Skip to content

CCL-2140: add per-cluster Envoy access log override - #310

Open
lakhansamani wants to merge 1 commit into
mainfrom
ccl-2140-per-cluster-access-log
Open

CCL-2140: add per-cluster Envoy access log override#310
lakhansamani wants to merge 1 commit into
mainfrom
ccl-2140-per-cluster-access-log

Conversation

@lakhansamani

Copy link
Copy Markdown
Contributor

Ticket: CCL-2140

Summary
The Envoy access log is enabled per region (operator#981), which is too coarse to act on during an incident: in ap-south-1 one tenant carries 1216 of the region's 1404 rps, so silencing it meant giving up the log for the other 170 clusters.
Ingress.EnableAccessLog is three-state — unset follows the region, true and false override it in either direction. Additive and optional, so no existing cluster changes behaviour.

Tests
manifests / generate / fmt / fmt_imports / vet / lint / test: 0 failures, 0 lint issues.
Table test covers all five states, including the two that matter — forcing off against an enabled region and on against a disabled one — plus a JSON test that unset stays absent from the spec.

The access log is enabled per region, which is too coarse to act on during
an incident: a single tenant can carry most of a region's traffic, so
silencing one cluster meant giving up the log for every other cluster there.

Ingress.EnableAccessLog is three-state — unset follows the region, true and
false override it in either direction.
@lakhansamani
lakhansamani requested a review from a team as a code owner August 21, 2026 13:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant