feat(monitoring): access logging on the monitoring Caddy (real client IPs, #100) #156

Sammanfogat
supernaut sammanfogade 1 incheckning från fix/100-monitoring-caddy-access-log in i main 2026-07-19 21:41:16 +00:00
Ägare

Follow-up to #154 (#100 socket activation). The monitoring Caddy had no access-log directive, so real client IPs — now that socket activation delivers them — weren't observable, and the "access logs" the issue referenced didn't actually exist.

Change

Add an (access_log) snippet (JSON → stdout → container log → Loki) and import it in all three hosts (grafana/stats/ntfy).

Verified live

Applied --tags monitoring (clean restart — the socket already owns 80/443, no EADDRINUSE). Three external probes from a known public IP produced:

"remote_ip":"155.4.69.98" ... "host":"grafana.gitborg.se" ... "status":200   ×3

plus other genuine external clients (155.4.244.250, 185.213.154.181) — and zero pasta 10.x bridge addresses in remote_ip. That's the literal confirmation that #100's socket activation delivers real client IPs; request attribution + GoatCounter analytics are now correct.

Note: this was applied ahead of merge to complete the #100 verification (with downtime OK'd). Merging syncs main with prod.

Refs #100.

Follow-up to #154 (#100 socket activation). The monitoring Caddy had **no access-log directive**, so real client IPs — now that socket activation delivers them — weren't observable, and the "access logs" the issue referenced didn't actually exist. ## Change Add an `(access_log)` snippet (JSON → stdout → container log → Loki) and import it in all three hosts (grafana/stats/ntfy). ## Verified live Applied `--tags monitoring` (clean restart — the socket already owns 80/443, no `EADDRINUSE`). Three external probes from a known public IP produced: ``` "remote_ip":"155.4.69.98" ... "host":"grafana.gitborg.se" ... "status":200 ×3 ``` plus other genuine external clients (`155.4.244.250`, `185.213.154.181`) — and **zero pasta `10.x` bridge addresses** in `remote_ip`. That's the literal confirmation that #100's socket activation delivers real client IPs; request attribution + GoatCounter analytics are now correct. > Note: this was applied ahead of merge to complete the #100 verification (with downtime OK'd). Merging syncs main with prod. Refs #100.
supernaut lade till 1 incheckning 2026-07-19 21:37:34 +00:00
feat(monitoring): add access logging to the monitoring Caddy
Alla kontroller lyckades
ci / ci (pull_request) Successful in 2m58s
2ddc60edab
The monitoring Caddy had no access-log directive, so the real client IPs
that #100's socket activation now delivers weren't observable. Add an
(access_log) snippet (JSON -> stdout -> container log -> Loki), imported
by all three hosts.

Verified: external probes log remote_ip=155.4.69.98 (+ other real public
IPs), zero pasta 10.x addresses — literal confirmation of the #100 fix.

Refs #100.
supernaut sammanfogade incheckning 4b76110b02 till main 2026-07-19 21:41:16 +00:00
supernaut tog bort grenen fix/100-monitoring-caddy-access-log 2026-07-19 21:41:16 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!156
Ingen beskrivning angiven.