Skip to content

fix(flags): load shared definitions without a secret key - #300

Open
dustinbyrne wants to merge 2 commits into
mainfrom
fix/flag-cache-without-secret-key
Open

dustinbyrne wants to merge 2 commits into
mainfrom
fix/flag-cache-without-secret-key

Conversation

@dustinbyrne

@dustinbyrne dustinbyrne commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

💡 Motivation and Context

Like PostHog/posthog-python#1039, a worker consuming shared feature flag definitions should not need a privileged secret key. Existing initialization gates prevent that supported cache-consumer configuration from evaluating flags locally.

Changes

  • Permit the configured definition cache provider to supply definitions without a secret/personal API key.
  • Keyless consumers read the shared cache directly, without invoking the fetch-decision callback or publishing definitions. They cannot claim fetch leadership they are unable to use.
  • With privileged credentials, retain the existing decision flow: false reads the cache; true fetches definitions and publishes them. Direct definition requests remain authenticated.
  • Add public-entry regressions, update active credential/provider docs, and include scoped patch release metadata.

Cache-only readers bypass the shared loader specification's decision-first provider step; credentialed consumers retain that step.

Existing sync/async initialization and TimerTask polling are retained. Unscoped evaluate_flags still performs its existing remote discovery; scoped/conclusive local evaluation avoids remote requests.

💚 How did you test it?

  • Focused provider/version/reload suites: 395 examples passed.
  • Full standard and optional-OpenTelemetry suites: 1,277 examples each, zero failures. Standard suite has two expected optional-OTel pending cases; the OTel suite has none.
  • RuboCop and public API snapshot check: passed.
  • Shared-leadership regression fails against the prior loader and passes with the fix.
  • Actual Redis example/Lua reproduction, with mocked PostHog HTTP: four publisher requests, fresh reader/publisher/cache values and no keyless lease ownership.
  • Local validation used Ruby 3.4.7.

Release scope

Patch release for posthog-ruby. Existing signatures, capture defaults and wire formats are unchanged.

🤖 Agent context

Autonomy: Human-driven (agent-assisted)

Implemented with Pi worker agents and reviewed by separate fresh-context Pi reviewers. A simplify pass covered the scoped source/tests/docs before final local validation. Human review remains required.

@dustinbyrne
dustinbyrne requested a review from a team as a code owner October 9, 2026 15:33
@dustinbyrne dustinbyrne self-assigned this Oct 9, 2026
@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

posthog-ruby-sync Compliance Report

Date: 2026-10-10T04:15:40.327214+00:00
Duration: 94093ms

⚠️ Some Tests Failed

45/47 tests passed, 2 failed


Capture Tests

⚠️ 29/30 tests passed, 1 failed

View Details
Test Status Duration
Format Validation.Event Has Required Fields ✅ 8ms
Format Validation.Event Has Uuid ✅ 6ms
Format Validation.Event Has Lib Properties ✅ 4ms
Format Validation.Distinct Id Is String ✅ 8ms
Format Validation.Token Is Present ✅ 7ms
Format Validation.Custom Properties Preserved ✅ 6ms
Format Validation.Event Has Timestamp ✅ 6ms
Format Validation.Non Utc Event Timestamp Is Converted To Utc ✅ 6ms
Retry Behavior.Retries On 503 ✅ 5338ms
Retry Behavior.Does Not Retry On 400 ✅ 2009ms
Retry Behavior.Does Not Retry On 401 ✅ 2011ms
Retry Behavior.Respects Retry After Header ✅ 8015ms
Retry Behavior.Implements Backoff ✅ 15311ms
Retry Behavior.Retries On 500 ✅ 5159ms
Retry Behavior.Retries On 502 ✅ 5115ms
Retry Behavior.Retries On 504 ✅ 5145ms
Retry Behavior.Max Retries Respected ✅ 15653ms
Deduplication.Generates Unique Uuids ✅ 20ms
Deduplication.Preserves Uuid On Retry ✅ 5115ms
Deduplication.Preserves Uuid And Timestamp On Retry ✅ 10248ms
Deduplication.Preserves Uuid And Timestamp On Batch Retry ✅ 5119ms
Deduplication.No Duplicate Events In Batch ✅ 16ms
Deduplication.Different Events Have Different Uuids ✅ 8ms
Compression.Sends Gzip When Enabled ✅ 5ms
Batch Format.Uses Proper Batch Structure ✅ 5ms
Batch Format.Flush With No Events Sends Nothing ✅ 2ms
Batch Format.Multiple Events Batched Together ❌ 14ms
Error Handling.Does Not Retry On 403 ✅ 2007ms
Error Handling.Does Not Retry On 413 ✅ 2007ms
Error Handling.Retries On 408 ✅ 5114ms

Failures

batch_format.multiple_events_batched_together

Expected 1 requests, got 5

Feature_Flags Tests

⚠️ 16/17 tests passed, 1 failed

View Details
Test Status Duration
Request Payload.Request With Person Properties Device Id ✅ 7ms
Request Payload.Flags Request Uses V2 Query Param ✅ 5ms
Request Payload.Flags Request Hits Flags Path Not Decide ✅ 6ms
Request Payload.Flags Request Omits Authorization Header ✅ 7ms
Request Payload.Token In Flags Body Matches Init ✅ 7ms
Request Payload.Groups Round Trip ✅ 8ms
Request Payload.Groups Default To Empty Object ✅ 7ms
Request Payload.Disable Geoip False Propagates As Geoip Disable False ✅ 5ms
Request Payload.Disable Geoip Omitted Defaults To False ❌ 6ms
Request Payload.Flag Keys To Evaluate Contains Only Requested Key ✅ 6ms
Request Lifecycle.No Flags Request On Init Alone ✅ 1ms
Request Lifecycle.No Flags Request On Normal Capture ✅ 5ms
Request Lifecycle.Two Flag Calls Produce Two Remote Requests ✅ 8ms
Request Lifecycle.Mock Response Value Is Returned To Caller ✅ 6ms
Retry Behavior.Retries Flags On 502 ✅ 150ms
Retry Behavior.Retries Flags On 504 ✅ 145ms
Side Effect Events.Get Feature Flag Captures Feature Flag Called Event ✅ 7ms

Failures

request_payload.disable_geoip_omitted_defaults_to_false

Field 'geoip_disable' not found in /flags request body at path 'geoip_disable'. Available keys: ['distinct_id', 'groups', 'person_properties', 'group_properties', 'flag_keys_to_evaluate', 'token']

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

posthog-ruby-async Compliance Report

Date: 2026-10-10T04:15:39.858594+00:00
Duration: 98214ms

⚠️ Some Tests Failed

46/47 tests passed, 1 failed


Capture Tests

✅ 30/30 tests passed

View Details
Test Status Duration
Format Validation.Event Has Required Fields ✅ 10ms
Format Validation.Event Has Uuid ✅ 105ms
Format Validation.Event Has Lib Properties ✅ 109ms
Format Validation.Distinct Id Is String ✅ 106ms
Format Validation.Token Is Present ✅ 107ms
Format Validation.Custom Properties Preserved ✅ 107ms
Format Validation.Event Has Timestamp ✅ 108ms
Format Validation.Non Utc Event Timestamp Is Converted To Utc ✅ 9ms
Retry Behavior.Retries On 503 ✅ 5411ms
Retry Behavior.Does Not Retry On 400 ✅ 2109ms
Retry Behavior.Does Not Retry On 401 ✅ 2109ms
Retry Behavior.Respects Retry After Header ✅ 8017ms
Retry Behavior.Implements Backoff ✅ 15523ms
Retry Behavior.Retries On 500 ✅ 5212ms
Retry Behavior.Retries On 502 ✅ 5212ms
Retry Behavior.Retries On 504 ✅ 5212ms
Retry Behavior.Max Retries Respected ✅ 15622ms
Deduplication.Generates Unique Uuids ✅ 112ms
Deduplication.Preserves Uuid On Retry ✅ 5213ms
Deduplication.Preserves Uuid And Timestamp On Retry ✅ 10319ms
Deduplication.Preserves Uuid And Timestamp On Batch Retry ✅ 5214ms
Deduplication.No Duplicate Events In Batch ✅ 111ms
Deduplication.Different Events Have Different Uuids ✅ 107ms
Compression.Sends Gzip When Enabled ✅ 106ms
Batch Format.Uses Proper Batch Structure ✅ 106ms
Batch Format.Flush With No Events Sends Nothing ✅ 6ms
Batch Format.Multiple Events Batched Together ✅ 110ms
Error Handling.Does Not Retry On 403 ✅ 2108ms
Error Handling.Does Not Retry On 413 ✅ 2109ms
Error Handling.Retries On 408 ✅ 5211ms

Feature_Flags Tests

⚠️ 16/17 tests passed, 1 failed

View Details
Test Status Duration
Request Payload.Request With Person Properties Device Id ✅ 107ms
Request Payload.Flags Request Uses V2 Query Param ✅ 108ms
Request Payload.Flags Request Hits Flags Path Not Decide ✅ 109ms
Request Payload.Flags Request Omits Authorization Header ✅ 108ms
Request Payload.Token In Flags Body Matches Init ✅ 108ms
Request Payload.Groups Round Trip ✅ 107ms
Request Payload.Groups Default To Empty Object ✅ 107ms
Request Payload.Disable Geoip False Propagates As Geoip Disable False ✅ 106ms
Request Payload.Disable Geoip Omitted Defaults To False ❌ 107ms
Request Payload.Flag Keys To Evaluate Contains Only Requested Key ✅ 107ms
Request Lifecycle.No Flags Request On Init Alone ✅ 3ms
Request Lifecycle.No Flags Request On Normal Capture ✅ 105ms
Request Lifecycle.Two Flag Calls Produce Two Remote Requests ✅ 112ms
Request Lifecycle.Mock Response Value Is Returned To Caller ✅ 105ms
Retry Behavior.Retries Flags On 502 ✅ 209ms
Retry Behavior.Retries Flags On 504 ✅ 257ms
Side Effect Events.Get Feature Flag Captures Feature Flag Called Event ✅ 109ms

Failures

request_payload.disable_geoip_omitted_defaults_to_false

Field 'geoip_disable' not found in /flags request body at path 'geoip_disable'. Available keys: ['distinct_id', 'groups', 'person_properties', 'group_properties', 'flag_keys_to_evaluate', 'token']

Comment thread lib/posthog/feature_flags.rb
Comment thread .changeset/cache-consumers-without-secret.md Outdated
@turnipdabeets
turnipdabeets requested a review from a team October 9, 2026 20:03

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants