Skip to content

feat(aws-lambda-microvm): refresh identity on Flask run hook - #19825

Draft
litianningdatadog wants to merge 1 commit into
tianning.li/2-flask-web-request-starting-eventfrom
tianning.li/4-1-flask-microvm-run-hook-activation
Draft

litianningdatadog wants to merge 1 commit into
tianning.li/2-flask-web-request-starting-eventfrom
tianning.li/4-1-flask-microvm-run-hook-activation

Conversation

@litianningdatadog

@litianningdatadog litianningdatadog commented Aug 23, 2026 •

Copy link
Copy Markdown
Contributor

Stacked PRs:

Description

This is the Flask-only MicroVM /run activation path. When running inside an AWS Lambda MicroVM image, ddtrace registers a listener for the pre-request web event emitted by Flask. The listener matches the fixed platform hook:

POST /aws/lambda-microvms/runtime/v1/run

and calls runtime.refresh_identity() once per process. This keeps the activation path focused on Flask while the identity consumers are split across the 3-series draft PRs.

The hook registration is driven from ddtrace.__init__ after ddtrace.config is exported. ddtrace.internal.runtime imports the shared ddtrace.internal.core.event_names.WEB_REQUEST_STARTING constant and reuses ddtrace.internal.serverless.in_aws_lambda_microvm() for the environment check. This avoids importing ddtrace.contrib while ddtrace is partially initialized in MicroVM images.

Testing

  • scripts/lint fmt ddtrace/__init__.py ddtrace/internal/runtime/__init__.py tests/tracer/runtime/test_runtime_id.py tests/contrib/flask/test_microvm_identity_refresh.py ddtrace/internal/serverless/__init__.py
  • git diff --check
  • uv run --script scripts/import-analysis/cycles.py analyze /tmp/ddtrace-cycles-pr19825.json
    • No cycle involving ddtrace.internal.runtime, ddtrace.internal.serverless, ddtrace.internal.settings, or ddtrace.contrib.internal.flask.patch; existing repository total remains 3.
  • scripts/run-tests --venv 12c5734 -- -- tests/internal/test_serverless.py tests/tracer/runtime/test_runtime_id.py tests/contrib/flask/test_microvm_identity_refresh.py
    • Blocked locally during collection/build by the existing native-extension mismatch: ImportError: cannot import name 'process_metrics' from 'ddtrace.internal.native._native'

Stack

Depends on #19816.

Extracted from #19781 (closed)

@litianningdatadog litianningdatadog added the aws-microvm Work related to AWS MicroVM onboarding label Aug 23, 2026
@cit-pr-commenter-54b7da

cit-pr-commenter-54b7da Bot commented Aug 23, 2026 •

Copy link
Copy Markdown

Codeowners resolved as

Resolved from the full PR diff against tianning.li/2-flask-web-request-starting-event using the target branch CODEOWNERS file.
CODEOWNERS team requests not listed below are not required by the current file set.

ddtrace/__init__.py                                                     @DataDog/python-guild
ddtrace/internal/runtime/__init__.py                                    @DataDog/apm-sdk-capabilities-python
releasenotes/notes/aws-lambda-microvm-identity-refresh-3a672cd6bcbad16d.yaml  @DataDog/apm-python
tests/contrib/flask/test_microvm_identity_refresh.py                    @DataDog/apm-core-python @DataDog/apm-idm-python
tests/tracer/runtime/test_runtime_id.py                                 @DataDog/apm-sdk-capabilities-python

@cit-pr-commenter-54b7da

cit-pr-commenter-54b7da Bot commented Aug 23, 2026 •

Copy link
Copy Markdown

Circular import analysis

⚠️ Existing circular imports

There are 3 circular imports that already exist on the base branch and have not been changed by this PR.

ddtrace.llmobs -> ddtrace.llmobs._evaluators -> ddtrace.llmobs._evaluators.format -> ddtrace.llmobs._experiment -> ddtrace.llmobs
ddtrace.errortracking._handled_exceptions.bytecode_injector -> ddtrace.errortracking._handled_exceptions.callbacks -> ddtrace.errortracking._handled_exceptions.collector -> ddtrace.errortracking._handled_exceptions.bytecode_reporting -> ddtrace.errortracking._handled_exceptions.bytecode_injector
ddtrace.appsec._asm_request_context -> ddtrace.appsec._iast._iast_request_context_base -> ddtrace.appsec._iast._iast_env -> ddtrace.appsec._iast.reporter -> ddtrace.appsec._exploit_prevention.stack_traces -> ddtrace.appsec._asm_request_context

@cit-pr-commenter-54b7da

cit-pr-commenter-54b7da Bot commented Aug 23, 2026 •

Copy link
Copy Markdown

Dependency direction analysis

📈 Existing violations got worse

10 pre-existing violation(s) increased in severity (e.g. their target became more depended-on, or got pulled into an import cycle), though the edge itself isn't new:

Show violations that got worse (showing 5 of 10 highest severity)
ddtrace.internal.writer.writer -×-> ddtrace.internal.runtime  (internal-core -> product:runtime, score=15, +1 vs base)
ddtrace.internal.symbol_db.remoteconfig -×-> ddtrace.internal.runtime  (internal-core -> product:runtime, score=15, +1 vs base)
ddtrace.internal.remoteconfig.client -×-> ddtrace.internal.runtime  (internal-core -> product:runtime, score=15, +1 vs base)
ddtrace.internal.telemetry.writer -×-> ddtrace.internal.runtime  (internal-core -> product:runtime, score=15, +1 vs base)
ddtrace.internal.core.crashtracking -×-> ddtrace.internal.runtime  (internal-core -> product:runtime, score=15, +1 vs base)

To see all violations, download the layers-base.json and layers-pr.json artifacts from this CI job and run:

uv run --script scripts/import-analysis/layers.py compare layers-base.json layers-pr.json

⚠️ Existing dependency direction violations

There are 250 dependency direction violations that already exist on the base branch and have not been changed by this PR.

Show existing violations (showing 5 of 250 highest severity)
ddtrace.internal.tracemethods -×-> ddtrace.trace  (internal-core -> product:tracing, score=135)
ddtrace.aiguard._api_client -×-> ddtrace.trace  (product:aiguard -> product:tracing, score=133)
ddtrace.debugging._signal.model -×-> ddtrace.trace  (product:debugging -> product:tracing, score=133)
ddtrace.internal.test_visibility.api -×-> ddtrace.trace  (product:ci_visibility -> product:tracing, score=133)
ddtrace.llmobs._integrations.base -×-> ddtrace.trace  (product:llmobs -> product:tracing, score=133)

To see all violations, download the layers-base.json and layers-pr.json artifacts from this CI job and run:

uv run --script scripts/import-analysis/layers.py compare layers-base.json layers-pr.json

@datadog-datadog-us1-prod

datadog-datadog-us1-prod Bot commented Aug 23, 2026 •

Copy link
Copy Markdown

Tests

🎉 All green!

🧪 All tests passed
❄️ No new flaky tests detected

🔄 Datadog auto-retried 2 jobs - 2 passed on retry View in Datadog

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 5703c03 | Docs | View more details | Give us feedback!

@litianningdatadog
litianningdatadog force-pushed the tianning.li/4-1-flask-microvm-run-hook-activation branch from aba2924 to 5d444c6 Compare August 23, 2026 22:24
@pr-commenter

pr-commenter Bot commented Aug 23, 2026 •

Copy link
Copy Markdown

Benchmarks

Benchmark execution time: 2026-08-25 03:16:45

Comparing candidate commit 5703c03 in PR branch tianning.li/4-1-flask-microvm-run-hook-activation with baseline commit a0e3c42 in branch tianning.li/2-flask-web-request-starting-event.

📊 Benchmarking dashboard

Found 0 performance improvements and 11 performance regressions! Performance is the same for 603 metrics, 10 unstable metrics.

Explanation

This is an A/B test comparing a candidate commit's performance against that of a baseline commit. Performance changes are noted in the tables below as:

  • 🟩 = significantly better candidate vs. baseline
  • 🟥 = significantly worse candidate vs. baseline

We compute a confidence interval (CI) over the relative difference of means between metrics from the candidate and baseline commits, considering the baseline as the reference.

If the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD), the change is considered significant.

Feel free to reach out to #apm-benchmarking-platform on Slack if you have any questions.

More details about the CI and significant changes

You can imagine this CI as a range of values that is likely to contain the true difference of means between the candidate and baseline commits.

CIs of the difference of means are often centered around 0%, because often changes are not that big:

---------------------------------(------|---^--------)-------------------------------->
                              -0.6%    0%  0.3%     +1.2%
                                 |          |        |
         lower bound of the CI --'          |        |
sample mean (center of the CI) -------------'        |
         upper bound of the CI ----------------------'

As described above, a change is considered significant if the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD).

For instance, for an execution time metric, this confidence interval indicates a significantly worse performance:

----------------------------------------|---------|---(---------^---------)---------->
                                       0%        1%  1.3%      2.2%      3.1%
                                                  |   |         |         |
       significant impact threshold --------------'   |         |         |
                      lower bound of CI --------------'         |         |
       sample mean (center of the CI) --------------------------'         |
                      upper bound of CI ----------------------------------'

scenario:httppropagationextract-wsgi_valid_headers_all

  • 🟥 execution_time [+435.820ns; +490.755ns] or [+8.010%; +9.020%]

scenario:httppropagationinject-ids_only

  • 🟥 execution_time [+1.934µs; +2.094µs] or [+10.063%; +10.895%]

scenario:iastaspects-add_aspect

  • 🟥 execution_time [+15.382µs; +18.502µs] or [+15.190%; +18.270%]

scenario:iastaspects-join_aspect

  • 🟥 execution_time [+44.045µs; +49.458µs] or [+20.741%; +23.290%]

scenario:iastaspects-ljust_noaspect

  • 🟥 execution_time [+58.053µs; +63.383µs] or [+20.277%; +22.139%]

scenario:iastaspects-title_aspect

  • 🟥 execution_time [+66.894µs; +71.900µs] or [+25.087%; +26.964%]

scenario:iastaspectsospath-ospathbasename_aspect

  • 🟥 execution_time [+143.065µs; +151.100µs] or [+35.227%; +37.205%]

scenario:iastaspectssplit-rsplit_aspect

  • 🟥 execution_time [+19.545µs; +23.635µs] or [+13.527%; +16.358%]

scenario:span-start

  • 🟥 execution_time [+1.424ms; +1.605ms] or [+9.390%; +10.587%]

scenario:telemetryaddmetric-1-count-metric-1-times

  • 🟥 execution_time [+402.780ns; +445.184ns] or [+14.868%; +16.433%]

scenario:tracer-small

  • 🟥 execution_time [+27.607µs; +30.034µs] or [+8.182%; +8.901%]

Unstable benchmarks

These benchmarks have a confidence interval too wide to call a change; treat them as noise rather than signal.

scenario:coreapiscenario-context_with_data_listeners

  • unstable execution_time [-701.922ns; +786.042ns] or [-6.352%; +7.113%]

scenario:coreapiscenario-core_dispatch_1_listener

  • unstable execution_time [-35.324ns; +31.047ns] or [-5.773%; +5.074%]

scenario:coreapiscenario-core_dispatch_50_listeners

  • unstable execution_time [-1750.938ns; +1586.665ns] or [-10.177%; +9.222%]

scenario:coreapiscenario-core_dispatch_exception_listeners

  • unstable execution_time [-1188.258ns; +1267.891ns] or [-9.230%; +9.849%]

scenario:coreapiscenario-core_dispatch_listeners

  • unstable execution_time [-344.536ns; +311.594ns] or [-9.327%; +8.435%]

scenario:coreapiscenario-core_dispatch_no_args_listeners

  • unstable execution_time [-278.165ns; +230.459ns] or [-9.485%; +7.858%]

scenario:coreapiscenario-core_dispatch_with_results_1_listener

  • unstable execution_time [-95.601ns; +52.388ns] or [-8.308%; +4.553%]

scenario:coreapiscenario-core_dispatch_with_results_50_listeners

  • unstable execution_time [-3650.380ns; +4214.846ns] or [-9.092%; +10.498%]

scenario:coreapiscenario-core_dispatch_with_results_listeners

  • unstable execution_time [-759.789ns; +769.972ns] or [-9.498%; +9.625%]

scenario:packagesupdateimporteddependencies-import_many_stdlib_cached

  • unstable execution_time [-63.695µs; +57.802µs] or [-9.892%; +8.977%]

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds AWS Lambda MicroVM-specific runtime identity rotation triggered by Flask’s pre-request web event, so restored MicroVM instances regenerate stable identifiers (runtime ID / RC client ID) on the platform /run lifecycle hook.

Changes:

  • Register a WEB_REQUEST_STARTING listener (MicroVM-only) that refreshes identity exactly once when the request matches POST /aws/lambda-microvms/runtime/v1/run.
  • Add subprocess and Flask integration tests covering exact-match behavior, ordering relative to root span creation, concurrency, and no-op behavior outside MicroVMs.
  • Add a release note describing stable identifier regeneration for AWS Lambda MicroVM deployments.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.

File Description
ddtrace/internal/runtime/__init__.py Adds MicroVM /run hook constants, listener registration, and the once-per-process guarded refresh logic.
tests/tracer/runtime/test_runtime_id.py Adds unit/subprocess tests for hook matching, ordering vs. span creation, thread safety, and no-op cases.
tests/contrib/flask/test_microvm_identity_refresh.py Updates Flask event assertions to use the real MicroVM /run hook path and verifies identity refresh via emitted events.
releasenotes/notes/aws-lambda-microvm-identity-refresh-3a672cd6bcbad16d.yaml Documents the MicroVM-only stable identifier regeneration behavior.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread ddtrace/internal/runtime/__init__.py Outdated
@litianningdatadog
litianningdatadog force-pushed the tianning.li/2-flask-web-request-starting-event branch from d59e112 to 16a5332 Compare August 24, 2026 02:23
@litianningdatadog
litianningdatadog force-pushed the tianning.li/4-1-flask-microvm-run-hook-activation branch from 5d444c6 to c7d02b5 Compare August 24, 2026 02:26
@litianningdatadog
litianningdatadog force-pushed the tianning.li/2-flask-web-request-starting-event branch from 16a5332 to 8dd7e8e Compare August 24, 2026 02:31
@litianningdatadog
litianningdatadog force-pushed the tianning.li/4-1-flask-microvm-run-hook-activation branch from c7d02b5 to 7595e97 Compare August 24, 2026 02:32
@litianningdatadog

Copy link
Copy Markdown
Contributor Author

Circular import analysis

🚨 New circular imports detected 🚨

1 new circular import(s) have been introduced by this PR:

ddtrace._trace._span_pointer -> ddtrace._trace.telemetry -> ddtrace.internal.telemetry -> ddtrace.internal.telemetry.writer -> ddtrace.internal.runtime -> ddtrace.contrib._events.web_framework -> ddtrace._trace.events -> ddtrace._trace.provider -> ddtrace._trace.span -> ddtrace._trace._span_pointer

Please consider refactoring your changes in accordance to the Separation of Concerns principle.

⚠️ Existing circular imports

There are 3 circular imports that already exist on the base branch and have not been changed by this PR.

ddtrace.llmobs -> ddtrace.llmobs._evaluators -> ddtrace.llmobs._evaluators.format -> ddtrace.llmobs._experiment -> ddtrace.llmobs
ddtrace.errortracking._handled_exceptions.bytecode_injector -> ddtrace.errortracking._handled_exceptions.callbacks -> ddtrace.errortracking._handled_exceptions.collector -> ddtrace.errortracking._handled_exceptions.bytecode_reporting -> ddtrace.errortracking._handled_exceptions.bytecode_injector
ddtrace.appsec._asm_request_context -> ddtrace.appsec._iast._iast_request_context_base -> ddtrace.appsec._iast._iast_env -> ddtrace.appsec._iast.reporter -> ddtrace.appsec._exploit_prevention.stack_traces -> ddtrace.appsec._asm_request_context

@cit-pr-commenter-54b7da This has been fixed in upstream PR

@litianningdatadog
litianningdatadog force-pushed the tianning.li/4-1-flask-microvm-run-hook-activation branch from 7595e97 to 203ca67 Compare August 24, 2026 14:24
@litianningdatadog
litianningdatadog force-pushed the tianning.li/2-flask-web-request-starting-event branch from 8dd7e8e to d4c1810 Compare August 24, 2026 14:56
@litianningdatadog
litianningdatadog force-pushed the tianning.li/4-1-flask-microvm-run-hook-activation branch from 203ca67 to dc34f17 Compare August 24, 2026 15:03
@litianningdatadog
litianningdatadog force-pushed the tianning.li/2-flask-web-request-starting-event branch from d4c1810 to 12b6c50 Compare August 24, 2026 15:31
@litianningdatadog
litianningdatadog force-pushed the tianning.li/4-1-flask-microvm-run-hook-activation branch 2 times, most recently from dce366c to 46e2121 Compare August 24, 2026 15:41
@litianningdatadog
litianningdatadog force-pushed the tianning.li/2-flask-web-request-starting-event branch from 12b6c50 to 0fa6836 Compare August 24, 2026 16:01
@litianningdatadog
litianningdatadog force-pushed the tianning.li/4-1-flask-microvm-run-hook-activation branch from 46e2121 to c1ffc6d Compare August 24, 2026 16:04
@litianningdatadog
litianningdatadog force-pushed the tianning.li/2-flask-web-request-starting-event branch from 0fa6836 to cde3045 Compare August 24, 2026 17:19
@litianningdatadog
litianningdatadog force-pushed the tianning.li/4-1-flask-microvm-run-hook-activation branch 3 times, most recently from c81ebfb to f2de1fd Compare August 24, 2026 18:20
@litianningdatadog
litianningdatadog marked this pull request as ready for review August 24, 2026 18:24
@litianningdatadog
litianningdatadog requested a review from a team as a code owner August 24, 2026 18:24
@litianningdatadog
litianningdatadog requested a review from a team as a code owner August 24, 2026 18:24
@litianningdatadog
litianningdatadog requested review from RamyElkest, brettlangdon, quinna-h and rachelyangdog and removed request for a team August 24, 2026 18:24

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f2de1fd207

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread ddtrace/internal/runtime/__init__.py Outdated
Comment thread ddtrace/internal/runtime/__init__.py Outdated
Comment thread ddtrace/internal/runtime/__init__.py
Comment thread ddtrace/internal/runtime/__init__.py
Comment thread ddtrace/internal/runtime/__init__.py Outdated
@litianningdatadog
litianningdatadog marked this pull request as draft August 24, 2026 19:38
@litianningdatadog
litianningdatadog force-pushed the tianning.li/4-1-flask-microvm-run-hook-activation branch from f2de1fd to 35ab0c3 Compare August 24, 2026 23:09
@litianningdatadog
litianningdatadog force-pushed the tianning.li/2-flask-web-request-starting-event branch from cde3045 to a0e3c42 Compare August 24, 2026 23:56
@litianningdatadog
litianningdatadog force-pushed the tianning.li/4-1-flask-microvm-run-hook-activation branch from 35ab0c3 to d67a43d Compare August 24, 2026 23:58

@emmettbutler emmettbutler left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Converted to draft because the base is not main. Please mark as ready once the diff is ready to merge into main.

@litianningdatadog litianningdatadog removed the aws-microvm Work related to AWS MicroVM onboarding label Sep 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants