Serve Prometheus metrics at /metrics behind basic auth (closes #94)
check / check (push) Successful in 2m47s
check / check (push) Successful in 2m47s
With METRICS_USERNAME and METRICS_PASSWORD both set, the backend records request metrics through go-http-metrics in a registry of its own, with Go's runtime and process metrics, and serves them at GET /metrics behind basic auth with those credentials; nginx passes /metrics to it. With neither set there is no such route; one alone stops the start with an error naming both, and a METRICS_USERNAME containing ":" stops it with an error naming that. Only requests that reach the health check or POST /api/v1/reports are recorded, not every request as the conventions show: the labels are path and method, which clients can make up without end. So POST /api/v1/reports is registered by its full path, not inside a route group. Deviation: go get and go mod tidy ran directly; no entrypoint adds a Go dependency yet (#45). Model: opus-5-5
This commit is contained in:
@@ -201,9 +201,9 @@ static file host (S3, GCS, Cloudflare Pages, Vercel, Netlify, GitHub Pages) or
|
||||
use the Docker image behind a reverse proxy.
|
||||
|
||||
The Docker image, built from `Dockerfile`, is the whole service in one
|
||||
container: nginx serves the built frontend and passes `/api/` and
|
||||
`/.well-known/healthcheck` to the Go backend, `netwatch-server`, which listens
|
||||
only inside the container, on `127.0.0.1:8081`. The image:
|
||||
container: nginx serves the built frontend and passes `/api/`,
|
||||
`/.well-known/healthcheck` and `/metrics` to the Go backend, `netwatch-server`,
|
||||
which listens only inside the container, on `127.0.0.1:8081`. The image:
|
||||
|
||||
- Listens on port 8080 by default (override with `PORT` env var)
|
||||
- Takes the client address from `X-Forwarded-For` only on requests from the
|
||||
@@ -251,6 +251,12 @@ What the [upaas](https://git.eeqj.de/sneak/upaas) app for netwatch needs:
|
||||
connects from one can write its own `X-Forwarded-For`, and through a port
|
||||
Docker publishes, every client may connect from the Docker network's
|
||||
gateway, such as `172.17.0.1`.
|
||||
- `METRICS_USERNAME` and `METRICS_PASSWORD`, default empty: with both set,
|
||||
the backend records Prometheus metrics of its requests and serves them at
|
||||
`/metrics` on the container port, to requests with this user name and
|
||||
password as their basic auth credentials. With neither set, there are no
|
||||
metrics and `/metrics` is not found. One set without the other, or a user
|
||||
name containing `:`, stops the container
|
||||
- **Health check:** the image's `HEALTHCHECK` requests
|
||||
`/.well-known/healthcheck` through nginx every 30 seconds, so it fails unless
|
||||
both nginx and the backend answer. upaas reads the container's health 60
|
||||
|
||||
Reference in New Issue
Block a user