Skip to content

Configure OpenTelemetry - #563

Draft
rob93c wants to merge 10 commits into
mainfrom
configure-opentelemetry
Draft

rob93c wants to merge 10 commits into
mainfrom
configure-opentelemetry

Conversation

@rob93c

@rob93c rob93c commented Sep 26, 2026 •

Copy link
Copy Markdown
Member

Summary by CodeRabbit

  • Improvements
    • Application activity can now be traced across bot responses, file downloads, media checks and conversions, and command execution. Trace details include media types and executed commands.
    • OpenTelemetry tracing is configured in the standard runtime with the SDK disabled. Railway deployments configure the SDK as enabled.

@rob93c rob93c self-assigned this Sep 26, 2026
@rob93c rob93c added enhancement New feature or request docker This marks issues revolving around Docker labels Sep 26, 2026
@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: b0b22408-5505-4f69-8ca3-a54f24bd3704

📥 Commits

Reviewing files that changed from the base of the PR and between 0733f0e and 595c8ed.

📒 Files selected for processing (1)
  • Dockerfile

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The application adds named OpenTelemetry spans to bot, media and process methods. The Docker runtime downloads and loads the OpenTelemetry Java agent. Railway sets OTEL_SDK_DISABLED=false, and the generated JRE module list includes java.management.

Changes

OpenTelemetry tracing

Layer / File(s) Summary
Add annotated spans
gradle/libs.versions.toml, build.gradle.kts, src/main/java/com/github/stickerifier/stickerify/bot/Stickerify.java, src/main/java/com/github/stickerifier/stickerify/media/MediaHelper.java, src/main/java/com/github/stickerifier/stickerify/process/ProcessHelper.java
Adds the OpenTelemetry instrumentation annotations dependency. Annotates bot methods with bot.answer, bot.answer_file, bot.download_file and bot.answer_text; media methods with conversion and compliance-check span names; and executeCommand with process.execute. The media.convert span records mimeType as an attribute, and executeCommand records command as an attribute.
Configure agent in container builds
Dockerfile, Railway.dockerfile, build.gradle.kts
The Docker runtime downloads and loads the OpenTelemetry Java agent and sets OTEL_SDK_DISABLED=true. Railway sets OTEL_SDK_DISABLED=false. The generated JRE module list includes java.management.

Priority: ⬇️ Low

Merge Risk: ⚪ Minimal · up to 595c8

The OpenTelemetry container configuration is mergeable with no known current-head risk requiring resolution.

Security Architecture Review

Security architecture risk: 🟡 Moderate · up to 595c8

Railway now enables tracing of bot and media activity, but the available configuration does not establish where traces are sent or how sensitive request details are excluded. No credential disclosure has been verified.

Retained concerns

  • Medium · security · inferred: Railway enables traces across bot and media processing without a repository-defined trace destination or sensitive-attribute policy. Credential exposure through automatically instrumented Telegram requests remains a possibility, not a verified leak.
Security review details

Security Blast Radius

  • inferred — Enabling the agent in Railway potentially extends telemetry beyond explicit application spans to instrumented client operations. Its effective reach cannot be bounded without the agent behavior and deployed configuration.

Security Findings and Attack Paths

  • inferred — If automatic HTTP spans retain token-bearing Telegram URLs and traces reach a collector, access to those traces could expose the bot credential. Neither URL capture nor trace delivery was verified; the explicitly annotated bot methods do not attach the token.

Trust Boundaries and Controls

  • observed — The base image's disabled SDK and disabled metrics and logs exporters constrain telemetry there; Railway explicitly enables the SDK. Repository configuration does not establish an equivalent trace-data destination or redaction control.

Hardening Proposals

  • proposed — Verify the effective Railway trace destination and the agent's handling of Telegram request URLs, then set explicit exporter and sensitive-attribute controls appropriate to that destination.
  • proposed — Consider verifying the downloaded agent artifact against a trusted digest before loading it into the application process.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 50.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 14 functions across 4 files. (1 skipped: … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: configuring OpenTelemetry across the application and runtime images.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 50.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 14 functions across 4 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1


ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: 477d969a-d34f-47b9-a437-f8e0906cfc7f

📥 Commits

Reviewing files that changed from the base of the PR and between c202851 and 7ec8b2b.

📒 Files selected for processing (7)
  • Dockerfile
  • Railway.dockerfile
  • build.gradle.kts
  • gradle/libs.versions.toml
  • src/main/java/com/github/stickerifier/stickerify/bot/Stickerify.java
  • src/main/java/com/github/stickerifier/stickerify/media/MediaHelper.java
  • src/main/java/com/github/stickerifier/stickerify/process/ProcessHelper.java

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

Comment thread Railway.dockerfile Outdated
@railway-app
railway-app Bot temporarily deployed to Stickerify / test September 26, 2026 11:02 Inactive
@railway-app
railway-app Bot temporarily deployed to Stickerify / test September 26, 2026 15:07 Inactive

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1


ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: f05cd4bb-e5ef-4175-9321-d0c8172a0f45

📥 Commits

Reviewing files that changed from the base of the PR and between 7ec8b2b and acfbaf8.

📒 Files selected for processing (3)
  • Dockerfile
  • Railway.dockerfile
  • src/main/java/com/github/stickerifier/stickerify/media/MediaHelper.java

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

Comment thread src/main/java/com/github/stickerifier/stickerify/media/MediaHelper.java Outdated
@rob93c
rob93c force-pushed the configure-opentelemetry branch from acfbaf8 to 96a9b79 Compare September 26, 2026 15:17
@railway-app
railway-app Bot temporarily deployed to Stickerify / test September 26, 2026 15:17 Inactive
@rob93c
rob93c force-pushed the configure-opentelemetry branch from 96a9b79 to 76f6da5 Compare September 26, 2026 15:24
@railway-app
railway-app Bot temporarily deployed to Stickerify / test September 26, 2026 15:24 Inactive
@railway-app
railway-app Bot temporarily deployed to Stickerify / test September 26, 2026 15:53 Inactive
@rob93c
rob93c force-pushed the configure-opentelemetry branch from d960a95 to c47370a Compare September 26, 2026 16:00
@railway-app
railway-app Bot temporarily deployed to Stickerify / test September 26, 2026 16:00 Inactive
@rob93c
rob93c force-pushed the configure-opentelemetry branch from c47370a to f1d5ea4 Compare September 26, 2026 16:08
@railway-app
railway-app Bot temporarily deployed to Stickerify / test September 26, 2026 16:08 Inactive
@rob93c
rob93c force-pushed the configure-opentelemetry branch from f1d5ea4 to 0bb33a6 Compare September 26, 2026 16:13
@railway-app
railway-app Bot temporarily deployed to Stickerify / test September 26, 2026 16:13 Inactive
@rob93c
rob93c force-pushed the configure-opentelemetry branch from 0bb33a6 to bd590e9 Compare September 26, 2026 16:18
@railway-app
railway-app Bot temporarily deployed to Stickerify / test September 26, 2026 16:18 Inactive
@rob93c
rob93c force-pushed the configure-opentelemetry branch from bd590e9 to a105660 Compare September 26, 2026 16:21
@railway-app
railway-app Bot temporarily deployed to Stickerify / test September 26, 2026 16:21 Inactive
@rob93c
rob93c force-pushed the configure-opentelemetry branch from a105660 to dc6cdb1 Compare September 26, 2026 16:23
@railway-app
railway-app Bot temporarily deployed to Stickerify / test September 26, 2026 16:23 Inactive
@rob93c
rob93c force-pushed the configure-opentelemetry branch from dc6cdb1 to 6591499 Compare September 26, 2026 16:27
@railway-app
railway-app Bot temporarily deployed to Stickerify / test September 26, 2026 16:27 Inactive
@rob93c
rob93c force-pushed the configure-opentelemetry branch from 6591499 to 933ab01 Compare September 26, 2026 16:28
@railway-app
railway-app Bot temporarily deployed to Stickerify / test September 26, 2026 16:28 Inactive
@rob93c
rob93c force-pushed the configure-opentelemetry branch from 933ab01 to ced7b6d Compare September 26, 2026 16:30
@railway-app
railway-app Bot temporarily deployed to Stickerify / test September 26, 2026 16:30 Inactive
@rob93c
rob93c force-pushed the configure-opentelemetry branch from ced7b6d to 837f445 Compare September 26, 2026 16:32
@railway-app
railway-app Bot temporarily deployed to Stickerify / test September 26, 2026 16:32 Inactive
@rob93c
rob93c force-pushed the configure-opentelemetry branch from 837f445 to 6139733 Compare September 26, 2026 16:34
@railway-app
railway-app Bot temporarily deployed to Stickerify / test September 26, 2026 16:34 Inactive
@rob93c
rob93c force-pushed the configure-opentelemetry branch from 6139733 to 9f32ebf Compare September 26, 2026 16:48
@railway-app
railway-app Bot temporarily deployed to Stickerify / test September 26, 2026 16:48 Inactive

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1


ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: 4668305c-a8ce-4f1d-b6ab-428756ba7f60

📥 Commits

Reviewing files that changed from the base of the PR and between acfbaf8 and 9f32ebf.

📒 Files selected for processing (6)
  • Dockerfile
  • Railway.dockerfile
  • gradle/libs.versions.toml
  • src/main/java/com/github/stickerifier/stickerify/bot/Stickerify.java
  • src/main/java/com/github/stickerifier/stickerify/media/MediaHelper.java
  • src/main/java/com/github/stickerifier/stickerify/process/ProcessHelper.java

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

Comment thread Dockerfile Outdated
@railway-app
railway-app Bot temporarily deployed to Stickerify / test September 26, 2026 18:10 Inactive
@railway-app
railway-app Bot temporarily deployed to Stickerify / test September 26, 2026 18:24 Inactive
@rob93c
rob93c force-pushed the configure-opentelemetry branch from dbab188 to 0733f0e Compare September 26, 2026 19:59
@railway-app
railway-app Bot temporarily deployed to Stickerify / test September 26, 2026 19:59 Inactive
@railway-app
railway-app Bot temporarily deployed to Stickerify / test September 26, 2026 20:20 Inactive
@rob93c
rob93c force-pushed the configure-opentelemetry branch from 4529c95 to 595c8ed Compare September 27, 2026 08:29
@railway-app
railway-app Bot temporarily deployed to Stickerify / test September 27, 2026 08:29 Inactive

This branch was previously deployed

1 inactive deployment
Stickerify / test — 595c8ed8 Deployed Sep 27, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

docker This marks issues revolving around Docker enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant