Skip to content

[tls_mgm] Export active TLS connection statistics - #4283

Open
darwvin-dev wants to merge 2 commits into
OpenSIPS:masterfrom
darwvin-dev:feature/tls-mgm-statistics
Open

darwvin-dev wants to merge 2 commits into
OpenSIPS:masterfrom
darwvin-dev:feature/tls-mgm-statistics

Conversation

@darwvin-dev

@darwvin-dev darwvin-dev commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Export active TLS connection gauges from tls_mgm so operators can monitor negotiated TLS versions, peer verification state and cipher families through the standard OpenSIPS statistics interface / Prometheus exporter.

Statistics

  • tls_mgm:connections
  • tls_mgm:tls_v1_0_connections
  • tls_mgm:tls_v1_1_connections
  • tls_mgm:tls_v1_2_connections
  • tls_mgm:tls_v1_3_connections
  • tls_mgm:peer_verified_connections
  • tls_mgm:peer_unverified_connections
  • tls_mgm:aes_gcm_connections
  • tls_mgm:chacha20_connections
  • tls_mgm:other_cipher_connections

Implementation

The gauges are computed from TLS metadata already cached on active tcp_connection objects. A generic TCP traversal helper holds one partition lock at a time while invoking a read-only callback. This avoids counter drift and avoids adding work to the TLS handshake hot path. Exact cipher names are grouped into stable cipher families instead of creating unbounded dynamic statistic names.

Validation

  • make include_modules="tls_mgm tls_openssl proto_tls" modules -j8 — passed
  • make app -j8 — passed
  • git diff --check — passed

Refs #3315

Safety / validation update

The TCP traversal now ignores non-TLS/WSS connections before interpreting shared_data as tcp_tls_info. This keeps the generic TCP shared_data slot type-safe for other protocols while preserving TLS and WSS statistics.

Revalidated after rebasing onto current master:

  • make include_modules="tls_mgm tls_openssl proto_tls" modules -j$(nproc) — passed
  • make app -j$(nproc) — passed
  • git diff --check — passed

@razvancrainea

Copy link
Copy Markdown
Member

@darwvin-dev the PR contains some stats in the tls_openssl, but the works seems to be incomplete - can you remove the changes, so I can merge this patch? thanks!

@darwvin-dev
darwvin-dev force-pushed the feature/tls-mgm-statistics branch from d839b8a to db03ff8 Compare October 7, 2026 13:50
@darwvin-dev

Copy link
Copy Markdown
Contributor Author

Thanks @razvancrainea! I've removed the incomplete tls_openssl changes. The PR now only contains the tls_mgm connection statistics and the generic TCP traversal helper (4 files), rebased on current master.

FYI, the handshake outcome/latency statistics are now done properly, backend-independent in tls_mgm with no tls_openssl changes, in #4309, which is stacked on this PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants