Commit Graph
29 Commits
Author SHA1 Message Date
Wez Furlong 9efc2a031c allow mocking mta-sts end-to-end, add integration test coverage
This sets up plumbing to allow testing the broken mta-sts aliasing
issue, and enables feeding an optional resolver through the mx lookups
as well.

closes: https://github.com/KumoCorp/kumomta/pull/524
2026-07-27 08:02:37 +01:00
Wez Furlong 41be60dfce Evaluate MTA-STS during MX resolution to fix aliasing issue
refs: https://github.com/KumoCorp/kumomta/issues/484

Briefly, the issue is that if some random domain that shares MX records
with another (eg: someone is using google apps or icloud for their
vanity domain) publishes a broken MTA-STS policy that requires eg:
cloudflare MX hosts then because we roll up by site name, that broken
MTA-STS policy bleeds into all the other domains that share those MX
records.

The resolution is simple, but is technically a breaking change.

Moving the policy resolution to happen during site_name resolution
allows us to resolve both per-domain things at the same and have the
MTA-STS policy amend the effective set of MX hosts.  The output of that
is then used for site_name aggregation/rollup.

The consequence of this is quite nice: an MTA-STS policy that is more
restrictive than the full set of MX hosts now prevents delivering to
any of the excluded hosts, and a totally broken policy that prevents all
of its MX hosts is now completely undeliverable and will produce
transient failures.

The downside is that for users that had previously disabled mta-sts in
their default shaping block, they will need to change a different config
option to continue to prevent MTA-STS from being consulted.  One example
of this that I recall is that one user's network posture prevented
MTA-STS from making HTTPS requests to fetch the policy.  Another user
just wanted to cut out the additional DNS traffic.  Those use cases
require altering the new kumo.dns.set_mta_sts_enabled enabled to false
during `init`.
2026-07-27 08:02:37 +01:00
Wez Furlong 909b1190cd refactor: extract kumo-api-client from kcli
This enables reusing just the http client parts of kcli
in another module in the future.
2026-02-24 12:19:53 +00:00
Wez Furlong e3fdcaa628 cargo clippy --fix 2025-04-09 10:26:07 -07:00
Wez Furlong ff8c0ccff2 Expose ready queue states via api, and in kcli queue-summary
This adds connection limit/throttle states to the readyq rows
in `kcli queue-summary`, alongside where we would show the
suspension state.

This makes it easier to understand when a given egress path
might be hitting connection limits.
2024-12-21 07:44:29 -07:00
Wez Furlong 2366efad7e kcli queue-summary: show bounce/suspend reason
Include the reason for the bounce/suspension in the status annotation
that we show alongside a queue.

Previously, I considered this to be potentially noisy, but if you
consider that the most likely source of these annotations is likely
to be TSA, having that additional context is helpful.
2024-09-13 08:52:54 -07:00
Wez Furlong ed92367ea9 kcli: queue-summary: fix displaying suspension status
When rendering the suspension and bounce status, the various
queue name component parameters were flipped wrt. to the
suspension and bounce entries, causing them not to match.

This commit fixes that and restores stop sign and trash can
emoji status annotations to the output.
2024-09-13 08:52:54 -07:00
Wez Furlong 9c05e5e681 kcli queue-summary: fixup --limit handling for scheduled queues
The optimization to window over the minimal set wasn't excluding results
in the right way, so let's just remove that; we handle truncating
the overall results at a later stage anyway.
2024-09-13 08:52:54 -07:00
Wez Furlong aecb0d9713 kcli: *summary: use thousands separators for numeric output
Especially with provider-summary, the numbers can be very large
and adding the thousands separators makes them easier for humans
to parse.
2024-09-13 08:52:54 -07:00
Wez Furlong a90445a921 kcli: queue-summary: fixup output mentioning metrics endpoint
We switched from metrics.json to the main metrics endpoint,
so update this help text.
2024-09-13 08:52:54 -07:00
Wez Furlong ad9a110920 rustfmt 2024-09-05 08:24:54 -07:00
Wez Furlong 5d4648782d kcli queue-summary: fix D and T columns in output
The recent changes in the streaming metrics parser made these look
at the wrong metric names.
2024-09-05 07:44:35 -07:00
Wez Furlong 484e8aeb4a kcli: adopt streaming metrics parser for top
This makes performance super fast in the prescence of millions
of queues.
2024-09-02 10:42:15 -07:00
Wez Furlong 285f246bc7 kcli: adopt streaming prometheus parser for queue-summary
This makes it work faster when there are a large number of queues.
2024-09-02 10:42:15 -07:00
Wez Furlong 8c1bfe4c7e kcli: handle list form of json metrics
```
  "scheduled_by_tenant_campaign": {
    "help": "number of messages in the scheduled queue for a specific tenant and campaign combination",
    "type": "gauge",
    "value": [
      {
        "@": 0.0,
        "campaign": "my-campaign",
        "tenant": "my-tenant"
      },
      ]
```
2024-08-22 14:20:16 -07:00
Wez Furlong d68859969d kcli: make it easier to add and consume histograms
Add a pass over the metrics data to collect the items more dynamically
than previously. This should parse out any newly added metric without
requiring that it be specifically named in the metrics struct in
here, making for less boilerplate.
2024-08-22 11:07:07 -07:00
Wez Furlong a9daff1f42 metrics: kcli: display p90 instead of avg
This commit adjusts the formatting of the json rendition of
histogram buckets, and then teaches kcli how to compute
quantiles over the buckets.

We use that to collect and show the p90 rather than the avg
latency in kcli top.

I want to add more histogram specific presentation options
to kcli in a follow up commit; this is just capturing
the quantile logic.
2024-08-22 11:07:07 -07:00
Wez Furlong b7754fe509 smtp server: add histograms around reading and processing data 2024-08-20 11:06:52 -07:00
Wez Furlong 0d8cbf32c1 smtp server: add overall transaction latency histogram 2024-08-20 10:43:05 -07:00
Wez Furlong 6fcb8ca47e add dkim signing histograms to metrics 2024-08-20 10:03:26 -07:00
Wez Furlong abab4a2759 kcli: add latency metrics to kcli top
I'm not totally happy with how these render, as it looks a little
cluttered, but it's nice to have the rates for the various
events shown along with the average latencies.
2024-08-17 14:24:12 -07:00
Wez Furlong bef8baebc2 kcli top: improve layout, add metrics
Add permfail and thread pool utilization metrics.
Make the vertical layout work a bit better.
2024-05-06 20:06:34 -07:00
Wez Furlong b8a0b26936 NEW: kcli top
This will shows some TUI sparkline charts of major system metrics
over time.
2024-05-04 13:13:09 -07:00
Wez Furlong fbb140026d kcli queue-summary: use stop emoji rather than pause emoji
It looks clearer and easier to understand than the pause emoji,
especially at normal terminal font sizes.
2023-08-07 08:06:39 -07:00
Wez Furlong 927e18dd58 kcli queue-summary: use emoji to indicate suspensions and bounces
Use the pause emoji for suspensions, and the wastebasket emoji for
bounces.  These are shown in the final column of the respective
sections.

Note that for bounces there will only be a short time window where you
will see a bounced domain show up in the list because the bounce will
remove it from the system fairly quickly.
2023-08-05 13:43:58 -07:00
Wez Furlong 93423f7778 kcli queue-summary: parallelize domain resolution with --domain
Resolve them all concurrently
2023-08-05 10:27:00 -07:00
Wez Furlong 5e966f4571 kcli queue-summary: use natural sort for names
So that `source10` sorts after `source9` rather than `source1`
2023-08-05 09:57:51 -07:00
Wez Furlong 7b63f7d80d kcli queue-summary: add --domain option
Allows filtering the results to just those queues associated
with the requested domain.  Uses site names to map domains
to their associated ready queues.
2023-08-04 22:57:46 -07:00
Wez Furlong 6b8a6b8435 kcli: add queue-summary command
Helpful for an at-a-glance idea of what's happening
2023-08-04 20:19:45 -07:00