From 86b7b04d7b4445e299f489339b58fad9d350cc22 Mon Sep 17 00:00:00 2001 From: Matt Westrik Date: Wed, 9 Sep 2026 15:04:01 -0700 Subject: [PATCH 1/2] [feat] Send agent-sandbox metrics to the telemetry pod MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Include `retool.telemetry.includeEnvVars` on the agent-sandbox controller and proxy deployments, add `STATSD_HOST`/`STATSD_PORT` (telemetry service, UDP 9125) plus `NODE_NAME` to the sandbox Job template, and tag sandbox Jobs with `telemetry.retool.com/service-name` — all gated on `telemetry.enabled`. Also allow UDP 9125 egress from the sandbox, controller, and proxy NetworkPolicies to the telemetry pod so the agent_executor statsd emissions (`retool.ae.*`) reach Grafana like backend and code-executor metrics do. --- .../agent_sandbox_networkpolicy.yaml | 27 +++++++++++++++++++ .../templates/deployment_agent_sandbox.yaml | 13 +++++++-- 2 files changed, 38 insertions(+), 2 deletions(-) diff --git a/charts/retool/templates/agent_sandbox_networkpolicy.yaml b/charts/retool/templates/agent_sandbox_networkpolicy.yaml index 4ba72d42..810a70b2 100644 --- a/charts/retool/templates/agent_sandbox_networkpolicy.yaml +++ b/charts/retool/templates/agent_sandbox_networkpolicy.yaml @@ -65,6 +65,15 @@ spec: ports: - port: {{ $as.proxy.port }} protocol: TCP + {{- if .Values.telemetry.enabled }} + - to: + - podSelector: + matchLabels: + {{- include "retool.telemetry.selectorLabels" . | nindent 14 }} + ports: + - port: 9125 + protocol: UDP + {{- end }} {{- with $as.networkPolicy.extraEgress }} {{- toYaml . | nindent 4 }} {{- end }} @@ -124,6 +133,15 @@ spec: protocol: TCP - port: 6443 protocol: TCP + {{- if .Values.telemetry.enabled }} + - to: + - podSelector: + matchLabels: + {{- include "retool.telemetry.selectorLabels" . | nindent 14 }} + ports: + - port: 9125 + protocol: UDP + {{- end }} --- {{- /* ======================================================================= @@ -213,4 +231,13 @@ spec: - {{ . }} {{- end }} {{- end }} + {{- if .Values.telemetry.enabled }} + - to: + - podSelector: + matchLabels: + {{- include "retool.telemetry.selectorLabels" . | nindent 14 }} + ports: + - port: 9125 + protocol: UDP + {{- end }} {{- end }} diff --git a/charts/retool/templates/deployment_agent_sandbox.yaml b/charts/retool/templates/deployment_agent_sandbox.yaml index daf4a70a..387b8935 100644 --- a/charts/retool/templates/deployment_agent_sandbox.yaml +++ b/charts/retool/templates/deployment_agent_sandbox.yaml @@ -107,7 +107,8 @@ data: "metadata": { "labels": { "retoolService": "{{ include "retool.agentSandbox.name" . }}", - "app.kubernetes.io/name": "{{ include "retool.agentSandbox.name" . }}" + "app.kubernetes.io/name": "{{ include "retool.agentSandbox.name" . }}", + "telemetry.retool.com/service-name": "agent-sandbox" } }, "spec": { @@ -118,7 +119,8 @@ data: "annotations": {{- $sandboxAnnotations := dict "karpenter.sh/do-not-disrupt" "true" -}}{{- $_ := set $sandboxAnnotations "cluster-autoscaler.kubernetes.io/safe-to-evict" "false" -}}{{- range $k, $v := $as.sandbox.annotations }}{{- $_ := set $sandboxAnnotations $k $v }}{{- end }}{{ toJson $sandboxAnnotations }}, "labels": { "retoolService": "{{ include "retool.agentSandbox.name" . }}", - "app.kubernetes.io/name": "{{ include "retool.agentSandbox.name" . }}" + "app.kubernetes.io/name": "{{ include "retool.agentSandbox.name" . }}", + "telemetry.retool.com/service-name": "agent-sandbox" } }, "spec": { @@ -198,6 +200,11 @@ data: ,{"name": "SANDBOX_IDLE_TIMEOUT_MS", "value": "{{ $as.sandbox.sandboxIdleTimeoutMs }}"} ,{"name": "SANDBOX_GLOBAL_LIFETIME_MS", "value": "{{ $as.sandbox.sandboxGlobalLifetimeMs }}"} ,{"name": "SANDBOX_READY_TIMEOUT_MS", "value": "{{ $as.sandbox.sandboxReadyTimeoutMs }}"} + {{- if .Values.telemetry.enabled }} + ,{"name": "STATSD_HOST", "value": "{{ include "retool.telemetry.fullname" . }}.{{ .Release.Namespace }}"} + ,{"name": "STATSD_PORT", "value": "9125"} + ,{"name": "NODE_NAME", "valueFrom": {"fieldRef": {"fieldPath": "spec.nodeName"}}} + {{- end }} {{- if $as.jwtPublicKey }} ,{"name": "AGENT_SANDBOX_JWT_PUBLIC_KEY", "value": {{ $as.jwtPublicKey | toJson }}} {{- else if $as.externalSecret.name }} @@ -327,6 +334,7 @@ spec: value: "controller" - name: CONTROLLER_PORT value: {{ $as.controller.port | quote }} + {{- include "retool.telemetry.includeEnvVars" . | nindent 12 }} - name: STATE_BACKEND value: "postgres" {{- include "retool.agentSandbox.postgresUrlEnv" . | nindent 12 }} @@ -534,6 +542,7 @@ spec: value: "proxy" - name: PROXY_PORT value: {{ $as.proxy.port | quote }} + {{- include "retool.telemetry.includeEnvVars" . | nindent 12 }} - name: STATE_BACKEND value: "postgres" {{- include "retool.agentSandbox.postgresUrlEnv" . | nindent 12 }} From 9f4fe54d2d744ccc52b128b1b5dadc2e52014c21 Mon Sep 17 00:00:00 2001 From: Matt Westrik Date: Wed, 9 Sep 2026 15:26:17 -0700 Subject: [PATCH 2/2] [chore] Bump chart version for agent-sandbox telemetry changes --- charts/retool/Chart.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/charts/retool/Chart.yaml b/charts/retool/Chart.yaml index 54936837..47e125e1 100644 --- a/charts/retool/Chart.yaml +++ b/charts/retool/Chart.yaml @@ -2,7 +2,7 @@ apiVersion: v2 name: retool description: A Helm chart for Kubernetes type: application -version: 6.11.25 +version: 6.11.26 maintainers: - name: Retool Engineering email: engineering+helm@retool.com