feat(diagnostics): report MXAccess session health on the active probe
Adds a `mxaccess-sessions` health check reporting how many MXAccess sessions are
healthy. Each session is one worker process holding one MXAccess COM instance —
a live connection into a Galaxy — so this answers "how many Galaxy connections
are healthy" in the vocabulary the code actually uses.
Zero sessions is Healthy, deliberately, and the rest of the design follows from
that. The gateway opens a session when a client asks and holds none otherwise,
so an idle gateway is working normally. A count threshold ("unhealthy below N")
would sit red forever on a host nothing dials yet, and a permanently red probe
is one operators stop reading — which leaves them worse off than no probe. The
check therefore grades on whether the sessions that exist are usable: nothing
faulted is Healthy, some faulted beside a ready or starting one is Degraded, and
every session faulted is Unhealthy. Counts ride along as entry data for the
family Overview dashboard.
Tagged `active` rather than `ready` for the same reason. Readiness decides
whether the process should be sent traffic, and a gateway with no sessions is
ready to serve — unlike the auth store, which every call depends on. Failing
readiness here would pull a working gateway out of rotation over a condition its
own clients create.
Reads ISessionRegistry, which already exposes Snapshot(); ISessionManager stays
the command surface and grows no enumerator.
This commit is contained in:
@@ -217,6 +217,30 @@ The order matters: putting the logging scope first ensures that authentication f
|
||||
- `DashboardRedactor.Redact` delegates to `RedactClientIdentity` for any value containing the `mxgw_` marker, then falls back to a marker-keyword check for fields like `password` or `token`. This keeps dashboard renders aligned with log redaction.
|
||||
- `ZB.MOM.WW.MxGateway.Tests/Diagnostics/GatewayLogRedactorTests.cs` covers each redaction branch, including the assertion that `WriteSecured` values stay redacted even when `valueLoggingEnabled` is true.
|
||||
|
||||
## Health Checks
|
||||
|
||||
The shared `ZB.MOM.WW.Health` package maps three endpoints — `/healthz` (live), `/health/ready`, and
|
||||
`/health/active` — and each registered check opts into a tier by tag. The gateway registers two:
|
||||
|
||||
| Check | Endpoint tier | Fails when |
|
||||
|---|---|---|
|
||||
| `auth-store` | `ready` | The SQLite auth store cannot be opened. Every gRPC call authenticates against it, so its reachability genuinely gates whether the process should receive traffic. |
|
||||
| `mxaccess-sessions` | `active` | Sessions exist and their workers have faulted. Reports `total` / `ready` / `faulted` / `starting` / `closing` as entry `data`. |
|
||||
|
||||
**Zero sessions is Healthy, and the tier choice follows from that.** The gateway opens an MXAccess
|
||||
session when a client asks for one and holds none otherwise, so an idle gateway is working normally,
|
||||
not broken. A count threshold ("unhealthy below N") would sit red forever on a host nothing dials
|
||||
yet, and a permanently red probe is one operators stop reading — which leaves them worse off than no
|
||||
probe at all. `mxaccess-sessions` is therefore graded on whether the sessions that exist are usable:
|
||||
|
||||
- nothing faulted → **Healthy** (including no sessions at all)
|
||||
- some faulted, some still ready or starting → **Degraded**
|
||||
- every session faulted → **Unhealthy**
|
||||
|
||||
For the same reason it is tagged `active` rather than `ready`. Readiness decides whether the process
|
||||
should be sent traffic, and a gateway with no sessions is ready to serve; failing readiness there
|
||||
would pull a working gateway out of rotation over a condition its clients create.
|
||||
|
||||
## Related Documentation
|
||||
|
||||
- [Identifying A Deployed Build](./runbooks/IdentifyingADeployedBuild.md) — mapping a running binary back to a commit, and why the `InformationalVersion` stamp cannot be trusted on Windows builds from 2026-07-09 to 2026-08-10
|
||||
|
||||
Reference in New Issue
Block a user