fix(audit): 审计按账号 id 归属并记录来源 IP/UA,登录失败与限速入审计和指标,写入失败计数告警

This commit is contained in:
Lemon-miaow committed 2026-09-24 16:02:44 +08:00
1 parent c4e4953f3d
commit 857c73a66a
39 files changed
+794 -161

No files matched your search

+25 -1
View File
@@ -6,7 +6,9 @@
# - felis-operator pod :8080/metrics → felis_servers_total, felis_start_duration_seconds
# - felis-api internal :8081/metrics → felis_image_build_failures_total,
# felis_mail_total, felis_rate_limited_total,
# felis_auth_otp_lockouts_total
# felis_auth_otp_lockouts_total,
# felis_auth_failures_total,
# felis_audit_write_failures_total
# - node-exporter textfile collector → felis_db_backup_* (felis-db-backup.timer)
# node_* / kube_* series come from node-exporter / kube-state-metrics.
groups:
@@ -142,3 +144,25 @@ groups:
The audit log names the account (action auth.otp.locked); the owner was
mailed. Unless they fumbled codes, someone is guessing at it
(troubleshooting §17).
- alert: FelisSignInFailures
expr: sum(increase(felis_auth_failures_total[15m])) > 30
for: 5m
labels:
severity: warning
annotations:
summary: "over 30 refused sign-ins in 15 minutes"
description: >-
Wrong codes, unknown addresses or bad passkey assertions well above people
mistyping: someone is guessing or enumerating. `sum by (door, reason)
(increase(felis_auth_failures_total[15m]))` shows where; the audit rows
(action auth.<door>.failed) carry each caller's client_ip (troubleshooting §17).
- alert: FelisAuditWriteFailing
expr: increase(felis_audit_write_failures_total[15m]) > 0
labels:
severity: warning
annotations:
summary: "felis-api failed to write audit rows"
description: >-
The actions went through but their audit rows were lost. The felis-api log
names each lost row (`audit: lost ...`); the usual cause is PostgreSQL
being unreachable or out of disk.
+55
View File
@@ -236,3 +236,58 @@ tests:
- eval_time: 90m
alertname: FelisOTPAccountLocked
exp_alerts: []
- name: sign-in failure rate
interval: 1m
input_series:
# Two doors failing at 3/min between them from t=0.
- series: 'felis_auth_failures_total{door="login_email",reason="bad_code",job="felis-api"}'
values: '0+2x40'
- series: 'felis_auth_failures_total{door="op_login",reason="no_account",job="felis-api"}'
values: '0+1x40'
alert_rule_test:
- eval_time: 8m
alertname: FelisSignInFailures
exp_alerts: []
- eval_time: 25m
alertname: FelisSignInFailures
exp_alerts:
- exp_labels:
severity: warning
exp_annotations:
summary: "over 30 refused sign-ins in 15 minutes"
description: >-
Wrong codes, unknown addresses or bad passkey assertions well above people
mistyping: someone is guessing or enumerating. `sum by (door, reason)
(increase(felis_auth_failures_total[15m]))` shows where; the audit rows
(action auth.<door>.failed) carry each caller's client_ip (troubleshooting §17).
- name: people mistyping stays quiet
interval: 1m
input_series:
- series: 'felis_auth_failures_total{door="login_email",reason="bad_code",job="felis-api"}'
values: '0 0 1 1 2 2 3 3 4 4 5x30'
alert_rule_test:
- eval_time: 30m
alertname: FelisSignInFailures
exp_alerts: []
- name: audit rows lost
interval: 1m
input_series:
- series: 'felis_audit_write_failures_total{job="felis-api",instance="api-0"}'
values: '0 0 0 2x20'
alert_rule_test:
- eval_time: 2m
alertname: FelisAuditWriteFailing
exp_alerts: []
- eval_time: 5m
alertname: FelisAuditWriteFailing
exp_alerts:
- exp_labels:
severity: warning
job: felis-api
instance: api-0
exp_annotations:
summary: "felis-api failed to write audit rows"
description: >-
The actions went through but their audit rows were lost. The felis-api log
names each lost row (`audit: lost ...`); the usual cause is PostgreSQL
being unreachable or out of disk.
+22
View File
@@ -144,3 +144,25 @@ spec:
The audit log names the account (action auth.otp.locked); the owner was
mailed. Unless they fumbled codes, someone is guessing at it
(troubleshooting §17).
- alert: FelisSignInFailures
expr: sum(increase(felis_auth_failures_total[15m])) > 30
for: 5m
labels:
severity: warning
annotations:
summary: "over 30 refused sign-ins in 15 minutes"
description: >-
Wrong codes, unknown addresses or bad passkey assertions well above people
mistyping: someone is guessing or enumerating. `sum by (door, reason)
(increase(felis_auth_failures_total[15m]))` shows where; the audit rows
(action auth.<door>.failed) carry each caller's client_ip (troubleshooting §17).
- alert: FelisAuditWriteFailing
expr: increase(felis_audit_write_failures_total[15m]) > 0
labels:
severity: warning
annotations:
summary: "felis-api failed to write audit rows"
description: >-
The actions went through but their audit rows were lost. The felis-api log
names each lost row (`audit: lost ...`); the usual cause is PostgreSQL
being unreachable or out of disk.