mirror of
https://github.com/bitechdev/ResolveSpec.git
synced 2026-10-05 13:01:58 +00:00
fix(tracing): address audit findings
Default to TLS export with Insecure/TLSConfig/Headers options, parent-based ratio sampling (default 0.1), and no query string or Host in span attributes. Name spans by route template, record status and panics (re-raised), guard the tracer with atomic.Pointer, reject double init, add init timeout and attribute length limit, and move to semconv v1.26.0. Add tracing.insecure and tracing.sample_rate config keys and tests.
This commit is contained in:
@@ -33,6 +33,10 @@ type Config struct {
|
||||
ServiceVersion string // Version for tracking deployments
|
||||
Endpoint string // OTLP collector endpoint (e.g., "localhost:4317")
|
||||
Enabled bool // Enable/disable tracing
|
||||
Insecure bool // Plaintext gRPC export (default: TLS)
|
||||
TLSConfig *tls.Config // Optional TLS customisation
|
||||
Headers map[string]string // OTLP auth headers
|
||||
SampleRate float64 // Root-trace sampling fraction (default 0.1)
|
||||
}
|
||||
```
|
||||
|
||||
@@ -429,8 +433,10 @@ if err != nil {
|
||||
For high-traffic services, configure sampling:
|
||||
|
||||
```go
|
||||
// In production: sample 10% of traces
|
||||
// Currently using AlwaysSample() - update in tracing.go if needed
|
||||
// Default is ParentBased(TraceIDRatioBased(0.1)); set Config.SampleRate (0-1) to change.
|
||||
// Query strings are never exported; span names use the matched route pattern
|
||||
// (Request.Pattern, or MiddlewareWithRoute for other routers). Install the
|
||||
// middleware inside the panic-recovery middleware.
|
||||
```
|
||||
|
||||
### 5. Context Propagation
|
||||
|
||||
Reference in New Issue
Block a user