Skip to content

Commit

Permalink
feat: dev environment for monitoring setup (#231)
Browse files Browse the repository at this point in the history
  • Loading branch information
bo0tzz authored Oct 11, 2024
1 parent 3a83a05 commit d007928
Show file tree
Hide file tree
Showing 17 changed files with 320 additions and 0 deletions.
1 change: 1 addition & 0 deletions kubernetes/apps/authentication/dexidp/app/helmrelease.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -104,6 +104,7 @@ spec:
secretEnv: GRAFANA_OAUTH_CLIENT_SECRET
redirectURIs:
- "https://monitoring.immich.cloud/login/generic_oauth"
- "https://monitoring.dev.immich.cloud/login/generic_oauth"

resources:
requests:
Expand Down
15 changes: 15 additions & 0 deletions kubernetes/apps/monitoring-dev/grafana/app/datasource.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
apiVersion: grafana.integreatly.org/v1beta1
kind: GrafanaDatasource
metadata:
name: victoria-metrics
namespace: monitoring-dev
spec:
instanceSelector:
matchLabels:
dashboards: "grafana"
datasource:
name: victoria-metrics
type: prometheus
access: proxy
url: http://vmsingle-vmetrics:8429
isDefault: true
63 changes: 63 additions & 0 deletions kubernetes/apps/monitoring-dev/grafana/app/grafana.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,63 @@
apiVersion: grafana.integreatly.org/v1beta1
kind: Grafana
metadata:
name: grafana
namespace: monitoring-dev
labels:
dashboards: "grafana"
spec:
config:
server:
root_url: https://monitoring.dev.immich.cloud/
auth.generic_oauth:
enabled: "true"
client_id: grafana
client_secret: ${GRAFANA_OAUTH_CLIENT_SECRET}
scopes: openid email profile groups offline_access
auth_url: https://auth.immich.cloud/auth
token_url: https://auth.immich.cloud/token
api_url: https://auth.immich.cloud/userinfo
role_attribute_path: contains(groups[*], 'immich-app:Admins') && 'GrafanaAdmin' || 'Viewer'
allow_assign_grafana_admin: "true"
auto_login: "true"
persistentVolumeClaim:
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 20Gi
deployment:
spec:
template:
metadata:
labels:
dashboards: grafana
spec:
securityContext:
fsGroup: 472
volumes:
- name: grafana-data
persistentVolumeClaim:
claimName: grafana-pvc
ingress:
metadata:
annotations:
cert-manager.io/cluster-issuer: letsencrypt-production
spec:
ingressClassName: nginx
rules:
- host: &host monitoring.dev.immich.cloud
http:
paths:
- backend:
service:
name: grafana-service
port:
number: 3000
path: /
pathType: Prefix
tls:
- hosts:
- *host
secretName: grafana-tls-secret
6 changes: 6 additions & 0 deletions kubernetes/apps/monitoring-dev/grafana/app/kustomization.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./datasource.yaml
- ./grafana.yaml
47 changes: 47 additions & 0 deletions kubernetes/apps/monitoring-dev/grafana/ks.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
name: &app grafana-secrets-dev
namespace: flux-system
spec:
commonMetadata:
labels:
app.kubernetes.io/name: *app
path: ./kubernetes/apps/monitoring-dev/grafana/secrets
prune: true
sourceRef:
kind: GitRepository
name: immich-kubernetes
wait: true
interval: 30m
retryInterval: 1m
timeout: 5m
dependsOn:
- name: cluster-apps-onepassword
---
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
name: &app grafana-dev
namespace: flux-system
spec:
commonMetadata:
labels:
app.kubernetes.io/name: *app
path: ./kubernetes/apps/monitoring-dev/grafana/app
prune: true
sourceRef:
kind: GitRepository
name: immich-kubernetes
wait: true
interval: 30m
retryInterval: 1m
timeout: 5m
dependsOn:
- name: grafana-operator
- name: victoria-metrics-dev
- name: grafana-secrets-dev
postBuild:
substituteFrom:
- kind: Secret
name: grafana-oauth-dev
7 changes: 7 additions & 0 deletions kubernetes/apps/monitoring-dev/grafana/secrets/admin.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
apiVersion: onepassword.com/v1
kind: OnePasswordItem
metadata:
name: grafana-admin-credentials
namespace: monitoring-dev
spec:
itemPath: "vaults/Kubernetes/items/grafana-admin-credentials"
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./oauth.yaml
- ./admin.yaml
7 changes: 7 additions & 0 deletions kubernetes/apps/monitoring-dev/grafana/secrets/oauth.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
apiVersion: onepassword.com/v1
kind: OnePasswordItem
metadata:
name: grafana-oauth-dev
namespace: flux-system
spec:
itemPath: "vaults/Kubernetes/items/grafana-oauth-client-secret"
7 changes: 7 additions & 0 deletions kubernetes/apps/monitoring-dev/kustomization.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./namespace.yaml
- ./victoria-metrics/ks.yaml
- ./grafana/ks.yaml
5 changes: 5 additions & 0 deletions kubernetes/apps/monitoring-dev/namespace.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: monitoring-dev
Original file line number Diff line number Diff line change
@@ -0,0 +1,65 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: victoria-metrics-dev
namespace: monitoring-dev
spec:
interval: 5m
chart:
spec:
chart: victoria-metrics-k8s-stack
version: 0.27.3
interval: 15m
sourceRef:
kind: HelmRepository
name: victoria-metrics
namespace: flux-system
maxHistory: 2
install:
createNamespace: true
remediation:
retries: 3
upgrade:
crds: CreateReplace
cleanupOnFail: true
remediation:
retries: 3
uninstall:
keepHistory: false
values:
fullnameOverride: vmetrics-dev
# Disable all the scrapes, we don't need them for dev
crds:
enabled: false
defaultDashboards:
enabled: false
defaultRules:
create: false
victoria-metrics-operator:
enabled: false
prometheus-node-exporter:
enabled: false
kube-state-metrics:
enabled: false
kubelet:
enabled: false
coreDns:
enabled: false
kubeControllerManager:
enabled: false
kubeScheduler:
enabled: false
alertmanager:
enabled: false
vmalert:
enabled: false
grafana:
enabled: false
kubeEtcd:
enabled: false
vmsingle:
spec:
extraArgs:
search.maxUniqueTimeseries: "600000"
resources: {}
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./helmrelease.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./secret.yaml
- ./vmuser.yaml
- ./vmauth.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
apiVersion: onepassword.com/v1
kind: OnePasswordItem
metadata:
name: cf-workers-metrics-token
namespace: monitoring-dev
spec:
itemPath: "vaults/Kubernetes/items/cf-workers-metrics-token"
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
apiVersion: operator.victoriametrics.com/v1beta1
kind: VMAuth
metadata:
name: cf-workers-metrics-ingress
namespace: monitoring-dev
spec:
userSelector: {}
userNamespaceSelector: {}
selectAllByDefault: true
ingress:
tlsSecretName: cf-workers-metrics-tls
annotations:
cert-manager.io/cluster-issuer: letsencrypt-production
class_name: nginx
tlsHosts:
- cf-workers.monitoring.dev.immich.cloud
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
apiVersion: operator.victoriametrics.com/v1beta1
kind: VMUser
metadata:
name: cf-workers
namespace: monitoring-dev
spec:
tokenRef:
name: cf-workers-metrics-token
key: token
targetRefs:
- crd:
kind: VMSingle
name: vmetrics-dev
namespace: monitoring-dev
paths: ["/write"]
41 changes: 41 additions & 0 deletions kubernetes/apps/monitoring-dev/victoria-metrics/ks.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
name: &app1 victoria-metrics-dev
namespace: flux-system
spec:
commonMetadata:
labels:
app.kubernetes.io/name: *app1
dependsOn:
- name: grafana-operator
path: ./kubernetes/apps/monitoring-dev/victoria-metrics/app
prune: true
sourceRef:
kind: GitRepository
name: immich-kubernetes
wait: true
interval: 30m
retryInterval: 1m
timeout: 5m
---
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
name: &app2 cf-workers-metrics-ingress-dev
namespace: flux-system
spec:
commonMetadata:
labels:
app.kubernetes.io/name: *app2
dependsOn:
- name: victoria-metrics-dev
path: ./kubernetes/apps/monitoring-dev/victoria-metrics/ingress
prune: true
sourceRef:
kind: GitRepository
name: immich-kubernetes
wait: true
interval: 30m
retryInterval: 1m
timeout: 5m

0 comments on commit d007928

Please sign in to comment.