ecluse:ecluse-runtime
Safe HaskellNone
LanguageGHC2021

Ecluse.Runtime.Telemetry.Tracing.Internal

Description

The middleware, the manager settings, the domain-span brackets and the attribute mappings behind Ecluse.Runtime.Telemetry.Tracing, which documents the tracing layer and re-exports the curated surface. Importing this module opts out of that stability promise, the convention text and bytestring use, so production code imports the public one.

Synopsis

WAI server span

telemetryWaiMiddleware :: Telemetry -> IO Middleware Source #

Build the WAI server-span middleware, or id when telemetry is disabled. It belongs outermost in the stack, so the span covers the whole request (see Ecluse.Runtime.Server).

http-client data-plane instrumentation

instrumentDataPlaneManagerSettings :: Telemetry -> ManagerSettings -> IO ManagerSettings Source #

Instrument a data-plane ManagerSettings so upstream fetches open a client span and carry W3C trace-context headers. Return the settings untouched when telemetry is disabled.

dataPlaneInstrumentationConfig :: HttpClientInstrumentationConfig Source #

The http-client instrumentation configuration for the data plane. It records no request or response headers, so an Authorization header never reaches a span.

Domain spans

withRuleEvalSpan :: MonadUnliftIO m => Telemetry -> PackageName -> Version -> m (a, ServeDecision) -> m a Source #

Run a rule-evaluation domain span around an action that yields its result and the verdict to record (ruleVerdictFields).

withMirrorEnqueueSpan :: MonadUnliftIO m => Telemetry -> PackageName -> Version -> Text -> (a -> Maybe Text) -> (Maybe RemoteSpanContext -> m a) -> m a Source #

Run a mirror-enqueue Producer span, handing the body this span's trace context to stamp onto the job. It records the artifact authority alone: a URL can carry a credential in userinfo or query.

withMirrorJobSpan :: MonadUnliftIO m => Telemetry -> PackageName -> Version -> Maybe RemoteSpanContext -> (a -> JobSpanOutcome) -> m a -> m a Source #

Run a mirror-worker-job Consumer span around the worker's fetch, verify, and publish, linking back to the enqueueing producer span through the carried trace context.

withAdvisorySyncSpan :: MonadUnliftIO m => Telemetry -> Ecosystem -> (a -> AdvisorySyncResult) -> m a -> m a Source #

Run an advisory-sync Internal span around one sync attempt. The ecosystem and the result are the vocabulary the ecluse.advisory.sync.* metrics label with, so a trace and a series join on one.

The core tracing ports

tracingPortOf :: Telemetry -> TracingPort Source #

Project this module's serve-path spans onto the core TracingPort the pipeline brackets with.

workerTracingPortOf :: Telemetry -> WorkerTracingPort Source #

Project withMirrorJobSpan onto the core WorkerTracingPort that Ecluse.Core.Worker uses.

advisorySyncTracingPortOf :: Telemetry -> AdvisorySyncTracingPort Source #

Project withAdvisorySyncSpan onto the core AdvisorySyncTracingPort that Ecluse.Runtime.Cve.Sync brackets through. Inert when telemetry is disabled.

Verdict attribute mapping

ruleVerdictFields :: ServeDecision -> [(Text, Text)] Source #

Map a serve verdict to the rule-evaluation span's attribute fields. None can carry a secret: the rule name and reason class are a closed vocabulary, and the message is the rendered decision.