Serve Prometheus metrics at /metrics behind basic auth (closes #94)
check / check (push) Successful in 2m47s
check / check (push) Successful in 2m47s
With METRICS_USERNAME and METRICS_PASSWORD both set, the backend records request metrics through go-http-metrics in a registry of its own, with Go's runtime and process metrics, and serves them at GET /metrics behind basic auth with those credentials; nginx passes /metrics to it. With neither set there is no such route; one alone stops the start with an error naming both, and a METRICS_USERNAME containing ":" stops it with an error naming that. Only requests that reach the health check or POST /api/v1/reports are recorded, not every request as the conventions show: the labels are path and method, which clients can make up without end. So POST /api/v1/reports is registered by its full path, not inside a route group. Deviation: go get and go mod tidy ran directly; no entrypoint adds a Go dependency yet (#45). Model: opus-5-5
This commit is contained in:
@@ -23,6 +23,19 @@ latest run passes.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: the backend serves Prometheus metrics (issue #94). With
|
||||
`METRICS_USERNAME` and `METRICS_PASSWORD` both set, it records request
|
||||
duration and response size through `go-http-metrics` and serves them, with
|
||||
Go's runtime and process metrics, at `GET /metrics` behind basic auth with
|
||||
those credentials; nginx passes `/metrics` to it as it does `/api/`. With
|
||||
neither set there are no metrics and `/metrics` is 404; one without the other
|
||||
stops the start with an error naming both, and so does a `METRICS_USERNAME`
|
||||
containing `:`, with an error naming it. Only requests that reach the health
|
||||
check or `POST /api/v1/reports` are recorded, not `/metrics` itself and not
|
||||
every request as `GO_HTTP_SERVER_CONVENTIONS.md` shows, because the labels are
|
||||
the request's path and method, which clients can make up without end. For
|
||||
that, `POST /api/v1/reports` is now registered by its full path instead of
|
||||
inside a `/api/v1` route group; it answers as before
|
||||
- 2026-10-04: `script/` and `Makefile` follow the org models (issue #28):
|
||||
`make dev` shims to the new `script/dev`, the Vite dev server, and the new
|
||||
`make build` to `script/build`, the frontend production build.
|
||||
|
||||
Reference in New Issue
Block a user