Skip to content

fix(infra): expose Redpanda Admin API port 9644 [OMN-4959] - #819

Merged
jonahgabriel merged 1 commit into
mainfrom
jonah/omn-4959-expose-redpanda-admin-port
Mar 13, 2026
Merged

jonahgabriel merged 1 commit into
mainfrom
jonah/omn-4959-expose-redpanda-admin-port

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented Mar 13, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Add --admin-addr 0.0.0.0:9644 to Redpanda command args in docker-compose.infra.yml
  • Expose port 9644 externally via REDPANDA_ADMIN_PORT env var (default: 9644)

Context

Part of epic OMN-4956 (Omnidash Dashboard Health), Wave 0 / Phase 1: Foundation.

Redpanda Admin API port 9644 was not exposed, causing omnidash event-bus-health-poller.ts to fail with connection refused every 30 seconds.

Test plan

  • docker port omnibase-infra-redpanda output includes 9644
  • curl http://localhost:9644/v1/brokers returns JSON broker list
  • omnidash health poller stops logging connection errors
  • Existing Redpanda produce/consume on 19092 unaffected

Summary by CodeRabbit

  • Chores
    • Updated infrastructure configuration to expose an admin API port for service health monitoring and diagnostics.

…N-4959]

Add --admin-addr 0.0.0.0:9644 to Redpanda command args and expose port
9644 externally. This fixes omnidash event-bus-health-poller which was
failing with connection refused every 30s.
@coderabbitai

coderabbitai Bot commented Mar 13, 2026 •

Copy link
Copy Markdown
📝 Walkthrough

Walkthrough

Configuration update to docker-compose.infra.yml that adds Redpanda admin API support by including an admin address flag in the startup command and exposing the admin port mapping via host port 9644.

Changes

Cohort / File(s) Summary
Redpanda Admin API Configuration
docker/docker-compose.infra.yml
Added --admin-addr 0.0.0.0:9644 flag to Redpanda startup and exposed admin API port mapping (${REDPANDA_ADMIN_PORT:-9644}:9644) with note indicating usage for omnidash health polling.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Poem

🐰 A port opens wide, nine-six-four-four,
Where rabbits peek through the admin door,
Health checks bounce like carrots so green,
The finest dashboards we've ever seen! 🥕

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and specifically summarizes the main change: exposing Redpanda Admin API port 9644 in the infrastructure configuration, which is the primary focus of the changeset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch jonah/omn-4959-expose-redpanda-admin-port
📝 Coding Plan
  • Generate coding plan for human review comments

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
docker/docker-compose.infra.yml (1)

281-281: Optional hardening: bind Admin API to localhost by default.

Line 281 currently publishes the admin endpoint on all host interfaces. For safer local defaults, consider binding to 127.0.0.1 unless remote access is explicitly needed.

Suggested change
-      - "${REDPANDA_ADMIN_PORT:-9644}:9644"
+      - "127.0.0.1:${REDPANDA_ADMIN_PORT:-9644}:9644"
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@docker/docker-compose.infra.yml` at line 281, The Admin API port mapping
currently exposes "${REDPANDA_ADMIN_PORT:-9644}:9644" on all interfaces; change
it to bind to localhost by default by prefixing the host IP, e.g.
"127.0.0.1:${REDPANDA_ADMIN_PORT:-9644}:9644", so the Admin API is only
reachable from the host unless an explicit remote bind is needed; update any
related docs or environment variable notes for REDPANDA_ADMIN_PORT if remote
access should be enabled in specific deployments.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Nitpick comments:
In `@docker/docker-compose.infra.yml`:
- Line 281: The Admin API port mapping currently exposes
"${REDPANDA_ADMIN_PORT:-9644}:9644" on all interfaces; change it to bind to
localhost by default by prefixing the host IP, e.g.
"127.0.0.1:${REDPANDA_ADMIN_PORT:-9644}:9644", so the Admin API is only
reachable from the host unless an explicit remote bind is needed; update any
related docs or environment variable notes for REDPANDA_ADMIN_PORT if remote
access should be enabled in specific deployments.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 6bd397a7-dbc6-4348-80a9-9e873cfd4899

📥 Commits

Reviewing files that changed from the base of the PR and between f315a02 and 6fc8dc6.

📒 Files selected for processing (1)
  • docker/docker-compose.infra.yml

@jonahgabriel
jonahgabriel enabled auto-merge March 13, 2026 19:59
@jonahgabriel
jonahgabriel added this pull request to the merge queue Mar 13, 2026
Merged via the queue into main with commit c09fa0f Mar 13, 2026
37 checks passed
@jonahgabriel
jonahgabriel deleted the jonah/omn-4959-expose-redpanda-admin-port branch March 13, 2026 20:13
jonahgabriel added a commit that referenced this pull request Aug 7, 2026
…2669)

* docs(OMN-15125): first dated Aug-5 readiness/rollback packet — honest NO-GO

First real instance of the OMN-15125 GO/NO-GO packet (the template was
never filled before). Fills all 15 fields with real content or an explicit,
proven BLOCKED marker -- no placeholder, no invented value:

- source_digest / previous_digest / amd64_manifest: live, ECR-verified
  (round-4 vs round-3 candidate tuple; round-3 = the prior pin in the
  build lineage, not a live kubectl-rollout-history readback -- caveated).
- vulnerability_result: LIVE finding, 4 CRITICAL / 12 HIGH on the round-4
  image (describe-image-scan-findings is authoritative; describe-images'
  imageScanStatus field disagrees and returns null for the same digest --
  discrepancy flagged, not silently resolved).
- a6_thresholds_with_live_samples: 5/5 loaded, 0/5 live-sampled -- counted
  as unloaded per the manifest's own definition.
- reconciled_blocker_graph: live list_issues(parentId=OMN-14724) readback,
  surfaces two real tensions not present in any prior instance -- B2 (worker
  capacity) canceled today with no successor, and B11/B12 marked Done in
  Linear while their own cited evidence artifacts (runbook Sec 3.4, this
  session's RDS reachability probe) don't independently confirm.
- dated_chain_with_slack: negative slack -- the gating pin PRs
  (omninode_infra#818/#819) are open with a live, non-flake test conflict.
- t20_handoff: searched and genuinely not found under docs/plans or
  docs/handoff -- recorded as absent, not force-fit to an adjacent artifact.
- config_hash / policy_hash / b12_psql_readback / teardown_readback /
  executable_rollback (dry-run half): BLOCKED, same k8s/RDS access gap as
  the sibling OMN-15123/15124 round-4 packets, each with proof not assertion.
- plan_row_binding: RESOLVED, same 2026-08-04 plan-governor fix as the
  sibling tickets, re-confirmed live here.

go_no_go_decision: NO-GO for tonight's window, stated as the mechanical
conclusion the template's own rule requires when the three gating fields
carry real (if gapped) content -- not an operator override, and not
silently deferred. Cross-checked against docs/tracking/2026-08-05-beta-
blocking-axis-register.md (same-day EOD refresh) -- no contradiction found.

Seam test 13/13 green. Zero AWS/k8s mutation -- every command run was a
read-only describe/list/get/manifest-inspect. No merge (Codex lands).

OMN-15125

* chore(OMN-15125): trigger companion mint (empty commit, no content change)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant