Workers Logs keep every log only where every failure matters, a tenth on the busy request paths
Every Worker kept 100% of its invocation logs. Billing, identity, runner, actions, deployments, status and sudo keep all of them: money, sign-in, runs someone will ask about, or too few requests to matter. Web, api, pages, repos, og, models, search, context, events, work, webhooks, integrations, packages, projects, security and docs keep a tenth. Head sampling drops an unsampled request's errors with the rest of its logs; the dashboard's error counts are not sampled. docs/RATE-LIMITS.md has the table and when to raise a Worker's rate to chase a rare error.
23 files+47−230/23 viewed
| 48 | 48 | { "name": "API_ANONYMOUS_LIMIT", "namespace_id": "4401", "simple": { "limit": 60, "period": 60 } }, | |
| 49 | 49 | { "name": "API_TOKEN_LIMIT", "namespace_id": "4402", "simple": { "limit": 1000, "period": 60 } } | |
| 50 | 50 | ], | |
| 51 | − | "observability": { "enabled": true } | |
| 51 | + | // Logs of a tenth of requests: agents call it constantly. | |
| 52 | + | "observability": { "enabled": true, "head_sampling_rate": 0.1 } | |
| 52 | 53 | } |
| 8 | 8 | "directory": "./dist", | |
| 9 | 9 | "not_found_handling": "404-page" | |
| 10 | 10 | }, | |
| 11 | − | "routes": [{ "pattern": "docs.g1t.sh", "custom_domain": true }] | |
| 11 | + | "routes": [{ "pattern": "docs.g1t.sh", "custom_domain": true }], | |
| 12 | + | // Logs of a tenth of requests: files only, nothing to debug in each. | |
| 13 | + | "observability": { "enabled": true, "head_sampling_rate": 0.1 } | |
| 12 | 14 | } |
| 76 | 76 | { "name": "STATUS_SUBSCRIBE_LIMIT", "namespace_id": "4601", "simple": { "limit": 3, "period": 60 } }, | |
| 77 | 77 | { "name": "STATUS_EMAIL_LIMIT", "namespace_id": "4602", "simple": { "limit": 2, "period": 60 } } | |
| 78 | 78 | ], | |
| 79 | − | "observability": { "enabled": true } | |
| 79 | + | // Every log kept: few requests, and the checks' failures are what it is for. | |
| 80 | + | "observability": { "enabled": true, "head_sampling_rate": 1 } | |
| 80 | 81 | } |
| 42 | 42 | // The Access application needs a Service Auth policy including it. | |
| 43 | 43 | "STAFF_SERVICE_TOKENS": "434297ede60761875e84742d0486cf27.access=claude" | |
| 44 | 44 | }, | |
| 45 | − | "observability": { "enabled": true }, | |
| 45 | + | // Every log kept: staff only, few requests. | |
| 46 | + | "observability": { "enabled": true, "head_sampling_rate": 1 }, | |
| 46 | 47 | "upload_source_maps": true | |
| 47 | 48 | } |
| 54 | 54 | { "name": "GIT_ANONYMOUS_LIMIT", "namespace_id": "4205", "simple": { "limit": 120, "period": 60 } }, | |
| 55 | 55 | { "name": "GIT_SIGNED_LIMIT", "namespace_id": "4206", "simple": { "limit": 1200, "period": 60 } } | |
| 56 | 56 | ], | |
| 57 | − | "observability": { "enabled": true }, | |
| 57 | + | // Logs of a tenth of requests: every page view is one, too many to keep all. | |
| 58 | + | "observability": { "enabled": true, "head_sampling_rate": 0.1 }, | |
| 58 | 59 | "upload_source_maps": true | |
| 59 | 60 | } |
| 41 | 41 | }, | |
| 42 | 42 | // Schedules, jobs waiting for room, and jobs whose runner went quiet. | |
| 43 | 43 | "triggers": { "crons": ["* * * * *"] }, | |
| 44 | − | "observability": { "enabled": true } | |
| 44 | + | // Every log kept: few requests, and a failed job must be traceable. | |
| 45 | + | "observability": { "enabled": true, "head_sampling_rate": 1 } | |
| 45 | 46 | } |
| 145 | 145 | // STRIPE_WEBHOOK_SECRET: the signing secret (whsec_…) of the destination | |
| 146 | 146 | // made in Stripe's dashboard for https://api.g1t.sh/stripe/webhook. | |
| 147 | 147 | // Without it every event is refused (the replay still reads them). | |
| 148 | − | "observability": { "enabled": true } | |
| 148 | + | // Every log kept: money moves here, and every failure matters. | |
| 149 | + | "observability": { "enabled": true, "head_sampling_rate": 1 } | |
| 149 | 150 | } |
| 41 | 41 | { "queue": "g1t-context-jobs", "max_batch_size": 1, "max_batch_timeout": 1, "max_retries": 2 } | |
| 42 | 42 | ] | |
| 43 | 43 | }, | |
| 44 | − | "observability": { "enabled": true } | |
| 44 | + | // Logs of a tenth of requests: agents search it constantly. | |
| 45 | + | "observability": { "enabled": true, "head_sampling_rate": 0.1 } | |
| 45 | 46 | } |
| 55 | 55 | // Secret: CLOUDFLARE_API_TOKEN, scoped to Workers Scripts (edit) and | |
| 56 | 56 | // Account Analytics (read), and, for custom domains, SSL and | |
| 57 | 57 | // Certificates (edit) on the g1t.page zone. Without it nothing deploys. | |
| 58 | − | "observability": { "enabled": true } | |
| 58 | + | // Every log kept: few requests, and a failed deploy must be traceable. | |
| 59 | + | "observability": { "enabled": true, "head_sampling_rate": 1 } | |
| 59 | 60 | } |
| 56 | 56 | // older than AUDIT_MIN_DAYS, the shortest any plan keeps, are asked about. | |
| 57 | 57 | "triggers": { "crons": ["41 3 * * *"] }, | |
| 58 | 58 | "vars": { "AUDIT_MAX_DAYS": "400", "AUDIT_MIN_DAYS": "7" }, | |
| 59 | − | "observability": { "enabled": true } | |
| 59 | + | // Logs of a tenth of requests: every change in g1t is an event. | |
| 60 | + | "observability": { "enabled": true, "head_sampling_rate": 0.1 } | |
| 60 | 61 | } |
| 70 | 70 | "INVITE_STAFF_WORKSPACES": "flagon-io", | |
| 71 | 71 | "WAITLIST_NOTIFY_EMAIL": "hey@flagon.io" | |
| 72 | 72 | }, | |
| 73 | − | "observability": { "enabled": true } | |
| 73 | + | // Every log kept: sign-ins and tokens, where every failure matters. | |
| 74 | + | "observability": { "enabled": true, "head_sampling_rate": 1 } | |
| 74 | 75 | } |
| 43 | 43 | }, | |
| 44 | 44 | // Secret: INTEGRATIONS_KEY, 64 hex characters. Connections' secrets are | |
| 45 | 45 | // sealed with it; without it nothing can be connected. | |
| 46 | − | "observability": { "enabled": true } | |
| 46 | + | // Logs of a tenth of requests: every page and event asks it. | |
| 47 | + | "observability": { "enabled": true, "head_sampling_rate": 0.1 } | |
| 47 | 48 | } |
| 30 | 30 | // not hold g1t's key; WORKERS_AI_TOKEN, a Cloudflare API token with | |
| 31 | 31 | // Workers AI Read on this account, for the AI Gateway's open models | |
| 32 | 32 | // (without it AI_GATEWAY_TOKEN is tried, and needs that permission too). | |
| 33 | − | "observability": { "enabled": true } | |
| 33 | + | // Logs of a tenth of requests: every model call is one. | |
| 34 | + | "observability": { "enabled": true, "head_sampling_rate": 0.1 } | |
| 34 | 35 | } |
| 36 | 36 | // Cards drawn for a cache miss, per address (src/index.ts). Past it, | |
| 37 | 37 | // the brand card. Id and limit: RATE_LIMITS in packages/contracts. | |
| 38 | 38 | "ratelimits": [{ "name": "OG_RENDER_LIMIT", "namespace_id": "4501", "simple": { "limit": 60, "period": 60 } }], | |
| 39 | − | "observability": { "enabled": true } | |
| 39 | + | // Logs of a tenth of requests: every link shared is one. | |
| 40 | + | "observability": { "enabled": true, "head_sampling_rate": 0.1 } | |
| 40 | 41 | } |
| 72 | 72 | "queues": { | |
