Serve Prometheus metrics at /metrics behind basic auth (closes #94)
check / check (push) Successful in 4m8s

With METRICS_USERNAME and METRICS_PASSWORD both set, the backend
records request metrics through go-http-metrics and serves them at
GET /metrics behind basic auth with those credentials; nginx passes
/metrics to it. With neither set there is no such route; one alone
stops the start with an error naming both.

Only requests chi has matched to a route are recorded, not every
request as the conventions show: the labels are path and method, which
clients can make up without end. So POST /api/v1/reports is registered
by its full path, not inside a route group.

Deviation: go get and go mod tidy ran directly; no entrypoint adds a Go
dependency yet (#45).

Model: opus-5-5
This commit is contained in:
2026-10-04 01:47:49 +00:00
parent 3b1262718d
commit a388121784
12 changed files with 252 additions and 34 deletions
+2 -2
View File
@@ -1,6 +1,6 @@
# The one image netwatch ships: nginx serves the built frontend and
# passes /api/ and /.well-known/healthcheck to netwatch-server, the Go
# backend, which runs in the same container on loopback only.
# passes /api/, /.well-known/healthcheck and /metrics to netwatch-server,
# the Go backend, which runs in the same container on loopback only.
# bin/entrypoint.sh starts and watches both.
# Lint stage — fast feedback on formatting and lint issues. The