Documentation
¶
Overview ¶
Package metric holds the OpenTelemetry instruments used to observe the audit pipeline. Labels are limited to low-cardinality dimensions (auth_type, decision) so a hostile client cannot explode the metric cardinality; per-subject / per-issuer detection is the job of the Valkey rate store.
Index ¶
- type Metrics
- func (m *Metrics) AddQueueDepth(ctx context.Context, delta int64)
- func (m *Metrics) IncDropped(ctx context.Context)
- func (m *Metrics) IncPanic(ctx context.Context)
- func (m *Metrics) IncRateStoreError(ctx context.Context)
- func (m *Metrics) IncUnauthenticated(ctx context.Context, authType string)
- func (m *Metrics) IncUnauthorized(ctx context.Context, authType, decision string)
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Metrics ¶
type Metrics struct {
// contains filtered or unexported fields
}
Metrics bundles the audit-pipeline instruments. All methods are safe to call on a nil *Metrics (they become no-ops), so call sites need not guard.
func New ¶
New builds the audit instruments from the given meter. When meter is nil the global MeterProvider installed by otlp.Init is used. It returns an error if any instrument fails to register.
func (*Metrics) AddQueueDepth ¶
AddQueueDepth adjusts the current audit queue depth by delta (+1 on enqueue, -1 on drain).
func (*Metrics) IncDropped ¶
IncDropped records an audit event that was dropped due to a full queue.
func (*Metrics) IncRateStoreError ¶
IncRateStoreError records a Valkey rate-store failure.
func (*Metrics) IncUnauthenticated ¶
IncUnauthenticated records an observed unauthenticated result.