17, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants