Skip to content

Add triple chain-of-causation with kafka test - #850

Merged
Sheeproid merged 20 commits into
masterfrom
kafka-test
Aug 18, 2025
Merged

Sheeproid merged 20 commits into
masterfrom
kafka-test

Conversation

@Sheeproid

Copy link
Copy Markdown
Collaborator

Test case demonstrating a chain of causation for Kafka latency:

  1. Order service produces messages to Kafka topic
  2. Analytics service consumes messages and writes them to OpenSearch
  3. OpenSearch has aggressive index optimization enabled with background threads continuously optimizing indices
  4. These optimization operations consume excessive CPU, making OpenSearch writes slow
  5. Slow writes cause the analytics service to lag behind in consuming messages
  6. This consumer lag manifests as Kafka high latency alerts

@Sheeproid
Sheeproid requested a review from arikalon1 August 17, 2025 06:27
@coderabbitai

coderabbitai Bot commented Aug 17, 2025 •

Copy link
Copy Markdown
Contributor

Walkthrough

Adds a multi-stage Kubernetes test fixture under tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency: namespace app-156, Zookeeper, a Python in-memory OpenSearch-like service, Kafka broker, producer (order-service), consumer (analytics-service), orchestration YAML, verification script, and increases a test-run timeout constant.

Changes

Cohort / File(s) Summary
Base namespace and in-memory OpenSearch
tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage1-base.yaml
Adds Namespace app-156; Service & Deployment zookeeper (Bitnami); Service & Deployment opensearch running python:3.9-slim executing opensearch_server.py from ConfigMap opensearch-script. Adds ConfigMap with embedded Python OpenSearch-like server. Includes env (MERGE_POLICY, REFRESH_INTERVAL), resources, startupProbe, volumes.
Kafka broker
tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage2-kafka.yaml
Adds Service & Deployment kafka (Bitnami Kafka) in app-156, configured for PLAINTEXT with Zookeeper, advertised listeners, readiness/liveness probes, and resource requests/limits.
Consumer (analytics-service)
tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage3-consumer.yaml
Adds ConfigMap analytics-service-script containing analytics_service.py and Deployment analytics-service (python:3.9-slim) that installs kafka-python/opensearch-py, waits for OpenSearch, ensures index kafka-messages, consumes messages topic, and indexes into OpenSearch.
Producer (order-service)
tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage4-producer.yaml
Adds ConfigMap order-service-script with order_service.py and Deployment order-service (python:3.9-slim) that installs kafka-python and continuously produces JSON messages to topic messages with startup retries and resource settings.
Test orchestration
tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/test_case.yaml
Adds test_case describing scenario and expected outputs, staged apply sequence (stage1→stage4), readiness waits to allow lag buildup, and teardown steps.
Verification script
tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/verify_setup.sh
Adds verify_setup.sh to validate namespace/pod counts, per-service Running state, Kafka & OpenSearch readiness loops, consumer lag polling, optional OpenSearch CPU reporting, and producer/consumer log checks.
Test utils timeout
tests/llm/utils/commands.py
Increases default EVAL_SETUP_TIMEOUT from 180 to 210 (affects subprocess.run timeouts for setup/cleanup commands).

Sequence Diagram(s)

sequenceDiagram
  participant Producer as order-service
  participant Kafka as Kafka Broker
  participant Consumer as analytics-service
  participant OpenSearch as OpenSearch (Python)

  Producer->>Kafka: Produce JSON message (topic: messages)
  Kafka-->>Producer: ACK
  Consumer->>Kafka: Poll (group: analytics-group)
  Kafka-->>Consumer: Deliver messages
  Consumer->>OpenSearch: Index document (refresh=true)
  OpenSearch-->>Consumer: Index response (may delay / heavy CPU when MERGE_POLICY=tiered)
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

Possibly related PRs

Suggested reviewers

  • arikalon1
  • moshemorad
  • aantn

Tip

🔌 Remote MCP (Model Context Protocol) integration is now available!

Pro plan users can now connect to remote MCP servers from the Integrations page. Connect with popular remote MCPs such as Notion and Linear to add more context to your reviews and chats.

✨ Finishing Touches
🧪 Generate unit tests
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch kafka-test

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
🪧 Tips

Chat

There are 3 ways to chat with CodeRabbit:

  • Review comments: Directly reply to a review comment made by CodeRabbit. Example:
    • I pushed a fix in commit <commit_id>, please review it.
    • Open a follow-up GitHub issue for this discussion.
  • Files and specific lines of code (under the "Files changed" tab): Tag @coderabbitai in a new review comment at the desired location with your query.
  • PR comments: Tag @coderabbitai in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples:
    • @coderabbitai gather interesting stats about this repository and render them as a table. Additionally, render a pie chart showing the language distribution in the codebase.
    • @coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.

Support

Need help? Create a ticket on our support page for assistance with any issues or questions.

CodeRabbit Commands (Invoked using PR/Issue comments)

Type @coderabbitai help to get the list of available commands.

Other keywords and placeholders

  • Add @coderabbitai ignore anywhere in the PR description to prevent this PR from being reviewed.
  • Add @coderabbitai summary to generate the high-level summary at a specific location in the PR description.
  • Add @coderabbitai anywhere in the PR title to generate the title automatically.

CodeRabbit Configuration File (.coderabbit.yaml)

  • You can programmatically configure CodeRabbit by adding a .coderabbit.yaml file to the root of your repository.
  • Please see the configuration documentation for more information.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json

Status, Documentation and Community

  • Visit our Status Page to check the current availability of CodeRabbit.
  • Visit our Documentation for detailed information on how to use CodeRabbit.
  • Join our Discord Community to get help, request features, and share feedback.
  • Follow us on X/Twitter for updates and announcements.

@Sheeproid
Sheeproid enabled auto-merge (squash) August 17, 2025 06:27

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🧹 Nitpick comments (6)
tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage1-base.yaml (6)

36-51: Harden Zookeeper container with securityContext (allowPrivilegeEscalation/root).

Static analysis flags missing securityContext. Add least-privilege defaults.

 spec:
   containers:
   - name: zookeeper
     image: bitnami/zookeeper:3.8
+    securityContext:
+      allowPrivilegeEscalation: false
+      readOnlyRootFilesystem: true
+      capabilities:
+        drop: ["ALL"]
   ...
+  securityContext:
+    runAsNonRoot: true
+    seccompProfile:
+      type: RuntimeDefault

Confirm the bitnami image is compatible with readOnlyRootFilesystem; if not, relax only that setting but keep allowPrivilegeEscalation: false and drop caps.


81-99: Harden OpenSearch container with securityContext (allowPrivilegeEscalation/root).

Apply least-privilege defaults to the Python container.

     spec:
       containers:
       - name: opensearch
         image: python:3.9-slim
+        securityContext:
+          allowPrivilegeEscalation: false
+          readOnlyRootFilesystem: true
+          runAsUser: 1000
+          runAsGroup: 1000
+          capabilities:
+            drop: ["ALL"]
       ...
+      securityContext:
+        runAsNonRoot: true
+        seccompProfile:
+          type: RuntimeDefault

99-106: Add liveness/readiness probes (not just startupProbe).

StartupProbe is good for boot, but adding liveness/readiness will improve stability for test orchestration.

         startupProbe:
           httpGet:
             path: /_cluster/health
             port: 9200
           initialDelaySeconds: 10
           periodSeconds: 10
           failureThreshold: 30
+        readinessProbe:
+          httpGet:
+            path: /_cluster/health
+            port: 9200
+          initialDelaySeconds: 5
+          periodSeconds: 5
+          failureThreshold: 6
+        livenessProbe:
+          httpGet:
+            path: /_cluster/health
+            port: 9200
+          initialDelaySeconds: 20
+          periodSeconds: 10
+          failureThreshold: 3

121-130: Use ThreadingHTTPServer to avoid single-threaded request handling.

The current HTTPServer handles requests serially; with heavy background CPU, single-threading can amplify latency. ThreadingHTTPServer offers more realistic concurrent behavior for the eval.

-    from http.server import HTTPServer, BaseHTTPRequestHandler
+    from http.server import ThreadingHTTPServer, BaseHTTPRequestHandler
-        httpd = HTTPServer(server_address, OpenSearchHandler)
+        httpd = ThreadingHTTPServer(server_address, OpenSearchHandler)

Also applies to: 308-314


233-247: Guard against invalid JSON bodies in indexing endpoint.

A bad JSON body will throw and crash the handler. Wrap json.loads with try/except and return 400.

-                if index_name in documents:
-                    doc = json.loads(body) if body else {}
+                if index_name in documents:
+                    try:
+                        doc = json.loads(body) if body else {}
+                    except json.JSONDecodeError:
+                        self.send_json_response(400, {'error': 'invalid_json'})
+                        return

240-249: Minor: REFRESH_INTERVAL is unused beyond logging.

If intentional, comment it as a no-op for realism; otherwise wire it into timing logic.

📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

💡 Knowledge Base configuration:

  • MCP integration is disabled by default for public repositories
  • Jira integration is disabled by default for public repositories
  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between fd80272 and 247de96.

📒 Files selected for processing (1)
  • tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage1-base.yaml (1 hunks)
🧰 Additional context used
📓 Path-based instructions (1)
tests/llm/**/*.yaml

📄 CodeRabbit Inference Engine (CLAUDE.md)

tests/llm/**/*.yaml: In evals, ALWAYS use Kubernetes Secrets for scripts; do not embed scripts in inline manifests or ConfigMaps
Each eval test must use a dedicated Kubernetes namespace named app-
All pod names in evals must be unique and should not hint at the problem (use neutral names)

Files:

  • tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage1-base.yaml
🪛 Checkov (3.2.334)
tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage1-base.yaml

[MEDIUM] 21-51: Containers should not run with allowPrivilegeEscalation

(CKV_K8S_20)


[MEDIUM] 21-51: Minimize the admission of root containers

(CKV_K8S_23)


[MEDIUM] 66-113: Containers should not run with allowPrivilegeEscalation

(CKV_K8S_20)


[MEDIUM] 66-113: Minimize the admission of root containers

(CKV_K8S_23)

⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (3)
  • GitHub Check: Pre-commit checks
  • GitHub Check: llm_evals
  • GitHub Check: Pre-commit checks
🔇 Additional comments (1)
tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage1-base.yaml (1)

2-6: Namespace complies with eval guideline (dedicated app-156).

Namespace name matches the required pattern app-.

arikalon1
arikalon1 previously approved these changes Aug 18, 2025

@arikalon1 arikalon1 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@Sheeproid
Sheeproid disabled auto-merge August 18, 2025 09:58

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (3)
tests/llm/utils/commands.py (3)

9-13: Harden env var parsing to avoid import-time ValueError when EVAL_SETUP_TIMEOUT is invalid.

If someone sets EVAL_SETUP_TIMEOUT to a non-integer, importing this module will crash. Fall back to a sane default and log a warning instead.

Apply this diff:

-EVAL_SETUP_TIMEOUT = int(os.environ.get("EVAL_SETUP_TIMEOUT", "210"))
+DEFAULT_EVAL_SETUP_TIMEOUT = 210
+_raw_timeout = os.environ.get("EVAL_SETUP_TIMEOUT", str(DEFAULT_EVAL_SETUP_TIMEOUT))
+try:
+    EVAL_SETUP_TIMEOUT = int(_raw_timeout)
+except ValueError:
+    logging.warning(
+        "Invalid EVAL_SETUP_TIMEOUT=%r; defaulting to %s",
+        _raw_timeout,
+        DEFAULT_EVAL_SETUP_TIMEOUT,
+    )
+    EVAL_SETUP_TIMEOUT = DEFAULT_EVAL_SETUP_TIMEOUT

30-39: Use Optional[...] where defaults are None to align with type hints and future mypy enforcement.

This is a small cleanup that will help if we ever remove the file-level type ignore.

Apply this diff:

-    def __init__(
+    def __init__(
         self,
         command: str,
         test_case_id: str,
         success: bool,
-        exit_code: int = None,
-        elapsed_time: float = 0,
-        error_type: str = None,
-        error_details: str = None,
+        exit_code: Optional[int] = None,
+        elapsed_time: float = 0.0,
+        error_type: Optional[str] = None,
+        error_details: Optional[str] = None,
     ):

56-69: Force Bash in subprocess invocation for verify scripts

The verify_setup.sh fixture uses Bash-only syntax (#!/bin/bash, [[ … ]]), but subprocess.run(shell=True) defaults to /bin/sh. This can break on shells without Bash extensions. To ensure compatibility, explicitly set the executable to Bash.

Locations to update:

  • tests/llm/utils/commands.py at the subprocess.run call inside _invoke_command

Proposed diff:

     result = subprocess.run(
         command,
         shell=True,
+        executable="/bin/bash",
         capture_output=True,
         text=True,
         check=True,
         stdin=subprocess.DEVNULL,
         cwd=cwd,
         timeout=EVAL_SETUP_TIMEOUT,
     )
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

💡 Knowledge Base configuration:

  • MCP integration is disabled by default for public repositories
  • Jira integration is disabled by default for public repositories
  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 247de96 and a250557.

📒 Files selected for processing (1)
  • tests/llm/utils/commands.py (1 hunks)
🧰 Additional context used
📓 Path-based instructions (2)
**/*.py

📄 CodeRabbit Inference Engine (CLAUDE.md)

**/*.py: ALWAYS place Python imports at the top of the file, not inside functions or methods
Type hints are required (project is type-checked with mypy)
Use Ruff for formatting and linting (configured in pyproject.toml)

Files:

  • tests/llm/utils/commands.py
{tests/**/*.py,pyproject.toml}

📄 CodeRabbit Inference Engine (CLAUDE.md)

Only use pytest markers that are defined in pyproject.toml; never introduce undefined markers in tests

Files:

  • tests/llm/utils/commands.py
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (2)
  • GitHub Check: Pre-commit checks
  • GitHub Check: Pre-commit checks
🔇 Additional comments (1)
tests/llm/utils/commands.py (1)

11-11: LGTM: Timeout bump to 210s is reasonable for the new multi-service setup.

This should reduce flakiness when bringing up Kafka/OpenSearch in CI, and it remains easily overrideable via EVAL_SETUP_TIMEOUT.

@github-actions

Copy link
Copy Markdown
Contributor

Results of HolmesGPT evals

  • ask_holmes: 22/39 test cases were successful, 1 regressions, 2 skipped, 14 mock failures
Test suite Test case Status
ask 01_how_many_pods ✅
ask 02_what_is_wrong_with_pod ✅
ask 03_what_is_the_command_to_port_forward 🔧
ask 04_related_k8s_events ↪️
ask 05_image_version 🔧
ask 09_crashpod ✅
ask 10_image_pull_backoff 🔧
ask 11_init_containers ✅
ask 14_pending_resources ✅
ask 15_failed_readiness_probe 🔧
ask 17_oom_kill ✅
ask 18_crash_looping_v2 ❌
ask 19_detect_missing_app_details 🔧
ask 20_long_log_file_search 🔧
ask 24_misconfigured_pvc 🔧
ask 28_permissions_error ✅
ask 29_events_from_alert_manager ↪️
ask 39_failed_toolset 🔧
ask 41_setup_argo ✅
ask 42_dns_issues_steps_new_tools 🔧
ask 43_current_datetime_from_prompt ✅
ask 45_fetch_deployment_logs_simple ✅
ask 51_logs_summarize_errors 🔧
ask 53_logs_find_term ✅
ask 54_not_truncated_when_getting_pods 🔧
ask 59_label_based_counting ✅
ask 60_count_less_than 🔧
ask 61_exact_match_counting ✅
ask 63_fetch_error_logs_no_errors ✅
ask 79_configmap_mount_issue 🔧
ask 83_secret_not_found 🔧
ask 86_configmap_like_but_secret 🔧
ask 93_calling_datadog ✅
ask 93_calling_datadog ✅
ask 93_calling_datadog ✅
ask 97_logs_clarification_needed ✅
ask 110_k8s_events_image_pull 🔧
ask 24a_misconfigured_pvc_basic 🔧
ask 13a_pending_node_selector_basic 🔧

Legend

  • ✅ the test was successful
  • ↪️ the test was skipped
  • ⚠️ the test failed but is known to be flaky or known to fail
  • 🔧 the test failed due to mock data issues (not a code regression)
  • ❌ the test failed and should be fixed before merging the PR

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

♻️ Duplicate comments (7)
tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage1-base.yaml (2)

11-18: Rename technology-specific resources to neutral names (svc-a/svc-b) per eval guidelines.

Pods/Services must be neutral and not hint at the scenario. Please rename zookeeper → svc-a and opensearch → svc-b across metadata names, labels/selectors, and container names.

Apply:

@@
-metadata:
-  name: zookeeper
+metadata:
+  name: svc-a
@@
-  selector:
-    app: zookeeper
+  selector:
+    app: svc-a
@@
-metadata:
-  name: zookeeper
+metadata:
+  name: svc-a
@@
-    matchLabels:
-      app: zookeeper
+    matchLabels:
+      app: svc-a
@@
-      labels:
-        app: zookeeper
+      labels:
+        app: svc-a
@@
-      - name: zookeeper
+      - name: svc-a
@@
-metadata:
-  name: opensearch
+metadata:
+  name: svc-b
@@
-  selector:
-    app: opensearch
+  selector:
+    app: svc-b
@@
-metadata:
-  name: opensearch
+metadata:
+  name: svc-b
@@
-    matchLabels:
-      app: opensearch
+    matchLabels:
+      app: svc-b
@@
-      labels:
-        app: opensearch
+      labels:
+        app: svc-b
@@
-      - name: opensearch
+      - name: svc-b

Run this to locate all remaining tech-specific names that must be neutralized across the fixture set:

#!/bin/bash
# Scan the repo for tech-specific names in test YAMLs that violate neutrality
rg -n -C2 -g 'tests/llm/**/*.yaml' -e '\b(zookeeper|opensearch|kafka|order-service|analytics-service)\b'

Also applies to: 24-38, 55-62, 68-81


105-112: Use Secrets for scripts; replace ConfigMap and volume with a Secret.

Per tests/llm guidelines, embed scripts in Secrets, not ConfigMaps. Also align the script/volume name with the neutral svc-b naming.

@@
-        - name: opensearch-script
+        - name: svc-b-script
           mountPath: /app
@@
-      - name: opensearch-script
-        configMap:
-          name: opensearch-script
+      - name: svc-b-script
+        secret:
+          secretName: svc-b-script
---
-# ConfigMap for OpenSearch
-apiVersion: v1
-kind: ConfigMap
+# Secret for OpenSearch script
+apiVersion: v1
+kind: Secret
 metadata:
-  name: opensearch-script
+  name: svc-b-script
   namespace: app-156
-data:
+type: Opaque
+stringData:
   opensearch_server.py: |
     import json
     import time
     import os
     import threading
     from http.server import HTTPServer, BaseHTTPRequestHandler

Also applies to: 114-121

tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage2-kafka.yaml (1)

5-12: Neutralize Kafka resource names and update env to match svc-a/svc-c.

Rename kafka → svc-c and ensure ZK reference points to svc-a. Also update advertised listeners.

@@
-metadata:
-  name: kafka
+metadata:
+  name: svc-c
@@
-  selector:
-    app: kafka
+  selector:
+    app: svc-c
@@
-metadata:
-  name: kafka
+metadata:
+  name: svc-c
@@
-    matchLabels:
-      app: kafka
+    matchLabels:
+      app: svc-c
@@
-      labels:
-        app: kafka
+      labels:
+        app: svc-c
@@
-      - name: kafka
+      - name: svc-c
         image: bitnami/kafka:3.5
@@
-        - name: KAFKA_CFG_ZOOKEEPER_CONNECT
-          value: "zookeeper:2181"
+        - name: KAFKA_CFG_ZOOKEEPER_CONNECT
+          value: "svc-a:2181"
@@
-        - name: KAFKA_CFG_ADVERTISED_LISTENERS
-          value: "PLAINTEXT://kafka:9092"
+        - name: KAFKA_CFG_ADVERTISED_LISTENERS
+          value: "PLAINTEXT://svc-c:9092"

Also applies to: 18-29, 31-45

tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage4-producer.yaml (2)

1-9: Store producer script in a Secret and mount via secret volume.

ConfigMaps must not embed scripts in evals. Convert to Secret and adjust the volume reference.

-# Order Service ConfigMap
+# Producer script Secret
 apiVersion: v1
-kind: ConfigMap
+kind: Secret
 metadata:
-  name: order-service-script
+  name: svc-e-script
   namespace: app-156
-data:
+type: Opaque
+stringData:
   order_service.py: |
@@
-      - name: order-service-script
-        configMap:
-          name: order-service-script
+      - name: svc-e-script
+        secret:
+          secretName: svc-e-script

Also applies to: 88-90


53-67: Neutralize producer resource names and update bootstrap servers to svc-c.

Rename order-service → svc-e across metadata/container/labels/volumes and set KAFKA_BOOTSTRAP_SERVERS to svc-c.

@@
-metadata:
-  name: order-service
+metadata:
+  name: svc-e
@@
-    matchLabels:
-      app: order-service
+    matchLabels:
+      app: svc-e
@@
-      labels:
-        app: order-service
+      labels:
+        app: svc-e
@@
-      - name: order-service
+      - name: svc-e
         image: python:3.9-slim
@@
-        - name: KAFKA_BOOTSTRAP_SERVERS
-          value: "kafka:9092"
+        - name: KAFKA_BOOTSTRAP_SERVERS
+          value: "svc-c:9092"
@@
-        - name: order-service-script
+        - name: svc-e-script
           mountPath: /app
@@
-      - name: order-service-script
+      - name: svc-e-script

Also applies to: 59-64, 74-80, 82-87, 88-90

tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage3-consumer.yaml (2)

1-8: Move analytics script to a Secret and mount via secret volume.

Replace ConfigMap with a Secret and update the volume to use secretName.

-# Analytics Service ConfigMap
+# Analytics script Secret
 apiVersion: v1
-kind: ConfigMap
+kind: Secret
 metadata:
-  name: analytics-service-script
+  name: svc-d-script
   namespace: app-156
-data:
+type: Opaque
+stringData:
   analytics_service.py: |
@@
-      - name: analytics-service-script
-        configMap:
-          name: analytics-service-script
+      - name: svc-d-script
+        secret:
+          secretName: svc-d-script

Also applies to: 133-136


94-108: Neutralize consumer resource names and align service env with svc-b/svc-c.

Rename analytics-service → svc-d across metadata/container/labels/volumes. Update OPENSEARCH_HOST to svc-b and KAFKA_BOOTSTRAP_SERVERS to svc-c.

@@
-metadata:
-  name: analytics-service
+metadata:
+  name: svc-d
@@
-    matchLabels:
-      app: analytics-service
+    matchLabels:
+      app: svc-d
@@
-      labels:
-        app: analytics-service
+      labels:
+        app: svc-d
@@
-      - name: analytics-service
+      - name: svc-d
         image: python:3.9-slim
@@
-        - name: KAFKA_BOOTSTRAP_SERVERS
-          value: "kafka:9092"
+        - name: KAFKA_BOOTSTRAP_SERVERS
+          value: "svc-c:9092"
@@
-        - name: OPENSEARCH_HOST
-          value: "opensearch"
+        - name: OPENSEARCH_HOST
+          value: "svc-b"
@@
-        - name: analytics-service-script
+        - name: svc-d-script
           mountPath: /app
@@
-      - name: analytics-service-script
+      - name: svc-d-script

Also applies to: 100-105, 114-121, 123-136

🧹 Nitpick comments (4)
tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage1-base.yaml (1)

36-50: Harden containers with a minimal securityContext (optional).

Reduce Checkov findings by setting non-root and disabling privilege escalation. Safe for these evals.

@@
       - name: svc-a
         image: bitnami/zookeeper:3.8
+        securityContext:
+          runAsNonRoot: true
+          allowPrivilegeEscalation: false
+          readOnlyRootFilesystem: true
@@
       - name: svc-b
         image: python:3.9-slim
+        securityContext:
+          runAsNonRoot: true
+          allowPrivilegeEscalation: false
+          readOnlyRootFilesystem: true

Also applies to: 80-98

tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage2-kafka.yaml (1)

30-52: Add basic securityContext to reduce container risk (optional).

@@
       - name: svc-c
         image: bitnami/kafka:3.5
+        securityContext:
+          runAsNonRoot: true
+          allowPrivilegeEscalation: false
+          readOnlyRootFilesystem: true
tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage4-producer.yaml (1)

65-73: Optional: add securityContext and minor startup hardening.

Add a basic securityContext. Consider using pip with no cache to reduce layer size and speed.

@@
-      - name: svc-e
+      - name: svc-e
         image: python:3.9-slim
         command: ["sh", "-c"]
         args:
           - |
-            pip install kafka-python
+            pip install --no-cache-dir kafka-python
             python /app/order_service.py
+        securityContext:
+          runAsNonRoot: true
+          allowPrivilegeEscalation: false
+          readOnlyRootFilesystem: true

Also applies to: 81-87

tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage3-consumer.yaml (1)

106-114: Add a minimal securityContext for the consumer container (optional).

