app: Add active sessions Prometheus gauge (#65008)

* fncache: Pass non-cancellable context to `OnExpiry` callbacks

Call `OnExpiry` when `get()` replaces an expired entry on reload.
Previously, entries that expired between cleanup intervals were
silently dropped when a new request triggered a reload, skipping
the `OnExpiry` callback entirely.

Use `context.WithoutCancel(c.cfg.Context)` at both the
`removeExpiredLocked` and `get` call sites so that `OnExpiry` work
completes even after shutdown begins. `Shutdown` cancels
`c.cfg.Context` via `c.cancel()` before processing entries, but
these two call sites passed `c.cfg.Context` directly, meaning
goroutines spawned by `OnExpiry` could run with an
already-cancelled context.

Update the `OnExpiry` doc comment to warn that the cache mutex may
be held when the callback is invoked.

* app: Add active sessions Prometheus gauge

Add a `teleport_app_active_sessions` gauge labeled by app name that
tracks HTTP app sessions on each agent. The gauge increments when a
session chunk is created and decrements after the session chunk
finishes closing, so it reflects sessions still holding resources
(audit streams, disk I/O) rather than just sessions accepting new
requests.

TCP and MCP sessions are excluded because they bypass the session
chunk cache.

* fncache: Fix `OnExpires` typo in `Shutdown` doc comment

Correct the stale field name `OnExpires` to `OnExpiry` in the
`Shutdown` method's doc comment to match the actual field name in
`FnCacheConfig`.
This commit is contained in:
Julia Ogris
2026-04-23 02:44:47 +00:00
committed by GitHub
parent ed41e6c9d5
commit 6c8ea32bc2
6 changed files with 264 additions and 5 deletions
+6
View File
@@ -200,6 +200,12 @@ The following table identifies all metrics available for incoming connections.
| `teleport_kubernetes_server_join_sessions_total` | counter | Teleport Kubernetes Proxy | Total number of joining sessions. |
## Application Service
| Name | Type | Component | Description |
|------|------|-----------|-------------|
| `teleport_app_active_sessions` | gauge | Teleport Application Service | Number of active HTTP app sessions on this agent, labeled by `app` name. Does not include TCP or MCP sessions. |
## Teleport SSH Service
| Name | Type | Component | Description |