fix(obs): 对齐无兼容层与健康/UV 权威语义

Agent 本地旧观测缓冲直接删除并运行重建;设计文档去掉兼容期表述。
健康当前态以 PG status/message 为准,CH 仅存 status 与连接时序;
Zone 曲线标明分桶 UV,顶部为整窗独立访客。
This commit is contained in:
ryan
2026-07-18 12:09:27 +08:00
parent 802d516f5b
commit 55f8c9a527
8 changed files with 285 additions and 107 deletions
+45 -38
View File
@@ -45,7 +45,7 @@
* Agent 保持轻量:解析日志行、读 `/proc`、健康检查;不做业务分析。
* 控制面 API 错误仍走统一信封与 `response.Abort*`。
* 访问日志字段变更须同时更新 OpenResty `log_format` 与 Agent 解析器,并保证向后兼容至少一个小版本。
* 访问日志字段变更须同时更新 OpenResty `log_format` 与 Agent 解析器;Agent 与控制面同版本发布,不保留旧协议解析。
---
@@ -228,20 +228,18 @@ flowchart TB
| 概念 | 字段 | 展示名 |
| --- | --- | --- |
| CPU / 内存 / 磁盘占用 | 现有 snapshot | 保持 |
| CPU / 内存 / 磁盘占用 | `host_metrics` | 保持 |
| 网卡累计字节 | `network_rx_bytes` / `network_tx_bytes` | **宿主机网卡入/出站** |
| 磁盘 IO 累计 | `disk_read_bytes` / `disk_write_bytes` | 磁盘读/写 |
### 6.2 废弃或降级字段
### 6.2 已删除字段(无兼容层)
| 现字段 | 处置 | 原因 |
| 原字段 | 处置 | 原因 |
| --- | --- | --- |
| `openresty_tx_bytes` | **废弃业务用途**;迁移期可读但 UI 不再展示为业务出站 | 与 `bytes_sent` 重复 |
| `openresty_rx_bytes` | **废弃业务用途**;由 `request_length` 聚合替代 | 与日志重复 |
| `TrafficReport` 全量 | **废弃权威地位**;迁移期可停写或仅兼容旧 Agent | 边缘预聚合 |
| `TrafficReport.top_domains` / `status_codes` / `unique_visitor_count` | 改由 Server 查日志 | 同上 |
| `openresty_tx_bytes` / `openresty_rx_bytes` | **删除** | 业务字节以 access log 为准 |
| `TrafficReport` 及 TopN/窗内 UV | **删除** | 边缘预聚合 |
| Agent state 内业务 lifetime 累计 | 删除 | 违背 P1 |
| Lua shared dict 业务吞吐/窗口请求计数 | 删除或仅保留本地诊断 | 非投递主路径 |
| Lua shared dict 业务吞吐/窗口请求计数 | 删除 | 非投递主路径 |
### 6.3 命名对照(前端文案强制)
@@ -262,21 +260,22 @@ flowchart TB
```text
NodePayload
identity / version / openresty_status
identity / version / openresty_status / openresty_message # 最新态 → PG
profile # 主机概况(低频)
snapshot # L3 资源读数(含网卡累计原值)
openresty_connections # L2 瞬时(可挂在精简 observation 或 snapshot 扩展)
host_metrics # L3 资源读数(含网卡累计原值)
edge_health # L2:status + connections(CH 时序;message 不进 CH)
access_logs[] # L1 明细(主路径)
health_events[]
buffered_observability[] # 缓冲的是上述事实,不是报表
buffered[] # 缓冲的是上述事实,不是报表
waf_ip_group_checksums
```
移除或标记 deprecated(兼容窗口内 Server 忽略写入分析权威路径):
协议中已删除(无兼容层):
```text
traffic_report # deprecated
openresty_observation.rx/tx # deprecated(connections 迁出后可删结构)
traffic_report
openresty_observation
snapshot / buffered_observability 别名
```
### 7.2 Access log 上报要求
@@ -291,7 +290,7 @@ openresty_observation.rx/tx # deprecated(connections 迁出后可删结构
| `path` | ✅ | 可截断 |
| `status_code` | ✅ | |
| `bytes_sent` | ✅ | body 字节,已提供数据 |
| `request_length` | ✅(协议补齐) | 接收数据;旧 Agent 可缺省为 0 |
| `request_length` | ✅ | 接收数据 |
Agent 职责:
@@ -329,10 +328,10 @@ Agent 职责:
| 输入 | 表 | 说明 |
| --- | --- | --- |
| `access_logs[]` | `of_node_access_logs` | 权威业务明细;补齐 `request_length` 列(若尚无) |
| `snapshot` | `of_node_metric_snapshots` | L3;网卡/磁盘累计 |
| 连接数 / 健康 | 现有节点状态或精简 obs 表 | L2 |
| `traffic_report` / openresty rx/tx | **停止作为权威写入** 或兼容期双写但不读 | 迁移后删除写入 |
| `access_logs[]` | `of_node_access_logs` | 权威业务明细 |
| `host_metrics` | `of_node_metric_snapshots` | L3;网卡/磁盘累计 |
| `openresty_status` / `openresty_message` | **PG 节点表** | L2 **最新态权威**(message 仅此) |
| `edge_health` | `of_node_edge_health` | L2 时序:status + connections(**无 message**) |
GeoIP:继续在 Server 入库路径解析 `remote_addr` → `region`,不在 Agent 做。
@@ -407,7 +406,7 @@ of_access_log_hourly
}
```
兼容:旧字段 `bytes_sent` 可在一个版本内作为 `bytes_provided` 的别名返回,文档标注 deprecated。
API 业务字节字段使用 `bytes_provided` / `bytes_received`(访问日志聚合);不再返回 openresty 吞吐别名。
### 9.2 看板
@@ -457,28 +456,36 @@ bytes_sent (= $body_bytes_sent), request_length
---
## 11. 兼容与迁移
## 11. 升级与迁移(无兼容层)
### 11.1 阶段划分
### 11.1 阶段回顾(已落地)
| 阶段 | 内容 | 结果 |
| --- | --- | --- |
| **M1 读路径切换** | 看板/节点业务趋势改为 access log 聚合;UI 文案改为已提供/接收数据 | 对账立刻成立;旧字段可仍写入 |
| **M2 协议补齐** | AccessLog 上报 `request_length`;Server 入库 | 接收数据可用 |
| **M3 停写预聚合** | Server 忽略/停写 TrafficReport 与 openresty rx/tx 权威路径 | 减负 |
| **M4 Agent 瘦身** | 移除边缘 TrafficReport 构建、Lua 业务计数、lifetime 累计 state | 符合 P1 |
| **M5 清理** | 删除废弃 CH 表/列、API 字段、前端类型 | 无冗余 |
| 阶段 | 内容 |
| --- | --- |
| **M1–M5** | 读路径切 access log;协议 v2;停预聚合;edge_health + access_log_hourly;删旧表与 API 兼容字段 |
### 11.2 兼容策略
### 11.2 升级策略
* 旧 Agent 仍发 `TrafficReport`:Server **不用于** 看板业务趋势。
* 旧 Agent 无 `request_length`:`bytes_received` 为 0 或不展示。
* 明细缺失时段:业务图为空或仅部分;**不得**回退到 openresty_tx 冒充已提供数据(避免再次双真相)。
* **Agent:销毁重建优先**;允许二进制替换。
* 二进制替换时:本地旧观测缓冲(含 `snapshot` / `openresty_observation` / `traffic_report`)**整文件删除**,运行后重建。
* Server **不**解析 v1 字段,**不**双读 request_reports / openresty 吞吐。
* 明细缺失时段:业务图为空或仅部分;**不得**用网卡或已删除的 openresty 吞吐冒充已提供数据。
### 11.3 数据回填
* 历史「已提供数据」以 access log 为准,无需从 openresty 观测回填。
* 历史看板 openresty 曲线可保留只读至 TTL,或直接隐藏。
* 历史「已提供数据」以 access log 为准。
* `of_access_log_hourly` 创建前历史用 goose 回填 SQL(ANTI JOIN 防重)。
### 11.4 健康状态权威
* **当前态**:PG `openresty_status` / `openresty_message`。
* **时序**:CH `of_node_edge_health`(status + connections;无 message)。
### 11.5 UV
* **整窗独立访客**:`uniqExact(remote_addr)`(看板合计、Zone 合计)。
* **分桶 UV**(Zone 曲线):桶内 uniq,**不可跨桶相加**;UI 须标明。
* **小时趋势路径**:不绘 / 不填分时 UV(hourly 表不含 UV)。
---
@@ -527,7 +534,7 @@ sum(各 Zone 已提供) + sum(未归属 Host) = 全局已提供
| 明细量大导致 CH 与心跳变重 | 批量、压缩、采样策略评估;Server rollup;限制单次条数 |
| 短暂丢失日志导致业务量偏低 | 本地 buffer 与轮转处理;监控 access log 采集滞后 |
| 用户仍对比「网卡出站」与「已提供」 | UI 分区与文案强制「宿主机」前缀 |
| 旧 Agent 长期在线 | 兼容期忽略预聚合;文档要求升级 Agent 以获得接收数据 |
| 旧 Agent 长期在线 | **无兼容层**;必须升级/重建 Agent |
**为何不保留 Agent 预聚合作为优化?**