Compare commits

...
Author SHA1 Message Date
Chris Lu a4e5755560 s3: do not serve /metrics on the tenant-facing API port
Eight S3 metric families are labelled with bucket names, so serving the
shared registry on the client-facing S3 listener lets any client that can
reach the port enumerate buckets and their traffic, with no IAM check.
S3 already has a dedicated -metricsPort for this.

Master, volume and filer keep the route: they are internal cluster
services and their metrics carry no tenant identifiers.
2026-09-14 22:21:40 -07:00
Chris Lu ebbc6ed21f s3: expose /metrics on main HTTP port
Allows the admin server to scrape S3 API server metrics without a
separate -metricsPort. Placed alongside /status and /healthz.
2026-09-14 20:41:44 -07:00
Chris Lu 7d9c875599 filer: expose /metrics on main HTTP port
Allows the admin server to scrape filer metrics without a separate
-metricsPort.
2026-09-14 20:41:01 -07:00
Chris Lu 1788119e5a volume: expose /metrics on admin mux
Allows the admin server to scrape volume server metrics from the
admin HTTP port (same port as /status and /healthz).
2026-09-14 20:40:50 -07:00
Chris Lu 58ffa9cbba master: expose /metrics on main HTTP port
Allows the admin server to scrape master metrics without a separate
-metricsPort. Uses the same promhttp.HandlerFor(stats.Gather) pattern
as the admin server's own /metrics endpoint.
2026-09-14 20:40:35 -07:00
3 changed files with 6 additions and 0 deletions
+2
View File
@@ -10,6 +10,7 @@ import (
"sync/atomic"
"time"
"github.com/prometheus/client_golang/prometheus/promhttp"
"github.com/seaweedfs/seaweedfs/weed/credential"
"github.com/seaweedfs/seaweedfs/weed/stats"
"golang.org/x/sync/singleflight"
@@ -260,6 +261,7 @@ func NewFilerServer(defaultMux, readonlyMux *http.ServeMux, option *FilerOption)
if !option.DisableHttp {
defaultMux.HandleFunc("/healthz", requestIDMiddleware(fs.filerHealthzHandler))
defaultMux.HandleFunc("/readyz", requestIDMiddleware(fs.filerHealthzHandler))
defaultMux.Handle("/metrics", promhttp.HandlerFor(stats.Gather, promhttp.HandlerOpts{}))
// TUS resumable upload protocol handler
if option.TusBasePath != "" {
// Normalize TusPath to always have a leading slash and no trailing slash
+2
View File
@@ -14,6 +14,7 @@ import (
"sync"
"time"
"github.com/prometheus/client_golang/prometheus/promhttp"
"github.com/seaweedfs/seaweedfs/weed/cluster/maintenance"
"github.com/seaweedfs/seaweedfs/weed/stats"
"github.com/seaweedfs/seaweedfs/weed/telemetry"
@@ -175,6 +176,7 @@ func NewMasterServer(r *mux.Router, option *MasterOption, peers map[string]pb.Se
handleStaticResources2(r)
r.HandleFunc("/healthz", requestIDMiddleware(ms.healthzHandler)).Methods(http.MethodGet, http.MethodHead)
r.HandleFunc("/readyz", requestIDMiddleware(ms.readyzHandler)).Methods(http.MethodGet, http.MethodHead)
r.Handle("/metrics", promhttp.HandlerFor(stats.Gather, promhttp.HandlerOpts{})).Methods(http.MethodGet)
r.HandleFunc("/", ms.proxyToLeader(requestIDMiddleware(ms.uiStatusHandler)))
r.HandleFunc("/ui/index.html", requestIDMiddleware(ms.uiStatusHandler))
if !ms.option.DisableHttp {
+2
View File
@@ -6,6 +6,7 @@ import (
"sync"
"time"
"github.com/prometheus/client_golang/prometheus/promhttp"
"github.com/seaweedfs/seaweedfs/weed/pb"
"github.com/seaweedfs/seaweedfs/weed/pb/volume_server_pb"
"github.com/seaweedfs/seaweedfs/weed/storage/types"
@@ -142,6 +143,7 @@ func NewVolumeServer(adminMux, publicMux *http.ServeMux, ip string,
adminMux.HandleFunc("/status", requestIDMiddleware(vs.statusHandler))
adminMux.HandleFunc("/healthz", requestIDMiddleware(vs.healthzHandler))
adminMux.HandleFunc("/readyz", requestIDMiddleware(vs.healthzHandler))
adminMux.Handle("/metrics", promhttp.HandlerFor(stats.Gather, promhttp.HandlerOpts{}))
if signingKey == "" || enableUiAccess {
// only expose the volume server details for safe environments
adminMux.HandleFunc("/ui/index.html", requestIDMiddleware(vs.uiStatusHandler))