Skip to content

feat: geoip decorator support - #1027

Merged
grcevski merged 2 commits into
open-telemetry:mainfrom
theSuess:push-qrtrxrztxrxx
Jan 8, 2026
Merged

grcevski merged 2 commits into
open-telemetry:mainfrom
theSuess:push-qrtrxrztxrxx

Conversation

@theSuess

Copy link
Copy Markdown
Contributor

This PR adds support for GeoIP lookups using ipinfo.io or MaxMind GeoIP2-Lite.

By using this decorator, users can get more insights into traffic patterns without exploding the metric cardinality. An example metric looks like this:

obi_network_flow_bytes_total{direction="response",dst_asn="",dst_cidr="192.168.42.0/24",dst_country="",obi_ip="192.168.42.203",src_asn="AS16509",src_cidr="0.0.0.0/0",src_country="US"} 132

This functionality is enabled by setting the path to either the IPInfo Lite or GeoIP2 Lite databases.

We can't bundle the MaxMind database due to licensing restrictions (as discussed in open-telemetry/opentelemetry-collector-contrib#33510 (comment)) but it should be possible for ipinfo as it's licensed under the Creative Commons Attribution-ShareAlike 4.0 license.

The files used for testing are the MaxMind test-data and the IPInfo sample-database

@codecov

codecov Bot commented Dec 18, 2025 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 38.01653% with 75 lines in your changes missing coverage. Please review.
✅ Project coverage is 47.09%. Comparing base (daf7bb6) to head (33c236f).
⚠️ Report is 22 commits behind head on main.

Files with missing lines Patch % Lines
pkg/internal/netolly/flow/geoip.go 28.57% 64 Missing and 6 partials ⚠️
pkg/instrumenter/instrumenter.go 0.00% 2 Missing and 1 partial ⚠️
pkg/export/attributes/attr_defs.go 93.33% 1 Missing ⚠️
pkg/netolly/agent/pipeline.go 80.00% 1 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main    #1027      +/-   ##
==========================================
- Coverage   47.15%   47.09%   -0.07%     
==========================================
  Files         258      260       +2     
  Lines       26981    27286     +305     
==========================================
+ Hits        12722    12849     +127     
- Misses      13413    13575     +162     
- Partials      846      862      +16     
Flag Coverage Δ
integration-test 22.80% <16.00%> (-0.21%) ⬇️
integration-test-arm 0.00% <0.00%> (ø)
k8s-integration-test 2.64% <0.00%> (-0.05%) ⬇️
oats-test 0.00% <0.00%> (ø)
unittests 48.23% <46.00%> (+0.04%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@theSuess
theSuess force-pushed the push-qrtrxrztxrxx branch 4 times, most recently from 829f2dc to 9d69afa Compare December 18, 2025 10:57
@theSuess
theSuess marked this pull request as ready for review December 18, 2025 11:28
@theSuess
theSuess requested a review from a team as a code owner December 18, 2025 11:28
@NimrodAvni78

Copy link
Copy Markdown
Contributor

hey @theSuess this looks like a really cool feature
I think something similar is implemented in the otel collector with https://github.com/open-telemetry/opentelemetry-collector-contrib/tree/main/processor/geoipprocessor

can we use that instead of implementing it in obi, or does this give abilities we can't do with the processor?

@theSuess

Copy link
Copy Markdown
Contributor Author

By implementing it in OBI, we get the grouping out of the box, while it would be more complicated to do it in the collector.

For example, this config will only preserve the country looked up:

  select:
    obi.network.flow.bytes:
      include:
        - src.country
        - dst.country

Which would involve multiple processing steps when doing it on the collector layer.

For me the biggest advantage is in ease of use, though I can see the advantage of centralizing lookup in the collector

@mariomac

Copy link
Copy Markdown
Contributor

Amazing contribution @theSuess !! Tank you very much. We will review it carefully and come back to you with some comments. Please notice that this process might be slower than usual due to the holiday season.

I have a question regarding performance. Do you think is worth caching in-memory the most frequent IP lookups to minimize the access to the local GeoIP database? Or is the maxminddb Golang client already taking care of this and performing good under hundreds of requests/second?

@theSuess

Copy link
Copy Markdown
Contributor Author

I didn't check the underlying lookup performance too closely, but I can write a benchmark to make sure this is fast enough and put a cache in between if not

@theSuess

theSuess commented Dec 19, 2025 •

Copy link
Copy Markdown
Contributor Author

I ran a few benchmarks and caching does speed up things quite a bit, especially for the maxmind DB as it requires two lookups instead of one.

If the cache size is too small for the amount of IPs processed, it becomes a bit slower but only by a few ns

The latest commit includes these benchmarks and an updated implementation that uses the cache

@grcevski grcevski left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It looks like there are some lint issues.

@theSuess
theSuess force-pushed the push-qrtrxrztxrxx branch 2 times, most recently from 1f98961 to a1d2f3e Compare January 8, 2026 09:18
@theSuess

theSuess commented Jan 8, 2026

Copy link
Copy Markdown
Contributor Author

Lint issues should be fixed now. The ARM integration tests never failed before, so a restart should turn this check green (don't have the permission to do so myself)

@mariomac mariomac left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you a lot for your contribution! I have few minor comments related to the logging.

Comment thread pkg/internal/netolly/flow/geoip.go Outdated
Comment thread pkg/internal/netolly/flow/geoip.go Outdated
Comment thread pkg/internal/netolly/flow/geoip.go Outdated
for _, flow := range flows {
srcInfo, err := cachedLookup(flow.Id.SrcIP())
if err != nil {
log.Warn("failed to perform geoip lookup for source", "err", err)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could this flood the user output? In this case I'd either:

  • set this log as Debug level
  • or print the first message as warning, then the rest of messages as debug.

Comment thread pkg/internal/netolly/flow/geoip.go Outdated
}
dstInfo, err := cachedLookup(flow.Id.DstIP())
if err != nil {
log.Warn("failed to perform geoip lookup for destination", "err", err)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same as for the previous log.Warn

@mariomac mariomac left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! Thanks for addressing the changes

@grcevski grcevski left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@grcevski
grcevski merged commit 331c5a0 into open-telemetry:main Jan 8, 2026
43 checks passed
@grcevski

grcevski commented Jan 8, 2026

Copy link
Copy Markdown
Contributor

Thanks for your contribution @theSuess !

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants