Compare commits
460 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
4e816cde7b
|
|||
| 6435c77f32 | |||
|
06b389d207
|
|||
| 225a984f00 | |||
|
dbf80cb825
|
|||
| a3c0068165 | |||
|
29e9c88e72
|
|||
| c4ada1d98d | |||
|
8ccf698463
|
|||
| d30b04b81c | |||
|
388bd6ff21
|
|||
| 95557cb92f | |||
|
1b96d3acf6
|
|||
| 6daa1b4d5a | |||
|
bd7a7cd18f
|
|||
| 1f0470fa1d | |||
|
d893e89fe7
|
|||
| f4a1729f3f | |||
|
18fea18919
|
|||
| 13eb9bd0ef | |||
|
a30814f418
|
|||
| abadc1ebf1 | |||
|
4124010b0f
|
|||
| a662c3a5ad | |||
|
13bf9dd326
|
|||
| 0bb5b5a95e | |||
|
e9de27368a
|
|||
|
36d8ffda43
|
|||
|
639b6b1fd0
|
|||
|
714a61355e
|
|||
|
0a70a3d37b
|
|||
| d721b5e548 | |||
|
c2930220b2
|
|||
| 817e6a5216 | |||
|
7353c21bd3
|
|||
| a595ba4eb5 | |||
|
bedc35201d
|
|||
| a4177c871e | |||
|
bcab63b5da
|
|||
| 93fad921b3 | |||
|
02ad36c465
|
|||
| 970f65f0ba | |||
|
69a30fc946
|
|||
| f292c58256 | |||
|
14beb5da2b
|
|||
| bbf80b3189 | |||
|
5a854855d3
|
|||
| 27b448b5f7 | |||
| 2ab501bf94 | |||
|
75f729b29a
|
|||
|
f7e2e32f9c
|
|||
| 7a3897f3aa | |||
|
8566a78070
|
|||
| 5895c698e2 | |||
|
9a8241feb7
|
|||
| e661b56dc5 | |||
|
657200eb43
|
|||
| f4278286c0 | |||
|
184e5cdba7
|
|||
|
b0f4ed51c6
|
|||
| 11f540ab80 | |||
|
5fe0225ea0
|
|||
| f7c9bd4124 | |||
|
76783d0463
|
|||
| e26e6dc519 | |||
|
c7c28b79b5
|
|||
| 08dfcb87e3 | |||
|
37d4d6cad4
|
|||
| f29c140563 | |||
|
2f3b3104b5
|
|||
|
9a5befb246
|
|||
|
5560cb58bd
|
|||
|
8cf8de18d3
|
|||
|
c9dd02ba56
|
|||
| 2833316b8f | |||
|
98acfc6029
|
|||
| 863fd19674 | |||
|
ea6dfeff84
|
|||
| e97f789b83 | |||
|
83c4e9ac4a
|
|||
| 662e15c3ef | |||
|
e071c1744e
|
|||
| 4821188bee | |||
|
f5df07df08
|
|||
|
44000eba76
|
|||
|
50ca706c5b
|
|||
|
7efdf3eb86
|
|||
| 9abef4a475 | |||
|
2477c1f955
|
|||
| c6cdd5ad22 | |||
|
caa2b0ccd3
|
|||
| 0c9a3db42f | |||
|
fdf2736021
|
|||
| a70e709bb8 | |||
|
f9364b9c6e
|
|||
| 64877d4bc0 | |||
|
abbc8b07d9
|
|||
| c3830f0682 | |||
|
dcaaeba125
|
|||
|
73b4230d7e
|
|||
|
4729708822
|
|||
| a166620d28 | |||
|
7459ed9f70
|
|||
| 89c6c91923 | |||
|
dcdced6499
|
|||
| cf917a57d7 | |||
|
7c3454b439
|
|||
| 7da13df2d9 | |||
|
5a110d718e
|
|||
| dec862a5f4 | |||
| c35f7db43c | |||
|
e3ac881844
|
|||
|
cf61c7609e
|
|||
| 39f321bf5e | |||
|
80cb9788a0
|
|||
| 3b07fec227 | |||
| cd49b8fc66 | |||
|
640f735121
|
|||
|
693ec7efda
|
|||
| d9db0dedb7 | |||
|
4dd7d8550c
|
|||
|
e7f0ad8006
|
|||
| 78c384a8b1 | |||
|
eb4207f8e2
|
|||
|
28ff6422c4
|
|||
|
08634c018c
|
|||
| 3c462bde20 | |||
|
50379a84f1
|
|||
| e8e83d262d | |||
|
16e1870a4b
|
|||
| bc677afea0 | |||
|
d1886043bd
|
|||
| dd1cdd5da4 | |||
|
355093df0c
|
|||
| 9c702b1873 | |||
|
a30f6d4e69
|
|||
| f8c6a2f3e4 | |||
| 8f4d89f3d3 | |||
|
fa0cfd8b67
|
|||
|
2af24792e7
|
|||
| 44246cc4c1 | |||
|
28e5bf90b5
|
|||
| 7f65b1baef | |||
|
4fab22f7f1
|
|||
|
5796307f10
|
|||
|
e3858b302e
|
|||
| b3a093d67d | |||
| c82138d4fe | |||
|
0d8af53572
|
|||
|
79751e2e7f
|
|||
|
28ceaa11be
|
|||
| 18eb6ac82f | |||
|
01fbbcef02
|
|||
| dbf5e02807 | |||
|
379b2d9a2a
|
|||
| 9248d4c35a | |||
|
2f5c7b4c07
|
|||
| 74b24988be | |||
|
2dd4502409
|
|||
| 774cab3173 | |||
|
abeaf0c881
|
|||
| 7e57724ef8 | |||
|
1040199d45
|
|||
| caae6992ee | |||
|
5fcedff675
|
|||
| 88f65aeb67 | |||
|
49f29523c4
|
|||
| c75c56d28e | |||
|
29fa53acc1
|
|||
| 3e48ae6c4d | |||
|
2b4dbac471
|
|||
| ac95705df1 | |||
|
0ae3340140
|
|||
| 2427a823f4 | |||
|
127fdd54cf
|
|||
| 8df1305679 | |||
|
76f9c2e25c
|
|||
| 678e9381bd | |||
|
3966901b75
|
|||
| 8543e4b41f | |||
|
7a85ea4c23
|
|||
| 4eda2129f1 | |||
|
cdc4c39728
|
|||
| e46107ad02 | |||
|
0121927f26
|
|||
| eef0b13ab0 | |||
|
8c30536293
|
|||
| 841bd52da9 | |||
|
51e03a6e08
|
|||
| 6a0074676d | |||
|
dbf1380515
|
|||
| 2504e99cc8 | |||
| c50417c3da | |||
|
50b4f42a6e
|
|||
|
cd32ebd7c9
|
|||
| 3e655ae613 | |||
|
5bd1cdc714
|
|||
| 06e85aac5c | |||
|
dca946aadd
|
|||
| 0627c8d8d5 | |||
|
010eeaf903
|
|||
| 623d9a088e | |||
|
4da51ca17a
|
|||
| f8b3b81e83 | |||
|
30a8e59e35
|
|||
| 5172c5c265 | |||
|
0f638ce01a
|
|||
| 2f495c5cc5 | |||
|
29dab2f81e
|
|||
| c03fb7ffdc | |||
|
9fb678612a
|
|||
| 5ee7466152 | |||
|
452674709a
|
|||
|
99ec607e6d
|
|||
| 96424b124c | |||
|
96937cd358
|
|||
|
373823e565
|
|||
|
d36dd7735f
|
|||
|
1a0aeb0e64
|
|||
|
e6e63b5b2c
|
|||
|
0fcb071122
|
|||
|
e0f4fc71af
|
|||
|
e747bbe519
|
|||
| 067c3cbc59 | |||
| 27fcdd6bac | |||
|
67a7c32675
|
|||
|
c352c07f7b
|
|||
|
3397d80865
|
|||
|
39548b9b31
|
|||
|
9b75b8d4bf
|
|||
|
8d29dd8bd1
|
|||
| 4090830d95 | |||
|
21790a5a41
|
|||
|
4ab5ecdd6f
|
|||
|
c11f7897d7
|
|||
|
8839dd6eb1
|
|||
|
cc57178974
|
|||
| 3d95158244 | |||
|
141f05c6ae
|
|||
|
3651f23c72
|
|||
|
b4cbbd97a6
|
|||
| ede26d9c1d | |||
|
cc14ef66ed
|
|||
|
35b3f6cc42
|
|||
|
033a3b95ad
|
|||
|
f90060e366
|
|||
| 1f074a7087 | |||
|
c6cf3b7d84
|
|||
|
e611c68342
|
|||
|
d828d88078
|
|||
|
8fa00efc16
|
|||
|
fbe2274182
|
|||
|
bf4985040a
|
|||
|
ce3a367ec9
|
|||
|
6006e75db9
|
|||
| db590d1d2c | |||
|
7b6f92646f
|
|||
|
6bbd9748a2
|
|||
|
b22ff17c1d
|
|||
|
96900bea0c
|
|||
|
0f84c335de
|
|||
|
5e1b5dc007
|
|||
| f0f1b45c93 | |||
| 46c4e7b50f | |||
|
dbba05d7b6
|
|||
|
db9aa7c99d
|
|||
|
8f0d73946f
|
|||
|
d0ac6145e0
|
|||
|
b9830a2153
|
|||
|
4f51cc5799
|
|||
|
fe1707d078
|
|||
| df154d3b8b | |||
| 49d6684d0a | |||
|
179cdaffd7
|
|||
|
396c998336
|
|||
|
1829d76a07
|
|||
|
4315074427
|
|||
|
289a51fd7d
|
|||
|
b6f178ef88
|
|||
| eb021c1510 | |||
|
99e7e0ae30
|
|||
|
e80fb62fd7
|
|||
|
b6cf261505
|
|||
| cc2b1825d5 | |||
|
5b15d78da0
|
|||
|
3e54d7c96d
|
|||
|
52d680a143
|
|||
|
a5a604a496
|
|||
|
9194de2325
|
|||
| ce5a5c63e3 | |||
|
6a4c3e2253
|
|||
|
65013f6720
|
|||
|
9426dbeb71
|
|||
|
ca3234cb79
|
|||
| 6d2d895b67 | |||
| c2bd9b23ac | |||
|
0790ccd2ad
|
|||
|
ddcadddaaa
|
|||
|
8fabc526ad
|
|||
|
e285b581f3
|
|||
|
3f614405c8
|
|||
|
079fdd4da2
|
|||
| 6e22223c4b | |||
| 61d5ad7071 | |||
| cd3f663549 | |||
|
f1fd7c6cb1
|
|||
|
175b2c13f9
|
|||
|
a643de1085
|
|||
| e5aab6948d | |||
|
30456b3817
|
|||
|
ab12531084
|
|||
|
b789b7be21
|
|||
|
3a2cfdb84e
|
|||
|
506c034948
|
|||
|
7cbc80906e
|
|||
|
3fd705520c
|
|||
|
94d65decd1
|
|||
|
e06a1be194
|
|||
|
dc926c31de
|
|||
|
af31507e8c
|
|||
|
c0ca549393
|
|||
|
a113c84c9d
|
|||
|
a7cc46ed8a
|
|||
|
54e6a76aab
|
|||
|
33ef2866e9
|
|||
|
b609e87dd3
|
|||
|
e1ffafc161
|
|||
| 4170dfa26c | |||
|
5fcb92ee8b
|
|||
|
c5acc2416f
|
|||
|
87b667b2ab
|
|||
| d68d2db3bc | |||
| ad68a17eb5 | |||
|
b07c7bf3a0
|
|||
|
78fc45ae6c
|
|||
| 2fa1594e99 | |||
| b211327516 | |||
|
6885ec790c
|
|||
|
664cace62e
|
|||
|
dae06b2c05
|
|||
|
583831273d
|
|||
|
f327b23001
|
|||
|
6f2603d3a0
|
|||
| c26ea4e139 | |||
| b521924f00 | |||
|
19f203e374
|
|||
|
bb251462fb
|
|||
|
9a9d108e7c
|
|||
|
70d5ae2e48
|
|||
| e6e25baee1 | |||
| a08e9930d5 | |||
|
94bb98b4ed
|
|||
|
07f863b0a7
|
|||
| 79669aaf16 | |||
| 7237e23151 | |||
| f4cc060de7 | |||
| 15f5cb1cbc | |||
|
373b418601
|
|||
|
95af55533e
|
|||
|
24b29cc9a9
|
|||
|
ba292377ab
|
|||
|
9ee0e419a0
|
|||
|
0ee35ec27c
|
|||
|
9697736ed3
|
|||
|
1dea2edfcc
|
|||
|
ae3d90eb10
|
|||
|
72e16276b8
|
|||
| f1fe246f14 | |||
| afe3aaf866 | |||
| 603b6fdbd3 | |||
|
b4fa24c8d1
|
|||
|
1c344f11c4
|
|||
|
a9f1a7cf69
|
|||
| 335563a895 | |||
| 72df8103f2 | |||
|
22dbbaf64f
|
|||
|
f926df6bea
|
|||
|
ecba2195b6
|
|||
| da770facc5 | |||
|
f0dad1e033
|
|||
| ec154c641f | |||
|
f5405bf44d
|
|||
|
1442802804
|
|||
|
4ca30efa7e
|
|||
|
96ed8909af
|
|||
| dd69b42f26 | |||
|
98c688d4bd
|
|||
| 2bb9cdd402 | |||
|
c0a9301cad
|
|||
|
2104e6c2ad
|
|||
| b24a003397 | |||
| d134b4815e | |||
| f65b07a8f3 | |||
|
79e96ae6ea
|
|||
|
3ba9e5e420
|
|||
|
03a6abe1b8
|
|||
| 97fd5c118e | |||
|
f946189ff6
|
|||
|
e12aebefbc
|
|||
|
d0cf5b9064
|
|||
|
48e4a6aa7d
|
|||
| 25b1e757be | |||
| d6d9c402cf | |||
|
15fedb055f
|
|||
|
0c22389ac4
|
|||
| eba1779962 | |||
| 0a3ced36c7 | |||
|
7f84573f4c
|
|||
|
15544a2186
|
|||
| eda6ba5f28 | |||
|
c672a5cd22
|
|||
|
0fd46e4b75
|
|||
|
caca1c7ec5
|
|||
|
d328f7ff37
|
|||
| 3afb27bb3d | |||
|
e7775aa9dc
|
|||
|
e7cfab1232
|
|||
|
659aa5f1aa
|
|||
|
bab5bbb30b
|
|||
|
ec292a6973
|
|||
|
43c6ca185c
|
|||
|
927d4e6905
|
|||
|
dfaa4e2961
|
|||
|
1716e524a3
|
|||
|
6df782ae99
|
|||
|
6f3ce4f03d
|
|||
|
bc539ce7c3
|
|||
|
adea620df2
|
|||
|
9371f50404
|
|||
|
2a0e5004f0
|
|||
|
e7fb07343c
|
|||
| ae8f0e560a | |||
|
4c87356828
|
|||
| cc858dd8f3 | |||
|
5d71a0f199
|
|||
|
a4d2f870d9
|
|||
|
7136a0f322
|
|||
|
c2d6c0c8bb
|
|||
| f3c3741409 | |||
|
80b7cb2282
|
|||
| bf66dd0818 | |||
|
eea1c80a27
|
|||
|
612dd16d4b
|
|||
| 341b402f0e | |||
|
76eaa1dd98
|
|||
| a730f43cbd | |||
|
4bd23be552
|
|||
|
6cd4b20970
|
|||
|
c3c66cb9e3
|
|||
|
b0fb79f7ea
|
|||
|
624c5c7a8c
|
|||
|
ebf8f25342
|
|||
|
87c5d94e0d
|
|||
|
b9a8f3fea8
|
|||
|
6634531a37
|
|||
|
fb9a0e4015
|
|||
|
3c424ddc30
|
|||
|
a14e4c8aad
|
|||
|
c9f7587c8f
|
|||
|
0f61b0cd03
|
@@ -0,0 +1,37 @@
|
||||
# Main Infrastructure: weyma-talos
|
||||
|
||||
**Production Kubernetes infrastructure with disaster recovery capabilities**
|
||||
|
||||
This repository contains the foundational infrastructure for my Kubernetes homelab, designed with reliability and rapid recovery as core principles.
|
||||
|
||||
## Architecture
|
||||
|
||||
My infrastructure follows a layered "black start" approach - essential services run outside the Kubernetes cluster to enable cluster bootstrapping and recovery from total failures.
|
||||
|
||||
### Black Start Layer
|
||||
Static services (Docker Compose on TrueNAS/Proxmox) that provide cluster dependencies:
|
||||
- Image cache for faster deployments and offline capability
|
||||
- Talos discovery server for node bootstrapping
|
||||
- HashiCorp Vault for secrets management (external to cluster)
|
||||
- Future: Self-hosted Sidero Omni server (migrating from SaaS)
|
||||
|
||||
### System Apps Layer
|
||||
Applications running within Kubernetes that provide core cluster functionality, managed via ArgoCD with GitOps principles.
|
||||
|
||||
## Repository Structure
|
||||
|
||||
- **`black-start/`** - Docker Compose services for cluster dependencies
|
||||
- **`config-patches/`** - Talos Linux configuration patches for cluster and individual machines
|
||||
- **`omni/`** - Sidero Omni [cluster template](https://docs.siderolabs.com/omni/reference/cluster-templates)
|
||||
- **`system-apps/`** - System applications (ArgoCD projects) - monitoring, ingress, certificates, storage
|
||||
|
||||
## Tech Stack
|
||||
|
||||
**OS:** Talos Linux | **Orchestration:** Kubernetes | **GitOps:** ArgoCD | **Secrets:** Vault | **Storage:** Rook-Ceph
|
||||
|
||||
## Recovery Process
|
||||
|
||||
The "black start" architecture enables ~15-20 minute automated recovery from complete infrastructure failure:
|
||||
1. Start black-start services → 2. Bootstrap Talos → 3. Deploy system apps → 4. Deploy core apps
|
||||
|
||||
For application deployments, see [core-apps](https://git.dubyatp.xyz/core-apps).
|
||||
@@ -1,15 +0,0 @@
|
||||
services:
|
||||
prometheus:
|
||||
image: prom/prometheus:v3.7.3
|
||||
command:
|
||||
- '--config.file=/etc/prometheus/prometheus.yaml'
|
||||
- '--web.config.file=/etc/prometheus/web-config.yaml'
|
||||
- '--web.enable-remote-write-receiver'
|
||||
- '--storage.tsdb.retention.size=35GB'
|
||||
ports:
|
||||
- 9090:9090
|
||||
volumes:
|
||||
- ./.basicauthpass:/etc/prometheus/.basicauthpass
|
||||
- ./prometheus.yaml:/etc/prometheus/prometheus.yaml
|
||||
- ./web-config.yaml:/etc/prometheus/web-config.yaml
|
||||
- /mnt/prometheus-data:/prometheus
|
||||
@@ -1,32 +0,0 @@
|
||||
# my global config
|
||||
global:
|
||||
scrape_interval: 15s # Set the scrape interval to every 15 seconds. Default is every 1 minute.
|
||||
evaluation_interval: 15s # Evaluate rules every 15 seconds. The default is every 1 minute.
|
||||
# scrape_timeout is set to the global default (10s).
|
||||
|
||||
# Alertmanager configuration
|
||||
alerting:
|
||||
alertmanagers:
|
||||
- static_configs:
|
||||
- targets:
|
||||
# - alertmanager:9093
|
||||
|
||||
# Load rules once and periodically evaluate them according to the global 'evaluation_interval'.
|
||||
rule_files:
|
||||
# - "first_rules.yml"
|
||||
# - "second_rules.yml"
|
||||
|
||||
# A scrape configuration containing exactly one endpoint to scrape:
|
||||
# Here it's Prometheus itself.
|
||||
scrape_configs:
|
||||
# The job name is added as a label `job=<job_name>` to any timeseries scraped from this config.
|
||||
- job_name: "prometheus"
|
||||
|
||||
# metrics_path defaults to '/metrics'
|
||||
# scheme defaults to 'http'.
|
||||
|
||||
static_configs:
|
||||
- targets: ["localhost:9090"]
|
||||
basic_auth:
|
||||
username: prometheus
|
||||
password_file: /etc/prometheus/.basicauthpass
|
||||
@@ -1,2 +0,0 @@
|
||||
basic_auth_users:
|
||||
prometheus: <redacted>
|
||||
@@ -2,7 +2,7 @@ version: "3.8"
|
||||
services:
|
||||
discovery:
|
||||
restart: unless-stopped
|
||||
image: ghcr.io/siderolabs/discovery-service:v1.0.11
|
||||
image: ghcr.io/siderolabs/discovery-service:v1.1.0
|
||||
ports:
|
||||
- 10.105.6.215:3000:3000
|
||||
- 10.105.6.215:3001:3001
|
||||
@@ -5,7 +5,7 @@ services:
|
||||
command: tunnel run weyma-vault
|
||||
env_file: ".env"
|
||||
vault:
|
||||
image: hashicorp/vault:1.21
|
||||
image: hashicorp/vault:2.0
|
||||
env_file: ".env.vault"
|
||||
environment:
|
||||
VAULT_ADDR: "https://weyma-vault.infra.dubyatp.xyz:8200"
|
||||
|
||||
@@ -1,8 +1,213 @@
|
||||
cluster:
|
||||
extraManifests:
|
||||
- https://raw.githubusercontent.com/alex1989hu/kubelet-serving-cert-approver/main/deploy/standalone-install.yaml
|
||||
- https://github.com/kubernetes-sigs/metrics-server/releases/latest/download/components.yaml
|
||||
inlineManifests:
|
||||
- name: metrics-server
|
||||
contents: |-
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
labels:
|
||||
k8s-app: metrics-server
|
||||
name: metrics-server
|
||||
namespace: kube-system
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
labels:
|
||||
k8s-app: metrics-server
|
||||
rbac.authorization.k8s.io/aggregate-to-admin: "true"
|
||||
rbac.authorization.k8s.io/aggregate-to-edit: "true"
|
||||
rbac.authorization.k8s.io/aggregate-to-view: "true"
|
||||
name: system:aggregated-metrics-reader
|
||||
rules:
|
||||
- apiGroups:
|
||||
- metrics.k8s.io
|
||||
resources:
|
||||
- pods
|
||||
- nodes
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
labels:
|
||||
k8s-app: metrics-server
|
||||
name: system:metrics-server
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- nodes/metrics
|
||||
verbs:
|
||||
- get
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
- nodes
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
labels:
|
||||
k8s-app: metrics-server
|
||||
name: metrics-server-auth-reader
|
||||
namespace: kube-system
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: extension-apiserver-authentication-reader
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: metrics-server
|
||||
namespace: kube-system
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
labels:
|
||||
k8s-app: metrics-server
|
||||
name: metrics-server:system:auth-delegator
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: system:auth-delegator
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: metrics-server
|
||||
namespace: kube-system
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
labels:
|
||||
k8s-app: metrics-server
|
||||
name: system:metrics-server
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: system:metrics-server
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: metrics-server
|
||||
namespace: kube-system
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
labels:
|
||||
k8s-app: metrics-server
|
||||
name: metrics-server
|
||||
namespace: kube-system
|
||||
spec:
|
||||
ports:
|
||||
- appProtocol: https
|
||||
name: https
|
||||
port: 443
|
||||
protocol: TCP
|
||||
targetPort: https
|
||||
selector:
|
||||
k8s-app: metrics-server
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
labels:
|
||||
k8s-app: metrics-server
|
||||
name: metrics-server
|
||||
namespace: kube-system
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
k8s-app: metrics-server
|
||||
strategy:
|
||||
rollingUpdate:
|
||||
maxUnavailable: 0
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
k8s-app: metrics-server
|
||||
spec:
|
||||
containers:
|
||||
- args:
|
||||
- --cert-dir=/tmp
|
||||
- --secure-port=10250
|
||||
- --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname
|
||||
- --kubelet-use-node-status-port
|
||||
- --metric-resolution=15s
|
||||
- --kubelet-insecure-tls
|
||||
image: registry.k8s.io/metrics-server/metrics-server:v0.8.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
livenessProbe:
|
||||
failureThreshold: 3
|
||||
httpGet:
|
||||
path: /livez
|
||||
port: https
|
||||
scheme: HTTPS
|
||||
periodSeconds: 10
|
||||
name: metrics-server
|
||||
ports:
|
||||
- containerPort: 10250
|
||||
name: https
|
||||
protocol: TCP
|
||||
readinessProbe:
|
||||
failureThreshold: 3
|
||||
httpGet:
|
||||
path: /readyz
|
||||
port: https
|
||||
scheme: HTTPS
|
||||
initialDelaySeconds: 20
|
||||
periodSeconds: 10
|
||||
resources:
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 200Mi
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
readOnlyRootFilesystem: true
|
||||
runAsNonRoot: true
|
||||
runAsUser: 1000
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
volumeMounts:
|
||||
- mountPath: /tmp
|
||||
name: tmp-dir
|
||||
nodeSelector:
|
||||
kubernetes.io/os: linux
|
||||
priorityClassName: system-cluster-critical
|
||||
serviceAccountName: metrics-server
|
||||
volumes:
|
||||
- emptyDir: {}
|
||||
name: tmp-dir
|
||||
---
|
||||
apiVersion: apiregistration.k8s.io/v1
|
||||
kind: APIService
|
||||
metadata:
|
||||
labels:
|
||||
k8s-app: metrics-server
|
||||
name: v1beta1.metrics.k8s.io
|
||||
spec:
|
||||
group: metrics.k8s.io
|
||||
groupPriorityMinimum: 100
|
||||
insecureSkipTLSVerify: true
|
||||
service:
|
||||
name: metrics-server
|
||||
namespace: kube-system
|
||||
version: v1beta1
|
||||
versionPriority: 100
|
||||
|
||||
- name: metrics-lb
|
||||
contents: |-
|
||||
apiVersion: v1
|
||||
@@ -10,6 +215,8 @@ cluster:
|
||||
metadata:
|
||||
name: metrics-lb
|
||||
namespace: kube-system
|
||||
annotations:
|
||||
metallb.io/ip-allocated-from-pool: test-pool
|
||||
spec:
|
||||
type: LoadBalancer
|
||||
ports:
|
||||
@@ -19,4 +226,3 @@ cluster:
|
||||
targetPort: https
|
||||
selector:
|
||||
k8s-app: metrics-server
|
||||
|
||||
@@ -0,0 +1,532 @@
|
||||
kind: Cluster
|
||||
name: weyma-talos
|
||||
kubernetes:
|
||||
version: v1.35.4
|
||||
talos:
|
||||
version: v1.12.7
|
||||
features:
|
||||
backupConfiguration:
|
||||
interval: 6h0m0s
|
||||
patches:
|
||||
- idOverride: 500-5100c0c3-f72e-45f5-8cde-4a1c3b6f72a8
|
||||
annotations:
|
||||
description: pod-svc-subnets
|
||||
name: User defined patch
|
||||
inline:
|
||||
cluster:
|
||||
network:
|
||||
podSubnets:
|
||||
- 10.244.0.0/16
|
||||
serviceSubnets:
|
||||
- 10.112.0.0/12
|
||||
- idOverride: 500-7c228773-8b44-40b0-8b4c-30f617668af0
|
||||
annotations:
|
||||
description: weyma-image-cache
|
||||
name: User defined patch
|
||||
inline:
|
||||
machine:
|
||||
registries:
|
||||
mirrors:
|
||||
docker.io:
|
||||
endpoints:
|
||||
- http://10.105.6.215:6000
|
||||
factory.talos.dev:
|
||||
endpoints:
|
||||
- http://10.105.6.215:6004
|
||||
gcr.io:
|
||||
endpoints:
|
||||
- http://10.105.6.215:6002
|
||||
ghcr.io:
|
||||
endpoints:
|
||||
- http://10.105.6.215:6003
|
||||
registry.k8s.io:
|
||||
endpoints:
|
||||
- http://10.105.6.215:6001
|
||||
- idOverride: 500-f198cacc-280b-4874-a410-252c160621a7
|
||||
annotations:
|
||||
name: weyma-bind-addr
|
||||
inline:
|
||||
cluster:
|
||||
controllerManager:
|
||||
extraArgs:
|
||||
bind-address: 0.0.0.0
|
||||
proxy:
|
||||
extraArgs:
|
||||
proxy-mode: ipvs
|
||||
metrics-bind-address: 0.0.0.0:10249
|
||||
scheduler:
|
||||
extraArgs:
|
||||
bind-address: 0.0.0.0
|
||||
- idOverride: 500-fc113705-0777-4b52-8df0-7cee67fcc68e
|
||||
annotations:
|
||||
name: weyma-bootstrap-metrics
|
||||
inline:
|
||||
cluster:
|
||||
extraManifests:
|
||||
- https://raw.githubusercontent.com/alex1989hu/kubelet-serving-cert-approver/main/deploy/standalone-install.yaml
|
||||
inlineManifests:
|
||||
- contents: |-
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
labels:
|
||||
k8s-app: metrics-server
|
||||
name: metrics-server
|
||||
namespace: kube-system
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
labels:
|
||||
k8s-app: metrics-server
|
||||
rbac.authorization.k8s.io/aggregate-to-admin: "true"
|
||||
rbac.authorization.k8s.io/aggregate-to-edit: "true"
|
||||
rbac.authorization.k8s.io/aggregate-to-view: "true"
|
||||
name: system:aggregated-metrics-reader
|
||||
rules:
|
||||
- apiGroups:
|
||||
- metrics.k8s.io
|
||||
resources:
|
||||
- pods
|
||||
- nodes
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
labels:
|
||||
k8s-app: metrics-server
|
||||
name: system:metrics-server
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- nodes/metrics
|
||||
verbs:
|
||||
- get
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
- nodes
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
labels:
|
||||
k8s-app: metrics-server
|
||||
name: metrics-server-auth-reader
|
||||
namespace: kube-system
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: extension-apiserver-authentication-reader
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: metrics-server
|
||||
namespace: kube-system
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
labels:
|
||||
k8s-app: metrics-server
|
||||
name: metrics-server:system:auth-delegator
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: system:auth-delegator
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: metrics-server
|
||||
namespace: kube-system
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
labels:
|
||||
k8s-app: metrics-server
|
||||
name: system:metrics-server
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: system:metrics-server
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: metrics-server
|
||||
namespace: kube-system
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
labels:
|
||||
k8s-app: metrics-server
|
||||
name: metrics-server
|
||||
namespace: kube-system
|
||||
spec:
|
||||
ports:
|
||||
- appProtocol: https
|
||||
name: https
|
||||
port: 443
|
||||
protocol: TCP
|
||||
targetPort: https
|
||||
selector:
|
||||
k8s-app: metrics-server
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
labels:
|
||||
k8s-app: metrics-server
|
||||
name: metrics-server
|
||||
namespace: kube-system
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
k8s-app: metrics-server
|
||||
strategy:
|
||||
rollingUpdate:
|
||||
maxUnavailable: 0
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
k8s-app: metrics-server
|
||||
spec:
|
||||
containers:
|
||||
- args:
|
||||
- --cert-dir=/tmp
|
||||
- --secure-port=10250
|
||||
- --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname
|
||||
- --kubelet-use-node-status-port
|
||||
- --metric-resolution=15s
|
||||
- --kubelet-insecure-tls
|
||||
image: registry.k8s.io/metrics-server/metrics-server:v0.8.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
livenessProbe:
|
||||
failureThreshold: 3
|
||||
httpGet:
|
||||
path: /livez
|
||||
port: https
|
||||
scheme: HTTPS
|
||||
periodSeconds: 10
|
||||
name: metrics-server
|
||||
ports:
|
||||
- containerPort: 10250
|
||||
name: https
|
||||
protocol: TCP
|
||||
readinessProbe:
|
||||
failureThreshold: 3
|
||||
httpGet:
|
||||
path: /readyz
|
||||
port: https
|
||||
scheme: HTTPS
|
||||
initialDelaySeconds: 20
|
||||
periodSeconds: 10
|
||||
resources:
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 200Mi
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
readOnlyRootFilesystem: true
|
||||
runAsNonRoot: true
|
||||
runAsUser: 1000
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
volumeMounts:
|
||||
- mountPath: /tmp
|
||||
name: tmp-dir
|
||||
nodeSelector:
|
||||
kubernetes.io/os: linux
|
||||
priorityClassName: system-cluster-critical
|
||||
serviceAccountName: metrics-server
|
||||
volumes:
|
||||
- emptyDir: {}
|
||||
name: tmp-dir
|
||||
---
|
||||
apiVersion: apiregistration.k8s.io/v1
|
||||
kind: APIService
|
||||
metadata:
|
||||
labels:
|
||||
k8s-app: metrics-server
|
||||
name: v1beta1.metrics.k8s.io
|
||||
spec:
|
||||
group: metrics.k8s.io
|
||||
groupPriorityMinimum: 100
|
||||
insecureSkipTLSVerify: true
|
||||
service:
|
||||
name: metrics-server
|
||||
namespace: kube-system
|
||||
version: v1beta1
|
||||
versionPriority: 100
|
||||
name: metrics-server
|
||||
- contents: |-
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: metrics-lb
|
||||
namespace: kube-system
|
||||
annotations:
|
||||
metallb.io/ip-allocated-from-pool: test-pool
|
||||
spec:
|
||||
type: LoadBalancer
|
||||
ports:
|
||||
- name: https
|
||||
port: 443
|
||||
protocol: TCP
|
||||
targetPort: https
|
||||
selector:
|
||||
k8s-app: metrics-server
|
||||
name: metrics-lb
|
||||
- contents: |-
|
||||
apiVersion: v1
|
||||
data:
|
||||
Corefile: |
|
||||
.:53 {
|
||||
errors
|
||||
health {
|
||||
lameduck 5s
|
||||
}
|
||||
ready
|
||||
log . {
|
||||
class error
|
||||
}
|
||||
prometheus :9153
|
||||
|
||||
kubernetes cluster.local in-addr.arpa ip6.arpa {
|
||||
pods insecure
|
||||
fallthrough in-addr.arpa ip6.arpa
|
||||
ttl 30
|
||||
}
|
||||
|
||||
rewrite name git.dubyatp.xyz traefik-local.traefik.svc.cluster.local
|
||||
|
||||
forward . /etc/resolv.conf {
|
||||
max_concurrent 1000
|
||||
}
|
||||
cache 30 {
|
||||
disable success cluster.local
|
||||
disable denial cluster.local
|
||||
}
|
||||
loop
|
||||
reload
|
||||
loadbalance
|
||||
}
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: coredns
|
||||
namespace: kube-system
|
||||
name: coredns-config
|
||||
---
|
||||
kind: ControlPlane
|
||||
machines:
|
||||
- 20b4c826-e699-43b3-826d-73eb5173680b
|
||||
- 5fdea709-56ad-45f2-966d-5e344dbe4fdf
|
||||
- 30303031-3030-3030-6335-303731636600
|
||||
---
|
||||
kind: Workers
|
||||
machines:
|
||||
- 02c02200-f403-11ef-9372-70f446672600
|
||||
- 03000200-0400-0500-0006-000700080009
|
||||
- 1006b91a-ecbf-11ea-aed4-046ba1ee3700
|
||||
- 5f0cd701-0784-4fcc-8e52-3b3304049972
|
||||
- da507021-8912-4337-86a3-94a05bd1cf05
|
||||
---
|
||||
kind: Machine
|
||||
name: 02c02200-f403-11ef-9372-70f446672600
|
||||
patches:
|
||||
- idOverride: 400-cm-02c02200-f403-11ef-9372-70f446672600
|
||||
annotations:
|
||||
name: ""
|
||||
inline:
|
||||
machine:
|
||||
network:
|
||||
hostname: weyma-talos-w02
|
||||
interfaces:
|
||||
- deviceSelector:
|
||||
driver: igc
|
||||
hardwareAddr: e8:ff:1e:d4:b8:89
|
||||
dhcp: true
|
||||
vlans:
|
||||
- dhcp: false
|
||||
vlanId: 50
|
||||
- deviceSelector:
|
||||
hardwareAddr: e8:ff:1e:d4:b8:8a
|
||||
dhcp: true
|
||||
mtu: 9000
|
||||
- bridge:
|
||||
interfaces:
|
||||
- enp1s0.50
|
||||
dhcp: false
|
||||
interface: br0
|
||||
---
|
||||
kind: Machine
|
||||
name: 03000200-0400-0500-0006-000700080009
|
||||
patches:
|
||||
- idOverride: 400-cm-03000200-0400-0500-0006-000700080009
|
||||
annotations:
|
||||
name: ""
|
||||
inline:
|
||||
machine:
|
||||
network:
|
||||
hostname: weyma-talos-testw01
|
||||
interfaces:
|
||||
- deviceSelector:
|
||||
driver: igc
|
||||
hardwareAddr: e8:ff:1e:d5:f8:22
|
||||
dhcp: true
|
||||
vlans:
|
||||
- dhcp: false
|
||||
vlanId: 50
|
||||
- deviceSelector:
|
||||
hardwareAddr: e8:ff:1e:d5:f8:21
|
||||
dhcp: true
|
||||
mtu: 9000
|
||||
- bridge:
|
||||
interfaces:
|
||||
- enp2s0.50
|
||||
dhcp: false
|
||||
interface: br0
|
||||
---
|
||||
kind: Machine
|
||||
name: 1006b91a-ecbf-11ea-aed4-046ba1ee3700
|
||||
patches:
|
||||
- idOverride: 400-cm-1006b91a-ecbf-11ea-aed4-046ba1ee3700
|
||||
annotations:
|
||||
name: ""
|
||||
inline:
|
||||
machine:
|
||||
network:
|
||||
hostname: weyma-talos-testw04
|
||||
interfaces:
|
||||
- deviceSelector:
|
||||
driver: mlx4_core
|
||||
hardwareAddr: f4:52:14:60:5e:30
|
||||
dhcp: true
|
||||
vlans:
|
||||
- dhcp: false
|
||||
vlanId: 50
|
||||
- deviceSelector:
|
||||
hardwareAddr: f4:52:14:60:5e:31
|
||||
dhcp: true
|
||||
mtu: 9000
|
||||
- bridge:
|
||||
interfaces:
|
||||
- eno1.50
|
||||
dhcp: false
|
||||
interface: br0
|
||||
---
|
||||
kind: Machine
|
||||
name: 30303031-3030-3030-6335-303731636600
|
||||
patches:
|
||||
- idOverride: 400-cm-30303031-3030-3030-6335-303731636600
|
||||
inline:
|
||||
machine:
|
||||
network:
|
||||
hostname: weyma-talos-cp04
|
||||
interfaces:
|
||||
- deviceSelector:
|
||||
hardwareAddr: dc:a6:32:95:0f:cb
|
||||
dhcp: true
|
||||
---
|
||||
kind: Machine
|
||||
name: 20b4c826-e699-43b3-826d-73eb5173680b
|
||||
patches:
|
||||
- idOverride: 400-cm-20b4c826-e699-43b3-826d-73eb5173680b
|
||||
annotations:
|
||||
name: ""
|
||||
inline:
|
||||
machine:
|
||||
network:
|
||||
hostname: weyma-talos-cp02
|
||||
interfaces:
|
||||
- deviceSelector:
|
||||
driver: virtio*
|
||||
hardwareAddr: 00:16:3e:9c:01:27
|
||||
dhcp: true
|
||||
---
|
||||
kind: Machine
|
||||
name: 5f0cd701-0784-4fcc-8e52-3b3304049972
|
||||
patches:
|
||||
- idOverride: 400-cm-5f0cd701-0784-4fcc-8e52-3b3304049972
|
||||
annotations:
|
||||
name: ""
|
||||
inline:
|
||||
machine:
|
||||
network:
|
||||
hostname: weyma-talos-testw05
|
||||
interfaces:
|
||||
- deviceSelector:
|
||||
hardwareAddr: 00:16:3e:b3:dd:f8
|
||||
dhcp: true
|
||||
- deviceSelector:
|
||||
hardwareAddr: 00:16:3e:e5:79:0a
|
||||
dhcp: true
|
||||
mtu: 9000
|
||||
- deviceSelector:
|
||||
hardwareAddr: 00:16:3e:6b:1c:1d
|
||||
dhcp: false
|
||||
- bridge:
|
||||
interfaces:
|
||||
- enx00163e6b1c1d
|
||||
dhcp: false
|
||||
interface: br0
|
||||
---
|
||||
kind: Machine
|
||||
systemExtensions:
|
||||
- siderolabs/nut-client
|
||||
- siderolabs/qemu-guest-agent
|
||||
name: 5fdea709-56ad-45f2-966d-5e344dbe4fdf
|
||||
patches:
|
||||
- idOverride: 400-cm-5fdea709-56ad-45f2-966d-5e344dbe4fdf
|
||||
annotations:
|
||||
name: ""
|
||||
inline:
|
||||
machine:
|
||||
network:
|
||||
hostname: weyma-talos-cp01
|
||||
interfaces:
|
||||
- deviceSelector:
|
||||
driver: virtio*
|
||||
hardwareAddr: bc:24:11:e6:ff:7b
|
||||
dhcp: true
|
||||
---
|
||||
kind: Machine
|
||||
name: da507021-8912-4337-86a3-94a05bd1cf05
|
||||
patches:
|
||||
- idOverride: 400-cm-da507021-8912-4337-86a3-94a05bd1cf05
|
||||
annotations:
|
||||
name: ""
|
||||
inline:
|
||||
machine:
|
||||
network:
|
||||
hostname: weyma-talos-w03
|
||||
interfaces:
|
||||
- deviceSelector:
|
||||
driver: virtio*
|
||||
hardwareAddr: bc:24:11:be:6c:08
|
||||
dhcp: true
|
||||
- deviceSelector:
|
||||
driver: virtio*
|
||||
hardwareAddr: bc:24:11:f8:4a:92
|
||||
dhcp: true
|
||||
mtu: 8996
|
||||
- deviceSelector:
|
||||
driver: virtio*
|
||||
hardwareAddr: bc:24:11:93:02:0e
|
||||
dhcp: false
|
||||
- bridge:
|
||||
interfaces:
|
||||
- enxbc241193020e
|
||||
dhcp: false
|
||||
interface: br0
|
||||
@@ -14,6 +14,11 @@
|
||||
}
|
||||
],
|
||||
"packageRules": [
|
||||
{
|
||||
"description": "Consolidate patch and minor updates to one PR",
|
||||
"matchUpdateTypes": ["minor", "patch"],
|
||||
"groupName": "all-minor-patch-updates"
|
||||
},
|
||||
{
|
||||
"description": "Rook Ceph - auto-update minor and patch versions only",
|
||||
"matchDatasources": ["docker"],
|
||||
|
||||
@@ -24,5 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: argo-cd
|
||||
version: 9.1.4
|
||||
version: 10.2.1
|
||||
repository: https://argoproj.github.io/argo-helm
|
||||
@@ -36,6 +36,26 @@ argo-cd:
|
||||
rbac:
|
||||
policy.csv: |
|
||||
g, ArgoCD Admins, role:admin
|
||||
controller:
|
||||
metrics:
|
||||
enabled: true
|
||||
serviceMonitor:
|
||||
enabled: true
|
||||
rules:
|
||||
enabled: true
|
||||
spec:
|
||||
- alert: ArgoAppMissing
|
||||
expr: |
|
||||
absent(argocd_app_info) == 1
|
||||
for: 15m
|
||||
labels:
|
||||
severity: critical
|
||||
annotations:
|
||||
summary: "[Argo CD] No reported applications"
|
||||
description: >
|
||||
Argo CD has not reported any applications data for the past 15 minutes which
|
||||
means that it must be down or not functioning properly. This needs to be
|
||||
resolved for this cloud to continue to maintain state.
|
||||
server:
|
||||
ingress:
|
||||
enabled: true
|
||||
@@ -43,26 +63,51 @@ argo-cd:
|
||||
enabled: true
|
||||
readinessProbe:
|
||||
enabled: true
|
||||
metrics:
|
||||
enabled: true
|
||||
serviceMonitor:
|
||||
enabled: true
|
||||
repoServer:
|
||||
livenessProbe:
|
||||
enabled: true
|
||||
readinessProbe:
|
||||
enabled: true
|
||||
metrics:
|
||||
enabled: true
|
||||
serviceMonitor:
|
||||
enabled: true
|
||||
applicationSet:
|
||||
livenessProbe:
|
||||
enabled: true
|
||||
readinessProbe:
|
||||
enabled: true
|
||||
metrics:
|
||||
enabled: true
|
||||
serviceMonitor:
|
||||
enabled: true
|
||||
redis:
|
||||
livenessProbe:
|
||||
enabled: true
|
||||
readinessProbe:
|
||||
enabled: true
|
||||
metrics:
|
||||
enabled: true
|
||||
serviceMonitor:
|
||||
enabled: true
|
||||
dex:
|
||||
livenessProbe:
|
||||
enabled: true
|
||||
readinessProbe:
|
||||
enabled: true
|
||||
metrics:
|
||||
enabled: true
|
||||
serviceMonitor:
|
||||
enabled: true
|
||||
notifications:
|
||||
metrics:
|
||||
enabled: true
|
||||
serviceMonitor:
|
||||
enabled: true
|
||||
extraObjects:
|
||||
- apiVersion: external-secrets.io/v1
|
||||
kind: ExternalSecret
|
||||
@@ -83,18 +128,34 @@ argo-cd:
|
||||
remoteRef:
|
||||
key: argo-cd
|
||||
property: webhook.gitea.secret
|
||||
conversionStrategy: Default
|
||||
decodingStrategy: None
|
||||
metadataPolicy: None
|
||||
nullBytePolicy: Ignore
|
||||
- secretKey: admin.password
|
||||
remoteRef:
|
||||
key: argo-cd
|
||||
property: admin.password
|
||||
conversionStrategy: Default
|
||||
decodingStrategy: None
|
||||
metadataPolicy: None
|
||||
nullBytePolicy: Ignore
|
||||
- secretKey: admin.passwordMtime
|
||||
remoteRef:
|
||||
key: argo-cd
|
||||
property: admin.passwordMtime
|
||||
conversionStrategy: Default
|
||||
decodingStrategy: None
|
||||
metadataPolicy: None
|
||||
nullBytePolicy: Ignore
|
||||
- secretKey: dex.authentik.clientSecret
|
||||
remoteRef:
|
||||
key: argo-cd
|
||||
property: dex.authentik.clientSecret
|
||||
conversionStrategy: Default
|
||||
decodingStrategy: None
|
||||
metadataPolicy: None
|
||||
nullBytePolicy: Ignore
|
||||
- apiVersion: external-secrets.io/v1
|
||||
kind: ExternalSecret
|
||||
metadata:
|
||||
@@ -115,14 +176,26 @@ argo-cd:
|
||||
remoteRef:
|
||||
key: argo-cd-git
|
||||
property: sshPrivateKey
|
||||
conversionStrategy: Default
|
||||
decodingStrategy: None
|
||||
metadataPolicy: None
|
||||
nullBytePolicy: Ignore
|
||||
- secretKey: type
|
||||
remoteRef:
|
||||
key: argo-cd-git
|
||||
property: type
|
||||
conversionStrategy: Default
|
||||
decodingStrategy: None
|
||||
metadataPolicy: None
|
||||
nullBytePolicy: Ignore
|
||||
- secretKey: url
|
||||
remoteRef:
|
||||
key: argo-cd-git
|
||||
property: url.core-apps
|
||||
conversionStrategy: Default
|
||||
decodingStrategy: None
|
||||
metadataPolicy: None
|
||||
nullBytePolicy: Ignore
|
||||
- apiVersion: external-secrets.io/v1
|
||||
kind: ExternalSecret
|
||||
metadata:
|
||||
@@ -143,14 +216,26 @@ argo-cd:
|
||||
remoteRef:
|
||||
key: argo-cd-git
|
||||
property: sshPrivateKey
|
||||
conversionStrategy: Default
|
||||
decodingStrategy: None
|
||||
metadataPolicy: None
|
||||
nullBytePolicy: Ignore
|
||||
- secretKey: type
|
||||
remoteRef:
|
||||
key: argo-cd-git
|
||||
property: type
|
||||
conversionStrategy: Default
|
||||
decodingStrategy: None
|
||||
metadataPolicy: None
|
||||
nullBytePolicy: Ignore
|
||||
- secretKey: url
|
||||
remoteRef:
|
||||
key: argo-cd-git
|
||||
property: url.weyma-talos
|
||||
conversionStrategy: Default
|
||||
decodingStrategy: None
|
||||
metadataPolicy: None
|
||||
nullBytePolicy: Ignore
|
||||
- apiVersion: external-secrets.io/v1
|
||||
kind: ExternalSecret
|
||||
metadata:
|
||||
@@ -171,14 +256,26 @@ argo-cd:
|
||||
remoteRef:
|
||||
key: argo-cd-git
|
||||
property: sshPrivateKey
|
||||
conversionStrategy: Default
|
||||
decodingStrategy: None
|
||||
metadataPolicy: None
|
||||
nullBytePolicy: Ignore
|
||||
- secretKey: type
|
||||
remoteRef:
|
||||
key: argo-cd-git
|
||||
property: type
|
||||
conversionStrategy: Default
|
||||
decodingStrategy: None
|
||||
metadataPolicy: None
|
||||
nullBytePolicy: Ignore
|
||||
- secretKey: url
|
||||
remoteRef:
|
||||
key: argo-cd-git
|
||||
property: url.williamp-sites
|
||||
conversionStrategy: Default
|
||||
decodingStrategy: None
|
||||
metadataPolicy: None
|
||||
nullBytePolicy: Ignore
|
||||
- apiVersion: external-secrets.io/v1
|
||||
kind: ExternalSecret
|
||||
metadata:
|
||||
@@ -199,11 +296,23 @@ argo-cd:
|
||||
remoteRef:
|
||||
key: argo-cd-git
|
||||
property: sshPrivateKey
|
||||
conversionStrategy: Default
|
||||
decodingStrategy: None
|
||||
metadataPolicy: None
|
||||
nullBytePolicy: Ignore
|
||||
- secretKey: type
|
||||
remoteRef:
|
||||
key: argo-cd-git
|
||||
property: type
|
||||
conversionStrategy: Default
|
||||
decodingStrategy: None
|
||||
metadataPolicy: None
|
||||
nullBytePolicy: Ignore
|
||||
- secretKey: url
|
||||
remoteRef:
|
||||
key: argo-cd-git
|
||||
property: url.db-operators
|
||||
conversionStrategy: Default
|
||||
decodingStrategy: None
|
||||
metadataPolicy: None
|
||||
nullBytePolicy: Ignore
|
||||
@@ -24,5 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: cert-manager
|
||||
version: v1.19.1
|
||||
version: v1.21.0
|
||||
repository: https://charts.jetstack.io
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: argocd
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: argocd
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: attic
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: attic
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: authentik
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: authentik
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: duby-blog
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: duby-blog
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: dubyatp-xyz
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: dubyatp-xyz
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: frenworld-archive
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: frenworld-archive
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-frenworld-archive-io
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: gitea
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: gitea
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: grafana
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: grafana
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: jellyfin
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: jellyfin
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: kite
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: kite
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: lumfao-dubyatp-xyz
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: lumfao-dubyatp-xyz
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: netmaker
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: netmaker
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: nextcloud
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: nextcloud
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: rook-ceph
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: rook-ceph
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: test-dubyatp-xyz
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: default
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: traefik
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: traefik
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: vaultwarden
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: vaultwarden
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: whatismyip
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: whatismyip
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: williamtpeebles-com
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: williamtpeebles-com
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-williamtpeebles-com
|
||||
@@ -9,3 +9,7 @@ cert-manager:
|
||||
cainjector:
|
||||
serviceLabels:
|
||||
metrics_enabled: "true"
|
||||
prometheus:
|
||||
enabled: true
|
||||
servicemonitor:
|
||||
enabled: true
|
||||
@@ -24,5 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: external-secrets
|
||||
version: 1.1.0
|
||||
version: 2.8.0
|
||||
repository: https://charts.external-secrets.io
|
||||
@@ -171,7 +171,7 @@ resources: {}
|
||||
|
||||
serviceMonitor:
|
||||
# -- Specifies whether to create a ServiceMonitor resource for collecting Prometheus metrics
|
||||
enabled: false
|
||||
enabled: true
|
||||
|
||||
# -- namespace where you want to install ServiceMonitors
|
||||
namespace: ""
|
||||
|
||||
@@ -1,21 +0,0 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: guestbook-ui
|
||||
namespace: guestbook-ui
|
||||
spec:
|
||||
replicas: 1
|
||||
revisionHistoryLimit: 3
|
||||
selector:
|
||||
matchLabels:
|
||||
app: guestbook-ui
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: guestbook-ui
|
||||
spec:
|
||||
containers:
|
||||
- image: gcr.io/heptio-images/ks-guestbook-demo:0.2
|
||||
name: guestbook-ui
|
||||
ports:
|
||||
- containerPort: 80
|
||||
@@ -1,4 +0,0 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: guestbook-ui
|
||||
@@ -1,11 +0,0 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: guestbook-ui
|
||||
namespace: guestbook-ui
|
||||
spec:
|
||||
ports:
|
||||
- port: 80
|
||||
targetPort: 80
|
||||
selector:
|
||||
app: guestbook-ui
|
||||
@@ -0,0 +1,28 @@
|
||||
apiVersion: v2
|
||||
name: kite
|
||||
description: A Helm chart for Kubernetes
|
||||
|
||||
# A chart can be either an 'application' or a 'library' chart.
|
||||
#
|
||||
# Application charts are a collection of templates that can be packaged into versioned archives
|
||||
# to be deployed.
|
||||
#
|
||||
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
||||
# a dependency of application charts to inject those utilities and functions into the rendering
|
||||
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
||||
type: application
|
||||
|
||||
# This is the chart version. This version number should be incremented each time you make changes
|
||||
# to the chart and its templates, including the app version.
|
||||
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||
version: 0.1.0
|
||||
|
||||
# This is the version number of the application being deployed. This version number should be
|
||||
# incremented each time you make changes to the application. Versions are not expected to
|
||||
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||
appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: kite
|
||||
version: 0.14.1
|
||||
repository: https://zxh326.github.io/kite
|
||||
@@ -0,0 +1,30 @@
|
||||
apiVersion: external-secrets.io/v1
|
||||
kind: ExternalSecret
|
||||
metadata:
|
||||
name: kite-secret
|
||||
namespace: {{ .Release.Namespace }}
|
||||
spec:
|
||||
refreshInterval: 1h
|
||||
secretStoreRef:
|
||||
name: weyma-vault
|
||||
kind: ClusterSecretStore
|
||||
target:
|
||||
name: kite-secret
|
||||
creationPolicy: Owner
|
||||
data:
|
||||
- secretKey: JWT_SECRET
|
||||
remoteRef:
|
||||
key: kite
|
||||
property: JWT_SECRET
|
||||
- secretKey: KITE_ENCRYPT_KEY
|
||||
remoteRef:
|
||||
key: kite
|
||||
property: KITE_ENCRYPT_KEY
|
||||
- secretKey: KITE_PASSWORD
|
||||
remoteRef:
|
||||
key: kite
|
||||
property: KITE_PASSWORD
|
||||
- secretKey: KITE_USERNAME
|
||||
remoteRef:
|
||||
key: kite
|
||||
property: KITE_USERNAME
|
||||
@@ -0,0 +1,22 @@
|
||||
kite:
|
||||
host: "https://weyma-kite.infra.dubyatp.xyz"
|
||||
deploymentStrategy:
|
||||
type: Recreate
|
||||
secret:
|
||||
create: false
|
||||
existingSecret: kite-secret
|
||||
db:
|
||||
sqlite:
|
||||
persistence:
|
||||
pvc:
|
||||
enabled: true
|
||||
ingress:
|
||||
enabled: true
|
||||
className: "traefik"
|
||||
hosts:
|
||||
- host: weyma-kite.infra.dubyatp.xyz
|
||||
paths:
|
||||
- path: /
|
||||
pathType: ImplementationSpecific
|
||||
podAnnotations:
|
||||
backup.velero.io/backup-volumes: kite-storage
|
||||
@@ -24,5 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: kubernetes-replicator
|
||||
version: 2.12.2
|
||||
version: 2.12.4
|
||||
repository: https://helm.mittwald.de
|
||||
@@ -24,5 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: metallb
|
||||
version: 0.15.2
|
||||
version: 0.16.1
|
||||
repository: https://metallb.github.io/metallb
|
||||
@@ -1,354 +1,9 @@
|
||||
# Default values for metallb.
|
||||
# This is a YAML-formatted file.
|
||||
# Declare variables to be passed into your templates.
|
||||
|
||||
imagePullSecrets: []
|
||||
nameOverride: ""
|
||||
fullnameOverride: ""
|
||||
loadBalancerClass: ""
|
||||
|
||||
# To configure MetalLB, you must specify ONE of the following two
|
||||
# options.
|
||||
|
||||
rbac:
|
||||
# create specifies whether to install and use RBAC rules.
|
||||
create: true
|
||||
|
||||
prometheus:
|
||||
# scrape annotations specifies whether to add Prometheus metric
|
||||
# auto-collection annotations to pods. See
|
||||
# https://github.com/prometheus/prometheus/blob/release-2.1/documentation/examples/prometheus-kubernetes.yml
|
||||
# for a corresponding Prometheus configuration. Alternatively, you
|
||||
# may want to use the Prometheus Operator
|
||||
# (https://github.com/coreos/prometheus-operator) for more powerful
|
||||
# monitoring configuration. If you use the Prometheus operator, this
|
||||
# can be left at false.
|
||||
scrapeAnnotations: false
|
||||
|
||||
# port both controller and speaker will listen on for metrics
|
||||
metricsPort: 7472
|
||||
|
||||
# if set, enables rbac proxy on the controller and speaker to expose
|
||||
# the metrics via tls.
|
||||
# secureMetricsPort: 9120
|
||||
|
||||
# the name of the secret to be mounted in the speaker pod
|
||||
# to expose the metrics securely. If not present, a self signed
|
||||
# certificate to be used.
|
||||
speakerMetricsTLSSecret: ""
|
||||
|
||||
# the name of the secret to be mounted in the controller pod
|
||||
# to expose the metrics securely. If not present, a self signed
|
||||
# certificate to be used.
|
||||
controllerMetricsTLSSecret: ""
|
||||
|
||||
# prometheus doesn't have the permission to scrape all namespaces so we give it permission to scrape metallb's one
|
||||
rbacPrometheus: true
|
||||
|
||||
# the service account used by prometheus
|
||||
# required when " .Values.prometheus.rbacPrometheus == true " and " .Values.prometheus.podMonitor.enabled=true or prometheus.serviceMonitor.enabled=true "
|
||||
serviceAccount: ""
|
||||
|
||||
# the namespace where prometheus is deployed
|
||||
# required when " .Values.prometheus.rbacPrometheus == true " and " .Values.prometheus.podMonitor.enabled=true or prometheus.serviceMonitor.enabled=true "
|
||||
namespace: ""
|
||||
|
||||
# the image to be used for the kuberbacproxy container
|
||||
rbacProxy:
|
||||
repository: gcr.io/kubebuilder/kube-rbac-proxy
|
||||
tag: v0.12.0
|
||||
pullPolicy:
|
||||
|
||||
# Prometheus Operator PodMonitors
|
||||
metallb:
|
||||
frrk8s:
|
||||
enabled: false
|
||||
prometheus:
|
||||
rbacPrometheus: false
|
||||
podMonitor:
|
||||
# enable support for Prometheus Operator
|
||||
enabled: false
|
||||
|
||||
# optional additional labels for podMonitors
|
||||
additionalLabels: {}
|
||||
|
||||
# optional annotations for podMonitors
|
||||
annotations: {}
|
||||
|
||||
# Job label for scrape target
|
||||
jobLabel: "app.kubernetes.io/name"
|
||||
|
||||
# Scrape interval. If not set, the Prometheus default scrape interval is used.
|
||||
interval:
|
||||
|
||||
# metric relabel configs to apply to samples before ingestion.
|
||||
metricRelabelings: []
|
||||
# - action: keep
|
||||
# regex: 'kube_(daemonset|deployment|pod|namespace|node|statefulset).+'
|
||||
# sourceLabels: [__name__]
|
||||
|
||||
# relabel configs to apply to samples before ingestion.
|
||||
relabelings: []
|
||||
# - sourceLabels: [__meta_kubernetes_pod_node_name]
|
||||
# separator: ;
|
||||
# regex: ^(.*)$
|
||||
# target_label: nodename
|
||||
# replacement: $1
|
||||
# action: replace
|
||||
|
||||
# Prometheus Operator ServiceMonitors. To be used as an alternative
|
||||
# to podMonitor, supports secure metrics.
|
||||
serviceMonitor:
|
||||
# enable support for Prometheus Operator
|
||||
enabled: false
|
||||
|
||||
speaker:
|
||||
# optional additional labels for the speaker serviceMonitor
|
||||
additionalLabels: {}
|
||||
# optional additional annotations for the speaker serviceMonitor
|
||||
annotations: {}
|
||||
# optional tls configuration for the speaker serviceMonitor, in case
|
||||
# secure metrics are enabled.
|
||||
tlsConfig:
|
||||
insecureSkipVerify: true
|
||||
|
||||
controller:
|
||||
# optional additional labels for the controller serviceMonitor
|
||||
additionalLabels: {}
|
||||
# optional additional annotations for the controller serviceMonitor
|
||||
annotations: {}
|
||||
# optional tls configuration for the controller serviceMonitor, in case
|
||||
# secure metrics are enabled.
|
||||
tlsConfig:
|
||||
insecureSkipVerify: true
|
||||
|
||||
# Job label for scrape target
|
||||
jobLabel: "app.kubernetes.io/name"
|
||||
|
||||
# Scrape interval. If not set, the Prometheus default scrape interval is used.
|
||||
interval:
|
||||
|
||||
# metric relabel configs to apply to samples before ingestion.
|
||||
metricRelabelings: []
|
||||
# - action: keep
|
||||
# regex: 'kube_(daemonset|deployment|pod|namespace|node|statefulset).+'
|
||||
# sourceLabels: [__name__]
|
||||
|
||||
# relabel configs to apply to samples before ingestion.
|
||||
relabelings: []
|
||||
# - sourceLabels: [__meta_kubernetes_pod_node_name]
|
||||
# separator: ;
|
||||
# regex: ^(.*)$
|
||||
# target_label: nodename
|
||||
# replacement: $1
|
||||
# action: replace
|
||||
|
||||
# Prometheus Operator alertmanager alerts
|
||||
enabled: true
|
||||
prometheusRule:
|
||||
# enable alertmanager alerts
|
||||
enabled: false
|
||||
|
||||
# optional additional labels for prometheusRules
|
||||
additionalLabels: {}
|
||||
|
||||
# optional annotations for prometheusRules
|
||||
annotations: {}
|
||||
|
||||
# MetalLBStaleConfig
|
||||
staleConfig:
|
||||
enabled: true
|
||||
labels:
|
||||
severity: warning
|
||||
|
||||
# MetalLBConfigNotLoaded
|
||||
configNotLoaded:
|
||||
enabled: true
|
||||
labels:
|
||||
severity: warning
|
||||
|
||||
# MetalLBAddressPoolExhausted
|
||||
addressPoolExhausted:
|
||||
enabled: true
|
||||
labels:
|
||||
severity: critical
|
||||
|
||||
addressPoolUsage:
|
||||
enabled: true
|
||||
thresholds:
|
||||
- percent: 75
|
||||
labels:
|
||||
severity: warning
|
||||
- percent: 85
|
||||
labels:
|
||||
severity: warning
|
||||
- percent: 95
|
||||
labels:
|
||||
severity: critical
|
||||
|
||||
# MetalLBBGPSessionDown
|
||||
bgpSessionDown:
|
||||
enabled: true
|
||||
labels:
|
||||
severity: critical
|
||||
|
||||
extraAlerts: []
|
||||
|
||||
# controller contains configuration specific to the MetalLB cluster
|
||||
# controller.
|
||||
controller:
|
||||
enabled: true
|
||||
# -- Controller log level. Must be one of: `all`, `debug`, `info`, `warn`, `error` or `none`
|
||||
logLevel: info
|
||||
# command: /controller
|
||||
# webhookMode: enabled
|
||||
|
||||
## @param controller.updateStrategy.type Metallb controller deployment strategy type.
|
||||
## ref: https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#strategy
|
||||
## e.g:
|
||||
## strategy:
|
||||
## type: RollingUpdate
|
||||
## rollingUpdate:
|
||||
## maxSurge: 25%
|
||||
## maxUnavailable: 25%
|
||||
##
|
||||
strategy:
|
||||
type: RollingUpdate
|
||||
serviceAccount:
|
||||
# Specifies whether a ServiceAccount should be created
|
||||
create: true
|
||||
# The name of the ServiceAccount to use. If not set and create is
|
||||
# true, a name is generated using the fullname template
|
||||
name: ""
|
||||
annotations: {}
|
||||
securityContext:
|
||||
runAsNonRoot: true
|
||||
# nobody
|
||||
runAsUser: 65534
|
||||
fsGroup: 65534
|
||||
resources: {}
|
||||
# limits:
|
||||
# cpu: 100m
|
||||
# memory: 100Mi
|
||||
nodeSelector: {}
|
||||
tolerations: []
|
||||
priorityClassName: ""
|
||||
runtimeClassName: ""
|
||||
affinity: {}
|
||||
podAnnotations: {}
|
||||
labels: {}
|
||||
livenessProbe:
|
||||
enabled: true
|
||||
failureThreshold: 3
|
||||
initialDelaySeconds: 10
|
||||
periodSeconds: 10
|
||||
successThreshold: 1
|
||||
timeoutSeconds: 1
|
||||
readinessProbe:
|
||||
enabled: true
|
||||
failureThreshold: 3
|
||||
initialDelaySeconds: 10
|
||||
periodSeconds: 10
|
||||
successThreshold: 1
|
||||
timeoutSeconds: 1
|
||||
tlsMinVersion: "VersionTLS12"
|
||||
tlsCipherSuites: ""
|
||||
|
||||
extraContainers: []
|
||||
|
||||
# speaker contains configuration specific to the MetalLB speaker
|
||||
# daemonset.
|
||||
speaker:
|
||||
enabled: true
|
||||
# command: /speaker
|
||||
# -- Speaker log level. Must be one of: `all`, `debug`, `info`, `warn`, `error` or `none`
|
||||
logLevel: info
|
||||
tolerateMaster: true
|
||||
memberlist:
|
||||
enabled: true
|
||||
mlBindPort: 7946
|
||||
mlBindAddrOverride: ""
|
||||
mlSecretKeyPath: "/etc/ml_secret_key"
|
||||
excludeInterfaces:
|
||||
enabled: true
|
||||
# ignore the exclude-from-external-loadbalancer label
|
||||
ignoreExcludeLB: false
|
||||
|
||||
## @param speaker.updateStrategy.type Speaker daemonset strategy type
|
||||
## ref: https://kubernetes.io/docs/tasks/manage-daemon/update-daemon-set/
|
||||
##
|
||||
updateStrategy:
|
||||
## StrategyType
|
||||
## Can be set to RollingUpdate or OnDelete
|
||||
##
|
||||
type: RollingUpdate
|
||||
serviceAccount:
|
||||
# Specifies whether a ServiceAccount should be created
|
||||
create: true
|
||||
# The name of the ServiceAccount to use. If not set and create is
|
||||
# true, a name is generated using the fullname template
|
||||
name: ""
|
||||
annotations: {}
|
||||
securityContext: {}
|
||||
## Defines a secret name for the controller to generate a memberlist encryption secret
|
||||
## By default secretName: {{ "metallb.fullname" }}-memberlist
|
||||
##
|
||||
# secretName:
|
||||
resources: {}
|
||||
# limits:
|
||||
# cpu: 100m
|
||||
# memory: 100Mi
|
||||
nodeSelector: {}
|
||||
tolerations: []
|
||||
priorityClassName: ""
|
||||
affinity: {}
|
||||
## Selects which runtime class will be used by the pod.
|
||||
runtimeClassName: ""
|
||||
podAnnotations: {}
|
||||
labels: {}
|
||||
livenessProbe:
|
||||
enabled: true
|
||||
failureThreshold: 3
|
||||
initialDelaySeconds: 10
|
||||
periodSeconds: 10
|
||||
successThreshold: 1
|
||||
timeoutSeconds: 1
|
||||
readinessProbe:
|
||||
enabled: true
|
||||
failureThreshold: 3
|
||||
initialDelaySeconds: 10
|
||||
periodSeconds: 10
|
||||
successThreshold: 1
|
||||
timeoutSeconds: 1
|
||||
startupProbe:
|
||||
enabled: true
|
||||
failureThreshold: 30
|
||||
periodSeconds: 5
|
||||
# frr contains configuration specific to the MetalLB FRR container,
|
||||
# for speaker running alongside FRR.
|
||||
frr:
|
||||
enabled: false
|
||||
metricsPort: 7473
|
||||
resources: {}
|
||||
|
||||
# if set, enables a rbac proxy sidecar container on the speaker to
|
||||
# expose the frr metrics via tls.
|
||||
# secureMetricsPort: 9121
|
||||
|
||||
|
||||
reloader:
|
||||
resources: {}
|
||||
|
||||
frrMetrics:
|
||||
resources: {}
|
||||
|
||||
extraContainers: []
|
||||
|
||||
crds:
|
||||
enabled: true
|
||||
validationFailurePolicy: Fail
|
||||
|
||||
# frrk8s contains the configuration related to using an frrk8s instance
|
||||
# (github.com/metallb/frr-k8s) as the backend for the BGP implementation.
|
||||
# This allows configuring additional frr parameters in combination to those
|
||||
# applied by MetalLB.
|
||||
frrk8s:
|
||||
# if set, enables frrk8s as a backend. This is mutually exclusive to frr
|
||||
# mode.
|
||||
enabled: false
|
||||
external: false
|
||||
namespace: ""
|
||||
|
||||
@@ -24,5 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: kube-prometheus-stack
|
||||
version: 79.7.1
|
||||
version: 87.19.1
|
||||
repository: https://prometheus-community.github.io/helm-charts
|
||||
@@ -0,0 +1,22 @@
|
||||
apiVersion: external-secrets.io/v1
|
||||
kind: ExternalSecret
|
||||
metadata:
|
||||
name: discord-webhook
|
||||
namespace: {{ .Release.Namespace }}
|
||||
spec:
|
||||
refreshInterval: 1h
|
||||
secretStoreRef:
|
||||
name: weyma-vault
|
||||
kind: ClusterSecretStore
|
||||
target:
|
||||
name: discord-webhook
|
||||
creationPolicy: Owner
|
||||
data:
|
||||
- secretKey: webhook
|
||||
remoteRef:
|
||||
conversionStrategy: Default
|
||||
decodingStrategy: None
|
||||
metadataPolicy: None
|
||||
nullBytePolicy: Ignore
|
||||
key: monitoring
|
||||
property: discord_webhook
|
||||
@@ -0,0 +1,67 @@
|
||||
{{- if .Values.discord.enabled }}
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: alertmanager-discord
|
||||
namespace: {{ .Release.Namespace }}
|
||||
labels:
|
||||
app.kubernetes.io/name: alertmanager-discord
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: alertmanager-discord
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: alertmanager-discord
|
||||
spec:
|
||||
containers:
|
||||
- name: alertmanager-discord
|
||||
image: {{ .Values.discord.image | default "ghcr.io/rogerrum/alertmanager-discord:1.0.7" }}
|
||||
ports:
|
||||
- containerPort: 9094
|
||||
env:
|
||||
- name: LISTEN_ADDRESS
|
||||
value: "0.0.0.0:9094"
|
||||
- name: DISCORD_WEBHOOK
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.discord.secret.name | quote }}
|
||||
key: {{ .Values.discord.secret.key | quote }}
|
||||
{{- if .Values.discord.username }}
|
||||
- name: DISCORD_USERNAME
|
||||
value: {{ .Values.discord.username | quote }}
|
||||
{{- end }}
|
||||
{{- if .Values.discord.avatar_url }}
|
||||
- name: DISCORD_AVATAR_URL
|
||||
value: {{ .Values.discord.avatar_url | quote }}
|
||||
{{- end }}
|
||||
{{- if .Values.discord.verbose }}
|
||||
- name: VERBOSE
|
||||
value: "ON"
|
||||
{{- end }}
|
||||
resources:
|
||||
requests:
|
||||
memory: "128Mi"
|
||||
cpu: "500m"
|
||||
limits:
|
||||
memory: "512Mi"
|
||||
cpu: "1"
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: alertmanager-discord
|
||||
namespace: {{ .Release.Namespace }}
|
||||
spec:
|
||||
type: ClusterIP
|
||||
selector:
|
||||
app: alertmanager-discord
|
||||
ports:
|
||||
- port: 9094
|
||||
targetPort: 9094
|
||||
protocol: TCP
|
||||
{{- end }}
|
||||
@@ -1,5 +1,23 @@
|
||||
kube-prometheus-stack:
|
||||
alertmanager:
|
||||
config:
|
||||
route:
|
||||
group_by: ['namespace']
|
||||
group_wait: 30s
|
||||
group_interval: 5m
|
||||
repeat_interval: 12h
|
||||
receiver: 'null'
|
||||
routes:
|
||||
- receiver: "discord_webhook"
|
||||
matchers:
|
||||
- severity = "critical"
|
||||
continue: false
|
||||
- receiver: 'null'
|
||||
receivers:
|
||||
- name: "null"
|
||||
- name: "discord_webhook"
|
||||
webhook_configs:
|
||||
- url: "http://alertmanager-discord:9094"
|
||||
alertmanagerSpec:
|
||||
storage:
|
||||
volumeClaimTemplate:
|
||||
@@ -9,6 +27,19 @@ kube-prometheus-stack:
|
||||
resources:
|
||||
requests:
|
||||
storage: 50Gi
|
||||
additionalPrometheusRulesMap:
|
||||
rule-name:
|
||||
groups:
|
||||
- name: AdditionalAlerts
|
||||
rules:
|
||||
- alert: ExcessiveWarnings
|
||||
expr: count(ALERTS{severity="warning",alertstate="firing"}) >= 5
|
||||
for: 1m
|
||||
labels:
|
||||
severity: critical
|
||||
annotations:
|
||||
summary: Excessive 'warning' alerts are firing in the cluster
|
||||
description: "{{ $value }} alerts with 'warning' severity are firing and could be a sign of catastrophic failure in the cluster"
|
||||
prometheusOperator:
|
||||
admissionWebhooks:
|
||||
certManager:
|
||||
@@ -40,3 +71,10 @@ kube-prometheus-stack:
|
||||
storage: 50Gi
|
||||
grafana:
|
||||
enabled: false # Grafana is instead deployed in its own namespace in the core-apps repo
|
||||
discord:
|
||||
enabled: true
|
||||
secret:
|
||||
name: discord-webhook
|
||||
key: webhook
|
||||
username: "Alertmanager"
|
||||
verbose: true
|
||||
@@ -35,10 +35,10 @@ spec:
|
||||
resources:
|
||||
requests:
|
||||
cpu: "100m"
|
||||
memory: "50Mi"
|
||||
memory: "64Mi"
|
||||
limits:
|
||||
cpu: "100m"
|
||||
memory: "50Mi"
|
||||
cpu: "200m"
|
||||
memory: "256Mi"
|
||||
securityContext:
|
||||
privileged: true
|
||||
terminationMessagePolicy: FallbackToLogsOnError
|
||||
|
||||
@@ -21,7 +21,7 @@ spec:
|
||||
# versions running within the cluster. See tags available at https://hub.docker.com/r/ceph/ceph/tags/.
|
||||
# If you want to be more precise, you can always use a timestamp tag such as quay.io/ceph/ceph:v19.2.1-20250202
|
||||
# This tag might not contain a new Ceph version, just security fixes from the underlying operating system, which will reduce vulnerabilities
|
||||
image: quay.io/ceph/ceph:v19.2.3-20250717
|
||||
image: quay.io/ceph/ceph:v20.2.0-20251104
|
||||
# Whether to allow unsupported versions of Ceph. Currently Reef and Squid are supported.
|
||||
# Future versions such as Tentacle (v20) would require this to be set to `true`.
|
||||
# Do not set to true in production.
|
||||
|
||||
@@ -24,5 +24,8 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: rook-ceph
|
||||
version: v1.18.7
|
||||
version: v1.20.2
|
||||
repository: https://charts.rook.io/release
|
||||
- name: ceph-csi-drivers
|
||||
version: 1.0.4
|
||||
repository: https://ceph.github.io/ceph-csi-operator
|
||||
@@ -0,0 +1,842 @@
|
||||
{{- if and .Values.monitoring.enabled -}}
|
||||
---
|
||||
apiVersion: monitoring.coreos.com/v1
|
||||
kind: PrometheusRule
|
||||
metadata:
|
||||
name: prometheus-pvc-rules
|
||||
namespace: {{ .Release.Namespace }}
|
||||
spec:
|
||||
groups:
|
||||
- name: persistent-volume-alert.rules
|
||||
rules:
|
||||
- alert: PersistentVolumeUsageNearFull
|
||||
annotations:
|
||||
description: PVC {{ "{{" }} $labels.persistentvolumeclaim {{ "}}" }} utilization has crossed 75%. Free up some space or expand the PVC.
|
||||
message: PVC {{ "{{" }} $labels.persistentvolumeclaim {{ "}}" }} is nearing full. Data deletion or PVC expansion is required.
|
||||
severity_level: warning
|
||||
storage_type: ceph
|
||||
expr: |
|
||||
(kubelet_volume_stats_used_bytes * on (namespace,persistentvolumeclaim) group_left(storageclass, provisioner) (kube_persistentvolumeclaim_info * on (storageclass) group_left(provisioner) kube_storageclass_info {provisioner=~"(.*rbd.csi.ceph.com)|(.*cephfs.csi.ceph.com)"})) / (kubelet_volume_stats_capacity_bytes * on (namespace,persistentvolumeclaim) group_left(storageclass, provisioner) (kube_persistentvolumeclaim_info * on (storageclass) group_left(provisioner) kube_storageclass_info {provisioner=~"(.*rbd.csi.ceph.com)|(.*cephfs.csi.ceph.com)"})) > 0.75
|
||||
for: 5s
|
||||
labels:
|
||||
severity: warning
|
||||
- alert: PersistentVolumeUsageCritical
|
||||
annotations:
|
||||
description: PVC {{ "{{" }} $labels.persistentvolumeclaim {{ "}}" }} utilization has crossed 85%. Free up some space or expand the PVC immediately.
|
||||
message: PVC {{ "{{" }} $labels.persistentvolumeclaim {{ "}}" }} is critically full. Data deletion or PVC expansion is required.
|
||||
severity_level: error
|
||||
storage_type: ceph
|
||||
expr: |
|
||||
(kubelet_volume_stats_used_bytes * on (namespace,persistentvolumeclaim) group_left(storageclass, provisioner) (kube_persistentvolumeclaim_info * on (storageclass) group_left(provisioner) kube_storageclass_info {provisioner=~"(.*rbd.csi.ceph.com)|(.*cephfs.csi.ceph.com)"})) / (kubelet_volume_stats_capacity_bytes * on (namespace,persistentvolumeclaim) group_left(storageclass, provisioner) (kube_persistentvolumeclaim_info * on (storageclass) group_left(provisioner) kube_storageclass_info {provisioner=~"(.*rbd.csi.ceph.com)|(.*cephfs.csi.ceph.com)"})) > 0.85
|
||||
for: 5s
|
||||
labels:
|
||||
severity: critical
|
||||
---
|
||||
apiVersion: monitoring.coreos.com/v1
|
||||
kind: PrometheusRule
|
||||
metadata:
|
||||
name: prometheus-ceph-rules
|
||||
namespace: {{ .Release.Namespace }}
|
||||
spec:
|
||||
groups:
|
||||
- name: "cluster health"
|
||||
rules:
|
||||
- alert: "CephHealthError"
|
||||
annotations:
|
||||
description: "The cluster state has been HEALTH_ERROR for more than 5 minutes. Please check 'ceph health detail' for more information."
|
||||
summary: "Ceph is in the ERROR state"
|
||||
expr: "ceph_health_status == 2"
|
||||
for: "5m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.2.1"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "CephHealthWarning"
|
||||
annotations:
|
||||
description: "The cluster state has been HEALTH_WARN for more than 15 minutes. Please check 'ceph health detail' for more information."
|
||||
summary: "Ceph is in the WARNING state"
|
||||
expr: "ceph_health_status == 1"
|
||||
for: "15m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- name: "mon"
|
||||
rules:
|
||||
- alert: "CephMonDownQuorumAtRisk"
|
||||
annotations:
|
||||
description: "{{ "{{" }} $min := query \"floor(count(ceph_mon_metadata) / 2) + 1\" | first | value {{ "}}" }}Quorum requires a majority of monitors (x {{ "{{" }} $min {{ "}}" }}) to be active. Without quorum the cluster will become inoperable, affecting all services and connected clients. The following monitors are down: {{ "{{" }}- range query \"(ceph_mon_quorum_status == 0) + on(ceph_daemon) group_left(hostname) (ceph_mon_metadata * 0)\" {{ "}}" }} - {{ "{{" }} .Labels.ceph_daemon {{ "}}" }} on {{ "{{" }} .Labels.hostname {{ "}}" }} {{ "{{" }}- end {{ "}}" }}"
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#mon-down"
|
||||
summary: "Monitor quorum is at risk"
|
||||
expr: |
|
||||
(
|
||||
(ceph_health_detail{name="MON_DOWN"} == 1) * on() (
|
||||
count(ceph_mon_quorum_status == 1) == bool (floor(count(ceph_mon_metadata) / 2) + 1)
|
||||
)
|
||||
) == 1
|
||||
for: "30s"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.3.1"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "CephMonDown"
|
||||
annotations:
|
||||
description: |
|
||||
{{ "{{" }} $down := query "count(ceph_mon_quorum_status == 0)" | first | value {{ "}}" }}{{ "{{" }} $s := "" {{ "}}" }}{{ "{{" }} if gt $down 1.0 {{ "}}" }}{{ "{{" }} $s = "s" {{ "}}" }}{{ "{{" }} end {{ "}}" }}You have {{ "{{" }} $down {{ "}}" }} monitor{{ "{{" }} $s {{ "}}" }} down. Quorum is still intact, but the loss of an additional monitor will make your cluster inoperable. The following monitors are down: {{ "{{" }}- range query "(ceph_mon_quorum_status == 0) + on(ceph_daemon) group_left(hostname) (ceph_mon_metadata * 0)" {{ "}}" }} - {{ "{{" }} .Labels.ceph_daemon {{ "}}" }} on {{ "{{" }} .Labels.hostname {{ "}}" }} {{ "{{" }}- end {{ "}}" }}
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#mon-down"
|
||||
summary: "One or more monitors down"
|
||||
expr: |
|
||||
count(ceph_mon_quorum_status == 0) <= (count(ceph_mon_metadata) - floor(count(ceph_mon_metadata) / 2) + 1)
|
||||
for: "30s"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "CephMonDiskspaceCritical"
|
||||
annotations:
|
||||
description: "The free space available to a monitor's store is critically low. You should increase the space available to the monitor(s). The default directory is /var/lib/ceph/mon-*/data/store.db on traditional deployments, and /var/lib/rook/mon-*/data/store.db on the mon pod's worker node for Rook. Look for old, rotated versions of *.log and MANIFEST*. Do NOT touch any *.sst files. Also check any other directories under /var/lib/rook and other directories on the same filesystem, often /var/log and /var/tmp are culprits. Your monitor hosts are; {{ "{{" }}- range query \"ceph_mon_metadata\"{{ "}}" }} - {{ "{{" }} .Labels.hostname {{ "}}" }} {{ "{{" }}- end {{ "}}" }}"
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#mon-disk-crit"
|
||||
summary: "Filesystem space on at least one monitor is critically low"
|
||||
expr: "ceph_health_detail{name=\"MON_DISK_CRIT\"} == 1"
|
||||
for: "1m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.3.2"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "CephMonDiskspaceLow"
|
||||
annotations:
|
||||
description: "The space available to a monitor's store is approaching full (>70% is the default). You should increase the space available to the monitor(s). The default directory is /var/lib/ceph/mon-*/data/store.db on traditional deployments, and /var/lib/rook/mon-*/data/store.db on the mon pod's worker node for Rook. Look for old, rotated versions of *.log and MANIFEST*. Do NOT touch any *.sst files. Also check any other directories under /var/lib/rook and other directories on the same filesystem, often /var/log and /var/tmp are culprits. Your monitor hosts are; {{ "{{" }}- range query \"ceph_mon_metadata\"{{ "}}" }} - {{ "{{" }} .Labels.hostname {{ "}}" }} {{ "{{" }}- end {{ "}}" }}"
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#mon-disk-low"
|
||||
summary: "Drive space on at least one monitor is approaching full"
|
||||
expr: "ceph_health_detail{name=\"MON_DISK_LOW\"} == 1"
|
||||
for: "5m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "CephMonClockSkew"
|
||||
annotations:
|
||||
description: "Ceph monitors rely on closely synchronized time to maintain quorum and cluster consistency. This event indicates that the time on at least one mon has drifted too far from the lead mon. Review cluster status with ceph -s. This will show which monitors are affected. Check the time sync status on each monitor host with 'ceph time-sync-status' and the state and peers of your ntpd or chrony daemon."
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#mon-clock-skew"
|
||||
summary: "Clock skew detected among monitors"
|
||||
expr: "ceph_health_detail{name=\"MON_CLOCK_SKEW\"} == 1"
|
||||
for: "1m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- name: "osd"
|
||||
rules:
|
||||
- alert: "CephOSDDownHigh"
|
||||
annotations:
|
||||
description: "{{ "{{" }} $value | humanize {{ "}}" }}% or {{ "{{" }} with query \"count(ceph_osd_up == 0)\" {{ "}}" }}{{ "{{" }} . | first | value {{ "}}" }}{{ "{{" }} end {{ "}}" }} of {{ "{{" }} with query \"count(ceph_osd_up)\" {{ "}}" }}{{ "{{" }} . | first | value {{ "}}" }}{{ "{{" }} end {{ "}}" }} OSDs are down (>= 10%). The following OSDs are down: {{ "{{" }}- range query \"(ceph_osd_up * on(ceph_daemon) group_left(hostname) ceph_osd_metadata) == 0\" {{ "}}" }} - {{ "{{" }} .Labels.ceph_daemon {{ "}}" }} on {{ "{{" }} .Labels.hostname {{ "}}" }} {{ "{{" }}- end {{ "}}" }}"
|
||||
summary: "More than 10% of OSDs are down"
|
||||
expr: "count(ceph_osd_up == 0) / count(ceph_osd_up) * 100 >= 10"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.4.1"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "CephOSDHostDown"
|
||||
annotations:
|
||||
description: "The following OSDs are down: {{ "{{" }}- range query \"(ceph_osd_up * on(ceph_daemon) group_left(hostname) ceph_osd_metadata) == 0\" {{ "}}" }} - {{ "{{" }} .Labels.hostname {{ "}}" }} : {{ "{{" }} .Labels.ceph_daemon {{ "}}" }} {{ "{{" }}- end {{ "}}" }}"
|
||||
summary: "An OSD host is offline"
|
||||
expr: "ceph_health_detail{name=\"OSD_HOST_DOWN\"} == 1"
|
||||
for: "5m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.4.8"
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "CephOSDDown"
|
||||
annotations:
|
||||
description: |
|
||||
{{ "{{" }} $num := query "count(ceph_osd_up == 0)" | first | value {{ "}}" }}{{ "{{" }} $s := "" {{ "}}" }}{{ "{{" }} if gt $num 1.0 {{ "}}" }}{{ "{{" }} $s = "s" {{ "}}" }}{{ "{{" }} end {{ "}}" }}{{ "{{" }} $num {{ "}}" }} OSD{{ "{{" }} $s {{ "}}" }} down for over 5mins. The following OSD{{ "{{" }} $s {{ "}}" }} {{ "{{" }} if eq $s "" {{ "}}" }}is{{ "{{" }} else {{ "}}" }}are{{ "{{" }} end {{ "}}" }} down: {{ "{{" }}- range query "(ceph_osd_up * on(ceph_daemon) group_left(hostname) ceph_osd_metadata) == 0"{{ "}}" }} - {{ "{{" }} .Labels.ceph_daemon {{ "}}" }} on {{ "{{" }} .Labels.hostname {{ "}}" }} {{ "{{" }}- end {{ "}}" }}
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#osd-down"
|
||||
summary: "An OSD has been marked down"
|
||||
expr: "ceph_health_detail{name=\"OSD_DOWN\"} == 1"
|
||||
for: "5m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.4.2"
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "CephOSDNearFull"
|
||||
annotations:
|
||||
description: "One or more OSDs have reached the NEARFULL threshold. Use 'ceph health detail' and 'ceph osd df' to identify the problem. To resolve, add capacity to the affected OSD's failure domain, restore down/out OSDs, or delete unwanted data."
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#osd-nearfull"
|
||||
summary: "OSD(s) running low on free space (NEARFULL)"
|
||||
expr: "ceph_health_detail{name=\"OSD_NEARFULL\"} == 1"
|
||||
for: "5m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.4.3"
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "CephOSDFull"
|
||||
annotations:
|
||||
description: "An OSD has reached the FULL threshold. Writes to pools that share the affected OSD will be blocked. Use 'ceph health detail' and 'ceph osd df' to identify the problem. To resolve, add capacity to the affected OSD's failure domain, restore down/out OSDs, or delete unwanted data."
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#osd-full"
|
||||
summary: "OSD full, writes blocked"
|
||||
expr: "ceph_health_detail{name=\"OSD_FULL\"} > 0"
|
||||
for: "1m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.4.6"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "CephOSDBackfillFull"
|
||||
annotations:
|
||||
description: "An OSD has reached the BACKFILL FULL threshold. This will prevent rebalance operations from completing. Use 'ceph health detail' and 'ceph osd df' to identify the problem. To resolve, add capacity to the affected OSD's failure domain, restore down/out OSDs, or delete unwanted data."
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#osd-backfillfull"
|
||||
summary: "OSD(s) too full for backfill operations"
|
||||
expr: "ceph_health_detail{name=\"OSD_BACKFILLFULL\"} > 0"
|
||||
for: "1m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "CephOSDTooManyRepairs"
|
||||
annotations:
|
||||
description: "Reads from an OSD have used a secondary PG to return data to the client, indicating a potential failing drive."
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#osd-too-many-repairs"
|
||||
summary: "OSD reports a high number of read errors"
|
||||
expr: "ceph_health_detail{name=\"OSD_TOO_MANY_REPAIRS\"} == 1"
|
||||
for: "30s"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "CephOSDTimeoutsPublicNetwork"
|
||||
annotations:
|
||||
description: "OSD heartbeats on the cluster's 'public' network (frontend) are running slow. Investigate the network for latency or loss issues. Use 'ceph health detail' to show the affected OSDs."
|
||||
summary: "Network issues delaying OSD heartbeats (public network)"
|
||||
expr: "ceph_health_detail{name=\"OSD_SLOW_PING_TIME_FRONT\"} == 1"
|
||||
for: "1m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "CephOSDTimeoutsClusterNetwork"
|
||||
annotations:
|
||||
description: "OSD heartbeats on the cluster's 'cluster' network (backend) are slow. Investigate the network for latency issues on this subnet. Use 'ceph health detail' to show the affected OSDs."
|
||||
summary: "Network issues delaying OSD heartbeats (cluster network)"
|
||||
expr: "ceph_health_detail{name=\"OSD_SLOW_PING_TIME_BACK\"} == 1"
|
||||
for: "1m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "CephOSDInternalDiskSizeMismatch"
|
||||
annotations:
|
||||
description: "One or more OSDs have an internal inconsistency between metadata and the size of the device. This could lead to the OSD(s) crashing in future. You should redeploy the affected OSDs."
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#bluestore-disk-size-mismatch"
|
||||
summary: "OSD size inconsistency error"
|
||||
expr: "ceph_health_detail{name=\"BLUESTORE_DISK_SIZE_MISMATCH\"} == 1"
|
||||
for: "1m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "CephDeviceFailurePredicted"
|
||||
annotations:
|
||||
description: "The device health module has determined that one or more devices will fail soon. To review device status use 'ceph device ls'. To show a specific device use 'ceph device info <dev id>'. Mark the OSD out so that data may migrate to other OSDs. Once the OSD has drained, destroy the OSD, replace the device, and redeploy the OSD."
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#id2"
|
||||
summary: "Device(s) predicted to fail soon"
|
||||
expr: "ceph_health_detail{name=\"DEVICE_HEALTH\"} == 1"
|
||||
for: "1m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "CephDeviceFailurePredictionTooHigh"
|
||||
annotations:
|
||||
description: "The device health module has determined that devices predicted to fail can not be remediated automatically, since too many OSDs would be removed from the cluster to ensure performance and availability. Prevent data integrity issues by adding new OSDs so that data may be relocated."
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#device-health-toomany"
|
||||
summary: "Too many devices are predicted to fail, unable to resolve"
|
||||
expr: "ceph_health_detail{name=\"DEVICE_HEALTH_TOOMANY\"} == 1"
|
||||
for: "1m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.4.7"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "CephDeviceFailureRelocationIncomplete"
|
||||
annotations:
|
||||
description: "The device health module has determined that one or more devices will fail soon, but the normal process of relocating the data on the device to other OSDs in the cluster is blocked. \nEnsure that the cluster has available free space. It may be necessary to add capacity to the cluster to allow data from the failing device to successfully migrate, or to enable the balancer."
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#device-health-in-use"
|
||||
summary: "Device failure is predicted, but unable to relocate data"
|
||||
expr: "ceph_health_detail{name=\"DEVICE_HEALTH_IN_USE\"} == 1"
|
||||
for: "1m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "CephOSDFlapping"
|
||||
annotations:
|
||||
description: "OSD {{ "{{" }} $labels.ceph_daemon {{ "}}" }} on {{ "{{" }} $labels.hostname {{ "}}" }} was marked down and back up {{ "{{" }} $value | humanize {{ "}}" }} times once a minute for 5 minutes. This may indicate a network issue (latency, packet loss, MTU mismatch) on the cluster network, or the public network if no cluster network is deployed. Check the network stats on the listed host(s)."
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/troubleshooting/troubleshooting-osd#flapping-osds"
|
||||
summary: "Network issues are causing OSDs to flap (mark each other down)"
|
||||
expr: "(rate(ceph_osd_up[5m]) * on(ceph_daemon) group_left(hostname) ceph_osd_metadata) * 60 > 1"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.4.4"
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "CephOSDReadErrors"
|
||||
annotations:
|
||||
description: "An OSD has encountered read errors, but the OSD has recovered by retrying the reads. This may indicate an issue with hardware or the kernel."
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#bluestore-spurious-read-errors"
|
||||
summary: "Device read errors detected"
|
||||
expr: "ceph_health_detail{name=\"BLUESTORE_SPURIOUS_READ_ERRORS\"} == 1"
|
||||
for: "30s"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "CephPGImbalance"
|
||||
annotations:
|
||||
description: "OSD {{ "{{" }} $labels.ceph_daemon {{ "}}" }} on {{ "{{" }} $labels.hostname {{ "}}" }} deviates by more than 30% from average PG count."
|
||||
summary: "PGs are not balanced across OSDs"
|
||||
expr: |
|
||||
abs(
|
||||
((ceph_osd_numpg > 0) - on (job) group_left avg(ceph_osd_numpg > 0) by (job)) /
|
||||
on (job) group_left avg(ceph_osd_numpg > 0) by (job)
|
||||
) * on (ceph_daemon) group_left(hostname) ceph_osd_metadata > 0.30
|
||||
for: "5m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.4.5"
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- name: "mds"
|
||||
rules:
|
||||
- alert: "CephFilesystemDamaged"
|
||||
annotations:
|
||||
description: "Filesystem metadata has been corrupted. Data may be inaccessible. Analyze metrics from the MDS daemon admin socket, or escalate to support."
|
||||
documentation: "https://docs.ceph.com/en/latest/cephfs/health-messages#cephfs-health-messages"
|
||||
summary: "CephFS filesystem is damaged."
|
||||
expr: "ceph_health_detail{name=\"MDS_DAMAGE\"} > 0"
|
||||
for: "1m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.5.1"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "CephFilesystemOffline"
|
||||
annotations:
|
||||
description: "All MDS ranks are unavailable. The MDS daemons managing metadata are down, rendering the filesystem offline."
|
||||
documentation: "https://docs.ceph.com/en/latest/cephfs/health-messages/#mds-all-down"
|
||||
summary: "CephFS filesystem is offline"
|
||||
expr: "ceph_health_detail{name=\"MDS_ALL_DOWN\"} > 0"
|
||||
for: "1m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.5.3"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "CephFilesystemDegraded"
|
||||
annotations:
|
||||
description: "One or more metadata daemons (MDS ranks) are failed or in a damaged state. At best the filesystem is partially available, at worst the filesystem is completely unusable."
|
||||
documentation: "https://docs.ceph.com/en/latest/cephfs/health-messages/#fs-degraded"
|
||||
summary: "CephFS filesystem is degraded"
|
||||
expr: "ceph_health_detail{name=\"FS_DEGRADED\"} > 0"
|
||||
for: "1m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.5.4"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "CephFilesystemMDSRanksLow"
|
||||
annotations:
|
||||
description: "The filesystem's 'max_mds' setting defines the number of MDS ranks in the filesystem. The current number of active MDS daemons is less than this value."
|
||||
documentation: "https://docs.ceph.com/en/latest/cephfs/health-messages/#mds-up-less-than-max"
|
||||
summary: "Ceph MDS daemon count is lower than configured"
|
||||
expr: "ceph_health_detail{name=\"MDS_UP_LESS_THAN_MAX\"} > 0"
|
||||
for: "1m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "CephFilesystemInsufficientStandby"
|
||||
annotations:
|
||||
description: "The minimum number of standby daemons required by standby_count_wanted is less than the current number of standby daemons. Adjust the standby count or increase the number of MDS daemons."
|
||||
documentation: "https://docs.ceph.com/en/latest/cephfs/health-messages/#mds-insufficient-standby"
|
||||
summary: "Ceph filesystem standby daemons too few"
|
||||
expr: "ceph_health_detail{name=\"MDS_INSUFFICIENT_STANDBY\"} > 0"
|
||||
for: "1m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "CephFilesystemFailureNoStandby"
|
||||
annotations:
|
||||
description: "An MDS daemon has failed, leaving only one active rank and no available standby. Investigate the cause of the failure or add a standby MDS."
|
||||
documentation: "https://docs.ceph.com/en/latest/cephfs/health-messages/#fs-with-failed-mds"
|
||||
summary: "MDS daemon failed, no further standby available"
|
||||
expr: "ceph_health_detail{name=\"FS_WITH_FAILED_MDS\"} > 0"
|
||||
for: "1m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.5.5"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "CephFilesystemReadOnly"
|
||||
annotations:
|
||||
description: "The filesystem has switched to READ ONLY due to an unexpected error when writing to the metadata pool. Either analyze the output from the MDS daemon admin socket, or escalate to support."
|
||||
documentation: "https://docs.ceph.com/en/latest/cephfs/health-messages#cephfs-health-messages"
|
||||
summary: "CephFS filesystem in read only mode due to write error(s)"
|
||||
expr: "ceph_health_detail{name=\"MDS_HEALTH_READ_ONLY\"} > 0"
|
||||
for: "1m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.5.2"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- name: "mgr"
|
||||
rules:
|
||||
- alert: "CephMgrModuleCrash"
|
||||
annotations:
|
||||
description: "One or more mgr modules have crashed and have yet to be acknowledged by an administrator. A crashed module may impact functionality within the cluster. Use the 'ceph crash' command to determine which module has failed, and archive it to acknowledge the failure."
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#recent-mgr-module-crash"
|
||||
summary: "A manager module has recently crashed"
|
||||
expr: "ceph_health_detail{name=\"RECENT_MGR_MODULE_CRASH\"} == 1"
|
||||
for: "5m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.6.1"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "CephMgrPrometheusModuleInactive"
|
||||
annotations:
|
||||
description: "The mgr/prometheus module at {{ "{{" }} $labels.instance {{ "}}" }} is unreachable. This could mean that the module has been disabled or the mgr daemon itself is down. Without the mgr/prometheus module metrics and alerts will no longer function. Open a shell to an admin node or toolbox pod and use 'ceph -s' to to determine whether the mgr is active. If the mgr is not active, restart it, otherwise you can determine module status with 'ceph mgr module ls'. If it is not listed as enabled, enable it with 'ceph mgr module enable prometheus'."
|
||||
summary: "The mgr/prometheus module is not available"
|
||||
expr: "up{job=\"ceph\"} == 0"
|
||||
for: "1m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.6.2"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- name: "pgs"
|
||||
rules:
|
||||
- alert: "CephPGsInactive"
|
||||
annotations:
|
||||
description: "{{ "{{" }} $value {{ "}}" }} PGs have been inactive for more than 5 minutes in pool {{ "{{" }} $labels.name {{ "}}" }}. Inactive placement groups are not able to serve read/write requests."
|
||||
summary: "One or more placement groups are inactive"
|
||||
expr: "ceph_pool_metadata * on(pool_id,instance) group_left() (ceph_pg_total - ceph_pg_active) > 0"
|
||||
for: "5m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.7.1"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "CephPGsUnclean"
|
||||
annotations:
|
||||
description: "{{ "{{" }} $value {{ "}}" }} PGs have been unclean for more than 15 minutes in pool {{ "{{" }} $labels.name {{ "}}" }}. Unclean PGs have not recovered from a previous failure."
|
||||
summary: "One or more placement groups are marked unclean"
|
||||
expr: "ceph_pool_metadata * on(pool_id,instance) group_left() (ceph_pg_total - ceph_pg_clean) > 0"
|
||||
for: "15m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.7.2"
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "CephPGsDamaged"
|
||||
annotations:
|
||||
description: "During data consistency checks (scrub), at least one PG has been flagged as being damaged or inconsistent. Check to see which PG is affected, and attempt a manual repair if necessary. To list problematic placement groups, use 'rados list-inconsistent-pg <pool>'. To repair PGs use the 'ceph pg repair <pg_num>' command."
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#pg-damaged"
|
||||
summary: "Placement group damaged, manual intervention needed"
|
||||
expr: "ceph_health_detail{name=~\"PG_DAMAGED|OSD_SCRUB_ERRORS\"} == 1"
|
||||
for: "5m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.7.4"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "CephPGRecoveryAtRisk"
|
||||
annotations:
|
||||
description: "Data redundancy is at risk since one or more OSDs are at or above the 'full' threshold. Add more capacity to the cluster, restore down/out OSDs, or delete unwanted data."
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#pg-recovery-full"
|
||||
summary: "OSDs are too full for recovery"
|
||||
expr: "ceph_health_detail{name=\"PG_RECOVERY_FULL\"} == 1"
|
||||
for: "1m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.7.5"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "CephPGUnavailableBlockingIO"
|
||||
annotations:
|
||||
description: "Data availability is reduced, impacting the cluster's ability to service I/O. One or more placement groups (PGs) are in a state that blocks I/O."
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#pg-availability"
|
||||
summary: "PG is unavailable, blocking I/O"
|
||||
expr: "((ceph_health_detail{name=\"PG_AVAILABILITY\"} == 1) - scalar(ceph_health_detail{name=\"OSD_DOWN\"})) == 1"
|
||||
for: "1m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.7.3"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "CephPGBackfillAtRisk"
|
||||
annotations:
|
||||
description: "Data redundancy may be at risk due to lack of free space within the cluster. One or more OSDs have reached the 'backfillfull' threshold. Add more capacity, or delete unwanted data."
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#pg-backfill-full"
|
||||
summary: "Backfill operations are blocked due to lack of free space"
|
||||
expr: "ceph_health_detail{name=\"PG_BACKFILL_FULL\"} == 1"
|
||||
for: "1m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.7.6"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "CephPGNotScrubbed"
|
||||
annotations:
|
||||
description: "One or more PGs have not been scrubbed recently. Scrubs check metadata integrity, protecting against bit-rot. They check that metadata is consistent across data replicas. When PGs miss their scrub interval, it may indicate that the scrub window is too small, or PGs were not in a 'clean' state during the scrub window. You can manually initiate a scrub with: ceph pg scrub <pgid>"
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#pg-not-scrubbed"
|
||||
summary: "Placement group(s) have not been scrubbed"
|
||||
expr: "ceph_health_detail{name=\"PG_NOT_SCRUBBED\"} == 1"
|
||||
for: "5m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "CephPGsHighPerOSD"
|
||||
annotations:
|
||||
description: "The number of placement groups per OSD is too high (exceeds the mon_max_pg_per_osd setting).\n Check that the pg_autoscaler has not been disabled for any pools with 'ceph osd pool autoscale-status', and that the profile selected is appropriate. You may also adjust the target_size_ratio of a pool to guide the autoscaler based on the expected relative size of the pool ('ceph osd pool set cephfs.cephfs.meta target_size_ratio .1') or set the pg_autoscaler mode to 'warn' and adjust pg_num appropriately for one or more pools."
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks/#too-many-pgs"
|
||||
summary: "Placement groups per OSD is too high"
|
||||
expr: "ceph_health_detail{name=\"TOO_MANY_PGS\"} == 1"
|
||||
for: "1m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "CephPGNotDeepScrubbed"
|
||||
annotations:
|
||||
description: "One or more PGs have not been deep scrubbed recently. Deep scrubs protect against bit-rot. They compare data replicas to ensure consistency. When PGs miss their deep scrub interval, it may indicate that the window is too small or PGs were not in a 'clean' state during the deep-scrub window."
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#pg-not-deep-scrubbed"
|
||||
summary: "Placement group(s) have not been deep scrubbed"
|
||||
expr: "ceph_health_detail{name=\"PG_NOT_DEEP_SCRUBBED\"} == 1"
|
||||
for: "5m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- name: "nodes"
|
||||
rules:
|
||||
- alert: "CephNodeRootFilesystemFull"
|
||||
annotations:
|
||||
description: "Root volume is dangerously full: {{ "{{" }} $value | humanize {{ "}}" }}% free."
|
||||
summary: "Root filesystem is dangerously full"
|
||||
expr: "node_filesystem_avail_bytes{mountpoint=\"/\"} / node_filesystem_size_bytes{mountpoint=\"/\"} * 100 < 5"
|
||||
for: "5m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.8.1"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- name: "pools"
|
||||
rules:
|
||||
- alert: "CephPoolGrowthWarning"
|
||||
annotations:
|
||||
description: "Pool '{{ "{{" }} $labels.name {{ "}}" }}' will be full in less than 5 days assuming the average fill-up rate of the past 48 hours."
|
||||
summary: "Pool growth rate may soon exceed capacity"
|
||||
expr: "(predict_linear(ceph_pool_percent_used[2d], 3600 * 24 * 5) * on(pool_id, instance, pod) group_right() ceph_pool_metadata) >= 95"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.9.2"
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "CephPoolBackfillFull"
|
||||
annotations:
|
||||
description: "A pool is approaching the near full threshold, which will prevent recovery/backfill operations from completing. Consider adding more capacity."
|
||||
summary: "Free space in a pool is too low for recovery/backfill"
|
||||
expr: "ceph_health_detail{name=\"POOL_BACKFILLFULL\"} > 0"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "CephPoolFull"
|
||||
annotations:
|
||||
description: "A pool has reached its MAX quota, or OSDs supporting the pool have reached the FULL threshold. Until this is resolved, writes to the pool will be blocked. Pool Breakdown (top 5) {{ "{{" }}- range query \"topk(5, sort_desc(ceph_pool_percent_used * on(pool_id) group_right ceph_pool_metadata))\" {{ "}}" }} - {{ "{{" }} .Labels.name {{ "}}" }} at {{ "{{" }} .Value {{ "}}" }}% {{ "{{" }}- end {{ "}}" }} Increase the pool's quota, or add capacity to the cluster first then increase the pool's quota (e.g. ceph osd pool set quota <pool_name> max_bytes <bytes>)"
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#pool-full"
|
||||
summary: "Pool is full - writes are blocked"
|
||||
expr: "ceph_health_detail{name=\"POOL_FULL\"} > 0"
|
||||
for: "1m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.9.1"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "CephPoolNearFull"
|
||||
annotations:
|
||||
description: "A pool has exceeded the warning (percent full) threshold, or OSDs supporting the pool have reached the NEARFULL threshold. Writes may continue, but you are at risk of the pool going read-only if more capacity isn't made available. Determine the affected pool with 'ceph df detail', looking at QUOTA BYTES and STORED. Increase the pool's quota, or add capacity to the cluster first then increase the pool's quota (e.g. ceph osd pool set quota <pool_name> max_bytes <bytes>). Also ensure that the balancer is active."
|
||||
summary: "One or more Ceph pools are nearly full"
|
||||
expr: "ceph_health_detail{name=\"POOL_NEAR_FULL\"} > 0"
|
||||
for: "5m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- name: "healthchecks"
|
||||
rules:
|
||||
- alert: "CephSlowOps"
|
||||
annotations:
|
||||
description: "{{ "{{" }} $value {{ "}}" }} OSD requests are taking too long to process (osd_op_complaint_time exceeded)"
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#slow-ops"
|
||||
summary: "OSD operations are slow to complete"
|
||||
expr: "ceph_healthcheck_slow_ops > 0"
|
||||
for: "30s"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "CephDaemonSlowOps"
|
||||
annotations:
|
||||
description: "{{ "{{" }} $labels.ceph_daemon {{ "}}" }} operations are taking too long to process (complaint time exceeded)"
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#slow-ops"
|
||||
summary: "{{ "{{" }} $labels.ceph_daemon {{ "}}" }} operations are slow to complete"
|
||||
expr: "ceph_daemon_health_metrics{type=\"SLOW_OPS\"} > 0"
|
||||
for: "30s"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- name: "hardware"
|
||||
rules:
|
||||
- alert: "HardwareStorageError"
|
||||
annotations:
|
||||
description: "Some storage devices are in error. Check `ceph health detail`."
|
||||
summary: "Storage devices error(s) detected"
|
||||
expr: "ceph_health_detail{name=\"HARDWARE_STORAGE\"} > 0"
|
||||
for: "30s"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.13.1"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "HardwareMemoryError"
|
||||
annotations:
|
||||
description: "DIMM error(s) detected. Check `ceph health detail`."
|
||||
summary: "DIMM error(s) detected"
|
||||
expr: "ceph_health_detail{name=\"HARDWARE_MEMORY\"} > 0"
|
||||
for: "30s"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.13.2"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "HardwareProcessorError"
|
||||
annotations:
|
||||
description: "Processor error(s) detected. Check `ceph health detail`."
|
||||
summary: "Processor error(s) detected"
|
||||
expr: "ceph_health_detail{name=\"HARDWARE_PROCESSOR\"} > 0"
|
||||
for: "30s"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.13.3"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "HardwareNetworkError"
|
||||
annotations:
|
||||
description: "Network error(s) detected. Check `ceph health detail`."
|
||||
summary: "Network error(s) detected"
|
||||
expr: "ceph_health_detail{name=\"HARDWARE_NETWORK\"} > 0"
|
||||
for: "30s"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.13.4"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "HardwarePowerError"
|
||||
annotations:
|
||||
description: "Power supply error(s) detected. Check `ceph health detail`."
|
||||
summary: "Power supply error(s) detected"
|
||||
expr: "ceph_health_detail{name=\"HARDWARE_POWER\"} > 0"
|
||||
for: "30s"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.13.5"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "HardwareFanError"
|
||||
annotations:
|
||||
description: "Fan error(s) detected. Check `ceph health detail`."
|
||||
summary: "Fan error(s) detected"
|
||||
expr: "ceph_health_detail{name=\"HARDWARE_FANS\"} > 0"
|
||||
for: "30s"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.13.6"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- name: "PrometheusServer"
|
||||
rules:
|
||||
- alert: "PrometheusJobMissing"
|
||||
annotations:
|
||||
description: "The prometheus job that scrapes from Ceph MGR is no longer defined, this will effectively mean you'll have no metrics or alerts for the cluster. Please review the job definitions in the prometheus.yml file of the prometheus instance."
|
||||
summary: "The scrape job for Ceph MGR is missing from Prometheus"
|
||||
expr: "absent(up{job=\"rook-ceph-mgr\"})"
|
||||
for: "30s"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.12.1"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "PrometheusJobExporterMissing"
|
||||
annotations:
|
||||
description: "The prometheus job that scrapes from Ceph Exporter is no longer defined, this will effectively mean you'll have no metrics or alerts for the cluster. Please review the job definitions in the prometheus.yml file of the prometheus instance."
|
||||
summary: "The scrape job for Ceph Exporter is missing from Prometheus"
|
||||
expr: "sum(absent(up{job=\"rook-ceph-exporter\"})) and sum(ceph_osd_metadata{ceph_version=~\"^ceph version (1[89]|[2-9][0-9]).*\"}) > 0"
|
||||
for: "30s"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.12.1"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- name: "rados"
|
||||
rules:
|
||||
- alert: "CephObjectMissing"
|
||||
annotations:
|
||||
description: "The latest version of a RADOS object can not be found, even though all OSDs are up. I/O requests for this object from clients will block (hang). Resolving this issue may require the object to be rolled back to a prior version manually, and manually verified."
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#object-unfound"
|
||||
summary: "Object(s) marked UNFOUND"
|
||||
expr: "(ceph_health_detail{name=\"OBJECT_UNFOUND\"} == 1) * on() (count(ceph_osd_up == 1) == bool count(ceph_osd_metadata)) == 1"
|
||||
for: "30s"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.10.1"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- name: "generic"
|
||||
rules:
|
||||
- alert: "CephDaemonCrash"
|
||||
annotations:
|
||||
description: "One or more daemons have crashed recently, and need to be acknowledged. This notification ensures that software crashes do not go unseen. To acknowledge a crash, use the 'ceph crash archive <id>' command."
|
||||
documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks/#recent-crash"
|
||||
summary: "One or more Ceph daemons have crashed, and are pending acknowledgement"
|
||||
expr: "ceph_health_detail{name=\"RECENT_CRASH\"} == 1"
|
||||
for: "1m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.1.2"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- name: "rbdmirror"
|
||||
rules:
|
||||
- alert: "CephRBDMirrorImagesPerDaemonHigh"
|
||||
annotations:
|
||||
description: "Number of image replications per daemon is not supposed to go beyond threshold 100"
|
||||
summary: "Number of image replications are now above 100"
|
||||
expr: "sum by (ceph_daemon, namespace) (ceph_rbd_mirror_snapshot_image_snapshots) > 100"
|
||||
for: "1m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.10.2"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "CephRBDMirrorImagesNotInSync"
|
||||
annotations:
|
||||
description: "Both local and remote RBD mirror images should be in sync."
|
||||
summary: "Some of the RBD mirror images are not in sync with the remote counter parts."
|
||||
expr: "sum by (ceph_daemon, image, namespace, pool) (topk by (ceph_daemon, image, namespace, pool) (1, ceph_rbd_mirror_snapshot_image_local_timestamp) - topk by (ceph_daemon, image, namespace, pool) (1, ceph_rbd_mirror_snapshot_image_remote_timestamp)) != 0"
|
||||
for: "1m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.10.3"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "CephRBDMirrorImagesNotInSyncVeryHigh"
|
||||
annotations:
|
||||
description: "More than 10% of the images have synchronization problems"
|
||||
summary: "Number of unsynchronized images are very high."
|
||||
expr: "count by (ceph_daemon) ((topk by (ceph_daemon, image, namespace, pool) (1, ceph_rbd_mirror_snapshot_image_local_timestamp) - topk by (ceph_daemon, image, namespace, pool) (1, ceph_rbd_mirror_snapshot_image_remote_timestamp)) != 0) > (sum by (ceph_daemon) (ceph_rbd_mirror_snapshot_snapshots)*.1)"
|
||||
for: "1m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.10.4"
|
||||
severity: "critical"
|
||||
type: "ceph_default"
|
||||
- alert: "CephRBDMirrorImageTransferBandwidthHigh"
|
||||
annotations:
|
||||
description: "Detected a heavy increase in bandwidth for rbd replications (over 80%) in the last 30 min. This might not be a problem, but it is good to review the number of images being replicated simultaneously"
|
||||
summary: "The replication network usage has been increased over 80% in the last 30 minutes. Review the number of images being replicated. This alert will be cleaned automatically after 30 minutes"
|
||||
expr: "rate(ceph_rbd_mirror_journal_replay_bytes[30m]) > 0.80"
|
||||
for: "1m"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.10.5"
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- name: "nvmeof"
|
||||
rules:
|
||||
- alert: "NVMeoFSubsystemNamespaceLimit"
|
||||
annotations:
|
||||
description: "Subsystems have a max namespace limit defined at creation time. This alert means that no more namespaces can be added to {{ "{{" }} $labels.nqn {{ "}}" }}"
|
||||
summary: "{{ "{{" }} $labels.nqn {{ "}}" }} subsystem has reached its maximum number of namespaces "
|
||||
expr: "(count by(nqn) (ceph_nvmeof_subsystem_namespace_metadata)) >= ceph_nvmeof_subsystem_namespace_limit"
|
||||
for: "1m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "NVMeoFTooManyGateways"
|
||||
annotations:
|
||||
description: "You may create many gateways, but 4 is the tested limit"
|
||||
summary: "Max supported gateways exceeded "
|
||||
expr: "count(ceph_nvmeof_gateway_info) > 4.00"
|
||||
for: "1m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "NVMeoFMaxGatewayGroupSize"
|
||||
annotations:
|
||||
description: "You may create many gateways in a gateway group, but 2 is the tested limit"
|
||||
summary: "Max gateways within a gateway group ({{ "{{" }} $labels.group {{ "}}" }}) exceeded "
|
||||
expr: "count by(group) (ceph_nvmeof_gateway_info) > 2.00"
|
||||
for: "1m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "NVMeoFSingleGatewayGroup"
|
||||
annotations:
|
||||
description: "Although a single member gateway group is valid, it should only be used for test purposes"
|
||||
summary: "The gateway group {{ "{{" }} $labels.group {{ "}}" }} consists of a single gateway - HA is not possible "
|
||||
expr: "count by(group) (ceph_nvmeof_gateway_info) == 1"
|
||||
for: "5m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "NVMeoFHighGatewayCPU"
|
||||
annotations:
|
||||
description: "Typically, high CPU may indicate degraded performance. Consider increasing the number of reactor cores"
|
||||
summary: "CPU used by {{ "{{" }} $labels.instance {{ "}}" }} NVMe-oF Gateway is high "
|
||||
expr: "label_replace(avg by(instance) (rate(ceph_nvmeof_reactor_seconds_total{mode=\"busy\"}[1m])),\"instance\",\"$1\",\"instance\",\"(.*):.*\") > 80.00"
|
||||
for: "10m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "NVMeoFGatewayOpenSecurity"
|
||||
annotations:
|
||||
description: "It is good practice to ensure subsystems use host security to reduce the risk of unexpected data loss"
|
||||
summary: "Subsystem {{ "{{" }} $labels.nqn {{ "}}" }} has been defined without host level security "
|
||||
expr: "ceph_nvmeof_subsystem_metadata{allow_any_host=\"yes\"}"
|
||||
for: "5m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "NVMeoFTooManySubsystems"
|
||||
annotations:
|
||||
description: "Although you may continue to create subsystems in {{ "{{" }} $labels.gateway_host {{ "}}" }}, the configuration may not be supported"
|
||||
summary: "The number of subsystems defined to the gateway exceeds supported values "
|
||||
expr: "count by(gateway_host) (label_replace(ceph_nvmeof_subsystem_metadata,\"gateway_host\",\"$1\",\"instance\",\"(.*):.*\")) > 16.00"
|
||||
for: "1m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "NVMeoFVersionMismatch"
|
||||
annotations:
|
||||
description: "This may indicate an issue with deployment. Check cephadm logs"
|
||||
summary: "The cluster has different NVMe-oF gateway releases active "
|
||||
expr: "count(count by(version) (ceph_nvmeof_gateway_info)) > 1"
|
||||
for: "1h"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "NVMeoFHighClientCount"
|
||||
annotations:
|
||||
description: "The supported limit for clients connecting to a subsystem is 32"
|
||||
summary: "The number of clients connected to {{ "{{" }} $labels.nqn {{ "}}" }} is too high "
|
||||
expr: "ceph_nvmeof_subsystem_host_count > 32.00"
|
||||
for: "1m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "NVMeoFHighHostCPU"
|
||||
annotations:
|
||||
description: "High CPU on a gateway host can lead to CPU contention and performance degradation"
|
||||
summary: "The CPU is high ({{ "{{" }} $value {{ "}}" }}%) on NVMeoF Gateway host ({{ "{{" }} $labels.host {{ "}}" }}) "
|
||||
expr: "100-((100*(avg by(host) (label_replace(rate(node_cpu_seconds_total{mode=\"idle\"}[5m]),\"host\",\"$1\",\"instance\",\"(.*):.*\")) * on(host) group_right label_replace(ceph_nvmeof_gateway_info,\"host\",\"$1\",\"instance\",\"(.*):.*\")))) >= 80.00"
|
||||
for: "10m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "NVMeoFInterfaceDown"
|
||||
annotations:
|
||||
description: "A NIC used by one or more subsystems is in a down state"
|
||||
summary: "Network interface {{ "{{" }} $labels.device {{ "}}" }} is down "
|
||||
expr: "ceph_nvmeof_subsystem_listener_iface_info{operstate=\"down\"}"
|
||||
for: "30s"
|
||||
labels:
|
||||
oid: "1.3.6.1.4.1.50495.1.2.1.14.1"
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "NVMeoFInterfaceDuplex"
|
||||
annotations:
|
||||
description: "Until this is resolved, performance from the gateway will be degraded"
|
||||
summary: "Network interface {{ "{{" }} $labels.device {{ "}}" }} is not running in full duplex mode "
|
||||
expr: "ceph_nvmeof_subsystem_listener_iface_info{duplex!=\"full\"}"
|
||||
for: "30s"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "NVMeoFHighReadLatency"
|
||||
annotations:
|
||||
description: "High latencies may indicate a constraint within the cluster e.g. CPU, network. Please investigate"
|
||||
summary: "The average read latency over the last 5 mins has reached 10 ms or more on {{ "{{" }} $labels.gateway {{ "}}" }}"
|
||||
expr: "label_replace((avg by(instance) ((rate(ceph_nvmeof_bdev_read_seconds_total[1m]) / rate(ceph_nvmeof_bdev_reads_completed_total[1m])))),\"gateway\",\"$1\",\"instance\",\"(.*):.*\") > 0.01"
|
||||
for: "5m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
- alert: "NVMeoFHighWriteLatency"
|
||||
annotations:
|
||||
description: "High latencies may indicate a constraint within the cluster e.g. CPU, network. Please investigate"
|
||||
summary: "The average write latency over the last 5 mins has reached 20 ms or more on {{ "{{" }} $labels.gateway {{ "}}" }}"
|
||||
expr: "label_replace((avg by(instance) ((rate(ceph_nvmeof_bdev_write_seconds_total[5m]) / rate(ceph_nvmeof_bdev_writes_completed_total[5m])))),\"gateway\",\"$1\",\"instance\",\"(.*):.*\") > 0.02"
|
||||
for: "5m"
|
||||
labels:
|
||||
severity: "warning"
|
||||
type: "ceph_default"
|
||||
{{- end }}
|
||||
@@ -1,2 +1,12 @@
|
||||
monitoring:
|
||||
enabled: true
|
||||
ceph-csi-drivers:
|
||||
drivers:
|
||||
rbd:
|
||||
name: rook-ceph.rbd.csi.ceph.com
|
||||
cephfs:
|
||||
name: rook-ceph.cephfs.csi.ceph.com
|
||||
nvmeof:
|
||||
enabled: false
|
||||
nfs:
|
||||
enabled: false
|
||||
@@ -24,5 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: traefik
|
||||
version: 37.4.0
|
||||
version: 41.0.2
|
||||
repository: https://traefik.github.io/charts
|
||||
@@ -4,6 +4,7 @@ traefik:
|
||||
- --entryPoints.websecure.transport.respondingTimeouts.readTimeout=0
|
||||
ports:
|
||||
web:
|
||||
http:
|
||||
redirections:
|
||||
entryPoint:
|
||||
to: websecure
|
||||
@@ -14,19 +15,29 @@ traefik:
|
||||
exposedPort: 22
|
||||
expose:
|
||||
default: true
|
||||
tls:
|
||||
passthrough: true
|
||||
metrics:
|
||||
prometheus:
|
||||
service:
|
||||
enabled: true
|
||||
serviceMonitor:
|
||||
enabled: true
|
||||
prometheusRule:
|
||||
enabled: true
|
||||
rules:
|
||||
- alert: TraefikDown
|
||||
expr: up{job="traefik"} == 0
|
||||
for: 5m
|
||||
labels:
|
||||
metrics_enabled: "true"
|
||||
context: traefik
|
||||
severity: critical
|
||||
annotations:
|
||||
summary: "Traefik Down"
|
||||
description: "{{ $labels.pod }} on {{ $labels.nodename }} is down"
|
||||
deployment:
|
||||
kind: DaemonSet
|
||||
additionalContainers:
|
||||
- name: cloudflared
|
||||
image: cloudflare/cloudflared:2025.11.1
|
||||
image: cloudflare/cloudflared:2026.7.3
|
||||
command:
|
||||
- cloudflared
|
||||
- tunnel
|
||||
@@ -58,10 +69,12 @@ traefik:
|
||||
dashboard:
|
||||
enabled: true
|
||||
providers:
|
||||
kubernetesGateway:
|
||||
enabled: true
|
||||
file:
|
||||
enabled: true
|
||||
watch: true
|
||||
content: |
|
||||
content:
|
||||
http:
|
||||
middlewares:
|
||||
cloudflarewarp:
|
||||
@@ -69,6 +82,19 @@ traefik:
|
||||
traefik-real-ip:
|
||||
excludednets:
|
||||
- "1.1.1.1/24"
|
||||
routers:
|
||||
dispatcharr:
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: dispatcharr
|
||||
tls:
|
||||
options: default
|
||||
rule: 'Host(`dispatcharr.dubyatp.xyz`) && PathPrefix(`/`)'
|
||||
services:
|
||||
dispatcharr:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: http://10.105.15.20:9191
|
||||
service:
|
||||
spec:
|
||||
externalTrafficPolicy: Local
|
||||
@@ -105,3 +131,26 @@ traefik:
|
||||
data:
|
||||
tls.crt: ""
|
||||
tls.key: ""
|
||||
- apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: traefik-local
|
||||
spec:
|
||||
sessionAffinity: ClientIP
|
||||
sessionAffinityConfig:
|
||||
clientIP:
|
||||
timeoutSeconds: 3600
|
||||
selector:
|
||||
app.kubernetes.io/name: traefik
|
||||
app.kubernetes.io/instance: traefik-traefik
|
||||
ports:
|
||||
- name: gitssh
|
||||
port: 22
|
||||
targetPort: gitssh
|
||||
- name: web
|
||||
port: 80
|
||||
targetPort: web
|
||||
- name: websecure
|
||||
port: 443
|
||||
targetPort: websecure
|
||||
type: ClusterIP
|
||||
@@ -24,5 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: velero
|
||||
version: 11.2.0
|
||||
version: 12.1.0
|
||||
repository: https://vmware-tanzu.github.io/helm-charts
|
||||
@@ -2,8 +2,48 @@ velero:
|
||||
backupsEnabled: true
|
||||
snapshotsEnabled: false
|
||||
metrics:
|
||||
serviceMonitor:
|
||||
enabled: true
|
||||
prometheusRule:
|
||||
enabled: true
|
||||
spec:
|
||||
- alert: VeleroBackupFailed
|
||||
annotations:
|
||||
message: Velero backup {{ $labels.schedule }} has failed
|
||||
expr: |-
|
||||
velero_backup_last_status{schedule!=""} != 1
|
||||
for: 15m
|
||||
labels:
|
||||
metrics_enabled: "true"
|
||||
severity: warning
|
||||
- alert: VeleroBackupFailing
|
||||
annotations:
|
||||
message: Velero backup {{ $labels.schedule }} has been failing for the last 12h
|
||||
expr: |-
|
||||
velero_backup_last_status{schedule!=""} != 1
|
||||
for: 12h
|
||||
labels:
|
||||
severity: critical
|
||||
- alert: VeleroNoNewBackup
|
||||
annotations:
|
||||
message: Velero backup {{ $labels.schedule }} has not run successfully in the last 25h
|
||||
expr: |-
|
||||
(
|
||||
(time() - velero_backup_last_successful_timestamp{schedule!=""}) >bool (25 * 3600)
|
||||
or
|
||||
absent(velero_backup_last_successful_timestamp{schedule!=""})
|
||||
) == 1
|
||||
for: 1h
|
||||
labels:
|
||||
severity: critical
|
||||
- alert: VeleroBackupPartialFailures
|
||||
annotations:
|
||||
message: Velero backup {{ $labels.schedule }} has {{ $value | humanizePercentage }} partialy failed backups
|
||||
expr: |-
|
||||
rate(velero_backup_partial_failure_total{schedule!=""}[25m])
|
||||
/ rate(velero_backup_attempt_total{schedule!=""}[25m]) > 0.5
|
||||
for: 15m
|
||||
labels:
|
||||
severity: warning
|
||||
configuration:
|
||||
backupStorageLocation:
|
||||
- name: weyma-truenas
|
||||
@@ -19,7 +59,7 @@ velero:
|
||||
insecureSkipTLSVerify: "true"
|
||||
initContainers:
|
||||
- name: velero-plugin-for-aws
|
||||
image: velero/velero-plugin-for-aws:v1.13.1
|
||||
image: velero/velero-plugin-for-aws:v1.14.2
|
||||
imagePullPolicy: IfNotPresent
|
||||
volumeMounts:
|
||||
- mountPath: /target
|
||||
|
||||
@@ -49,7 +49,7 @@ spec:
|
||||
cpu: "100m"
|
||||
memory: "100Mi"
|
||||
limits:
|
||||
cpu: "100m"
|
||||
cpu: "300m"
|
||||
memory: "200Mi"
|
||||
securityContext:
|
||||
privileged: true
|
||||
|
||||
Reference in New Issue
Block a user