@@
       - name: svc-d
         image: python:3.9-slim
         command: ["sh", "-c"]
         args:
           - |
             pip install kafka-python opensearch-py
             python /app/analytics_service.py
+        securityContext:
+          runAsNonRoot: true
+          allowPrivilegeEscalation: false
+          readOnlyRootFilesystem: true

Also applies to: 126-132

📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

💡 Knowledge Base configuration:

  • MCP integration is disabled by default for public repositories
  • Jira integration is disabled by default for public repositories
  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between a250557 and 653b336.

📒 Files selected for processing (4)
  • tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage1-base.yaml (1 hunks)
  • tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage2-kafka.yaml (1 hunks)
  • tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage3-consumer.yaml (1 hunks)
  • tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage4-producer.yaml (1 hunks)
🧰 Additional context used
📓 Path-based instructions (1)
tests/llm/**/*.yaml

📄 CodeRabbit Inference Engine (CLAUDE.md)

tests/llm/**/*.yaml: In evals, ALWAYS use Kubernetes Secrets for scripts; do not embed scripts in inline manifests or ConfigMaps
Each eval test must use a dedicated Kubernetes namespace named app-
All pod names in evals must be unique and should not hint at the problem (use neutral names)

Files:

  • tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage1-base.yaml
  • tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage2-kafka.yaml
  • tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage3-consumer.yaml
  • tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage4-producer.yaml
🧠 Learnings (2)
📚 Learning: 2025-08-17T08:42:48.763Z
Learnt from: CR
PR: robusta-dev/holmesgpt#0
File: CLAUDE.md:0-0
Timestamp: 2025-08-17T08:42:48.763Z
Learning: Applies to tests/llm/**/*.yaml : All pod names in evals must be unique and should not hint at the problem (use neutral names)

Applied to files:

  • tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage1-base.yaml
📚 Learning: 2025-08-17T08:42:48.763Z
Learnt from: CR
PR: robusta-dev/holmesgpt#0
File: CLAUDE.md:0-0
Timestamp: 2025-08-17T08:42:48.763Z
Learning: Applies to tests/llm/**/*.yaml : In evals, ALWAYS use Kubernetes Secrets for scripts; do not embed scripts in inline manifests or ConfigMaps

Applied to files:

  • tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage1-base.yaml
🪛 Checkov (3.2.334)
tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage1-base.yaml

[MEDIUM] 21-50: Containers should not run with allowPrivilegeEscalation

(CKV_K8S_20)


[MEDIUM] 21-50: Minimize the admission of root containers

(CKV_K8S_23)


[MEDIUM] 65-112: Containers should not run with allowPrivilegeEscalation

(CKV_K8S_20)


[MEDIUM] 65-112: Minimize the admission of root containers

(CKV_K8S_23)

tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage2-kafka.yaml

[MEDIUM] 15-61: Containers should not run with allowPrivilegeEscalation

(CKV_K8S_20)


[MEDIUM] 15-61: Minimize the admission of root containers

(CKV_K8S_23)

tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage3-consumer.yaml

[MEDIUM] 91-135: Containers should not run with allowPrivilegeEscalation

(CKV_K8S_20)


[MEDIUM] 91-135: Minimize the admission of root containers

(CKV_K8S_23)

tests/llm/fixtures/test_ask_holmes/156_kafka_opensearch_latency/app/stage4-producer.yaml

[MEDIUM] 50-90: Containers should not run with allowPrivilegeEscalation

(CKV_K8S_20)


[MEDIUM] 50-90: Minimize the admission of root containers

(CKV_K8S_23)

⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (6)
  • GitHub Check: build (3.12)
  • GitHub Check: build (3.10)
  • GitHub Check: build (3.11)
  • GitHub Check: build (3.10)
  • GitHub Check: build (3.11)
  • GitHub Check: build (3.12)

@arikalon1 arikalon1 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@Sheeproid
Sheeproid merged commit bcea41f into master Aug 18, 2025
10 of 11 checks passed
@Sheeproid
Sheeproid deleted the kafka-test branch August 18, 2025 12:04
@coderabbitai coderabbitai Bot mentioned this pull request Sep 23, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants