Skip to content

Correct what the telemetry guide says about egress and credentials - #504

Open
dennis-upbound wants to merge 1 commit into
modelplaneai:mainfrom
dennis-upbound:dennis/fix-telemetry-egress-claim
Open

dennis-upbound wants to merge 1 commit into
modelplaneai:mainfrom
dennis-upbound:dennis/fix-telemetry-egress-claim

Conversation

@dennis-upbound

Copy link
Copy Markdown
Collaborator

Description of your changes

One paragraph of the shipped v0.5 telemetry guide makes three claims, and all three are false. Found while researching #476.

Your clusters reach the control plane, and only the control plane reaches your backend. A cluster with no route to your observability stack still reports, and the backend's credential lives in one place instead of on every GPU cluster.

  • "only the control plane reaches your backend" — there is no control-plane collector. compose_collector (fn.py#L772) is called only from the ServingStack path and composes onto each inference cluster. Each cluster's collector exports to the sinks directly.
  • "a cluster with no route still reports" — it does not. Without a route to the backend it exports nothing.
  • "the credential lives in one place instead of on every GPU cluster" — the opposite, and deliberately so. Collect metrics from every inference cluster #470 added the copy precisely because the collector mounts the Secret on the workload cluster and nothing put it there, which was the bug @negz found in review (discussion).

The third is the one worth fixing quickly: someone deciding whether to hand Modelplane a vendor token reads that sentence and gets the wrong answer about where the token ends up.

The rest of the page already describes the copy correctly (docs/content/platform/telemetry.md:101), so this paragraph contradicts both the code and its own guide. I also dropped a colon on that line that ai-tells.ColonUsage flags locally.

Wants a backport to release-0.5 — the claim is in the published 0.5 docs.

I have:

  • Read and followed Modelplane's contribution process.
  • Run nix flake check (or ./nix.sh flake check) and made sure it passes.
  • Added or updated tests covering any composition function changes. Docs only.
  • Signed off every commit with git commit -s.

🤖 Generated with Claude Code

Three claims in one paragraph of the shipped guide are wrong, and the third
is about where a user's credential is held.

"Your clusters reach the control plane, and only the control plane reaches
your backend." Modelplane composes a collector onto each inference cluster
and no collector onto the control plane. Each cluster exports to the sinks
itself.

"A cluster with no route to your observability stack still reports." It does
not. Without a route to the backend it exports nothing.

"The backend's credential lives in one place instead of on every GPU
cluster." The opposite is true, and deliberately so: compose-serving-stack
resolves the Secret a sink names and composes a copy onto every cluster that
runs a collector, because the collector mounts it there. A reader deciding
whether to give Modelplane a vendor token would have read this and been
wrong about where the token ends up.

The guide elsewhere describes the copy correctly, so this paragraph is the
one place that contradicts both the code and the rest of the page.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Signed-off-by: Dennis Ramdass <dennis@upbound.io>
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

Docs preview: https://modelplane-docs-pr-504.vercel.app (ready once the site's Content workflow finishes)

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants