Mirrord – mirror production traffic to your development environment
github.com
github.com
Sampling is another useful tool but I don't see any sampling in the API for this. If you do sample though you could end up with inconsistent or divergent state if you just sampled a flat % of traffic, so in some contexts it makes sense for sampling to be determined per-user/tenant/etc. rather than per-request.
This is pod based so you could easily slice by pod. If you have a pod with a lot less traffic, more impactful traffic, or that is harder to debug (example: pod that periodically aggregates and exports metrics but you believe it's dropping data sometimes) you could just enroll that and have some kind of dev shard of a portion of the stack.
I could also see this being very useful if you believe it to be too big a liability to record actual user requests (or implement something special to scrub out sensitive stuff) or let devs peek too close. You have a way of investigating some classes of issues without necessarily looking at sensitive data or requiring extensive back and forth in a support case.
I can't tell if this is brilliant or insane. Brilliant in that I see the potential of catching bugs. Insane in that you'd need to be really really really sure that the environment the requests are diverted to can't change production data. Including sending out e-mails or other communciations.
Would mirrord actually work with podman? It would be pretty neat to setup something akin to a canary deployment
> mirrord lets you easily mirror traffic from your Kubernetes cluster to your development environment.
That said, cool application, although I can see a lot of compliance and/or data protection problems when production data is leaving the (hopefully protected) production environment.
This involves more than just standard web access logs, since you also need to capture any POST bodies too in order to be able to replay them later against a test environment.
I wrote more about this here: https://simonwillison.net/2021/Apr/12/porting-vaccinateca-to...
Example: if names/emails are in use
To be honest, while I imagine there are times when access to prod traffic might be useful, I suspect even having a tool like this would be an instant ISO27001 or ISO27002 audit fail.
If your approach to security is "I really hope this machine doesn't get compromised" then you're not doing a good enough job.
Also, as bmm6o says, keeping prod data in your secure, pentested prod environment avoids the problem in the first place.