From b64bf8df53ae0e8a8d1e3a53776676d0b64fa532 Mon Sep 17 00:00:00 2001 From: Dennis Ramdass Date: Mon, 5 Oct 2026 10:52:04 -0700 Subject: [PATCH] Correct what the telemetry guide says about egress and credentials Three claims in one paragraph of the shipped guide are wrong, and the third is about where a user's credential is held. "Your clusters reach the control plane, and only the control plane reaches your backend." Modelplane composes a collector onto each inference cluster and no collector onto the control plane. Each cluster exports to the sinks itself. "A cluster with no route to your observability stack still reports." It does not. Without a route to the backend it exports nothing. "The backend's credential lives in one place instead of on every GPU cluster." The opposite is true, and deliberately so: compose-serving-stack resolves the Secret a sink names and composes a copy onto every cluster that runs a collector, because the collector mounts it there. A reader deciding whether to give Modelplane a vendor token would have read this and been wrong about where the token ends up. The guide elsewhere describes the copy correctly, so this paragraph is the one place that contradicts both the code and the rest of the page. Co-Authored-By: Claude Opus 5 Signed-off-by: Dennis Ramdass --- docs/content/platform/telemetry.md | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/docs/content/platform/telemetry.md b/docs/content/platform/telemetry.md index cc5d0d560..02527c69b 100644 --- a/docs/content/platform/telemetry.md +++ b/docs/content/platform/telemetry.md @@ -98,7 +98,7 @@ spec: `type` names a collector exporter, by the name OpenTelemetry gives it. To authenticate with a bearer token, store the token in a Secret in -`modelplane-system` on your control plane. Create it once: Modelplane copies it to +`modelplane-system` on your control plane. Create it once. Modelplane copies it to every cluster running a collector, so you don't put the credential on each GPU cluster yourself. @@ -210,9 +210,10 @@ Modelplane doesn't run any collectors until you create a Creating a destination turns collection on everywhere at once, and there's no per-deployment opt-out. -Your clusters reach the control plane, and only the control plane reaches your backend. A -cluster with no route to your observability stack still reports, and the backend's -credential lives in one place instead of on every GPU cluster. +Each cluster's collector exports to your backend itself. A cluster needs a route to that +backend to report. Where a sink names a `secretRef`, you create that Secret once on the +control plane and Modelplane copies it to every cluster running a collector, so the +credential is held on each of them. ## Computing rates, quantiles, and ratios