mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add boundary usage tracking database schema and tracker skeleton (#21670)
feat: add boundary usage telemetry database schema and RBAC
Adds the foundation for tracking boundary usage telemetry across Coder
replicas. This includes:
- Database schema: `boundary_usage_stats` table with per-replica stats
(unique workspaces, unique users, allowed/denied request counts)
- Database queries: upsert stats, get aggregated summary, reset stats,
delete by replica ID
- RBAC: `boundary_usage` resource type with read/update/delete actions,
accessible only via system `BoundaryUsageTracker` subject (not regular
user roles)
- Tracker skeleton + docs: stub implementation in `coderd/boundaryusage/`
The tracker accumulates stats in memory and periodically flushes to the
database. Stats are aggregated across replicas for telemetry reporting,
then reset when a new reporting period begins. The tracker implementation
and plumbing will be done in a subsequent commit/PR.
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
This commit is contained in:
@@ -213,6 +213,10 @@ const (
|
||||
ApiKeyScopeTask APIKeyScope = "task:*"
|
||||
ApiKeyScopeWorkspaceShare APIKeyScope = "workspace:share"
|
||||
ApiKeyScopeWorkspaceDormantShare APIKeyScope = "workspace_dormant:share"
|
||||
ApiKeyScopeBoundaryUsage APIKeyScope = "boundary_usage:*"
|
||||
ApiKeyScopeBoundaryUsageDelete APIKeyScope = "boundary_usage:delete"
|
||||
ApiKeyScopeBoundaryUsageRead APIKeyScope = "boundary_usage:read"
|
||||
ApiKeyScopeBoundaryUsageUpdate APIKeyScope = "boundary_usage:update"
|
||||
)
|
||||
|
||||
func (e *APIKeyScope) Scan(src interface{}) error {
|
||||
@@ -445,7 +449,11 @@ func (e APIKeyScope) Valid() bool {
|
||||
ApiKeyScopeTaskDelete,
|
||||
ApiKeyScopeTask,
|
||||
ApiKeyScopeWorkspaceShare,
|
||||
ApiKeyScopeWorkspaceDormantShare:
|
||||
ApiKeyScopeWorkspaceDormantShare,
|
||||
ApiKeyScopeBoundaryUsage,
|
||||
ApiKeyScopeBoundaryUsageDelete,
|
||||
ApiKeyScopeBoundaryUsageRead,
|
||||
ApiKeyScopeBoundaryUsageUpdate:
|
||||
return true
|
||||
}
|
||||
return false
|
||||
@@ -647,6 +655,10 @@ func AllAPIKeyScopeValues() []APIKeyScope {
|
||||
ApiKeyScopeTask,
|
||||
ApiKeyScopeWorkspaceShare,
|
||||
ApiKeyScopeWorkspaceDormantShare,
|
||||
ApiKeyScopeBoundaryUsage,
|
||||
ApiKeyScopeBoundaryUsageDelete,
|
||||
ApiKeyScopeBoundaryUsageRead,
|
||||
ApiKeyScopeBoundaryUsageUpdate,
|
||||
}
|
||||
}
|
||||
|
||||
@@ -3702,6 +3714,24 @@ type AuditLog struct {
|
||||
ResourceIcon string `db:"resource_icon" json:"resource_icon"`
|
||||
}
|
||||
|
||||
// Per-replica boundary usage statistics for telemetry aggregation.
|
||||
type BoundaryUsageStat struct {
|
||||
// The unique identifier of the replica reporting stats.
|
||||
ReplicaID uuid.UUID `db:"replica_id" json:"replica_id"`
|
||||
// Count of unique workspaces that used boundary on this replica.
|
||||
UniqueWorkspacesCount int64 `db:"unique_workspaces_count" json:"unique_workspaces_count"`
|
||||
// Count of unique users that used boundary on this replica.
|
||||
UniqueUsersCount int64 `db:"unique_users_count" json:"unique_users_count"`
|
||||
// Total allowed requests through boundary on this replica.
|
||||
AllowedRequests int64 `db:"allowed_requests" json:"allowed_requests"`
|
||||
// Total denied requests through boundary on this replica.
|
||||
DeniedRequests int64 `db:"denied_requests" json:"denied_requests"`
|
||||
// Start of the time window for these stats, set on first flush after reset.
|
||||
WindowStart time.Time `db:"window_start" json:"window_start"`
|
||||
// Timestamp of the last update to this row.
|
||||
UpdatedAt time.Time `db:"updated_at" json:"updated_at"`
|
||||
}
|
||||
|
||||
type ConnectionLog struct {
|
||||
ID uuid.UUID `db:"id" json:"id"`
|
||||
ConnectTime time.Time `db:"connect_time" json:"connect_time"`
|
||||
|
||||
Reference in New Issue
Block a user