Skip to content

[Network/system-probe] stream-ish network connections over our unix socket#16806

Closed
nplanel wants to merge 1 commit intomainfrom
nplanel/avoid-memburst-streamish-to-agent
Closed

[Network/system-probe] stream-ish network connections over our unix socket#16806
nplanel wants to merge 1 commit intomainfrom
nplanel/avoid-memburst-streamish-to-agent

Conversation

@nplanel
Copy link
Copy Markdown
Contributor

@nplanel nplanel commented Apr 27, 2023

What does this PR do?

This would avoid spike memory allocation on system-probe as
we will pull all the NPM connections, but for DNS and USM we will populate only a bucket (maxConnectionsPerMessage)
and send it to process-agent when requested.

The mechanism relay on http status code 206 (StatusPartialContent), meaning the caller need to call system-probe again as we have more data.

Motivation

Avoid spike allocation and OOMs in containerized production

Additional Notes

Depend on agent-payload PR

Let's say it's a first step, as we could a better job on process-agent and system-probe
Would require specific E2E tests

Possible Drawbacks / Trade-offs

Describe how to test/QA your changes

Reviewer's Checklist

  • If known, an appropriate milestone has been selected; otherwise the Triage milestone is set.
  • Use the major_change label if your change either has a major impact on the code base, is impacting multiple teams or is changing important well-established internals of the Agent. This label will be use during QA to make sure each team pay extra attention to the changed behavior. For any customer facing change use a releasenote.
  • A release note has been added or the changelog/no-changelog label has been applied.
  • Changed code has automated tests for its functionality.
  • Adequate QA/testing plan information is provided if the qa/skip-qa label is not applied.
  • At least one team/.. label has been applied, indicating the team(s) that should QA this change.
  • If applicable, docs team has been notified or an issue has been opened on the documentation repo.
  • If applicable, the need-change/operator and need-change/helm labels have been applied.
  • If applicable, the k8s/<min-version> label, indicating the lowest Kubernetes version compatible with this feature.
  • If applicable, the config template has been updated.

@nplanel nplanel requested review from a team as code owners April 27, 2023 15:30
@nplanel nplanel requested a review from a team April 27, 2023 15:30
@nplanel nplanel changed the title [Network/system-probe] avoid stream [Network/system-probe] stream-ish network connections over our unix socket Apr 27, 2023
@nplanel nplanel force-pushed the nplanel/avoid-memburst-streamish-to-agent branch 2 times, most recently from e4e3d17 to ae1aa78 Compare April 27, 2023 15:36
Comment thread pkg/network/tracer/tracer.go Outdated

// GetActiveConnections returns the delta for connection info from the last time it was called with the same clientID
func (t *Tracer) GetActiveConnections(clientID string) (*network.Connections, error) {
func (t *Tracer) GetActiveConnections(clientID string, maxConnectionPerMessage int) (*network.Connections, bool, error) {
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think it would be better if the paging was one level up as it is more a function of the request. There is also this for reference: https://cloud.google.com/apis/design/design_patterns#list_pagination

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I can't do one level up, as the goal is to reduce the allocation during the aggregation of dns, http by processing only a page/subset of connections. NPM connections as reference.

On paging we can embedded the mechanism in the protobuf, but would matter as it's used only on our internal api (unix socket)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The paging needs to be a little more sophisticated to handle cases like where process-agent may crash/restart. Since process-agent uses the same client id every time, just using client id to track pages won't be sufficient.

For moving one level up, I meant do the pagination in modules/network_tracer.go. Another option would be to add something like GetActiveConnectionsPaged to the tracer which would entail fewer side-affects to existing code.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Adding GetActiveConnectionsPaged sound good
moving up to modules/network_tracer.go it's too late we will got the allocation spike from dns, http already

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I thought the allocations were coming from aggregations, and those happen in writeConnections, right? In the call to Marshal?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yes it happen on writeConnections, that why I give only a subset of connections

Next patch would fix the GetDelta()->GetStats per protocols that iterate only on a subset of connections, this would limit the allocation even more

@nplanel nplanel force-pushed the nplanel/avoid-memburst-streamish-to-agent branch 2 times, most recently from c2afcb6 to ba4c0ce Compare April 28, 2023 09:56
@nplanel nplanel requested a review from hmahmood April 28, 2023 12:46
@nplanel nplanel force-pushed the nplanel/avoid-memburst-streamish-to-agent branch from ba4c0ce to a6b8dcc Compare April 28, 2023 13:17
@pr-commenter
Copy link
Copy Markdown

pr-commenter bot commented Apr 28, 2023

Bloop Bleep... Dogbot Here

Regression Detector Results

Run ID: 19a6319c-eb64-471d-9227-5b10dddd1e3d
Baseline: a0d9ffd
Comparison: a6b8dcc
Total datadog-agent CPUs: 7

Explanation

A regression test is an integrated performance test for datadog-agent in a repeatable rig, with varying configuration for datadog-agent. What follows is a statistical summary of a brief datadog-agent run for each configuration across SHAs given above. The goal of these tests are to determine quickly if datadog-agent performance is changed and to what degree by a pull request.

