Skip to content

feat: add dual telemetry sinks - #8

Merged
emfpdlzj merged 2 commits into
mainfrom
feat/telemetry-dual-sinks
Jun 16, 2026
Merged

emfpdlzj merged 2 commits into
mainfrom
feat/telemetry-dual-sinks

Conversation

@emfpdlzj

@emfpdlzj emfpdlzj commented Jun 16, 2026 •

Copy link
Copy Markdown
Owner

요약

  • @vscode/extension-telemetry 기반 Application Insights sink와 PostHog sink를 함께 붙였습니다.
  • VS Code telemetry 설정과 extension-level telemetry, telemetry service를 추가했습니다.
  • AI gate, validation run, AI 문서 생성, preview apply 흐름에 최소 이벤트를 연결했습니다.

작업 배경

  • DSLForge의 실제 사용 흐름을 release 전에 계측할 수 있어야 했습니다.
  • 다만 VS Code extension 정책에 맞게 사용자 telemetry 설정을 존중하고, grammar 내용이나 prompt 같은 민감한 데이터는 보내지 않는 구조가 필요했습니다.

변경 내용

  • src/core/telemetry.ts 추가
    • App Insights와 PostHog를 dual sink로 관리
    • vscode.env.isTelemetryEnabled와 dslforge.telemetry.enabled를 함께 반영
    • PostHog distinct ID는 vscode.env.machineId를 해시해서 사용
    • 민감 속성 이름에 대한 방어적 redaction/filter 적용
  • package.json
    • @vscode/extension-telemetry, posthog-node 의존성 추가
    • telemetry 관련 설정 추가
      • dslforge.telemetry.enabled
      • dslforge.telemetry.appInsightsConnectionString
      • dslforge.telemetry.posthogApiKey
      • dslforge.telemetry.posthogHost
  • 주요 이벤트 wiring 추가
    • AI gate 결과
    • validation run 결과
    • AI explanation / scaffold / sample 생성 결과
    • reviewed preview apply prepared / conflict / completed
  • README와 CHANGELOG에 telemetry 설정/범위 설명 추가

검증

  • npm run typecheck
  • npm run test

비고

  • sink는 구현과 설정 경로까지 포함해 준비됐고, 실제 수집 활성화에는 App Insights connection string과 PostHog project API key를 release 환경 또는 설정에 넣어야 합니다.
  • telemetry는 grammar content, prompt, workspace path, raw validation output을 의도적으로 보내지 않도록 설계했습니다.

@gitguardian

gitguardian Bot commented Jun 16, 2026 •

Copy link
Copy Markdown

️✅ There are no secrets present in this pull request anymore.

If these secrets were true positive and are still valid, we highly recommend you to revoke them.
While these secrets were previously flagged, we no longer have a reference to the
specific commits where they were detected. Once a secret has been leaked into a git
repository, you should consider it compromised, even if it was deleted immediately.
Find here more information about risks.


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

@emfpdlzj
emfpdlzj force-pushed the feat/telemetry-dual-sinks branch from 441e883 to ae41683 Compare June 16, 2026 03:08
@emfpdlzj

Copy link
Copy Markdown
Owner Author

추가 반영했습니다.

이번 보강에서 바뀐 점:

  • 클라이언트에 내장했던 PostHog key를 제거했습니다.
  • telemetry를 Vercel proxy 경유 방식으로 전환했습니다.
  • proxy에서 허용 이벤트/속성만 수용하고, 민감 키 패턴과 과도한 payload를 차단합니다.
  • release workflow에서 DSLFORGE_TELEMETRY_PROXY_ENDPOINT를 주입해 배포 빌드에만 production endpoint가 들어가도록 정리했습니다.
  • local/staging 검증용으로 dslforge.telemetry.endpointOverride도 추가했습니다.
  • formatter / pre-commit / CI format check도 같이 정리했습니다.

운영 시 필요한 설정:

  • Vercel env: POSTHOG_PROJECT_API_KEY
  • optional Vercel env: POSTHOG_HOST, TELEMETRY_RATE_LIMIT_WINDOW_MS, TELEMETRY_RATE_LIMIT_MAX_EVENTS
  • GitHub repo variable: DSLFORGE_TELEMETRY_PROXY_ENDPOINT=https://<your-vercel-domain>/api/telemetry

검증:

  • npm run format:check
  • npm run typecheck
  • npm run test

참고:

  • GitGuardian에 걸렸던 하드코딩 key는 제거했고, PR 브랜치 히스토리도 secret 없는 상태로 재작성했습니다.

@emfpdlzj
emfpdlzj merged commit ffdf889 into main Jun 16, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant