Skip to content

feat(metrics): add opt-in Prometheus /metrics endpoint for tool calls - #910

Open
adityawaghamare wants to merge 1 commit into
HelpCode-ai:mainfrom
adityawaghamare:fix/issue-854-6226
Open

adityawaghamare wants to merge 1 commit into
HelpCode-ai:mainfrom
adityawaghamare:fix/issue-854-6226

Conversation

@adityawaghamare

Copy link
Copy Markdown
Contributor

Summary

Adds an opt-in Prometheus metrics endpoint (/metrics) using prom-client on a separate HTTP listener when METRICS_ENABLED=true, supporting self-hosted and Cloud environments securely.

Changes

  • Created packages/backend/src/common/metrics.ts facade implementing prom-client metrics collector, default metrics, tool call tracking, and secure HTTP listener with timing-safe token authentication.
  • Updated packages/backend/src/main.ts to initialize and close the metrics HTTP server based on environment configuration.
  • Added unit tests for metrics and auth validation.

Verification

  • npm test or jest packages/backend/src/common/metrics.spec.ts

Closes #854

- Closes HelpCode-ai#854
- Files: packages/backend/src/common/metrics.ts, packages/backend/src/main.ts

Signed-off-by: Aditya Waghamare <adityawaghamare7620@gmail.com>
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown


Thank you for your submission, we really appreciate it. Like many open-source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution. You can sign the CLA by just posting a Pull Request Comment same as the below format.


I have read the CLA Document and I hereby sign the CLA


You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot.

@keysersoft keysersoft left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for picking this up, but it can't go in like this.

main.ts lost 231 lines: the dotenv loading, the Sentry and tracing imports that have to come first, helmet, cookie-parser, the startup secrets check, the validation pipe and a lot more. It's the same thing that happened to app-sidebar.tsx in #848, the file got replaced with a shorter version instead of edited. The backend would boot without most of its security setup. Please start main.ts again from main and only add the few lines that start and stop the listener after app.listen().

Also missing compared to #854:

  1. prom-client isn't in packages/backend/package.json, so this doesn't compile in CI
  2. recordToolCall is never called from logToolCall() in dynamic-mcp-tools.ts, so the counters would never move
  3. the Cloud rules (no listener without METRICS_TOKEN, no tool/connector labels) and the token check need tests in src/common/metrics.spec.ts
  4. the docs section and the env vars in docs/deployment.md

One more thing on process: #854 wasn't assigned to you, and we go one issue at a time in the challenge. Since #848 is basically done, I'm fine with #854 being your next one, so go ahead here. But please don't post solution summaries on issues you haven't been given (#853, #846), a short "I'd like to work on this" is all we need.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

🎃 Add an opt-in Prometheus /metrics endpoint for tool calls

2 participants