Skip to content

TLS observability in Prometheus /metrics + CWIST v3.9 roadmap - #308

Merged
gg582 merged 1 commit into
devfrom
roadmap/v3.9-tls-observability
Oct 4, 2026
Merged

gg582 merged 1 commit into
devfrom
roadmap/v3.9-tls-observability

Conversation

@gg582

@gg582 gg582 commented Oct 4, 2026

Copy link
Copy Markdown
Member

Part 1 — ROADMAP.md: CWIST v3.9 Roadmap

Adds a CWIST v3.9 Roadmap section in the document's existing style (legend, status-at-a-glance table, entry/exit criteria), proposing the v3.9 theme: TLS observability & performance governance.

Entry/exit criteria follow the v3.8 spirit: every item must move a measured metric (handshake throughput, resumption ratio, churn latency, or regression-detection latency) or retire a mismeasured premise.

Part 2 — TLS observability (item b)

Counters are owned lock-free in src/net/http/https.c and mirrored into the Prometheus exposition by the metrics registry on load/render — the same sync contract as cwist_http_continuation_shed_count, so the HTTPS hot path never depends on the sys/metrics layer. Recording happens in https_wrap_established, the single choke point both handshake paths (in-worker cwist_https_accept and the shepherd's pre-handshaked dispatch) funnel through; https_connection_teardown decrements the active gauge.

New /metrics series:

Metric Type
cwist_tls_handshakes_total counter
cwist_tls_handshakes_resumed_total counter (SSL_session_reused)
cwist_tls_connections_active gauge
cwist_tls_handshakes_tls12_total / cwist_tls_handshakes_tls13_total counters (negotiated version)
cwist_tls_ciphers_aes128_gcm_total / cwist_tls_ciphers_aes256_gcm_total / cwist_tls_ciphers_chacha20_total / cwist_tls_ciphers_other_total counters (negotiated cipher)

Tests

New tests/test_https_metrics.c (wired into the tests target): performs a full and a resumed TLS 1.2 handshake plus a TLS 1.3 handshake over socketpairs, asserts every counter moves (resumption ratio, version buckets, cipher buckets, active gauge returning to baseline), and asserts the rendered Prometheus exposition contains the new series.

Verified locally: make libcwist.a clean; test_https_metrics, test_https, test_https_park, test_https_full_gc, and test_http2 all pass.

Refs #306, #294

…s, v3.9 roadmap

Add TLS handshake observability ahead of the v3.9 'TLS observability &
performance governance' theme (tracked in #306):

- https.c owns lock-free counters for total/resumed handshakes, TLS 1.2/1.3
  version buckets, cipher buckets (AES-128-GCM, AES-256-GCM, ChaCha20,
  other), and active established connections. Recording happens in
  https_wrap_established, the single choke point both the in-worker
  handshake path (cwist_https_accept) and the shepherd's pre-handshaked
  dispatch path funnel through; teardown decrements the active gauge.
- The metrics registry mirrors them into the Prometheus exposition on
  load/render (same sync contract as cwist_http_continuation_shed_count):
  cwist_tls_handshakes_total, cwist_tls_handshakes_resumed_total,
  cwist_tls_connections_active, cwist_tls_handshakes_tls12_total,
  cwist_tls_handshakes_tls13_total, cwist_tls_ciphers_aes128_gcm_total,
  cwist_tls_ciphers_aes256_gcm_total, cwist_tls_ciphers_chacha20_total,
  cwist_tls_ciphers_other_total.
- tests/test_https_metrics.c covers a full + a resumed TLS 1.2 handshake
  and a TLS 1.3 handshake, asserts counter movement, and checks the
  rendered /metrics exposition.

ROADMAP.md gains the CWIST v3.9 Roadmap section: (a) CI TLS performance
gates (in progress, gate PR pending, #306), (b) this PR's observability
item (done), (c) correcting #294's premise with measured data (done via
the #294 comment: the cwist_app_listen path never uses the sharded
handshake shepherds -- app.c calls https_pool_submit directly and workers
handshake inline; shepherds only serve the async_server.c path, so shard
tuning does not affect the standard app API).

Refs #306, #294
@gg582
gg582 force-pushed the roadmap/v3.9-tls-observability branch from a5ea4b7 to 6b1339c Compare October 4, 2026 12:22
@gg582
gg582 merged commit bbaefc5 into dev Oct 4, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant