Implementation complete and tested Co-authored-by: hsluoyz <3787410+hsluoyz@users.noreply.github.com>
A Prometheus logger implementation for Casbin, providing event-driven metrics collection for authorization events.
casbin_enforce_total - Total number of enforce requests (labeled by allowed, domain, and optionally subject, object, action)casbin_enforce_duration_seconds - Duration of enforce requests (labeled by allowed, domain, and optionally subject, object, action)casbin_policy_operations_total - Total number of policy operations (labeled by operation, success)casbin_policy_operations_duration_seconds - Duration of policy operations (labeled by operation)casbin_policy_rules_count - Number of policy rules affected by operations (labeled by operation)casbin_policy_state_count - Current number of policy rules by type (labeled by ptype)go get github.com/casbin/casbin-prometheus-logger
package main import ( "net/http" prometheuslogger "github.com/casbin/casbin-prometheus-logger" "github.com/prometheus/client_golang/prometheus" "github.com/prometheus/client_golang/prometheus/promhttp" ) func main() { // Create logger with default Prometheus registry logger := prometheuslogger.NewPrometheusLogger() defer logger.Unregister() // Or create with custom registry registry := prometheus.NewRegistry() logger := prometheuslogger.NewPrometheusLoggerWithRegistry(registry) defer logger.UnregisterFrom(registry) // Use with Casbin // enforcer.SetLogger(logger) // Expose metrics endpoint http.Handle("/metrics", promhttp.Handler()) http.ListenAndServe(":8080", nil) }
// Create logger with additional labels for enforce metrics options := &prometheuslogger.PrometheusLoggerOptions{ EnforceLabels: []string{ prometheuslogger.EnforceLabelSubject, prometheuslogger.EnforceLabelObject, prometheuslogger.EnforceLabelAction, }, } registry := prometheus.NewRegistry() logger := prometheuslogger.NewPrometheusLoggerWithOptions(registry, options) defer logger.UnregisterFrom(registry) // Enforce metrics will now include subject, object, and action labels // in addition to the default allowed and domain labels
// Update the current policy state count // This helps monitor permission growth over time logger.UpdatePolicyState("p", 100) // 100 p-type policies logger.UpdatePolicyState("g", 50) // 50 g-type role assignments logger.UpdatePolicyState("g1", 25) // 25 g1-type role assignments logger.UpdatePolicyState("g2", 10) // 10 g2-type role assignments logger.UpdatePolicyState("g3", 5) // 5 g3-type role assignments
// Only log specific event types logger.SetEventTypes([]prometheuslogger.EventType{ prometheuslogger.EventEnforce, prometheuslogger.EventAddPolicy, })
// Add custom processing for log entries logger.SetLogCallback(func(entry *prometheuslogger.LogEntry) error { fmt.Printf("Event: %s, Duration: %v\n", entry.EventType, entry.Duration) return nil })
The logger supports the following event types:
EventEnforce - Authorization enforcement requestsEventAddPolicy - Policy addition operationsEventRemovePolicy - Policy removal operationsEventLoadPolicy - Policy loading operationsEventSavePolicy - Policy saving operationsSee the examples/basic directory for a complete working example.
To run the example:
cd examples/basic go run main.go
Then visit http://localhost:8080/metrics to see the exported metrics.
This project is licensed under the Apache 2.0 License - see the LICENSE file for details.
Contributions are welcome! Please feel free to submit a Pull Request.