Documentation
¶
Overview ¶
Package middleware provides HTTP middleware shared between AI Studio and the Microgateway.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func MetricsBearerAuth ¶
func MetricsBearerAuth(token string) gin.HandlerFunc
MetricsBearerAuth returns middleware that requires "Authorization: Bearer <token>" on the metrics endpoint. Token comparison is constant-time.
func RegisterMetricsEndpoint ¶
func RegisterMetricsEndpoint(router gin.IRoutes, cfg MetricsEndpointConfig) bool
RegisterMetricsEndpoint mounts the metrics handler with secure defaults:
- AuthToken set: endpoint requires a matching bearer token
- AllowUnauthenticated true: endpoint is served without auth
- neither: endpoint is not registered at all
Returns true if the endpoint was registered.
Types ¶
type MetricsEndpointConfig ¶
type MetricsEndpointConfig struct {
// Path is the route path the handler is mounted on, e.g. "/metrics".
Path string
// Handler serves the metrics (typically a Prometheus handler). If nil,
// the endpoint is not registered.
Handler http.Handler
// AuthToken, when non-empty, protects the endpoint with bearer auth.
AuthToken string
// AllowUnauthenticated serves the endpoint without auth when no token is
// set (e.g. for in-cluster Prometheus scraping behind a network boundary).
AllowUnauthenticated bool
// Warn, if non-nil, is called with security-relevant warnings so each
// service can route them through its own logger.
Warn func(msg string)
}
MetricsEndpointConfig configures RegisterMetricsEndpoint.
Click to show internal directories.
Click to hide internal directories.