Repository navigation
perf(mfe): dispatch host-proxied panel queries concurrently - #268
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Central YAML (base), Organization UI (inherited) Review profile: CHILL Plan: Enterprise Run ID: 📒 Files selected for processing (4)
🔗 Linked repositories identifiedCodeRabbit considers these linked repositories for cross-repo context during reviews:
Included review availability: This review used your included allowance. Your plan provides up to 100 included reviews per hour; 82 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (3)
🧰 Additional context used📓 Path-based instructions (2)Do not allow use of `eslint-disable`, `@ts-expect-error`, or `@ts-ignore` unless there's a clear, inline comment explaining why it's necessary.⚙️ CodeRabbit configuration file Files:
We are operating at scale.⚙️ CodeRabbit configuration file Files:
🔇 Additional comments (1)
📝 WalkthroughWalkthrough
Priority: ➖ Normal Severity of issue fixed: Medium Merge Risk: ⚪ Minimal · up to No actionable merge-blocking risk is established for this change. Production performance acceptance remains pending deployment checks. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to Embedded dashboards can now send substantially more queries concurrently through the host proxy. The intended limit may also be exceeded in a late mode-switch scenario. No authentication or tenant-scope bypass was established, but downstream capacity protections could not be verified. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
✨ Simplify code
A rabbit watched the queries queue, Comment |
Summary
Remove the standalone HTTP/1 five-query bottleneck from the embedded Grafana host-proxy path. Use the existing multiplexed ceiling (1000) without pretending the Grafana server is using HTTP/2 or changing its protocol.
The minimal MFE boot config defaults
http2Enabledto false.fn_app.init()copies only panels/datasources/defaultDatasource from frontend settings, and the backend singleton constructs its worker before initialization. Consequently panels queued behind five unresolved requests despite independent backend queries.FetchQueueWorkernow reads the existing host-proxy mode when dispatching. Standalone HTTP/1 retains five, standalone HTTP/2 retains1000, API requests retain precedence, and request cancellation/error handling is unchanged. This applies to embedded query transport, not SQL authority: Handler still owns authentication, tenant/repository/provider scope and the separate restricted custom-SQL path.Evidence and validation
-41 queue/backend transport tests pass.22 unresolved panel requests dispatch22 through the host proxy versus5 standalone. Late mode activation, API priority, the multiplexed ceiling, and existing transport failures/cancellation are covered.
git diff --checkpass.yarn buildand all11 prerequisites pass; existing bundle-size warnings remain.Rollout / rollback
Normal review/checks followed by the authorized Grafana deployment. Verify real internal full-page cold/warm timings and errors after deployment; no performance acceptance is claimed yet. Revert this source change if needed; do not roll back unrelated services or alter reader flags. No IAM, SQL, credentials, ingestion, writers, table contracts or residency changes.
Handoff
User intent: complete the lean metrics migration and remove unnecessary serial bottlenecks. Existing Grafana checkout reused, branch
codex/mfe-query-dispatch, basecoderabbit_micro_frontendat c2f912c. Generated MFE HTML remains excluded. Follow normal review/merge controls; Grafana deployments are already explicitly authorized. Next: production internal end-to-end acceptance and remaining panels/filters/isolation/parity checks.Summary by CodeRabbit