Monitor resources using Cloud Monitoring

Cloud Monitoring can be used to monitor operations performed on resources in Certificate Authority Service.

Before you begin

If you haven't already done so, set up a Google Cloud project that has the Certificate Authority Service API enabled. For information, see Prepare your environment.

View metrics in Cloud Monitoring

Console

To view the metrics for a monitored resource by using the Metrics Explorer, do the following:

  1. In the Google Cloud console, go to the  Metrics explorer page:

    Go to Metrics explorer

    If you use the search bar to find this page, then select the result whose subheading is Monitoring.

  2. In the toolbar of the Google Cloud console, select your Google Cloud project. For App Hub configurations, select the App Hub host project or the app-enabled folder's management project.
  3. In the Metric element, expand the Select a metric menu, enter Certificate Authority in the filter bar, and then use the submenus to select a specific resource type and metric:
    1. In the Active resources menu, select Certificate Authority.
    2. To select a metric, use the Active metric categories and Active metrics menus. For a list of metrics, see privateca metrics.
    3. Click Apply.
  4. To add filters, which remove time series from the query results, use the Filter element.

  5. To combine time series, use the menus on the Aggregation element. For example, to display the CPU utilization for your VMs, based on their zone, set the first menu to Mean and the second menu to zone.

    All time series are displayed when the first menu of the Aggregation element is set to Unaggregated. The default settings for the Aggregation element are determined by the metric type you selected.

  6. For quota and other metrics that report one sample per day, do the following:
    1. In the Display pane, set the Widget type to Stacked bar chart.
    2. Set the time period to at least one week.

CA Service metrics

The list of metrics can be viewed in Cloud Monitoring documentation.

The monitored resource documentation can be viewed in Monitored resources.

Set up quota alerts and monitoring

You can set up quota usage alerts and monitoring by using Cloud Monitoring.

For more information on how to set up alerts and create charts, see Set up quota alerts and monitoring.

Use the following instructions to enable recommended alerts.

Console

  1. Go to the CA Service Overview page in the Google Cloud console.

    Certificate Authority Service

  2. On the top right of the Overview page, click the + 5 Recommended Alerts.

  3. Enable or disable each alert, reading its description.

    • Some alerts support custom thresholds. For example, you can specify when you want to be alerted for an expiring CA certificate, or the error rate for a high rate of certificate creation failures.
    • All alerts support notification channels.
  4. Click Submit once you have enabled all selected alerts.

Create an alerting policy

Console

You can create alerting policies to monitor the values of metrics and to notify you when those metrics violate a condition.

  1. In the Google Cloud console, go to the  Alerting page:

    Go to Alerting

    If you use the search bar to find this page, then select the result whose subheading is Monitoring.

  2. If you haven't created your notification channels and if you want to be notified, then click Edit Notification Channels and add your notification channels. Return to the Alerting page after you add your channels.
  3. From the Alerting page, select Create policy.
  4. To select the metric, expand the Select a metric menu and then do the following:
    1. To limit the menu to relevant entries, enter Certificate Authority into the filter bar. If there are no results after you filter the menu, then disable the Show only active resources & metrics toggle.
    2. For the Resource type, select Certificate Authority.
    3. For the Metric category, select Ca.
    4. For the Metric, select a metric from the list of privateca metrics.
    5. Select Apply.
  5. Click Next.
  6. The settings in the Configure alert trigger page determine when the alert is triggered. Select a condition type and, if necessary, specify a threshold. For more information, see Create metric-threshold alerting policies.
  7. Click Next.
  8. Optional: To add notifications to your alerting policy, click Notification channels. In the dialog, select one or more notification channels from the menu, and then click OK.
  9. Optional: Update the Incident autoclose duration. This field determines when Monitoring closes incidents in the absence of metric data.
  10. Optional: Click Documentation, and then add any information that you want included in a notification message.
  11. Click Alert name and enter a name for the alerting policy.
  12. Click Create Policy.
For more information, see Alerting overview.

Create Pub/Sub notification channel

A notification channel that publishes events to Pub/Sub can be set up by following these instructions.

Sample alert policies

You can use the following sample alert policies for common CA Service monitoring use cases.

To learn more about alert policies, see the documentation.

CA expiring in 30 days

This alert policy notifies you 30 days before a managed CA expires. This policy creates alert notifications for all managed CAs across all projects whose metrics are visible to the Google Cloud project selected in the Google Cloud console project picker. For information about metric visibility, see Understanding metrics scope.