Repository navigation
fix(infra): expose Redpanda Admin API port 9644 [OMN-4959] - #819
Conversation
…N-4959] Add --admin-addr 0.0.0.0:9644 to Redpanda command args and expose port 9644 externally. This fixes omnidash event-bus-health-poller which was failing with connection refused every 30s.
📝 WalkthroughWalkthroughConfiguration update to docker-compose.infra.yml that adds Redpanda admin API support by including an admin address flag in the startup command and exposing the admin port mapping via host port 9644. Changes
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes Poem
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
📝 Coding Plan
Comment |
There was a problem hiding this comment.
🧹 Nitpick comments (1)
docker/docker-compose.infra.yml (1)
281-281: Optional hardening: bind Admin API to localhost by default.Line 281 currently publishes the admin endpoint on all host interfaces. For safer local defaults, consider binding to
127.0.0.1unless remote access is explicitly needed.Suggested change
- - "${REDPANDA_ADMIN_PORT:-9644}:9644" + - "127.0.0.1:${REDPANDA_ADMIN_PORT:-9644}:9644"🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@docker/docker-compose.infra.yml` at line 281, The Admin API port mapping currently exposes "${REDPANDA_ADMIN_PORT:-9644}:9644" on all interfaces; change it to bind to localhost by default by prefixing the host IP, e.g. "127.0.0.1:${REDPANDA_ADMIN_PORT:-9644}:9644", so the Admin API is only reachable from the host unless an explicit remote bind is needed; update any related docs or environment variable notes for REDPANDA_ADMIN_PORT if remote access should be enabled in specific deployments.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Nitpick comments:
In `@docker/docker-compose.infra.yml`:
- Line 281: The Admin API port mapping currently exposes
"${REDPANDA_ADMIN_PORT:-9644}:9644" on all interfaces; change it to bind to
localhost by default by prefixing the host IP, e.g.
"127.0.0.1:${REDPANDA_ADMIN_PORT:-9644}:9644", so the Admin API is only
reachable from the host unless an explicit remote bind is needed; update any
related docs or environment variable notes for REDPANDA_ADMIN_PORT if remote
access should be enabled in specific deployments.
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 6bd397a7-dbc6-4348-80a9-9e873cfd4899
📒 Files selected for processing (1)
docker/docker-compose.infra.yml
…2669) * docs(OMN-15125): first dated Aug-5 readiness/rollback packet — honest NO-GO First real instance of the OMN-15125 GO/NO-GO packet (the template was never filled before). Fills all 15 fields with real content or an explicit, proven BLOCKED marker -- no placeholder, no invented value: - source_digest / previous_digest / amd64_manifest: live, ECR-verified (round-4 vs round-3 candidate tuple; round-3 = the prior pin in the build lineage, not a live kubectl-rollout-history readback -- caveated). - vulnerability_result: LIVE finding, 4 CRITICAL / 12 HIGH on the round-4 image (describe-image-scan-findings is authoritative; describe-images' imageScanStatus field disagrees and returns null for the same digest -- discrepancy flagged, not silently resolved). - a6_thresholds_with_live_samples: 5/5 loaded, 0/5 live-sampled -- counted as unloaded per the manifest's own definition. - reconciled_blocker_graph: live list_issues(parentId=OMN-14724) readback, surfaces two real tensions not present in any prior instance -- B2 (worker capacity) canceled today with no successor, and B11/B12 marked Done in Linear while their own cited evidence artifacts (runbook Sec 3.4, this session's RDS reachability probe) don't independently confirm. - dated_chain_with_slack: negative slack -- the gating pin PRs (omninode_infra#818/#819) are open with a live, non-flake test conflict. - t20_handoff: searched and genuinely not found under docs/plans or docs/handoff -- recorded as absent, not force-fit to an adjacent artifact. - config_hash / policy_hash / b12_psql_readback / teardown_readback / executable_rollback (dry-run half): BLOCKED, same k8s/RDS access gap as the sibling OMN-15123/15124 round-4 packets, each with proof not assertion. - plan_row_binding: RESOLVED, same 2026-08-04 plan-governor fix as the sibling tickets, re-confirmed live here. go_no_go_decision: NO-GO for tonight's window, stated as the mechanical conclusion the template's own rule requires when the three gating fields carry real (if gapped) content -- not an operator override, and not silently deferred. Cross-checked against docs/tracking/2026-08-05-beta- blocking-axis-register.md (same-day EOD refresh) -- no contradiction found. Seam test 13/13 green. Zero AWS/k8s mutation -- every command run was a read-only describe/list/get/manifest-inspect. No merge (Codex lands). OMN-15125 * chore(OMN-15125): trigger companion mint (empty commit, no content change)
Summary
--admin-addr 0.0.0.0:9644to Redpanda command args indocker-compose.infra.ymlREDPANDA_ADMIN_PORTenv var (default: 9644)Context
Part of epic OMN-4956 (Omnidash Dashboard Health), Wave 0 / Phase 1: Foundation.
Redpanda Admin API port 9644 was not exposed, causing omnidash
event-bus-health-poller.tsto fail with connection refused every 30 seconds.Test plan
docker port omnibase-infra-redpandaoutput includes 9644curl http://localhost:9644/v1/brokersreturns JSON broker listSummary by CodeRabbit