Skip to content

Conversation

@anik120
Copy link
Contributor

@anik120 anik120 commented Mar 7, 2025

Description

Reviewer Checklist

  • API Go Documentation
  • Tests: Unit Tests (and E2E Tests, if appropriate)
  • Comprehensive Commit Messages
  • Links to related GitHub Issue(s)

@anik120 anik120 requested a review from a team as a code owner March 7, 2025 21:31
@netlify
Copy link

netlify bot commented Mar 7, 2025

Deploy Preview for olmv1 ready!

Name Link
🔨 Latest commit a05376e
🔍 Latest deploy log https://app.netlify.com/sites/olmv1/deploys/67cb65a75e698c00081d41a2
😎 Deploy Preview https://deploy-preview-1855--olmv1.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site configuration.

args:
- --leader-elect
- --metrics-bind-address=:7443
- --pprof-bind-address=:6060
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This feature is handy for testing and debugging, but I’m wondering if it should be enabled by default. I have concerns about performance impact and security risks. That’s why we added a warning in Kubebuilder’s docs.

I think it's fine to enable pprof in production when needed, do the profiling, and then disable it. My concern is leaving it enabled indefinitely. That seems to be the general approach others take as well (enable/disable), see: Google Groups discussion.

⚠️ Some references highlight security risks:

Also, I found this issue: golang/go#65208

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

But let's also see what the other thinks @tmshort @joelanford, what are your thoughts?
Are you OK with?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That's super helpful information @camilamacedo86. We'd already discussed this on slack and I decided to close the PR, but this detailed information is really helpful, so thank you!

@anik120
Copy link
Contributor Author

anik120 commented Mar 10, 2025

TIL it's not best practice to have pprof enabled indefinitely.

@anik120 anik120 closed this Mar 10, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants