Expose ACME cooldown end time and error details

Operators could see that a rate-limit cooldown was active, but not
when it ends, and failure logs omitted most of the CA problem
document. Add a until-timestamp gauge and log the full acme.Error
surface so cooldowns and ACME responses are diagnosable.

Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
Ludovic Vielle
2026-07-22 15:50:09 +02:00
parent 6313278c0d
commit cbd0387490
4 changed files with 99 additions and 32 deletions

View File

@@ -47,10 +47,11 @@ const (
)
type metrics struct {
provisionSteps *prometheus.CounterVec
acmeErrors *prometheus.CounterVec
acmeCooldown prometheus.Gauge
stepDuration *prometheus.HistogramVec
provisionSteps *prometheus.CounterVec
acmeErrors *prometheus.CounterVec
acmeCooldown prometheus.Gauge
acmeCooldownUntil prometheus.Gauge
stepDuration *prometheus.HistogramVec
}
func newMetrics(registerer prometheus.Registerer) *metrics {
@@ -91,6 +92,16 @@ func newMetrics(registerer prometheus.Registerer) *metrics {
},
),
),
acmeCooldownUntil: registerCollector(
registerer,
prometheus.NewGauge(
prometheus.GaugeOpts{
Subsystem: "certmanager",
Name: "certificate_acme_cooldown_until_timestamp_seconds",
Help: "Unix timestamp when the global ACME rate-limit cooldown ends; 0 when not cooling down.",
},
),
),
stepDuration: registerCollector(
registerer,
prometheus.NewHistogramVec(
@@ -173,11 +184,14 @@ func normalizeProblemType(problemType string) string {
return suffix
}
func (m *metrics) setCooldown(active bool) {
if active {
func (m *metrics) setCooldown(until time.Time) {
if time.Now().Before(until) {
m.acmeCooldown.Set(1)
m.acmeCooldownUntil.Set(float64(until.Unix()))
return
}
m.acmeCooldown.Set(0)
m.acmeCooldownUntil.Set(0)
}