feat(analytics): instance census, full capture, richer error context (#511)

Add a once-per-boot instance_started event (arch, os, deploy_mode,
gpu_present) so the fleet architecture mix is measurable. It reuses the
existing per-instance instance_id and is exempt from the volume sample
rate, since a census that fires once per boot must not be thinned.

Restore useful capture depth now that the sponsored plan removes the
quota pressure behind the earlier hardening:

- PostHog sample rate 0.1 to 1.0 (full analytics when enabled); the
  property allowlist still blocks file data.
- Sentry per-instance ceiling 20 to 500/hr, breadcrumb trail restored
  (sanitized: urls/paths redacted, data payloads dropped), full stack
  paths kept; local vars, request bodies, and PII still dropped. Both
  api and web.

Honor ANALYTICS_ENABLED=false as an opt-out alias: it was documented on
the Docker Hub README but never wired in 2.x, so anyone who set it was
still tracked.

All capture stays behind the analytics opt-out gate.
This commit is contained in:
SnapOtter
2026-07-13 14:23:16 +08:00
committed by GitHub
parent b6fdabaea8
commit e1b8c24e5d
22 changed files with 378 additions and 106 deletions
+8
View File
@@ -13,6 +13,7 @@ export const ANALYTICS_EVENTS = {
BATCH_PROCESSED: "batch_processed",
FEEDBACK_SUBMITTED: "feedback_submitted",
SPONSOR_CLICKED: "sponsor_clicked",
INSTANCE_STARTED: "instance_started",
} as const;
export type AnalyticsEvent = (typeof ANALYTICS_EVENTS)[keyof typeof ANALYTICS_EVENTS];
@@ -47,3 +48,10 @@ export interface AiBundleActionProperties {
action: "installed" | "uninstalled";
duration_ms: number;
}
export interface InstanceStartedProperties {
arch: "arm64" | "amd64";
os_platform: string;
deploy_mode: "embedded" | "external" | "native";
gpu_present: boolean;
}