headroom/tests/test_telemetry_warning.py
Tejas Chopra 53be64ca12
chore(telemetry): remove Supabase anonymous beacon; fix contact domain to headroomlabs.ai (#1526)
## Description

Removes the anonymous-telemetry **beacon** — the only external,
third-party data flow Headroom ever initiated. When telemetry was opted
in, it POSTed aggregate `/stats` to a hardcoded **Supabase** REST
endpoint (with an embedded anon API key in the source). For
enterprise/on-prem deployments this is exactly the kind of
vendor-controlled data egress a security review flags, so it's gone
entirely — **zero "Supabase" references remain in the codebase.**

What stays (by design): the **local** telemetry collector + the
`HEADROOM_TELEMETRY` opt-in (it only feeds `/stats` and `/v1/telemetry`
— nothing leaves the process), **OpenTelemetry export**
(`HEADROOM_OTEL_METRICS_*`, so operators send operational metrics to
*their own* collector), and the license usage reporter (your own domain,
license-key-gated).

Also fixes the contact domain: `headroom.dev` → `headroomlabs.ai`
everywhere.

Closes # (no tracking issue)

## Type of Change

- [x] Bug fix (non-breaking change that fixes an issue)
- [ ] New feature (non-breaking change that adds functionality)
- [ ] Breaking change (fix or feature that would cause existing
functionality to change)
- [ ] Documentation update
- [ ] Performance improvement
- [x] Code refactoring (no functional changes)

> Non-breaking: `HEADROOM_TELEMETRY` is still accepted (now gates local
collection only). The only behavior change is that no telemetry is ever
sent externally.

## Changes Made

- **Deleted the Supabase beacon**: `TelemetryBeacon` class,
`_SUPABASE_URL`/`_SUPABASE_KEY`/`_TABLE`/`_ENDPOINT`, the JSONB
projection helper, the proxy-lifespan beacon wiring, the `SUPABASE_`
install env passthrough, and `tests/test_strategy_stats_supabase.py`.
- **Kept** the local opt-in predicate (`is_telemetry_enabled` etc.) in
`beacon.py` — still used by the local collector + CLI — reworded to
"local only".
- **Retained** the single-worker-owner file lock (the cc-switch
reconciler depends on it); updated its comments to drop the beacon
framing.
- `/stats` `anon_telemetry_shipping` is now always `False` (nothing
ships externally); startup log reworded to "Local telemetry".
- Reworded remaining "Supabase" comments in `collector.py`,
`context.py`, `prometheus_metrics.py`, and two test docstrings.
- Contact domain: `security@headroom.dev` → `security@headroomlabs.ai`,
`conduct@headroom.dev` → `conduct@headroomlabs.ai`, FUNDING.yml sponsor
URL.

## Testing

- [x] Unit tests pass (`pytest`)
- [x] Linting passes (`ruff check`)
- [x] Type checking passes (`mypy`)
- [x] New tests added for new functionality
- [x] Manual testing performed

### Test Output

```text
$ grep -rniI "supabase" --include=*.py --include=*.md --include=*.mdx .   # (excl .venv/sbom)
>>> ZERO Supabase references

$ grep -rniI "headroom.dev" .
>>> ZERO headroom.dev references

$ ruff check <changed files>           -> All checks passed!
$ ruff format --check <changed files>  -> 10 files already formatted
$ mypy <changed telemetry files>       -> Success: no issues found

$ pytest tests/test_telemetry.py tests/test_telemetry_warning.py \
    tests/test_proxy_telemetry_env.py tests/test_compression_observability.py \
    tests/test_paths.py tests/test_paths_backward_compat.py -q
============================= 173 passed in 6.67s ==============================
```

## Real Behavior Proof

- **Environment:** macOS, Python 3.12 (`.venv`).
- **Exact command / steps:** repo-wide grep for
`supabase`/`headroom.dev`; `create_app(...)` driven through a full
`TestClient` lifespan (startup + shutdown) in
`test_proxy_telemetry_env.py`; `/stats` exercised in
`test_telemetry_warning.py`.
- **Observed result:** zero `supabase`/`headroom.dev` strings remain;
the proxy starts and shuts down cleanly with the beacon removed (the
worker-owner lock + reconciler still elect a single owner);
`/stats.anon_telemetry_shipping` is `False` even with
`HEADROOM_TELEMETRY=on`; local collector + OTEL paths unchanged.
- **Not tested:** no live network call was ever made (the point — the
external POST is gone). OTEL export and the license reporter were not
exercised (unchanged by this PR).

## Review Readiness

- [x] I have performed a self-review
- [x] This PR is ready for human review

## Checklist

- [x] My code follows the project's style guidelines
- [x] I have performed a self-review of my code
- [x] I have commented my code, particularly in hard-to-understand areas
- [ ] I have made corresponding changes to the documentation
- [x] My changes generate no new warnings
- [x] I have added tests that prove my fix is effective or that my
feature works
- [x] New and existing unit tests pass locally with my changes
- [ ] I have updated the CHANGELOG.md if applicable

## Additional Notes

- The license usage reporter (`reporter.py` → `app.headroomlabs.ai`) is
intentionally **kept** — it's license-key-gated (dormant for
unlicensed/OSS deployments) and goes to your own domain, not a third
party.
- Docs/CHANGELOG left unchecked: a couple of docs mention the telemetry
beacon and may want a follow-up note that it now collects locally only;
happy to add.
2026-06-27 22:48:26 -07:00

298 lines
11 KiB
Python
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

"""Tests for anonymous telemetry warning feature.
Covers:
- is_telemetry_warn_enabled() feature flag
- format_telemetry_notice() helper
- proxy CLI banner includes telemetry status
- wrap CLI prints telemetry notice
- /stats endpoint exposes anon_telemetry_shipping flag
"""
from unittest.mock import patch
import pytest
click = pytest.importorskip("click")
from click.testing import CliRunner # noqa: E402
from headroom.telemetry.beacon import ( # noqa: E402
format_telemetry_notice,
is_telemetry_warn_enabled,
)
# ---------------------------------------------------------------------------
# is_telemetry_warn_enabled
# ---------------------------------------------------------------------------
class TestIsTelemetryWarnEnabled:
"""Tests for the HEADROOM_TELEMETRY_WARN feature flag."""
def test_enabled_by_default(self, monkeypatch):
monkeypatch.delenv("HEADROOM_TELEMETRY_WARN", raising=False)
assert is_telemetry_warn_enabled() is True
@pytest.mark.parametrize("value", ["off", "OFF", "false", "0", "no", "disable", "disabled"])
def test_disabled_by_env_var(self, monkeypatch, value):
monkeypatch.setenv("HEADROOM_TELEMETRY_WARN", value)
assert is_telemetry_warn_enabled() is False
@pytest.mark.parametrize("value", ["on", "ON", "1", "yes", "true"])
def test_enabled_by_truthy_env_var(self, monkeypatch, value):
monkeypatch.setenv("HEADROOM_TELEMETRY_WARN", value)
assert is_telemetry_warn_enabled() is True
# ---------------------------------------------------------------------------
# format_telemetry_notice
# ---------------------------------------------------------------------------
class TestFormatTelemetryNotice:
"""Tests for format_telemetry_notice()."""
def test_returns_notice_when_telemetry_on(self, monkeypatch):
monkeypatch.setenv("HEADROOM_TELEMETRY", "on")
monkeypatch.delenv("HEADROOM_TELEMETRY_WARN", raising=False)
notice = format_telemetry_notice()
assert notice != ""
assert "ENABLED" in notice
assert "HEADROOM_TELEMETRY=off" in notice
assert "--no-telemetry" in notice
def test_empty_when_telemetry_off(self, monkeypatch):
monkeypatch.setenv("HEADROOM_TELEMETRY", "off")
monkeypatch.delenv("HEADROOM_TELEMETRY_WARN", raising=False)
assert format_telemetry_notice() == ""
def test_empty_when_warn_flag_off(self, monkeypatch):
monkeypatch.setenv("HEADROOM_TELEMETRY", "on")
monkeypatch.setenv("HEADROOM_TELEMETRY_WARN", "off")
assert format_telemetry_notice() == ""
def test_prefix_is_applied(self, monkeypatch):
monkeypatch.setenv("HEADROOM_TELEMETRY", "on")
monkeypatch.delenv("HEADROOM_TELEMETRY_WARN", raising=False)
notice = format_telemetry_notice(prefix=" ")
assert notice.startswith(" ")
def test_no_prefix_by_default(self, monkeypatch):
monkeypatch.setenv("HEADROOM_TELEMETRY", "on")
monkeypatch.delenv("HEADROOM_TELEMETRY_WARN", raising=False)
notice = format_telemetry_notice()
# Default prefix is "" so the string should start with "Telemetry"
assert notice.startswith("Telemetry:")
# ---------------------------------------------------------------------------
# proxy CLI banner
# ---------------------------------------------------------------------------
class TestProxyCLITelemetryBanner:
"""Proxy CLI startup banner must include telemetry status."""
@pytest.fixture
def runner(self):
return CliRunner()
def test_banner_shows_telemetry_enabled(self, runner, monkeypatch):
# Telemetry is opt-in: it only shows ENABLED once explicitly turned on.
monkeypatch.setenv("HEADROOM_TELEMETRY", "on")
from headroom.cli.main import main
with patch("headroom.proxy.server.run_server", side_effect=SystemExit(0)):
result = runner.invoke(main, ["proxy"])
assert "Telemetry:" in result.output
assert "ENABLED" in result.output
def test_banner_disabled_by_default(self, runner, monkeypatch):
# The whole point of opt-in: unset env => telemetry off, banner says so
# and surfaces how to opt in.
monkeypatch.delenv("HEADROOM_TELEMETRY", raising=False)
from headroom.cli.main import main
with patch("headroom.proxy.server.run_server", side_effect=SystemExit(0)):
result = runner.invoke(main, ["proxy"])
assert "Telemetry:" in result.output
assert "DISABLED" in result.output
assert "HEADROOM_TELEMETRY=on" in result.output or "--telemetry" in result.output
def test_telemetry_flag_opts_in(self, runner, monkeypatch):
monkeypatch.delenv("HEADROOM_TELEMETRY", raising=False)
from headroom.cli.main import main
with patch("headroom.proxy.server.run_server", side_effect=SystemExit(0)):
result = runner.invoke(main, ["proxy", "--telemetry"])
assert "Telemetry:" in result.output
assert "ENABLED" in result.output
def test_banner_shows_telemetry_disabled(self, runner, monkeypatch):
monkeypatch.setenv("HEADROOM_TELEMETRY", "off")
from headroom.cli.main import main
with patch("headroom.proxy.server.run_server", side_effect=SystemExit(0)):
result = runner.invoke(main, ["proxy"])
assert "Telemetry:" in result.output
assert "DISABLED" in result.output
def test_no_telemetry_flag_disables(self, runner, monkeypatch):
monkeypatch.delenv("HEADROOM_TELEMETRY", raising=False)
from headroom.cli.main import main
with patch("headroom.proxy.server.run_server", side_effect=SystemExit(0)):
result = runner.invoke(main, ["proxy", "--no-telemetry"])
assert "Telemetry:" in result.output
assert "DISABLED" in result.output
def test_banner_shows_opt_out_instructions_when_enabled(self, runner, monkeypatch):
monkeypatch.setenv("HEADROOM_TELEMETRY", "on")
from headroom.cli.main import main
with patch("headroom.proxy.server.run_server", side_effect=SystemExit(0)):
result = runner.invoke(main, ["proxy"])
assert "HEADROOM_TELEMETRY=off" in result.output or "--no-telemetry" in result.output
def test_banner_shows_context_tool(self, runner, monkeypatch):
monkeypatch.setenv("HEADROOM_CONTEXT_TOOL", "lean-ctx")
from headroom.cli.main import main
with patch("headroom.proxy.server.run_server", side_effect=SystemExit(0)):
result = runner.invoke(main, ["proxy"])
assert result.exit_code == 0
assert "Context Tool: lean-ctx" in result.output
# ---------------------------------------------------------------------------
# wrap CLI telemetry notice
# ---------------------------------------------------------------------------
class TestWrapCLITelemetryNotice:
"""_print_telemetry_notice() is called from wrap commands."""
def test_print_notice_outputs_when_telemetry_on(self, monkeypatch, capsys):
monkeypatch.setenv("HEADROOM_TELEMETRY", "on")
monkeypatch.delenv("HEADROOM_TELEMETRY_WARN", raising=False)
from headroom.cli.wrap import _print_telemetry_notice
_print_telemetry_notice()
captured = capsys.readouterr()
assert "Telemetry" in captured.out
assert "HEADROOM_TELEMETRY=off" in captured.out
def test_print_notice_silent_when_telemetry_off(self, monkeypatch, capsys):
monkeypatch.setenv("HEADROOM_TELEMETRY", "off")
from headroom.cli.wrap import _print_telemetry_notice
_print_telemetry_notice()
captured = capsys.readouterr()
assert captured.out == ""
def test_print_notice_silent_when_warn_flag_off(self, monkeypatch, capsys):
monkeypatch.setenv("HEADROOM_TELEMETRY", "on")
monkeypatch.setenv("HEADROOM_TELEMETRY_WARN", "off")
from headroom.cli.wrap import _print_telemetry_notice
_print_telemetry_notice()
captured = capsys.readouterr()
assert captured.out == ""
# ---------------------------------------------------------------------------
# /stats endpoint anon_telemetry_shipping flag
# ---------------------------------------------------------------------------
@pytest.mark.asyncio
class TestStatsEndpointTelemetryFlag:
"""The /stats endpoint must expose anon_telemetry_shipping."""
pytest.importorskip("fastapi")
async def test_stats_anon_telemetry_shipping_always_false(self, monkeypatch):
# The anonymous telemetry beacon was removed, so nothing is ever shipped
# externally — even with telemetry explicitly enabled.
monkeypatch.setenv("HEADROOM_TELEMETRY", "on")
from headroom.proxy.server import ProxyConfig, create_app
app = create_app(
ProxyConfig(
cache_enabled=False,
rate_limit_enabled=False,
cost_tracking_enabled=False,
)
)
from httpx import ASGITransport, AsyncClient
async with AsyncClient(transport=ASGITransport(app=app), base_url="http://test") as client:
resp = await client.get("/stats")
assert resp.status_code == 200
data = resp.json()
assert "anon_telemetry_shipping" in data
assert data["anon_telemetry_shipping"] is False
async def test_stats_includes_anon_telemetry_shipping_false(self, monkeypatch):
monkeypatch.setenv("HEADROOM_TELEMETRY", "off")
from headroom.proxy.server import ProxyConfig, create_app
app = create_app(
ProxyConfig(
cache_enabled=False,
rate_limit_enabled=False,
cost_tracking_enabled=False,
)
)
from httpx import ASGITransport, AsyncClient
async with AsyncClient(transport=ASGITransport(app=app), base_url="http://test") as client:
resp = await client.get("/stats")
assert resp.status_code == 200
data = resp.json()
assert "anon_telemetry_shipping" in data
assert data["anon_telemetry_shipping"] is False
# ---------------------------------------------------------------------------
# telemetry __init__ exports
# ---------------------------------------------------------------------------
class TestTelemetryModuleExports:
"""New helpers must be exported from headroom.telemetry."""
def test_is_telemetry_warn_enabled_exported(self):
from headroom.telemetry import is_telemetry_warn_enabled as fn
assert callable(fn)
def test_is_telemetry_enabled_exported(self):
from headroom.telemetry import is_telemetry_enabled as fn
assert callable(fn)
def test_format_telemetry_notice_exported(self):
from headroom.telemetry import format_telemetry_notice as fn
assert callable(fn)