Skip to content

Metrics and alerts

Terminal window
curral serve ... --metrics-listen 127.0.0.1:9090

/metrics is served on its own port without authentication. Keep it on the internal network.

Metric Type Labels
curral_queries_total counter status, decision, decided_by, statement_type
curral_policy_decisions_total counter role, decision
curral_query_stage_seconds histogram stage: queue, inspect, authorize, execute, total
curral_queries_running · _waiting · curral_query_slots gauge
curral_rows_returned_total · curral_response_bytes_total counter
curral_queries_throttled_total counter
curral_queries_rewritten_total counter
curral_auth_failures_total counter method
curral_auth_lockouts_total · curral_auth_blocked_total counter scope
curral_audit_events_written_total · _dropped_total counter
curral_audit_healthy gauge 0 = queries are being refused
curral_catalog_cache_requests_total counter database, result
curral_config_reloads_total counter
curral_policy_info gauge policy hash in effect
curral_build_info gauge version, commit, duckdb, policy_sha256

Go runtime and process metrics (go_*, process_*) are exported too.

- alert: CurralAuditDown
expr: curral_audit_healthy == 0 # queries are being refused
- alert: CurralRefusing
expr: rate(curral_queries_total{status="503"}[5m]) > 0 # queue full or audit down
- alert: CurralQueueBacklog
expr: curral_queries_waiting > 0
for: 10m # raise --max-concurrency

Also watch for spikes in curral_policy_decisions_total{decision="deny"} and curral_auth_failures_total.