mirror of
https://github.com/agent-substrate/substrate.git
synced 2026-10-02 03:24:42 +08:00
Working on https://github.com/agent-substrate/substrate/issues/1563 ## Summary Initializes an embedded OpenFGA server within `ateapi` backed by PostgreSQL and updates the top-level authorization scope. ## Key Changes - **Rename scope to `global`**: Renamed `type cluster` and `parent_cluster` to `type global` and `parent_global`, adding `can_set_policy` and `can_get_policy` to `global`. - **Embedded OpenFGA server (`internal/authz/server.go`)**: - Compiles `model.fga` into OpenFGA's protobuf representation. - Runs OpenFGA PostgreSQL schema migrations (`goose_db_version`). - Serializes startup via `pg_advisory_lock` to avoid multi-replica races. - Connects OpenFGA's PostgreSQL adapter with a new dedicated `*pgxpool.Pool`. - Idempotently creates or reuses the `"substrate"` store and authorization model. - **Service wiring (`cmd/ateapi`)**: Exposes `Pool()` on `*atepg.Persistence` and initializes `authz.NewServer` on bootstrap. ## Verification - `openfga model test`: 103/103 checks passing (`model_test.fga.yaml`). - `go test -mod=mod ./internal/authz/...`: Passes against PostgreSQL (migrations, tuple writes, permission checks, and restart idempotency).
Prometheus Collector for PGX Pool
This is a Prometheus Collector for PGX Pool.
Example Usage
package main
import (
"context"
"log"
"net/http"
"os"
"github.com/jackc/pgx/v5/pgxpool"
"github.com/prometheus/client_golang/prometheus"
"github.com/prometheus/client_golang/prometheus/promhttp"
"github.com/IBM/pgxpoolprometheus"
)
func main() {
pool, err := pgxpool.Connect(context.Background(), os.Getenv("DATABASE_URL"))
if err != nil {
log.Fatal(err)
}
collector := pgxpoolprometheus.NewCollector(pool, map[string]string{"db_name": "my_db"})
prometheus.MustRegister(collector)
http.Handle("/metrics", promhttp.Handler())
log.Fatal(http.ListenAndServe(":8080", nil))
}
Metrics Collected
This collector provides metrics for all the stats produced by pgxpool.Stat all prefixed with pgxpool:
| Name | Description |
|---|---|
| pgxpool_acquire_count | Cumulative count of successful acquires from the pool. |
| pgxpool_acquire_duration_ns | Total duration of all successful acquires from the pool in nanoseconds. |
| pgxpool_acquired_conns | Number of currently acquired connections in the pool. |
| pgxpool_canceled_acquire_count | Cumulative count of acquires from the pool that were canceled by a context. |
| pgxpool_constructing_conns | Number of conns with construction in progress in the pool. |
| pgxpool_empty_acquire | Cumulative count of successful acquires from the pool that waited for a resource to be released or constructed because the pool was empty. |
| pgxpool_empty_acquire_wait_time_ns | Cumulative time waited for successful acquires from the pool for a resource to be released or constructed because the pool was empty. |
| pgxpool_idle_conns | Number of currently idle conns in the pool. |
| pgxpool_max_conns | Maximum size of the pool. |
| pgxpool_max_idle_destroy_count | Cumulative count of connections destroyed because they exceeded MaxConnIdleTime. |
| pgxpool_max_lifetime_destroy_count | Cumulative count of connections destroyed because they exceeded MaxConnLifetime. |
| pgxpool_new_conns_count | Cumulative count of new connections opened. |
| pgxpool_total_conns | Total number of resources currently in the pool. The value is the sum of ConstructingConns, AcquiredConns, and IdleConns. |