feat(aws-lambda-microvm): refresh identity on Flask run hook - #19825
litianningdatadog wants to merge 1 commit into
Conversation
Codeowners resolved asResolved from the full PR diff against |
Circular import analysis
|
Dependency direction analysis📈 Existing violations got worse10 pre-existing violation(s) increased in severity (e.g. their target became more depended-on, or got pulled into an import cycle), though the edge itself isn't new: Show violations that got worse (showing 5 of 10 highest severity)
|
🎉 All green!🧪 All tests passed 🔄 Datadog auto-retried 2 jobs - 2 passed on retry 🔗 Commit SHA: 5703c03 | Docs | View more details | Give us feedback! |
aba2924 to
5d444c6
Compare
BenchmarksBenchmark execution time: 2026-08-25 03:16:45 Comparing candidate commit 5703c03 in PR branch Found 0 performance improvements and 11 performance regressions! Performance is the same for 603 metrics, 10 unstable metrics.
|
There was a problem hiding this comment.
Pull request overview
Adds AWS Lambda MicroVM-specific runtime identity rotation triggered by Flask’s pre-request web event, so restored MicroVM instances regenerate stable identifiers (runtime ID / RC client ID) on the platform /run lifecycle hook.
Changes:
- Register a
WEB_REQUEST_STARTINGlistener (MicroVM-only) that refreshes identity exactly once when the request matchesPOST /aws/lambda-microvms/runtime/v1/run. - Add subprocess and Flask integration tests covering exact-match behavior, ordering relative to root span creation, concurrency, and no-op behavior outside MicroVMs.
- Add a release note describing stable identifier regeneration for AWS Lambda MicroVM deployments.
Reviewed changes
Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
ddtrace/internal/runtime/__init__.py |
Adds MicroVM /run hook constants, listener registration, and the once-per-process guarded refresh logic. |
tests/tracer/runtime/test_runtime_id.py |
Adds unit/subprocess tests for hook matching, ordering vs. span creation, thread safety, and no-op cases. |
tests/contrib/flask/test_microvm_identity_refresh.py |
Updates Flask event assertions to use the real MicroVM /run hook path and verifies identity refresh via emitted events. |
releasenotes/notes/aws-lambda-microvm-identity-refresh-3a672cd6bcbad16d.yaml |
Documents the MicroVM-only stable identifier regeneration behavior. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
d59e112 to
16a5332
Compare
5d444c6 to
c7d02b5
Compare
16a5332 to
8dd7e8e
Compare
c7d02b5 to
7595e97
Compare
@cit-pr-commenter-54b7da This has been fixed in upstream PR |
7595e97 to
203ca67
Compare
8dd7e8e to
d4c1810
Compare
203ca67 to
dc34f17
Compare
d4c1810 to
12b6c50
Compare
dce366c to
46e2121
Compare
12b6c50 to
0fa6836
Compare
46e2121 to
c1ffc6d
Compare
0fa6836 to
cde3045
Compare
c81ebfb to
f2de1fd
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f2de1fd207
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
f2de1fd to
35ab0c3
Compare
cde3045 to
a0e3c42
Compare
35ab0c3 to
d67a43d
Compare
d67a43d to
5703c03
Compare
emmettbutler
left a comment
There was a problem hiding this comment.
Converted to draft because the base is not main. Please mark as ready once the diff is ready to merge into main.
Stacked PRs:
Description
This is the Flask-only MicroVM
/runactivation path. When running inside an AWS Lambda MicroVM image,ddtraceregisters a listener for the pre-request web event emitted by Flask. The listener matches the fixed platform hook:and calls
runtime.refresh_identity()once per process. This keeps the activation path focused on Flask while the identity consumers are split across the 3-series draft PRs.The hook registration is driven from
ddtrace.__init__afterddtrace.configis exported.ddtrace.internal.runtimeimports the sharedddtrace.internal.core.event_names.WEB_REQUEST_STARTINGconstant and reusesddtrace.internal.serverless.in_aws_lambda_microvm()for the environment check. This avoids importingddtrace.contribwhileddtraceis partially initialized in MicroVM images.Testing
scripts/lint fmt ddtrace/__init__.py ddtrace/internal/runtime/__init__.py tests/tracer/runtime/test_runtime_id.py tests/contrib/flask/test_microvm_identity_refresh.py ddtrace/internal/serverless/__init__.pygit diff --checkuv run --script scripts/import-analysis/cycles.py analyze /tmp/ddtrace-cycles-pr19825.jsonddtrace.internal.runtime,ddtrace.internal.serverless,ddtrace.internal.settings, orddtrace.contrib.internal.flask.patch; existing repository total remains 3.scripts/run-tests --venv 12c5734 -- -- tests/internal/test_serverless.py tests/tracer/runtime/test_runtime_id.py tests/contrib/flask/test_microvm_identity_refresh.pyImportError: cannot import name 'process_metrics' from 'ddtrace.internal.native._native'Stack
Depends on #19816.
Extracted from #19781 (closed)