Skip to content

feat(sdk): add layered diagnostics remote configuration - #103683

Draft
marandaneto wants to merge 5 commits into
masterfrom
feat/sdk-diagnostics-remote-config
Draft

marandaneto wants to merge 5 commits into
masterfrom
feat/sdk-diagnostics-remote-config

Conversation

@marandaneto

@marandaneto marandaneto commented Sep 21, 2026 •

Copy link
Copy Markdown
Member

Problem

SDK integrations need a remote control for diagnostics that PostHog, organization admins, and project admins can independently disable.
This adds the backend contract for the experimental Python SDK integration, alongside remote-config fetching.

Changes

  • Remote config returns sdkDiagnosticsEnabled, enabled only when the global switch is on and neither organization nor project opts out.
  • SDK_DIAGNOSTICS_ENABLED defaults to false; both sdk_diagnostics_opt_out fields default to false.
  • Admins can change the opt-outs through existing organization and project APIs. No settings UI is added.
  • Organization changes refresh remote config for that organization's projects after commit. Project changes use the existing refresh path.
  • Organization refresh dispatch retries broker connection errors up to three times with backoff and jitter. Repeated refreshes are safe.
  • Ingestion forces person processing off for $sdk_diagnostics_config, even when a sender requests it, and strips person-property updates.
  • Generated API types and the snapshot update are mechanical. SDK reporting itself remains outside this PR.
+ "sdkDiagnosticsEnabled": false

Warning

The two migrations alter core organization and team tables. Hot-table approval and deployment coordination remain outstanding; acknowledgment entries are intentionally absent.
Global changes require restarting config-building workers and syncing existing configs. SDK polling and caching mean this is not an immediate kill switch.

How did you test this code?

  • Added coverage for all eight global/organization/project combinations, preventing a lower-level preference from overriding a disable.
  • Added organization refresh scoping and unchanged-value checks, plus API tests for admin updates and member rejection.
  • A partial-dispatch regression test reproduces a broker failure after the first project. It fails before the retry fix and passes afterward.
  • Ran the targeted tests and startup receiver checks, regenerated OpenAPI artifacts, and ran strict preflight with hooks enabled.
  • Ran the ingestion restriction and normalization suites. New cases reject sender overrides, strip person updates, and preserve similarly named events.
  • The new diagnostics cases failed before the guard and passed afterward.
  • Checked migration SQL for persistent database defaults and checked for migration-state drift.
  • Not checked: end-to-end Python SDK consumption or deployment. Full frontend typecheck remains blocked by the local missing @posthog/hogvm build; no UI changes remain.

👉 Stay up-to-date with PostHog coding conventions for a smoother review.

Automatic notifications

  • Publish to changelog?

Docs update

Updated docs/internal/feature-flags/hypercache-system.md with precedence, API controls, cache propagation requirements, and the diagnostics person-processing guard.

🤖 Agent context

Autonomy: Human-driven (agent-assisted)

Agent: Pi, OpenAI gpt-6-astra (openai-codex). Used file editing, shell, and GitHub CLI in a dedicated worktree. Human review is required.

The final scope is backend-only; UI controls explored during implementation were removed. CodeRabbit was signed out, and the operator explicitly chose to skip the local review. No substitute agent review ran.

Skills used: /django-migrations, /improving-drf-endpoints, /implementing-mcp-tools, /adopting-generated-api-types, /writing-tests, /writing-user-facing-copy, /writing-ui-components, /placing-product-frontend-code, /writing-kea-logics, /adding-activity-logging, /hogli, /running-ci-preflight, /reviewing-with-coderabbit, /writing-pr-descriptions, and /pr. No customer data or private operational details are included.

@marandaneto marandaneto self-assigned this Sep 21, 2026
@trunk-io

trunk-io Bot commented Sep 21, 2026

Copy link
Copy Markdown

Merging to master in this repository is managed by Trunk.

  • To merge this pull request, check the box to the left or comment /trunk merge below.

After your PR is submitted to the merge queue, this comment will be automatically updated with its status. If the PR fails, failure details will also be posted here

@github-actions

github-actions Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

🤖 CI report

⚠️ Trunk lane — backend Python lane

This PR is assigned to the backend Python lane. It runs backend Python tests and may merge in parallel with PRs in other lanes.

✅ Complexity (TypeScript) — clean

Cyclomatic complexity above the limit in changed typescript files (10 for production files, 15 for test files). Warn only: worth simplifying when you next touch these functions.

⚠️ Duplication (Python) — 1 new duplicated block (worst 100 tokens)

New Python code duplication introduced by this branch. Fails at 70+ tokens in app code, or 150+ tokens when both copies live in test files. Advisory while the gate proves itself: extract a shared helper instead of copying.

First copy Second copy Lines Tokens
posthog/api/project.py:679 posthog/api/project.py:790 50 100
✅ Duplication (TypeScript) — clean

New TypeScript code duplication introduced by this branch. Fails at 70+ tokens in app code, or 150+ tokens when both copies live in test files. Advisory while the gate proves itself: extract a shared helper instead of copying.

✅ Bundle size — no change

Uncompressed size of every built .js bundle, compared against the base branch.

Total: 69.10 MiB · no change

No file changed by more than 1000 B.

Posted automatically by build-bundle-size-report · uncompressed bytes from dist-report

✅ Eager graph — within budget

How much code each root ships on the eager path — downloaded and parsed before the surface is interactive. Measured from the esbuild output chunks (post-tree-shake, static imports only); lazy import() / React.lazy chunks are not counted.

Root Eager (shipped) Δ vs base Budget
entry (logged-out pages, app bootstrap)
src/index.tsx
1.56 MiB · 22 files no change ████████░░ 84.5% of 1.84 MiB
logged-out boot: index + App + bootApp (preloaded by every page, including /login)
src/index.tsx + src/scenes/App.tsx + src/scenes/bootApp.ts
3.55 MiB · 628 files no change █████████░ 88.2% of 4.03 MiB
authenticated shell (every logged-in page)
src/scenes/AuthenticatedShell.tsx
8.39 MiB · 2,772 files no change █████████░ 88.2% of 9.51 MiB

🟢 node_modules/monaco-editor/ stays out of src/index.tsx
🟢 src/lib/components/ActivityLog/describers stays out of src/index.tsx
🟢 [object Object] stays out of src/index.tsx
🟢 [object Object] stays out of src/index.tsx
🟢 node_modules/monaco-editor/ stays out of src/index.tsx + src/scenes/App.tsx + src/scenes/bootApp.ts
🟢 src/layout/navigation-3000/navigationLogic.tsx stays out of src/index.tsx + src/scenes/App.tsx + src/scenes/bootApp.ts
🟢 src/scenes/dashboard/dashboardLogic.tsx stays out of src/index.tsx + src/scenes/App.tsx + src/scenes/bootApp.ts
🟢 src/lib/lemon-ui/LemonMarkdown/ stays out of src/index.tsx + src/scenes/App.tsx + src/scenes/bootApp.ts
🟢 src/lib/components/RichContentEditor/ stays out of src/index.tsx + src/scenes/App.tsx + src/scenes/bootApp.ts
🟢 src/lib/components/CodeSnippet/ stays out of src/index.tsx + src/scenes/App.tsx + src/scenes/bootApp.ts
🟢 src/taxonomy/core-filter-definitions-by-group.json stays out of src/index.tsx + src/scenes/App.tsx + src/scenes/bootApp.ts
🟢 node_modules/monaco-editor/ stays out of src/scenes/AuthenticatedShell.tsx
🟢 src/lib/components/ActivityLog/describers stays out of src/scenes/AuthenticatedShell.tsx
🟢 [object Object] stays out of src/scenes/AuthenticatedShell.tsx
🟢 src/scenes/session-recordings/player/sessionRecordingPlayerLogic.ts stays out of src/scenes/AuthenticatedShell.tsx
🟢 [object Object] stays out of src/scenes/AuthenticatedShell.tsx
🟢 [object Object] stays out of src/scenes/AuthenticatedShell.tsx

Largest files eagerly shipped from src/index.tsx
Size File
126.8 KiB ../node_modules/.pnpm/react-dom@18.3.1_react@18.3.1/node_modules/react-dom/cjs/react-dom.production.min.js
24.6 KiB ../node_modules/.pnpm/buffer@6.0.3/node_modules/buffer/index.js
6.3 KiB ../node_modules/.pnpm/react@18.3.1/node_modules/react/cjs/react.production.min.js
4.5 KiB ../node_modules/.pnpm/@jspm+core@2.1.0/node_modules/@jspm/core/nodelibs/browser/process.js
3.9 KiB ../node_modules/.pnpm/scheduler@0.23.2/node_modules/scheduler/cjs/scheduler.production.min.js
1.4 KiB ../node_modules/.pnpm/base64-js@1.5.1/node_modules/base64-js/index.js
1.3 KiB src/index.tsx
1.3 KiB src/RootErrorBoundary.tsx
912 B ../node_modules/.pnpm/ieee754@1.2.1/node_modules/ieee754/index.js
854 B src/scenes/ChunkLoadErrorBoundary.tsx
Largest files eagerly shipped from src/index.tsx + src/scenes/App.tsx + src/scenes/bootApp.ts
Size File
301.9 KiB ../node_modules/.pnpm/posthog-js@1.434.3_@types+react@18.3.27_react@18.3.1/node_modules/posthog-js/dist/module.mjs
267.7 KiB ../node_modules/.pnpm/@posthog+icons@0.38.0_react-dom@18.3.1_react@18.3.1__react@18.3.1/node_modules/@posthog/icons/dist/posthog-icons.es.js
126.8 KiB ../node_modules/.pnpm/react-dom@18.3.1_react@18.3.1/node_modules/react-dom/cjs/react-dom.production.min.js
104.4 KiB src/lib/api.ts
82.6 KiB src/products.tsx
68.5 KiB src/lib/lemon-ui/icons/icons.tsx
63.4 KiB src/lib/utils/eventUsageLogic.ts
38.8 KiB ../node_modules/.pnpm/@dnd-kit+core@6.0.8_react-dom@18.3.1_react@18.3.1__react@18.3.1/node_modules/@dnd-kit/core/dist/core.esm.js
33.9 KiB ../node_modules/.pnpm/kea@4.0.0-pre.6_patch_hash=139b8d1f1304f9d9da452a9a1244c94ea679dbcb85687d8999563146879fb6f5_react@18.3.1/node_modules/kea/lib/index.cjs.js
28.5 KiB src/scenes/scenes.ts
Largest files eagerly shipped from src/scenes/AuthenticatedShell.tsx
Size File
301.9 KiB ../node_modules/.pnpm/posthog-js@1.434.3_@types+react@18.3.27_react@18.3.1/node_modules/posthog-js/dist/module.mjs
267.7 KiB ../node_modules/.pnpm/@posthog+icons@0.38.0_react-dom@18.3.1_react@18.3.1__react@18.3.1/node_modules/@posthog/icons/dist/posthog-icons.es.js
265.0 KiB src/taxonomy/core-filter-definitions-by-group.json
153.8 KiB ../node_modules/.pnpm/re2js@0.4.1/node_modules/re2js/build/index.esm.js
126.8 KiB ../node_modules/.pnpm/react-dom@18.3.1_react@18.3.1/node_modules/react-dom/cjs/react-dom.production.min.js
104.4 KiB src/lib/api.ts
98.4 KiB ../packages/quill/packages/quill/dist/index.js
93.3 KiB ../node_modules/.pnpm/prosemirror-view@1.40.1/node_modules/prosemirror-view/dist/index.js
90.6 KiB ../node_modules/.pnpm/@tiptap+core@3.20.6_@tiptap+pm@3.20.6/node_modules/@tiptap/core/dist/index.js
82.6 KiB src/products.tsx

Posted automatically by check-eager-graph · sizes are eager output bytes (shipped, post-tree-shake) from the esbuild metafile · part of #32479

✅ Toolbar bundle — eager 2.36 MiB within budget

What the toolbar ships to customer pages, measured from the esbuild output (minified, post-tree-shake). The eager set is the entry plus everything statically imported from it — fetched before any feature runs; deferred chunks load lazily. The eager guardrail is 5.72 MiB. Each output file must also stay below 10 MB, where CloudFront stops compressing it. The module boundary is enforced separately by check-toolbar-graph.

Metric Size Δ vs base Budget
Eager (shipped)
entry + static imports
2.36 MiB · 19 files no change ████░░░░░░ 41.2% of 5.72 MiB
Deferred (lazy) 2.09 MiB · 44 files no change n/a — loads on demand
Loader dist/toolbar.js 1.2 KiB no change █░░░░░░░░░ 6.0% of 19.5 KiB
Largest eagerly-shipped chunks
Size File
781.7 KiB dist/toolbar/toolbar-app-HZTP7LYX.css
649.4 KiB dist/toolbar/chunk-chunk-A4FPANTB.js
483.6 KiB dist/toolbar/chunk-chunk-OEXBM2YC.js
138.1 KiB dist/toolbar/chunk-chunk-P3IL4POG.js
131.8 KiB dist/toolbar/chunk-chunk-FDH2IBXT.js
75.1 KiB dist/toolbar/toolbar-app-AGIWZH5K.js
69.0 KiB dist/toolbar/chunk-chunk-TSAL54PB.js
35.6 KiB dist/toolbar/chunk-chunk-MUYRBQXF.js
21.0 KiB dist/toolbar/chunk-chunk-EXFIBJWO.js
6.8 KiB dist/toolbar/chunk-chunk-DV7IWQNF.js

Posted automatically by check-toolbar-size · sizes are toolbar output bytes (shipped, post-tree-shake) from the esbuild metafile

✅ Dist folder size — 🔺 +1.7 KiB (+0.0%)

Total size of the built frontend/dist folder (all assets), compared against the base branch.

Total: 1510.38 MiB · 🔺 +1.7 KiB (+0.0%)

ℹ️ MCP UI apps size — 33 app(s), 17628.2 KB JS

Built size of each MCP UI app (main.js + styles.css).

App JS CSS
debug 597.8 KB 196.2 KB
action 454.1 KB 196.2 KB
action-list 564.1 KB 196.2 KB
cohort 453.1 KB 196.2 KB
cohort-list 563.1 KB 196.2 KB
email-template 452.9 KB 196.2 KB
error-details 469.1 KB 196.2 KB
error-issue 453.8 KB 196.2 KB
error-issue-list 564.0 KB 196.2 KB
experiment 561.2 KB 196.2 KB
experiment-list 564.9 KB 196.2 KB
experiment-results 566.2 KB 196.2 KB
feature-flag 566.7 KB 196.2 KB
feature-flag-list 570.5 KB 196.2 KB
feature-flag-testing 457.3 KB 196.2 KB
inline-scan 453.6 KB 196.2 KB
insight-actors 562.3 KB 196.2 KB
invite-email-preview 452.3 KB 196.2 KB
llm-costs 559.3 KB 196.2 KB
session-recording 454.9 KB 196.2 KB
survey 454.7 KB 196.2 KB
survey-global-stats 561.8 KB 196.2 KB
survey-list 564.8 KB 196.2 KB
survey-stats 561.8 KB 196.2 KB
trace-span 453.5 KB 196.2 KB
trace-span-list 564.0 KB 196.2 KB
vision-observation-list 563.2 KB 196.2 KB
workflow 453.4 KB 196.2 KB
workflow-list 563.5 KB 196.2 KB
loops-review 457.8 KB 196.2 KB
query-results 774.0 KB 196.2 KB
render-ui 856.5 KB 196.2 KB
visual-review-snapshots 457.9 KB 196.2 KB
⚠️ MCP snapshots — 1 updated (1 modified, 0 added, 0 deleted)

Snapshots: MCP unit test snapshots updated

Changes: 1 snapshots (1 modified, 0 added, 0 deleted)

What this means:

  • Snapshots have been automatically updated to match current output

Next steps:

  • Review the changes to ensure they're intentional
  • If unexpected, investigate what caused the output to change

Review snapshot changes →

⚠️ Django migration SQL — 2 new migrations to review

We've detected new migrations on this PR. Review the SQL output for each migration:

posthog/migrations/1374_sdk_diagnostics_opt_out.py

/opt/hostedtoolcache/Python/3.13.13/x64/lib/python3.13/site-packages/infi/clickhouse_orm/__init__.py:1: UserWarning: pkg_resources is deprecated as an API. See https://setuptools.pypa.io/en/latest/pkg_resources.html. The pkg_resources package is slated for removal as early as 2025-11-30. Refrain from using this package or pin to Setuptools<81.
  __import__("pkg_resources").declare_namespace(__name__)
System check identified some issues:

WARNINGS:
?: (axes.W001) You are using the django-axes cache handler for login attempt tracking. Your cache configuration is however invalid and will not work correctly with django-axes. This can leave security holes in your login systems as attempts are not tracked correctly. Reconfigure settings.AXES_CACHE and settings.CACHES per django-axes configuration documentation.
?: (staticfiles.W004) The directory '/home/runner/work/posthog/posthog/frontend/dist' in the STATICFILES_DIRS setting does not exist.
BEGIN;
--
-- Add field sdk_diagnostics_opt_out to organization
--
ALTER TABLE "posthog_organization" ADD COLUMN "sdk_diagnostics_opt_out" boolean DEFAULT false NOT NULL;
COMMIT;

posthog/migrations/1375_team_sdk_diagnostics_opt_out.py

/opt/hostedtoolcache/Python/3.13.13/x64/lib/python3.13/site-packages/infi/clickhouse_orm/__init__.py:1: UserWarning: pkg_resources is deprecated as an API. See https://setuptools.pypa.io/en/latest/pkg_resources.html. The pkg_resources package is slated for removal as early as 2025-11-30. Refrain from using this package or pin to Setuptools<81.
  __import__("pkg_resources").declare_namespace(__name__)
System check identified some issues:

WARNINGS:
?: (axes.W001) You are using the django-axes cache handler for login attempt tracking. Your cache configuration is however invalid and will not work correctly with django-axes. This can leave security holes in your login systems as attempts are not tracked correctly. Reconfigure settings.AXES_CACHE and settings.CACHES per django-axes configuration documentation.
?: (staticfiles.W004) The directory '/home/runner/work/posthog/posthog/frontend/dist' in the STATICFILES_DIRS setting does not exist.
BEGIN;
--
-- Add field sdk_diagnostics_opt_out to team
--
ALTER TABLE "posthog_team" ADD COLUMN "sdk_diagnostics_opt_out" boolean DEFAULT false NOT NULL;
COMMIT;

Last updated: 2026-09-21 12:08 UTC (a0d8ce5)

❌ Django migration risk — blocked migration detected

We've analyzed your migrations for potential risks.

Summary: 0 Safe | 0 Needs Review | 2 Blocked

❌ Blocked

Causes locks or breaks compatibility

posthog.1374_sdk_diagnostics_opt_out
  │  └─ #1 ✅ AddField
  │     Adding NOT NULL field with constant default (safe in PG11+)
  │     model: organization, field: sdk_diagnostics_opt_out
  │
  └──> �[91m📋 POSTHOG POLICY VIOLATIONS:�[0m
       ❌ BLOCKED: AddField on "posthog_organization" - this table is
       read on virtually every request. Any ALTER TABLE on it takes an
       ACCESS EXCLUSIVE lock; while that lock request waits behind in-
       flight queries, every later query on the table queues behind it,
       so even a metadata-only ADD COLUMN can stall site-wide traffic
       until lock_timeout cancels it - and each bin/migrate retry
       repeats the stall. This has caused production 5xx incidents.
       Prefer not altering this table at all: new domain-specific team
       fields belong on a Team extension model (see
       posthog/models/team/README.md), which only creates a new table.
       If this change genuinely must alter posthog_organization, add
       "posthog.1374_sdk_diagnostics_opt_out" to posthog/management/migr
       ation_analysis/hot_table_acknowledged_migrations.txt to accept
       the risk, and coordinate the deploy with #team-infrastructure for
       a low-traffic window. See https://github.com/PostHog/posthog/blob
       /master/docs/published/handbook/engineering/safe-django-
       migrations.md#altering-hot-tables
posthog.1375_team_sdk_diagnostics_opt_out
  │  └─ #1 ✅ AddField
  │     Adding NOT NULL field with constant default (safe in PG11+)
  │     model: team, field: sdk_diagnostics_opt_out
  │
  └──> �[91m📋 POSTHOG POLICY VIOLATIONS:�[0m
       ❌ BLOCKED: AddField on "posthog_team" - this table is read on
       virtually every request. Any ALTER TABLE on it takes an ACCESS
       EXCLUSIVE lock; while that lock request waits behind in-flight
       queries, every later query on the table queues behind it, so even
       a metadata-only ADD COLUMN can stall site-wide traffic until
       lock_timeout cancels it - and each bin/migrate retry repeats the
       stall. This has caused production 5xx incidents. Prefer not
       altering this table at all: new domain-specific team fields
       belong on a Team extension model (see
       posthog/models/team/README.md), which only creates a new table.
       If this change genuinely must alter posthog_team, add
       "posthog.1375_team_sdk_diagnostics_opt_out" to posthog/management
       /migration_analysis/hot_table_acknowledged_migrations.txt to
       accept the risk, and coordinate the deploy with #team-
       infrastructure for a low-traffic window. See https://github.com/P
       ostHog/posthog/blob/master/docs/published/handbook/engineering/sa
       fe-django-migrations.md#altering-hot-tables

Last updated: 2026-09-21 12:09 UTC (a0d8ce5)

ℹ️ Docs preview — preview build triggered

Docs from this PR will be published at posthog.com.

Project Preview Updated (UTC)
posthog.com Open preview Sep 21, 2026, 12:06 PM

The preview should be ready in about 10 minutes. Open the preview at /handbook/engineering/.

@marandaneto
marandaneto requested review from a team September 21, 2026 11:53
@greptile-apps

greptile-apps Bot commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Retrigger

The PR is not safe to merge until the hot-table migrations are approved and acknowledged, the organization refresh fanout handles partial failures, and the production environment variable is wired.

Reviews (1) · Last reviewed commit: "chore: merge master into sdk diagnostics..."

Comment on lines +12 to +19
migrations.AddField(
model_name="organization",
name="sdk_diagnostics_opt_out",
field=models.BooleanField(
db_default=False,
default=False,
help_text="Disables SDK diagnostics for every project in this organization when true.",
),

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Hot-table migrations lack approval

This migration and 1375_team_sdk_diagnostics_opt_out.py alter the hot posthog_organization and posthog_team tables without entries in hot_table_acknowledged_migrations.txt. HotTableAlterPolicy rejects these changes because even metadata-only additions require an ACCESS EXCLUSIVE lock that can stall production traffic. Add the acknowledgments after infrastructure approval and coordinate deployment, or move the project setting to a Team extension.

Prompt To Fix With AI
This is a comment left during a code review.
Path: posthog/migrations/1374_sdk_diagnostics_opt_out.py
Line: 12-19

Comment:
**Hot-table migrations lack approval**

This migration and `1375_team_sdk_diagnostics_opt_out.py` alter the hot `posthog_organization` and `posthog_team` tables without entries in `hot_table_acknowledged_migrations.txt`. `HotTableAlterPolicy` rejects these changes because even metadata-only additions require an `ACCESS EXCLUSIVE` lock that can stall production traffic. Add the acknowledgments after infrastructure approval and coordinate deployment, or move the project setting to a Team extension.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Comment thread posthog/tasks/remote_config.py
CAPTURE_INTERNAL_MAX_WORKERS = get_from_env("CAPTURE_INTERNAL_MAX_WORKERS", type_cast=int, default=8)

NEW_ANALYTICS_CAPTURE_ENDPOINT = os.getenv("NEW_CAPTURE_ENDPOINT", "/i/v0/e/")
SDK_DIAGNOSTICS_ENABLED = get_from_env("SDK_DIAGNOSTICS_ENABLED", False, type_cast=str_to_bool)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Production setting is not wired

This adds a new environment variable without satisfying the repository directive to add it to posthog/charts and configure it through posthog/secrets. Without that production wiring, workers retain the false default and diagnostics cannot be enabled. This repository requirement must be satisfied before merging.

Rule Used: When a new secret or environment variable is added (e.g. via get_from_env in settings files, or new entries in .env.example/env.default), warn that it must also be added to the posthog/charts repository and set via posthog/secrets to take effec... (source)

Prompt To Fix With AI
This is a comment left during a code review.
Path: posthog/settings/ingestion.py
Line: 83

Comment:
**Production setting is not wired**

This adds a new environment variable without satisfying the repository directive to add it to `posthog/charts` and configure it through `posthog/secrets`. Without that production wiring, workers retain the false default and diagnostics cannot be enabled. This repository requirement must be satisfied before merging.

**Rule Used:** When a new secret or environment variable is added (e.g. via `get_from_env` in settings files, or new entries in `.env.example`/`env.default`), warn that it must also be added to the posthog/charts repository and set via posthog/secrets to take effec... ([source](https://app.greptile.com/posthog-org-19734/github/PostHog/posthog/-/custom-context?memory=c7932f06-eec7-4fbe-b35f-ac93bc7b7a80))

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

@trunk-io

trunk-io Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Static Badge   Static Badge   Static Badge

Failed Test Failure Summary Logs
flags::feature_flag_list::tests::test_fetch_flags_from_redis The test failed because fetching flags from Redis timed out. Logs ↗︎

View Full Report ↗︎ ⋅ Docs

@coderabbitai

coderabbitai Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: PostHog/posthog/.coderabbit.yaml

Review profile: QUIET

Plan: Enterprise

Run ID: 5a620c0b-488e-4114-980c-847169632c28

📥 Commits

Reviewing files that changed from the base of the PR and between a0d8ce5 and d6d1c08.

📒 Files selected for processing (3)
  • docs/internal/feature-flags/hypercache-system.md
  • nodejs/src/ingestion/common/steps/event-preprocessing/apply-person-processing-restrictions.test.ts
  • nodejs/src/ingestion/common/steps/event-preprocessing/apply-person-processing-restrictions.ts

Included review availability: Your plan provides up to 12 included reviews per hour; 10 remain after this review.


📝 Walkthrough

Walkthrough

The change adds organization- and project-level SDK diagnostics opt-out fields. APIs and generated schemas expose the settings with admin authorization. Remote configuration now includes sdkDiagnosticsEnabled, gated by the global setting and both opt-out fields. Organization changes refresh project configurations after commit with retry handling. Ingestion forces person processing off for $sdk_diagnostics_config events and removes specified person-property updates during normalization. Tests and documentation cover these changes.

Priority: ⬇️ Low

Merge Risk: ⚪ Minimal · up to d6d1c

This change adds organization and project opt-outs for SDK diagnostics and gates a new remote-config flag that stays off by default. It also stops diagnostics events from creating or updating persons. Existing billing behavior is unchanged, and no merge-blocking issue remains; the migration coordination the author noted still applies at deploy time.

Architecture Summary

Architecture risk: 🔵 Low · up to d6d1c

The change affects 4 systems.

Changed systems: nodejs, posthog, services/mcp, docs

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — nodejs (service) was modified; 2 changed files map to changed impact.
  • observed — posthog (service) was modified; 18 changed files map to changed impact.
  • observed — services/mcp (api) was modified; 2 changed files map to changed impact.
  • observed — docs (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in posthog/api/organization.py: Added sdk_diagnostics_opt_out to the organization serializer’s output fields.
  • observed — Modified behavior in posthog/api/project.py: Added sdk_diagnostics_opt_out to the backward-compatible project serializer’s exposed fields.
  • observed — Modified behavior in posthog/api/project.py: Added sdk_diagnostics_opt_out to the fields delegated from Project updates to its passthrough Team.
  • observed — Modified behavior in posthog/api/team.py: Added sdk_diagnostics_opt_out to the team configuration field registry.
🚥 Pre-merge checks | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description covers the problem, user-visible changes, testing, documentation, migration risks, and agent context. However, it omits the required Release status section and does not select exactly … Add the Release status section and select exactly one applicable option: no feature flag, behind a feature flag, or fully available. Base the selection on the SDK_DIAGNOSTICS_ENABLED feature-flag checks in the changed code.
Full details: Description check

Explanation

The description covers the problem, user-visible changes, testing, documentation, migration risks, and agent context. However, it omits the required Release status section and does not select exactly one feature-flag option.

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
⚔️ Resolve merge conflicts 💡
  • Resolve merge conflict in branch feat/sdk-diagnostics-remote-config
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@marandaneto
marandaneto added this pull request to stack #106465 September 25, 2026 07:53

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant