Completed work

opnsense2otel

109 completed tasks.

OPN-0108Update both testbed firewalls to their channel head on every canary sessionhighcanarytestbedOPN-0112Comment on the canary issues only when the findings changelowcanaryciOPN-0111Narrow the support policy to the current stable OPNsense releasemediumdocscanaryOPN-0107Stamp the OPNsense generation on both testbed canary reportshighcanarytestbedciOPN-0106Retire the production-firewall schema canaryhighcanarytestbedchoreOPN-0105Diversify Grafana dashboard visualizationsUnspecifiedOPN-0102Skip the GeoIP startup fetch when the installed database is freshmediumOPN-0103Console quiet mode when self-logs ship over OTLPhighOPN-0057Measure UDP receiver throughput: same-harness before/after for buffers and worker poollowM5 - Pipeline & dashboard polishneeds-triageOPN-0101Syslog UDP receiver refuses to start on FreeBSD when the requested receive buffer exceeds the kernel limithighbugsyslogfreebsdOPN-0097Bound config revision diff input before redaction to cap transient allocationlowenhancementsecurityOPN-0099Document and harness the Loki visibility delay for historical config revision eventsmediumdocstestbedOPN-0021HAProxy maintenance-state visibility (api/haproxy/maintenance/searchServer)lowM4 - New collectorsOPN-0100Define a Content-Security-Policy for the embedded consolelowwebuisecurityOPN-0033Metric naming: breaking rename of _total gauges and wireguard handshake timestamp at next majormediumM7 - Next majorOPN-0053Restyle the embedded console onto design system v2 (family follower)Unspecifieddesign-systemOPN-0060Prove live Loki and OTLP delivery end to end against the m7kni stackhighOPN-0096Triage the standing nightly and release-vm canary drift findings open since 2026-09-01mediumapi-driftcanaryOPN-0098Reclaim expired Zenarmor inventory entries before rejecting fresh sightingsmediumneeds-triageOPN-0095Firmware-status cache pins a transient empty last_check for the full TTLmediumbugexternal-reportOPN-0094Shared sensitive-key vocabulary is imprecise in both directionsmediumbugOPN-0092Config diff loses redaction state when the diff prefix changes mid-elementhighbugOPN-0093Credential nested inside a JSON string value is never field-scannedhighbugOPN-0086Emit configuration revision diffs in old-to-new orderhighneeds-triageOPN-0087Correct the UDP measurement guide after receiver observability shippedlowneeds-triageOPN-0088Recover DNS enrichment cache capacity from expired answershighneeds-triageOPN-0089Count tolerated ZeroTier per-network 404 fetch failuresmediumneeds-triageOPN-0090Preserve unresolved interface labels during NetFlow enrichment startupmediumneeds-triageOPN-0091Present console API counters as lifetime history rather than current auth healthmediumneeds-triageOPN-0085Preserve firewall snapshot delivery when search rows share a rule identityhighneeds-triageOPN-0084Serialize Release Please: no concurrency group on a workflow that publishesUnspecifiedbugOPN-0077Redact credential-bearing HTML URL attributes after backslasheshighneeds-triageOPN-0078Redact sensitive malformed-JSON fields after stray quoteshighneeds-triageOPN-0079Redact credential URLs in malformed JSON after stray quoteshighneeds-triageOPN-0080Resynchronise credential URL scanning after redacted overlapshighneeds-triageOPN-0081Redact credential URLs after malformed single-quoted HTMLhighneeds-triageOPN-0082Redact sensitive fields in malformed JSON-like syntaxhighneeds-triageOPN-0083Redact Unicode-escaped malformed JSON-like credential keyshighneeds-triageOPN-0062Stop NetFlow intake before the correlator final flushhighneeds-triageOPN-0071Preserve Zenarmor-first enrichment at the correlator caphighOPN-0072Drain in-flight Zenarmor bulk handlers before pipeline shutdownhighOPN-0073Make startup and shutdown self-log loss observablemediumOPN-0074Bound log pipeline source shutdown by its deadlinehighOPN-0075Correct false manual flow and Zenarmor runtime contractsmediumOPN-0076Close credential-vocabulary gaps in config and API-error redactionhighOPN-0070Live delivery proof miscategorises structured metadata as promoted labelsUnspecifiedbugOPN-0069Ship source poll errors to the log backend instead of stderr onlyUnspecifiedbugOPN-0063Preserve fractional flow-correlation window boundariesmediumneeds-triageOPN-0064Account for Zenarmor connections rejected at the capmediumneeds-triageOPN-0065Redact credential-bearing URLs from exporter self-logshighneeds-triageOPN-0066Persist device-inventory seen identities across restartmediumneeds-triageOPN-0067Correct console documentation to match the opt-in runtime defaulthighneeds-triageOPN-0068State pfTop retained-cardinality and address-label costs accuratelymediumneeds-triageOPN-0061Fix Grafana GitSync verifier after repository ownership movehighOPN-0030Security posture snapshot to LokimediumM2 - Loki config-data platformOPN-0059Prune pre-25.1 healthCheck legacy fields and their canary exemptionslowOPN-0022pfTop / top-talkers diagnostics collector, capped top-NmediumM4 - New collectorsOPN-0027Config revision diff events to Loki with dashboard annotationshighM1 - Bugs & first wavefirst-waveOPN-0028Config-state snapshots to Loki: per-entity JSON, opt-in per family, 6h heartbeathighM2 - Loki config-data platformOPN-0029Device inventory fusion: one record per device to LokimediumM2 - Loki config-data platformOPN-0031Gateway/routing change events (snapshot diff mode)lowM2 - Loki config-data platformOPN-0037Standing unparsed-syslog metric (logs_unparsed_total by subsystem)mediumM5 - Pipeline & dashboard polishOPN-0038DNS-domain enrichment for filterlog recordsmediumM5 - Pipeline & dashboard polishOPN-0049Ship the exporter's own logs through its OTLP logs pipeline (opt-in)mediumM2 - Loki config-data platformOPN-0041Config-file support via kingpin @file expansionlowM6 - Deployment & configOPN-0058Narrow auto-rc so only shipped-code commits cut a release candidatelowwave3OPN-0023Per-plugin service-status collectors for the agent-family pluginslowM4 - New collectorsOPN-0020IPsec per-lease collector (api/ipsec/leases/search)lowM4 - New collectorsOPN-0018ZeroTier plugin collector (network search/info)mediumM4 - New collectorsOPN-0017Complete FRR coverage: BGP route tables + BFD summarymediumM4 - New collectorsOPN-0019Firewall legacy-rule migration debt gauge (api/firewall/migration, 26.7)mediumM3 - 26.7 catch-upOPN-0016Gateway groups collector (api/routing/groupsettings, new in 26.7)mediumM3 - 26.7 catch-upOPN-0044Deep-link hot firewall rules to the OPNsense UI from dashboard tableslowM5 - Pipeline & dashboard polishOPN-0043Dashboard polish: cert-expiry colour thresholds + DHCP leases-nearing-expiry viewlowM5 - Pipeline & dashboard polishOPN-0042Gateway threshold-vs-actual dashboard panelmediumM5 - Pipeline & dashboard polishOPN-0015Kea DHCP reservation inventory counts for unclaimed reservations (both families)highM3 - 26.7 catch-upOPN-0014Unbound search_queries payload churn on 26.7: blocklist value rewritten, new category keylowM1 - Bugs & first waveOPN-0035Syslog UDP receiver: decouple read loop with a worker poolhighM1 - Bugs & first wavefirst-waveOPN-0039Expose NetFlow worker/queue sizing as flagslowM5 - Pipeline & dashboard polishOPN-0055Preserve stable Unbound blocklist identity across search-query response generationslowneeds-triageOPN-0056Correct `just gen` dependency order for new catalogue metricsmediumneeds-triageOPN-0025Document 26.7 ACL privilege merge impact on restricted API keyslowM3 - 26.7 catch-upOPN-0026Account for 26.7 NetFlow-service restart gaps in flow gap-detection/alertinglowM3 - 26.7 catch-upOPN-0054CodeQL initialization fails with repository Contents API 404highneeds-triageOPN-0007Kea reserved/dynamic lease split silently wrong on OPNsense 26.7 (upstream removed is_reserved)highM1 - Bugs & first wavebugfirst-waveOPN-0032Reserve fast-tier poll capacity in the schedulerhighM1 - Bugs & first wavefirst-waveOPN-0051Comment the deliberate is_enabled (not isBlockListEnabled) choice in the unbound clientlowM3 - 26.7 catch-upOPN-0036Set SO_RCVBUF on syslog and NetFlow UDP socketsmediumM5 - Pipeline & dashboard polishOPN-0034Surface gateway threshold parse failures (Warn + counter)mediumM5 - Pipeline & dashboard polishOPN-0024Verify monit status-XML parser against monit 6.0.0 (ships in OPNsense 26.7.3)mediumM3 - 26.7 catch-upOPN-0040Operator console: receivers/flow visibility tabmediumM5 - Pipeline & dashboard polishOPN-0045Helm chart ships default resources in values.yamlmediumM6 - Deployment & configOPN-0046Opt-in NetworkPolicy template in the Helm chart (all three receiver ports)mediumM6 - Deployment & configOPN-0047Raw k8s manifest gets the config-check initContainer the chart already haslowM6 - Deployment & configOPN-0048Troubleshooting docs for the push receivers (syslog/Zenarmor/NetFlow)highM5 - Pipeline & dashboard polishOPN-0050Pre-classify expected canary drift from 26.7 daemon bumps (Kea 3.0.4, Unbound 1.26, Suricata 8.0.6, dpinger 3.6)lowM3 - 26.7 catch-upOPN-0052Metric naming lint: reject non-monotonic _total gauges and unsuffixed timestamp metricsmediumM1 - Bugs & first waveOPN-0013interfaces link_type label drifts on OPNsense 26.7.2: IPv6 fallback removed, new link_typev6 fieldlowM1 - Bugs & first waveOPN-0012AGENTS.md mislabels internal/options/otlp.go as OTLP-tracing configlowM1 - Bugs & first waveOPN-0011deploy/k8s NetworkPolicy omits Zenarmor (9200/TCP) and NetFlow (2055/UDP) ingressmediumM1 - Bugs & first waveOPN-0010docs/flow.md flag table shows 10x-stale defaults for --flow.top-n and --flow.max-keyslowM1 - Bugs & first waveOPN-0009Secondary-fetch failures invisible: scrape_collector_success stays 1 and endpoint_errors_total never incrementshighM1 - Bugs & first wavebugfirst-waveOPN-0008hasync collector never emits remote_reachable=0 despite documented 0 statemediumM1 - Bugs & first waveOPN-0006Migrate the repo task surface to just and retire Makefiles and ad-hoc scriptsmediumwave:2-fleetOPN-0005Remediate 20 Codex Security findingshighsecurityOPN-0004Upgrade Go toolchain to 1.27UnspecifiedOPN-0001Rare data race in syslog Listener shutdown (Close vs the TLS accept goroutine)Unspecifiedbugarea:logshipflaky-ciOPN-0003Add Codex cloud manual environment setupUnspecifiedOPN-0002main is red: WAN address reintroduced into public fixtures, check-public-ips failing since 2026-08-08highbugsecurityarea:logshipneeds-triage