Skip to content

Distributor: add experimental OTLP metrics ingestion over gRPC - #7873

Open
friedrichg wants to merge 1 commit into
masterfrom
otlp-grpc-ingestion
Open

friedrichg wants to merge 1 commit into
masterfrom
otlp-grpc-ingestion

Conversation

@friedrichg

@friedrichg friedrichg commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

What this PR does:

Adds experimental OTLP metrics ingestion over gRPC to the distributor. The distributor serves the standard opentelemetry.proto.collector.metrics.v1.MetricsService/Export on the existing gRPC server port, so the OpenTelemetry Collector otlp exporter can push to Cortex. Enable it with -distributor.otlp.grpc-enabled (default false).

  • The tenant comes from the X-Scope-OrgID gRPC metadata. The request size is limited by -server.grpc-max-recv-msg-size-bytes.
  • The HTTP and gRPC receivers share one conversion function. The HTTP behavior does not change.
  • Distributor errors map to the gRPC codes that OTLP clients use to decide if they retry (429 and 5xx become UNAVAILABLE, 4xx becomes INVALID_ARGUMENT). When some metrics cannot be converted, the response is a partial success with an error message.
  • Fix: the Cortex proto gRPC codec is registered after the pdata codec and replaced it, so no OTLP gRPC request could be decoded. The Cortex codec now handles pdata messages.

Tested with unit tests (bufconn and the real pmetricotlp client) and the integration test TestOTLPGRPC.

AI disclosure: I wrote this feature with Claude Code. I reviewed every line and I can explain every change.

Which issue(s) this PR fixes:
Fixes #7872

Checklist

  • Tests updated
  • Documentation added
  • CHANGELOG.md updated - the order of entries should be [CHANGE], [FEATURE], [ENHANCEMENT], [BUGFIX]
  • docs/configuration/v1-guarantees.md updated if this PR introduces experimental flags

@friedrichg
friedrichg requested a review from a team as a code owner October 1, 2026 18:07
@friedrichg
friedrichg requested a review from SungJin1212 October 1, 2026 18:07
@friedrichg
friedrichg force-pushed the otlp-grpc-ingestion branch from 550f92f to 049a978 Compare October 1, 2026 18:08
Add the OTLP metrics gRPC service
(opentelemetry.proto.collector.metrics.v1.MetricsService/Export) to the
distributor gRPC server port, so the OpenTelemetry Collector otlp exporter
can push to Cortex. Enable it with -distributor.otlp.grpc-enabled.

The HTTP and gRPC receivers now share convertOTLPToWriteRequest. The gRPC
receiver maps distributor errors to the gRPC codes that OTLP clients use to
decide if they retry, and it returns a partial success when some metrics
cannot be converted.

The Cortex "proto" gRPC codec replaced the pdata codec, because it is
registered after it. The Cortex codec now encodes and decodes pdata
messages, so OTLP gRPC requests work with either init order.

Signed-off-by: Friedrich Gonzalez <1517449+friedrichg@users.noreply.github.com>
@friedrichg
friedrichg force-pushed the otlp-grpc-ingestion branch from 049a978 to fd39350 Compare October 1, 2026 18:38
Comment thread docs/api/_index.md
|---|---|---|
| Request deduplicated by the HA tracker | `OK` | No |
| Invalid request (HTTP 4xx) | `INVALID_ARGUMENT` | No |
| Missing or wrong tenant | `UNAUTHENTICATED` / `PERMISSION_DENIED` | No |

@SungJin1212 SungJin1212 Oct 2, 2026 •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current ServerUserHeaderInterceptor behavior emits UNKNOWN as ServerUserHeaderInterceptor before Export runs in the missing tenant case, so the client gets UNKNOWN, the same as for every other gRPC method.

I think we should change the interceptor in fakeauth.SetupAuthMiddleware to return codes.Unauthenticated for user.ErrNoOrgID, since this is the first gRPC API we expose to external clients.

Comment thread docs/api/_index.md
| Client canceled the request | `CANCELED` | No |
| Deadline exceeded | `DEADLINE_EXCEEDED` | Yes |

_Requires [authentication](#authentication)._

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The authentication link points to a section that describes the X-Scope-OrgID HTTP header, not gRPC metadata.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support OTLP/grpc ingestion

2 participants