Prometheus metrics at /metrics, off unless an operator turns them on #50
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo#50
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Observation
Shape
Off by default, and that is most of the design:
POSTULO_METRICS_ENABLED(defaultfalse) and a switch under Server settings → Monitoring. Off, the address is a plain 404 —
not a 403, which would confirm that something is there.
Clean means the numbers an operator needs to run the instance, and nothing about the
people on it:
postulo_info{version, python, django}— one gauge carrying the build, the conventionalway to expose it.
view's name and never the path, so no company, application id or search text can become
a label.
syncs run and failed.
What is deliberately absent: anything per person, per company or per application. A
metric with somebody's identifier in a label is a record of what they are doing, exported
somewhere else, and calling it monitoring does not change that.
Who may read it: a bearer token (
POSTULO_METRICS_TOKEN) or an allow-list ofaddresses, at the operator's choice. With neither set the endpoint is readable by anybody
who can reach the instance, and the page says exactly that rather than implying it is
protected.
Classification
Enhancement. Not breaking: nothing exists until an operator asks for it.
Depends on
Nothing. It shares the "off unless asked, environment variable or setting" pattern with
#51, and the two switches should live in one Monitoring section.
Open questions
prometheus_client, or write the exposition format by hand? It is a handful of linesfor the text format. Proposal: decide on the answer to the next question first.
shared directory is configured. Whichever way it goes must be documented, because a
graph quietly showing a third of the traffic is worse than no graph at all.