Class FcMetricsServlet
java.lang.Object
jakarta.servlet.GenericServlet
jakarta.servlet.http.HttpServlet
org.frontcache.metrics.FcMetricsServlet
- All Implemented Interfaces:
jakarta.servlet.Servlet, jakarta.servlet.ServletConfig, Serializable
public class FcMetricsServlet
extends jakarta.servlet.http.HttpServlet
The Prometheus scrape endpoint,
/fc-metrics.
This exposes traffic volumes, error rates, circuit state and command names - and, since the JVM
binders were added, this node's heap and CPU.
The API key is what protects it
A scrape endpoint is unauthenticated by convention, and this one used to rely on that convention plus afront-cache.management.port check. That check was never a boundary - it compared
getServerPort(), which comes from the Host header, so any caller able to reach any connector
could ask for Host: host:443 and be served - and it has been removed. Restricting which
connector answers management traffic is the reverse proxy's job, not this node's.
So when the node has a front-cache.api-key, a scrape must carry it as
Authorization: Bearer <key> - which is also the only form Prometheus can send, a
scrape_config having no way to set an arbitrary header. A node with no API key configured is open,
which is the historical default.
Deliberately not /fc-metrics.stream - that name is reserved for the SSE stream's eventual
alias, and two endpoints one suffix apart, one a scrape and one an infinite stream, is a support
ticket waiting to happen.- See Also:
-
Field Summary
Fields inherited from class jakarta.servlet.http.HttpServlet
LEGACY_DO_HEAD -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionprotected voiddoGet(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response) Methods inherited from class jakarta.servlet.http.HttpServlet
doDelete, doHead, doOptions, doPost, doPut, doTrace, getLastModified, init, service, serviceMethods inherited from class jakarta.servlet.GenericServlet
destroy, getInitParameter, getInitParameterNames, getServletConfig, getServletContext, getServletInfo, getServletName, init, log, log
-
Constructor Details
-
FcMetricsServlet
public FcMetricsServlet()
-
-
Method Details
-
doGet
protected void doGet(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response) throws jakarta.servlet.ServletException, IOException - Overrides:
doGetin classjakarta.servlet.http.HttpServlet- Throws:
jakarta.servlet.ServletExceptionIOException
-