-
Notifications
You must be signed in to change notification settings - Fork 461
feat(appsec): enable Exploit Prevention in Lambda #14827
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
feat(appsec): enable Exploit Prevention in Lambda #14827
Conversation
|
Bootstrap import analysisComparison of import times between this PR and base. SummaryThe average import time from this PR is: 240 ± 3 ms. The average import time from base is: 242 ± 2 ms. The import time difference between this PR and base is: -2.4 ± 0.1 ms. Import time breakdownThe following import paths have shrunk:
|
Performance SLOsComparing candidate florentin.labelle/APPSEC-59590/enable-rasp-for-lambda (7e60435) with baseline main (75a8246) 🟡 Near SLO Breach (5 suites)🟡 djangosimple - 30/30✅ appsecTime: ✅ 20.441ms (SLO: <22.300ms -8.3%) vs baseline: -0.2% Memory: ✅ 65.534MB (SLO: <67.000MB -2.2%) vs baseline: +5.1% ✅ exception-replay-enabledTime: ✅ 1.345ms (SLO: <1.450ms -7.2%) vs baseline: ~same Memory: ✅ 64.660MB (SLO: <67.000MB -3.5%) vs baseline: +5.0% ✅ iastTime: ✅ 20.432ms (SLO: <22.250ms -8.2%) vs baseline: ~same Memory: ✅ 65.449MB (SLO: <67.000MB -2.3%) vs baseline: +4.8% ✅ profilerTime: ✅ 15.242ms (SLO: <16.550ms -7.9%) vs baseline: ~same Memory: ✅ 53.772MB (SLO: <54.500MB 🟡 -1.3%) vs baseline: +4.9% ✅ resource-renamingTime: ✅ 20.587ms (SLO: <21.750ms -5.3%) vs baseline: -0.3% Memory: ✅ 65.510MB (SLO: <67.000MB -2.2%) vs baseline: +4.8% ✅ span-code-originTime: ✅ 26.217ms (SLO: <28.200ms -7.0%) vs baseline: -0.2% Memory: ✅ 67.577MB (SLO: <69.500MB -2.8%) vs baseline: +4.9% ✅ tracerTime: ✅ 20.488ms (SLO: <21.750ms -5.8%) vs baseline: ~same Memory: ✅ 65.497MB (SLO: <67.000MB -2.2%) vs baseline: +4.9% ✅ tracer-and-profilerTime: ✅ 22.075ms (SLO: <23.500ms -6.1%) vs baseline: +0.3% Memory: ✅ 66.578MB (SLO: <67.500MB 🟡 -1.4%) vs baseline: +4.8% ✅ tracer-dont-create-db-spansTime: ✅ 19.304ms (SLO: <21.500ms 📉 -10.2%) vs baseline: -0.3% Memory: ✅ 65.479MB (SLO: <66.000MB 🟡 -0.8%) vs baseline: +4.9% ✅ tracer-minimalTime: ✅ 16.686ms (SLO: <17.500ms -4.7%) vs baseline: +0.4% Memory: ✅ 65.523MB (SLO: <66.000MB 🟡 -0.7%) vs baseline: +4.9% ✅ tracer-nativeTime: ✅ 20.486ms (SLO: <21.750ms -5.8%) vs baseline: ~same Memory: ✅ 71.358MB (SLO: <72.500MB 🟡 -1.6%) vs baseline: +4.8% ✅ tracer-no-cachesTime: ✅ 18.451ms (SLO: <19.650ms -6.1%) vs baseline: +0.4% Memory: ✅ 65.445MB (SLO: <67.000MB -2.3%) vs baseline: +4.9% ✅ tracer-no-databasesTime: ✅ 18.737ms (SLO: <20.100ms -6.8%) vs baseline: -0.3% Memory: ✅ 65.085MB (SLO: <67.000MB -2.9%) vs baseline: +4.7% ✅ tracer-no-middlewareTime: ✅ 20.196ms (SLO: <21.500ms -6.1%) vs baseline: +0.2% Memory: ✅ 65.478MB (SLO: <67.000MB -2.3%) vs baseline: +4.9% ✅ tracer-no-templatesTime: ✅ 20.288ms (SLO: <22.000ms -7.8%) vs baseline: +0.2% Memory: ✅ 65.441MB (SLO: <67.000MB -2.3%) vs baseline: +4.9% 🟡 errortrackingdjangosimple - 6/6✅ errortracking-enabled-allTime: ✅ 18.041ms (SLO: <19.850ms -9.1%) vs baseline: ~same Memory: ✅ 65.235MB (SLO: <66.500MB 🟡 -1.9%) vs baseline: +4.8% ✅ errortracking-enabled-userTime: ✅ 18.030ms (SLO: <19.400ms -7.1%) vs baseline: -0.1% Memory: ✅ 65.215MB (SLO: <66.500MB 🟡 -1.9%) vs baseline: +4.9% ✅ tracer-enabledTime: ✅ 18.047ms (SLO: <19.450ms -7.2%) vs baseline: +0.1% Memory: ✅ 65.167MB (SLO: <66.500MB -2.0%) vs baseline: +4.7% 🟡 flasksimple - 18/18✅ appsec-getTime: ✅ 4.573ms (SLO: <4.750ms -3.7%) vs baseline: +0.1% Memory: ✅ 62.030MB (SLO: <65.000MB -4.6%) vs baseline: +4.9% ✅ appsec-postTime: ✅ 6.585ms (SLO: <6.750ms -2.4%) vs baseline: ~same Memory: ✅ 62.010MB (SLO: <65.000MB -4.6%) vs baseline: +4.9% ✅ appsec-telemetryTime: ✅ 4.572ms (SLO: <4.750ms -3.8%) vs baseline: +0.2% Memory: ✅ 62.010MB (SLO: <65.000MB -4.6%) vs baseline: +5.0% ✅ debuggerTime: ✅ 1.858ms (SLO: <2.000ms -7.1%) vs baseline: ~same Memory: ✅ 45.436MB (SLO: <47.000MB -3.3%) vs baseline: +4.9% ✅ iast-getTime: ✅ 1.863ms (SLO: <2.000ms -6.8%) vs baseline: -0.2% Memory: ✅ 42.389MB (SLO: <49.000MB 📉 -13.5%) vs baseline: +5.0% ✅ profilerTime: ✅ 1.912ms (SLO: <2.100ms -8.9%) vs baseline: ~same Memory: ✅ 46.439MB (SLO: <47.000MB 🟡 -1.2%) vs baseline: +4.8% ✅ resource-renamingTime: ✅ 3.384ms (SLO: <3.650ms -7.3%) vs baseline: ~same Memory: ✅ 52.219MB (SLO: <53.500MB -2.4%) vs baseline: +4.9% ✅ tracerTime: ✅ 3.369ms (SLO: <3.650ms -7.7%) vs baseline: -0.3% Memory: ✅ 52.258MB (SLO: <53.500MB -2.3%) vs baseline: +4.9% ✅ tracer-nativeTime: ✅ 3.370ms (SLO: <3.650ms -7.7%) vs baseline: ~same Memory: ✅ 58.318MB (SLO: <60.000MB -2.8%) vs baseline: +4.9% 🟡 otelspan - 22/22✅ add-eventTime: ✅ 42.455ms (SLO: <47.150ms -10.0%) vs baseline: ~same Memory: ✅ 44.383MB (SLO: <47.000MB -5.6%) vs baseline: +4.7% ✅ add-metricsTime: ✅ 321.268ms (SLO: <344.800ms -6.8%) vs baseline: +1.2% Memory: ✅ 595.050MB (SLO: <600.000MB 🟡 -0.8%) vs baseline: +4.8% ✅ add-tagsTime: ✅ 290.976ms (SLO: <314.000ms -7.3%) vs baseline: +1.5% Memory: ✅ 596.741MB (SLO: <600.000MB 🟡 -0.5%) vs baseline: +4.8% ✅ get-contextTime: ✅ 80.899ms (SLO: <92.350ms 📉 -12.4%) vs baseline: ~same Memory: ✅ 40.009MB (SLO: <46.500MB 📉 -14.0%) vs baseline: +5.0% ✅ is-recordingTime: ✅ 39.021ms (SLO: <44.500ms 📉 -12.3%) vs baseline: +0.3% Memory: ✅ 44.009MB (SLO: <47.500MB -7.4%) vs baseline: +5.1% ✅ record-exceptionTime: ✅ 58.923ms (SLO: <67.650ms 📉 -12.9%) vs baseline: ~same Memory: ✅ 40.254MB (SLO: <47.000MB 📉 -14.4%) vs baseline: +4.7% ✅ set-statusTime: ✅ 45.000ms (SLO: <50.400ms 📉 -10.7%) vs baseline: +0.4% Memory: ✅ 44.003MB (SLO: <47.000MB -6.4%) vs baseline: +5.1% ✅ startTime: ✅ 38.010ms (SLO: <43.450ms 📉 -12.5%) vs baseline: -0.9% Memory: ✅ 43.931MB (SLO: <47.000MB -6.5%) vs baseline: +4.8% ✅ start-finishTime: ✅ 82.918ms (SLO: <88.000ms -5.8%) vs baseline: ~same Memory: ✅ 34.603MB (SLO: <46.500MB 📉 -25.6%) vs baseline: +4.9% ✅ start-finish-telemetryTime: ✅ 84.341ms (SLO: <89.000ms -5.2%) vs baseline: -0.2% Memory: ✅ 34.564MB (SLO: <46.500MB 📉 -25.7%) vs baseline: +4.9% ✅ update-nameTime: ✅ 40.289ms (SLO: <45.150ms 📉 -10.8%) vs baseline: +0.3% Memory: ✅ 44.184MB (SLO: <47.000MB -6.0%) vs baseline: +4.9% 🟡 span - 26/26✅ add-eventTime: ✅ 20.871ms (SLO: <22.500ms -7.2%) vs baseline: +1.3% Memory: ✅ 50.291MB (SLO: <53.000MB -5.1%) vs baseline: +4.6% ✅ add-metricsTime: ✅ 90.038ms (SLO: <93.500ms -3.7%) vs baseline: -0.6% Memory: ✅ 661.209MB (SLO: <961.000MB 📉 -31.2%) vs baseline: +4.8% ✅ add-tagsTime: ✅ 147.659ms (SLO: <155.000ms -4.7%) vs baseline: +0.3% Memory: ✅ 662.220MB (SLO: <962.500MB 📉 -31.2%) vs baseline: +5.0% ✅ get-contextTime: ✅ 19.395ms (SLO: <20.500ms -5.4%) vs baseline: +0.6% Memory: ✅ 49.176MB (SLO: <53.000MB -7.2%) vs baseline: +4.8% ✅ is-recordingTime: ✅ 19.669ms (SLO: <20.500ms -4.1%) vs baseline: +0.4% Memory: ✅ 49.153MB (SLO: <53.000MB -7.3%) vs baseline: +4.8% ✅ record-exceptionTime: ✅ 38.328ms (SLO: <40.000ms -4.2%) vs baseline: -0.1% Memory: ✅ 42.687MB (SLO: <53.000MB 📉 -19.5%) vs baseline: +4.6% ✅ set-statusTime: ✅ 21.336ms (SLO: <22.000ms -3.0%) vs baseline: +0.5% Memory: ✅ 49.211MB (SLO: <53.000MB -7.1%) vs baseline: +5.0% ✅ startTime: ✅ 19.361ms (SLO: <20.500ms -5.6%) vs baseline: +1.1% Memory: ✅ 49.222MB (SLO: <53.000MB -7.1%) vs baseline: +5.2% ✅ start-finishTime: ✅ 51.704ms (SLO: <52.500ms 🟡 -1.5%) vs baseline: +0.6% Memory: ✅ 32.165MB (SLO: <34.000MB -5.4%) vs baseline: +5.1% ✅ start-finish-telemetryTime: ✅ 53.298ms (SLO: <54.500ms -2.2%) vs baseline: +1.2% Memory: ✅ 32.106MB (SLO: <34.000MB -5.6%) vs baseline: +4.7% ✅ start-finish-traceid128Time: ✅ 55.426ms (SLO: <56.000ms 🟡 -1.0%) vs baseline: +1.2% Memory: ✅ 32.145MB (SLO: <34.000MB -5.5%) vs baseline: +5.1% ✅ start-traceid128Time: ✅ 19.728ms (SLO: <22.500ms 📉 -12.3%) vs baseline: +0.5% Memory: ✅ 49.186MB (SLO: <53.000MB -7.2%) vs baseline: +5.0% ✅ update-nameTime: ✅ 20.083ms (SLO: <22.000ms -8.7%) vs baseline: ~same Memory: ✅ 49.786MB (SLO: <53.000MB -6.1%) vs baseline: +4.9%
|
7c88886
to
edc1a9b
Compare
edc1a9b
to
485aefb
Compare
Description
Stop explicitely disabling Exploit Prevention in AWS Lambda
Testing
system-tests for lambda are passing using local builds with DataDog/system-tests#5505 and will be enabled after this PR is merged.
Risks
None
Additional Notes