Skip to content

GKE Autopilot allowlist onboarding #3083

@dashpole

Description

@dashpole

Grafana Beyla, which has been donated to OTel as https://opentelemetry.io/docs/zero-code/obi/, is allowlisted by GKE autopilot to be able to use elevated permissions on autopilot, which are required for it to work.

Maintainers of OBI (@open-telemetry/ebpf-instrumentation-maintainers ) reached out to me, and are interested in allowing OBI to work in a similar way.

Autopilot has a partner program, which allows partners to allowlist their workloads, and manage the permissions needed for them to work on autopilot. Onboarding requires a GCP project (for testing changes to the allowlist), and a google group to manage access.

There are a few questions before we initiate the process:

  • Can @open-telemetry/ebpf-instrumentation-maintainers confirm that they are interested in owning this as a SIG?
  • Scope: IMO we should onboard as "OpenTelemetry", rather than "OpenTelemetry-eBPF-Instrumentation" in-case other workloads would like to integrate in the future.
  • Are there other SIGs that should be involved, or be shared owners?

Disclaimer: I work for Google, and previously worked on GKE.

This is a completely optional integration, and is entirely up to the community to decide if they want to pursue it. If we are not interested, I can reach out to the Googlers that initially introduced support for Beyla to see if they are willing to add similar support for OBI.

cc @svrnm

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/project-infraNon-GitHub project infra (DockerHub, etc.)

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions