Repository navigation
[NETPATH-1182] Add Network Path metadata to the CNM connection payload - #527
Draft
tonytran-dd wants to merge 1 commit into
Draft
tonytran-dd wants to merge 1 commit into
tonytran-dd wants to merge 1 commit into
Conversation
Adds a nested NetworkPath message on Connection at field 65, carrying:
- hasTest: policy approved a dynamic Network Path test for this connection
- correlationKey: identity of that test, matching correlation_key on the
Network Path event
The nested message is a pointer in the generated Go, so absent (nil) stays
distinguishable from present-but-false (empty message). That three-state
encoding is what lets consumers tell "never evaluated" apart from
"evaluated, policy said no".
Regenerated with Go 1.24.0 to match go.mod.
NETPATH-1182
tonytran-dd
force-pushed
the
tony/netpath-1182-correlation-key
branch
from
October 5, 2026 15:53
7e2ca1b to
6ed7c04
Compare
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The PR remains a draft pending human validation of the implementation plan and coordinated downstream rollout.
Review effort: Balanced
Findings: None
What changed in this PR
Adds Network Path metadata to CNM connections, enabling downstream consumers to distinguish evaluation states and correlate flows with Network Path events.
Changes:
- Adds field 65 with test eligibility and a correlation key.
- Preserves absent versus present-empty metadata.
- Regenerates Go message bindings and streaming builders.
| File | Description |
|---|---|
| proto/process/connections.proto | Defines Network Path metadata and advances the field marker. |
| process/connections.proto_builder.go | Adds builders for the new metadata. |
| process/connections.pb.go | Adds generated types, descriptors, and serialization support. |
Files not reviewed (1)
- process/connections.pb.go: Generated file
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The PR explicitly remains a not-for-merge draft pending human sign-off on the cross-service contract and coordinated rollout.
Review effort: Balanced
Findings: None
Files not reviewed (1)
- process/connections.pb.go: Generated file
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Draft for the CNM ⇒ Network Path Pivot RFC. Not for merge yet.
What
Nested
NetworkPathmessage onConnectionat field 65 (was free;next identifierbumped 65 → 66).First step of NETPATH-949.
Why nested
Generated as a pointer, so three states survive the wire:
nilA flat
boolcollapses the first two.Verification
Built #57114 against this branch and ran the Agent locally, via the QA steps below. 20 real connections carried the field: 10 with
testEligible: trueplus a 32-hex key, 10 withnetworkPath: {}.Three destinations produced byte-identical keys in a run a day earlier against a different system-probe, which is what the empty-nested-message and populated-message cases above look like in practice.
A locally built Agent also posts the payload for real and its flows appear in the CNM UI, so field 65 survives a live intake round trip, not only the decoder test above.
Regenerated with
inv codegen.allunder Go 1.24.0 to matchgo.mod.QA
Follows the team's Agent Development Setup. Three terminals, all in
datadog-agent.Leave the socket paths in
dev/distalone. They point inside the checkout on purpose, so your build does not pick up the IT-installed Agent's config.Expect
testEligible: trueplus a 32-hex key on outbound TCP,np: {}on incoming and multicast, the same key for every connection to the same destination. Rerun step 7; keys must not change.Order
logs-backend → dd-go CNM → dd-go NPP → datadog-agent → web-ui