Repository navigation
fix(metrics): address PR #38 review findings and refresh the dashboard - #39
Merged
Merged
Conversation
Review of the metrics code merged by PR #38, scoped to what is shared with the upstream PR (40 files byte-identical to daeuniverse#1015 head 8573436). Findings: node metrics export proxy credentials through the link label; duplicate node names in a group fail the whole scrape with HTTP 500 (reproduced with client_golang v1.19.1); tcp4(DNS)/tcp6(DNS) series alias tcp4/tcp6 under v2.1.1; plus HELP, BasicAuth, example bind address, TLS permission and health-check counting fixes, each with a minimal patch sketch and the rollout order for daeuniverse#1015 and fork main. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BYykYRdT6p8qLLe4RMiV7s
- Drop dae_node_latency_seconds and dae_node_alive: their link label is the node share link (Trojan password, SS cipher:password, VLESS/VMess ID), and they duplicate the per-dialer health metrics. Revert the NodeLatencySnapshot Name/Group fields they needed. - Keep dialer label sets unique: same-named nodes in one group (common with several subscriptions) get a " #N" suffix. A duplicate label set made promhttp return HTTP 500 for the whole scrape; serve with ContinueOnError so one collector error cannot blank the endpoint. - Export each distinct health collection once via StandardHealthKeys. tcp4(DNS)/tcp6(DNS) alias tcp4/tcp6 in v2.1.1 and doubled every TCP series. Remove the DialerGroup.AliveDialerSets accessor. - Fix the dae_dns_cache_hit_total help: it includes lazy hits. - Require endpoint_username and endpoint_password together; a password alone left the endpoint open. - example.dae: bind the sample endpoint to 127.0.0.1. - TLS files: reject group/other write on the certificate and any group/other access on the key instead of matching exact modes, so 0400 keys and 0600 certificates pass. Remove the unused ValidateFilePermissionNotTooOpen. - Count dae_health_check_total only for checks with a verdict; skips and probe-infrastructure failures diluted the failure ratio. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BYykYRdT6p8qLLe4RMiV7s
…hboard Both fork dashboards queried the removed dae_node_* metrics and treated dae_dns_cache_hit_total as fresh-only (hit + lazy double-counted stale hits). Use the daeuniverse#1015 dashboard (blob 21ce121), which derives fresh hits as hit - lazy and does not use dae_node_*. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BYykYRdT6p8qLLe4RMiV7s
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BYykYRdT6p8qLLe4RMiV7s
Rename it back to "dae Transparent Proxy-Grafana_dashboard.json" and use the same revision as daeuniverse#1015: the sanitized v6 export (no id/version, datasource or group selection), with the network variable listing udp4(DNS)/udp6(DNS), the health check success rate showing No data when no checks ran, and the health check descriptions matching the verdict-only counters. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BYykYRdT6p8qLLe4RMiV7s
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BYykYRdT6p8qLLe4RMiV7s
DNS Benchmark Compare
Suite Status
control_dns_cacheDNS Benchmark Compare
benchstatcomponent_upstream_hotpathDNS Benchmark Compare
benchstat |
1 of 3 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Background
This PR fixes the P0–P2 findings from a review of the metrics code merged in #38. The same metrics code is open upstream as daeuniverse#1015, and the 40 metrics files are byte-identical between the two. The same fix commit has already been pushed to the daeuniverse#1015 head branch
feat/metrics-endpoint-clean(5c9df67).The review report, with evidence and rationale for each finding, is in
.plan/metrics/pr38-upstream-1015-review.md.Checklist
Full Changelogs
3c02657fix(metrics): address review findingsdae_node_latency_secondsanddae_node_alive. Theirlinklabel exported the node share link, which embeds the Trojan password, the SScipher:password, or the VLESS/VMess ID.promhttpfail the whole scrape with HTTP 500. Dialer labels now get a#Nsuffix, and the handler usesContinueOnError.dialer.StandardHealthKeys().tcp4(DNS)/tcp6(DNS)aliastcp4/tcp6in v2.1.1, so every TCP series was duplicated.dae_dns_cache_hit_totalhelp text. The counter includes lazy hits.endpoint_usernameandendpoint_passwordtogether. A password alone silently disabled auth.example.daenow binds the sample endpoint to127.0.0.1.0400keys and0600certs pass. Remove the unusedValidateFilePermissionNotTooOpen.dae_health_check_totalnow counts only checks that reach a verdict.ea9f706,3006758docs(metrics): replace the stale fork dashboards with the v6-based dashboard, which is also used in feat(metrics): add Prometheus /metrics endpoint with DNS, dialer, connection, and runtime stats daeuniverse/dae#1015networkvariable listsudp4(DNS)/udp6(DNS).0fc3f93,d0eebc5,b0fd810docs: the review report and its implementation statusIssue Reference
Follow-up to #38. Mirrors daeuniverse#1015 (
5c9df67,8502e56).Test Result
Local checks used go1.26.0, the CI
GOEXPERIMENTset, and-tags dae_stub_ebpf:go build ./...andgo vetpass.go mod tidyare clean.go testpasses for./pkg/... ./common/... ./component/outbound/... ./cmd ./configand for the metrics tests in./control.TestPrometheusHandlerSurvivesCollectorError: status=500 before.TestCheck_CountersCountOnlyVerdicts: total=3 before.The full Linux runtime suites (go-test, bpf-test, kernel-test) run in CI on this PR.
🤖 Generated with Claude Code
https://claude.ai/code/session_01BYykYRdT6p8qLLe4RMiV7s
Generated by Claude Code