Conversation
A hosting platform can now give every worker and pod the same signing secret (DASH_SECRET_KEY) and pick the shared-storage backend (DASH_SHARED_STORAGE) without editing the app. Without a shared secret, multi-worker stream requests 403 silently; the first failure in each process now logs a warning.
|
Contributor
Dash performance benchmarks✅ all within thresholds
growth = late-third / early-third per-op time; ~1 is flat, a large value means the per-op cost scales with accumulated state. machine scale vs baseline: 0.97x - divided out of the baseline ratios so they compare like for like (the absolute warn/fail ceilings are left un-scaled); calibrated on |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Streaming callbacks (#3931) and shared storage (#3930) break once an app runs on several workers or pods, and a hosting platform (Plotly Cloud, Dash Enterprise, self-hosted) can't fix that without editing app code. This adds two env vars, following the existing
DASH_*convention, and a warning for the failure that is silent today.Changes
DASH_SECRET_KEY: the signing secret is now looked up asserver.secret_key>DASH_SECRET_KEY> secret saved in the background-callback store > random per process. Used for Dash's own signing only and never copied ontoserver.secret_key, so Flask sessions are untouched. An empty value counts as unset.-w 4and nosecret_key, most downlink polls return 403 (25 of 40 measured).DASH_SHARED_STORAGE: picks the backend when the app doesn't passshared_storage=:local,none,diskcache:///abs/path, or aredis:///rediss://URL.shared_storagenow has a sentinel default, so an explicit argument,Noneincluded, always wins.app.shared_storageis first read.dash[redis]/dash[diskcache]raises the sameImportErroras the explicit path, atDash()construction.cluster://is reserved and raises "not supported in this version". Anything else raisesInvalidConfignaming the variable and value, with URL credentials replaced by***.server.secret_key/DASH_SECRET_KEY. Still 403. A request with no token is not logged.No behavior change for apps that set neither variable.
Tests
ImportErrortext, credential redaction, warning fires once.tests/streaming/test_stream_wsgi.py: gunicorn-w 4.DASH_SECRET_KEY: every poll is 200 and a stream completes in the browser. Fails before this change.dash_duotest selecting Redis throughDASH_SHARED_STORAGE. Skips without Redis, like the other Redis tests.