fix(tracing): address audit findings

Default to TLS export with Insecure/TLSConfig/Headers options, parent-based
ratio sampling (default 0.1), and no query string or Host in span attributes.
Name spans by route template, record status and panics (re-raised), guard the
tracer with atomic.Pointer, reject double init, add init timeout and attribute
length limit, and move to semconv v1.26.0. Add tracing.insecure and
tracing.sample_rate config keys and tests.
This commit is contained in:
Hein
2026-09-30 13:39:50 +02:00
parent 164ba2b240
commit f9c948ca4e
8 changed files with 356 additions and 46 deletions
+6
View File
@@ -91,6 +91,12 @@ type TracingConfig struct {
ServiceName string `mapstructure:"service_name"`
ServiceVersion string `mapstructure:"service_version"`
Endpoint string `mapstructure:"endpoint"`
// Insecure exports traces over plaintext gRPC (default false: TLS).
Insecure bool `mapstructure:"insecure"`
// SampleRate is the fraction of root traces sampled; 0 selects the default (0.1).
SampleRate float64 `mapstructure:"sample_rate"`
// Headers are sent with every OTLP export request (e.g. auth tokens).
Headers map[string]string `mapstructure:"headers"`
}
// CacheConfig holds cache provider configuration
+2
View File
@@ -250,6 +250,8 @@ func setDefaults(v *viper.Viper) {
v.SetDefault("tracing.service_name", "resolvespec")
v.SetDefault("tracing.service_version", "1.0.0")
v.SetDefault("tracing.endpoint", "")
v.SetDefault("tracing.insecure", false)
v.SetDefault("tracing.sample_rate", 0.1)
// Cache defaults
v.SetDefault("cache.provider", "memory")