Repository navigation
feat(telemetry): support custom OTLP headers in telemetry configuration - #29641
Conversation
Summary of ChangesHello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request introduces a flexible mechanism for configuring custom headers for OTLP telemetry exporters. By allowing users to specify headers via configuration files, environment variables, or CLI arguments, it enables integration with authenticated telemetry backends like Grafana Cloud, Honeycomb, and Datadog. The implementation includes robust parsing, validation, and a precedence-based resolution strategy to ensure secure and reliable header management. Highlights
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here. Footnotes
|
|
📊 PR Size: size/L
|
There was a problem hiding this comment.
Code Review
This pull request adds support for custom OTLP headers (otlpHeaders) in telemetry configuration, allowing users to configure them via settings, environment variables, or CLI arguments, and updates the telemetry SDK to pass these headers to HTTP and gRPC exporters. Feedback on the changes includes: (1) adhering to the repository style guide by using vi.stubEnv and vi.unstubAllEnvs() in tests instead of directly modifying process.env, (2) splitting OTLP headers only by commas instead of semicolons to prevent corrupting valid header values, and (3) wrapping gRPC metadata assignments in a try-catch block to avoid application crashes from invalid keys.
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request introduces support for custom OTLP headers (otlpHeaders) in telemetry configuration, allowing users to define headers via settings, environment variables (GEMINI_TELEMETRY_OTLP_HEADERS and OTEL_EXPORTER_OTLP_HEADERS), or command-line arguments. It implements robust parsing logic for both JSON objects and comma-separated key-value pairs, handles case-insensitive deduplication, and applies these headers to HTTP exporters or as metadata to gRPC exporters. The review feedback highlights a security improvement opportunity to sanitize the environment used for variable expansion in HTTP headers to prevent potential exfiltration of sensitive system environment variables by malicious extensions.
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request introduces support for custom OTLP headers (otlpHeaders) in telemetry configuration, allowing users to define headers via settings, environment variables (OTEL_EXPORTER_OTLP_HEADERS and GEMINI_TELEMETRY_OTLP_HEADERS), or CLI arguments. The changes include parsing, validation, and merging logic, as well as applying these headers to HTTP and gRPC exporters. The review feedback highlights critical security concerns regarding the potential exposure of sensitive credentials (such as bearer tokens) when raw header strings are interpolated directly into configuration error messages. Additionally, the feedback points out a potential runtime crash in validateHeadersObject if headers is null or an array, suggesting a safer type guard to prevent runtime TypeErrors.
…on-object headers
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request introduces support for custom OTLP headers (otlpHeaders) in telemetry configuration, allowing headers to be defined via settings, environment variables, or command-line arguments, and integrates them into HTTP and gRPC exporters. Review feedback recommends percent-decoding parsed header keys and values to comply with the OpenTelemetry specification, and extracting repetitive error strings in the configuration resolver into a helper function to reduce duplication.
Note: Security Review did not run due to the size of the PR.
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request introduces support for custom OTLP headers (otlpHeaders) in telemetry configuration, allowing users to configure custom headers via settings, environment variables (GEMINI_TELEMETRY_OTLP_HEADERS and OTEL_EXPORTER_OTLP_HEADERS), or CLI arguments. The changes include parsing logic for both JSON and comma-separated key-value formats, merging headers with case-insensitive deduplication, and applying them to HTTP and gRPC exporters. Documentation, schemas, and comprehensive unit tests have been updated accordingly. Feedback on the pull request suggests explicitly rejecting special keys like proto and constructor in isValidHeaderName to prevent potential prototype pollution when handling user-controlled header names.
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request adds support for custom OTLP headers (otlpHeaders) in the telemetry configuration, allowing users to supply custom headers via settings, environment variables (GEMINI_TELEMETRY_OTLP_HEADERS and OTEL_EXPORTER_OTLP_HEADERS), or CLI arguments. The implementation includes robust parsing for both JSON and comma-separated key-value formats, validation against header injection and prototype pollution, and integration with both HTTP and gRPC exporters. Comprehensive unit tests and documentation updates have been added to support this feature. There are no review comments on this pull request, and I have no feedback to provide.
This PR adds support for custom OTLP headers in the Gemini CLI telemetry configuration, allowing users to authenticate and pass custom metadata to OTLP HTTP and gRPC endpoints (such as Grafana Cloud, Honeycomb, Datadog, or authenticated OpenTelemetry Collectors).
Key Changes
packages/core/src/config/config.ts,packages/core/src/telemetry/config.ts):otlpHeaders?: Record<string, string>toTelemetrySettingsandgetTelemetryOtlpHeaders()toConfig.parseOtlpHeaders()supporting both JSON object format ({"Authorization":"Bearer token"}) and comma/semicolon-separatedkey=valuepairs (Authorization=Bearer token,x-api-key=abc123), with RFC 7230 header name and control-character validation.otlpHeadersinresolveTelemetrySettings()by mergingsettings.otlpHeaders(lowest precedence),OTEL_EXPORTER_OTLP_HEADERS,GEMINI_TELEMETRY_OTLP_HEADERS, andargv.telemetryOtlpHeaders(highest precedence) with case-insensitive header key deduplication.packages/core/src/telemetry/sdk.ts):headersto HTTP OTLP exporters (OTLPTraceExporterHttp,OTLPLogExporterHttp,OTLPMetricExporterHttp) whenotlpHeadersis non-empty.@grpc/grpc-jsMetadatafromotlpHeadersand passedmetadatato gRPC OTLP exporters (OTLPTraceExporter,OTLPLogExporter,OTLPMetricExporter) whenotlpHeadersis non-empty.packages/cli/src/config/settingsSchema.ts,schemas/settings.schema.json,docs/):otlpHeaderstoTelemetrySettingsinsettingsSchema.tsandschemas/settings.schema.json(which automatically supports$VAR_NAME/${VAR_NAME}environment variable resolution insettings.json).otlpHeadersandGEMINI_TELEMETRY_OTLP_HEADERSindocs/cli/telemetry.mdanddocs/reference/configuration.md.Related Issues
Fixes #11802
How to Validate
.gemini/settings.json(with optional environment variable interpolation) or viaGEMINI_TELEMETRY_OTLP_HEADERS/OTEL_EXPORTER_OTLP_HEADERS:{ "telemetry": { "enabled": true, "otlpEndpoint": "https://otlp.example.com", "otlpProtocol": "http", "otlpHeaders": { "Authorization": "Bearer ${OTLP_AUTH_TOKEN}" } } }