Skip to content

align monitoring-user grants across CDB/PDB/RDS/ADB - #1445

Open
RamanaReddy8801 wants to merge 13 commits into
mainfrom
fix/oracle-otel-grant-alignment
Open

RamanaReddy8801 wants to merge 13 commits into
mainfrom
fix/oracle-otel-grant-alignment

Conversation

@RamanaReddy8801

@RamanaReddy8801 RamanaReddy8801 commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Aligns the Oracle, PostgreSQL, MySQL and MSSQL NRDOT recipes with New Relic's published OpenTelemetry database docs. It covers monitoring-user grants, collector config, the config presets, and multi-instance pipeline generation. A few grant and config additions go beyond the docs and were made on request; they are listed separately below.

Recipes are under recipes/newrelic/infrastructure/nrdot/{oracle,postgresql,mysql,mssql}-otel/.

All four databases

Presets renamed and reworked (Oracle, PostgreSQL, MySQL, MSSQL)

  • The NRDOT configuration prompt is now 1) Basic 2) Advanced. It was Database only / Host + Database on Oracle and Standard / Full-feature on the others.
  • The host-metrics pipeline is removed from all presets: hostmetrics, resource_detection, and the filter/transform processors. The presets now differ only in the metrics list:
    • Basic enables the essential metrics (30 on Oracle).
    • Advanced enables the full metric list (135 on Oracle).
  • collection_interval is now a fixed 15s in both presets. MSSQL Full-feature previously used 30s.
  • READMEs are updated to match. The MSSQL README also notes that the default of 200 applies to both presets.

Multi-instance pipelines consolidated (Oracle, PostgreSQL, MSSQL)

  • N instances used to generate N metrics/<x> and logs/<x> pipeline pairs. They now generate one metrics pipeline and one logs pipeline listing every instance's receiver, for example receivers: [nrpostgresql/db1, nrpostgresql/db2]. This matches the documented multi-receiver pattern.

Oracle

Grants, verified against the docs.newrelic.com host-cdb, host-pdb, rds and adb pages

  • V_$SQL_PLAN is replaced by V_$SQL_PLAN_STATISTICS_ALL in oci-linux (CDB and PDB paths) and the RDS recipes. The plain view lacks the execution statistics the receiver needs.
  • The oci-linux CDB path adds V_$PDBS and CDB_SERVICES, which the docs mark mandatory. It also adds the optional V_$ASM_DISKGROUP_STAT and V_$ASM_DISK_STAT.
  • The oci-linux PDB path adds CDB_SERVICES.

Grants beyond the docs, added on request

  • oci-linux CDB path: CDB_DATA_FILES, CDB_PROCEDURES and CDB_OBJECTS.
  • RDS recipes: V_$SQLSTATS is removed, and V_$PROCESS and V_$TRANSACTION are added.
  • ADB recipes: V_$PROCESS and V_$TRANSACTION are added. The rest already matched the docs.

Collector config

  • The resource/add_event_name processor is removed from all recipes and from both pipelines. The receiver already emits server.address and server.port.
  • The old receiver resource_attributes overrides are replaced by a single oracle.db.edition override.
  • db.server.top_procedure and db.server.query_plan events are added, along with a top_procedure_collection block (1000 samples, top 250, 60s).
  • ADB recipes switch the exporter from otlphttp to otlp (gRPC) and add the missing :4317 to OTLP_ENDPOINT.
  • The metrics list is restructured into Basic and Advanced sets. On RDS, the previously disabled v$sysmetric metrics are now enabled.

PostgreSQL

  • Generated config now includes service.telemetry.metrics.level: none, as in the docs.
  • db.system.version is added to resource_attributes. This was requested and is not in the docs.
  • Single-instance installs use unsuffixed names (nrpostgresql, metrics, logs), matching the hosted doc. Multi-instance installs keep the /dbN convention.
  • The resource/postgresql processor (the server.address and server.port upsert) is removed entirely.
  • Verified field by field against the documented Basic and Advanced configs for self-hosted and RDS/Aurora (including exclude_databases: [rdsadmin] on RDS). Receivers, metrics, processors and exporter already matched.

MySQL

Receiver (both presets)

  • collection_interval is 15s (was 10s) and top_query_collection.lookback_time is 60 (was 120).
  • The db.server.query_plan event and the db.system.version resource attribute are enabled.
  • allow_native_passwords: true is now also set on the RDS recipes.
  • The tls: block is removed. On RDS this also removes the CA-file plumbing: NR_CLI_MYSQL_TLS_CA_FILE, CA_FILE_LINE, and the head/tail heredoc split.
  • Basic enables mysql.query.count, mysql.query.slow.count, mysql.commands and mysql.innodb.data_file.io. Advanced enables the full metric list (70 metrics).

Collector config, Advanced only: now follows the documented advanced-config structure

  • Adds the health_check extension and an otlp receiver (grpc and http).
  • Processors are now batch, transform (truncates span and resource attributes to 4095 chars), and resource_detection, resource_detection/cloud and resource_detection/env.
  • The exporter gets a sending_queue (bytes-based batching).
  • Pipelines: metrics/mysql and logs/mysql carry the nrmysql data. New traces, metrics and logs pipelines take otlp input. With several instances the nrmysql pipelines are metrics/mysql-instanceN and logs/mysql-instanceN, and
    the otlp pipelines are still written once.
  • The per-instance resource/mysql processors (static server.address and server.port) are removed, so those attributes are no longer set on Advanced MySQL metrics.

Collector config, Basic: unchanged structure

  • Keeps batch plus the per-instance resource/mysql processors, so server.address and server.port are still set.
  • Keeps the plain metrics and logs pipelines (metrics/instanceN and logs/instanceN with several instances). No otlp receiver, no health_check, no traces pipeline.

nrdot-config-samples/mysql-otel is regenerated from the updated recipes.

MSSQL (all 8 recipes)

  • top_query_collection and query_sample_collection values are corrected (now 1000 samples and top 250). collect_full_query_text and allowed_comment_keys are moved to the correct nesting.
  • The db.server.query_plan and db.server.top_procedure events and a top_procedure_collection block are added.
  • A resource_attributes block is added with db.system.version and sqlserver.db.edition.
  • The per-instance resource/sqlserver processor and the batch processor are removed.
  • The exporter switches from otlphttp to otlp (gRPC, :4317), and a sending_queue block is added.
  • Single-instance installs use bare names (nrsqlserver, metrics, logs). The old Full-feature special case is gone, because the generic host passthrough pipelines it collided with are removed.

Known issues before merge

  • The Debian and RHEL PostgreSQL and MSSQL recipes (including RDS) still contain a TEMPORARY DIAGNOSTIC (remove before merge) block in restart_nrdot. Remove it before merging, or state here that it is intentional.

@Nandu-pns

Copy link
Copy Markdown
Contributor

Quick one on the MySQL RDS/Aurora recipes (rds-debian.yml, rds-rhel.yml) — the tls: insecure: false block and the NR_CLI_MYSQL_TLS_CA_FILE input got dropped along with the on-host TLS removal.

Checked the mysqlreceiver source directly: when tls: is absent, Config.Unmarshal() defaults to Insecure = true. That's a no-op for the on-host recipe (already the effective default there), but for RDS/Aurora specifically, the removed comment said this was "Required for Amazon RDS/Aurora with SSL/TLS enforcement." Without it we'd either connect unencrypted or fail outright if the instance enforces secure transport.

Is dropping TLS intentional for the RDS/Aurora variants too, or should insecure: false go back in just for those two files?

@Nandu-pns

Nandu-pns commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

On the preset consolidation — for Oracle specifically (oci-linux.yml, rds-debian.yml, rds-rhel.yml) the hostmetrics receiver is removed entirely along with the old "Host + Database" option, so anyone re-running this recipe on an existing Host+Database install would lose host metrics collection outright. (MSSQL/PostgreSQL don't have a hostmetrics receiver to begin with — what's removed there is just the resource_detection/cloud/env processors, so smaller blast radius, mostly resource-attribute enrichment.)

Is dropping host metrics from the Oracle presets an intentional, already-aligned scope decision? If so, all good — just want to make sure it's called out as a behavior change for existing installs rather than a quiet side effect of the preset cleanup.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants