From 77560e5c7aa35c5515b0b2538dfcf509a3718ce9 Mon Sep 17 00:00:00 2001 From: Cody Lawson Date: Mon, 3 Aug 2026 13:29:46 -0600 Subject: [PATCH 1/2] feat: Re-add K8s namespace to replicaset relationship (staging) Co-Authored-By: Claude Sonnet 5 --- ...ACE-to-INFRA-KUBERNETES_REPLICASET.stg.yml | 54 +++++++++++++++++++ 1 file changed, 54 insertions(+) create mode 100644 relationships/synthesis/INFRA-KUBERNETES_NAMESPACE-to-INFRA-KUBERNETES_REPLICASET.stg.yml diff --git a/relationships/synthesis/INFRA-KUBERNETES_NAMESPACE-to-INFRA-KUBERNETES_REPLICASET.stg.yml b/relationships/synthesis/INFRA-KUBERNETES_NAMESPACE-to-INFRA-KUBERNETES_REPLICASET.stg.yml new file mode 100644 index 000000000..3ff3d57dd --- /dev/null +++ b/relationships/synthesis/INFRA-KUBERNETES_NAMESPACE-to-INFRA-KUBERNETES_REPLICASET.stg.yml @@ -0,0 +1,54 @@ +relationships: + - name: k8sNamespaceContainsReplicaSet + version: "1" + origins: + - Kubernetes Integration + conditions: + - attribute: eventType + anyOf: [ "K8sReplicasetSample" ] + - attribute: entityGuid + present: true + - attribute: namespaceName + present: true + - attribute: clusterName + present: true + relationship: + expires: PT75M + relationshipType: CONTAINS + source: + lookupGuid: + candidateCategory: KUBERNETES_NAMESPACE + fields: + - field: k8s.clusterName + attribute: clusterName + - field: k8s.namespaceName + attribute: namespaceName + target: + extractGuid: + attribute: entityGuid + entityType: + value: KUBERNETES_REPLICASET + - name: otelKsmK8sNamespaceContainsReplicaSet + # use kube-state-metrics kube_replicaset_owner + version: "1" + origins: + - OpenTelemetry + conditions: + - attribute: metricName + anyOf: [ "kube_replicaset_owner" ] + relationship: + expires: PT75M + relationshipType: CONTAINS + source: + lookupGuid: + candidateCategory: KUBERNETES_NAMESPACE + fields: + - field: k8s.clusterName + attribute: k8s.cluster.name + - field: k8s.namespaceName + attribute: k8s.namespace.name + target: + extractGuid: + attribute: entity.guid + entityType: + value: KUBERNETES_REPLICASET \ No newline at end of file From 1a8802c33b7045855c8f1a192a8726a3e10634a9 Mon Sep 17 00:00:00 2001 From: Cody Lawson Date: Mon, 3 Aug 2026 13:50:08 -0600 Subject: [PATCH 2/2] fix: Restrict replicaset namespace relationship to cut CPU/event volume Excludes scaled-to-zero ReplicaSets (podsDesired=0) from the NRI-based rule, which account for over half of matched K8sReplicasetSample events in sampled data - these are historical rollout artifacts with no live pods and don't need a continuously-refreshed namespace edge. Also fixes the OTel rule's source resolver from lookupGuid to buildGuid to match the Deployment/DaemonSet/StatefulSet sibling rules, removing an unnecessary candidate-search lookup on every matched event. Co-Authored-By: Claude Sonnet 5 --- ...ACE-to-INFRA-KUBERNETES_REPLICASET.stg.yml | 22 +++++++++++++------ 1 file changed, 15 insertions(+), 7 deletions(-) diff --git a/relationships/synthesis/INFRA-KUBERNETES_NAMESPACE-to-INFRA-KUBERNETES_REPLICASET.stg.yml b/relationships/synthesis/INFRA-KUBERNETES_NAMESPACE-to-INFRA-KUBERNETES_REPLICASET.stg.yml index 3ff3d57dd..7a7b6088e 100644 --- a/relationships/synthesis/INFRA-KUBERNETES_NAMESPACE-to-INFRA-KUBERNETES_REPLICASET.stg.yml +++ b/relationships/synthesis/INFRA-KUBERNETES_NAMESPACE-to-INFRA-KUBERNETES_REPLICASET.stg.yml @@ -12,6 +12,8 @@ relationships: present: true - attribute: clusterName present: true + - attribute: podsDesired + regex: "^[1-9][0-9]*$" relationship: expires: PT75M relationshipType: CONTAINS @@ -40,13 +42,19 @@ relationships: expires: PT75M relationshipType: CONTAINS source: - lookupGuid: - candidateCategory: KUBERNETES_NAMESPACE - fields: - - field: k8s.clusterName - attribute: k8s.cluster.name - - field: k8s.namespaceName - attribute: k8s.namespace.name + buildGuid: + account: + lookup: true + domain: + value: INFRA + type: + value: KUBERNETES_NAMESPACE + identifier: + fragments: + - attribute: k8s.cluster.name + - value: ":" + - attribute: k8s.namespace.name + hashAlgorithm: FARM_HASH target: extractGuid: attribute: entity.guid