Metrics and alerts
curral serve ... --metrics-listen 127.0.0.1:9090/metrics is served on its own port without authentication. Keep it on
the internal network.
| Metric | Type | Labels |
|---|---|---|
curral_queries_total |
counter | status, decision, decided_by, statement_type |
curral_policy_decisions_total |
counter | role, decision |
curral_query_stage_seconds |
histogram | stage: queue, inspect, authorize, execute, total |
curral_queries_running · _waiting · curral_query_slots |
gauge | |
curral_rows_returned_total · curral_response_bytes_total |
counter | |
curral_queries_throttled_total |
counter | |
curral_queries_rewritten_total |
counter | |
curral_auth_failures_total |
counter | method |
curral_auth_lockouts_total · curral_auth_blocked_total |
counter | scope |
curral_audit_events_written_total · _dropped_total |
counter | |
curral_audit_healthy |
gauge | 0 = queries are being refused |
curral_catalog_cache_requests_total |
counter | database, result |
curral_config_reloads_total |
counter | |
curral_policy_info |
gauge | policy hash in effect |
curral_build_info |
gauge | version, commit, duckdb, policy_sha256 |
Go runtime and process metrics (go_*, process_*) are exported too.
Suggested alerts
Section titled “Suggested alerts”- alert: CurralAuditDown expr: curral_audit_healthy == 0 # queries are being refused- alert: CurralRefusing expr: rate(curral_queries_total{status="503"}[5m]) > 0 # queue full or audit down- alert: CurralQueueBacklog expr: curral_queries_waiting > 0 for: 10m # raise --max-concurrencyAlso watch for spikes in
curral_policy_decisions_total{decision="deny"} and
curral_auth_failures_total.