Skip to content

design-proposals: network flow observability for cozyplane - #65

Open
lfneosequentia (lfinmauritius) wants to merge 1 commit into
cozystack:mainfrom
lfinmauritius:proposal/cozyplane-flow-observability
Open

design-proposals: network flow observability for cozyplane#65
lfneosequentia (lfinmauritius) wants to merge 1 commit into
cozystack:mainfrom
lfinmauritius:proposal/cozyplane-flow-observability

Conversation

@lfinmauritius

Copy link
Copy Markdown

What

Adds a design proposal: network flow observability for cozyplane — Hubble-parity L3/L4 flow verdicts, reasons, distribution metrics, and DNS metrics for the cozyplane networking variant.

Why

A cluster running the cozyplane variant has no Cilium and no Hubble (cozyplane replaces kube-ovn + Cilium + kube-proxy). Today its datapath exposes only four aggregate counters; two of the most important drop sites are silent, and the anti-spoof drop is indistinguishable from a policy deny. This proposal fills that gap: per-flow events with a verdict and a reason (which SecurityGroup / NetworkPolicy / isolation rule), an operator CLI (flowctl observe), bounded-cardinality Prometheus series scrapable by Prometheus and VictoriaMetrics, and DNS metrics from the resolver cozyplane already runs.

Operator-only, off by default (matching Cozystack's Hubble-disabled-by-default posture), bounded cardinality, byte-identical datapath behaviour when disabled.

Scope

  • Deliberately stops at L4 — HTTP/Kafka/gRPC L7 stays with Cilium/Hubble (the kubeovn-cilium variant), which cozyplane never coexists with.
  • Complementary to distributed-tracing (OTLP app spans, different layer) and coroot-ebpf-observability (service-map/profiling platform) — neither can see cozyplane's policy verdicts, which live only in the CNI datapath.

Requesting feedback.

Hubble-parity L3/L4 flow verdicts, reasons, distribution metrics and DNS metrics for the cozyplane networking variant, which ships without Cilium/Hubble. Operator-only, off by default, bounded cardinality.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Loïc Fontaine <lfinmauritius@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Aug 25, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 32a08b11-d041-4ba9-956d-96840443fa74


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

1 participant