Files
tproxy-web-proxy/references/tproxy-monitoring.md
T
2026-09-06 13:51:10 +00:00

3.1 KiB

tproxy-server monitoring reference

Admin HTTP endpoints (bound to 127.0.0.1:8081 = admin_listen, loopback only):

Endpoint Returns
/healthz always 200 ok while the process runs; does NOT touch backends
/readyz 200 ready if TCP dial succeeds to EVERY profile backend; 503 backend unavailable if any backend dial fails (timeout = timeouts.backend_dial, default 5s)
/metrics Prometheus text format (Content-Type: text/plain; version=0.0.4), 13 counters
/debug/pprof/* only when config.enable_pprof: true

Metrics (from serveMetrics, internal/server/server.go)

tproxy_sessions_live              # currently active sessions
tproxy_streams_live               # currently active streams
tproxy_backend_dials_in_flight    # in-flight dials to MTProxy (127.0.0.1:2398)
tproxy_pending_bytes              # queued payload waiting to be relayed
tproxy_pending_items              # queued items
tproxy_sessions_created_total     # cumulative
tproxy_sessions_closed_total      # cumulative
tproxy_streams_opened_total       # cumulative
tproxy_streams_rejected_total     # cumulative
tproxy_backend_dial_failures_total  # cumulative — growth = MTProxy down/unreachable
tproxy_bytes_up_total             # cumulative, client→proxy→backend
tproxy_bytes_down_total           # cumulative, backend→client
tproxy_limit_hits_total           # cumulative, rate-limit / capacity hits

Note: live values come from manager.Capacity() (current), _total counters from manager.Metrics() (cumulative). No labels/help strings emitted — plain name value lines.

Prometheus scrape config (prometheus runs network_mode: host)

- job_name: 'tproxy'
  static_configs:
    - targets: ['77.67.89.154:8081']   # vps03 public IP; port must be opened
      labels:
        host: vps03
        service: tproxy

Exposing 8081 to the monitor (vps03, nft)

Endpoint listens on loopback only — open for ONE source IP, e.g. bigbox:

nft add rule inet filter input ip saddr <BIGBOX_IP> tcp dport 8081 accept
systemctl restart tproxy-server   # or nft reload

Never publish to 0.0.0.0; the endpoint has no auth.

Alert ideas

  • tproxy_backend_dial_failures_total increases → MTProxy unreachable
  • /readyz non-200 → chain broken (but remember: ONE dead profile backend fails readyz for everyone)
  • tproxy_limit_hits_total increases → abuse / capacity exceeded
  • up{job="tproxy"} == 0 → exporter itself down

Monitoring task location

/opt/monitoring/PLAN.md — «Этап 6. Метрики tproxy-server (vps03)» (written 2026-08-31), git repo gitverse.ru:kpa39l/monitoring.git, gitea mirror.

Verified live sample (vps03, 2026-08-31, idle-ish)

tproxy_sessions_live 1
tproxy_streams_live 5
tproxy_backend_dials_in_flight 0
tproxy_pending_bytes 0
tproxy_pending_items 0
tproxy_sessions_created_total 1
tproxy_sessions_closed_total 0
tproxy_streams_opened_total 15
tproxy_streams_rejected_total 0
tproxy_backend_dial_failures_total 0
tproxy_bytes_up_total 166853
tproxy_bytes_down_total 5076719
tproxy_limit_hits_total 0