Class FcMetricsServlet

java.lang.Object
jakarta.servlet.GenericServlet
jakarta.servlet.http.HttpServlet
org.frontcache.metrics.FcMetricsServlet
All Implemented Interfaces:
jakarta.servlet.Servlet, jakarta.servlet.ServletConfig, Serializable

public class FcMetricsServlet extends jakarta.servlet.http.HttpServlet
The Prometheus scrape endpoint, /fc-metrics. This exposes traffic volumes, error rates, circuit state and command names - and, since the JVM binders were added, this node's heap and CPU.

The API key is what protects it

A scrape endpoint is unauthenticated by convention, and this one used to rely on that convention plus a front-cache.management.port check. That check was never a boundary - it compared getServerPort(), which comes from the Host header, so any caller able to reach any connector could ask for Host: host:443 and be served - and it has been removed. Restricting which connector answers management traffic is the reverse proxy's job, not this node's. So when the node has a front-cache.api-key, a scrape must carry it as Authorization: Bearer <key> - which is also the only form Prometheus can send, a scrape_config having no way to set an arbitrary header. A node with no API key configured is open, which is the historical default. Deliberately not /fc-metrics.stream - that name is reserved for the SSE stream's eventual alias, and two endpoints one suffix apart, one a scrape and one an infinite stream, is a support ticket waiting to happen.
See Also:
  • Field Summary

    Fields inherited from class jakarta.servlet.http.HttpServlet

    LEGACY_DO_HEAD
  • Constructor Summary

    Constructors
    Constructor
    Description
     
  • Method Summary

    Modifier and Type
    Method
    Description
    protected void
    doGet(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response)
     

    Methods inherited from class jakarta.servlet.http.HttpServlet

    doDelete, doHead, doOptions, doPost, doPut, doTrace, getLastModified, init, service, service

    Methods inherited from class jakarta.servlet.GenericServlet

    destroy, getInitParameter, getInitParameterNames, getServletConfig, getServletContext, getServletInfo, getServletName, init, log, log

    Methods inherited from class Object

    clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
  • Constructor Details

    • FcMetricsServlet

      public FcMetricsServlet()
  • Method Details

    • doGet

      protected void doGet(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response) throws jakarta.servlet.ServletException, IOException
      Overrides:
      doGet in class jakarta.servlet.http.HttpServlet
      Throws:
      jakarta.servlet.ServletException
      IOException