perf(product-analytics): bound the insight upgrade scan by id window - #111230
posthog[bot] wants to merge 1 commit into
Conversation
get_insights_to_migrate parsed the query JSONB of every row until it found a full page, so a page with few matches read most of posthog_dashboarditem in one statement. Each statement now scans a fixed id window, and the cursor advances past empty windows. The workflow ends on a done flag, gated by workflow.patched for in-flight histories. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Generated-By: PostHog Desktop Task-Id: 8d89fd12-0501-4ef9-8dff-5543466a1a0e
|
Merging to
After your PR is submitted to the merge queue, this comment will be automatically updated with its status. If the PR fails, failure details will also be posted here |
🤖 CI report
|
| File | Comment lines | Added lines |
|---|---|---|
products/product_analytics/backend/temporal/upgrade_queries_activities.py |
3 | 29 |
products/product_analytics/backend/temporal/upgrade_queries_workflow.py |
1 | 17 |
This check does not block merging. It updates on every push and clears when the share drops.
HostHog preview —
|
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 🧰 Additional context used📚 Code guidelines (8)No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (4)
Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 7 remain after this review. 📝 WalkthroughWalkthroughThe activity now scans dashboard-item IDs in bounded windows and returns a completion flag with each result. The workflow uses that flag to determine when to exit, while continuing to migrate nonempty pages. Tests cover the captured SQL and pagination across multiple activity calls. Priority: ⬇️ Low Merge Risk: ⚪ Minimal · up to No concrete migration-pagination failure remains identified. The change is mergeable after normal checks; the scheduled run can provide the planned timing measurement. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to The bounded scan reduces database work without visibly adding access or privileges. However, old and new job versions disagree on completion. Unless rollout keeps compatible versions together, upgrades can stop early or repeatedly poll the shared database. Retained concerns
Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 1✅ Passed checks (1 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Problem
upgrade-queriesTemporal workflow loads the main Postgres primary every 6 hours. One call toget_insights_to_migratecan run for minutes, close to the 5-minute activity timeout. When a call times out, the insight schema upgrade backlog stops.queryJSONB of each row it reads.LIMIT 100and no upper bound, a page that has few matches reads most ofposthog_dashboarditemin one statement.Origin
4829393Changes
id > after AND id <= after + 5000). One call scans at most 20 windows, or stops when it has a full batch, then returns. The cursor moves past empty windows.donewhen the cursor reachesmax(id). Before, the workflow stopped when it got an empty page, but an empty window is now a valid page.migrate_insights_batchfor an empty page and stops ondone. Aworkflow.patched("upgrade-queries-id-window")gate keeps the previous command sequence for histories from before this change.DISTINCTon the primary key, and it sends the bounds as parameters, not as f-string values.flowchart LR subgraph Before A1[get page: id > after LIMIT 100] -->|empty| D1[finish] A1 -->|ids| M1[migrate] --> A1 end subgraph After A2[get page: up to 20 windows of 5k ids] -->|ids| M2[migrate] --> C2{done?} A2 -->|empty| C2 C2 -->|no| A2 C2 -->|yes| D2[finish] end style A2 fill:#1D4AFF,color:#fff style C2 fill:#F9BD2BNote
The 5k window size is an estimate. One window should take well under a second, but nobody has measured it in production. After the next scheduled run, compare the max and mean time per call in pganalyze.
How did you test this code?
pytest products/product_analytics/backend/temporal/tests/test_upgrade_queries_workflow.pyagainst a local Postgres. All 5 tests pass, including the end-to-end workflow test.ruff checkandruff formatare clean.Test rationale: The new test
test_get_insights_to_migrate_activity_pages_through_small_id_windowspages withbatch_size=2andscan_window_size=2. It fails if the scan stops at the first empty window, or if a page that ends partway through a window drops the remaining matches. The existing single-call test does not cover these cases because it gets all rows in one page. The existing snapshot test now replaces the id bounds with a fixed value, so the snapshot does not change when the test database's id sequence changes.Release status
Automatic notifications
Docs update
None.
🤖 Agent context
Autonomy: Fully autonomous
Agent: Claude Code, claude-opus-5-5
/writing-tests. Followed the repo Temporal workflow-versioning rule (workflow.patchedgate).Created with PostHog Desktop from this inbox report.
🤖 Generated with Claude Code