Serve Prometheus metrics at /metrics behind basic auth (closes #94)
check / check (push) Successful in 4m8s

With METRICS_USERNAME and METRICS_PASSWORD both set, the backend
records request metrics through go-http-metrics and serves them at
GET /metrics behind basic auth with those credentials; nginx passes
/metrics to it. With neither set there is no such route; one alone
stops the start with an error naming both.

Only requests chi has matched to a route are recorded, not every
request as the conventions show: the labels are path and method, which
clients can make up without end. So POST /api/v1/reports is registered
by its full path, not inside a route group.

Deviation: go get and go mod tidy ran directly; no entrypoint adds a Go
dependency yet (#45).

Model: opus-5-5
This commit is contained in:
2026-10-04 01:47:49 +00:00
parent 3b1262718d
commit a388121784
12 changed files with 252 additions and 34 deletions
+21 -6
View File
@@ -5,6 +5,7 @@ import (
"github.com/go-chi/chi/v5"
"github.com/go-chi/chi/v5/middleware"
"github.com/prometheus/client_golang/prometheus/promhttp"
)
const (
@@ -29,13 +30,27 @@ func (s *Server) SetupRoutes() {
s.router.Use(s.mw.MaxBodyBytes(maxRequestBodyBytes))
s.router.Use(middleware.Timeout(requestTimeout))
s.router.Get(
"/.well-known/healthcheck",
s.h.HandleHealthCheck(),
)
// Requests are measured only once chi has matched them to one of
// these routes, by path and method. The metrics are labelled with
// both, which any client can make up, so measuring every request
// would let clients add labels without bound. A Route here would
// be matched by its path prefix alone, so each path is given in
// full.
s.router.Group(func(r chi.Router) {
// config.New refuses one of the two credentials without the
// other.
if s.params.Config.MetricsUsername != "" {
r.Use(s.mw.Metrics())
}
r.Get("/.well-known/healthcheck", s.h.HandleHealthCheck())
s.router.Route("/api/v1", func(r chi.Router) {
r.With(s.mw.RateLimit(s.params.Config.ReportsPerMinute)).
Post("/reports", s.h.HandleReport())
Post("/api/v1/reports", s.h.HandleReport())
})
if s.params.Config.MetricsUsername != "" {
s.router.With(s.mw.MetricsAuth()).
Get("/metrics", promhttp.Handler().ServeHTTP)
}
}