| 73 | 73 | "consumers": [{ "queue": "g1t-events-packages", "max_batch_size": 20, "max_batch_timeout": 1 }] | |
| 74 | 74 | }, | |
| 75 | − | "observability": { "enabled": true } | |
| 75 | + | // Logs of a tenth of requests: every registry pull is one. | |
| 76 | + | "observability": { "enabled": true, "head_sampling_rate": 0.1 } | |
| 76 | 77 | } |
| 24 | 24 | "dispatch_namespaces": [{ "binding": "APPS", "namespace": "g1t-deployments" }], | |
| 25 | 25 | // Custom domains: hostname to app, written by the deployments service. | |
| 26 | 26 | "kv_namespaces": [{ "binding": "DOMAINS", "id": "14bc5c233d4c46a5bbf23b5367cce5fd" }], | |
| 27 | − | "observability": { "enabled": true } | |
| 27 | + | // Logs of a tenth of requests: every visit to a deployed site is one. | |
| 28 | + | "observability": { "enabled": true, "head_sampling_rate": 0.1 } | |
| 28 | 29 | } |
| 28 | 28 | "queues": { | |
| 29 | 29 | "consumers": [{ "queue": "g1t-events-projects", "max_batch_size": 20, "max_batch_timeout": 1 }] | |
| 30 | 30 | }, | |
| 31 | − | "observability": { "enabled": true } | |
| 31 | + | // Logs of a tenth of requests: every repository page asks it. | |
| 32 | + | "observability": { "enabled": true, "head_sampling_rate": 0.1 } | |
| 32 | 33 | } |
| 132 | 132 | { "name": "PACK_FILL_LIMIT", "namespace_id": "4301", "simple": { "limit": 30, "period": 60 } }, | |
| 133 | 133 | { "name": "ANONYMOUS_FETCH_LIMIT", "namespace_id": "4302", "simple": { "limit": 120, "period": 60 } } | |
| 134 | 134 | ], | |
| 135 | − | "observability": { "enabled": true } | |
| 135 | + | // Logs of a tenth of requests: every git request and page is one. | |
| 136 | + | "observability": { "enabled": true, "head_sampling_rate": 0.1 } | |
| 136 | 137 | } |
| 119 | 119 | "BACKUPS_PER_SWEEP": "4", | |
| 120 | 120 | "BACKUPS_RUNNING": "6" | |
| 121 | 121 | }, | |
| 122 | − | "observability": { "enabled": true } | |
| 122 | + | // Every log kept: few requests, and a failed run must be traceable. | |
| 123 | + | "observability": { "enabled": true, "head_sampling_rate": 1 } | |
| 123 | 124 | } |
| 34 | 34 | { "queue": "g1t-search-jobs", "max_batch_size": 1, "max_batch_timeout": 1, "max_retries": 3 } | |
| 35 | 35 | ] | |
| 36 | 36 | }, | |
| 37 | − | "observability": { "enabled": true } | |
| 37 | + | // Logs of a tenth of requests: every search is one. | |
| 38 | + | "observability": { "enabled": true, "head_sampling_rate": 0.1 } | |
| 38 | 39 | } |
| 45 | 45 | "vars": { | |
| 46 | 46 | "SITE_URL": "https://g1t.sh" | |
| 47 | 47 | }, | |
| 48 | − | "observability": { "enabled": true } | |
| 48 | + | // Logs of a tenth of requests: every push and page asks it. | |
| 49 | + | "observability": { "enabled": true, "head_sampling_rate": 0.1 } | |
| 49 | 50 | } |
| 29 | 29 | "triggers": { "crons": ["* * * * *"] }, | |
| 30 | 30 | // Secret: WEBHOOKS_KEY, 64 hex characters. Webhooks' signing secrets are | |
| 31 | 31 | // sealed with it; without it none can be made. | |
| 32 | − | "observability": { "enabled": true } | |
| 32 | + | // Logs of a tenth of requests: every event is a delivery to look up. | |
| 33 | + | "observability": { "enabled": true, "head_sampling_rate": 0.1 } | |
| 33 | 34 | } |
| 26 | 26 | "queues": { | |
| 27 | 27 | "consumers": [{ "queue": "g1t-events-work", "max_batch_size": 100, "max_batch_timeout": 1 }] | |
| 28 | 28 | }, | |
| 29 | − | "observability": { "enabled": true } | |
| 29 | + | // Logs of a tenth of requests: every issue and pull request page asks it. | |
| 30 | + | "observability": { "enabled": true, "head_sampling_rate": 0.1 } | |
| 30 | 31 | } |