How to monitor hosted FusionAuth instance performance and metrics?
-
We are running a hosted FusionAuth deployment and need to monitor its performance, including metrics like memory and CPU utilization. What options are available for monitoring a hosted instance beyond basic health checks?
-
There are several ways to monitor your hosted FusionAuth deployment:
Basic Health Monitoring
You can use the System Status API to get basic information about your deployment, including whether it is healthy. For dedicated health checks (particularly useful for load balancers), there's also the Health API available since version 1.51.1.
Detailed Metrics with Prometheus
For more detailed performance monitoring, you can configure Prometheus to retrieve system metrics from FusionAuth. FusionAuth exposes:
- JVM-level gauges: memory usage, garbage collection stats, thread counts, class loading, buffer pools
- Request timers: endpoint latency and request counts (e.g.,
prime_mvc_*metrics)
You can then set up Prometheus dashboards to visualize this data and track CPU, memory, and other performance metrics over time.
See the FusionAuth Prometheus documentation for configuration details and the Prometheus Metrics API for endpoint information.
Important Considerations for Hosted Deployments
If your hosted FusionAuth deployment has multiple compute nodes, be aware that both the Status API and Prometheus metrics endpoints return data per-node. Since requests are round-robined across nodes, successive API calls may hit different nodes and return inconsistent data. This makes direct polling less reliable for multi-node deployments.
Additional Monitoring Options
Beyond Prometheus, FusionAuth can integrate with other monitoring tools:
- Datadog: Use the Datadog Agent with OpenMetrics integration
- CloudWatch: Monitor FusionAuth metrics in AWS environments
- Grafana: Visualize Prometheus data with pre-built dashboards
You can also access:
- System logs: Available via API (exportable as ZIP files)
- Audit logs: Track administrative actions via API or webhook
- Event logs: Debug information for external integrations
- Login records: Successful login history with timestamps, IPs, and user details
- Webhooks: Get real-time notifications for specific events
Related Documentation
-
D dan has marked this topic as solved
-
D dan moved this topic from Staged