Because a target's optimization goal performance in each experiment will vary somewhat each time it is run, we can only estimate mean differences in optimization goal relative to the baseline target. We express these differences as a percentage change relative to the baseline target, denoted "Δ mean %". These estimates are made to a precision that balances accuracy and cost control. We represent this precision as a 90.00% confidence interval denoted "Δ mean % CI": there is a 90.00% chance that the true value of "Δ mean %" is in that interval.

We decide whether a change in performance is a "regression" -- a change worth investigating further -- if both of the following two criteria are true:

  1. The estimated |Δ mean %| ≥ 5.00%. This criterion intends to answer the question "Does the estimated change in mean optimization goal performance have a meaningful impact on your customers?". We assume that when |Δ mean %| < 5.00%, the impact on your customers is not meaningful. We also assume that a performance change in optimization goal is worth investigating whether it is an increase or decrease, so long as the magnitude of the change is sufficiently large.

  2. Zero is not in the 90.00% confidence interval "Δ mean % CI" about "Δ mean %". This statement is equivalent to saying that there is at least a 90.00% chance that the mean difference in optimization goal is not zero. This criterion intends to answer the question, "Is there a statistically significant difference in mean optimization goal performance?". It also means there is no more than a 10.00% chance this criterion reports a statistically significant difference when the true difference in mean optimization goal is zero -- a "false positive". We assume you are willing to accept a 10.00% chance of inaccurately detecting a change in performance when no true difference exists.

The table below, if present, lists those experiments that have experienced a statistically significant change in mean optimization goal performance between baseline and comparison SHAs with 90.00% confidence OR have been detected as newly erratic. Negative values of "Δ mean %" mean that baseline is faster, whereas positive values of "Δ mean %" mean that comparison is faster. Results that do not exhibit more than a ±5.00% change in their mean optimization goal are discarded. An experiment is erratic if its coefficient of variation is greater than 0.1. The abbreviated table will be omitted if no interesting change is observed.

Changes in experiment optimization goals with confidence ≥ 90.00% and |Δ mean %| ≥ 5.00%:

experiment goal Δ mean % confidence
tcp_dd_logs_filter_exclude ingress throughput +6.10 100.00%
Fine details of change detection per experiment.
experiment goal Δ mean % Δ mean % CI confidence
tcp_dd_logs_filter_exclude ingress throughput +6.10 [+5.87, +6.32] 100.00%
tcp_syslog_to_blackhole ingress throughput -0.07 [-0.15, +0.02] 67.82%
uds_dogstatsd_to_api ingress throughput -0.08 [-1.10, +0.94] 7.98%
otel_to_otel_logs ingress throughput -0.88 [-0.97, -0.78] 100.00%
file_to_blackhole ingress throughput -2.90 [-3.02, -2.78] 100.00%

Comment thread pkg/process/checks/net.go Outdated
if !more {
return connections, err
}
connections.Aggregate(cnx)
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Where is this defined? I couldn't find it in agent-payload

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread pkg/network/tracer/tracer.go Outdated
ebpfTracer connection.Tracer
bpfTelemetry *telemetry.EBPFTelemetry

clientConnections map[string]connections
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This could use a comment explaining how it's used. It took some reading to figure out that this field was used to cache the last run of the tracer

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

done

Comment thread pkg/network/tracer/tracer.go Outdated
Comment on lines +417 to +453
t.clientConnections[clientID] = connections{
latestTime: latestTime,
active: t.activeBuffer.Connections(),
}
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This will not copy the underlying buffer no? So if getActiveConnections() gets called with another client, the current value in clientConnections[firstClient] will get clobbered

@nplanel nplanel force-pushed the nplanel/avoid-memburst-streamish-to-agent branch 4 times, most recently from edae1bf to 48ea60f Compare May 9, 2023 16:48
@nplanel nplanel marked this pull request as draft May 9, 2023 17:17
@nplanel nplanel force-pushed the nplanel/avoid-memburst-streamish-to-agent branch from 48ea60f to f044638 Compare June 9, 2023 15:54
@nplanel nplanel force-pushed the nplanel/avoid-memburst-streamish-to-agent branch from f044638 to f53fc73 Compare June 9, 2023 16:14
@dd-devflow dd-devflow bot closed this Apr 19, 2024
@dd-devflow dd-devflow bot deleted the nplanel/avoid-memburst-streamish-to-agent branch April 19, 2024 00:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants