Send fx's own events through the service's logger (closes #183)
check / check (push) Successful in 3m14s

fx printed its dependency graph and lifecycle hooks through its own console logger on standard error, so an operator shipping the JSON log to a collector got a second shape on a second stream for every start. The production app now passes fx.WithLogger with a small FxLogger in internal/logger that writes fx's events through the service's logger: graph events at debug, lifecycle at info, failures at error. Its constructor takes the configuration, so DEBUG=true applies before fx replays the events it held back. go.uber.org/fx moves from v1.20.1 to v1.24.0. Tests keep fx.NopLogger. The README says a failure before the logger exists, and the Go runtime's own output, still go to standard error as plain text.

Model: opus-5-5
This commit was merged in pull request #443.
This commit is contained in:
2026-10-02 17:22:05 +02:00
parent c22ca6218e
commit 385fbc1a6a
7 changed files with 238 additions and 40 deletions
+19 -14
View File
@@ -557,8 +557,8 @@ If it is lost, run `webhooker resetpw admin` on a stopped deployment.
```
It is a banner rather than a log line because that is the only time it
is ever shown: as one `INFO` record it sat among the roughly 45 fx
`PROVIDE`/`RUN`/`HOOK` lines a boot writes, and under `docker run -d`
is ever shown: as one `INFO` record it would sit among the records fx
writes as each start hook runs, and under `docker run -d`
it is one line in a log subject to rotation. The database stores only
its Argon2id hash. There is no second account and no forgot-password
flow, so the banner and the reset command below are the only two ways
@@ -628,7 +628,8 @@ Changing a password you still know needs none of this — use
`DEBUG=true` lowers the log level to `DEBUG`, which turns on every
statement GORM runs, the two by-design lookup misses on the
unauthenticated routes, and the rate limiter's own rejections. It is
unauthenticated routes, the rate limiter's own rejections, and fx's
records of building the dependency graph at startup. It is
meant to be safe to turn on while diagnosing a live service and safe to
paste the output of into a bug report.
@@ -2637,16 +2638,20 @@ read as more than it is:
that type on a specific webhook, and each line it writes is bounded
per event by the 1 MB receiver body cap. Adding one is a decision to
spend log volume on that webhook's payloads.
- **Two writers that do not go through `internal/logger` at all**, both
on standard error. `fx` prints the dependency graph and the lifecycle
hooks through its default console logger at startup and shutdown —
nothing calls `fx.WithLogger`, and `fx.New` builds that logger over
`os.Stderr`. The Go runtime writes a panic or a fatal error itself; a
panic in a background worker rather than in a request handler is the
case that reaches it, since nothing recovers those. Neither carries a
client-chosen value at a client-chosen length: the five `panic` calls
in this service are invariant guards over constants and over
`crypto/rand`.
- **The Go runtime**, which does not go through `internal/logger`. The
runtime writes an unrecovered panic or a fatal error itself, as plain
text on standard error, and that output cannot be redirected. A panic
in a background worker rather than in a request handler is the case
that reaches it, since nothing recovers those. It carries no
client-chosen value at a client-chosen length: the service's own
`panic` calls are invariant guards over constants and over
`crypto/rand`, apart from the one that hands `http.ErrAbortHandler`
back to `net/http`, described below.
- **A failure before fx's logger is built**, such as an invalid
configuration value. fx's logger takes the configuration, so when
that fails fx's own console logger still prints the failure as plain
text on standard error. Its values come from the operator's
environment, not from a client.
- **`net/http`'s own faults**, which are _not_ a separate writer.
`internal/server/http.go` builds its server with a nil `ErrorLog`, so
`net/http` falls back to the `log` package's default logger — and
@@ -2996,7 +3001,7 @@ webhooker/
│ ├── lifecycle/
│ │ └── lifecycle.go # Shared stop-hook waiter, bounded by the stop context
│ ├── logger/
│ │ └── logger.go # slog setup with TTY detection
│ │ └── logger.go # slog setup with TTY detection; fx's event logger
│ ├── metrics/
│ │ └── metrics.go # Delivery Prometheus collectors, labelled by target type
│ ├── middleware/