Skip to content

fix[installer](opensearch): set index.max_shards=30000 on v11-log ind… - #2758

Merged
osmontero merged 2 commits into
v11from
backlog/v11_opensearch_log_explorer_max_shards
Sep 25, 2026
Merged

osmontero merged 2 commits into
v11from
backlog/v11_opensearch_log_explorer_max_shards

Conversation

@AlexSanchez-bit

Copy link
Copy Markdown
Contributor

No description provided.

@AlexSanchez-bit
AlexSanchez-bit requested a review from a team September 25, 2026 17:13
@github-actions

Copy link
Copy Markdown

❌ Go dependencies check failed

There are outdated Go dependencies, or modules that could not be inspected.
Run bash .github/scripts/go-deps.sh --update --discover locally and
commit the updated go.mod / go.sum files.

Script output
🔍 Discovered 25 Go projects

📦 Dependencies with updates available:

  📁 ./utmstack-collector:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/gcp:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/aws:
     - github.com/aws/aws-sdk-go-v2: v1.47.0 → v1.47.1
     - github.com/aws/aws-sdk-go-v2/config: v1.33.5 → v1.33.6
     - github.com/aws/aws-sdk-go-v2/credentials: v1.20.5 → v1.20.6
     - github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs: v1.88.0 → v1.88.1
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/events:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/inputs:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/stats:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/rule-flood-guard:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/o365:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/modules-config:
     - github.com/aws/aws-sdk-go-v2/config: v1.33.5 → v1.33.6
     - github.com/aws/aws-sdk-go-v2/credentials: v1.20.5 → v1.20.6
     - github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs: v1.88.0 → v1.88.1
     - github.com/aws/aws-sdk-go-v2/service/sts: v1.51.0 → v1.51.1
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/config:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/soc-ai:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/sophos:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/azure:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/crowdstrike:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/bitdefender:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/geolocation:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./agent-manager:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./agent:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./as400:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./as400/updater:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

�[0;31m❌ Please update dependencies before merging.�[0m

@github-actions

Copy link
Copy Markdown

🛑 AI review — Engineer review required

This PR touches critical paths or introduces changes the model cannot judge with sufficient confidence. @Kbayero @osmontero please review.

🛑 architecture (silas-1.7-pro) — blocking — must fix before merge

Summary: Installer upgrade path and OpenSearch index settings/template changes introduce critical-path deployment and compatibility risk.

  • high installer/setup/apply.go:257 — Installer code adds a new upgrade mutation path controlled by a hard-coded lock. This touches the release/upgrade flow and requires Tier 3 review for idempotence, failure recovery, and compatibility with existing deployments.
  • medium installer/services/search.go:81 — UpdateOpenSearch changes OpenSearch index settings and creates an index template during updates. Ensure this is safe for existing indices, backwards-compatible, and does not force destructive or non-rolling schema-like changes.

🛑 bugs (silas-1.7-pro) — blocking — must fix before merge

Summary: Fresh installs no longer set index.mapping.total_fields.limit for alert/UTM indexes because the new template only covers v11-log-* max_shards.

  • high installer/services/search.go:66 — InitOpenSearch replaces the previous PUT settings that applied index.mapping.total_fields.limit=50000 to v11-alert-, v11-log-, .utm-, and .utmstack- with a composable index template that only applies index.max_shards=30000 to v11-log-. On a fresh install, v11-alert-/.utm-/.utmstack- indexes can be created without the required mapping limit and may fail when the mapping exceeds the default limit. Add the total_fields.limit setting to the template or restore a separate settings update for all affected index patterns.

🛑 security (silas-1.7-pro) — blocking — must fix before merge

Summary: No new vulnerabilities identified; changes touch installer path, so Tier 3 for human verification.

No findings.

@utmstackprapprover utmstackprapprover Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes requested — Go dependencies check failed (see above).

@osmontero
osmontero merged commit 6d687d5 into v11 Sep 25, 2026
5 of 7 checks passed
@osmontero
osmontero deleted the backlog/v11_opensearch_log_explorer_max_shards branch September 25, 2026 17:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants