-
Notifications
You must be signed in to change notification settings - Fork 82
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
【腾讯犀牛鸟开源课题实战】prometheus插件专项建设(PUSH模式支持等) #175
Changes from 10 commits
809dfe0
ccfc856
8a1de0e
c879973
e1916f8
b980723
7f42fbd
cd24612
816bc28
3d907d6
2309769
1a5bb30
8cb45d4
a931cfc
3a9fe81
35ef136
f87a954
973bf4b
18dc6d7
919b8b3
c986e4f
12afca9
16b5b8c
078f31d
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -44,3 +44,13 @@ cc_library( | |
"@trpc_cpp//trpc/metrics/prometheus:prometheus_metrics_api", | ||
], | ||
) | ||
|
||
cc_binary( | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 不需要push这个文件,去掉与之相关的编译引入 |
||
name = "push", | ||
srcs = ["push.cc"], | ||
deps = [ | ||
"@trpc_cpp//trpc/metrics/prometheus:prometheus_metrics_api", | ||
"@trpc_cpp//trpc/log:trpc_log", | ||
|
||
], | ||
) |
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -77,6 +77,12 @@ ::trpc::Status ForwardServiceImpl::Route(::trpc::ServerContextPtr context, | |
"counter_name", "counter_desc", {{"const_counter_key", "const_counter_value"}}); | ||
::prometheus::Counter& counter = counter_family->Add({{"counter_key", "counter_value"}}); | ||
counter.Increment(random_num); | ||
|
||
if (::trpc::prometheus::PushMetricsInfo()) { | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 为啥这里还需要手动调用呢?不能配置一下yaml文件就生效吗? |
||
TRPC_FMT_INFO("Successfully pushed metrics to Pushgateway"); | ||
} else { | ||
TRPC_FMT_ERROR("Failed to push metrics to Pushgateway"); | ||
} | ||
#endif | ||
|
||
auto client_context = ::trpc::MakeClientContext(context, greeter_proxy_); | ||
|
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,22 @@ | ||
#include <chrono> | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 这个文件和框架无关,没必要增加,用法放在文档就好了 |
||
#include <thread> | ||
#include "trpc/metrics/prometheus/prometheus_metrics_api.h" | ||
#include "trpc/log/trpc_log.h" | ||
|
||
|
||
|
||
int main(int argc, char** argv) { | ||
|
||
while (true) { | ||
if (::trpc::prometheus::PushMetricsInfo()) | ||
{ | ||
std::cout << "Successfully pushed metrics to Pushgateway" << std::endl; | ||
} else { | ||
std::cerr << "Failed to push metrics to Pushgateway" << std::endl; | ||
} | ||
|
||
std::this_thread::sleep_for(std::chrono::seconds(5)); // 每60秒推送一次 | ||
} | ||
|
||
return 0; | ||
} |
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -44,6 +44,11 @@ plugins: | |
const_labels: | ||
const_key1: const_value1 | ||
const_key2: const_value2 | ||
push_mode: | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 例子需要演示pull模式和push模式,应该给出2个文件配置 |
||
enabled: true | ||
gateway_url: "http://pushgateway:9091" | ||
job_name: "test_job" | ||
push_interval_seconds: 2 | ||
log: | ||
default: | ||
- name: default | ||
|
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -18,12 +18,68 @@ | |
|
||
namespace trpc::admin { | ||
|
||
PrometheusHandler::PrometheusHandler() { description_ = "[GET /metrics] get prometheus metrics"; } | ||
PrometheusHandler::PrometheusHandler() { | ||
description_ = "[GET /metrics] get prometheus metrics"; | ||
bool ret = TrpcConfig::GetInstance()->GetPluginConfig<PrometheusConfig>( | ||
"metrics", trpc::prometheus::kPrometheusMetricsName, prometheus_conf_); | ||
if (!ret) { | ||
TRPC_LOG_WARN( | ||
"Failed to obtain Prometheus plugin configuration from the framework configuration file. Default configuration " | ||
"will be used."); | ||
} | ||
Init(); | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 构造函数别执行太复杂的事情,Init不能放在外面执行吗? There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 已修改。 |
||
} | ||
|
||
void PrometheusHandler::Init() { | ||
auto& cfg = prometheus_conf_.auth_cfg; | ||
if (cfg.count("username") && cfg.count("password")) { | ||
auth_conf_.username = cfg["username"]; | ||
auth_conf_.password = cfg["password"]; | ||
} else { | ||
TRPC_LOG_INFO("can not found prometheus auth config"); | ||
} | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 构造函数做了太复杂的事情,可以定义一个Init函数,把这部分逻辑放在Init函数里 There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 已修改。 |
||
} | ||
|
||
void PrometheusHandler::CommandHandle(http::HttpRequestPtr req, rapidjson::Value& result, | ||
rapidjson::Document::AllocatorType& alloc) { | ||
static std::unique_ptr<::prometheus::Serializer> serializer = std::make_unique<::prometheus::TextSerializer>(); | ||
|
||
if (auth_conf_.username.size() && auth_conf_.password.size()) { | ||
std::string token = req->GetHeader("Authorization"); | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 这块逻辑有啥用?看起来只是判断用户名和密码是否匹配,判断之后有啥用? There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 只有用户名密码都正确的情况下,才会返回metric数据,否则拒绝请求。 There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 用户名和密码,在prometheus的gateway服务哪里能配置呢?文档有给出吗? There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 想起来了,这是pull模式的,那用户名和密码在prometheus服务器里哪里能配置呢? There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 文档我还没有写,确认一下,Prometheus鉴权相关的使用方法是直接添加在prometheus_metrics.md吗? There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 可以的 |
||
auto splited = Split(token, ' '); | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 鉴权部分单独提出一个类私有成员接口 There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 已修改。 |
||
if (splited.size() != 2) { | ||
result.AddMember("message", "wrong request without authorization", alloc); | ||
TRPC_LOG_INFO("error token: " << token); | ||
return; | ||
} | ||
if (splited[0] != "Basic") { | ||
result.AddMember("message", "wrong request without right auth", alloc); | ||
TRPC_LOG_INFO("error token: " << token); | ||
return; | ||
} | ||
|
||
std::string username_pwd = http::Base64Decode(std::begin(splited[1]), std::end(splited[1])); | ||
auto sp = Split(username_pwd, ':'); | ||
if (sp.size() != 2) { | ||
result.AddMember("message", "wrong request without authorization", alloc); | ||
TRPC_LOG_INFO("error token: " << token); | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 使用错误日志宏 TRPC_FMT_ERROR There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 已修改。 |
||
return; | ||
weimch marked this conversation as resolved.
Show resolved
Hide resolved
|
||
} | ||
|
||
auto username = sp[0]; | ||
if (username != auth_conf_.username) { | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 用户名和密码应该一起判断,如果不对,统一返回 wrong username or password 的信息,现在这种实现,攻击者能猜对用户名 There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 已修改。 |
||
result.AddMember("message", "wrong request without right username", alloc); | ||
TRPC_LOG_INFO("error username: " << username << ",right username: " << auth_conf_.username); | ||
return; | ||
} | ||
auto pwd = sp[1]; | ||
if (pwd != auth_conf_.password) { | ||
result.AddMember("message", "wrong request without right password", alloc); | ||
TRPC_LOG_INFO("error password: " << pwd << ",right password: " << auth_conf_.password); | ||
return; | ||
} | ||
} | ||
|
||
std::string prometheus_str = serializer->Serialize(trpc::prometheus::Collect()); | ||
result.AddMember(rapidjson::StringRef("trpc-html"), rapidjson::Value(prometheus_str, alloc).Move(), alloc); | ||
} | ||
|
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -16,6 +16,12 @@ | |
|
||
#include "trpc/admin/admin_handler.h" | ||
#include "trpc/util/prometheus.h" | ||
#include "trpc/util/http/base64.h" | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 用clang-format格式化一下,头文件顺序需要按照字母序顺序排列 There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 已修改。 |
||
#include "trpc/util/string/string_helper.h" | ||
#include "trpc/util/time.h" | ||
#include "trpc/log/trpc_log.h" | ||
#include "trpc/metrics/prometheus/prometheus_metrics.h" | ||
#include "trpc/common/config/trpc_config.h" | ||
|
||
namespace trpc::admin { | ||
|
||
|
@@ -26,6 +32,15 @@ class PrometheusHandler : public AdminHandlerBase { | |
|
||
void CommandHandle(http::HttpRequestPtr req, rapidjson::Value& result, | ||
rapidjson::Document::AllocatorType& alloc) override; | ||
private: | ||
void Init(); | ||
|
||
PrometheusConfig prometheus_conf_; | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 还是不理解鉴权相关的参数放admin服务的意图,可以描述下 There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 因为Prometheus拉取数据是要走admin服务的,我感觉只有在这里才能拿到http包头中的用户名密码信息,才能进行鉴权。 There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 看实现,只需要填充username和password就好了吧?不需要保留prometheus_conf_,只需要填充CommandHandle里的username和password字段 There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 已修改。 |
||
|
||
struct AuthConf { | ||
std::string username; | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 为啥不使用token的方式来鉴权呢? There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 是可以使用token,一开始的实现也是token,但是我查了资料,pushgateway没办法用token来鉴权。所以如果pull模式用token的话,就相当于是两套鉴权模式了。 There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. push和pull确实是两套鉴权模式吧,配置区分开就好 There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 实现了一版两套鉴权模式的,但是发现Prometheus配置最多只能同时存在一种鉴权机制(否则Prometheus服务器会启动不了),所以应该只能按照现在这样pull和push都通过一套机制鉴权。 There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 没懂你意思,我的意思是,这里并不要求push和pull功能同时启用,一个server在prometheus的push或pull两种模式选择一个,他能在选择的模式下进行鉴权。如果选择push模式,则用push模式鉴权的配置,如果选择pull模式,则用pull模式鉴权的配置。 你可以举个例子来说明你得意思 There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 意思是prometheus插件不会同时使用pull和push模式吗?如果需要同时使用pull和push,那么就只能统一通过账号密码的方式;否则就是如果一个server使用pull模式,那prometheus服务器的配置就是配置token,如果这个server切换成push模式,那prometheus服务器配置也要手动修改为用户名密码。 There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 对的,不会同时使用pull和push,一般这种切换是架构层面的事情,改动配置没什么问题 |
||
std::string password; | ||
} auth_conf_; | ||
}; | ||
|
||
} // namespace trpc::admin | ||
|
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -71,7 +71,7 @@ class Plugin : public RefCounted<Plugin> { | |
|
||
/// @brief Stop the runtime environment of the plugin | ||
virtual void Stop() noexcept {} | ||
|
||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 记得用clang-format把所有代码文件都格式化一遍(使用项目根目录的.clang-format配置的格式化规范) There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 这里出现了不必要的空格 |
||
/// @brief destroy plugin internal resources | ||
virtual void Destroy() noexcept {} | ||
|
||
|
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -9,6 +9,16 @@ filegroup( | |
]), | ||
) | ||
|
||
cc_library( | ||
name = "prometheus_pusher", | ||
srcs = ["prometheus_pusher.cc"], | ||
hdrs = ["prometheus_pusher.h"], | ||
deps = [ | ||
"//trpc/util/log:logging", | ||
"@com_github_jupp0r_prometheus_cpp//push", | ||
], | ||
) | ||
|
||
cc_library( | ||
name = "prometheus_conf", | ||
srcs = ["prometheus_conf.cc"], | ||
|
@@ -73,15 +83,20 @@ cc_library( | |
":prometheus_conf", | ||
":prometheus_conf_parser", | ||
"//trpc/util:prometheus", | ||
"@com_github_jupp0r_prometheus_cpp//core", | ||
|
||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 不必要的换行,BUILD文件使用 buildifier 格式化一下 |
||
"//trpc/common/config:trpc_config", | ||
":prometheus_pusher", | ||
"//trpc/metrics", | ||
] + select({ | ||
"//conditions:default": [], | ||
"//trpc:trpc_include_prometheus": [ | ||
"@com_github_jupp0r_prometheus_cpp//pull", | ||
"@com_github_jupp0r_prometheus_cpp//push", | ||
], | ||
"//trpc:include_metrics_prometheus": [ | ||
"@com_github_jupp0r_prometheus_cpp//pull", | ||
"@com_github_jupp0r_prometheus_cpp//push", | ||
], | ||
}), | ||
) | ||
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
默认关闭prometheus,这行可以删掉