Skip to main content

Module telemetry

Module telemetry 

Source
Expand description

Metrics facade and logging hygiene (PRD §8 M0: tracing, metrics, redaction).

Metrics is a plain trait rather than a dependency on the metrics crate, so the core stays backend-free on wasm32; the native binary bridges it to the metrics facade (planner default Q20).

Two header lists govern credentials (SPEC-TRANSPORT-CONNECT §5.1): NEVER_ECHO names request credentials a response never carries, and NEVER_LOG adds the receipts and signatures that a response may pass through to the client but that must stay out of logs, traces and error messages. Redactor extends NEVER_LOG with deployment-configured names, such as the headers an admission helper attaches.

Modules§

pressure
Physical storage pressure and alert bookkeeping shared by adapters. Alert on physical bytes against the put soft limit. No storage I/O or wall clock is hidden here: callers supply measurements and time.

Structs§

NoopMetrics
A Metrics sink that discards everything.
Redactor
Log redaction policy: NEVER_LOG plus names the deployment adds, for example its configured admission_headers. The default redacts NEVER_LOG only.

Constants§

METRIC_INDEX_LOOKUP_CAPPED
Counter: an object index lookup hit a bounded-work cap. Label: reason.
METRIC_INDEX_REJECTED_WRITE_FAILED
Counter: a content rejection could not be persisted in verification state.
METRIC_INDEX_SLICE_SUBREQUESTS
Gauge: subrequests the last scheduled-verification slice spent (WP-4.8).
METRIC_INSPECTION_CALLS
Counter: synchronous inspector calls. Label: result.
METRIC_LATENCY
Histogram: request latency in milliseconds. Labels: procedure.
METRIC_NAMESPACE_QUOTA_REBASE
Counter: a restored shard’s cumulative contribution was re-baselined.
METRIC_NAMESPACE_QUOTA_ROLLUP_ERROR
Counter: a quota rollup failed. Label: reason.
METRIC_NAMESPACE_QUOTA_VIEW_FALLBACK
Namespace quota writes admitted with no recent coordinator view.
METRIC_REF_POLICY_ANCESTRY_UNCHECKED
Counter: a fast-forward check ended unproven (a walk or lookup cap, the decode budget or a corrupt member) and its write was denied. Label: reason.
METRIC_RELAY_BACKLOG_ROWS
Gauge: source outbox rows inspected in the current relay window.
METRIC_RELAY_LAG_EXCEEDED
Counter: an outbox row exceeded the relay lag bound. Label: source_kind.
METRIC_RELAY_LEASE_LAG
Counter: an expired shard lease remains kept beyond the relay lag bound.
METRIC_REQUESTS
Counter: requests handled. Labels: procedure, code.
METRIC_UPLOAD_BYTES
Counter: accepted upload bytes.
NEVER_ECHO
Request credentials that are never set on a response, compared ignoring ASCII case. Every entry is also in NEVER_LOG.
NEVER_LOG
Header names whose values never reach a log, trace or error message, compared ignoring ASCII case: NEVER_ECHO plus payment receipts, the auth v2 signature and Set-Cookie. A response may still carry the receipts (SPEC-TRANSPORT-CONNECT §5.1).
REDACTED_VALUE
The placeholder logged in place of a redacted header value.

Traits§

Metrics
Metrics sink. Label values are borrowed so a hot path allocates nothing.

Functions§

is_never_echo
Whether name is in NEVER_ECHO, ignoring ASCII case.
is_never_log
Whether name is in NEVER_LOG, ignoring ASCII case.