Skip to main content
Calico Enterprise 3.21 (early preview) documentation

Prometheus metrics

Felix can be configured to report a number of metrics through Prometheus. See the configuration reference for how to enable metrics reporting.

Metric reference

Felix specific

Felix exports a number of Prometheus metrics. The current set is as follows. Since some metrics are tied to particular implementation choices inside Felix we can't make any hard guarantees that metrics will persist across releases. However, we aim not to make any spurious changes to existing metrics.

Cluster-wide metrics

NameDescription
felix_cluster_num_host_endpointsTotal number of host endpoints cluster-wide.
felix_cluster_num_hostsTotal number of Calico Enterprise hosts in the cluster.
felix_cluster_num_policiesTotal number of policies in the cluster.
felix_cluster_num_profilesTotal number of profiles in the cluster.
felix_cluster_num_tiersTotal number of Calico Enterprise tiers in the cluster.
felix_cluster_num_workload_endpointsTotal number of workload endpoints cluster-wide.

General metrics

NameDescription
felix_active_local_endpointsNumber of active endpoints (workload+host) on this host.
felix_active_local_policiesNumber of active policies on this host. Only "active" policies that match a local endpoint have a significant cost.
felix_active_local_selectorsNumber of active selectors on this host. Only "active" rule src/dest selectors have significant cost.
felix_exec_time_microsSummary of time taken to fork/exec child processes.
felix_log_errorsNumber of errors encountered while making normal "process" logs (for example to stdout).
felix_logs_droppedNumber of logs dropped because the output stream was blocked.

Calculation graph metrics

The calculation graph processes updates from the datastore to calculate the active endpoints/policy/etc for this node.

NameDescription
felix_calc_graph_output_eventsNumber of events emitted by the calculation graph.
felix_calc_graph_update_time_secondsSeconds to update calculation graph for each datastore OnUpdate call.
felix_calc_graph_updates_processedNumber of datastore updates processed by the calculation graph.

Common data plane metrics

NameDescription
felix_resyncs_startedNumber of times Felix has started resyncing with the datastore. (Not meaningful in a Typha deployment.)
felix_resync_stateCurrent datastore-dataplane synchronisation state, encoded as a number 1="waiting for datastore", 2="resync in progress", 3="in sync with datastore".
felix_int_dataplane_addr_msg_batch_sizeNumber of interface address messages processed in each batch. Higher values indicate we're doing more batching to try to keep up.
felix_int_dataplane_apply_time_secondsTime in seconds that it took to apply a data plane update.
felix_int_dataplane_failuresNumber of times data plane updates failed and will be retried.
felix_int_dataplane_iface_msg_batch_sizeNumber of interface state messages processed in each batch. Higher values indicate we're doing more batching to try to keep up.
felix_int_dataplane_messagesNumber data plane messages by type.
felix_int_dataplane_msg_batch_sizeNumber of messages processed in each batch. Higher values indicate we're doing more batching to try to keep up.
felix_route_table_list_secondsTime taken to list all the interfaces during a resync.
felix_route_table_per_iface_sync_secondsTime taken to sync each interface

iptables data plane metrics

NameDescription
felix_iptables_chainsNumber of active iptables chains.
felix_iptables_lines_executedNumber of iptables rule updates executed.
felix_iptables_lock_acquire_secsTime taken to acquire the iptables lock.
felix_iptables_lock_retriesNumber of times the iptables lock was already held and felix had to retry to acquire it.
felix_iptables_restore_callsNumber of iptables-restore calls.
felix_iptables_restore_errorsNumber of iptables-restore errors.
felix_iptables_rulesNumber of active iptables rules.
felix_iptables_save_callsNumber of iptables-save calls.
felix_iptables_save_errorsNumber of iptables-save errors.

BPF data plane metrics

NameDescription
felix_bpf_dataplane_endpointsNumber of BPF endpoints managed in the data plane.
felix_bpf_dirty_dataplane_endpointsNumber of BPF endpoints managed in the data plane that are left dirty after a failure.
felix_bpf_happy_dataplane_endpointsNumber of BPF endpoints that are successfully programmed.
felix_bpf_conntrack_cleanedNumber of entries cleaned during a conntrack table sweep.
felix_bpf_conntrack_cleaned_totalTotal number of entries cleaned during conntrack table sweeps, incremented for each clean individually.
felix_bpf_conntrack_expiredNumber of entries cleaned during a conntrack table sweep due to expiration.
felix_bpf_conntrack_expired_totalTotal number of entries cleaned during conntrack table sweep due to expiration - by reason.
felix_bpf_conntrack_inforeader_blocksConntrack InfoReader would-blocks.
felix_bpf_conntrack_stale_natNumber of entries cleaned during a conntrack table sweep due to stale NAT.
felix_bpf_conntrack_stale_nat_totalTotal number of entries cleaned during conntrack table sweeps due to stale NAT.
felix_bpf_conntrack_sweepsNumber of conntrack table sweeps made so far.
felix_bpf_conntrack_usedNumber of used entries visited during a conntrack table sweep.
felix_bpf_conntrack_sweep_durationConntrack sweep execution time (ns).
felix_bpf_num_ip_setsNumber of BPF IP sets managed in the data plane.

BPF events listener metrics

Low level component that receives messages from the BPF programs when notable events occur (suach as policy decisions).

NameDescription
felix_bpf_eventsNumber of events generated by BPF data plane split by type/category.
felix_bpf_events_collector_blocksNumber of times the output channel of the event loop blocked (because the downstream reader didn't keep up).

Egress gateway function metrics

NameDescription
felix_egress_gateway_remote_polls{status="total"}Total number of remote egress gateway pods that Felix is polling for health/connectivity. Only egress gateways with a named "health" port will be polled.
felix_egress_gateway_remote_polls{status="up"}Total number of remote egress gateway pods that have successful probes.
felix_egress_gateway_remote_polls{status="probe-failed"}Total number of remote egress gateway pods that have failed probes.

IPSec function metrics

NameDescription
felix_ipsec_bindings_totalTotal number of ipsec bindings.
felix_ipsec_errorsNumber of ipsec command failures.
felix_ipset_callsNumber of ipset commands executed.
felix_ipset_errorsNumber of ipset command failures.
felix_ipset_lines_executedNumber of ipset operations executed.
felix_ipsets_calicoNumber of active Calico Enterprise IP sets.
felix_ipsets_totalTotal number of active IP sets.

NFLOG reader metrics

Low level component that receives messages from the kernel when packets hit certain iptables rules. Used to collect policy verdicts, and DNS packets.

NameDescription
felix_nflog_netlink_messages_receivedTotal number of NFLOG "envelope" messages received from the kernel, broken down by NFLOG group. Each envelope message holds one or more NFLOGs.
felix_nflog_logs_receivedTotal number of NFLOG logs received from the kernel, broken down by NFLOG group. NFLOG messages are sent from the kernel for each policy verdict and for DNS logs.
felix_nflog_buffer_overrunsTotal number of times the kernel had to drop NFLOG messages because the kernel-to-Felix buffer was full.
felix_nflog_block_time_secondsTotal amount of time the NFLOG reader spent blocking waiting to send data to the "NFLOG aggregator".
felix_nflog_parse_errorsTotal number of errors encountered when trying to parse NFLOG messages.
felix_nflog_aggregates_createdTotal number of NFLOG "aggregates" created. Aggregates combine NFLOG messages that share the same 5-tuple before passing to the "collector".
felix_nflog_aggregates_flushedTotal number of NFLOG "aggregates" flushed to the "collector". The difference between this value and the "created" value shows how many aggregates are pending.

Flow logs collector metrics

Component that collects flow logs and metrics.

NameDescription
felix_collector_allowed_flowlog_aggregator_storeTotal number of FlowEntries with a given action currently residing in the FlowStore cache used by the aggregator.
felix_collector_conntrack_processing_latency_secondsHistogram for measuring the latency of Conntrack processing.
felix_collector_dataplanestats_update_processing_errors_per_minuteNumber of errors encountered when processing merging the proto.DataplaneStatistics to the current data cache.
felix_collector_dataplanestats_update_processing_latency_secondsHistogram for measuring latency for processing merging the proto.DataplaneStatistics to the current data cache.
felix_collector_dumpstats_latency_secondsHistogram for measuring latency for processing cached stats to stats file.
felix_collector_epstatsTotal number of entries currently residing in the endpoints statistics cache.
felix_collector_lookupcache_endpointsNumber of endpoints tracked in the look-up cache, used to resolve IP addresses to identities.
felix_collector_lookupcache_networksetsNumber of NetowrkSets tracked in the look-up cache, used to resolve IP addresses to identities.
felix_collector_lookupcache_servicesNumber of Services tracked in the look-up cache, used to resolve IP addresses to identities.
felix_collector_lookups_cache_policiesNumber of policies tracked in the look-up cache, used to resolve IP addresses to identities.
felix_collector_packet_info_processing_latency_secondsHistogram for measuring latency of processing "packet info" aggregates from the data plane.

DNS Policy/Logging metrics

NameDescription
felix_dns_req_packets_inNumber of DNS request packets received.
felix_dns_invalid_packets_inNumber of invalid DNS packets received.
felix_dns_non_query_packets_inNumber of non-query DNS packets received (and ignored).
felix_dns_resp_packets_inNumber of DNS responses received.

DNS DelayDeniedPacket mode metrics

NameDescription
felix_dns_packet_nfqueue_monitor_hold_timeSummary of the length of time the DNS response packets were held in userspace.
felix_dns_packet_nfqueue_monitor_num_unreleased_packetsGauge of the number of DNS response packets to release currently in memory.
felix_dns_packet_nfqueue_monitor_packets_inNumber of packets queued to Felix for delay.
felix_dns_packet_nfqueue_monitor_packets_released_conn_closedCount of how many DNS response packets in userspace have been dropped due to an NFQUEUE connection close.
felix_dns_packet_nfqueue_monitor_packets_released_programmedCount of how many DNS response packets have been released after updating data plane.
felix_dns_packet_nfqueue_monitor_packets_released_timeoutCount of how many DNS response packets have been released due to exceeding the delay timeout.
felix_dns_packet_nfqueue_monitor_queued_latencySummary of time packets spent delayed in the queue.
felix_dns_packet_nfqueue_monitor_shutdown_countCount of how many times nfqueue was shut down due to an error.
felix_dns_packet_nfqueue_monitor_verdict_failedCount of the number of times setting the verdict on a packet failed.

DNS DelayDNSResponse mode metrics

NameDescription
felix_dns_policy_nfqueue_monitor_nf_verdict_failedCount of how many times that the packet processor has failed to set the verdict on the packet.
felix_dns_policy_nfqueue_monitor_packets_dnr_droppedCount of the number of packets that have been dropped because the "do not recycle" mark was present.
felix_dns_policy_nfqueue_monitor_packets_inCount of the number of packets received on the queue.
felix_dns_policy_nfqueue_monitor_packets_releasedCount of total packets released.
felix_dns_policy_nfqueue_monitor_queued_latencySummary of time packets spent delayed in the queue.
felix_dns_policy_nfqueue_monitor_release_latencySummary of the latency for releasing packets.
felix_dns_policy_nfqueue_monitor_release_packets_batch_sizeGauge of the number of packets to release currently in memory
felix_dns_policy_nfqueue_shutdown_countCount of how many times nfqueue was shut down due to an error.

Flow logs reporter metrics

Component that sends flow logs to syslog.

NameDescription
felix_reporter_log_errorsNumber of errors encountered while logging (flow logs) to Syslog.
felix_reporter_logs_droppedNumber of flow logs dropped because the output was blocked in the Syslog reporter.

Prometheus metrics are self-documenting, with metrics turned on, curl can be used to list the metrics along with their help text and type information.

curl -s http://localhost:9091/metrics | head

Example response:

# HELP felix_active_local_endpoints Number of active endpoints on this host.
# TYPE felix_active_local_endpoints gauge
felix_active_local_endpoints 91
# HELP felix_active_local_policies Number of active policies on this host.
# TYPE felix_active_local_policies gauge
felix_active_local_policies 0
# HELP felix_active_local_selectors Number of active selectors on this host.
# TYPE felix_active_local_selectors gauge
felix_active_local_selectors 82
...

Label indexing metrics

The label index is a subcomponent of Felix that is responsible for calculating the set of endpoints and network sets that match each selector that is in an active policy rule. Policy rules are active on a particular node if the policy they belong to selects a workload or host endpoint on that node with its top-level selector (in spec.selector). Inactive policies have minimal CPU cost because their selectors do not get indexed.

Since the label index must match the active selectors against all endpoints and network sets in the cluster, its performance is critical and it supports various optimizations to minimize CPU usage. Its metrics can be used to check that the optimizations are active for your policy set.

felix_label_index_num_endpoints

Reports the total number of endpoints (and similar objects such as network sets) being tracked by the index. This should match the number of endpoints and network sets in your cluster.

felix_label_index_num_active_selectors{optimized="true|false"}

Reports the total number of active selectors, broken into optimized="true" and optimized="false" sub-totals.

The optimized="true" total tracks the number of selectors that the label index was able to optimize. Those selectors should be calculated efficiently even in clusters with hundreds of thousands of endpoints. In general the CPU used to calculate them should be proportional to the number of endpoints that match them and the churn rate of those endpoints.

The optimized="false" total tracks the number of selectors that could not be optimized. Unoptimized selectors are much more costly to calculate; the CPU used to calculate them is proportional to the number of endpoints in the cluster and their churn rate. It is generally OK to have a handful of unoptimized selectors, but if many selectors are unoptimized the CPU usage can be substantial at high scale.

For more information on writing selectors that can be optimized, see the this section of the NetworkPolicy reference.

felix_label_index_selector_evals{result="true|false"}

Counts the total number of times that a selector was evaluated vs an endpoint to determine if it matches, broken down by match (true) or no-match (false). The ratio of match to no-match shows how effective the selector indexing optimizations are for your policy set. The more effectively the label index can optimize the selectors, the fewer "no-match" results it will report relative to "match".

