Skip to content

fix: give the engine this stack's admin UI links - #172

Merged
catinspace-au merged 1 commit into
mainfrom
fix/admin-links-for-the-engine
Sep 28, 2026
Merged

catinspace-au merged 1 commit into
mainfrom
fix/admin-links-for-the-engine

Conversation

@catinspace-au

Copy link
Copy Markdown
Contributor

The engine reads DFE_ADMIN_LINKS since hyperi-io/dfe-engine#598, and Compose was handing it nothing. This is the Compose half of hyperi-io/dfe-engine#594.

  • scripts/resolve_profile.py builds the list in ONE place and writes it to .profile.mk as DFE_ADMIN_LINKS_RESOLVED.
    • Presence comes from the footprint it already resolves: Kafbat on a kafka profile with the kafbat footprint, HyperDX with the hyperdx footprint.
    • Publication comes from the Makefile's KAFBAT_GATED / HYPERDX_GATED, passed in as --unpublished kafbat|hyperdx. Nothing re-derives the dials in Python.
  • A UI is listed only when it runs AND its port is published. Gated means not listed, auth or no auth.
  • url is DFE_EXTERNAL_ORIGIN (default http://localhost) plus the host port, with the same per-surface overrides compose uses: DFE_HYPERDX_APP_URL for HyperDX, and DFE_OAUTH2_PROXY_EXTERNAL_ORIGIN for both once the auth profile puts the proxies in front.
  • probe_url is the in-network address: http://kafka-ui:8080 and http://dfe-hyperdx-proxy:8090.
  • ClickHouse Play, dfe-ui and the engine API stay out. Play is an operator port on DFE_BIND_HOST, loopback by design and outside the UI dials. The other two are the product, not admin consoles.
  • docker-compose.yml hands the engine DFE_ADMIN_LINKS: ${DFE_ADMIN_LINKS_RESOLVED:-}, so a raw docker compose outside make gets no links.

What it renders, read off the test runs:

  • default (slim, localhost): [{"name":"HyperDX","purpose":"Logs, metrics and traces search","url":"http://localhost:8090","probe_url":"http://dfe-hyperdx-proxy:8090"}]
  • single, DFE_BIND_SCOPE=all, DFE_EXTERNAL_ORIGIN=http://dfe.example.test: Kafbat on http://dfe.example.test:8081 and HyperDX on http://dfe.example.test:8090
  • the same with DFE_INFRA_UIS_EXTERNAL=false: []

Tests: scripts/tests/test_admin_links.py, 147 of them.

  • The matrix: kafka vs grpc x kafbat on/off x hyperdx on/off x each gate x auth on/off x localhost vs an external origin, 128 cases through resolve_profile.main().
  • Every entry is checked against the engine's own shape: no extra keys, non-empty strings, absolute http(s) URLs, no credentials.
  • Seven cases run the REAL Makefile in a scratch copy of the checkout and render docker compose config for dfe-engine, so the JSON is shown to survive make, the environment and compose interpolation byte for byte. Nothing is started.

make check-python check-tests check-compose check-docs check-hardfail all pass locally (609 tests).

Done when the engine on a Compose stack lists exactly the infra UIs that stack publishes.

The engine reads DFE_ADMIN_LINKS since hyperi-io/dfe-engine#598 and Compose was handing it nothing. resolve_profile.py now builds the list in one place, from the footprint that starts Kafbat and HyperDX plus the Makefile's KAFBAT_GATED and HYPERDX_GATED, which make passes in as --unpublished. So a UI is listed only when it runs AND its port is published.

Each url is DFE_EXTERNAL_ORIGIN (or the per-surface override compose already builds that UI's URLs from) plus the host port. Each probe_url is the in-network address. ClickHouse Play, dfe-ui and the engine API stay out: Play is an operator port on DFE_BIND_HOST, and the other two are the product.

Tests cover the transport, footprint, gate, auth and origin matrix, and run the real Makefile in a scratch copy through docker compose config, so the JSON is shown to reach the engine service byte for byte. Nothing is started.

Part of hyperi-io/dfe-engine#594.
@catinspace-au
catinspace-au merged commit d8ee7d1 into main Sep 28, 2026
7 checks passed
@catinspace-au
catinspace-au deleted the fix/admin-links-for-the-engine branch September 28, 2026 04:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant