Expose ACME cooldown end time and error details
Operators could see that a rate-limit cooldown was active, but not when it ends, and failure logs omitted most of the CA problem document. Add a until-timestamp gauge and log the full acme.Error surface so cooldowns and ACME responses are diagnosable. Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
@@ -47,10 +47,11 @@ const (
|
||||
)
|
||||
|
||||
type metrics struct {
|
||||
provisionSteps *prometheus.CounterVec
|
||||
acmeErrors *prometheus.CounterVec
|
||||
acmeCooldown prometheus.Gauge
|
||||
stepDuration *prometheus.HistogramVec
|
||||
provisionSteps *prometheus.CounterVec
|
||||
acmeErrors *prometheus.CounterVec
|
||||
acmeCooldown prometheus.Gauge
|
||||
acmeCooldownUntil prometheus.Gauge
|
||||
stepDuration *prometheus.HistogramVec
|
||||
}
|
||||
|
||||
func newMetrics(registerer prometheus.Registerer) *metrics {
|
||||
@@ -91,6 +92,16 @@ func newMetrics(registerer prometheus.Registerer) *metrics {
|
||||
},
|
||||
),
|
||||
),
|
||||
acmeCooldownUntil: registerCollector(
|
||||
registerer,
|
||||
prometheus.NewGauge(
|
||||
prometheus.GaugeOpts{
|
||||
Subsystem: "certmanager",
|
||||
Name: "certificate_acme_cooldown_until_timestamp_seconds",
|
||||
Help: "Unix timestamp when the global ACME rate-limit cooldown ends; 0 when not cooling down.",
|
||||
},
|
||||
),
|
||||
),
|
||||
stepDuration: registerCollector(
|
||||
registerer,
|
||||
prometheus.NewHistogramVec(
|
||||
@@ -173,11 +184,14 @@ func normalizeProblemType(problemType string) string {
|
||||
return suffix
|
||||
}
|
||||
|
||||
func (m *metrics) setCooldown(active bool) {
|
||||
if active {
|
||||
func (m *metrics) setCooldown(until time.Time) {
|
||||
if time.Now().Before(until) {
|
||||
m.acmeCooldown.Set(1)
|
||||
m.acmeCooldownUntil.Set(float64(until.Unix()))
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
m.acmeCooldown.Set(0)
|
||||
m.acmeCooldownUntil.Set(0)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user