If you have more than a handful of active selectors and felix_label_index_selector_evals{result="false"} is many times felix_label_index_selector_evals{result="true"} then it is likely that some selectors in the policy set are not being optimized effectively.

felix_label_index_strategy_evals{strategy="..."}

This is a technical statistic that shows how many times the label index has employed each optimization strategy that it has available. The strategies will likely evolve over time but, at time of writing, they are as follows:

  • endpoint-full-scan: the least efficient fall back strategy for unoptimized selectors. The index scanned all endpoints to find the matches for a selector.

  • endpoint|parent-no-match: the most efficient strategy; the index was able to prove that nothing matched the selector so it was able to skip the scan entirely.

  • endpoint|parent-single-value: the label index was able to limit the scan to only those endpoints/parents that have a particular label and value combination. For example, selector label == "value" would only scan items that had exactly that label set to "value".

  • endpoint|parent-multi-value: the label index was able to limit the scan to only those endpoints/parents that have a particular label and one of a few values. For example, selector label in {"a", "b") would only scan items that had exactly that label with one of the given values.

  • endpoint|parent-label-name: the label index was able to limit the scan to only those endpoints/parents that hava a particular label (but was unable to limit it to a particular subset of values). For example, has(label) would result in that kind of scan.

Terminology: here "endpoint" means "endpoint or NetworkSet" and "parent" is Felix's internal name for resources like Kubernetes Namespaces. A "parent" scan means that the label index scanned all endpoints that have a parent matching the strategy.

CPU / memory metrics

Felix also exports the default set of metrics that Prometheus makes available. Currently, those include:

NameDescription
go_gc_duration_secondsA summary of the GC invocation durations.
go_goroutinesNumber of goroutines that currently exist.
go_infoGo version.
go_memstats_alloc_bytesNumber of bytes allocated and still in use.
go_memstats_alloc_bytes_totalTotal number of bytes allocated, even if freed.
go_memstats_buck_hash_sys_bytesNumber of bytes used by the profiling bucket hash table.
go_memstats_frees_totalTotal number of frees.
go_memstats_gc_cpu_fractionThe fraction of this program’s available CPU time used by the GC since the program started.
go_memstats_gc_sys_bytesNumber of bytes used for garbage collection system metadata.
go_memstats_heap_alloc_bytesNumber of heap bytes allocated and still in use.
go_memstats_heap_idle_bytesNumber of heap bytes waiting to be used.
go_memstats_heap_inuse_bytesNumber of heap bytes that are in use.
go_memstats_heap_objectsNumber of allocated objects.
go_memstats_heap_released_bytesNumber of heap bytes released to OS.
go_memstats_heap_sys_bytesNumber of heap bytes obtained from system.
go_memstats_last_gc_time_secondsNumber of seconds since 1970 of last garbage collection.
go_memstats_lookups_totalTotal number of pointer lookups.
go_memstats_mallocs_totalTotal number of mallocs.
go_memstats_mcache_inuse_bytesNumber of bytes in use by mcache structures.
go_memstats_mcache_sys_bytesNumber of bytes used for mcache structures obtained from system.
go_memstats_mspan_inuse_bytesNumber of bytes in use by mspan structures.
go_memstats_mspan_sys_bytesNumber of bytes used for mspan structures obtained from system.
go_memstats_next_gc_bytesNumber of heap bytes when next garbage collection will take place.
go_memstats_other_sys_bytesNumber of bytes used for other system allocations.
go_memstats_stack_inuse_bytesNumber of bytes in use by the stack allocator.
go_memstats_stack_sys_bytesNumber of bytes obtained from system for stack allocator.
go_memstats_sys_bytesNumber of bytes obtained by system. Sum of all system allocations.
go_threadsNumber of OS threads created.
process_cpu_seconds_totalTotal user and system CPU time spent in seconds.
process_max_fdsMaximum number of open file descriptors.
process_open_fdsNumber of open file descriptors.
process_resident_memory_bytesResident memory size in bytes.
process_start_time_secondsStart time of the process since unix epoch in seconds.
process_virtual_memory_bytesVirtual memory size in bytes.
process_virtual_memory_max_bytesMaximum amount of virtual memory available in bytes.

Wireguard Metrics

Felix also exports wireguard device stats if found/detected. Can be disabled via Felix configuration.

NameDescription
wireguard_metaGauge. Device / interface information for a felix/calico node, values are in this metric's labels
wireguard_bytes_rcvdCounter. Current bytes received from a peer identified by a peer public key and endpoint
wireguard_bytes_sentCounter. Current bytes sent to a peer identified by a peer public key and endpoint
wireguard_latest_handshake_secondsGauge. Last handshake with a peer, unix timestamp in seconds.