[3/6] Add the /ui/analytics page - #390
Merged
Merged
Conversation
This was referenced Oct 1, 2026
This was referenced Oct 1, 2026
- Add GetEcosystemStats, aggregating packages, versions, artifacts, cache size, downloads and downloaded bytes per ecosystem - Publish six proxy_ecosystem_* gauges from it on the existing one-minute cache-stats tick - Set and selectively delete rather than Reset, so no scrape lands on a half-populated vector - Report artifacts with no package row under "unattributed" rather than dropping them, so the figures still add up Part 2 of 6 splitting git-pkgs#381 up. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- Ring of download size by ecosystem, cache figures, per-ecosystem table, vulnerability overview and a Runtime card - Add metrics.Gather so the page can render counters that were never in the database - Add proxy_response_bytes_total and response-writer byte counting - Serve a retained snapshot behind a staleness banner when the aggregation fails, rather than rendering old figures as current - Extract the security overview into a shared component Part 3 of 6 splitting git-pkgs#381 up. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
wickedOne
force-pushed
the
analytics-3-page
branch
from
October 1, 2026 14:19
fc0f281 to
0501534
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
/ui/analytics: download volume, per-ecosystem breakdown and a runtime card/ui/reported what the cache holds but nothing about what it has served, and most of what/metricsexposes had no home in the UI at all. This adds a second page.The page carries a ring of download size by ecosystem with the total in the middle (six slices maximum, the tail folded into "Other" and named in the legend), the cache figures from
/ui/, a per-ecosystem table, the vulnerability overview, and a Runtime card covering every remaining metric.No history is stored
The proxy keeps no time series. The page reads the database and the in-process registry at request time and reports current state; history, trends and alerting are Prometheus and Grafana's job. That splits the figures in two and the page says which is which: database-derived figures survive a restart, while everything in the Runtime card lives only in this process's registry and restarts from zero.
When the aggregation fails but a previous snapshot was retained, the page serves the stale figures behind an amber banner saying when they were read. Without that distinction a database down for an hour renders hour-old numbers as current, with the failure visible only in the logs.
Also in here
metrics.Gather()and a smallSnapshottype, so the UI can render counters that were never in the database. The Runtime card is its only caller, which is why this is not in part 2.proxy_response_bytes_total{ecosystem}and byte counting on the response writer -- the Runtime card's "Served" tile is its first consumer. Theecosystemlabel here comes from the request path, not the package record; the README now sets out all three label sets side by side, since that is the thing most likely to produce a wrong query.The Security Overview block moves out of
dashboard.htmlinto a shared component so the two pages cannot drift.TestEveryMetricIsSurfacedmakes the page a required consumer of every future metric: adding one fails the build until a tile exists. That is deliberate, and per the review it is now written down rather than discovered -- a comment onmetricSurfaceand a line under Code Style in CONTRIBUTING.md.avgArtifactSizereturned an em dash for the empty case, flagged in the review; it returns0 B.joinLabelsandformatDurationreturn-, where0 Bwould be meaningless.