Serve Prometheus metrics at /metrics behind basic auth (closes #94)
check / check (push) Successful in 4m8s
check / check (push) Successful in 4m8s
With METRICS_USERNAME and METRICS_PASSWORD both set, the backend records request metrics through go-http-metrics and serves them at GET /metrics behind basic auth with those credentials; nginx passes /metrics to it. With neither set there is no such route; one alone stops the start with an error naming both. Only requests chi has matched to a route are recorded, not every request as the conventions show: the labels are path and method, which clients can make up without end. So POST /api/v1/reports is registered by its full path, not inside a route group. Deviation: go get and go mod tidy ran directly; no entrypoint adds a Go dependency yet (#45). Model: opus-5-5
This commit is contained in:
@@ -18,9 +18,13 @@ import (
|
||||
"sneak.berlin/go/netwatch/internal/globals"
|
||||
"sneak.berlin/go/netwatch/internal/logger"
|
||||
|
||||
basicauth "github.com/99designs/basicauth-go"
|
||||
"github.com/go-chi/chi/v5/middleware"
|
||||
"github.com/go-chi/cors"
|
||||
"github.com/go-chi/httprate"
|
||||
metrics "github.com/slok/go-http-metrics/metrics/prometheus"
|
||||
ghmm "github.com/slok/go-http-metrics/middleware"
|
||||
"github.com/slok/go-http-metrics/middleware/std"
|
||||
"go.uber.org/fx"
|
||||
)
|
||||
|
||||
@@ -364,3 +368,25 @@ func (s *Middleware) RateLimit(
|
||||
),
|
||||
)
|
||||
}
|
||||
|
||||
// Metrics returns middleware that records each request's duration and
|
||||
// response size, and the requests in progress, in Prometheus' default
|
||||
// registry, which GET /metrics serves. They are labelled by the request
|
||||
// path. Call it once per process: the registry refuses the same metrics
|
||||
// twice, and this panics.
|
||||
func (s *Middleware) Metrics() func(http.Handler) http.Handler {
|
||||
mdlw := ghmm.New(ghmm.Config{
|
||||
Recorder: metrics.NewRecorder(metrics.Config{}),
|
||||
})
|
||||
|
||||
return std.HandlerProvider("", mdlw)
|
||||
}
|
||||
|
||||
// MetricsAuth returns middleware that lets a request through only with
|
||||
// METRICS_USERNAME and METRICS_PASSWORD as its basic auth credentials,
|
||||
// and answers any other with 401.
|
||||
func (s *Middleware) MetricsAuth() func(http.Handler) http.Handler {
|
||||
return basicauth.New("metrics", map[string][]string{
|
||||
s.params.Config.MetricsUsername: {s.params.Config.MetricsPassword},
|
||||
})
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user