mirror of
https://github.com/headroomlabs-ai/headroom.git
synced 2026-08-27 14:17:10 -04:00
## In one line
Headroom starts reporting **how well compression is working** — counters
and percentages only. **No prompts. No code. No file paths. Nothing
about what you're building.**
## Why
Right now nobody knows whether compression actually helps real users.
You can see your own numbers in `/stats`, but that's it — there's no way
to tell whether a given workload compresses well, or why it sometimes
doesn't. This closes that loop so we can make compression better for
everyone.
## Exactly what gets sent
One message per session, and every 5 minutes while you're active:
```json
{
"session": { "id": "random", "turns": 47, "duration_s": 4210, "seq": 3 },
"tokens": { "original": 890000, "attempted": 410000, "saved": 320000,
"tool_saved": 48000, "cache_read": 210000 },
"rates": { "saved_pct": 35.96, "eligible_pct": 46.07, "yield_pct": 78.05,
"cache_read_pct": 23.60, "overhead_pct": 1.96 },
"compression": { "transforms": {"crush": 47}, "passthrough_turns": 0 },
"skips": {},
"sources": { "proxy": 47 },
"providers": ["anthropic"],
"models": ["claude-sonnet-4-5-20250929"],
"failures": 2
}
```
Plus a random install ID, the Headroom version, and OS/architecture
(`darwin`, `arm64`).
That's the whole thing. A full example lives at
`deploy/beacon/sample-event.json`.
## What is never sent
- Your prompts or the model's responses
- Your code
- File paths, project names, repo names
- Tool names or MCP server names
- Hostname, username, or IP address
- Custom or fine-tuned model names (an id like `ft:gpt-4o:acme-corp:…`
contains a company name, so only models in a public registry are
reported)
**This is structural, not a pinky-swear.** Every value in the payload is
a number, a fixed word, or a random ID — there is no free-text field
anywhere for content to hide in. The receiver
(`deploy/beacon/worker.js`, in this repo so you can read it) drops
anything not on an explicit allowlist before storing.
## Turning it off
Any one of these:
```bash
HEADROOM_BEACON=off # or
DO_NOT_TRACK=1 # or
# offline mode
```
It's on by default, and Headroom says so at startup:
```
Telemetry: anonymous compression stats — never prompts, code, or file paths.
Helps us improve compression | Off: HEADROOM_BEACON=off
```
`HEADROOM_TELEMETRY` is a **separate** switch that still only affects
local stats. If you had turned that on, this change does not start
uploading anything — you answered a different question, and upgrading
should not change the answer.
## Why the percentages, not just "tokens saved"
"We saved 36%" hides the interesting part. In the example above only
**46% of tokens were eligible** for compression at all — the rest is
frozen cache prefix and system prompts we deliberately do not touch. Of
what we *could* touch, we removed **78%**.
Those are two separate problems. Raising eligibility is proxy work;
raising yield is compressor work. A single number cannot tell us which
to fix.
## Coverage
`emit_request_outcome` is a single chokepoint —
`handler.metrics.record_request` is called from exactly one place,
inside the funnel — so all 30 `RequestOutcome` construction sites are
covered: Anthropic, OpenAI, Gemini, Bedrock, batch, streaming, and the
long-lived Codex Responses-WS path.
The `headroom_compress` MCP path bypassed that funnel and is now wired
in separately. It has a different shape (no provider, no upstream
latency, and everything handed to the tool is eligible by construction),
so `sources` counts turns by origin — MCP turns always read
`eligible_pct: 100` and must not drag the proxy's real eligibility
ceiling upward.
**Subagents.** All subagent traffic through the proxy merges into one
session, which is correct for savings and retention but means `turns`
conflates fan-out with depth. Fan-out is still derivable —
`compression.latency_ms_total / session.duration_s` gives the
concurrency ratio (~1x serial, ~4x for four parallel agents), so no
extra field is needed. Verified no lost updates under 6-way concurrency
(1,200 turns).
**Known gap:** `--workers N` gives each process its own aggregator, so
one user session becomes up to N. Token totals and fleet rates stay
correct; session counts inflate. This matches the existing documented
limitation that TOIN state, CostTracker, and the prefix tracker are all
per-process.
## Notes for reviewers
- **Cumulative snapshots, not deltas.** Every report restates running
totals under one session ID, so the highest `seq` per `(install,
session)` is the complete session. Dedupe is a window function, and a
lost report costs nothing.
- **Never breaks the proxy.** Every path swallows its own exceptions;
uploads go out on a daemon thread so nothing blocks the request loop.
- **Explicit User-Agent is load-bearing.** urllib's default is blocked
by Cloudflare (error 1010). Combined with fire-and-forget error
handling, that would have failed every upload while looking perfectly
healthy.
- **The exit flush was broken and is fixed.** `atexit` handed the POST
to a daemon thread, and daemon threads are killed before they finish
during interpreter shutdown — so nothing was sent. That silently dropped
*every session shorter than the 5-minute heartbeat*, plus all
short-lived subagent MCP processes. The exit path now posts
synchronously with a 2s timeout.
- Receiver and query tooling are in `deploy/beacon/`.
## Testing
- `python -m headroom.telemetry.session` self-check: dedupe, cumulative
totals, dropped-report recovery, payload contains no model id or
prompt-derived string, allowlist coverage
- 175 telemetry/outcome tests pass; 6 new ones cover the opt-out notice
- Verified end to end against a live deployment: client → receiver →
storage → query
## Still to do before release
The default endpoint currently points at a temporary `workers.dev` URL.
It needs to move to a Headroom-owned hostname before this ships in a
tagged release — noted inline at `DEFAULT_ENDPOINT`.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
94 lines
3.7 KiB
Bash
Executable file
94 lines
3.7 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
# Query the telemetry corpus in R2 with DuckDB.
|
|
#
|
|
# ./query.sh # fleet summary
|
|
# ./query.sh sessions # one row per session (deduped)
|
|
# ./query.sh "SELECT ..." # your own SQL against the corpus
|
|
#
|
|
# Setup, once:
|
|
# brew install duckdb
|
|
# Cloudflare > R2 > API > Create Account API Token (Object Read only,
|
|
# scoped to headroom-telemetry), then put the values in ~/env.txt
|
|
# (or any file named by HEADROOM_ENV_FILE):
|
|
#
|
|
# R2_ACCOUNT_ID=...
|
|
# R2_ACCESS_KEY_ID=...
|
|
# R2_SECRET_ACCESS_KEY=...
|
|
#
|
|
# R2_ACCOUNT_TOKEN is Cloudflare's REST-API token and is NOT used here — the
|
|
# S3 protocol wants the access-key pair.
|
|
set -euo pipefail
|
|
|
|
BUCKET="${R2_BUCKET:-headroom-telemetry}"
|
|
_repo_env="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)/.env"
|
|
ENV_FILE="${HEADROOM_ENV_FILE:-$HOME/env.txt}"
|
|
[ -f "$ENV_FILE" ] || ENV_FILE="$_repo_env"
|
|
|
|
[ -f "$ENV_FILE" ] || { echo "no env file (~/env.txt or $_repo_env) — see this script's header" >&2; exit 1; }
|
|
# shellcheck disable=SC1090
|
|
set -a; source "$ENV_FILE"; set +a
|
|
|
|
for v in R2_ACCOUNT_ID R2_ACCESS_KEY_ID R2_SECRET_ACCESS_KEY; do
|
|
[ -n "${!v:-}" ] || { echo "$v not set in $ENV_FILE" >&2; exit 1; }
|
|
done
|
|
command -v duckdb >/dev/null || { echo "duckdb not installed: brew install duckdb" >&2; exit 1; }
|
|
|
|
# Credentials go in via a heredoc on stdin, never on the command line, so they
|
|
# stay out of `ps` and shell history.
|
|
SECRET="
|
|
INSTALL httpfs; LOAD httpfs;
|
|
CREATE OR REPLACE SECRET r2corpus (
|
|
TYPE r2,
|
|
KEY_ID '${R2_ACCESS_KEY_ID}',
|
|
SECRET '${R2_SECRET_ACCESS_KEY}',
|
|
ACCOUNT_ID '${R2_ACCOUNT_ID}'
|
|
);
|
|
"
|
|
|
|
# The corpus is heartbeats: a session reports every 5 minutes with CUMULATIVE
|
|
# totals under one id. So the row with the highest seq per (install, session) is
|
|
# the whole session — never SUM across heartbeats, you would count each session
|
|
# once per report.
|
|
DEDUPE="
|
|
CREATE OR REPLACE TEMP VIEW sessions AS
|
|
SELECT * FROM read_ndjson('r2://${BUCKET}/sessions/**/*.json', union_by_name = true)
|
|
QUALIFY row_number() OVER (
|
|
PARTITION BY resource['headroom.install_id'], session.id
|
|
ORDER BY session.seq DESC
|
|
) = 1;
|
|
"
|
|
|
|
case "${1:-summary}" in
|
|
summary)
|
|
# Fleet rates come from summing raw counts. Averaging the per-session
|
|
# rates.*_pct fields would weight a 10-token session equal to a 1M one.
|
|
QUERY="
|
|
SELECT count(*) AS sessions,
|
|
count(DISTINCT resource['headroom.install_id']) AS installs,
|
|
sum(session.turns) AS turns,
|
|
sum(tokens.saved) AS tokens_saved,
|
|
sum(tokens.tool_saved) AS tool_tokens_saved,
|
|
round(sum(tokens.attempted) * 100.0
|
|
/ nullif(sum(tokens.original), 0), 2) AS eligible_pct,
|
|
round(sum(tokens.saved) * 100.0
|
|
/ nullif(sum(tokens.attempted), 0), 2) AS yield_pct,
|
|
round(sum(tokens.saved) * 100.0
|
|
/ nullif(sum(tokens.original), 0), 2) AS saved_pct,
|
|
sum(failures) AS failures
|
|
FROM sessions;"
|
|
;;
|
|
sessions)
|
|
QUERY="
|
|
SELECT resource['headroom.install_id'][1:8] AS install,
|
|
session.id, session.seq, session.turns, session.duration_s,
|
|
tokens.original, tokens.attempted, tokens.saved,
|
|
rates.saved_pct, rates.eligible_pct, rates.yield_pct,
|
|
providers, models, skips
|
|
FROM sessions
|
|
ORDER BY session.duration_s DESC
|
|
LIMIT 50;"
|
|
;;
|
|
*) QUERY="$1" ;;
|
|
esac
|
|
|
|
printf '%s\n%s\n%s\n' "$SECRET" "$DEDUPE" "$QUERY" | duckdb -box
|