Skip to content

docs: remove expose_trace references - #775

Open
matthewmcneely wants to merge 1 commit into
mainfrom
matthewmcneely/remove-expose-trace-refs
Open

matthewmcneely wants to merge 1 commit into
mainfrom
matthewmcneely/remove-expose-trace-refs

Conversation

@matthewmcneely

@matthewmcneely matthewmcneely commented Sep 21, 2026 •

Copy link
Copy Markdown
Collaborator

Description

dgraph-io/dgraph#9593 removes the expose_trace flag from Dgraph. This PR clears the references to it here, and fixes a long-standing inaccuracy on the debug-information page.

docs-learn/howto/retrieving-debug-information.md

The Metrics section said you need --expose_trace=true to collect /debug/vars from outside the instance, and that it's localhost-only otherwise. That was never true. /debug/vars is served through x.SanitizedDefaultServeMux(), which routes it straight to filteredExpvarHandler with no source-IP check, so anyone who can reach the Alpha or Zero HTTP port can already read it. expose_trace only ever set trace.AuthRequest for the golang.org/x/net/trace endpoints (/debug/requests and /debug/events).

Replaced with what actually happens, plus a note to restrict the port at the network layer if you don't want the metrics public.

installation/lambda-server.md

--expose_trace in the Docker example is copy-paste cruft. It has nothing to do with the lambda server, and pasting it into a production compose file exposes the trace endpoints to any remote caller with sensitive data included. The command behaves identically without it.

Removed from the current page and from the five versioned copies. The flag is valid in those released versions, so this isn't a correctness fix for them, but it's a bad example to ship in any of them. Happy to narrow this to docs/ only if you'd rather leave the version snapshots frozen.

Related

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

The `expose_trace` flag is being removed from Dgraph in
dgraph-io/dgraph#9593. Drop it from the lambda-server Docker example and
correct the metrics section of the debug-information page, which
described the flag as gating `/debug/vars`. It never did.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant