• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

opendefensecloud / artifact-conduit / 35592011123
86%

Build:
DEFAULT BRANCH: main
Ran 21 Sep 2026 11:12AM UTC
Jobs 1
Files 17
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

21 Sep 2026 11:03AM UTC coverage: 86.364% (+0.5%) from 85.818%
35592011123

push

github

web-flow
feat(chart): scrape ARC and ship the reference dashboard (#480)

## What

Scraping for the metrics #471 added, plus the reference dashboard which
closes #316:

<img width="2758" height="1820" alt="image"
src="https://github.com/user-attachments/assets/27d7e950-c97c-46b9-b98a-36905a6049a3"
/>


- `honorLabels` on the controller ServiceMonitor, new one for the API
Server, both off by default
- `{release}-apiserver-metrics-reader` ClusterRole, created but unbound,
and `system:auth-delegator` bound to the API Server SA when the monitor
is on
- `targetLabels` so every ARC series carries `part-of` and `component`
- the dashboard itself, 14 panels in 4 sections, shipped as a ConfigMap
for the Grafana sidecar, `dashboards.enabled`, off by default
- a test that fails if a panel queries a metric ARC does not emit
- `observability.md` rewritten, it still claimed ARC has no custom
metrics
- `.dockerignore`, unrelated but it was blocking local image builds

## Why

ARC metrics carry a `namespace` label for the Order's namespace.
Prometheus Operator attaches its own for the install namespace and
renames the scraped one to `exported_namespace` -> every dashboard
filter on `namespace` matches nothing, so `honorLabels` goes on. The API
Server already served `/metrics` and nothing collected it.
`targetLabels` matters more than it looks: `apiserver_request_total` and
`workqueue_depth` are emitted by the control plane too, and in the test
cluster that is 24 ARC series out of 397, and 6 out of 39. Unfiltered
those panels quietly average ARC together with kube-controller-manager.

A scrape hits the Service directly, not through the aggregation layer,
so the API Server authenticates the token itself. Our ClusterRole had
`subjectaccessreviews` but no `tokenreviews` -> auth just failed. Gated
on the monitor, nothing widens by default. TLS verifies against the
cert-manager issued CA by default, `serverName` and `caSecret` resolve
on their own, and rendering fails with a clear ... (continued)

50 of 54 new or added lines in 4 files covered. (92.59%)

4 existing lines in 2 files now uncovered.

1596 of 1848 relevant lines covered (86.36%)

3036.71 hits per line

Uncovered Changes

Lines Coverage ∆ File
3
89.29
pkg/metrics/schedule.go
1
94.24
-0.16% pkg/metrics/collector.go

Coverage Regressions

Lines Coverage ∆ File
2
83.92
-0.77% pkg/controller/artifactworkflow_controller.go
2
85.77
2.03% pkg/controller/workflow_handler.go
Jobs
ID Job ID Ran Files Coverage
1 35592011123.1 21 Sep 2026 11:12AM UTC 17
86.36
GitHub Action Run
Source Files on build 35592011123
  • Tree
  • List 17
  • Changed 5
  • Source Changed 3
  • Coverage Changed 5
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #35592011123
  • 10e008c7 on github
  • Prev Build on main (#35337656786)
  • Next Build on main (#35727937888)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc