Impact GateDocs

Connect & index

Connect Prometheus or Datadog

Bring existing request metrics and APM observations into your repository API inventory.

On this page

Before you connect#

Impact Gate reads your existing observability data and matches it to APIs discovered in your selected repositories. Continue using Prometheus for metrics and Datadog for full traces, dashboards, and alerts. Impact Gate adds the runtime evidence to API usage and dependency review.

  1. Index the API providers

    Connect GitHub and index repositories containing supported OpenAPI contracts. Confirm that the provider service and API paths appear in API usage.

  2. Instrument every provider you want to observe

    Use your existing Prometheus client/exporter or Datadog APM library. Each observation must identify the provider service, HTTP method, and a stable route template such as /orders/{id}. Full URLs or paths containing individual customer IDs will not be guessed into API templates.

  3. Prepare read credentials and access

    A workspace owner or admin with a verified identity can create the connection in Settings. Prometheus must be reachable from the Impact Gate deployment. Datadog requires an API key and an application key with the apm_read permission.

Connect Prometheus#

  1. Check the metric in Prometheus

    Find a cumulative HTTP request counter with labels for provider service, HTTP method, and route template. Common names include http_requests_total or a request duration histogram's _count series. Adapt the query and label names to your application's instrumentation.

  2. Open the connection form

    In Settings, choose Connect Prometheus. Enter the HTTPS query-server URL and select its authentication method. Enter a bearer token or username/password if required. The form starts with source access; it does not ask you to type every service name.

  3. Adjust the defaults when needed

    The defaults use http_requests_total with service, method, and route labels over 24 hours. Open Advanced settings if your exporter uses another counter or labels. Keep {{window}} inside increase(). The query must return an instant vector of request counts rather than a rate per second.

  4. Find and match services

    Choose Find and match services. Impact Gate reads service names from the source and compares them with indexed package names, repository names, deployment name variants, and API routes. Clear matches are preselected and grouped under matches ready to connect. Discovery does not save credentials or create a connection.

  5. Review exceptions and connect

    Choose the correct indexed service from a dropdown for uncertain matches. Use all suggested matches applies the available suggestions in one action after your review. Leave services outside this workspace unselected. Choose Connect to validate and save the selected mappings, then open API usage. Manual mapping supports inactive services, additional aliases, and Fill with repository names without requiring discovery.

promql
sum by (service, method, route) (increase(http_requests_total{route!=""}[{{window}}]))
text
http_requests_total{service="catalog-api-prod",method="GET",route="/orders/{id}"} 1234

For caller relationships, record a low-cardinality caller_service label when you have a trustworthy caller identity. Include it in sum by (service, method, route, caller_service) and set the optional Caller service label. Map the caller's service name too if you want a dependency edge to an indexed consumer.

Connect Datadog APM#

  1. Confirm request spans exist

    Use Datadog's existing APM instrumentation for each API provider. In Trace Explorer, check that the selected environment has indexed server request spans, with the correct service and a route resource such as GET /orders/{id}. Configure retention in Datadog when the traffic you need is not indexed.

  2. Create read credentials

    Create a Datadog API key and a scoped application key for an identity that can read APM (apm_read). In Settings, choose Connect Datadog, select your account's Datadog site, and enter both keys.

  3. Select the spans and route fields

    The defaults use env:production, service, and resource_name. Open Advanced settings to use the same environment/provider filter as Trace Explorer and restrict it to server request spans. If your account uses separate route fields, choose @http.route and @http.method; custom attributes must be configured as searchable APM facets.

  4. Discover, review, and connect

    Choose Find and match services to discover actual source names and preselect clear matches. Review the exceptions using dropdowns; use Use all suggested matches to apply the proposed matches together. Choose Connect to save. If a configured caller facet supplies consumer names, those names are discovered too. Saved imports are restricted to the selected source services within your configured query.

  5. Inspect full traces in Datadog

    Use Open source from the connection card to open Datadog APM. Reuse the configured search query and observation window to investigate individual traces, errors, and latency there. Impact Gate imports aggregate evidence and does not copy raw spans or request payloads.

Read endpoint coverage#

StateMeaningNext action
Runtime not connectedNo source is connected for this workspace.Connect a source from Settings.
No current observationsNo positive count matched this endpoint, or its import failed or is stale.Check source status, query scope, service mapping, route labels, instrumentation, and retention.
Estimated requestsPositive counter increases matched the endpoint in Prometheus.Read the window and compare the query in Prometheus. Fractional values can result from counter extrapolation.
Indexed spansPositive indexed spans matched the endpoint in Datadog.Use Datadog APM to inspect sampled traces and retention coverage.
Runtime or both evidenceA caller identity was supplied and mapped to an indexed service; both also has a static reference.Inspect the consumer and provider in Dependency graph.

Every indexed endpoint remains in the inventory, including endpoints with missing observations. In an endpoint's Overview, the Runtime observation section shows the source, request/span count, observation window, and whether caller identity is available. A query evaluation timestamp is not the last request timestamp, so Last observed can remain unavailable even when traffic counts are present.

Refresh, edit, and disconnect#

  • Each connection becomes eligible for an automatic import every 15 minutes. Imports are bounded and processed in small batches; backlog can delay a refresh. Use Sync now in Settings to request an immediate import.
  • Edit connection retains your saved mappings. Choose Find services again to discover new names. Changes to the source settings require discovery again, or manual mappings. For Prometheus choose Keep saved credentials; for Datadog leave both keys blank to retain them. Changing the origin/site requires fresh credentials. Choose No authentication only for a Prometheus source that permits unauthenticated reads.
  • A failed import is shown as Sync error. Current endpoint coverage becomes unknown until a successful import. Observations older than 45 minutes are also excluded from current coverage.
  • Disconnect removes the saved encrypted credentials and imported evidence for that source. Repositories and static evidence remain available. Disconnect does not modify your Prometheus or Datadog account; revoke an obsolete key in that provider as well.
  • When both sources observe an endpoint, the inventory prefers Prometheus counter increases for volume and can use Datadog for caller evidence. Counts from the two sources are not added together.

Resolve connection and coverage problems#

ProblemWhat to check
Credentials rejectedCheck the Prometheus bearer/basic credentials, or the Datadog site and API/application key pair with apm_read access.
Server unreachable or restrictedCheck TLS, DNS, and reachability from the Impact Gate backend. Ask the deployment owner about the exact private origin allowlist.
Source rows but no matched endpointsMatch the telemetry service name to the correct indexed provider; compare the HTTP method and route template. Refresh indexing after an API contract change.
Invalid rowsUse separate service/method/template labels, or a Datadog resource_name containing METHOD /route. Avoid raw URLs, query strings, malformed counts, and missing facets.
Rate limit, timeout, or too many seriesNarrow the environment, services, routes, or time window. Queries time out and imports accept at most 5,000 rows and 2 MiB. Datadog aggregation limits can omit groups even below the row limit.
No caller relationshipsTraffic counts do not imply caller identity. Add a trustworthy low-cardinality caller field and map its service names, or continue using static caller references.

Explore the documentation

↑↓ NavigateEnter Open guideSearch stays in your browser