Skip to content

fix: turn hyperdx usage stats off by default - #188

Merged
catinspace-au merged 1 commit into
mainfrom
fix/query-reader-auth
Sep 29, 2026
Merged

catinspace-au merged 1 commit into
mainfrom
fix/query-reader-auth

Conversation

@catinspace-au

Copy link
Copy Markdown
Contributor

Every HyperDX API start on a Compose stack with an existing team logs two ClickHouse auth failures as dfe_query_reader. It is not a stale or rotated password. The stored connection logs in fine (HTTP 200).

The cause is upstream's usage-stats task (packages/api/src/tasks/usageStats.ts). It reads connections with Connection.find(), the model marks password select: false, so it queries system.parts with no password and gets a 516 once per (connection, database) pair -- two for the admin team (dfe and system). Upstream main still has the same code. The task also sends user counts and host details to in-otel.hyperdx.io every 4h.

The k8s hyperdx chart already defaults USAGE_STATS_ENABLED to false. Compose never set it, so it ran upstream's default of on. This sets it from DFE_HYPERDX_USAGE_STATS_ENABLED, default false.

Checked on a local rc.14 stack (hyperdx v0.2.7):

  • hyperdx recreated on the old compose: two 516s at API start, CH text_log shows them from the hyperdx container's IP
  • recreated on this branch: none, and USAGE_STATS_ENABLED=false in the container
  • make post after the change: 6/8 claims PASS, 2 skipped by profile, same as before

One more edit belongs with this and could not go in: env.example/hyperdx.env still says # USAGE_STATS_ENABLED=false. The compose environment entry now beats that file, so the line should point at DFE_HYPERDX_USAGE_STATS_ENABLED in .env instead. Our tooling blocks agents from staging that path as a credential file, so it needs a human commit.

Upstream HyperDX's usage-stats task runs on every API start and every 4h. It reads each connection with Connection.find(), which leaves out the password (the model marks it select: false), so it logs in to ClickHouse as the team's reader with no password and fails with a 516 twice per start. It also reports user counts and host details to in-otel.hyperdx.io, a third party.

The Kubernetes hyperdx chart already sets USAGE_STATS_ENABLED=false unless a deployer opts in. Compose left it at upstream's default of on. It now matches the chart, with DFE_HYPERDX_USAGE_STATS_ENABLED=true as the opt-in.
@catinspace-au
catinspace-au merged commit 879a4ec into main Sep 29, 2026
7 checks passed
@catinspace-au
catinspace-au deleted the fix/query-reader-auth branch September 29, 2026 12:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant