Skip to content

feat: enforce ClickHouse resource limits on endpoint queries - #4052

Draft
djwhitt wants to merge 5 commits into
mainfrom
feat/enforced-clickhouse-endpoint-settings
Draft

djwhitt wants to merge 5 commits into
mainfrom
feat/enforced-clickhouse-endpoint-settings

Conversation

@djwhitt

@djwhitt djwhitt commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Persist endpoint-owned ClickHouse resource limits separately from caller SQL settings. Apply them to the final default or sandboxed query and reject conflicting caller settings.
  • Add an admin-only section to the endpoint edit UI for setting or clearing byte, row, memory, and execution-time limits. Admins can open a customer endpoint by ID to configure limits while its ordinary fields remain read-only; normal users cannot see the controls or forge saves.
  • Validate positive numeric limits, force read-overflow failure, invalidate endpoint caches on changes, and retain the existing caller SQL allowlist.

User.admin is assigned out of band. The server reloads the persisted flag for every protected settings save. The internal Logflare.Endpoints.configure_enforced_clickhouse_settings/3 function remains available; neither the customer endpoint API nor ordinary endpoint changesets accept this field. ClickHouse query-user profile constraints remain the stronger choice for cluster-wide ceilings.

Validation

  • ../bin/test test/logflare_web/live_views/endpoints_live_test.exs test/logflare/endpoints/clickhouse_settings_test.exs test/logflare/endpoints_test.exs — 136 tests, 0 failures (3 excluded)
  • MIX_ENV=test ../bin/format --check-formatted
  • MIX_ENV=test ../bin/x mix lint.all
  • MIX_ENV=test ../bin/x mix test.structure
  • MIX_ENV=test ../bin/x mix test.slop

Linear: O11Y-2220

@djwhitt
djwhitt force-pushed the feat/enforced-clickhouse-endpoint-settings branch from d6311e6 to 37310b1 Compare October 8, 2026 19:00
@djwhitt
djwhitt added this pull request to stack #4121 October 8, 2026 19:04

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant