1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
//! `[metrics]` — the Prometheus exposition endpoint.
use Deserialize;
/// Governs the metrics listener and the `GET /metrics` it serves.
///
/// A **third socket**, not a route on either of the other two, and that is the
/// whole design: a scrape is a different network stream from ACME traffic and
/// from the web admin, so it gets its own port and its own firewall rules. That
/// is also what settles the authentication question — the endpoint carries no
/// session and needs none, because reaching the port at all is the permission.
/// Putting it on the ACME listener would have meant an unauthenticated route on
/// a public socket; putting it on the admin listener would have meant an
/// explicit auth exemption on a listener whose rule is that every route but
/// sign-in needs a session, plus coupling metrics to the panel being enabled.
///
/// Process-wide, so deliberately absent from `PROFILE_SECTIONS`: there is one
/// counter set for the process, and the endpoint is a *dimension* of it rather
/// than something each endpoint configures for itself. A per-profile switch
/// would mean a scrape whose totals silently omitted whichever profiles had it
/// off.
///
/// There is deliberately no `path` key. `/metrics` is the convention every
/// scrape configuration already assumes, and this listener serves nothing else,
/// so making it configurable would buy a way to get it wrong and nothing else.
///
/// There is deliberately no `[metrics.tls]` either, unlike `[server.tls]` and
/// `[admin.tls]`. Those two carry a client's signed requests and an operator's
/// session cookie; a scrape carries no credential and the exposition contains
/// no secret. If it ever needs to cross an untrusted network, that is the point
/// to add one rather than now.