Prometheus metrics at /metrics behind basic auth when METRICS_USERNAME and METRICS_PASSWORD are set #94

Closed
opened 2026-10-03 17:25:20 +02:00 by clawbot · 1 comment
Collaborator

Split out of #27. The backend reads METRICS_USERNAME and METRICS_PASSWORD and does nothing with them. GO_HTTP_SERVER_CONVENTIONS.md in sneak/prompts (section 14, "Prometheus Metrics", and the Metrics() / MetricsAuth() middleware in section 7) makes Prometheus metrics mandatory, with the libraries it names: github.com/prometheus/client_golang, github.com/slok/go-http-metrics and github.com/99designs/basicauth-go.

Definition of done

  • When both METRICS_USERNAME and METRICS_PASSWORD are set, the backend records request metrics through go-http-metrics and serves GET /metrics behind basic auth with those credentials, as the conventions show; when either is empty, it does neither, and /metrics is 404. Only one of the two set stops the start with an error naming both.
  • nginx passes /metrics to the backend, as it does /api/, so the endpoint is reachable on the container's port; the backend still listens only on loopback.
  • Tests: no credentials, no route; wrong credentials, 401; right credentials, metrics that include a request just made.
  • README.md "Running under upaas" and backend/README.md list both settings and what they do.
  • Dependencies checked against the Go package defaults and pinned by go.sum.
  • Root make check and script/cibuild pass; TODO.md updated in the same commit; commit title ends (closes #N).

Model: opus-5-5

Split out of https://git.eeqj.de/sneak/netwatch/issues/27. The backend reads `METRICS_USERNAME` and `METRICS_PASSWORD` and does nothing with them. `GO_HTTP_SERVER_CONVENTIONS.md` in `sneak/prompts` (section 14, "Prometheus Metrics", and the `Metrics()` / `MetricsAuth()` middleware in section 7) makes Prometheus metrics mandatory, with the libraries it names: `github.com/prometheus/client_golang`, `github.com/slok/go-http-metrics` and `github.com/99designs/basicauth-go`. ## Definition of done - When both `METRICS_USERNAME` and `METRICS_PASSWORD` are set, the backend records request metrics through `go-http-metrics` and serves `GET /metrics` behind basic auth with those credentials, as the conventions show; when either is empty, it does neither, and `/metrics` is 404. Only one of the two set stops the start with an error naming both. - nginx passes `/metrics` to the backend, as it does `/api/`, so the endpoint is reachable on the container's port; the backend still listens only on loopback. - Tests: no credentials, no route; wrong credentials, 401; right credentials, metrics that include a request just made. - `README.md` "Running under upaas" and `backend/README.md` list both settings and what they do. - Dependencies checked against the Go package defaults and pinned by `go.sum`. - Root `make check` and `script/cibuild` pass; `TODO.md` updated in the same commit; commit title ends ` (closes #N)`. Model: opus-5-5
clawbot self-assigned this 2026-10-03 17:25:20 +02:00
Author
Collaborator

Built in #103: with both settings set, request metrics through go-http-metrics and GET /metrics behind basic auth; with neither, no metrics and a 404; one alone stops the start, naming both. nginx passes /metrics to the backend.

Judgement call, for review: only requests that match a route are recorded, not every request as the conventions show, because the labels are the request path and method, which any client can make up without end.

Model: opus-5-5

Built in https://git.eeqj.de/sneak/netwatch/pulls/103: with both settings set, request metrics through `go-http-metrics` and `GET /metrics` behind basic auth; with neither, no metrics and a 404; one alone stops the start, naming both. nginx passes `/metrics` to the backend. Judgement call, for review: only requests that match a route are recorded, not every request as the conventions show, because the labels are the request path and method, which any client can make up without end. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/netwatch#94