Repository navigation
[FEATURE] add CloudWatch plugin - #856
Draft
T-Chittibabu wants to merge 1 commit into
Draft
T-Chittibabu wants to merge 1 commit into
T-Chittibabu wants to merge 1 commit into
Conversation
Contributor
|
Please don't forget to document this new plugin by adding content to https://github.com/perses/plugins/tree/main/docs |
Add a CloudWatch plugin querying Amazon CloudWatch metrics. The datasource is a regular HTTPProxy to the CloudWatch API of a region, with a secret holding a sigv4 configuration: the Perses server signs the requests with the AWS Signature Version 4, so the browser never receives AWS credentials. The plugin calls the CloudWatch API (AWS JSON 1.0 protocol) directly through this proxy. - CloudWatchDatasource: an HTTP proxy to https://monitoring.<region>.amazonaws.com, restricted to POST /, with a mandatory secret. The editor builds the URL from the region. - CloudWatchTimeSeriesQuery: metrics and metric math expressions sent in a single GetMetricData request, with the pages merged, and a metric discovery (ListMetrics) in the editor. The period of a metric is a minimum: it is increased to the step suggested by the panel, and so the series stay under 10000 datapoints (for example over 7 days). - CloudWatchDimensionValuesVariable: the values of a dimension in a namespace, discovered with ListMetrics (at most 1000 metrics). - Dashboard variables can be used in the namespaces, metric names, dimensions, expressions and legends. - AWS errors are reported with their type and message. - Go SDK for the datasource, the query and the variable, and the documentation of the plugin in docs/cloudwatch. The datasource doesn't define a health check path: the CloudWatch API only accepts signed POST requests, so the generic connection test doesn't apply. It requires the sigv4 authentication of the HTTP proxy of Perses. Co-authored-by: Jagath P <87551823+jagath25@users.noreply.github.com> Signed-off-by: Chittibabu Terala <102535438+T-Chittibabu@users.noreply.github.com>
T-Chittibabu
force-pushed
the
feat/cloudwatch-plugin
branch
from
October 8, 2026 15:50
1f67fd0 to
06ef019
Compare
Author
|
Thanks @AntoineThebaud, I added the docs in |
3 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Design discussion: perses/perses#4547
Description
This adds a CloudWatch plugin for Amazon CloudWatch metrics, reworked following the design discussion: there is no dedicated proxy anymore. The datasource is a regular
HTTPProxyto the CloudWatch API of a region, with a secret holding asigv4configuration, and all the CloudWatch logic lives in the plugin.The Perses server signs the requests with the AWS Signature Version 4, so the browser never receives AWS credentials. The plugin calls the CloudWatch API directly through the proxy, with the AWS JSON 1.0 protocol (
X-Amz-Target: GraniteServiceVersion20100801.GetMetricData/ListMetrics).Depends on the
sigv4authentication of the HTTP proxy in perses/perses (perses/perses#4569). The plugin itself only uses released packages, so its CI doesn't depend on it, but the requests can't be signed without it.Plugins
CloudWatchDatasource:HTTPProxytohttps://monitoring.<region>.amazonaws.com, restricted toPOST /, with a mandatory secret;CloudWatchTimeSeriesQuery:GetMetricDatarequest;returnData: falsehides the series only used by an expression;ListMetrics) to add a metric in one click.CloudWatchDimensionValuesVariable: the values of a dimension in a namespace (for example everyInstanceId), optionally filtered by metric name and by other dimension values.Behavior
dependsOnlists them.InvalidParameterValueException: ...), and so are the errors of the Perses proxy.healthCheckPathis defined, as the CloudWatch API only accepts signedPOSTrequests. The editor doesn't show the generic test button; the metric discovery checks the datasource.CloudWatch(region, secretName, URL(...))), the query (Metric,Expression,Label,Hidden) and the variable.docs/cloudwatch(overview and setup, data model, Go SDK), as requested by @AntoineThebaud.Testing
npm run type-check,lintandbuildfor the workspace.lintreports no new warning (only the existingsetup-tests.tsone shared by every plugin).npm run test: 43 tests covering:GetMetricData/ListMetricsrequests (headers, body, epoch timestamps);dependsOnand query validation;oxfmt --check,cue fmt,mdoxand the license check.percli plugin lintpasses, andpercli plugin test-schemaspasses all 9 schema tests.go vet,go testandgolangci-lintv2.13.2 (0 issues).Screenshots
The editors use the standard MUI fields of the other plugins. I'll add screenshots once the SigV4 change is available in a running Perses.
Checklist
[<catalog_entry>] <commit message>naming convention.UI Changes