Instance name on process log lines and every metric (closes #91)
check / check (push) Waiting to run

Process log lines carry instance, as request lines do; the instance name
is read before the other settings, so the line saying a setting is
invalid carries it too. Every metric, Go's and the process's included,
carries the label instance, set once on the registry. README.md says so,
and that Prometheus keeps it as exported_instance unless the scrape sets
honor_labels.

Tests that read metrics expect the label. One test helper replaces the
two alert tests' loops that wait for the metrics.

Judgement call: the label is named instance, as in the log lines and
alerts, although Prometheus gives each target a label of that name.

Model: opus-5-5
This commit is contained in:
2026-10-07 04:16:39 +00:00
parent 70a8ea1b92
commit 5ceef3edf3
14 changed files with 232 additions and 120 deletions
+10 -2
View File
@@ -210,7 +210,8 @@ effective settings are logged at start.
`https`, a host and an optional port, and nothing more.
- `SWWAF_INSTANCE_NAME` (default: the host's name, which docker sets to the
first 12 characters of the container's id unless the deployment names one):
the name each request log line gives as `instance`. Set it, for example to
the name every log line and alert gives as `instance`, and every metric
carries as its label `instance` (see "Metrics" below). Set it, for example to
`fsn1app1/gitea`, for a name that stays the same when a deploy replaces the
container, and that tells instances apart when several log to one place.
- `SWWAF_MODE` (default `enforce`): `enforce`, or `observe` to pass on the
@@ -513,7 +514,7 @@ A field that does not apply to a request is left out of its line, apart from
No body is logged, and no header but those above. `smallwebwaf`'s own messages
(start, the settings, stop, errors) share the stream as JSON lines marked
`"type":"process"`.
`"type":"process"`, each with `instance` as a request's line has it.
Go's HTTP server, on which `smallwebwaf` is built, reads a request's line and
headers before `smallwebwaf` sees the request, and some requests end there,
@@ -897,6 +898,13 @@ empty directory or set `SWWAF_RULES_ENABLED=false`.
format, for a scraper that sends `SWWAF_METRICS_TOKEN`, through traefik like any
other request. No metric carries a client's address.
Every metric below, Go's and the process's included, carries the label
`instance`, `SWWAF_INSTANCE_NAME`, as a constant label set once on the registry
the metrics are kept in, rather than as a label each metric declares. Prometheus
gives each series it scrapes an `instance` label of its own, the address it
scraped, and keeps this one as `exported_instance` unless the scrape sets
`honor_labels: true`.
- `smallwebwaf_requests_total`, `smallwebwaf_request_bytes_total` and
`smallwebwaf_response_bytes_total`: requests, and their body bytes each way,
by `status_class`, such as `2xx`, or `none` when nothing was sent, and by