Skip to content

Harden Agentless Feature Flags EVP delivery - #12477

Open
leoromanovsky wants to merge 5 commits into
masterfrom
leoromanovsky/fflsdk-187-java-evp-fallback
Open

leoromanovsky wants to merge 5 commits into
masterfrom
leoromanovsky/fflsdk-187-java-evp-fallback

Conversation

@leoromanovsky

@leoromanovsky leoromanovsky commented Sep 12, 2026 •

Copy link
Copy Markdown
Contributor

Motivation

Java already delivers agentless exposures (#12195) and flag evaluations (#12204) directly to EVP. This follow-up closes reliability gaps found while checking the cross-SDK contract: unsafe replay, inconsistent writer routes, lost Agent URL prefixes and permanent disablement when no route exists at startup. Tracks FFLSDK-187.

Changes

  • Share Agentless route state between writers, preserve URL prefixes, and require both identity-forwarding capabilities before selecting local EVP.
  • Keep direct routing sticky; recover only from unavailable state with bounded probes.
  • Disable underlying retries and redirects; replay only after 404/405 or a proven pre-connect failure. Keep credentials route-specific and Remote Config fixed to Agent EVP v2.
  • Bound exposure shutdown flushing, including trace-disabled operation, with lifecycle and concurrency coverage.

Decisions

  • SDK origin/version emission is isolated in stacked identity PR Send Java SDK identity with Feature Flagging EVP events #12575. This bottom PR alone is not completion of the identity contract.
  • Bounded shutdown remains explicit additional lifecycle scope here; it is independent of identity attribution.
  • No new product surface or system-test changes. Existing delivery is hardened rather than reimplemented from scratch.

Validation

  • Existing default-branch base: 3110972ccf744f304a7cf59973e240f9ccd1a071.
  • Exact reduced candidate: 1b5766b56c67bb7151a084abb752e62e5bb4b332.
  • ./gradlew :communication:spotlessApply :products:feature-flagging:feature-flagging-lib:spotlessApply :communication:test :products:feature-flagging:feature-flagging-lib:test --console=plain --max-workers=4: PASS; communication 234/234, feature-flagging-lib 279/279.
  • Capability regression proves missing or partial forwarding support is rejected even without identity-header configuration. Credential and no-replay tests remain below the identity split.
  • git diff --check: PASS. New scope-reduction commit is GitHub verified: verified=true, reason=valid.
  • No refreshed whole-agent lifecycle, CI, system-tests, dogfooding or backend-intake evidence for this candidate. Earlier results belong to e20a9d77c333ddb0c0444835f23fafba70952373 and must not be carried forward as current proof.
  • Fresh CI remains separate from local validation. This PR remains a draft.

Add capability-gated local discovery, safe sticky direct fallback, shared route state, send-once semantics, and bounded lifecycle handling for Java Feature Flags telemetry.

Environment: Datadog workspace
@leoromanovsky leoromanovsky added type: feature Enhancements and improvements tag: ai generated Largely based on code generated by an AI or LLM comp: openfeature OpenFeature labels Sep 12, 2026
@linear-code

linear-code Bot commented Sep 12, 2026

Copy link
Copy Markdown

FFLSDK-187

@datadog-official

This comment has been minimized.

@dd-octo-sts

dd-octo-sts Bot commented Sep 12, 2026 •

Copy link
Copy Markdown
Contributor

🟢 Java Benchmark SLOs — All performance SLOs passed

Suite Status
Startup 🟢 pass

SLO thresholds are defined here based on automatically generated metrics. A warning is raised when results are within 5% of the threshold.

PR vs. master results
Scenario Candidate master Δ (95% CI of mean)
startup:insecure-bank:iast:Agent 14.09 s 13.96 s [+0.1%; +1.7%] (maybe worse)
startup:insecure-bank:tracing:Agent 12.96 s 13.01 s [-1.0%; +0.2%] (no difference)
startup:petclinic:appsec:Agent 16.63 s 17.02 s [-6.6%; +2.1%] (no difference)
startup:petclinic:iast:Agent 16.94 s 17.04 s [-1.5%; +0.4%] (no difference)
startup:petclinic:profiling:Agent 16.63 s 16.74 s [-1.9%; +0.5%] (no difference)
startup:petclinic:sca:Agent 17.08 s 16.89 s [+0.1%; +2.2%] (maybe worse)
startup:petclinic:tracing:Agent 15.79 s 15.81 s [-5.9%; +5.6%] (unstable)

Commit: 42185593 · CI Pipeline · Benchmarking Platform UI


Load and DaCapo benchmarks can be triggered manually in the GitLab pipeline. Results will appear in the Benchmarking Platform UI after completion.

Move identity attribution to a follow-up branch while keeping forwarding-capability requirements explicit and independent of emitted headers. Preserve credential isolation, no-replay coverage, and existing lifecycle hardening.

Validation: communication tests 234/234 and feature-flagging-lib tests 279/279 pass; scoped Spotless formatting passes.

Environment: Datadog workspace
@leoromanovsky
leoromanovsky marked this pull request as ready for review September 21, 2026 14:42
@leoromanovsky
leoromanovsky requested review from a team as code owners September 21, 2026 14:42
@leoromanovsky
leoromanovsky requested review from bric3, btthomas, pavlokhrebto and vandonr and removed request for a team September 21, 2026 14:42
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-21T14:47:50.191853Z 1b5766b Draft marked ready
🔒 Security Review ✅ Completed 2026-09-21T14:51:15.140290Z 1b5766b Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@datadog-official datadog-official Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Autotest was unable to complete this review. View session

Please try again by commenting @autotest review.

@dougqh dougqh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Generated with Claude Code

Environment: Datadog workspace
Gate shutdown instrumentation on tracing or resolved feature flag enablement, and share Agent path joining. Pin recovery generations, discovery concurrency, replay, idle recovery, and disabled-product behavior with regression tests.

Environment: Datadog workspace
@leoromanovsky
leoromanovsky requested a review from dougqh October 7, 2026 02:58
@leoromanovsky
leoromanovsky requested review from typotter and vjfridge and removed request for btthomas and pavlokhrebto October 7, 2026 02:58

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comp: openfeature OpenFeature tag: ai generated Largely based on code generated by an AI or LLM type: feature Enhancements and improvements

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants