Add VictoriaMetrics observability stack + sync catalog for monitoring test

- VM stack 10 charts: victoria-metrics-cluster/auth, victoria-logs-cluster,
  victoria-metrics-agent/alert, opentelemetry-collector, kube-state-metrics,
  prometheus-node-exporter, alertmanager, perses (JWT/OIDC, Infisical-ready)
- ArgoCD ApplicationSet (syncWave) + per-chart dip-values overlays
- doc/victoria-metrics-architecture.md, define-chart-resources updates
- includes pending working-tree changes (mlflow, kubeflow, apisix, CLAUDE.md)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
wbsong111
2026-06-25 11:10:51 +09:00
parent a55427730e
commit 6290322f1b
514 changed files with 68103 additions and 40 deletions
@@ -0,0 +1,29 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/
*.md.gotmpl
CHANGELOG.md
_changelog.md
_index.md
e2e/
lint/
tests/
@@ -0,0 +1,70 @@
# victoria-logs-cluster 버전 갱신 가이드
> **카탈로그 업데이트 방식**: 기존 버전 디렉토리는 유지하고, 신규 버전 디렉토리를 새로 생성한다.
> `manifests/helm/victoria-logs-cluster/<new-version>/` 디렉토리를 직접 추가하는 방식으로 관리한다.
## 1. git 작업 환경 구성
- dip-catalog git 다운로드
```sh
git clone https://github.com/paasup/dip-catalog.git
```
- 작업 브랜치로 체크아웃
```sh
git checkout -b update-victoria-logs-cluster/<new-version>
```
## 2. helm chart 업데이트
### 1) 기존 버전 디렉토리 복사
신규 버전 디렉토리를 기존 버전에서 복사하여 시작한다.
`BUILD-README.md`, `CUSTOM-README.md`, `custom-values.yaml`가 함께 복사된다.
```sh
cd ~/dip-catalog/manifests/helm/victoria-logs-cluster
# 기존 버전에서 신규 버전 디렉토리 복사
cp -r 0.1.5 <new-version>
```
### 2) 업스트림 차트 파일 업데이트
신규 버전 디렉토리에서 업스트림 차트 파일만 교체한다.
`BUILD-README.md`, `CUSTOM-README.md`, `custom-values.yaml`는 유지한다.
```sh
cd ~/dip-catalog/manifests/helm/victoria-logs-cluster
# helm repo 추가
helm repo add victoria-metrics https://victoriametrics.github.io/helm-charts/
helm repo update
# 신규 버전 차트 다운로드 후 압축 해제
helm pull victoria-metrics/victoria-logs-cluster --version="<new-version>"
tar xzvf victoria-logs-cluster-<new-version>.tgz -C <new-version> --strip-components=1
# 불필요한 파일 삭제
rm victoria-logs-cluster-<new-version>.tgz
```
## 3. git push 및 tag 추가
```sh
git add .
git commit -m "update victoria-logs-cluster/<new-version>"
git checkout main
git merge update-victoria-logs-cluster/<new-version>
git push -u origin main
git branch -d update-victoria-logs-cluster/<new-version>
git tag victoria-logs-cluster/<new-version>
git push origin victoria-logs-cluster/<new-version>
```
## 4. 차트 버전 정보
- victoria-logs-cluster/0.1.5
- Chart version: 0.1.5
- App version: v1.50.0
- 업스트림: https://victoriametrics.github.io/helm-charts/
@@ -0,0 +1,36 @@
# VictoriaLogs Cluster 배포
AccountID 기반 스토리지 격리를 지원하는 로그 스토리지. vlinsert(쓰기)·vlstorage(저장)·vlselect(조회)로 구성된다.
## 1. 배포 방법
```sh
helm upgrade vlogs ./ -f custom-values.yaml --install -n monitoring
```
배포 시 주의:
- **클러스터 모드**를 사용한다. 단일 노드(victoria-logs-single)는 AccountID 헤더를 수신하지만 스토리지를 분리하지 않는다. 클러스터는 URL/헤더의 AccountID로 실제 격리 저장한다.
- `vlstorage`는 PVC를 사용한다(기본 5Gi).
## 2. custom-values.yaml 설정 설명
| 컴포넌트 | 포트 | 역할 |
|----------|------|------|
| vlinsert | 9481 | 로그 쓰기 — `/insert/{AccountID}/opentelemetry/v1/logs` |
| vlstorage | 9491 | AccountID별 격리 저장 (보존기간 `retentionPeriod: 7d`) |
| vlselect | 9471 | LogsQL 쿼리 — `/select/{AccountID}/logsql/query` |
`vlstorage.extraArgs."memory.allowedPercent": "60"`으로 메모리 사용 상한을 제한한다.
## 3. 의존 관계
- **쓰기**: opentelemetry-collector → vlinsert:9481 (`VictoriaLogs-AccountID` 헤더로 테넌트 지정)
- **조회**: vmauth → vlselect:9471 (Perses victorialogs 데이터소스가 vmauth 경유)
## 4. 검증
```sh
kubectl get pods -n monitoring -l app.kubernetes.io/instance=vlogs
kubectl port-forward -n monitoring svc/vlogs-victoria-logs-cluster-vlselect 9471:9471
curl -s 'http://localhost:9471/select/0/logsql/query?query=*&limit=1'
```
@@ -0,0 +1,9 @@
dependencies:
- name: vector
repository: https://helm.vector.dev
version: 0.52.0
- name: victoria-metrics-common
repository: oci://ghcr.io/victoriametrics/helm-charts
version: 0.3.0
digest: sha256:2ed29f6e03ca10a4d2d316bdff3fbbea4c23229718ab7bc409a16055aa8abed8
generated: "2026-04-23T05:14:26.335754154Z"
@@ -0,0 +1,45 @@
annotations:
artifacthub.io/category: monitoring-logging
artifacthub.io/changes: |
- render Vector dashboard only if subchart is enabled. See [#2896](https://github.com/VictoriaMetrics/helm-charts/issues/2896).
artifacthub.io/license: Apache-2.0
artifacthub.io/links: |
- name: Sources
url: https://github.com/VictoriaMetrics/helm-charts/tree/master/charts/victoria-logs-cluster
- name: Charts repo
url: https://victoriametrics.github.io/helm-charts/
- name: Docs
url: https://docs.victoriametrics.com/victorialogs/cluster/
- name: Changelog
url: https://docs.victoriametrics.com/victorialogs/changelog/
artifacthub.io/readme: |
# VictoriaLogs Cluster Helm chart
Chart documentation is available [here](https://docs.victoriametrics.com/helm/victoria-logs-cluster/).
Changelog is [here](https://docs.victoriametrics.com/helm/victoria-logs-cluster/changelog/).
apiVersion: v2
appVersion: v1.50.0
dependencies:
- condition: vector.enabled
name: vector
repository: https://helm.vector.dev
version: 0.52.*
- name: victoria-metrics-common
repository: oci://ghcr.io/victoriametrics/helm-charts
version: 0.3.*
description: The VictoriaLogs cluster Helm chart deploys VictoriaLogs cluster database
in Kubernetes.
home: https://github.com/VictoriaMetrics/helm-charts
icon: https://avatars.githubusercontent.com/u/43720803?s=200&v=4
keywords:
- victorialogs
- logs
- kubernetes
- observability
- logsql
kubeVersion: '>=1.25.0-0'
name: victoria-logs-cluster
sources:
- https://github.com/VictoriaMetrics/helm-charts
type: application
version: 0.1.5
@@ -0,0 +1,4 @@
# VictoriaLogs Cluster Helm chart
Chart documentation is available [here](https://docs.victoriametrics.com/helm/victoria-logs-cluster/).
Changelog is [here](https://docs.victoriametrics.com/helm/victoria-logs-cluster/changelog/).
@@ -0,0 +1,7 @@
# Release notes for version 0.1.5
**Release date:** 21 May 2026
![Helm: v3](https://img.shields.io/badge/Helm-v3.14%2B-informational?color=informational&logo=helm&link=https%3A%2F%2Fgithub.com%2Fhelm%2Fhelm%2Freleases%2Ftag%2Fv3.14.0) ![AppVersion: v1.50.0](https://img.shields.io/badge/v1.50.0-success?logo=VictoriaMetrics&labelColor=gray&link=https%3A%2F%2Fdocs.victoriametrics.com%2Fvictorialogs%2Fchangelog%2F%23v1500)
- render Vector dashboard only if subchart is enabled. See [#2896](https://github.com/VictoriaMetrics/helm-charts/issues/2896).
@@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/
@@ -0,0 +1,32 @@
annotations:
artifacthub.io/images: |
- name: vector
image: timberio/vector:0.55.0-distroless-libc
- name: haproxy
image: haproxytech/haproxy-alpine:2.6.12
artifacthub.io/license: MPL-2.0
artifacthub.io/links: |
- name: Chart Source
url: https://github.com/vectordotdev/helm-charts
artifacthub.io/prerelease: "false"
apiVersion: v2
appVersion: 0.55.0-distroless-libc
description: A lightweight, ultra-fast tool for building observability pipelines
home: https://vector.dev/
icon: https://vector.dev/press/vector-icon.svg
keywords:
- vector
- events
- logs
- metrics
- observability
- stream-processing
kubeVersion: '>=1.28.0-0'
maintainers:
- email: vector@datadoghq.com
name: Datadog
name: vector
sources:
- https://github.com/vectordotdev/vector/
type: application
version: 0.52.0
@@ -0,0 +1,301 @@
# Vector
![Version: 0.52.0](https://img.shields.io/badge/Version-0.52.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 0.55.0-distroless-libc](https://img.shields.io/badge/AppVersion-0.55.0--distroless--libc-informational?style=flat-square)
[Vector](https://vector.dev/) is a high-performance, end-to-end observability data pipeline that puts you in control of your observability data. Collect, transform, and route all your logs, metrics, and traces to any vendors you want today and any other vendors you may want tomorrow. Vector enables dramatic cost reduction, novel data enrichment, and data security where you need it, not where is most convenient for your vendors.
## How to use Vector Helm repository
You need to add this repository to your Helm repositories:
```
helm repo add vector https://helm.vector.dev
helm repo update
```
## Requirements
Kubernetes: `>=1.28.0-0`
## Quick start
By default, Vector runs as a `StatefulSet` in the "Aggregator" role. It can alternatively run as a `Deployment` for the "Stateless-Aggregator" role or a `DaemonSet` for the "Agent" role.
### Installing the Vector chart
To install the chart with the release name `<RELEASE_NAME>` run:
```bash
helm install <RELEASE_NAME> vector/vector
```
### Upgrading
#### From original charts
* [Migrate from the `vector-agent` chart](docs/Migrate_from_vector-agent.md)
* [Migrate from the `vector-aggregator` chart](docs/Migrate_from_vector-aggregator.md)
### Uninstalling the chart
To uninstall/delete the `<RELEASE_NAME>` deployment:
```bash
helm delete <RELEASE_NAME>
```
The command removes all the Kubernetes components associated with the chart and deletes the release.
## Configuration
1. Using our [`default-values.yaml`](values.yaml) configuration file as a reference, create your own `values.yaml`.
2. Upgrade the Vector chart with your new `values.yaml` file:
```bash
helm upgrade -f values.yaml <RELEASE_NAME> vector/vector
```
**Vector recommends that your `values.yaml` only contain values that need to be overridden, as it allows a smoother experience when upgrading chart versions.**
See the [configuration options](#all-configuration-options) section to discover all possibilities offered by the Vector chart.
### Running on control plane nodes
Depending on your Kubernetes distribution, you may need to configure `tolerations` to run Vector on nodes acting as the control plane.
For example to run Vector on [Openshift](https://www.redhat.com/en/technologies/cloud-computing/openshift) control plane nodes you can set:
```yaml
tolerations:
- effect: NoSchedule
key: node-role.kubernetes.io/master
operator: Exists
- effect: NoSchedule
key: node-role.kubernetes.io/infra
operator: Exists
```
Or for [RKE](https://rancher.com/products/rke) control plane nodes set:
```yaml
tolerations:
- effect: NoSchedule
key: node-role.kubernetes.io/controlplane
operator: Exists
- effect: NoExecute
key: node-role.kubernetes.io/etcd
operator: Exists
```
### Using template syntax in `customConfig`
As Vector's [template syntax](https://vector.dev/docs/reference/configuration/template-syntax/) shares the same syntax as Helm templates, explicit handling is required
if you are using Vector's template syntax in the `customConfig` option. To avoid Helm templating configuration intended for Vector you can supply configuration like so:
```yaml
customConfig:
#...
sinks:
loki:
#...
labels:
foo: bar
host: |-
{{ print "{{ host }}" }}
source: |-
{{ print "{{ source_type }}" }}
```
### API exposure and health probes
When using chart-managed default configuration (without `customConfig` and `existingConfigMaps`),
Vector's API listens on `0.0.0.0:8686`, and the chart applies a default readiness probe
(`grpc` on port `8686`).
If you use `customConfig`, ensure `api.enabled`/`api.address` and probe settings are aligned
with your configuration.
As this API can expose internal state, restrict reachability with Kubernetes controls such as
`NetworkPolicy` and carefully scoped Service/Ingress exposure.
## All configuration options
The following table lists the configurable parameters of the Vector chart and their default values. Specify each parameter using the `--set key=value[,key=value]` argument to `helm install`. For example,
```bash
helm install <RELEASE_NAME> \
vector/vector \
--set role=Agent
```
## Values
### Vector values
| Key | Type | Default | Description |
|-----|------|---------|-------------|
| affinity | object | `{}` | Configure [affinity](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#affinity-and-anti-affinity) rules for Vector Pods. |
| args | list | `["--config-dir","/etc/vector/"]` | Override Vector's default arguments. |
| autoscaling.annotations | object | `{}` | Annotations to add to Vector's HPA. |
| autoscaling.behavior | object | `{}` | Configure separate scale-up and scale-down behaviors. |
| autoscaling.customMetric | object | `{}` | Target a custom metric for autoscaling. |
| autoscaling.enabled | bool | `false` | Create a [HorizontalPodAutoscaler](https://kubernetes.io/docs/tasks/run-application/horizontal-pod-autoscale/) for Vector. Valid for the "Aggregator" and "Stateless-Aggregator" roles. |
| autoscaling.external | bool | `false` | Set to `true` if using an external autoscaler like [KEDA](https://keda.sh/). Valid for the "Aggregator and "Stateless-Aggregator" roles. |
| autoscaling.maxReplicas | int | `10` | Maximum replicas for Vector's HPA. |
| autoscaling.minReplicas | int | `1` | Minimum replicas for Vector's HPA. |
| autoscaling.targetCPUUtilizationPercentage | int | `80` | Target CPU utilization for Vector's HPA. |
| autoscaling.targetMemoryUtilizationPercentage | int | `nil` | Target memory utilization for Vector's HPA. |
| command | list | `[]` | Override Vector's default command. |
| commonLabels | object | `{}` | Add additional labels to all created resources. |
| containerPorts | list | `[]` | Manually define Vector's containerPorts, overriding automated generation of containerPorts. |
| customConfig | object | `{}` | Override Vector's default configs, if used **all** options need to be specified. This section supports using helm templates to populate dynamic values. See Vector's [configuration documentation](https://vector.dev/docs/reference/configuration/) for all options. |
| daemonSet.apiVersion | string | `""` | Override the DaemonSet apiVersion. Valid for the "Agent" role. |
| dataDir | string | `""` | Specify the path for Vector's data, only used when existingConfigMaps are used. |
| defaultVolumeMounts | list | See `values.yaml` | Default volume mounts. Corresponds to `volumes`. |
| defaultVolumes | list | See `values.yaml` | Default volumes that are mounted into pods. In most cases, these should not be changed. Use `extraVolumes`/`extraVolumeMounts` for additional custom volumes. |
| dnsConfig | object | `{}` | Specify the [dnsConfig](https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config) options for Vector Pods. |
| dnsPolicy | string | `"ClusterFirst"` | Specify the [dnsPolicy](https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-s-dns-policy) for Vector Pods. |
| env | list | `[]` | Set environment variables for Vector containers. |
| envFrom | list | `[]` | Define environment variables from Secrets or ConfigMaps. |
| existingConfigMaps | list | `[]` | List of existing ConfigMaps for Vector's configuration instead of creating a new one. Requires dataDir to be set. Additionally, containerPorts, service.ports, and serviceHeadless.ports should be specified based on your supplied configuration. If set, this parameter takes precedence over customConfig and the chart's default configs. |
| extraContainers | list | `[]` | Extra Containers to be added to the Vector Pods. This also supports template content, which will eventually be converted to yaml. |
| extraObjects | list | `[]` | Create extra manifests via values. Would be passed through `tpl` for templating. |
| extraVolumeMounts | list | `[]` | Additional Volume to mount into Vector Containers. |
| extraVolumes | list | `[]` | Additional Volumes to use with Vector Pods. |
| fullnameOverride | string | `""` | Override the full name of resources. |
| hostAliases | list | `[]` | |
| image.base | string | `""` | The base distribution to use for vector. If set, then the base in appVersion will be replaced with this base alongside the version. For example: with a `base` of `debian` `0.38.0-distroless-libc` becomes `0.38.0-debian` |
| image.pullPolicy | string | `"IfNotPresent"` | The [pullPolicy](https://kubernetes.io/docs/concepts/containers/images/#image-pull-policy) for Vector's image. |
| image.pullSecrets | list | `[]` | The [imagePullSecrets](https://kubernetes.io/docs/concepts/containers/images/#specifying-imagepullsecrets-on-a-pod) to reference for the Vector Pods. |
| image.repository | string | `"docker.io/timberio/vector"` | Override default registry and name for Vector's image. |
| image.sha | string | `""` | The SHA to use for Vector's image. |
| image.tag | string | Derived from the Chart's appVersion. | The tag to use for Vector's image. |
| ingress.annotations | object | `{}` | Set annotations on the Ingress. |
| ingress.className | string | `""` | Specify the [ingressClassName](https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress), requires Kubernetes >= 1.18 |
| ingress.enabled | bool | `false` | If true, create and use an Ingress resource. |
| ingress.hosts | list | `[]` | Configure the hosts and paths for the Ingress. |
| ingress.tls | list | `[]` | Configure TLS for the Ingress. |
| initContainers | list | `[]` | Init Containers to be added to the Vector Pods. This also supports template content, which will eventually be converted to yaml. |
| lifecycle | object | `{}` | Set lifecycle hooks for Vector containers. |
| livenessProbe | object | `{}` | Override default liveness probe settings. If customConfig is used, requires customConfig.api.enabled to be set to true. `grpc` is recommended once the cluster is on Vector 0.55+; the `httpGet /health` probe is kept for backwards compatibility with older Vector versions. |
| logLevel | string | `"info"` | |
| minReadySeconds | int | `0` | Specify the minimum number of seconds a newly spun up pod should wait to pass healthchecks before it is considered available. |
| nameOverride | string | `""` | Override the name of resources. |
| nodeSelector | object | `{}` | Configure a [nodeSelector](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector) for Vector Pods. |
| persistence.accessModes | list | `["ReadWriteOnce"]` | Specifies the accessModes for PersistentVolumeClaims. Valid for the "Aggregator" role. |
| persistence.enabled | bool | `false` | If true, create and use PersistentVolumeClaims. |
| persistence.existingClaim | string | `""` | Name of an existing PersistentVolumeClaim to use. Valid for the "Aggregator" role. |
| persistence.finalizers | list | `["kubernetes.io/pvc-protection"]` | Specifies the finalizers of PersistentVolumeClaims. Valid for the "Aggregator" role. |
| persistence.hostPath.enabled | bool | `true` | If true, use hostPath persistence. Valid for the "Agent" role, if it's disabled the "Agent" role will use emptyDir. |
| persistence.hostPath.path | string | `"/var/lib/vector"` | Override path used for hostPath persistence. Valid for the "Agent" role, persistence is always used for the "Agent" role. |
| persistence.retentionPolicy | object | `{}` | Configure a [PersistentVolumeClaimRetentionPolicy](https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#persistentvolumeclaim-retention) for Vector's PersistentVolumeClaims. Valid for the "Aggregator" role. |
| persistence.selectors | object | `{}` | Specifies the selectors for PersistentVolumeClaims. Valid for the "Aggregator" role. |
| persistence.size | string | `"10Gi"` | Specifies the size of PersistentVolumeClaims. Valid for the "Aggregator" role. |
| podAnnotations | object | `{}` | Set annotations on Vector Pods. |
| podDisruptionBudget.enabled | bool | `false` | Enable a [PodDisruptionBudget](https://kubernetes.io/docs/tasks/run-application/configure-pdb/) for Vector. |
| podDisruptionBudget.maxUnavailable | int | `nil` | The number of Pods that can be unavailable after an eviction. |
| podDisruptionBudget.minAvailable | int | `1` | The number of Pods that must still be available after an eviction. |
| podHostNetwork | bool | `false` | Configure hostNetwork on Vector Pods. |
| podLabels | object | `{"vector.dev/exclude":"true"}` | Set labels on Vector Pods. |
| podManagementPolicy | string | `"OrderedReady"` | Specify the [podManagementPolicy](https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#pod-management-policies) for the StatefulSet. Valid for the "Aggregator" role. |
| podMonitor.additionalLabels | object | `{}` | Adds additional labels to the PodMonitor. |
| podMonitor.enabled | bool | `false` | If true, create a PodMonitor for Vector. |
| podMonitor.honorLabels | bool | `false` | If true, honor_labels is set to true in the [scrape config](https://prometheus.io/docs/prometheus/latest/configuration/configuration/#scrape_config). |
| podMonitor.honorTimestamps | bool | `true` | If true, honor_timestamps is set to true in the [scrape config](https://prometheus.io/docs/prometheus/latest/configuration/configuration/#scrape_config). |
| podMonitor.interval | string | `nil` | Override the interval at which metrics should be scraped. |
| podMonitor.jobLabel | string | `"app.kubernetes.io/name"` | Override the label to retrieve the job name from. |
| podMonitor.metricRelabelings | list | `[]` | [MetricRelabelConfigs](https://prometheus.io/docs/prometheus/latest/configuration/configuration/#metric_relabel_configs) to apply to samples before ingestion. |
| podMonitor.path | string | `"/metrics"` | Override the path to scrape. |
| podMonitor.podTargetLabels | list | `[]` | [podTargetLabels](https://prometheus-operator.dev/docs/operator/api/#monitoring.coreos.com/v1.PodMonitorSpec) transfers labels on the Kubernetes Pod onto the target. |
| podMonitor.port | string | `"prom-exporter"` | Override the port to scrape. |
| podMonitor.relabelings | list | `[]` | [RelabelConfigs](https://prometheus.io/docs/prometheus/latest/configuration/configuration/#relabel_config) to apply to samples before scraping. |
| podMonitor.scrapeTimeout | string | `nil` | Override the timeout after which the scrape is ended. |
| podPriorityClassName | string | `""` | Set the [priorityClassName](https://kubernetes.io/docs/concepts/scheduling-eviction/pod-priority-preemption/#priorityclass) on Vector Pods. |
| podSecurityContext | object | `{}` | Allows you to overwrite the default [PodSecurityContext](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/) for Vector Pods. |
| psp.create | bool | `false` | If true, create a [PodSecurityPolicy](https://kubernetes.io/docs/concepts/security/pod-security-policy/) resource. PodSecurityPolicy is deprecated as of Kubernetes v1.21, and will be removed in v1.25. Intended for use with the "Agent" role. |
| rbac.create | bool | `true` | If true, create and use RBAC resources. Only valid for the "Agent" role. |
| rbac.extraRules | list | `[]` | List of additional Kubernetes RBAC rules to append to the ClusterRole. Rules defined here are appended after the chart's standard rules. Each item must follow the Kubernetes ClusterRole rule syntax. Example: extraRules: - apiGroups: [""] resources: ["nodes/metrics", "nodes/stats"] verbs: ["get"] |
| readinessProbe | object | `{}` | Override default readiness probe settings. If not set, this chart applies an `httpGet /health` readinessProbe on port `8686` for chart-managed default configs. If customConfig is used, requires customConfig.api.enabled to be set to true. `grpc` is recommended once the cluster is on Vector 0.55+; the `httpGet /health` probe is kept for backwards compatibility with older Vector versions. |
| replicas | int | `1` | Specify the number of Pods to create. Valid for the "Aggregator" and "Stateless-Aggregator" roles. |
| resources | object | `{}` | Set Vector resource requests and limits. |
| role | string | `"Aggregator"` | [Role](https://vector.dev/docs/setup/deployment/roles/) for this Vector instance, valid options are: "Agent", "Aggregator", and "Stateless-Aggregator". |
| rollWorkload | bool | `true` | Add a checksum of the generated ConfigMap to workload annotations. |
| rollWorkloadExtraObjects | bool | `false` | Add a checksum of the generated ExtraObjects to workload annotations. |
| rollWorkloadSecrets | bool | `false` | Add a checksum of the generated Secret to workload annotations. |
| secrets.generic | object | `{}` | Each Key/Value will be added to the Secret's data key, each value should be raw and NOT base64 encoded. Any secrets can be provided here. It's commonly used for credentials and other access related values. **NOTE: Don't commit unencrypted secrets to git!** |
| securityContext | object | `{}` | Specify securityContext on Vector containers. |
| service.annotations | object | `{}` | Set annotations on Vector's Service. |
| service.enabled | bool | `true` | If true, create and provide a Service resource for Vector. |
| service.externalTrafficPolicy | string | `""` | Specify the [externalTrafficPolicy](https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip). |
| service.internalTrafficPolicy | string | `""` | Specify the [internalTrafficPolicy](https://kubernetes.io/docs/concepts/services-networking/service-traffic-policy). |
| service.ipFamilies | list | `[]` | Configure [IPv4/IPv6 dual-stack](https://kubernetes.io/docs/concepts/services-networking/dual-stack/). |
| service.ipFamilyPolicy | string | `""` | Configure [IPv4/IPv6 dual-stack](https://kubernetes.io/docs/concepts/services-networking/dual-stack/). |
| service.loadBalancerIP | string | `""` | Specify the [loadBalancerIP](https://kubernetes.io/docs/concepts/services-networking/service/#loadbalancer). |
| service.ports | list | `[]` | Manually set the Service ports, overriding automated generation of Service ports. |
| service.topologyKeys | list | `[]` | Specify the [topologyKeys](https://kubernetes.io/docs/concepts/services-networking/service-topology/#using-service-topology) field on Vector's Service. |
| service.trafficDistribution | string | `""` | Specify the [Traffic distribution](https://kubernetes.io/docs/concepts/services-networking/service/#traffic-distribution) additional Topology Aware Routing may be informative. Specify the [Topology Aware Routing](https://kubernetes.io/docs/concepts/services-networking/topology-aware-routing/) |
| service.type | string | `"ClusterIP"` | Set the type for Vector's Service. |
| serviceAccount.annotations | object | `{}` | Annotations to add to Vector's ServiceAccount. |
| serviceAccount.automountToken | bool | `true` | Automount API credentials for Vector's ServiceAccount. |
| serviceAccount.create | bool | `true` | If true, create a ServiceAccount for Vector. |
| serviceAccount.name | string | `nil` | The name of the ServiceAccount to use. If not set and serviceAccount.create is true, a name is generated using the fullname template. |
| serviceHeadless.enabled | bool | `true` | If true, create and provide a Headless Service resource for Vector. |
| shareProcessNamespace | bool | `false` | Specify the [shareProcessNamespace](https://kubernetes.io/docs/tasks/configure-pod-container/share-process-namespace/) options for Vector Pods. |
| startupProbe | object | `{}` | Override default startup probe settings. If customConfig is used, requires customConfig.api.enabled to be set to true. `grpc` is recommended once the cluster is on Vector 0.55+; the `httpGet /health` probe is kept for backwards compatibility with older Vector versions. |
| statefulSet.apiVersion | string | `""` | Override the StatefulSet apiVersion. Valid for the "Aggregator" role. |
| terminationGracePeriodSeconds | int | `60` | Override Vector's terminationGracePeriodSeconds. |
| tolerations | list | `[]` | Configure Vector Pods to be scheduled on [tainted](https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/) nodes. |
| topologySpreadConstraints | list | `[]` | Configure [topology spread constraints](https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/) for Vector Pods. Valid for the "Aggregator" and "Stateless-Aggregator" roles. |
| updateStrategy | object | `{}` | Customize the updateStrategy used to replace Vector Pods, this is also used for the DeploymentStrategy for the "Stateless-Aggregators". Valid options depend on the chosen role. |
| workloadResourceAnnotations | object | `{}` | Set annotations on the Vector DaemonSet, Deployment or StatefulSet. |
### HAProxy values
| Key | Type | Default | Description |
|-----|------|---------|-------------|
| haproxy.affinity | object | `{}` | Configure [affinity](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#affinity-and-anti-affinity) rules for HAProxy Pods. |
| haproxy.autoscaling.customMetric | object | `{}` | Target a custom metric for autoscaling. |
| haproxy.autoscaling.enabled | bool | `false` | Create a HorizontalPodAutoscaler for HAProxy. |
| haproxy.autoscaling.external | bool | `false` | HAProxy is controlled by an external HorizontalPodAutoscaler. |
| haproxy.autoscaling.maxReplicas | int | `10` | Maximum replicas for HAProxy's HPA. |
| haproxy.autoscaling.minReplicas | int | `1` | Minimum replicas for HAProxy's HPA. |
| haproxy.autoscaling.targetCPUUtilizationPercentage | int | `80` | Target CPU utilization for HAProxy's HPA. |
| haproxy.autoscaling.targetMemoryUtilizationPercentage | int | `nil` | Target memory utilization for HAProxy's HPA. |
| haproxy.containerPorts | list | `[]` | Manually define HAProxy's containerPorts, overrides automated generation of containerPorts. |
| haproxy.customConfig | string | `""` | Override HAProxy's default configs, if used **all** options need to be specified. This parameter supports using Helm templates to insert values dynamically. By default, this chart will parse Vector's configuration from customConfig to generate HAProxy's config, which can be overwritten with haproxy.customConfig. |
| haproxy.enabled | bool | `false` | If true, create a HAProxy load balancer. |
| haproxy.existingConfigMap | string | `""` | Use this existing ConfigMap for HAProxy's configuration instead of creating a new one. Additionally, haproxy.containerPorts and haproxy.service.ports should be specified based on your supplied configuration. If set, this parameter takes precedence over customConfig and the chart's default configs. |
| haproxy.extraContainers | list | `[]` | Extra Containers to be added to the HAProxy Pods. This also supports template content, which will eventually be converted to yaml. |
| haproxy.extraVolumeMounts | list | `[]` | Additional Volume to mount into HAProxy Containers. |
| haproxy.extraVolumes | list | `[]` | Additional Volumes to use with HAProxy Pods. |
| haproxy.image.pullPolicy | string | `"IfNotPresent"` | HAProxy image pullPolicy. |
| haproxy.image.pullSecrets | list | `[]` | The [imagePullSecrets](https://kubernetes.io/docs/concepts/containers/images/#specifying-imagepullsecrets-on-a-pod) to reference for the HAProxy Pods. |
| haproxy.image.repository | string | `"haproxytech/haproxy-alpine"` | Override default registry and name for HAProxy. |
| haproxy.image.tag | string | `"2.6.12"` | The tag to use for HAProxy's image. |
| haproxy.initContainers | list | `[]` | Init Containers to be added to the HAProxy Pods. This also supports template content, which will eventually be converted to yaml. |
| haproxy.livenessProbe | object | `{"tcpSocket":{"port":1024}}` | Override default HAProxy liveness probe settings. |
| haproxy.nodeSelector | object | `{}` | Configure a [nodeSelector](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector) for HAProxy Pods |
| haproxy.podAnnotations | object | `{}` | Set annotations on HAProxy Pods. |
| haproxy.podLabels | object | `{}` | Set labels on HAProxy Pods. |
| haproxy.podPriorityClassName | string | `""` | Set the priorityClassName on HAProxy Pods. |
| haproxy.podSecurityContext | object | `{}` | Allows you to overwrite the default PodSecurityContext for HAProxy. |
| haproxy.readinessProbe | object | `{"tcpSocket":{"port":1024}}` | Override default HAProxy readiness probe settings. |
| haproxy.replicas | int | `1` | Set the number of HAProxy Pods to create. |
| haproxy.resources | object | `{}` | Set HAProxy resource requests and limits. |
| haproxy.rollWorkload | bool | `true` | Add a checksum of the generated ConfigMap to the HAProxy Deployment. |
| haproxy.securityContext | object | `{}` | Specify securityContext on HAProxy containers. |
| haproxy.service.annotations | object | `{}` | Set annotations on HAProxy's Service. |
| haproxy.service.externalTrafficPolicy | string | `""` | Specify the [externalTrafficPolicy](https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip). |
| haproxy.service.ipFamilies | list | `[]` | Configure [IPv4/IPv6 dual-stack](https://kubernetes.io/docs/concepts/services-networking/dual-stack/). |
| haproxy.service.ipFamilyPolicy | string | `""` | Configure [IPv4/IPv6 dual-stack](https://kubernetes.io/docs/concepts/services-networking/dual-stack/). |
| haproxy.service.loadBalancerIP | string | `""` | Specify the [loadBalancerIP](https://kubernetes.io/docs/concepts/services-networking/service/#loadbalancer). |
| haproxy.service.ports | list | `[]` | Manually set HAPRoxy's Service ports, overrides automated generation of Service ports. |
| haproxy.service.topologyKeys | list | `[]` | Specify the [topologyKeys](https://kubernetes.io/docs/concepts/services-networking/service-topology/#using-service-topology) field on HAProxy's Service spec. |
| haproxy.service.type | string | `"ClusterIP"` | Set type of HAProxy's Service. |
| haproxy.serviceAccount.annotations | object | `{}` | Annotations to add to the HAProxy ServiceAccount. |
| haproxy.serviceAccount.automountToken | bool | `true` | Automount API credentials for the HAProxy ServiceAccount. |
| haproxy.serviceAccount.create | bool | `true` | If true, create a HAProxy ServiceAccount. |
| haproxy.serviceAccount.name | string | `nil` | The name of the HAProxy ServiceAccount to use. If not set and create is true, a name is generated using the fullname template. |
| haproxy.strategy | object | `{}` | Customize the [strategy](https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/deployment-v1/) used to replace HAProxy Pods. |
| haproxy.terminationGracePeriodSeconds | int | `60` | Override HAProxy's terminationGracePeriodSeconds. |
| haproxy.tolerations | list | `[]` | Configure HAProxy Pods to be scheduled on [tainted](https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/) nodes. |
@@ -0,0 +1,149 @@
# Vector
{{ template "chart.versionBadge" . }}{{ template "chart.typeBadge" . }}{{ template "chart.appVersionBadge" . }}
[Vector](https://vector.dev/) is a high-performance, end-to-end observability data pipeline that puts you in control of your observability data. Collect, transform, and route all your logs, metrics, and traces to any vendors you want today and any other vendors you may want tomorrow. Vector enables dramatic cost reduction, novel data enrichment, and data security where you need it, not where is most convenient for your vendors.
## How to use Vector Helm repository
You need to add this repository to your Helm repositories:
```
helm repo add vector https://helm.vector.dev
helm repo update
```
{{ template "chart.requirementsSection" . }}
## Quick start
By default, Vector runs as a `StatefulSet` in the "Aggregator" role. It can alternatively run as a `Deployment` for the "Stateless-Aggregator" role or a `DaemonSet` for the "Agent" role.
### Installing the Vector chart
To install the chart with the release name `<RELEASE_NAME>` run:
```bash
helm install <RELEASE_NAME> vector/vector
```
### Upgrading
#### From original charts
* [Migrate from the `vector-agent` chart](docs/Migrate_from_vector-agent.md)
* [Migrate from the `vector-aggregator` chart](docs/Migrate_from_vector-aggregator.md)
### Uninstalling the chart
To uninstall/delete the `<RELEASE_NAME>` deployment:
```bash
helm delete <RELEASE_NAME>
```
The command removes all the Kubernetes components associated with the chart and deletes the release.
## Configuration
1. Using our [`default-values.yaml`](values.yaml) configuration file as a reference, create your own `values.yaml`.
2. Upgrade the Vector chart with your new `values.yaml` file:
```bash
helm upgrade -f values.yaml <RELEASE_NAME> vector/vector
```
**Vector recommends that your `values.yaml` only contain values that need to be overridden, as it allows a smoother experience when upgrading chart versions.**
See the [configuration options](#all-configuration-options) section to discover all possibilities offered by the Vector chart.
### Running on control plane nodes
Depending on your Kubernetes distribution, you may need to configure `tolerations` to run Vector on nodes acting as the control plane.
For example to run Vector on [Openshift](https://www.redhat.com/en/technologies/cloud-computing/openshift) control plane nodes you can set:
```yaml
tolerations:
- effect: NoSchedule
key: node-role.kubernetes.io/master
operator: Exists
- effect: NoSchedule
key: node-role.kubernetes.io/infra
operator: Exists
```
Or for [RKE](https://rancher.com/products/rke) control plane nodes set:
```yaml
tolerations:
- effect: NoSchedule
key: node-role.kubernetes.io/controlplane
operator: Exists
- effect: NoExecute
key: node-role.kubernetes.io/etcd
operator: Exists
```
### Using template syntax in `customConfig`
As Vector's [template syntax](https://vector.dev/docs/reference/configuration/template-syntax/) shares the same syntax as Helm templates, explicit handling is required
if you are using Vector's template syntax in the `customConfig` option. To avoid Helm templating configuration intended for Vector you can supply configuration like so:
```yaml
customConfig:
#...
sinks:
loki:
#...
labels:
foo: bar
host: |-
{{ print "{{ print \"{{ host }}\" }}" }}
source: |-
{{ print "{{ print \"{{ source_type }}\" }}" }}
```
### API exposure and health probes
When using chart-managed default configuration (without `customConfig` and `existingConfigMaps`),
Vector's API listens on `0.0.0.0:8686`, and the chart applies a default readiness probe
(`grpc` on port `8686`).
If you use `customConfig`, ensure `api.enabled`/`api.address` and probe settings are aligned
with your configuration.
As this API can expose internal state, restrict reachability with Kubernetes controls such as
`NetworkPolicy` and carefully scoped Service/Ingress exposure.
## All configuration options
The following table lists the configurable parameters of the Vector chart and their default values. Specify each parameter using the `--set key=value[,key=value]` argument to `helm install`. For example,
```bash
helm install <RELEASE_NAME> \
vector/vector \
--set role=Agent
```
{{ template "chart.valuesHeader" . }}
### Vector values
| Key | Type | Default | Description |
|-----|------|---------|-------------|
{{- range .Values }}
{{- if not (contains "haproxy" .Key) }}
| {{ .Key }} | {{ .Type }} | {{ if .Default }}{{ .Default }}{{ else }}{{ .AutoDefault }}{{ end }} | {{ if .Description }}{{ .Description }}{{ else }}{{ .AutoDescription }}{{ end }} |
{{- end }}
{{- end }}
### HAProxy values
| Key | Type | Default | Description |
|-----|------|---------|-------------|
{{- range .Values }}
{{- if (contains "haproxy" .Key) }}
| {{ .Key }} | {{ .Type }} | {{ if .Default }}{{ .Default }}{{ else }}{{ .AutoDefault }}{{ end }} | {{ if .Description }}{{ .Description }}{{ else }}{{ .AutoDescription }}{{ end }} |
{{- end }}
{{- end }}
@@ -0,0 +1,3 @@
# Agent role
## Values file for testing default Agent parameters.
role: Agent
@@ -0,0 +1,130 @@
# Aggregator role
## Values file for testing all Aggregator parameters.
podSecurityContext:
fsGroup: 2000
securityContext:
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 1000
workloadResourceAnnotations:
kubernetes.io/description: "Vector aggregator deployment."
configmap.reloader.stakater.com/reload: additional-configmap
resources:
requests:
cpu: 200m
memory: 256Mi
limits:
cpu: 200m
memory: 256Mi
updateStrategy:
type: OnDelete
nodeSelector:
kubernetes.io/os: linux
tolerations:
- key: node-role.kubernetes.io/master
effect: NoSchedule
affinity:
nodeAffinity:
preferredDuringSchedulingIgnoredDuringExecution:
- weight: 1
preference:
matchExpressions:
- key: kubernetes.io/e2e-az-name
operator: In
values:
- e2e-az1
- e2e-az2
topologySpreadConstraints:
- labelSelector:
matchLabels:
app.kubernetes.io/name: vector
app.kubernetes.io/instance: vector
app.kubernetes.io/component: Aggregator
maxSkew: 1
topologyKey: topology.kubernetes.io/zone
whenUnsatisfiable: ScheduleAnyway
customConfig:
data_dir: /data
api:
enabled: true
address: 0.0.0.0:1212
healthchecks:
enabled: false
sources:
kafka:
type: kafka
acknowledgements: true
bootstrap_servers: kafka-bootstrap.svc.cluster.local:9092
group_id: vector-consumer
topics: [application-logs]
prom_remote:
type: prometheus_remote_write
address: 0.0.0.0:9999
transforms:
aggregate:
type: aggregate
inputs: [prom_remote]
interval_ms: 15000
remap:
type: remap
inputs: [kafka]
drop_on_error: true
source: |
. |= object!(parse_json!(.message))
sample:
type: sample
inputs: [remap]
exclude: |
.status_code != 200 && !includes(["info", "debug"], .severity)
rate: 10
sinks:
s3_archive:
type: aws_s3
inputs: [remap]
bucket: logs-archive
key_prefix: date=%F/
compression: gzip
encoding:
codec: json
region: us-east-1
elasticsearch:
type: elasticsearch
inputs: [aggregate, sample]
endpoint: http://elasticsearch.svc.cluster.local:9000
index: vector-%F
mode: data_stream
compression: gzip
service:
enabled: true
persistence:
enabled: true
storageClassName: standard
accessModes:
- ReadWriteOnce
size: 50Gi
finalizers:
- kubernetes.io/pvc-protection
livenessProbe:
httpGet:
path: /health
port: api
readinessProbe:
httpGet:
path: /health
port: api
@@ -0,0 +1,2 @@
# Aggregator role
## Emptry values file for testing default Aggregator parameters.
@@ -0,0 +1,4 @@
# HAProxy usage
## Values file for testing HAProxy parameters.
haproxy:
enabled: true
@@ -0,0 +1,16 @@
# Ingress usage
## Values file for testing Ingress parameters.
ingress:
enabled: true
className: "nginx"
annotations:
nginx.ingress.kubernetes.io/rewrite-target: /
kubernetes.io/tls-acme: "true"
hosts:
- host: chart-example.local
paths:
- path: /api/v1
pathType: Prefix
port:
name: "http"
number: "8080"
@@ -0,0 +1,24 @@
# Components sharing the same port with different protocols
## Values file for testing config that shares the same numeric port.
customConfig:
api:
enabled: false
sources:
syslog-tcp:
type: syslog
address: 0.0.0.0:514
max_length: 102400
mode: tcp
shutdown_timeout_secs: 30
syslog-udp:
type: syslog
address: 0.0.0.0:514
max_length: 102400
mode: udp
shutdown_timeout_secs: 30
sinks:
stdout:
type: console
inputs: ["syslog-*"]
encoding:
codec: json
@@ -0,0 +1,15 @@
# Including additional Volumes
## Values file for testing adding additional Volumes to Vector Pods.
extraVolumes:
- name: podinfo
downwardAPI:
items:
- path: "labels"
fieldRef:
fieldPath: metadata.labels
- path: "annotations"
fieldRef:
fieldPath: metadata.annotations
extraVolumeMounts:
- name: podinfo
mountPath: "/etc/podinfo"
@@ -0,0 +1,19 @@
# Including extraContainers and extraVolumes
## Values file for testing adding extraContainers and extraVolumeMounts to Vector Pods.
extraContainers:
- name: sleep
image: busybox
command: ['sh', '-c', "sleep 5"]
extraVolumes:
- name: podinfo
downwardAPI:
items:
- path: "labels"
fieldRef:
fieldPath: metadata.labels
- path: "annotations"
fieldRef:
fieldPath: metadata.annotations
extraVolumeMounts:
- name: podinfo
mountPath: "/etc/podinfo"
@@ -0,0 +1,6 @@
# Including extraContainers
## Values file for testing adding extraContainers to Vector Pods.
extraContainers:
- name: sleep
image: busybox
command: ['sh', '-c', "sleep 5"]
@@ -0,0 +1,7 @@
# Including haproxy.extraContainers
## Values file for testing adding extraContainers to HAProxy Pods.
haproxy:
extraContainers:
- name: sleep
image: busybox
command: ['sh', '-c', "sleep 5"]
@@ -0,0 +1,14 @@
# Including initContainers
## Values file for testing adding initContainers to Vector Pods.
initContainers:
- name: sleep
image: busybox
command: ['sh', '-c', "sleep 5"]
- name: touch
image: busybox
command:
- touch
- "/vector-data-dir/test"
volumeMounts:
- name: data
mountPath: "/vector-data-dir"
@@ -0,0 +1,11 @@
# Manually setting Ports
## Values file for testing manually setting ports and overriding automatically generated configuration.
containerPorts:
- name: override
containerPort: 9999
protocol: TCP
service:
ports:
- name: override
port: 9999
protocol: TCP
@@ -0,0 +1,8 @@
# Separately disable the Headless Service
## Values file for testing separate enabling for service and serviceHeadless.
service:
enabled: true
serviceHeadless:
enabled: false
@@ -0,0 +1,3 @@
# Stateless-Aggregator role
## Values file for testing default Agent parameters.
role: Stateless-Aggregator
@@ -0,0 +1,24 @@
# Using Vector's template syntax
## Values file for testing Vector's template syntax in `customConfig`.
customConfig:
data_dir: /data
api:
enabled: true
address: 127.0.0.1:8686
healthchecks:
enabled: false
sources:
generator:
type: demo_logs
format: json
sinks:
s3:
type: aws_s3
inputs: [generator]
bucket: logs-archive
key_prefix: >-
{{ print "{{kubernetes.pod_labels.\"app.kubernetes.io/client-id\"}}/%Y/%m/%d/{{kubernetes.pod_name}}/" }}
compression: gzip
encoding:
codec: json
region: us-east-1
@@ -0,0 +1,82 @@
# Migrate from `vector-agent` guide
To deploy the chart as a `DaemonSet`, set `role: "Agent"` in your `values.yaml` or with Helm arguments.
The `tolerations` option is no longer populated with default values, to match previous behavior you
can use the following:
```yaml
tolerations:
- key: node-role.kubernetes.io/master
effect: NoSchedule
```
There have been a couple minor changes to the default configuration:
- Vector's API is enabled
- A `console` sink is now included
- The default `prometheus_exporter` sink was renamed from "prometheus_sink" to "prom_exporter"
To keep the original defaults, use the following `customConfig`:
```yaml
customConfig:
data_dir: /vector-data-dir
api:
enabled: false
sources:
kubernetes_logs:
type: kubernetes_logs
host_metrics:
filesystem:
devices:
excludes: [binfmt_misc]
filesystems:
excludes: [binfmt_misc]
mountpoints:
excludes: ["*/proc/sys/fs/binfmt_misc"]
type: host_metrics
internal_metrics:
type: internal_metrics
sinks:
prometheus_sink:
type: prometheus_exporter
inputs: [host_metrics, internal_metrics]
address: 0.0.0.0:9090
```
## Upgrading
Once you have determined the changes you need to make to your `values.yaml` the upgrade is as simple as:
```bash
helm upgrade -f values.yaml <ORIGINAL_RELEASE_NAME> vector/vector -n <ORIGINAL_NAMESPACE>
```
## Vector values
| Old parameter | New parameter | Comment |
|--------------------------------------------------------|-----------------------------|---------------------------------------------------------------------------------------------------------|
| `dataVolume.hostPath.path` | `persistence.hostPath.path` | |
| `existingConfigMap` and `extraConfigDirSources` | `existingConfigMaps` | All ConfigMaps in the `existingConfigMaps` list are projected into Vector's configuration directory |
| `extraContainersPorts` | `containerPorts` | Ports will be automatically generated from `customConfig` but can be manually set with `containerPorts` |
| `globalOptions.*` | ∅ | Deprecated |
| `hostMetricsSource.*` | ∅ | Deprecated |
| `internalMetricsSource.*` | ∅ | Deprecated |
| `image.version`, `image.base` | ∅ | Only `image.tag` is now used to set the Vector tag |
| `imagePullSecrets` | `image.pullSecrets` | |
| `logSchema.*` | ∅ | Deprecated |
| `kubernetesLogsSource.*` | ∅ | Deprecated |
| `maxUnavailable` | ∅ | `maxUnavailable` should be passed in as part of the `updateStrategy` object |
| `podMonitor.additionalLabels` | ∅ | |
| `podMonitor.extraRelabelings` | `podMonitor.relabelings` | The chart adds no default relabelings |
| `podRollmeAnnotation` and`podValuesChecksumAnnotation` | ∅ | Replaced by `rollWorkload`, enabled by default |
| `prometheusSink.*` | ∅ | Deprecated |
| `psp.enabled` | `psp.create` | |
| `rbac.enabled` | `rbac.create` | |
| `secrets.generic` | ⚠️ | `secrets.generic` now takes raw values rather than base64 encoded values |
| `sinks.*` | ∅ | Deprecated |
| `sources.*` | ∅ | Deprecated |
| `transforms.*` | ∅ | Deprecated |
| `updateStrategy` | ⚠️ | `updateStrategy` now takes an object instead of a string |
| `vectorApi.*` | ∅ | Deprecated |
| `vectorSink.*` | ∅ | Deprecated |
@@ -0,0 +1,85 @@
# Migrate from `vector-aggregator` guide
By default, the chart will deploy Vector as a `StatefulSet` and the default `role` option should remain "Aggregator".
There have been a number of changes to the default configuration:
- Vector's API is enabled
- A `datadog_agent` source is now included
- A `fluent` source is now included
- A `logstash` source is now included
- A `splunk_hec` source is now included
- A `statsd` source is now included
- A `syslog` source is now included
- A `console` sink is now included
- The default `prometheus_exporter` sink was renamed from "prometheus_sink" to "prom_exporter"
To keep the original defaults, use the following `customConfig`:
```yaml
customConfig:
data_dir: /vector-data-dir
api:
enabled: false
sources:
vector:
address: 0.0.0.0:9000
type: vector
version: "2"
internal_metrics:
type: internal_metrics
sinks:
prometheus_sink:
type: prometheus_exporter
inputs: [internal_metrics]
address: 0.0.0.0:9090
```
## Upgrading
Once you have determined the changes you need to make to your `values.yaml` the upgrade is as simple as:
```bash
helm upgrade -f values.yaml <ORIGINAL_RELEASE_NAME> vector/vector -n <ORIGINAL_NAMESPACE>
```
## Vector values
| Old parameter | New parameter | Comment |
|--------------------------------------------------------|--------------------------------|-------------------------------------------------------------------------------------------------------------|
| `existingConfigMap` and `extraConfigDirSources` | `existingConfigMaps` | All ConfigMaps in the `existingConfigMaps` list are projected into Vector's configuration directory |
| `extraContainersPorts` | `containerPorts` | Ports will be automatically generated from `customConfig` but can be manually set with `containerPorts` |
| `global.clusterDomain` and `global.kubeDNSAddress` | ∅ | The paramters are set by default or by `haproxy.customConfig` or `haproxy.existingConfigMap` |
| `globalOptions.*` | ∅ | Deprecated |
| `internalMetricsSource.*` | ∅ | Deprecated |
| `image.version`, `image.base` | ∅ | Only `image.tag` is now used to set the Vector tag |
| `imagePullSecrets` | `image.pullSecrets` | |
| `logSchema.*` | ∅ | Deprecated |
| `podMonitor.additionalLabels` | ∅ | |
| `podMonitor.extraRelabelings` | `podMonitor.relabelings` | The chart adds no default relabelings |
| `podRollmeAnnotation` and`podValuesChecksumAnnotation` | ∅ | Replaced by `rollWorkload`, enabled by default |
| `prometheusSink.*` | ∅ | Deprecated |
| `psp.enabled` | `psp.create` | |
| `rbac.enabled` | `rbac.create` | |
| `secrets.generic` | ⚠️ | `secrets.generic` now takes raw values rather than base64 encoded values |
| `sinks.*` | ∅ | Deprecated |
| `sources.*` | ∅ | Deprecated |
| `storage.mode` | ∅ | If `persistence.enabled` a PersistentVolumeClaim will be created, unless `persistence.existingClaim` is set |
| `storage.hostPath` | ∅ | Vector running as an Aggregator no longer supports `hostPath` based storage |
| `storage.managedPersistentVolumeClaim.size` | `persistence.size` | |
| `storage.managedPersistentVolumeClaim.storageClass` | `persistence.storageClassName` | |
| `storage.existingPersistentVolumeClaim` | `persistence.existingClaim` | |
| `transforms.*` | ∅ | Deprecated |
| `vectorApi.*` | ∅ | Deprecated |
## HAProxy values
| Old parameter | New parameter | Comment |
|------------------------------------|----------------|---------------------------------------------------------------|
| `config` | `customConfig` | Default HAProxy config can be overwritten with `customConfig` |
| `mountedSecrets` | ∅ | |
| `podSecurityContext.*` | ⚠️ | `podSecurityContext` now takes an object |
| `replicaCount` | `replicas` | |
| `service.clusterIP` | ∅ | |
| `service.loadBalancerIP` | ∅ | |
| `service.loadBalancerSourceRanges` | ∅ | |
@@ -0,0 +1,174 @@
# Quickstart
In this quickstart guide, we will walk you through installing Vector with Helm
for a variety of common platforms and tools.
_NOTE: The instructions here assume the use of Helm v3, and Bash._
## Getting started with Datadog
### Prerequisites
Verify you have `helm` and `kubectl` installed locally to proceed. `helm` should
be `v3.0+`.
```bash
helm version
```
Ensure you have both the Datadog and Vector charts, and they are up-to-date.
```bash
helm repo add datadog https://helm.datadoghq.com
helm repo add vector https://helm.vector.dev
helm repo update
```
Access to a pre-existing Kubernetes cluster, or start a new cluster locally
with `minikube`.
```bash
minikube start
minikube addons enable metrics-server
minikube status
```
Clone this repository locally to have access to the quickstart values files.
```bash
git clone https://github.com/vectordotdev/helm-charts.git && \
cd helm-charts/charts/vector
```
### Installing
Export your Datadog API key into your local environment.
```bash
export DATADOG_API_KEY="<REPLACE_ME>"
```
Then install Vector into its own namespace, providing your API key as an
environment variable.
```bash
helm install vector vector/vector --namespace vector --create-namespace \
--values examples/datadog-values.yaml --set secrets.generic.datadog_api_key="${DATADOG_API_KEY}"
```
Run the next command to confirm Vector has been configured properly and can
connect to your Datadog account.
```bash
kubectl logs statefulset/vector --namespace vector --follow
```
Running the above will tail Vector's logs and allow to confirm your API key
is correct. In the logs you should only see INFO messages, and the following
logs (one for each configured sink):
```json lines
{"timestamp":"2022-03-30T20:25:48.016522Z","level":"INFO","message":"Healthcheck: Passed.","target":"vector::topology::builder"}
{"timestamp":"2022-03-30T20:25:48.024391Z","level":"INFO","message":"Healthcheck: Passed.","target":"vector::topology::builder"}
```
Once Vector has been installed and configured, you can install your Datadog Agents.
By default, the Agents will forward their logs and metrics directly to Datadog's
hosted intake, we'll create a values file to override that behavior to forward to
your new Vector Aggregators.
For Datadog Agents version `7.35`/`6.35` or greater:
```bash
cat <<-'VALUES' > dd-agent.yaml
---
datadog:
logs:
enabled: true
containerCollectAll: true
agents:
useConfigMap: true
customAgentConfig:
# NOTE: If you're using a quickstart environment like `minikube`,
# uncomment the line below; otherwise, we recommend leaving it with the
# default setting of `true`.
# kubelet_tls_verify: false
vector:
logs:
enabled: true
# Use https if SSL is enabled in Vector source configuration
url: http://vector-haproxy.vector:8282
metrics:
enabled: true
# Use https if SSL is enabled in Vector source configuration
url: http://vector-haproxy.vector:8282
VALUES
```
For Datadog Agents version `7.34`/`6.34` and older:
_NOTE: Metrics will not be routed through Vector for Datadog Agent versions older
than `7.35`/`6.35`._
```bash
cat <<-'VALUES' > dd-agent.yaml
---
datadog:
logs:
enabled: true
containerCollectAll: true
agents:
useConfigMap: true
customAgentConfig:
# NOTE: If you're using a quickstart environment like `minikube`,
# uncomment the line below; otherwise, we recommend leaving it with the
# default setting of `true`.
# kubelet_tls_verify: false
logs_config:
logs_dd_url: vector-haproxy.vector:8282
# Set to false if SSL is enabled in Vector source configuration
logs_no_ssl: true
use_http: true
VALUES
```
_NOTE: When you have the `datadog_agent` source configured, a `helm install` or
`helm upgrade` will output the appropriate values to provide to the datadog helm
chart._
```bash
helm install datadog datadog/datadog --namespace datadog --create-namespace \
--values dd-agent.yaml --set datadog.apiKey="${DATADOG_API_KEY}"
```
Once the Datadog Agents are running you should be able to see your logs in
Datadog's [Live Tail](https://app.datadoghq.com/logs/livetail?query=sender%3Avector) view,
by filtering for `sender:vector`. You can also use `vector top` to view Vector's
topology and related metrics:
```bash
kubectl --namespace vector exec --stdin --tty statefulset/vector -- vector top
```
### Troubleshooting
To diagnose problems the following commands may prove useful:
For Datadog Agents:
```bash
kubectl --namespace datadog exec --stdin --tty daemonset/datadog -- agent status
```
For the HAProxy:
```bash
kubectl --namespace vector logs --follow deployment/vector-haproxy
```
For the Vector Aggregators:
```bash
kubectl --namespace vector exec --stdin --tty statefulset/vector -- vector tap internal_logs
```
@@ -0,0 +1,185 @@
## See Vector helm documentation to learn more:
## https://vector.dev/docs/setup/installation/package-managers/helm/
# nameOverride -- Override name of app
fullnameOverride: vector
## Create a Secret resource for Vector to use
secrets:
# secrets.generic -- Each Key/Value will be added to the Secret's data key, each value should be raw and NOT base64 encoded
## Any secrets can be provided here, it's commonly used for credentials and other access related values.
## NOTE: Don't commit unencrypted secrets to git!
generic:
datadog_api_key: "REPLACE_ME"
## Configure a HorizontalPodAutoscaler for Vector
autoscaling:
enabled: true
minReplicas: 2
## The provided HAProxy config is limited to 10 backends
maxReplicas: 10
targetCPUUtilizationPercentage: 80
podDisruptionBudget:
enabled: true
minAvailable: 1
# env -- Set environment variables in Vector containers
## The examples below leverage examples from secrets.generic and assume no name overrides with a Release name of "vector"
env:
- name: DATADOG_API_KEY
valueFrom:
secretKeyRef:
name: vector
key: datadog_api_key
- name: VECTOR_LOG_FORMAT
value: json
# envFrom -- Define environment variables from Secrets or ConfigMaps
envFrom:
- secretRef:
name: vector
# resources -- Set Vector resource requests and limits.
resources:
## Required for HPA to function
requests:
cpu: 1000m
memory: 512Mi
# limits:
# cpu: 200m
# memory: 256Mi
# affinity -- Allow Vector to schedule using affinity rules
## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity
affinity:
## Scale across different AZs by default.
podAntiAffinity:
preferredDuringSchedulingIgnoredDuringExecution:
- weight: 100
podAffinityTerm:
labelSelector:
matchExpressions:
- key: app.kubernetes.io/name
operator: In
values:
- vector
- key: app.kubernetes.io/component
operator: In
values:
- Aggregator
topologyKey: topology.kubernetes.io/zone
# customConfig -- Override Vector's default configs, if used **all** options need to be specified
## This section supports using helm templates to populate dynamic values
## Ref: https://vector.dev/docs/reference/configuration/
customConfig:
data_dir: /vector-data-dir
api:
enabled: true
address: 0.0.0.0:8686
sources:
datadog_agent:
address: 0.0.0.0:8282
type: datadog_agent
multiple_outputs: true
internal_metrics:
type: internal_metrics
transforms:
remap_logs:
type: remap
inputs:
- datadog_agent.logs
source: |
# Parse the received .ddtags field so we can more easily access the contained tags
.ddtags = parse_key_value!(.ddtags, key_value_delimiter: ":", field_delimiter: ",")
.ddtags.sender = "vector"
.ddtags.vector_aggregator = get_hostname!()
# Re-encode Datadog tags as a string for the `datadog_logs` sink
.ddtags = encode_key_value(.ddtags, key_value_delimiter: ":", field_delimiter: ",")
# Datadog Agents pass a "status" field that is stripped when ingested
del(.status)
sinks:
datadog_logs:
type: datadog_logs
inputs:
- remap_logs
default_api_key: ${DATADOG_API_KEY}
compression: gzip
datadog_metrics:
type: datadog_metrics
inputs:
- datadog_agent.metrics
- internal_metrics
default_api_key: ${DATADOG_API_KEY}
# TODO: soon!
# datadog_traces:
# type: datadog_traces
# livenessProbe -- Override default liveness probe settings, if customConfig is used requires customConfig.api.enabled true
## Requires Vector's API to be enabled
livenessProbe:
httpGet:
path: /health
port: api
# readinessProbe -- Override default readiness probe settings, if customConfig is used requires customConfig.api.enabled true
## Requires Vector's API to be enabled
readinessProbe:
httpGet:
path: /health
port: api
## Optional built-in HAProxy load balancer
haproxy:
# haproxy.enabled -- If true, create a HAProxy load balancer
enabled: true
# haproxy.customConfig -- Override HAProxy's default configs, if used **all** options need to be specified.
# This parameter supports using Helm templates to insert values dynamically
## By default this chart will parse Vector's configuration from customConfig to generate HAProxy's config, this generated config
## can be overwritten with haproxy.customConfig
customConfig: |
global
log stdout format raw local0
maxconn 4096
stats socket /tmp/haproxy
hard-stop-after {{ .Values.haproxy.terminationGracePeriodSeconds }}s
defaults
log global
option dontlognull
retries 3
option redispatch
option allbackups
timeout client 5s
timeout server 5s
timeout connect 5s
resolvers coredns
nameserver dns1 kube-dns.kube-system.svc.cluster.local:53
resolve_retries 3
timeout resolve 2s
timeout retry 1s
accepted_payload_size 8192
hold valid 10s
hold obsolete 60s
frontend stats
mode http
bind :::1024
option httplog
http-request use-service prometheus-exporter if { path /metrics }
frontend datadog-agent
mode http
bind :::8282
option httplog
default_backend datadog-agent
backend datadog-agent
mode http
balance roundrobin
option tcp-check
server-template srv 10 _datadog-agent._tcp.{{ include "vector.fullname" $ }}-headless.{{ $.Release.Namespace }}.svc.cluster.local resolvers coredns check
@@ -0,0 +1,10 @@
{{ template "_divider" }}
{{ include "_logo" . | indent 34 }}
{{ template "_divider" }}
{{ include "_vector.top" . }}
{{ if not .Values.quiet }}{{ include "_configure.datadog" . }}{{ end }}
@@ -0,0 +1,402 @@
{{/*
Expand the name of the chart.
*/}}
{{- define "vector.name" -}}
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
{{- end }}
{{/*
Set the image tag when `base` is used to allow for updates that are pinned
to a specific base OS, but not to a specific version.
This assumes that the `appVersion` has a prefix of the actual version followed
by the default OS.
A manual tag takes precedence over everything else
*/}}
{{- define "vector.image.tag" -}}
{{- $version := .Chart.AppVersion }}
{{- if .Values.image.tag }}
{{- $version = .Values.image.tag }}
{{- else if .Values.image.base }}
{{- $version = (printf "%s-%s" (first (splitList "-" $version)) .Values.image.base) }}
{{- end }}
{{- printf "%s" $version }}
{{- end }}
{{/*
Build a valid image reference from available fields:
- tag only: repo:tag
- sha/digest only: repo@sha256:…
- tag@digest: repo:tag@sha256:…
- nothing set: repo:<Chart.AppVersion>
*/}}
{{- define "vector.image" -}}
{{- $repo := .Values.image.repository | default "timberio/vector" -}}
{{- $tagRaw := include "vector.image.tag" . | default "" -}}
{{- $shaRaw := (coalesce .Values.image.sha .Values.image.digest) | default "" -}}
{{- $tag := trim $tagRaw -}}
{{- /* Normalize SHA to ensure it has sha256: prefix for backward compatibility */ -}}
{{- $sha := "" -}}
{{- if $shaRaw -}}
{{- if hasPrefix "sha256:" $shaRaw -}}
{{- $sha = $shaRaw -}}
{{- else -}}
{{- $sha = printf "sha256:%s" $shaRaw -}}
{{- end -}}
{{- end -}}
{{- /* Case 1: digest field wins */ -}}
{{- if $sha -}}
{{- if $tag -}}
{{- printf "%s:%s@%s" $repo $tag $sha -}}
{{- else -}}
{{- printf "%s@%s" $repo $sha -}}
{{- end -}}
{{- /* Case 2: tag looks like a digest */ -}}
{{- else if hasPrefix "sha256:" $tag -}}
{{- printf "%s@%s" $repo $tag -}}
{{- /* Case 3: tag@digest combined syntax */ -}}
{{- else if contains "@sha256:" $tag -}}
{{- $parts := splitList "@" $tag -}}
{{- printf "%s:%s@%s" $repo (index $parts 0) (index $parts 1) -}}
{{- /* Case 4: normal tag */ -}}
{{- else if $tag -}}
{{- printf "%s:%s" $repo $tag -}}
{{- /* Fallback: use chart app version */ -}}
{{- else -}}
{{- printf "%s:%s" $repo .Chart.AppVersion -}}
{{- end -}}
{{- end -}}
{{/*
Create a default fully qualified app name.
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
If release name contains chart name it will be used as a full name.
*/}}
{{- define "vector.fullname" -}}
{{- if .Values.fullnameOverride }}
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
{{- else }}
{{- $name := default .Chart.Name .Values.nameOverride }}
{{- if contains $name .Release.Name }}
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
{{- else }}
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
{{- end }}
{{- end }}
{{- end }}
{{/*
Create chart name and version as used by the chart label.
*/}}
{{- define "vector.chart" -}}
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
{{- end }}
{{/*
Common labels.
*/}}
{{- define "vector.labels" -}}
helm.sh/chart: {{ include "vector.chart" . }}
{{ include "vector.selectorLabels" . }}
{{- if .Chart.AppVersion }}
app.kubernetes.io/version: {{ include "vector.image.tag" . | quote }}
{{- end }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{ with .Values.commonLabels }}
{{- toYaml . -}}
{{- end }}
{{- end }}
{{/*
Selector labels.
*/}}
{{- define "vector.selectorLabels" -}}
app.kubernetes.io/name: {{ include "vector.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
{{- if or (ne .Values.role "Agent") (ne .Values.role "Aggregator") (ne .Values.role "Stateless-Aggregator") }}
app.kubernetes.io/component: {{ .Values.role }}
{{- end }}
{{- end }}
{{/*
Create the name of the service account to use.
*/}}
{{- define "vector.serviceAccountName" -}}
{{- if .Values.serviceAccount.create }}
{{- default (include "vector.fullname" .) .Values.serviceAccount.name }}
{{- else }}
{{- default "default" .Values.serviceAccount.name }}
{{- end }}
{{- end }}
{{/*
Return the appropriate apiVersion for PodDisruptionBudget policy APIs.
*/}}
{{- define "policy.poddisruptionbudget.apiVersion" -}}
"policy/v1"
{{- end -}}
{{/*
Return the appropriate apiVersion for HPA autoscaling APIs.
*/}}
{{- define "autoscaling.apiVersion" -}}
"autoscaling/v2"
{{- end -}}
{{/*
Generate an array of ServicePorts based on `.Values.customConfig`.
*/}}
{{- define "vector.ports" -}}
{{- range $componentKind, $components := .Values.customConfig }}
{{- if eq $componentKind "sources" }}
{{- tuple $components "_helper.generatePort" | include "_helper.componentIter" }}
{{- else if eq $componentKind "sinks" }}
{{- tuple $components "_helper.generatePort" | include "_helper.componentIter" }}
{{- else if eq $componentKind "api" }}
{{- if $components.enabled }}
- name: api
port: {{ mustRegexFind "[0-9]+$" (get $components "address") }}
protocol: TCP
targetPort: {{ mustRegexFind "[0-9]+$" (get $components "address") }}
{{- end }}
{{- end }}
{{- end }}
{{- end }}
{{/*
Iterate over the components defined in `.Values.customConfig`.
*/}}
{{- define "_helper.componentIter" -}}
{{- $components := index . 0 }}
{{- $helper := index . 1 }}
{{- range $id, $options := $components }}
{{- if (hasKey $options "address") }}
{{- tuple $id $options | include $helper -}}
{{- end }}
{{- end }}
{{- end }}
{{/*
Generate a single ServicePort based on a component configuration.
*/}}
{{- define "_helper.generatePort" -}}
{{- $name := index . 0 | kebabcase -}}
{{- $config := index . 1 -}}
{{- $port := mustRegexFind "[0-9]+$" (get $config "address") -}}
{{- $protocol := default "TCP" (get $config "mode" | upper) }}
- name: {{ $name }}
port: {{ $port }}
protocol: {{ $protocol }}
targetPort: {{ $port }}
{{- if not (mustHas $protocol (list "TCP" "UDP")) }}
{{ fail "Component's `mode` is not a supported protocol, please raise a issue at https://github.com/vectordotdev/vector" }}
{{- end }}
{{- end }}
{{/*
Generate an array of ContainerPorts based on `.Values.customConfig`.
*/}}
{{- define "vector.containerPorts" -}}
{{- range $componentKind, $components := .Values.customConfig }}
{{- if eq $componentKind "sources" }}
{{- tuple $components "_helper.generateContainerPort" | include "_helper.componentIter" }}
{{- else if eq $componentKind "sinks" }}
{{- tuple $components "_helper.generateContainerPort" | include "_helper.componentIter" }}
{{- else if eq $componentKind "api" }}
{{- if $components.enabled }}
- name: api
containerPort: {{ mustRegexFind "[0-9]+$" (get $components "address") }}
protocol: TCP
{{- end }}
{{- end }}
{{- end }}
{{- end }}
{{/*
Generate a single ContainerPort based on a component configuration.
*/}}
{{- define "_helper.generateContainerPort" -}}
{{- $name := index . 0 | kebabcase -}}
{{- $config := index . 1 -}}
{{- $port := mustRegexFind "[0-9]+$" (get $config "address") -}}
{{- $protocol := default "TCP" (get $config "mode" | upper) }}
- name: {{ $name | trunc 15 | trimSuffix "-" }}
containerPort: {{ $port }}
protocol: {{ $protocol }}
{{- if not (mustHas $protocol (list "TCP" "UDP")) }}
{{ fail "Component's `mode` is not a supported protocol, please raise a issue at https://github.com/vectordotdev/vector" }}
{{- end }}
{{- end }}
{{/*
Print Vector's logo.
*/}}
{{- define "_logo" -}}
{{ print "__ __ __" }}
{{ print "\\ \\ / / / /" }}
{{ print " \\ V / / / " }}
{{ print " \\_/ \\/ " }}
{{ print "V E C T O R" }}
{{- end }}
{{/*
Print line divider.
*/}}
{{- define "_divider" -}}
{{ print "--------------------------------------------------------------------------------" }}
{{- end }}
{{/*
Print `vector top` instructions.
*/}}
{{- define "_vector.top" -}}
{{- if eq "true" (include "_vector.apiEnabled" $) -}}
{{ print "Vector is starting in your cluster. After a few minutes, you can use Vector's" }}
{{ println "API to view internal metrics by running:" }}
{{- $resource := include "_vector.role" $ -}}
{{- $url := include "_vector.url" $ }}
$ kubectl -n {{ $.Release.Namespace }} exec -it {{ $resource }}/{{ include "vector.fullname" $ }} -- vector top {{ $url }}
{{- else -}}
{{- $resource := include "_vector.role" $ -}}
{{ print "Vector is starting in your cluster. After a few minutes, you can view Vector's" }}
{{ println "internal logs by running:" }}
$ kubectl -n {{ $.Release.Namespace }} logs -f {{ $resource }}/{{ include "vector.fullname" $ }}
{{- end }}
{{- end }}
{{/*
Return `true` if we can determine if Vector's API is enabled.
*/}}
{{- define "_vector.apiEnabled" -}}
{{- if $.Values.existingConfigMaps -}}
false
{{- else if $.Values.customConfig -}}
{{- if $.Values.customConfig.api -}}
{{- if $.Values.customConfig.api.enabled -}}
true
{{- end }}
{{- end }}
{{- else -}}
true
{{- end }}
{{- end }}
{{/*
Return Vector's Resource type based on its `.Values.role`.
*/}}
{{- define "_vector.role" -}}
{{- if eq $.Values.role "Stateless-Aggregator" -}}
deployment
{{- else if eq $.Values.role "Agent" -}}
daemonset
{{- else -}}
statefulset
{{- end -}}
{{- end }}
{{/*
Print the `url` option for the Vector command.
*/}}
{{- define "_vector.url" -}}
{{- if $.Values.customConfig -}}
{{- if $.Values.customConfig.api -}}
{{- if $.Values.customConfig.api.address -}}
{{ print "\\" }}
--url {{ printf "http://%s/graphql" $.Values.customConfig.api.address }}
{{- end }}
{{- end }}
{{- end }}
{{- end }}
{{/*
Configuring Datadog Agents to forward to Vector.
This is really alpha level, and should be refactored
to be more generally usable for other components.
*/}}
{{- define "_configure.datadog" -}}
{{- $hasSourceDatadogAgent := false }}
{{- $sourceDatadogAgentPort := "" }}
{{- $hasTls := "" }}
{{- $protocol := "http" }}
{{- range $componentKind, $configs := .Values.customConfig }}
{{- if eq $componentKind "sources" }}
{{- range $componentId, $componentConfig := $configs }}
{{- if eq (get $componentConfig "type") "datadog_agent" }}
{{- $hasSourceDatadogAgent = true }}
{{- $sourceDatadogAgentPort = mustRegexFind "[0-9]+$" (get $componentConfig "address") }}
{{- if (hasKey $componentConfig "tls") }}
{{- $tlsOpts := get $componentConfig "tls" }}
{{- $hasTls = get $tlsOpts "enabled" }}
{{- if $hasTls }}{{ $protocol = "https" }}{{ end }}
{{- end }}
{{- end }}
{{- end }}
{{- end }}
{{- end }}
{{- if or (not .Values.customConfig) (and .Values.customConfig $hasSourceDatadogAgent) }}
{{- template "_divider" }}
{{ print "datadog_agent:" }}
To forward logs from Datadog Agents deployed with the "datadog" Helm chart,
include the following in the "values.yaml" for your "datadog" chart:
For Datadog Agents version "7.34"/"6.34" or lower:
datadog:
containerExclude: "name:vector"
logs:
enabled: true
containerCollectAll: true
agents:
useConfigMap: true
customAgentConfig:
kubelet_tls_verify: false
logs_config:
{{- if .Values.haproxy.enabled }}
logs_dd_url: "{{ include "haproxy.fullname" $ }}.{{ $.Release.Namespace }}:{{ $sourceDatadogAgentPort | default "8282" }}"
{{- else }}
logs_dd_url: "{{ include "vector.fullname" $ }}.{{ $.Release.Namespace }}:{{ $sourceDatadogAgentPort | default "8282" }}"
{{- end }}
{{- if $hasTls }}
logs_no_ssl: false
{{- else }}
logs_no_ssl: true
{{- end }}
use_http: true
{{- end }}
For Datadog Agents version "7.35"/"6.35" or greater:
datadog:
containerExclude: "name:vector"
logs:
enabled: true
containerCollectAll: true
agents:
useConfigMap: true
customAgentConfig:
kubelet_tls_verify: false
vector:
logs:
enabled: true
{{- if .Values.haproxy.enabled }}
url: "{{ $protocol }}://{{ include "haproxy.fullname" $ }}.{{ $.Release.Namespace }}:{{ $sourceDatadogAgentPort | default "8282" }}"
{{- else }}
url: "{{ $protocol }}://{{ include "vector.fullname" $ }}.{{ $.Release.Namespace }}:{{ $sourceDatadogAgentPort | default "8282" }}"
{{- end }}
metrics:
enabled: true
{{- if .Values.haproxy.enabled }}
url: "{{ $protocol }}://{{ include "haproxy.fullname" $ }}.{{ $.Release.Namespace }}:{{ $sourceDatadogAgentPort | default "8282" }}"
{{- else }}
url: "{{ $protocol }}://{{ include "vector.fullname" $ }}.{{ $.Release.Namespace }}:{{ $sourceDatadogAgentPort | default "8282" }}"
{{- end }}
{{- end }}
@@ -0,0 +1,222 @@
{{/*
Defines the PodSpec for Vector.
*/}}
{{- define "vector.pod" -}}
serviceAccountName: {{ include "vector.serviceAccountName" . }}
{{- with .Values.podHostNetwork }}
hostNetwork: {{ . }}
{{- end }}
{{- with .Values.podSecurityContext }}
securityContext:
{{ toYaml . | indent 2 }}
{{- end }}
{{- with .Values.podPriorityClassName }}
priorityClassName: {{ . }}
{{- end }}
{{- with .Values.shareProcessNamespace }}
shareProcessNamespace: {{ . }}
{{- end }}
{{- with .Values.dnsPolicy }}
dnsPolicy: {{ . }}
{{- end }}
{{- with .Values.dnsConfig }}
dnsConfig:
{{ toYaml . | indent 2 }}
{{- end }}
{{- with .Values.image.pullSecrets }}
imagePullSecrets:
{{ toYaml . | indent 2 }}
{{- end }}
{{- with .Values.hostAliases }}
hostAliases:
{{ toYaml . | indent 2 }}
{{- end }}
{{- if .Values.initContainers }}
initContainers:
{{- tpl (toYaml .Values.initContainers) . | nindent 2 }}
{{- end }}
containers:
- name: vector
{{- with .Values.securityContext }}
securityContext:
{{ toYaml . | indent 6 }}
{{- end }}
image: "{{ include "vector.image" . }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
{{- with .Values.command }}
command:
{{- toYaml . | nindent 6 }}
{{- end }}
{{- with .Values.args }}
args:
{{- toYaml . | nindent 6 }}
{{- end }}
env:
- name: VECTOR_LOG
value: "{{ .Values.logLevel | default "info" }}"
{{- if .Values.env }}
{{- with .Values.env }}
{{- toYaml . | nindent 6 }}
{{- end }}
{{- end }}
{{- if (eq .Values.role "Agent") }}
- name: VECTOR_SELF_NODE_NAME
valueFrom:
fieldRef:
fieldPath: spec.nodeName
- name: VECTOR_SELF_POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: VECTOR_SELF_POD_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- name: PROCFS_ROOT
value: "/host/proc"
- name: SYSFS_ROOT
value: "/host/sys"
{{- end }}
{{- if .Values.envFrom }}
{{- with .Values.envFrom }}
envFrom:
{{- toYaml . | nindent 6 }}
{{- end }}
{{- end }}
ports:
{{- if or .Values.containerPorts .Values.existingConfigMaps }}
{{- toYaml .Values.containerPorts | nindent 6 }}
{{- else if .Values.customConfig }}
{{- include "vector.containerPorts" . | indent 6 }}
{{- else if or (eq .Values.role "Aggregator") (eq .Values.role "Stateless-Aggregator") }}
- name: datadog-agent
containerPort: 8282
protocol: TCP
- name: fluent
containerPort: 24224
protocol: TCP
- name: logstash
containerPort: 5044
protocol: TCP
- name: splunk-hec
containerPort: 8080
protocol: TCP
- name: statsd
containerPort: 8125
protocol: TCP
- name: syslog
containerPort: 9000
protocol: TCP
- name: vector
containerPort: 6000
protocol: TCP
- name: prom-exporter
containerPort: 9090
protocol: TCP
{{- else if (eq .Values.role "Agent") }}
- name: prom-exporter
containerPort: 9090
protocol: TCP
{{- end }}
{{- with .Values.livenessProbe }}
livenessProbe:
{{- toYaml . | trim | nindent 6 }}
{{- end }}
{{- if .Values.readinessProbe }}
readinessProbe:
{{- toYaml .Values.readinessProbe | trim | nindent 6 }}
{{- else if and (not .Values.existingConfigMaps) (not .Values.customConfig) }}
readinessProbe:
httpGet:
path: /health
port: 8686
{{- end }}
{{- with .Values.startupProbe }}
startupProbe:
{{- toYaml . | trim | nindent 6 }}
{{- end }}
{{- with .Values.resources }}
resources:
{{- toYaml . | nindent 6 }}
{{- end }}
{{- with .Values.lifecycle }}
lifecycle:
{{- toYaml . | nindent 6 }}
{{- end }}
volumeMounts:
- name: data
{{- if .Values.existingConfigMaps }}
mountPath: "{{ if .Values.dataDir }}{{ .Values.dataDir }}{{ else }}{{ fail "Specify `dataDir` if you're using `existingConfigMaps`" }}{{ end }}"
{{- else }}
mountPath: "{{ .Values.customConfig.data_dir | default "/vector-data-dir" }}"
{{- end }}
- name: config
mountPath: "/etc/vector/"
readOnly: true
{{- if (eq .Values.role "Agent") }}
{{- with .Values.defaultVolumeMounts }}
{{- toYaml . | nindent 6 }}
{{- end }}
{{- end }}
{{- with .Values.extraVolumeMounts }}
{{- toYaml . | nindent 6 }}
{{- end }}
{{- if .Values.extraContainers }}
{{- tpl (toYaml .Values.extraContainers) . | nindent 2 }}
{{- end }}
terminationGracePeriodSeconds: {{ .Values.terminationGracePeriodSeconds }}
{{- with .Values.nodeSelector }}
nodeSelector:
{{ toYaml . | indent 2 }}
{{- end }}
{{- with .Values.affinity }}
affinity:
{{ toYaml . | indent 2 }}
{{- end }}
{{- with .Values.tolerations }}
tolerations:
{{ toYaml . | indent 2 }}
{{- end }}
{{- with .Values.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 2 }}
{{- end }}
volumes:
{{- if and .Values.persistence.enabled (eq .Values.role "Aggregator") }}
{{- with .Values.persistence.existingClaim }}
- name: data
persistentVolumeClaim:
claimName: {{ . }}
{{- end }}
{{- else if (ne .Values.role "Agent") }}
- name: data
emptyDir: {}
{{- end }}
- name: config
projected:
sources:
{{- if .Values.existingConfigMaps }}
{{- range .Values.existingConfigMaps }}
- configMap:
name: {{ . }}
{{- end }}
{{- else }}
- configMap:
name: {{ template "vector.fullname" . }}
{{- end }}
{{- if (eq .Values.role "Agent") }}
- name: data
{{- if .Values.persistence.hostPath.enabled }}
hostPath:
path: {{ .Values.persistence.hostPath.path | quote }}
{{- else }}
emptyDir: {}
{{- end }}
{{- with .Values.defaultVolumes }}
{{- toYaml . | nindent 2 }}
{{- end }}
{{- end }}
{{- with .Values.extraVolumes }}
{{- toYaml . | nindent 2 }}
{{- end }}
{{- end }}
@@ -0,0 +1,87 @@
{{- if not .Values.existingConfigMaps }}
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ include "vector.fullname" . }}
namespace: {{ .Release.Namespace | quote }}
labels:
{{- include "vector.labels" . | nindent 4 }}
data:
{{- if .Values.customConfig }}
vector.yaml: |
{{ tpl (toYaml .Values.customConfig) . | indent 4 }}
{{- else if or (eq .Values.role "Aggregator") (eq .Values.role "Stateless-Aggregator") }}
aggregator.yaml: |
data_dir: /vector-data-dir
api:
enabled: true
address: 0.0.0.0:8686
sources:
datadog_agent:
address: 0.0.0.0:8282
type: datadog_agent
fluent:
address: 0.0.0.0:24224
type: fluent
internal_metrics:
type: internal_metrics
logstash:
address: 0.0.0.0:5044
type: logstash
splunk_hec:
address: 0.0.0.0:8080
type: splunk_hec
statsd:
address: 0.0.0.0:8125
mode: tcp
type: statsd
syslog:
address: 0.0.0.0:9000
mode: tcp
type: syslog
vector:
address: 0.0.0.0:6000
type: vector
version: "2"
sinks:
prom_exporter:
type: prometheus_exporter
inputs: [internal_metrics]
address: 0.0.0.0:9090
stdout:
type: console
inputs: [datadog_agent, fluent, logstash, splunk_hec, statsd, syslog, vector]
encoding:
codec: json
{{- else if (eq .Values.role "Agent") }}
agent.yaml: |
data_dir: /vector-data-dir
api:
enabled: true
address: 0.0.0.0:8686
sources:
kubernetes_logs:
type: kubernetes_logs
host_metrics:
filesystem:
devices:
excludes: [binfmt_misc]
filesystems:
excludes: [binfmt_misc]
mountpoints:
excludes: ["*/proc/sys/fs/binfmt_misc"]
type: host_metrics
internal_metrics:
type: internal_metrics
sinks:
prom_exporter:
type: prometheus_exporter
inputs: [host_metrics, internal_metrics]
address: 0.0.0.0:9090
stdout:
type: console
inputs: [kubernetes_logs]
encoding:
codec: json
{{- end }}
{{- end }}
@@ -0,0 +1,55 @@
{{- if (eq .Values.role "Agent") -}}
apiVersion: {{ .Values.daemonSet.apiVersion | default "apps/v1" }}
kind: DaemonSet
metadata:
name: {{ include "vector.fullname" . }}
namespace: {{ .Release.Namespace | quote }}
labels:
{{- include "vector.labels" . | nindent 4 }}
{{- with .Values.workloadResourceAnnotations }}
annotations:
{{- toYaml . | nindent 4 }}
{{- end }}
spec:
{{- with .Values.revisionHistoryLimit }}
revisionHistoryLimit: {{ . }}
{{- end }}
selector:
matchLabels:
{{- include "vector.selectorLabels" . | nindent 6 }}
minReadySeconds: {{ .Values.minReadySeconds }}
{{- with .Values.updateStrategy }}
updateStrategy:
{{- toYaml . | nindent 4 }}
{{- end }}
template:
metadata:
annotations:
{{- if .Values.rollWorkload }}
{{- if .Values.existingConfigMaps }}
{{- range .Values.existingConfigMaps }}
{{- range $file, $contents := (lookup "v1" "ConfigMap" (print $.Release.Namespace) (print .)).data }}
checksum/{{ $file }}: {{ $contents | sha256sum }}
{{- end }}
{{- end }}
{{- else }}
checksum/config: {{ include (print $.Template.BasePath "/configmap.yaml") . | sha256sum }}
{{- end }}
{{- end }}
{{- if .Values.rollWorkloadSecrets }}
checksum/secrets: {{ include (print $.Template.BasePath "/secret.yaml") . | sha256sum }}
{{- end }}
{{- if .Values.rollWorkloadExtraObjects }}
checksum/extraObjects: {{ include (print $.Template.BasePath "/extra-manifests.yaml") . | sha256sum }}
{{- end }}
{{- with .Values.podAnnotations }}
{{- toYaml . | nindent 8 }}
{{- end }}
labels:
{{- include "vector.selectorLabels" . | nindent 8 }}
{{- with .Values.podLabels }}
{{- toYaml . | nindent 8 }}
{{- end }}
spec:
{{- include "vector.pod" . | nindent 6 }}
{{- end }}
@@ -0,0 +1,56 @@
{{- if (eq .Values.role "Stateless-Aggregator") -}}
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "vector.fullname" . }}
namespace: {{ .Release.Namespace | quote }}
labels:
{{- include "vector.labels" . | nindent 4 }}
annotations:
{{- toYaml .Values.workloadResourceAnnotations | nindent 4 }}
spec:
{{- with .Values.revisionHistoryLimit }}
revisionHistoryLimit: {{ . }}
{{- end }}
{{- if not (or .Values.autoscaling.enabled .Values.autoscaling.external) }}
replicas: {{ .Values.replicas }}
{{- end }}
selector:
matchLabels:
{{- include "vector.selectorLabels" . | nindent 6 }}
minReadySeconds: {{ .Values.minReadySeconds }}
{{- with .Values.updateStrategy }}
strategy:
{{- toYaml . | nindent 4 }}
{{- end }}
template:
metadata:
annotations:
{{- if .Values.rollWorkload }}
{{- if .Values.existingConfigMaps }}
{{- range .Values.existingConfigMaps }}
{{- range $file, $contents := (lookup "v1" "ConfigMap" (print $.Release.Namespace) (print .)).data }}
checksum/{{ $file }}: {{ $contents | sha256sum }}
{{- end }}
{{- end }}
{{- else }}
checksum/config: {{ include (print $.Template.BasePath "/configmap.yaml") . | sha256sum }}
{{- end }}
{{- end }}
{{- if .Values.rollWorkloadSecrets }}
checksum/secrets: {{ include (print $.Template.BasePath "/secret.yaml") . | sha256sum }}
{{- end }}
{{- if .Values.rollWorkloadExtraObjects }}
checksum/extraObjects: {{ include (print $.Template.BasePath "/extra-manifests.yaml") . | sha256sum }}
{{- end }}
{{- with .Values.podAnnotations }}
{{- toYaml . | nindent 8 }}
{{- end }}
labels:
{{- include "vector.selectorLabels" . | nindent 8 }}
{{- with .Values.podLabels }}
{{- toYaml . | nindent 8 }}
{{- end }}
spec:
{{- include "vector.pod" . | nindent 6 }}
{{- end }}
@@ -0,0 +1,4 @@
{{ range .Values.extraObjects }}
---
{{ tpl (toYaml .) $ }}
{{ end }}
@@ -0,0 +1,47 @@
{{/*
Create a default fully qualified app name.
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
If release name contains chart name it will be used as a full name.
*/}}
{{- define "haproxy.fullname" -}}
{{- printf "%s-haproxy" (include "vector.fullname" .) | trunc 63 | trimSuffix "-" }}
{{- end }}
{{/*
Common labels
*/}}
{{- define "haproxy.labels" -}}
helm.sh/chart: {{ include "vector.chart" . }}
{{ include "haproxy.selectorLabels" . }}
{{- if .Chart.AppVersion }}
app.kubernetes.io/version: {{ .Values.haproxy.image.tag | quote }}
{{- end }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{/*
Selector labels
*/}}
{{- define "haproxy.selectorLabels" -}}
app.kubernetes.io/name: {{ include "vector.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
app.kubernetes.io/component: load-balancer
{{- end }}
{{/*
Create the name of the service account to use
*/}}
{{- define "haproxy.serviceAccountName" -}}
{{- if .Values.haproxy.serviceAccount.create }}
{{- default (include "haproxy.fullname" .) .Values.haproxy.serviceAccount.name }}
{{- else }}
{{- default "default" .Values.haproxy.serviceAccount.name }}
{{- end }}
{{- end }}
{{/*
Return the appropriate apiVersion for HPA autoscaling APIs.
*/}}
{{- define "autoscaling.apiVersion" -}}
"autoscaling/v2"
{{- end -}}
@@ -0,0 +1,129 @@
{{- if and .Values.haproxy.enabled (not .Values.haproxy.existingConfigMap) }}
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ include "haproxy.fullname" . }}
namespace: {{ .Release.Namespace | quote }}
labels:
{{- include "haproxy.labels" . | nindent 4 }}
data:
haproxy.cfg: |
{{- if .Values.haproxy.customConfig }}
{{ tpl .Values.haproxy.customConfig . | nindent 4 }}
{{- else }}
global
log stdout format raw local0
maxconn 4096
stats socket /tmp/haproxy
hard-stop-after {{ .Values.haproxy.terminationGracePeriodSeconds }}s
defaults
log global
option dontlognull
retries 3
option redispatch
option allbackups
timeout client 5s
timeout server 5s
timeout connect 5s
resolvers coredns
nameserver dns1 kube-dns.kube-system.svc.cluster.local:53
resolve_retries 3
timeout resolve 2s
timeout retry 1s
accepted_payload_size 8192
hold valid 10s
hold obsolete 60s
frontend stats
mode http
bind :::1024
option httplog
http-request use-service prometheus-exporter if { path /metrics }
frontend datadog-agent
mode http
bind :::8282
option httplog
default_backend datadog-agent
frontend fluent
mode tcp
bind :::24224
option tcplog
default_backend fluent
frontend logstash
mode tcp
bind :::5044
option tcplog
default_backend logstash
frontend splunk-hec
mode http
bind :::8080
option httplog
default_backend splunk-hec
frontend statsd
mode tcp
bind :::8125
option tcplog
default_backend statsd
frontend syslog
mode tcp
bind :::9000
option tcplog
default_backend syslog
frontend vector
mode http
bind :::6000 proto h2
option httplog
default_backend vector
backend datadog-agent
mode http
balance roundrobin
option tcp-check
server-template srv 10 _datadog-agent._tcp.{{ include "vector.fullname" $ }}-headless.{{ $.Release.Namespace }}.svc.cluster.local resolvers coredns check
backend fluent
mode tcp
balance roundrobin
option tcp-check
server-template srv 10 _fluent._tcp.{{ include "vector.fullname" $ }}-headless.{{ $.Release.Namespace }}.svc.cluster.local resolvers coredns check
backend logstash
mode tcp
balance roundrobin
option tcp-check
server-template srv 10 _logstash._tcp.{{ include "vector.fullname" $ }}-headless.{{ $.Release.Namespace }}.svc.cluster.local resolvers coredns check
backend splunk-hec
mode http
balance roundrobin
option tcp-check
server-template srv 10 _splunk-hec._tcp.{{ include "vector.fullname" $ }}-headless.{{ $.Release.Namespace }}.svc.cluster.local resolvers coredns check
backend statsd
mode tcp
balance roundrobin
option tcp-check
server-template srv 10 _statsd._tcp.{{ include "vector.fullname" $ }}-headless.{{ $.Release.Namespace }}.svc.cluster.local resolvers coredns check
backend syslog
mode tcp
balance roundrobin
option tcp-check
server-template srv 10 _syslog._tcp.{{ include "vector.fullname" $ }}-headless.{{ $.Release.Namespace }}.svc.cluster.local resolvers coredns check
backend vector
mode http
balance roundrobin
option tcp-check
server-template srv 10 _vector._tcp.{{ include "vector.fullname" $ }}-headless.{{ $.Release.Namespace }}.svc.cluster.local resolvers coredns proto h2 check
{{- end }}
{{- end }}
@@ -0,0 +1,139 @@
{{- if .Values.haproxy.enabled }}
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "haproxy.fullname" . }}
namespace: {{ .Release.Namespace | quote }}
labels:
{{- include "haproxy.labels" . | nindent 4 }}
spec:
{{- if not (or .Values.haproxy.autoscaling.enabled .Values.haproxy.autoscaling.external) }}
replicas: {{ .Values.haproxy.replicas }}
{{- end }}
selector:
matchLabels:
{{- include "haproxy.selectorLabels" . | nindent 6 }}
{{- with .Values.haproxy.strategy }}
strategy:
{{- toYaml . | nindent 4 }}
{{- end }}
template:
metadata:
annotations:
{{- if .Values.haproxy.rollWorkload }}
checksum/config: {{ include (print $.Template.BasePath "/haproxy/configmap.yaml") . | sha256sum }}
{{- end }}
{{- with .Values.haproxy.podAnnotations }}
{{- toYaml . | nindent 8 }}
{{- end }}
labels:
{{- include "haproxy.selectorLabels" . | nindent 8 }}
{{- with .Values.haproxy.podLabels }}
{{- toYaml . | nindent 8 }}
{{- end }}
spec:
{{- with .Values.haproxy.image.pullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
serviceAccountName: {{ include "haproxy.serviceAccountName" . }}
securityContext:
{{- toYaml .Values.haproxy.podSecurityContext | nindent 8 }}
terminationGracePeriodSeconds: {{ .Values.haproxy.terminationGracePeriodSeconds }}
{{- with .Values.haproxy.podPriorityClassName }}
priorityClassName: {{ . }}
{{- end }}
{{- if .Values.haproxy.initContainers }}
initContainers:
{{- tpl (toYaml .Values.haproxy.initContainers) . | nindent 8 }}
{{- end }}
containers:
- name: haproxy
securityContext:
{{- toYaml .Values.haproxy.securityContext | nindent 12 }}
image: "{{ .Values.haproxy.image.repository }}:{{ .Values.haproxy.image.tag }}"
imagePullPolicy: {{ .Values.haproxy.image.pullPolicy }}
args:
- -f
- /usr/local/etc/haproxy/haproxy.cfg
ports:
{{- if or .Values.haproxy.containerPorts .Values.haproxy.existingConfigMap }}
{{- toYaml .Values.haproxy.containerPorts | nindent 12 }}
{{- else if .Values.customConfig }}
{{- include "vector.containerPorts" . | indent 12 }}
{{- else if or (eq .Values.role "Aggregator") (eq .Values.role "Stateless-Aggregator") }}
- name: datadog-agent
containerPort: 8282
protocol: TCP
- name: fluent
containerPort: 24224
protocol: TCP
- name: logstash
containerPort: 5044
protocol: TCP
- name: splunk-hec
containerPort: 8080
protocol: TCP
- name: statsd
containerPort: 8125
protocol: TCP
- name: syslog
containerPort: 9000
protocol: TCP
- name: vector
containerPort: 6000
protocol: TCP
- name: prom-exporter
containerPort: 9090
protocol: TCP
{{- else if (eq .Values.role "Agent") }}
- name: prom-exporter
containerPort: 9090
protocol: TCP
{{- end }}
{{- if not .Values.haproxy.customConfig }}
- name: stats
containerPort: 1024
protocol: TCP
{{- end }}
{{- with .Values.haproxy.livenessProbe }}
livenessProbe:
{{- toYaml . | trim | nindent 12 }}
{{- end }}
{{- with .Values.haproxy.readinessProbe }}
readinessProbe:
{{- toYaml . | trim | nindent 12 }}
{{- end }}
{{- with .Values.haproxy.resources }}
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
volumeMounts:
- name: haproxy-config
mountPath: /usr/local/etc/haproxy
{{- with .Values.haproxy.extraVolumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if .Values.haproxy.extraContainers }}
{{- tpl (toYaml .Values.haproxy.extraContainers) . | nindent 8 }}
{{- end }}
volumes:
- name: haproxy-config
configMap:
name: {{ if .Values.haproxy.existingConfigMap }}{{ .Values.haproxy.existingConfigMap }}{{ else }}{{ template "haproxy.fullname" . }}{{ end }}
{{- with .Values.haproxy.extraVolumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.haproxy.nodeSelector }}
nodeSelector:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.haproxy.affinity }}
affinity:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.haproxy.tolerations }}
tolerations:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- end }}
@@ -0,0 +1,36 @@
{{- if and .Values.haproxy.enabled .Values.haproxy.autoscaling.enabled }}
apiVersion: {{ template "autoscaling.apiVersion" . }}
kind: HorizontalPodAutoscaler
metadata:
name: {{ include "haproxy.fullname" . }}
namespace: {{ .Release.Namespace | quote }}
labels:
{{- include "haproxy.labels" . | nindent 4 }}
spec:
scaleTargetRef:
apiVersion: apps/v1
kind: Deployment
name: {{ include "haproxy.fullname" . }}
minReplicas: {{ .Values.haproxy.autoscaling.minReplicas }}
maxReplicas: {{ .Values.haproxy.autoscaling.maxReplicas }}
metrics:
{{- if .Values.haproxy.autoscaling.targetCPUUtilizationPercentage }}
- type: Resource
resource:
name: cpu
target:
type: Utilization
averageUtilization: {{ .Values.haproxy.autoscaling.targetCPUUtilizationPercentage }}
{{- end }}
{{- if .Values.haproxy.autoscaling.targetMemoryUtilizationPercentage }}
- type: Resource
resource:
name: memory
target:
type: Utilization
averageUtilization: {{ .Values.haproxy.autoscaling.targetMemoryUtilizationPercentage }}
{{- end }}
{{- with .Values.haproxy.autoscaling.customMetric -}}
{{ toYaml . | nindent 4 }}
{{- end }}
{{- end }}
@@ -0,0 +1,76 @@
{{- if .Values.haproxy.enabled }}
apiVersion: v1
kind: Service
metadata:
name: {{ include "haproxy.fullname" . }}
namespace: {{ .Release.Namespace | quote }}
labels:
{{- include "haproxy.labels" . | nindent 4 }}
annotations:
{{- with .Values.haproxy.service.annotations }}
{{- toYaml . | nindent 4 }}
{{- end }}
spec:
{{- if .Values.haproxy.service.externalTrafficPolicy }}
externalTrafficPolicy: {{ .Values.haproxy.service.externalTrafficPolicy }}
{{- end }}
{{- if .Values.haproxy.service.loadBalancerIP }}
loadBalancerIP: {{ .Values.haproxy.service.loadBalancerIP }}
{{- end }}
{{- if .Values.haproxy.service.ipFamilyPolicy }}
ipFamilyPolicy: {{ .Values.haproxy.service.ipFamilyPolicy }}
{{- end }}
{{- if .Values.haproxy.service.ipFamilies }}
{{- with .Values.haproxy.service.ipFamilies }}
ipFamilies:
{{- toYaml . | nindent 4 }}
{{- end }}
{{- end }}
ports:
{{- if or .Values.haproxy.service.ports .Values.haproxy.existingConfigMap }}
{{- toYaml .Values.haproxy.service.ports | nindent 4 }}
{{- else if .Values.customConfig }}
{{- include "vector.ports" . | indent 4 }}
{{- else if or (eq .Values.role "Aggregator") (eq .Values.role "Stateless-Aggregator") }}
- name: datadog-agent
port: 8282
protocol: TCP
- name: fluent
port: 24224
protocol: TCP
- name: logstash
port: 5044
protocol: TCP
- name: splunk-hec
port: 8080
protocol: TCP
- name: statsd
port: 8125
protocol: TCP
- name: syslog
port: 9000
protocol: TCP
- name: vector
port: 6000
protocol: TCP
- name: prom-exporter
port: 9090
protocol: TCP
{{- else if (eq .Values.role "Agent") }}
- name: prom-exporter
port: 9090
protocol: TCP
{{- end }}
{{- if not .Values.haproxy.customConfig }}
- name: stats
port: 1024
protocol: TCP
{{- end }}
selector:
{{- include "haproxy.selectorLabels" . | nindent 4 }}
type: {{ .Values.haproxy.service.type }}
{{- with .Values.haproxy.service.topologyKeys }}
topologyKeys:
{{- toYaml . | nindent 4 }}
{{- end }}
{{- end }}
@@ -0,0 +1,14 @@
{{- if and .Values.haproxy.enabled .Values.haproxy.serviceAccount.create -}}
apiVersion: v1
kind: ServiceAccount
metadata:
name: {{ include "haproxy.serviceAccountName" . }}
namespace: {{ .Release.Namespace | quote }}
labels:
{{- include "haproxy.labels" . | nindent 4 }}
{{- with .Values.haproxy.serviceAccount.annotations }}
annotations:
{{- toYaml . | nindent 4 }}
{{- end }}
automountServiceAccountToken: {{ .Values.haproxy.serviceAccount.automountToken }}
{{- end }}
@@ -0,0 +1,48 @@
{{- if or (eq .Values.role "Aggregator") (eq .Values.role "Stateless-Aggregator") -}}
{{- if .Values.autoscaling.enabled }}
apiVersion: {{ template "autoscaling.apiVersion" . }}
kind: HorizontalPodAutoscaler
metadata:
name: {{ include "vector.fullname" . }}
namespace: {{ .Release.Namespace | quote }}
labels:
{{- include "vector.labels" . | nindent 4 }}
annotations:
{{- toYaml .Values.autoscaling.annotations | nindent 4 }}
spec:
scaleTargetRef:
apiVersion: apps/v1
{{- if (eq .Values.role "Aggregator") }}
kind: StatefulSet
{{- else if (eq .Values.role "Stateless-Aggregator") }}
kind: Deployment
{{- end }}
name: {{ include "vector.fullname" . }}
minReplicas: {{ .Values.autoscaling.minReplicas }}
maxReplicas: {{ .Values.autoscaling.maxReplicas }}
metrics:
{{- if .Values.autoscaling.targetMemoryUtilizationPercentage }}
- type: Resource
resource:
name: memory
target:
type: Utilization
averageUtilization: {{ .Values.autoscaling.targetMemoryUtilizationPercentage }}
{{- end }}
{{- if .Values.autoscaling.targetCPUUtilizationPercentage }}
- type: Resource
resource:
name: cpu
target:
type: Utilization
averageUtilization: {{ .Values.autoscaling.targetCPUUtilizationPercentage }}
{{- end }}
{{- with .Values.autoscaling.customMetric -}}
{{ toYaml . | nindent 4 }}
{{- end }}
{{- with .Values.autoscaling.behavior }}
behavior:
{{- toYaml . | nindent 4 }}
{{- end }}
{{- end }}
{{- end }}
@@ -0,0 +1,48 @@
{{- if .Values.ingress.enabled -}}
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: {{ include "vector.fullname" . }}
namespace: {{ .Release.Namespace | quote }}
labels:
{{- include "vector.labels" . | nindent 4 }}
{{- with .Values.ingress.annotations }}
annotations:
{{- toYaml . | nindent 4 }}
{{- end }}
spec:
{{- if .Values.ingress.className }}
ingressClassName: {{ .Values.ingress.className }}
{{- end }}
{{- if .Values.ingress.tls }}
tls:
{{- range .Values.ingress.tls }}
- hosts:
{{- range .hosts }}
- {{ . | quote }}
{{- end }}
secretName: {{ .secretName }}
{{- end }}
{{- end }}
rules:
{{- range .Values.ingress.hosts }}
- host: {{ .host | quote }}
http:
paths:
{{- range .paths }}
- path: {{ .path }}
{{- if .pathType }}
pathType: {{ .pathType }}
{{- end }}
backend:
service:
name: {{ if $.Values.haproxy.enabled }}{{ include "haproxy.fullname" $ }}{{ else }}{{ include "vector.fullname" $ }}{{ end }}
port:
{{- if .port.name }}
name: {{ .port.name }}
{{- else }}
number: {{ .port.number }}
{{- end }}
{{- end }}
{{- end }}
{{- end }}
@@ -0,0 +1,19 @@
{{- if .Values.podDisruptionBudget.enabled }}
apiVersion: {{ template "policy.poddisruptionbudget.apiVersion" . }}
kind: PodDisruptionBudget
metadata:
name: {{ template "vector.fullname" . }}
namespace: {{ .Release.Namespace | quote }}
labels:
{{- include "vector.labels" . | nindent 4 }}
spec:
{{- with .Values.podDisruptionBudget.minAvailable }}
minAvailable: {{ . }}
{{- end }}
{{- with .Values.podDisruptionBudget.maxUnavailable }}
maxUnavailable: {{ . }}
{{- end }}
selector:
matchLabels:
{{- include "vector.selectorLabels" . | nindent 6 }}
{{- end }}
@@ -0,0 +1,43 @@
{{- if and .Values.podMonitor.enabled (.Capabilities.APIVersions.Has "monitoring.coreos.com/v1") }}
apiVersion: monitoring.coreos.com/v1
kind: PodMonitor
metadata:
name: {{ include "vector.fullname" . }}
namespace: {{ .Release.Namespace | quote }}
labels:
{{- with .Values.podMonitor.additionalLabels }}
{{- toYaml . | nindent 4 }}
{{- end }}
{{- include "vector.labels" . | nindent 4 }}
spec:
jobLabel: {{ .Values.podMonitor.jobLabel }}
selector:
matchLabels:
{{- include "vector.selectorLabels" . | nindent 6 }}
namespaceSelector:
matchNames:
- {{ .Release.Namespace | quote }}
{{- with .Values.podMonitor.podTargetLabels }}
podTargetLabels:
{{- toYaml . | nindent 4 }}
{{- end }}
podMetricsEndpoints:
- port: {{ .Values.podMonitor.port }}
path: {{ .Values.podMonitor.path }}
{{- if .Values.podMonitor.interval }}
interval: {{ .Values.podMonitor.interval }}
{{- end }}
{{- if .Values.podMonitor.scrapeTimeout }}
scrapeTimeout: {{ .Values.podMonitor.scrapeTimeout }}
{{- end }}
honorLabels: {{ .Values.podMonitor.honorLabels }}
honorTimestamps: {{ .Values.podMonitor.honorTimestamps }}
{{- with .Values.podMonitor.relabelings }}
relabelings:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.podMonitor.metricRelabelings }}
metricRelabelings:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- end }}
@@ -0,0 +1,48 @@
{{- if and .Values.psp.create (.Capabilities.APIVersions.Has "policy/v1beta1") }}
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: {{ include "vector.fullname" . }}
labels:
{{- include "vector.labels" . | nindent 4 }}
spec:
privileged: false
allowPrivilegeEscalation: false
readOnlyRootFilesystem: false
requiredDropCapabilities:
- ALL
volumes:
- 'hostPath'
- 'configMap'
- 'emptyDir'
- 'secret'
- 'projected'
allowedHostPaths:
- pathPrefix: "/var/log"
readOnly: true
- pathPrefix: "/var/lib"
readOnly: true
- pathPrefix: {{ .Values.persistence.hostPath.path | quote }}
readOnly: false
- pathPrefix: "/sys"
readOnly: true
- pathPrefix: "/proc"
readOnly: true
hostNetwork: {{ .Values.podHostNetwork }}
hostIPC: false
hostPID: false
runAsUser:
rule: 'RunAsAny'
seLinux:
rule: 'RunAsAny'
supplementalGroups:
rule: 'MustRunAs'
ranges:
- min: 1
max: 65535
fsGroup:
rule: 'MustRunAs'
ranges:
- min: 1
max: 65535
{{- end }}
@@ -0,0 +1,48 @@
{{- if and .Values.rbac.create (eq .Values.role "Agent") -}}
# Permissions to use Kubernetes API.
# Requires that RBAC authorization is enabled.
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: {{ include "vector.fullname" . }}
labels:
{{- include "vector.labels" . | nindent 4 }}
rules:
- apiGroups:
- ""
resources:
- namespaces
- nodes
- pods
verbs:
- list
- watch
{{- if and .Values.psp.create (.Capabilities.APIVersions.Has "policy/v1beta1") }}
- apiGroups:
- policy
resources:
- podsecuritypolicies
verbs:
- use
resourceNames:
- {{ include "vector.fullname" . }}
{{- end }}
{{- if .Values.rbac.extraRules }}
{{ toYaml .Values.rbac.extraRules | nindent 2 }}
{{- end }}
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: {{ include "vector.fullname" . }}
labels:
{{- include "vector.labels" . | nindent 4 }}
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: {{ include "vector.fullname" . }}
subjects:
- kind: ServiceAccount
name: {{ include "vector.serviceAccountName" . }}
namespace: {{ .Release.Namespace | quote }}
{{- end }}
@@ -0,0 +1,14 @@
{{- with .Values.secrets.generic }}
apiVersion: v1
kind: Secret
metadata:
name: {{ include "vector.fullname" $ }}
namespace: {{ $.Release.Namespace | quote }}
labels:
{{- include "vector.labels" $ | nindent 4 }}
type: Opaque
data:
{{- range $key, $value := $.Values.secrets.generic }}
{{ $key }}: {{ $value | b64enc | quote }}
{{- end }}
{{- end }}
@@ -0,0 +1,131 @@
{{/*
TODO: Remove outer "if/elseif"
*/}}
{{- if .Values.serviceHeadless }}
{{- if .Values.serviceHeadless.enabled }}
apiVersion: v1
kind: Service
metadata:
name: {{ include "vector.fullname" . }}-headless
namespace: {{ .Release.Namespace | quote }}
labels:
{{- include "vector.labels" . | nindent 4 }}
annotations:
{{- with .Values.service.annotations }}
{{- toYaml . | nindent 4 }}
{{- end }}
spec:
clusterIP: None
{{- if .Values.service.ipFamilyPolicy }}
ipFamilyPolicy: {{ .Values.service.ipFamilyPolicy }}
{{- end }}
{{- if .Values.service.ipFamilies }}
{{- with .Values.service.ipFamilies }}
ipFamilies:
{{- toYaml . | nindent 4 }}
{{- end }}
{{- end }}
ports:
{{- if or .Values.service.ports .Values.existingConfigMaps }}
{{- toYaml .Values.service.ports | nindent 4 }}
{{- else if .Values.customConfig }}
{{- include "vector.ports" . | indent 4 }}
{{- else }}
- name: datadog-agent
port: 8282
protocol: TCP
- name: fluent
port: 24224
protocol: TCP
- name: logstash
port: 5044
protocol: TCP
- name: splunk-hec
port: 8080
protocol: TCP
- name: statsd
port: 8125
protocol: TCP
- name: syslog
port: 9000
protocol: TCP
- name: vector
port: 6000
protocol: TCP
- name: prom-exporter
port: 9090
protocol: TCP
{{- end }}
selector:
{{- include "vector.selectorLabels" . | nindent 4 }}
type: ClusterIP
{{- with or .Values.service.topologyKeys }}
topologyKeys:
{{- toYaml . | nindent 4 }}
{{- end }}
{{- end }}
{{/*
Allow for clean upgrade from 0.16.3 -> 0.17.0
*/}}
{{- else if .Values.service.enabled }}
apiVersion: v1
kind: Service
metadata:
name: {{ include "vector.fullname" . }}-headless
namespace: {{ .Release.Namespace | quote }}
labels:
{{- include "vector.labels" . | nindent 4 }}
annotations:
{{- with .Values.service.annotations }}
{{- toYaml . | nindent 4 }}
{{- end }}
spec:
clusterIP: None
{{- if .Values.service.ipFamilyPolicy }}
ipFamilyPolicy: {{ .Values.service.ipFamilyPolicy }}
{{- end }}
{{- if .Values.service.ipFamilies }}
{{- with .Values.service.ipFamilies }}
ipFamilies:
{{- toYaml . | nindent 4 }}
{{- end }}
{{- end }}
ports:
{{- if or .Values.service.ports .Values.existingConfigMaps }}
{{- toYaml .Values.service.ports | nindent 4 }}
{{- else if .Values.customConfig }}
{{- include "vector.ports" . | indent 4 }}
{{- else }}
- name: datadog-agent
port: 8282
protocol: TCP
- name: fluent
port: 24224
protocol: TCP
- name: logstash
port: 5044
protocol: TCP
- name: splunk-hec
port: 8080
protocol: TCP
- name: statsd
port: 8125
protocol: TCP
- name: syslog
port: 9000
protocol: TCP
- name: vector
port: 6000
protocol: TCP
- name: prom-exporter
port: 9090
protocol: TCP
{{- end }}
selector:
{{- include "vector.selectorLabels" . | nindent 4 }}
type: ClusterIP
{{- with .Values.service.topologyKeys }}
topologyKeys:
{{- toYaml . | nindent 4 }}
{{- end }}
{{- end }}
@@ -0,0 +1,77 @@
{{- if .Values.service.enabled }}
apiVersion: v1
kind: Service
metadata:
name: {{ include "vector.fullname" . }}
namespace: {{ .Release.Namespace | quote }}
labels:
{{- include "vector.labels" . | nindent 4 }}
annotations:
{{- with .Values.service.annotations }}
{{- toYaml . | nindent 4 }}
{{- end }}
spec:
{{- if .Values.service.externalTrafficPolicy }}
externalTrafficPolicy: {{ .Values.service.externalTrafficPolicy }}
{{- end }}
{{- if .Values.service.internalTrafficPolicy }}
internalTrafficPolicy: {{ .Values.service.internalTrafficPolicy }}
{{- end }}
{{- if .Values.service.loadBalancerIP }}
loadBalancerIP: {{ .Values.service.loadBalancerIP }}
{{- end }}
{{- if .Values.service.ipFamilyPolicy }}
ipFamilyPolicy: {{ .Values.service.ipFamilyPolicy }}
{{- end }}
{{- if .Values.service.ipFamilies }}
{{- with .Values.service.ipFamilies }}
ipFamilies:
{{- toYaml . | nindent 4 }}
{{- end }}
{{- end }}
{{- if .Values.service.trafficDistribution }}
trafficDistribution: {{ .Values.service.trafficDistribution }}
{{- end }}
ports:
{{- if or .Values.service.ports .Values.existingConfigMaps }}
{{- toYaml .Values.service.ports | nindent 4 }}
{{- else if .Values.customConfig }}
{{- include "vector.ports" . | indent 4 }}
{{- else if or (eq .Values.role "Aggregator") (eq .Values.role "Stateless-Aggregator") }}
- name: datadog-agent
port: 8282
protocol: TCP
- name: fluent
port: 24224
protocol: TCP
- name: logstash
port: 5044
protocol: TCP
- name: splunk-hec
port: 8080
protocol: TCP
- name: statsd
port: 8125
protocol: TCP
- name: syslog
port: 9000
protocol: TCP
- name: vector
port: 6000
protocol: TCP
- name: prom-exporter
port: 9090
protocol: TCP
{{- else if (eq .Values.role "Agent") }}
- name: prom-exporter
port: 9090
protocol: TCP
{{- end }}
selector:
{{- include "vector.selectorLabels" . | nindent 4 }}
type: {{ .Values.service.type }}
{{- with .Values.service.topologyKeys }}
topologyKeys:
{{- toYaml . | nindent 4 }}
{{- end }}
{{- end }}
@@ -0,0 +1,14 @@
{{- if .Values.serviceAccount.create -}}
apiVersion: v1
kind: ServiceAccount
metadata:
name: {{ include "vector.serviceAccountName" . }}
namespace: {{ .Release.Namespace | quote }}
labels:
{{- include "vector.labels" . | nindent 4 }}
{{- with .Values.serviceAccount.annotations }}
annotations:
{{- toYaml . | nindent 4 }}
{{- end }}
automountServiceAccountToken: {{ .Values.serviceAccount.automountToken }}
{{- end }}
@@ -0,0 +1,79 @@
{{- if (eq .Values.role "Aggregator") -}}
apiVersion: {{ .Values.statefulSet.apiVersion | default "apps/v1" }}
kind: StatefulSet
metadata:
name: {{ include "vector.fullname" . }}
namespace: {{ .Release.Namespace | quote }}
labels:
{{- include "vector.labels" . | nindent 4 }}
annotations:
{{- toYaml .Values.workloadResourceAnnotations | nindent 4 }}
spec:
{{- with .Values.revisionHistoryLimit }}
revisionHistoryLimit: {{ . }}
{{- end }}
{{- if not (or .Values.autoscaling.enabled .Values.autoscaling.external) }}
replicas: {{ .Values.replicas }}
{{- end }}
podManagementPolicy: {{ .Values.podManagementPolicy }}
{{- if .Values.persistence.retentionPolicy }}
persistentVolumeClaimRetentionPolicy:
{{ toYaml .Values.persistence.retentionPolicy | nindent 4 }}
{{- end }}
selector:
matchLabels:
{{- include "vector.selectorLabels" . | nindent 6 }}
minReadySeconds: {{ .Values.minReadySeconds }}
{{- with .Values.updateStrategy }}
updateStrategy:
{{- toYaml . | nindent 4 }}
{{- end }}
serviceName: {{ template "vector.fullname" . }}-headless
template:
metadata:
annotations:
{{- if .Values.rollWorkload }}
{{- if .Values.existingConfigMaps }}
{{- range .Values.existingConfigMaps }}
{{- range $file, $contents := (lookup "v1" "ConfigMap" (print $.Release.Namespace) (print .)).data }}
checksum/{{ $file }}: {{ $contents | sha256sum }}
{{- end }}
{{- end }}
{{- else }}
checksum/config: {{ include (print $.Template.BasePath "/configmap.yaml") . | sha256sum }}
{{- end }}
{{- end }}
{{- if .Values.rollWorkloadSecrets }}
checksum/secrets: {{ include (print $.Template.BasePath "/secret.yaml") . | sha256sum }}
{{- end }}
{{- if .Values.rollWorkloadExtraObjects }}
checksum/extraObjects: {{ include (print $.Template.BasePath "/extra-manifests.yaml") . | sha256sum }}
{{- end }}
{{- with .Values.podAnnotations }}
{{- toYaml . | nindent 8 }}
{{- end }}
labels:
{{- include "vector.selectorLabels" . | nindent 8 }}
{{- with .Values.podLabels }}
{{- toYaml . | nindent 8 }}
{{- end }}
spec:
{{- include "vector.pod" . | nindent 6 }}
volumeClaimTemplates:
{{- if and .Values.persistence.enabled (not .Values.persistence.existingClaim) }}
- metadata:
name: data
spec:
accessModes: {{ .Values.persistence.accessModes }}
{{- if .Values.persistence.storageClassName }}
storageClassName: {{ .Values.persistence.storageClassName }}
{{- end }}
resources:
requests:
storage: {{ .Values.persistence.size }}
{{- with .Values.persistence.selector }}
selector:
{{ toYaml . | indent 8 }}
{{- end }}
{{- end }}
{{- end }}
@@ -0,0 +1,743 @@
# Default values for Vector
# See Vector helm documentation to learn more:
# https://vector.dev/docs/setup/installation/package-managers/helm/
# nameOverride -- Override the name of resources.
nameOverride: ""
# fullnameOverride -- Override the full name of resources.
fullnameOverride: ""
# role -- [Role](https://vector.dev/docs/setup/deployment/roles/) for this Vector instance, valid options are:
# "Agent", "Aggregator", and "Stateless-Aggregator".
# Each role is created with the following workloads:
# Agent = DaemonSet
# Aggregator = StatefulSet
# Stateless-Aggregator = Deployment
role: "Aggregator"
# Workload API version overrides. Use these to switch to custom controllers
# or to test new Kubernetes API versions.
daemonSet:
# daemonSet.apiVersion -- Override the DaemonSet apiVersion. Valid for the "Agent" role.
apiVersion: ""
statefulSet:
# statefulSet.apiVersion -- Override the StatefulSet apiVersion. Valid for the "Aggregator" role.
apiVersion: ""
# rollWorkload -- Add a checksum of the generated ConfigMap to workload annotations.
rollWorkload: true
# rollWorkloadSecrets -- Add a checksum of the generated Secret to workload annotations.
rollWorkloadSecrets: false
# rollWorkloadExtraObjects -- Add a checksum of the generated ExtraObjects to workload annotations.
rollWorkloadExtraObjects: false
# commonLabels -- Add additional labels to all created resources.
commonLabels: {}
# Define the Vector image to use.
# Vector images are available from:
# - Docker Hub: docker.io/timberio/vector
# - GitHub Container Registry: ghcr.io/vectordotdev/vector
image:
# image.repository -- Override default registry and name for Vector's image.
repository: docker.io/timberio/vector
# image.pullPolicy -- The [pullPolicy](https://kubernetes.io/docs/concepts/containers/images/#image-pull-policy) for
# Vector's image.
pullPolicy: IfNotPresent
# image.pullSecrets -- The [imagePullSecrets](https://kubernetes.io/docs/concepts/containers/images/#specifying-imagepullsecrets-on-a-pod)
# to reference for the Vector Pods.
pullSecrets: []
# image.tag -- The tag to use for Vector's image.
# @default -- Derived from the Chart's appVersion.
tag: ""
# image.sha -- The SHA to use for Vector's image.
sha: ""
# image.base -- The base distribution to use for vector. If set, then the base in appVersion will be replaced with this base alongside the version.
# For example: with a `base` of `debian` `0.38.0-distroless-libc` becomes `0.38.0-debian`
base: ""
# replicas -- Specify the number of Pods to create. Valid for the "Aggregator" and "Stateless-Aggregator" roles.
replicas: 1
# Adding additional entries with hostAliases
hostAliases: []
# - ip: "127.0.0.1"
# hostnames:
# - "foo.local"
# - "bar.local"
# podManagementPolicy -- Specify the [podManagementPolicy](https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#pod-management-policies)
# for the StatefulSet. Valid for the "Aggregator" role.
podManagementPolicy: OrderedReady
# Create a Secret resource for Vector to use.
secrets:
# secrets.generic -- Each Key/Value will be added to the Secret's data key, each value should be raw and NOT base64
# encoded. Any secrets can be provided here. It's commonly used for credentials and other access related values.
# **NOTE: Don't commit unencrypted secrets to git!**
generic: {}
# my_variable: "my-secret-value"
# datadog_api_key: "api-key"
# awsAccessKeyId: "access-key"
# awsSecretAccessKey: "secret-access-key"
autoscaling:
# autoscaling.enabled -- Create a [HorizontalPodAutoscaler](https://kubernetes.io/docs/tasks/run-application/horizontal-pod-autoscale/)
# for Vector. Valid for the "Aggregator" and "Stateless-Aggregator" roles.
enabled: false
# autoscaling.external -- Set to `true` if using an external autoscaler like [KEDA](https://keda.sh/).
# Valid for the "Aggregator and "Stateless-Aggregator" roles.
external: false
# autoscaling.annotations -- Annotations to add to Vector's HPA.
annotations: {}
# autoscaling.minReplicas -- Minimum replicas for Vector's HPA.
minReplicas: 1
# autoscaling.maxReplicas -- Maximum replicas for Vector's HPA.
maxReplicas: 10
# autoscaling.targetCPUUtilizationPercentage -- Target CPU utilization for Vector's HPA.
targetCPUUtilizationPercentage: 80
# autoscaling.targetMemoryUtilizationPercentage -- (int) Target memory utilization for Vector's HPA.
targetMemoryUtilizationPercentage:
# autoscaling.customMetric -- Target a custom metric for autoscaling.
customMetric: {}
# - type: Pods
# pods:
# metric:
# name: utilization
# target:
# type: AverageValue
# averageValue: 95
# autoscaling.behavior -- Configure separate scale-up and scale-down behaviors.
behavior: {}
# scaleDown:
# stabilizationWindowSeconds: 300
podDisruptionBudget:
# podDisruptionBudget.enabled -- Enable a [PodDisruptionBudget](https://kubernetes.io/docs/tasks/run-application/configure-pdb/)
# for Vector.
enabled: false
# podDisruptionBudget.minAvailable -- The number of Pods that must still be available after an eviction.
minAvailable: 1
# podDisruptionBudget.maxUnavailable -- (int) The number of Pods that can be unavailable after an eviction.
maxUnavailable:
rbac:
# rbac.create -- If true, create and use RBAC resources. Only valid for the "Agent" role.
create: true
# rbac.extraRules -- List of additional Kubernetes RBAC rules to append to the ClusterRole.
# Rules defined here are appended after the chart's standard rules.
# Each item must follow the Kubernetes ClusterRole rule syntax.
#
# Example:
# extraRules:
# - apiGroups: [""]
# resources: ["nodes/metrics", "nodes/stats"]
# verbs: ["get"]
extraRules: []
psp:
# psp.create -- If true, create a [PodSecurityPolicy](https://kubernetes.io/docs/concepts/security/pod-security-policy/)
# resource. PodSecurityPolicy is deprecated as of Kubernetes v1.21, and will be removed in v1.25. Intended for use
# with the "Agent" role.
create: false
serviceAccount:
# serviceAccount.create -- If true, create a ServiceAccount for Vector.
create: true
# serviceAccount.annotations -- Annotations to add to Vector's ServiceAccount.
annotations: {}
# serviceAccount.name -- The name of the ServiceAccount to use. If not set and serviceAccount.create is true, a name
# is generated using the fullname template.
name:
# serviceAccount.automountToken -- Automount API credentials for Vector's ServiceAccount.
automountToken: true
# podAnnotations -- Set annotations on Vector Pods.
podAnnotations: {}
# podLabels -- Set labels on Vector Pods.
podLabels:
vector.dev/exclude: "true"
# podPriorityClassName -- Set the [priorityClassName](https://kubernetes.io/docs/concepts/scheduling-eviction/pod-priority-preemption/#priorityclass)
# on Vector Pods.
podPriorityClassName: ""
# podHostNetwork -- Configure hostNetwork on Vector Pods.
podHostNetwork: false
# podSecurityContext -- Allows you to overwrite the default [PodSecurityContext](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/)
# for Vector Pods.
podSecurityContext: {}
# workloadResourceAnnotations -- Set annotations on the Vector DaemonSet, Deployment or StatefulSet.
workloadResourceAnnotations: {}
# securityContext -- Specify securityContext on Vector containers.
securityContext: {}
# command -- Override Vector's default command.
command: []
# args -- Override Vector's default arguments.
args:
- --config-dir
- "/etc/vector/"
# env -- Set environment variables for Vector containers.
env: []
# - name: MY_VARIABLE
# valueFrom:
# secretKeyRef:
# name: vector
# key: my_variable
# - name: AWS_ACCESS_KEY_ID
# valueFrom:
# secretKeyRef:
# name: vector
# key: awsAccessKeyId
# envFrom -- Define environment variables from Secrets or ConfigMaps.
envFrom: []
# - secretRef:
# name: vector
# containerPorts -- Manually define Vector's containerPorts, overriding automated generation of containerPorts.
containerPorts: []
# resources -- Set Vector resource requests and limits.
resources: {}
# requests:
# cpu: 200m
# memory: 256Mi
# limits:
# cpu: 200m
# memory: 256Mi
# lifecycle -- Set lifecycle hooks for Vector containers.
lifecycle: {}
# preStop:
# exec:
# command:
# - /bin/sleep
# - "10"
# minReadySeconds -- Specify the minimum number of seconds a newly spun up pod should wait to
# pass healthchecks before it is considered available.
minReadySeconds: 0
# revisionHistoryLimit -- The number of historical changes to retain to allow rollback. Valid for all roles (Agent, Aggregator, Stateless-Aggregator).
# defaults to 10 if not set
# revisionHistoryLimit: 10
# updateStrategy -- Customize the updateStrategy used to replace Vector Pods, this is also used for the
# DeploymentStrategy for the "Stateless-Aggregators". Valid options depend on the chosen role.
# Agent (DaemonSetUpdateStrategy): https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/daemon-set-v1/#DaemonSetSpec)
# Aggregator (StatefulSetUpdateStrategy): https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/stateful-set-v1/#StatefulSetSpec
# Stateless-Aggregator (DeploymentStrategy): https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/deployment-v1/
updateStrategy: {}
# type: RollingUpdate
# rollingUpdate:
# maxUnavailable: 1
# terminationGracePeriodSeconds -- Override Vector's terminationGracePeriodSeconds.
terminationGracePeriodSeconds: 60
# nodeSelector -- Configure a [nodeSelector](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
# for Vector Pods.
nodeSelector: {}
# tolerations -- Configure Vector Pods to be scheduled on [tainted](https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/)
# nodes.
tolerations: []
# affinity -- Configure [affinity](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#affinity-and-anti-affinity)
# rules for Vector Pods.
affinity: {}
# topologySpreadConstraints -- Configure [topology spread constraints](https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/)
# for Vector Pods. Valid for the "Aggregator" and "Stateless-Aggregator" roles.
topologySpreadConstraints: []
# Configuration for Vector's Service.
service:
# service.enabled -- If true, create and provide a Service resource for Vector.
enabled: true
# service.type -- Set the type for Vector's Service.
type: "ClusterIP"
# service.annotations -- Set annotations on Vector's Service.
annotations: {}
# service.topologyKeys -- Specify the [topologyKeys](https://kubernetes.io/docs/concepts/services-networking/service-topology/#using-service-topology)
# field on Vector's Service.
topologyKeys: []
# - "kubernetes.io/hostname"
# - "topology.kubernetes.io/zone"
# - "topology.kubernetes.io/region"
# - "*"
# service.ports -- Manually set the Service ports, overriding automated generation of Service ports.
ports: []
# service.externalTrafficPolicy -- Specify the [externalTrafficPolicy](https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip).
externalTrafficPolicy: ""
# service.internalTrafficPolicy -- Specify the [internalTrafficPolicy](https://kubernetes.io/docs/concepts/services-networking/service-traffic-policy).
internalTrafficPolicy: ""
# service.loadBalancerIP -- Specify the [loadBalancerIP](https://kubernetes.io/docs/concepts/services-networking/service/#loadbalancer).
loadBalancerIP: ""
# service.ipFamilyPolicy -- Configure [IPv4/IPv6 dual-stack](https://kubernetes.io/docs/concepts/services-networking/dual-stack/).
ipFamilyPolicy: ""
# service.ipFamilies -- Configure [IPv4/IPv6 dual-stack](https://kubernetes.io/docs/concepts/services-networking/dual-stack/).
ipFamilies: []
# service.trafficDistribution -- Specify the [Traffic distribution](https://kubernetes.io/docs/concepts/services-networking/service/#traffic-distribution)
# additional Topology Aware Routing may be informative. Specify the [Topology Aware Routing](https://kubernetes.io/docs/concepts/services-networking/topology-aware-routing/)
trafficDistribution: ""
# Configuration for Vector's Headless Service.
serviceHeadless:
# serviceHeadless.enabled -- If true, create and provide a Headless Service resource for Vector.
enabled: true
# Configuration for Vector's Ingress.
ingress:
# ingress.enabled -- If true, create and use an Ingress resource.
enabled: false
# ingress.className -- Specify the [ingressClassName](https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress),
# requires Kubernetes >= 1.18
className: ""
# ingress.annotations -- Set annotations on the Ingress.
annotations: {}
# kubernetes.io/ingress.class: nginx
# kubernetes.io/tls-acme: "true"
# ingress.hosts -- Configure the hosts and paths for the Ingress.
hosts: []
# - host: chart-example.local
# paths:
# - path: /
# pathType: ImplementationSpecific
# # Specify the port name or number on the Service
# # Using name requires Kubernetes >=1.19
# port:
# name: ""
# number: ""
# ingress.tls -- Configure TLS for the Ingress.
tls: []
# - secretName: chart-example-tls
# hosts:
# - chart-example.local
# existingConfigMaps -- List of existing ConfigMaps for Vector's configuration instead of creating a new one. Requires
# dataDir to be set. Additionally, containerPorts, service.ports, and serviceHeadless.ports should be specified based on
# your supplied configuration. If set, this parameter takes precedence over customConfig and the chart's default configs.
existingConfigMaps: []
# dataDir -- Specify the path for Vector's data, only used when existingConfigMaps are used.
dataDir: ""
# customConfig -- Override Vector's default configs, if used **all** options need to be specified. This section supports
# using helm templates to populate dynamic values. See Vector's [configuration documentation](https://vector.dev/docs/reference/configuration/)
# for all options.
customConfig: {}
# data_dir: /vector-data-dir
# api:
# enabled: true
# address: 127.0.0.1:8686
# sources:
# vector:
# address: 0.0.0.0:6000
# type: vector
# version: "2"
# sinks:
# stdout:
# type: console
# inputs: [vector]
# encoding:
# codec: json
# defaultVolumes -- Default volumes that are mounted into pods. In most cases, these should not be changed.
# Use `extraVolumes`/`extraVolumeMounts` for additional custom volumes.
# @default -- See `values.yaml`
defaultVolumes:
- name: var-log
hostPath:
path: "/var/log/"
- name: var-lib
hostPath:
path: "/var/lib/"
- name: procfs
hostPath:
path: "/proc"
- name: sysfs
hostPath:
path: "/sys"
# defaultVolumeMounts -- Default volume mounts. Corresponds to `volumes`.
# @default -- See `values.yaml`
defaultVolumeMounts:
- name: var-log
mountPath: "/var/log/"
readOnly: true
- name: var-lib
mountPath: "/var/lib"
readOnly: true
- name: procfs
mountPath: "/host/proc"
readOnly: true
- name: sysfs
mountPath: "/host/sys"
readOnly: true
# extraVolumes -- Additional Volumes to use with Vector Pods.
extraVolumes: []
# extraVolumeMounts -- Additional Volume to mount into Vector Containers.
extraVolumeMounts: []
# initContainers -- Init Containers to be added to the Vector Pods.
# This also supports template content, which will eventually be converted to yaml.
initContainers: []
# initContainers:
# - name: test
# image: busybox:latest
# command:
# - cp
# args:
# - /bin/sleep
# - /test/sleep
# volumeMounts:
# - name: test
# mountPath: /test
# extraContainers -- Extra Containers to be added to the Vector Pods.
# This also supports template content, which will eventually be converted to yaml.
extraContainers: []
# extraContainers:
# - name: test
# command:
# - cp
# args:
# - /bin/sleep
# - /test/sleep
# image: busybox:latest
# volumeMounts:
# - name: test
# mountPath: /test
# Configuration for Vector's data persistence.
persistence:
# persistence.enabled -- If true, create and use PersistentVolumeClaims.
enabled: false
# persistence.existingClaim -- Name of an existing PersistentVolumeClaim to use. Valid for the "Aggregator" role.
existingClaim: ""
# persistence.storageClassName -- Specifies the storageClassName for PersistentVolumeClaims. Valid for the
# "Aggregator" role.
# storageClassName: default
# persistence.retentionPolicy -- Configure a [PersistentVolumeClaimRetentionPolicy](https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#persistentvolumeclaim-retention)
# for Vector's PersistentVolumeClaims. Valid for the "Aggregator" role.
retentionPolicy: {}
# whenDeleted: Retain
# whenScaled: Retain
# persistence.accessModes -- Specifies the accessModes for PersistentVolumeClaims. Valid for the "Aggregator" role.
accessModes:
- ReadWriteOnce
# persistence.size -- Specifies the size of PersistentVolumeClaims. Valid for the "Aggregator" role.
size: 10Gi
# persistence.finalizers -- Specifies the finalizers of PersistentVolumeClaims. Valid for the "Aggregator" role.
finalizers:
- kubernetes.io/pvc-protection
# persistence.selectors -- Specifies the selectors for PersistentVolumeClaims. Valid for the "Aggregator" role.
selectors: {}
hostPath:
# persistence.hostPath.enabled -- If true, use hostPath persistence. Valid for the "Agent" role, if it's disabled
# the "Agent" role will use emptyDir.
enabled: true
# persistence.hostPath.path -- Override path used for hostPath persistence. Valid for the "Agent" role, persistence
# is always used for the "Agent" role.
path: "/var/lib/vector"
# dnsPolicy -- Specify the [dnsPolicy](https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-s-dns-policy)
# for Vector Pods.
dnsPolicy: ClusterFirst
# dnsConfig -- Specify the [dnsConfig](https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config)
# options for Vector Pods.
dnsConfig: {}
# nameservers:
# - 1.2.3.4
# searches:
# - ns1.svc.cluster-domain.example
# - my.dns.search.suffix
# options:
# - name: ndots
# value: "2"
# - name: edns0
# shareProcessNamespace -- Specify the [shareProcessNamespace](https://kubernetes.io/docs/tasks/configure-pod-container/share-process-namespace/)
# options for Vector Pods.
shareProcessNamespace: false
# livenessProbe -- Override default liveness probe settings. If customConfig is used, requires customConfig.api.enabled
# to be set to true. `grpc` is recommended once the cluster is on Vector 0.55+; the `httpGet /health` probe is kept
# for backwards compatibility with older Vector versions.
livenessProbe: {}
# Option 1: gRPC probe (uses grpc.health.v1.Health/Check, requires Vector 0.55+)
# grpc:
# port: 8686
#
# Option 2: HTTP probe
# httpGet:
# path: /health
# port: 8686
# readinessProbe -- Override default readiness probe settings. If not set, this chart applies an
# `httpGet /health` readinessProbe on port `8686` for chart-managed default configs. If customConfig is used,
# requires customConfig.api.enabled to be set to true. `grpc` is recommended once the cluster is on Vector 0.55+;
# the `httpGet /health` probe is kept for backwards compatibility with older Vector versions.
readinessProbe: {}
# Option 1: gRPC probe (uses grpc.health.v1.Health/Check, requires Vector 0.55+)
# grpc:
# port: 8686
#
# Option 2: HTTP probe
# httpGet:
# path: /health
# port: 8686
# startupProbe -- Override default startup probe settings. If customConfig is used,
# requires customConfig.api.enabled to be set to true. `grpc` is recommended once the cluster is on Vector 0.55+;
# the `httpGet /health` probe is kept for backwards compatibility with older Vector versions.
startupProbe: {}
# Option 1: gRPC probe (uses grpc.health.v1.Health/Check, requires Vector 0.55+)
# grpc:
# port: 8686
#
# Option 2: HTTP probe
# httpGet:
# path: /health
# port: 8686
# Configure a PodMonitor for Vector, requires the PodMonitor CRD to be installed.
podMonitor:
# podMonitor.enabled -- If true, create a PodMonitor for Vector.
enabled: false
# podMonitor.jobLabel -- Override the label to retrieve the job name from.
jobLabel: app.kubernetes.io/name
# podMonitor.port -- Override the port to scrape.
port: prom-exporter
# podMonitor.path -- Override the path to scrape.
path: /metrics
# podMonitor.interval -- Override the interval at which metrics should be scraped.
interval:
# podMonitor.scrapeTimeout -- Override the timeout after which the scrape is ended.
scrapeTimeout:
# podMonitor.relabelings -- [RelabelConfigs](https://prometheus.io/docs/prometheus/latest/configuration/configuration/#relabel_config)
# to apply to samples before scraping.
relabelings: []
# podMonitor.metricRelabelings -- [MetricRelabelConfigs](https://prometheus.io/docs/prometheus/latest/configuration/configuration/#metric_relabel_configs)
# to apply to samples before ingestion.
metricRelabelings: []
# podMonitor.podTargetLabels -- [podTargetLabels](https://prometheus-operator.dev/docs/operator/api/#monitoring.coreos.com/v1.PodMonitorSpec)
# transfers labels on the Kubernetes Pod onto the target.
podTargetLabels: []
# podMonitor.additionalLabels -- Adds additional labels to the PodMonitor.
additionalLabels: {}
# podMonitor.honorLabels -- If true, honor_labels is set to true in the [scrape config](https://prometheus.io/docs/prometheus/latest/configuration/configuration/#scrape_config).
honorLabels: false
# podMonitor.honorTimestamps -- If true, honor_timestamps is set to true in the [scrape config](https://prometheus.io/docs/prometheus/latest/configuration/configuration/#scrape_config).
honorTimestamps: true
# Log level for Vector.
logLevel: "info"
# Optional built-in HAProxy load balancer.
haproxy:
# haproxy.enabled -- If true, create a HAProxy load balancer.
enabled: false
# Define the HAProxy image to use.
image:
# haproxy.image.repository -- Override default registry and name for HAProxy.
repository: haproxytech/haproxy-alpine
# haproxy.image.pullPolicy -- HAProxy image pullPolicy.
pullPolicy: IfNotPresent
# haproxy.image.pullSecrets -- The [imagePullSecrets](https://kubernetes.io/docs/concepts/containers/images/#specifying-imagepullsecrets-on-a-pod)
# to reference for the HAProxy Pods.
pullSecrets: []
# haproxy.image.tag -- The tag to use for HAProxy's image.
tag: "2.6.12"
# haproxy.rollWorkload -- Add a checksum of the generated ConfigMap to the HAProxy Deployment.
rollWorkload: true
# haproxy.replicas -- Set the number of HAProxy Pods to create.
replicas: 1
serviceAccount:
# haproxy.serviceAccount.create -- If true, create a HAProxy ServiceAccount.
create: true
# haproxy.serviceAccount.annotations -- Annotations to add to the HAProxy ServiceAccount.
annotations: {}
# haproxy.serviceAccount.name -- The name of the HAProxy ServiceAccount to use. If not set and create is true, a
# name is generated using the fullname template.
name:
# haproxy.serviceAccount.automountToken -- Automount API credentials for the HAProxy ServiceAccount.
automountToken: true
# haproxy.strategy -- Customize the [strategy](https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/deployment-v1/)
# used to replace HAProxy Pods.
strategy: {}
# rollingUpdate:
# maxSurge: 25%
# maxUnavailable: 25%
# type: RollingUpdate
# haproxy.terminationGracePeriodSeconds -- Override HAProxy's terminationGracePeriodSeconds.
terminationGracePeriodSeconds: 60
# haproxy.podAnnotations -- Set annotations on HAProxy Pods.
podAnnotations: {}
# haproxy.podLabels -- Set labels on HAProxy Pods.
podLabels: {}
# haproxy.podPriorityClassName -- Set the priorityClassName on HAProxy Pods.
podPriorityClassName: ""
# haproxy.podSecurityContext -- Allows you to overwrite the default PodSecurityContext for HAProxy.
podSecurityContext: {}
# fsGroup: 2000
# haproxy.securityContext -- Specify securityContext on HAProxy containers.
securityContext: {}
# capabilities:
# drop:
# - ALL
# readOnlyRootFilesystem: true
# runAsNonRoot: true
# runAsUser: 1000
# haproxy.containerPorts -- Manually define HAProxy's containerPorts, overrides automated generation of containerPorts.
containerPorts: []
# HAProxy's Service configuration.
service:
# haproxy.service.type -- Set type of HAProxy's Service.
type: ClusterIP
# haproxy.service.annotations -- Set annotations on HAProxy's Service.
annotations: {}
# haproxy.service.topologyKeys -- Specify the [topologyKeys](https://kubernetes.io/docs/concepts/services-networking/service-topology/#using-service-topology)
# field on HAProxy's Service spec.
topologyKeys: []
# - "kubernetes.io/hostname"
# - "topology.kubernetes.io/zone"
# - "topology.kubernetes.io/region"
# - "*"
# haproxy.service.ports -- Manually set HAPRoxy's Service ports, overrides automated generation of Service ports.
ports: []
# haproxy.service.externalTrafficPolicy -- Specify the [externalTrafficPolicy](https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip).
externalTrafficPolicy: ""
# haproxy.service.loadBalancerIP -- Specify the [loadBalancerIP](https://kubernetes.io/docs/concepts/services-networking/service/#loadbalancer).
loadBalancerIP: ""
# haproxy.service.ipFamilyPolicy -- Configure [IPv4/IPv6 dual-stack](https://kubernetes.io/docs/concepts/services-networking/dual-stack/).
ipFamilyPolicy: ""
# haproxy.service.ipFamilies -- Configure [IPv4/IPv6 dual-stack](https://kubernetes.io/docs/concepts/services-networking/dual-stack/).
ipFamilies: []
# haproxy.existingConfigMap -- Use this existing ConfigMap for HAProxy's configuration instead of creating a new one.
# Additionally, haproxy.containerPorts and haproxy.service.ports should be specified based on your supplied
# configuration. If set, this parameter takes precedence over customConfig and the chart's default configs.
existingConfigMap: ""
# haproxy.customConfig -- Override HAProxy's default configs, if used **all** options need to be specified.
# This parameter supports using Helm templates to insert values dynamically. By default, this chart will parse
# Vector's configuration from customConfig to generate HAProxy's config, which can be overwritten with
# haproxy.customConfig.
customConfig: ""
# haproxy.extraVolumes -- Additional Volumes to use with HAProxy Pods.
extraVolumes: []
# haproxy.extraVolumeMounts -- Additional Volume to mount into HAProxy Containers.
extraVolumeMounts: []
# haproxy.initContainers -- Init Containers to be added to the HAProxy Pods.
# This also supports template content, which will eventually be converted to yaml.
initContainers: []
# haproxy.extraContainers -- Extra Containers to be added to the HAProxy Pods.
# This also supports template content, which will eventually be converted to yaml.
extraContainers: []
autoscaling:
# haproxy.autoscaling.enabled -- Create a HorizontalPodAutoscaler for HAProxy.
enabled: false
# haproxy.autoscaling.external -- HAProxy is controlled by an external HorizontalPodAutoscaler.
external: false
# haproxy.autoscaling.minReplicas -- Minimum replicas for HAProxy's HPA.
minReplicas: 1
# haproxy.autoscaling.maxReplicas -- Maximum replicas for HAProxy's HPA.
maxReplicas: 10
# haproxy.autoscaling.targetCPUUtilizationPercentage -- Target CPU utilization for HAProxy's HPA.
targetCPUUtilizationPercentage: 80
# haproxy.autoscaling.targetMemoryUtilizationPercentage -- (int) Target memory utilization for HAProxy's HPA.
targetMemoryUtilizationPercentage:
# haproxy.autoscaling.customMetric -- Target a custom metric for autoscaling.
customMetric: {}
# - type: Pods
# pods:
# metric:
# name: utilization
# target:
# type: AverageValue
# averageValue: 95
# haproxy.resources -- Set HAProxy resource requests and limits.
resources: {}
# limits:
# cpu: 100m
# memory: 128Mi
# requests:
# cpu: 100m
# memory: 128Mi
# haproxy.livenessProbe -- Override default HAProxy liveness probe settings.
livenessProbe:
tcpSocket:
port: 1024
# haproxy.readinessProbe -- Override default HAProxy readiness probe settings.
readinessProbe:
tcpSocket:
port: 1024
# haproxy.nodeSelector -- Configure a [nodeSelector](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
# for HAProxy Pods
nodeSelector: {}
# haproxy.tolerations -- Configure HAProxy Pods to be scheduled on [tainted](https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/)
# nodes.
tolerations: []
# haproxy.affinity -- Configure [affinity](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#affinity-and-anti-affinity)
# rules for HAProxy Pods.
affinity: {}
# extraObjects -- Create extra manifests via values. Would be passed through `tpl` for templating.
extraObjects: []
# - apiVersion: v1
# kind: ConfigMap
# metadata:
# name: vector-dashboards
# labels:
# grafana_dashboard: "1"
# data:
# vector.json: |
# {{ .Files.Get "dashboards/vector.json" | fromJson | toJson }}
@@ -0,0 +1,26 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/
*.md.gotmpl
CHANGELOG.md
_changelog.md
_index.md
@@ -0,0 +1,3 @@
dependencies: []
digest: sha256:643d5437104296e21d906ecb15b2c96ad278f20cfc4af53b12bb6069bd853726
generated: "2024-11-13T12:10:17.363248379Z"
@@ -0,0 +1,33 @@
annotations:
artifacthub.io/category: monitoring-logging
artifacthub.io/changes: |
- reverted usage of `app` label in `vm.selectorLabels`
artifacthub.io/license: Apache-2.0
artifacthub.io/links: |
- name: Sources
url: https://github.com/VictoriaMetrics/helm-charts/tree/master/charts/victoria-metrics-common
- name: Charts repo
url: https://victoriametrics.github.io/helm-charts/
artifacthub.io/readme: |
# VictoriaMetrics Common Helm chart
Chart documentation is available [here](https://docs.victoriametrics.com/helm/victoria-metrics-common/).
Changelog is [here](https://docs.victoriametrics.com/helm/victoria-metrics-common/changelog/).
apiVersion: v2
description: VictoriaMetrics Common - contains shared templates for all Victoria Metrics
helm charts
keywords:
- victoriametrics
- monitoring
- kubernetes
- observability
- tsdb
- metrics
- metricsql
- timeseries
kubeVersion: '>=1.23.0-0'
name: victoria-metrics-common
sources:
- https://github.com/VictoriaMetrics/helm-charts
type: library
version: 0.3.0
@@ -0,0 +1,4 @@
# VictoriaMetrics Common Helm chart
Chart documentation is available [here](https://docs.victoriametrics.com/helm/victoria-metrics-common/).
Changelog is [here](https://docs.victoriametrics.com/helm/victoria-metrics-common/changelog/).
@@ -0,0 +1,7 @@
# Release notes for version 0.3.0
**Release date:** 16 Apr 2026
![Helm: v3](https://img.shields.io/badge/Helm-v3.14%2B-informational?color=informational&logo=helm&link=https%3A%2F%2Fgithub.com%2Fhelm%2Fhelm%2Freleases%2Ftag%2Fv3.14.0)
- reverted usage of `app` label in `vm.selectorLabels`
@@ -0,0 +1,87 @@
{{- define "vm.license.secret.key" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $plain := (($Values.license).secret).key | default ((($Values.global).license).secret).key -}}
{{- $managed := (($Values.license).keyRef).key | default ((($Values.global).license).keyRef).key }}
{{- if $plain -}}
{{- $plain -}}
{{- else if $managed -}}
{{- $managed -}}
{{- end -}}
{{- end -}}
{{- define "vm.license.secret.name" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $plain := (($Values.license).secret).name | default ((($Values.global).license).secret).name -}}
{{- $managed := (($Values.license).keyRef).name | default ((($Values.global).license).keyRef).name -}}
{{- if $plain -}}
{{- $plain -}}
{{- else if $managed -}}
{{- $managed -}}
{{- end -}}
{{- end -}}
{{- define "vm.license.key" -}}
{{- $Values := (.helm).Values | default .Values }}
{{- ($Values.license).key | default (($Values.global).license).key | default "" -}}
{{- end -}}
{{- define "vm.enterprise.disabled" -}}
{{- $licenseKey := (include "vm.license.key" .) -}}
{{- $licenseSecretKey := (include "vm.license.secret.key" .) -}}
{{- $licenseSecretName := (include "vm.license.secret.name" .) -}}
{{- or .noEnterprise (and (empty $licenseKey) (and (empty $licenseSecretName) (empty $licenseSecretKey))) -}}
{{- end -}}
{{- define "vm.enterprise.only" -}}
{{- if eq (include "vm.enterprise.disabled" .) "true" }}
{{ fail `Pass valid license at .Values.license or .Values.global.license if you have an enterprise license for running this software.
See https://victoriametrics.com/legal/esa/ for details.
Documentation - https://docs.victoriametrics.com/victoriametrics/enterprise/
for more information, visit https://victoriametrics.com/products/enterprise/
To request a trial license, go to https://victoriametrics.com/products/enterprise/trial/` }}
{{- end -}}
{{- end -}}
{{/*
Return license volume mount
*/}}
{{- define "vm.license.volume" -}}
{{- $licenseSecretKey := (include "vm.license.secret.key" .) -}}
{{- $licenseSecretName := (include "vm.license.secret.name" .) -}}
{{- if and $licenseSecretName $licenseSecretKey -}}
- name: license-key
secret:
secretName: {{ $licenseSecretName }}
{{- end -}}
{{- end -}}
{{/*
Return license volume mount for container
*/}}
{{- define "vm.license.mount" -}}
{{- $licenseSecretKey := (include "vm.license.secret.key" .) -}}
{{- $licenseSecretName := (include "vm.license.secret.name" .) -}}
{{- if and $licenseSecretName $licenseSecretKey -}}
- name: license-key
mountPath: /etc/vm-license-key
readOnly: true
{{- end -}}
{{- end -}}
{{/*
Return license flag if necessary.
*/}}
{{- define "vm.license.flag" -}}
{{- $licenseKey := (include "vm.license.key" .) -}}
{{- $licenseSecretKey := (include "vm.license.secret.key" .) -}}
{{- $licenseSecretName := (include "vm.license.secret.name" .) -}}
{{- if $licenseKey -}}
license: {{ $licenseKey }}
{{- else if and $licenseSecretName $licenseSecretKey -}}
{{- $flagName := "licenseFile" -}}
{{- if eq .flagStyle "kebab" }}
{{- $flagName = "license-file" -}}
{{- end -}}
{{- $flagName }}: /etc/vm-license-key/{{ $licenseSecretKey }}
{{- end -}}
{{- end -}}
@@ -0,0 +1,249 @@
{{- define "vm.namespace" -}}
{{- include "vm.validate.args" . -}}
{{- $Release := (.helm).Release | default .Release -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $Values.namespaceOverride | default ($Values.global).namespaceOverride | default $Release.Namespace -}}
{{- end -}}
{{- define "vm.validate.args" -}}
{{- $Chart := (.helm).Chart | default .Chart -}}
{{- $Capabilities := (.helm).Capabilities | default .Capabilities -}}
{{- if semverCompare "<3.14.0" $Capabilities.HelmVersion.Version }}
{{- fail "This chart requires helm version 3.14.0 or higher" }}
{{- end }}
{{- if empty $Chart -}}
{{- fail "invalid template data" -}}
{{- end -}}
{{- end -}}
{{- /* Expand the name of the chart. */ -}}
{{- define "vm.name" -}}
{{- include "vm.validate.args" . -}}
{{- $Chart := (.helm).Chart | default .Chart -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $nameOverride := $Values.nameOverride | default ($Values.global).nameOverride | default $Chart.Name -}}
{{- if or ($Values.global).disableNameTruncation $Values.disableNameTruncation -}}
{{- $nameOverride -}}
{{- else -}}
{{- $nameOverride | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{- /*
Create a default fully qualified app name.
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
If release name contains chart name it will be used as a full name.
*/ -}}
{{- define "vm.fullname" -}}
{{- include "vm.validate.args" . -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $Chart := (.helm).Chart | default .Chart -}}
{{- $Release := (.helm).Release | default .Release -}}
{{- $fullname := "" -}}
{{- if $Values.fullnameOverride -}}
{{- $fullname = $Values.fullnameOverride -}}
{{- else if ($Values.global).fullnameOverride -}}
{{- $fullname = $Values.global.fullnameOverride -}}
{{- else -}}
{{- $name := default $Chart.Name $Values.nameOverride -}}
{{- if contains $name $Release.Name -}}
{{- $fullname = $Release.Name -}}
{{- else -}}
{{- $fullname = (printf "%s-%s" $Release.Name $name) }}
{{- end -}}
{{- end -}}
{{- $fullname = tpl $fullname . -}}
{{- if or ($Values.global).disableNameTruncation $Values.disableNameTruncation -}}
{{- $fullname -}}
{{- else -}}
{{- $fullname | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end }}
{{- define "vm.cr.fullname" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $_ := set . "overrideKey" "name" -}}
{{- $fullname := include "vm.internal.key" . -}}
{{- $_ := unset . "overrideKey" -}}
{{- if empty $fullname -}}
{{- $fullname = include "vm.fullname" . -}}
{{- end -}}
{{- $fullname = tpl $fullname . -}}
{{- if or ($Values.global).disableNameTruncation $Values.disableNameTruncation -}}
{{- $fullname -}}
{{- else -}}
{{- $fullname | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{- define "vm.managed.fullname" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $_ := set . "overrideKey" "name" -}}
{{- $fullname := include "vm.internal.key" . -}}
{{- $_ := unset . "overrideKey" -}}
{{- if empty $fullname -}}
{{- $fullname = include "vm.fullname" . -}}
{{- end -}}
{{- with include "vm.internal.key.default" . -}}
{{- $prefix := ternary . (printf "vm%s" .) (or (hasPrefix "vm" .) (hasPrefix "vl" .)) -}}
{{- $fullname = printf "%s-%s" $prefix $fullname -}}
{{- end -}}
{{- $fullname = tpl $fullname . -}}
{{- if or ($Values.global).disableNameTruncation $Values.disableNameTruncation -}}
{{- $fullname -}}
{{- else -}}
{{- $fullname | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{- define "vm.plain.fullname" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $_ := set . "overrideKey" "fullnameOverride" -}}
{{- $fullname := include "vm.internal.key" . -}}
{{- $_ := unset . "overrideKey" -}}
{{- if empty $fullname -}}
{{- $fullname = include "vm.fullname" . -}}
{{- with include "vm.internal.key.default" . -}}
{{- $fullname = printf "%s-%s" $fullname . -}}
{{- end -}}
{{- end -}}
{{- $fullname = tpl $fullname . -}}
{{- if or ($Values.global).disableNameTruncation $Values.disableNameTruncation -}}
{{- $fullname -}}
{{- else -}}
{{- $fullname | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{- define "vm.internal.key" -}}
{{- include "vm.validate.args" . -}}
{{- $overrideKey := .overrideKey | default "fullnameOverride" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $key := "" -}}
{{- if .appKey -}}
{{- $appKey := ternary (list .appKey) .appKey (kindIs "string" .appKey) -}}
{{- $ctx := . -}}
{{- $values := $Values -}}
{{- range $ak := $appKey }}
{{- $values = ternary (dict) (index $values $ak | default dict) (empty $values) -}}
{{- $ctx = ternary (dict) (index $ctx $ak | default dict) (empty $ctx) -}}
{{- if and (empty $values) (empty $ctx) -}}
{{- fail (printf "No data for appKey %s" (join "->" $appKey)) -}}
{{- end -}}
{{- if and (kindIs "map" $values) (index $values $overrideKey) -}}
{{- $key = index $values $overrideKey -}}
{{- else if and (kindIs "map" $ctx) (index $ctx $overrideKey) -}}
{{- $key = index $ctx $overrideKey -}}
{{- end -}}
{{- end }}
{{- if and (empty $key) .fallback -}}
{{- $key = include "vm.internal.key.default" . -}}
{{- end -}}
{{- end -}}
{{- $key -}}
{{- end -}}
{{- define "vm.internal.key.default" -}}
{{- with .appKey -}}
{{- $key := ternary (list .) . (kindIs "string" .) -}}
{{- last (without $key "spec") -}}
{{- end -}}
{{- end -}}
{{- /* Create chart name and version as used by the chart label. */ -}}
{{- define "vm.chart" -}}
{{- include "vm.validate.args" . -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $Chart := (.helm).Chart | default .Chart -}}
{{- $chart := printf "%s-%s" $Chart.Name $Chart.Version | replace "+" "_" -}}
{{- if or ($Values.global).disableNameTruncation $Values.disableNameTruncation -}}
{{- $chart -}}
{{- else -}}
{{- $chart | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{- end }}
{{- /* Create the name of the service account to use */ -}}
{{- define "vm.sa.name" -}}
{{- include "vm.validate.args" . -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- if $Values.serviceAccount.create }}
{{- default (include "vm.fullname" .) $Values.serviceAccount.name }}
{{- else -}}
{{- default "default" $Values.serviceAccount.name -}}
{{- end }}
{{- end }}
{{- define "vm.metaLabels" -}}
{{- include "vm.validate.args" . -}}
{{- $Release := (.helm).Release | default .Release -}}
{{- $labels := .extraLabels | default dict -}}
{{- $_ := set $labels "helm.sh/chart" (include "vm.chart" .) -}}
{{- $_ := set $labels "app.kubernetes.io/managed-by" $Release.Service -}}
{{- toYaml $labels -}}
{{- end -}}
{{- define "vm.podLabels" -}}
{{- include "vm.validate.args" . -}}
{{- $Release := (.helm).Release | default .Release -}}
{{- $labels := fromYaml (include "vm.selectorLabels" .) -}}
{{- with $labels.app -}}
{{- $_ := set $labels "app.kubernetes.io/component" . -}}
{{- end -}}
{{- $labels = mergeOverwrite $labels (.extraLabels | default dict) -}}
{{- $_ := set $labels "app.kubernetes.io/managed-by" $Release.Service -}}
{{- toYaml $labels -}}
{{- end -}}
{{- /* Common labels */ -}}
{{- define "vm.labels" -}}
{{- include "vm.validate.args" . -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $globalLabels := deepCopy (($Values.global).extraLabels | default dict) -}}
{{- $labels := fromYaml (include "vm.commonLabels" .) -}}
{{- $labels = mergeOverwrite $globalLabels $labels (fromYaml (include "vm.metaLabels" .)) -}}
{{- with (include "vm.image.tag" .) }}
{{- $_ := set $labels "app.kubernetes.io/version" (regexReplaceAll "(.*)(@sha.*)" . "${1}") -}}
{{- end -}}
{{- toYaml $labels -}}
{{- end -}}
{{- define "vm.release" -}}
{{- include "vm.validate.args" . -}}
{{- $Release := (.helm).Release | default .Release -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $release := default $Release.Name $Values.argocdReleaseOverride -}}
{{- if or ($Values.global).disableNameTruncation $Values.disableNameTruncation -}}
{{- $release -}}
{{- else -}}
{{- $release | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{- define "vm.app.name" -}}
{{- $_ := set . "overrideKey" "name" -}}
{{- $_ := set . "fallback" true -}}
{{- tpl (include "vm.internal.key" .) . -}}
{{- $_ := unset . "overrideKey" -}}
{{- $_ := unset . "fallback" -}}
{{- end -}}
{{- /* Selector labels */ -}}
{{- define "vm.selectorLabels" -}}
{{- $labels := .extraLabels | default dict -}}
{{- $_ := set $labels "app.kubernetes.io/name" (include "vm.name" .) -}}
{{- $_ := set $labels "app.kubernetes.io/instance" (include "vm.release" .) -}}
{{- with (include "vm.app.name" .) -}}
{{- $_ := set $labels "app" . -}}
{{- end -}}
{{- toYaml $labels -}}
{{- end }}
{{- define "vm.commonLabels" -}}
{{- $labels := fromYaml (include "vm.selectorLabels" . ) -}}
{{- with $labels.app -}}
{{- $_ := set $labels "app.kubernetes.io/component" . -}}
{{- $_ := unset $labels "app" -}}
{{- end -}}
{{- toYaml $labels -}}
{{- end -}}
@@ -0,0 +1,61 @@
{{/*
Victoria Metrics Image
*/}}
{{- define "vm.image" -}}
{{- $image := (fromYaml (include "vm.internal.image" .)).image | default dict -}}
{{- $tag := include "vm.image.tag" . -}}
{{- if empty $image.repository -}}
{{- fail "cannot create image without `.repository` defined" -}}
{{- end -}}
{{- $result := tpl (printf "%s:%s" $image.repository $tag) . -}}
{{- with $image.registry | default "" -}}
{{- $result = (printf "%s/%s" . $result) -}}
{{- end -}}
{{- $result -}}
{{- end -}}
{{- define "vm.image.tag" -}}
{{- $Chart := (.helm).Chart | default .Chart -}}
{{- $image := (fromYaml (include "vm.internal.image" .)).image | default dict -}}
{{- $tag := $image.tag -}}
{{- if empty $tag }}
{{- $tag = $Chart.AppVersion -}}
{{- $variant := $image.variant }}
{{- if eq (include "vm.enterprise.disabled" .) "false" -}}
{{- if $variant }}
{{- $variant = printf "enterprise-%s" $variant }}
{{- else }}
{{- $variant = "enterprise" }}
{{- end }}
{{- end -}}
{{- with $variant -}}
{{- $tag = (printf "%s-%s" $tag .) -}}
{{- end -}}
{{- end -}}
{{- $tag -}}
{{- end -}}
{{- define "vm.internal.image" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $values := $Values -}}
{{- $ctx := . -}}
{{- with .appKey -}}
{{- $appKey := ternary (list .) . (kindIs "string" .) -}}
{{- range $ak := $appKey -}}
{{- $values = ternary (dict) (index $values $ak | default dict) (empty $values) -}}
{{- $ctx = ternary (dict) (index $ctx $ak | default dict) (empty $ctx) -}}
{{- if and (empty $values) (empty $ctx) -}}
{{- fail (printf "No data for appKey %s" (join "->" $appKey)) -}}
{{- end -}}
{{- end -}}
{{- end -}}
{{- $image := ternary (deepCopy ($ctx.image | default dict)) (deepCopy ($values.image | default dict)) (hasKey $ctx "image") -}}
{{- if not $image.registry }}
{{- if (($Values.global).image).registry -}}
{{- $_ := set $image "registry" (($Values.global).image).registry -}}
{{- else if hasKey $image "registry" -}}
{{- $_ := unset $image "registry" -}}
{{- end -}}
{{- end -}}
{{- toYaml (dict "image" $image) -}}
{{- end -}}
@@ -0,0 +1,8 @@
{{- define "vm.ingress.port" }}
{{- $port := dict "name" "http" }}
{{- with .port }}
{{- $numberTypes := list "int" "float64" }}
{{- $port = dict (ternary "number" "name" (has (kindOf .) $numberTypes)) . }}
{{- end -}}
{{- toYaml $port -}}
{{- end }}
@@ -0,0 +1,117 @@
{{- define "vm.port.from.flag" -}}
{{- $port := .default -}}
{{- with .flag -}}
{{- $port = regexReplaceAll ".*:(\\d+)" . "${1}" -}}
{{- end -}}
{{- $port -}}
{{- end }}
{{- /*
Return true if the detected platform is Openshift
Usage:
{{- include "vm.isOpenshift" . -}}
*/ -}}
{{- define "vm.isOpenshift" -}}
{{- $Capabilities := (.helm).Capabilities | default .Capabilities -}}
{{- if $Capabilities.APIVersions.Has "security.openshift.io/v1" -}}
{{- true -}}
{{- end -}}
{{- end -}}
{{- /*
Render a compatible securityContext depending on the platform.
Usage:
{{- include "vm.securityContext" (dict "securityContext" .Values.containerSecurityContext "helm" .) -}}
*/ -}}
{{- define "vm.securityContext" -}}
{{- $securityContext := omit .securityContext "enabled" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $adaptMode := (((($Values).global).compatibility).openshift).adaptSecurityContext | default "" -}}
{{- if or (eq $adaptMode "force") (and (eq $adaptMode "auto") (include "vm.isOpenshift" .)) -}}
{{- $securityContext = omit $securityContext "fsGroup" "runAsUser" "runAsGroup" "seLinuxOptions" -}}
{{- end -}}
{{- toYaml $securityContext -}}
{{- end -}}
{{- /*
Render probe
*/ -}}
{{- define "vm.probe" -}}
{{- /* undefined value */ -}}
{{- $null := (fromYaml "value: null").value -}}
{{- $probe := dig .type (dict) .app.probe -}}
{{- $probeType := "" -}}
{{- $defaultProbe := dict -}}
{{- if ne (dig "httpGet" $null $probe) $null -}}
{{- /* httpGet probe */ -}}
{{- $defaultProbe = dict "path" (include "vm.probe.http.path" .) "scheme" (include "vm.probe.http.scheme" .) "port" (include "vm.probe.port" .) -}}
{{- $probeType = "httpGet" -}}
{{- else if ne (dig "tcpSocket" $null $probe) $null -}}
{{- /* tcpSocket probe */ -}}
{{- $defaultProbe = dict "port" (include "vm.probe.port" .) -}}
{{- $probeType = "tcpSocket" -}}
{{- end -}}
{{- $defaultProbe = ternary (dict) (dict $probeType $defaultProbe) (empty $probeType) -}}
{{- $probe = mergeOverwrite $defaultProbe $probe -}}
{{- range $key, $value := $probe -}}
{{- if and (has (kindOf $value) (list "object" "map")) (ne $key $probeType) -}}
{{- $_ := unset $probe $key -}}
{{- end -}}
{{- end -}}
{{- tpl (toYaml $probe) . -}}
{{- end -}}
{{- /*
HTTP GET probe path
*/ -}}
{{- define "vm.probe.http.path" -}}
{{- index .app.extraArgs "http.pathPrefix" | default "" | trimSuffix "/" -}}/health
{{- end -}}
{{- /*
HTTP GET probe scheme
*/ -}}
{{- define "vm.probe.http.scheme" -}}
{{- $isSecure := false -}}
{{- with ((.app).extraArgs).tls -}}
{{- $isSecure = eq (toString .) "true" -}}
{{- end -}}
{{- ternary "HTTPS" "HTTP" $isSecure -}}
{{- end -}}
{{- /*
Net probe port
*/ -}}
{{- define "vm.probe.port" -}}
{{- dig "ports" "name" "http" (.app | dict) -}}
{{- end -}}
{{- define "vm.arg" -}}
{{- if and (empty .value) (kindIs "string" .value) (ne (toString .list) "true") }}
{{- .key -}}
{{- else if eq (toString .value) "true" -}}
-{{ ternary "" "-" (eq (len .key) 1) }}{{ .key }}
{{- else -}}
-{{ ternary "" "-" (eq (len .key) 1) }}{{ .key }}={{ ternary (toJson .value | squote) .value (has (kindOf .value) (list "map" "slice")) }}
{{- end -}}
{{- end -}}
{{- /*
command line arguments
*/ -}}
{{- define "vm.args" -}}
{{- $args := list -}}
{{- range $key, $value := . -}}
{{- if not $key -}}
{{- fail "Empty key in command line args is not allowed" -}}
{{- end -}}
{{- if kindIs "slice" $value -}}
{{- range $v := $value -}}
{{- $args = append $args (include "vm.arg" (dict "key" $key "value" $v "list" true)) -}}
{{- end -}}
{{- else -}}
{{- $args = append $args (include "vm.arg" (dict "key" $key "value" $value)) -}}
{{- end -}}
{{- end -}}
{{- toYaml (dict "args" $args) -}}
{{- end -}}
@@ -0,0 +1,88 @@
{{- /* Create the name for VM service */ -}}
{{- define "vm.service" -}}
{{- include "vm.validate.args" . -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $nameTpl := "" -}}
{{- if eq .style "managed" -}}
{{- $nameTpl = "vm.managed.fullname" }}
{{- else if eq .style "plain" -}}
{{- $nameTpl = "vm.plain.fullname" }}
{{- else -}}
{{- fail ".style argument should be either `plain` or `managed`"}}
{{- end -}}
{{- include $nameTpl . -}}
{{- end }}
{{- define "vm.fqdn" -}}
{{- $name := (include "vm.service" .) -}}
{{- if hasKey . "appIdx" -}}
{{- $name = (printf "%s-%d.%s" $name .appIdx $name) -}}
{{- end -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $ns := (include "vm.namespace" .) -}}
{{- $fqdn := printf "%s.%s.svc" $name $ns -}}
{{- with (($Values.global).cluster).dnsDomain -}}
{{- $fqdn = printf "%s.%s" $fqdn . -}}
{{- end -}}
{{- $fqdn -}}
{{- end -}}
{{- define "vm.host" -}}
{{- $fqdn := (include "vm.fqdn" .) -}}
{{- $port := 80 -}}
{{- $isSecure := ternary false true (empty .appSecure) -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- if .appKey -}}
{{- $appKey := ternary (list .appKey) .appKey (kindIs "string" .appKey) -}}
{{- $values := $Values -}}
{{- $ctx := . -}}
{{- range $ak := $appKey -}}
{{- $values = ternary (dict) (index $values $ak | default dict) (empty $values) -}}
{{- $ctx = ternary (dict) (index $ctx $ak | default dict) (empty $ctx) -}}
{{- end -}}
{{- $spec := dict -}}
{{- if $ctx -}}
{{- $spec = $ctx -}}
{{- else if $values -}}
{{- $spec = $values -}}
{{- end -}}
{{- with ($spec.extraArgs).tls -}}
{{- $isSecure = eq (toString .) "true" -}}
{{- end -}}
{{- $port = (ternary 443 80 $isSecure) -}}
{{- $port = $spec.port | default ($spec.service).servicePort | default ($spec.service).port | default $port -}}
{{- if hasKey . "appIdx" -}}
{{- $port = (include "vm.port.from.flag" (dict "flag" ($spec.extraArgs).httpListenAddr "default" $port)) -}}
{{- end }}
{{- end }}
{{- $fqdn }}:{{ $port }}
{{- end -}}
{{- define "vm.url" -}}
{{- $host := (include "vm.host" .) -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $proto := "http" -}}
{{- $path := .appRoute | default "/" -}}
{{- $isSecure := ternary false true (empty .appSecure) -}}
{{- if .appKey -}}
{{- $appKey := ternary (list .appKey) .appKey (kindIs "string" .appKey) -}}
{{- $values := $Values -}}
{{- $ctx := . -}}
{{- range $ak := $appKey -}}
{{- $values = ternary (dict) (index $values $ak | default dict) (empty $values) -}}
{{- $ctx = ternary (dict) (index $ctx $ak | default dict) (empty $ctx) -}}
{{- end -}}
{{- $spec := dict -}}
{{- if $values -}}
{{- $spec = $values -}}
{{- else if $ctx -}}
{{- $spec = $ctx -}}
{{- end -}}
{{- with ($spec.extraArgs).tls -}}
{{- $isSecure = eq (toString .) "true" -}}
{{- end -}}
{{- $proto = (ternary "https" "http" $isSecure) -}}
{{- $path = dig "http.pathPrefix" $path ($spec.extraArgs | default dict) -}}
{{- end -}}
{{- printf "%s://%s%s" $proto $host (trimSuffix "/" $path) -}}
{{- end -}}
@@ -0,0 +1 @@
unitTest: false
@@ -0,0 +1,45 @@
# =============================================================================
# VictoriaLogs Cluster — PaaSup 커스텀 오버라이드
# 차트: victoria-metrics/victoria-logs-cluster
# 멀티테넌시: AccountID 기반 스토리지 격리 (단일 노드와 달리 실제 격리)
# - 쓰기: vlinsert:9481 /insert/{AccountID}/opentelemetry/v1/logs
# - 조회: vlselect:9471 /select/{AccountID}/logsql/query
# 로그 수집은 opentelemetry-collector가 VictoriaLogs-AccountID 헤더로 전송한다.
# =============================================================================
vlinsert:
replicaCount: 1
resources:
requests:
cpu: 100m
memory: 128Mi
limits:
cpu: 500m
memory: 256Mi
vlstorage:
replicaCount: 1
retentionPeriod: 7d # 로그 보존 기간. 운영 규모에 맞게 조정
persistentVolume:
enabled: true
size: 5Gi
# storageClass: "longhorn"
extraArgs:
memory.allowedPercent: "60"
resources:
requests:
cpu: 100m
memory: 256Mi
limits:
cpu: 500m
memory: 512Mi
vlselect:
replicaCount: 1
resources:
requests:
cpu: 100m
memory: 128Mi
limits:
cpu: 500m
memory: 256Mi
@@ -0,0 +1,33 @@
{{- if .Values.printNotes }}
{{- $ctx := dict "helm" . "style" "plain" }}
{{- $ns := include "vm.namespace" $ctx }}
{{- if .Values.vlinsert.enabled }}
{{- if .Values.vmauth.enabled }}
{{- $_ := set $ctx "appKey" "vmauth" }}
{{- else }}
{{- $_ := set $ctx "appKey" "vlinsert" }}
{{- end }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
Write API:
The VictoriaLogs ingest APIs can be accessed with the following url:
{{ include "vm.url" $ctx }}
Check how to ingest data in https://docs.victoriametrics.com/victorialogs/data-ingestion/
{{- end }}
{{- if .Values.vlselect.enabled }}
{{- if .Values.vmauth.enabled }}
{{- $_ := set $ctx "appKey" "vmauth" }}
{{- else }}
{{- $_ := set $ctx "appKey" "vlselect" }}
{{- end }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
Read API:
The VictoriaLogs query APIs can be accessed with the following url:
{{ include "vm.url" $ctx }}
Check how to query data in https://docs.victoriametrics.com/victorialogs/querying/
{{- end }}
{{- end }}
@@ -0,0 +1,148 @@
{{- define "vlinsert.args" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $app := $Values.vlinsert -}}
{{- $args := dict "select.disable" "true" -}}
{{- $ctx := dict "style" "plain" "appKey" "vlstorage" "helm" .helm }}
{{- $args = mergeOverwrite $args (fromYaml (include "vm.license.flag" $ctx)) -}}
{{- $args = mergeOverwrite $args $app.extraArgs -}}
{{- $storage := $Values.vlstorage }}
{{- if and (not $app.suppressStorageFQDNsRender) $storage.enabled $storage.replicaCount }}
{{- $storageNodes := list }}
{{- $fqdn := include "vm.fqdn" $ctx }}
{{- $port := include "vm.port.from.flag" (dict "flag" $Values.vlstorage.extraArgs.httpListenAddr "default" "9491") }}
{{- range $i := until ($storage.replicaCount | int) -}}
{{- if not (has (float64 $i) $app.excludeStorageIDs) -}}
{{- $_ := set $ctx "appIdx" $i }}
{{- $storageNode := include "vm.fqdn" $ctx -}}
{{- $storageNodes = append $storageNodes (printf "%s:%s" $storageNode $port) -}}
{{- end -}}
{{- end -}}
{{- $_ := unset $ctx "appIdx" }}
{{- $_ := set $args "storageNode" (concat ($args.storageNode | default list) $storageNodes) }}
{{- end -}}
{{- if empty $args.storageNode }}
{{- fail "no storageNodes found. Either set vlstorage.enabled to true or add nodes to vlinsert.extraArgs.storageNode"}}
{{- end }}
{{- toYaml (fromYaml (include "vm.args" $args)).args -}}
{{- end -}}
{{- define "vmauth.args" -}}
{{- $Values := (.helm).Values | default .Values }}
{{- $app := $Values.vmauth -}}
{{- $args := dict -}}
{{- $_ := set $args "auth.config" "/config/auth.yml" -}}
{{- $args = mergeOverwrite $args (fromYaml (include "vm.license.flag" .)) -}}
{{- $args = mergeOverwrite $args $app.extraArgs -}}
{{- toYaml (fromYaml (include "vm.args" $args)).args -}}
{{- end -}}
{{- define "vlselect.args" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $app := $Values.vlselect -}}
{{- $args := dict "insert.disable" "true" -}}
{{- $ctx := dict "style" "plain" "appKey" "vlstorage" "helm" .helm }}
{{- $args = mergeOverwrite $args (fromYaml (include "vm.license.flag" .)) -}}
{{- $args = mergeOverwrite $args $app.extraArgs -}}
{{- $storage := $Values.vlstorage }}
{{- if and (not $app.suppressStorageFQDNsRender) $storage.enabled $storage.replicaCount }}
{{- $storageNodes := list }}
{{- $fqdn := include "vm.fqdn" $ctx }}
{{- $port := include "vm.port.from.flag" (dict "flag" $Values.vlstorage.extraArgs.httpListenAddr "default" "9491") }}
{{- range $i := until ($storage.replicaCount | int) -}}
{{- $_ := set $ctx "appIdx" $i }}
{{- $storageNode := include "vm.fqdn" $ctx -}}
{{- $storageNodes = append $storageNodes (printf "%s:%s" $storageNode $port) -}}
{{- end -}}
{{- $_ := unset $ctx "appIdx" }}
{{- $_ := set $args "storageNode" (concat ($args.storageNode | default list) $storageNodes) }}
{{- end }}
{{- if empty $args.storageNode }}
{{- fail "no storageNodes found. Either set vlstorage.enabled to true or add nodes to vlselect.extraArgs.storageNode"}}
{{- end }}
{{- toYaml (fromYaml (include "vm.args" $args)).args -}}
{{- end -}}
{{- define "vlstorage.args" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $app := $Values.vlstorage -}}
{{- $args := dict -}}
{{- if and (empty $app.retentionPeriod) (empty $app.retentionDiskSpaceUsage) (empty $app.retentionMaxDiskUsagePercent) -}}
{{- fail "either .Values.server.retentionPeriod, .Values.server.retentionDiskSpaceUsage or .Values.server.retentionMaxDiskUsagePercent should be defined" -}}
{{- end -}}
{{- with $app.retentionPeriod -}}
{{- $_ := set $args "retentionPeriod" $app.retentionPeriod -}}
{{- end -}}
{{- with $app.retentionDiskSpaceUsage -}}
{{- $retentionDiskSpaceUsage := int $app.retentionDiskSpaceUsage -}}
{{- if $retentionDiskSpaceUsage -}}
{{- $_ := set $args "retention.maxDiskSpaceUsageBytes" (printf "%dGiB" $retentionDiskSpaceUsage) -}}
{{- else -}}
{{- $_ := set $args "retention.maxDiskSpaceUsageBytes" $app.retentionDiskSpaceUsage -}}
{{- end -}}
{{- end -}}
{{- with $app.retentionMaxDiskUsagePercent -}}
{{- $_ := set $args "retention.maxDiskUsagePercent" $app.retentionMaxDiskUsagePercent -}}
{{- end -}}
{{- $_ := set $args "storageDataPath" $app.persistentVolume.mountPath -}}
{{- $args = mergeOverwrite $args (fromYaml (include "vm.license.flag" .)) -}}
{{- $args = mergeOverwrite $args $app.extraArgs -}}
{{- toYaml (fromYaml (include "vm.args" $args)).args -}}
{{- end -}}
{{- define "vlselect.ports" -}}
{{- $service := .service }}
{{- $extraArgs := .extraArgs -}}
- name: http
port: {{ $service.servicePort }}
protocol: TCP
targetPort: {{ $service.targetPort }}
{{- range $service.extraPorts }}
- name: {{ .name }}
port: {{ .port }}
protocol: TCP
targetPort: {{ .targetPort }}
{{- end }}
{{- end -}}
{{- define "vlinsert.ports" -}}
{{- $service := .service }}
{{- $extraArgs := .extraArgs -}}
- name: http
port: {{ $service.servicePort }}
protocol: TCP
targetPort: {{ $service.targetPort }}
{{- range $service.extraPorts }}
- name: {{ .name }}
port: {{ .port }}
protocol: {{ .protocol | default "TCP" }}
targetPort: {{ .targetPort }}
{{- end }}
{{- end -}}
{{- define "vlstorage.ports" -}}
{{- $service := .service -}}
- port: {{ $service.servicePort }}
targetPort: http
protocol: TCP
name: http
{{- range $service.extraPorts }}
- name: {{ .name }}
port: {{ .port }}
protocol: TCP
targetPort: {{ .targetPort }}
{{- end }}
{{- end -}}
{{- define "vmauth.ports" -}}
{{- $service := .service -}}
- port: {{ $service.servicePort }}
targetPort: http
protocol: TCP
name: http
{{- range $service.extraPorts }}
- name: {{ .name }}
port: {{ .port }}
protocol: TCP
targetPort: {{ .targetPort }}
{{- end }}
{{- end -}}
@@ -0,0 +1,4 @@
{{ range .Values.extraObjects }}
---
{{ tpl (ternary . (toYaml .) (typeIs "string" .)) $ }}
{{ end }}
@@ -0,0 +1,29 @@
{{- $ctx := dict "helm" . }}
{{- $ns := include "vm.namespace" . }}
{{- range $name, $app := .Values }}
{{- if and (kindIs "map" $app) $app.enabled ($app.horizontalPodAutoscaler).enabled }}
{{- $isStatefulSet := eq $name "vlstorage" }}
{{- $hpa := $app.horizontalPodAutoscaler }}
{{- $_ := set $ctx "extraLabels" $app.extraLabels }}
{{- $_ := set $ctx "appKey" $name }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
---
apiVersion: autoscaling/v2
kind: HorizontalPodAutoscaler
metadata:
labels: {{ include "vm.labels" $ctx | nindent 4 }}
name: {{ $fullname }}
namespace: {{ $ns }}
spec:
maxReplicas: {{ $hpa.maxReplicas }}
minReplicas: {{ $hpa.minReplicas }}
scaleTargetRef:
apiVersion: apps/v1
kind: {{ ternary "StatefulSet" "Deployment" $isStatefulSet }}
name: {{ $fullname }}
metrics: {{ toYaml $hpa.metrics | nindent 4 }}
{{- with $hpa.behavior }}
behavior: {{ toYaml . | nindent 4 }}
{{- end -}}
{{- end }}
{{- end }}
@@ -0,0 +1,43 @@
{{- $ctx := dict "helm" . }}
{{- range $name, $app := .Values }}
{{- if and (kindIs "map" $app) $app.enabled ($app.ingress).enabled }}
{{- $ingress := $app.ingress }}
{{- $_ := set $ctx "extraLabels" $ingress.extraLabels }}
{{- $_ := set $ctx "appKey" $name }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
{{- with $ingress.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
name: {{ $fullname }}
namespace: {{ include "vm.namespace" $ }}
spec:
{{- with $ingress.ingressClassName }}
ingressClassName: {{ . }}
{{- end }}
{{- with $ingress.tls }}
tls: {{ toYaml . | nindent 4 }}
{{- end }}
rules:
{{- range $host := $app.ingress.hosts }}
{{- $paths := ternary (list $host.path) $host.path (kindIs "string" $host.path) }}
- host: {{ tpl $host.name $ | quote }}
http:
paths:
{{- range $path := $paths }}
- path: {{ $path }}
{{- with $app.ingress.pathType }}
pathType: {{ . }}
{{- end }}
backend:
service:
name: {{ $fullname }}
port: {{ include "vm.ingress.port" $host | nindent 18 }}
{{- end }}
{{- end }}
{{- end }}
{{- end }}
@@ -0,0 +1,29 @@
{{- $ctx := dict "helm" . }}
{{- range $name, $app := .Values }}
{{- if and (kindIs "map" $app) $app.enabled ($app.podDisruptionBudget).enabled }}
{{- $pdb := $app.podDisruptionBudget }}
{{- $_ := set $ctx "extraLabels" $pdb.labels }}
{{- $_ := set $ctx "appKey" $name }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
---
apiVersion: policy/v1
kind: PodDisruptionBudget
metadata:
name: {{ $fullname }}
namespace: {{ include "vm.namespace" $ }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
spec:
{{- with $pdb.minAvailable }}
minAvailable: {{ . }}
{{- end }}
{{- with $pdb.maxUnavailable }}
maxUnavailable: {{ . }}
{{- end }}
{{- with $pdb.unhealthyPodEvictionPolicy }}
unhealthyPodEvictionPolicy: {{ . }}
{{- end }}
selector:
matchLabels: {{ include "vm.selectorLabels" $ctx | nindent 6 }}
{{- end }}
{{- end }}
@@ -0,0 +1,43 @@
{{- $ctx := dict "helm" . }}
{{- range $name, $app := .Values }}
{{- if and (kindIs "map" $app) $app.enabled ($app.route).enabled }}
{{- $route := $app.route }}
{{- $_ := set $ctx "extraLabels" $route.extraLabels }}
{{- $_ := set $ctx "appKey" $name }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
---
apiVersion: {{ $route.apiVersion | default "gateway.networking.k8s.io/v1" }}
kind: {{ $route.kind | default "HTTPRoute" }}
metadata:
name: {{ $fullname }}
namespace: {{ include "vm.namespace" $ }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- with $route.annotations }}
annotations: {{ tpl (toYaml .) $ | nindent 4 }}
{{- end }}
spec:
{{- with $route.parentRefs }}
parentRefs: {{ toYaml . | nindent 4 }}
{{- end }}
{{- with $route.hostnames }}
hostnames: {{ tpl (toYaml .) $ | nindent 4 }}
{{- end }}
rules:
{{- with $route.extraRules }}
{{- tpl (toYaml .) $ | nindent 4 }}
{{- end }}
- backendRefs:
- name: {{ $fullname }}
port: {{ $route.port | default (include "vm.port.from.flag" (dict "flag" ($app.extraArgs).httpListenAddr)) }}
group: ''
kind: Service
weight: 1
{{- with $route.filters }}
filters: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $route.matches }}
matches: {{ tpl (toYaml .) $ | nindent 8 }}
{{- end }}
{{- end }}
{{- end }}
@@ -0,0 +1,44 @@
{{- $ctx := dict "helm" . }}
{{- range $name, $app := .Values }}
{{- if and (kindIs "map" $app) $app.enabled ($app.vmServiceScrape).enabled }}
{{- $vmServiceScrape := $app.vmServiceScrape }}
{{- $_ := set $ctx "extraLabels" $vmServiceScrape.extraLabels }}
{{- $_ := set $ctx "appKey" $name }}
{{ $fullname := include "vm.plain.fullname" $ctx }}
---
{{ if not $vmServiceScrape.useServiceMonitor }}
apiVersion: operator.victoriametrics.com/v1beta1
kind: VMServiceScrape
{{ else }}
apiVersion: monitoring.coreos.com/v1
kind: ServiceMonitor
{{ end }}
metadata:
{{- with $vmServiceScrape.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
name: {{ $fullname }}
{{- with $vmServiceScrape.namespace }}
namespace: {{ . }}
{{- end }}
spec:
{{- with $vmServiceScrape.spec.namespaceSelector }}
namespaceSelector: {{ toYaml . | nindent 4 }}
{{- else }}
namespaceSelector:
matchNames:
- {{ include "vm.namespace" $ }}
{{- end }}
{{- with $vmServiceScrape.spec.selector }}
selector: {{ toYaml . | nindent 4 }}
{{- else }}
selector:
matchLabels: {{ include "vm.commonLabels" $ctx | nindent 6 }}
{{- end }}
{{- with omit $app.vmServiceScrape.spec "selector" "namespaceSelector"}}
{{ toYaml . | nindent 2 }}
{{- end }}
{{- end }}
{{- end }}
@@ -0,0 +1,63 @@
{{- $ctx := dict "helm" . }}
{{- range $name, $app := .Values }}
{{- if and (kindIs "map" $app) $app.enabled ($app.service).enabled }}
{{- $service := $app.service }}
{{- $_ := set $ctx "extraLabels" $service.labels }}
{{- $_ := set $ctx "appKey" $name }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
---
apiVersion: v1
kind: Service
metadata:
{{- with $service.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
name: {{ $fullname }}
namespace: {{ include "vm.namespace" $ }}
spec:
{{- with $service.trafficDistribution }}
trafficDistribution: {{ . }}
{{- end }}
{{- $type := $service.type }}
{{- if and (not $type) (eq $app.mode "statefulSet") }}
{{- $type = "ClusterIP" }}
{{- end }}
type: {{ $type }}
{{- if eq $type "ClusterIP" }}
{{- with $service.clusterIP }}
clusterIP: {{. }}
{{- end }}
{{- end }}
{{- with $service.externalIPs }}
externalIPs: {{ toYaml . | nindent 4 }}
{{- end }}
{{- with $service.loadBalancerIP }}
loadBalancerIP: {{ . }}
{{- end }}
{{- with $service.loadBalancerSourceRanges }}
loadBalancerSourceRanges: {{ toYaml . | nindent 4 }}
{{- end }}
{{- with $service.healthCheckNodePort }}
healthCheckNodePort: {{ . }}
{{- end }}
{{- with $service.externalTrafficPolicy }}
externalTrafficPolicy: {{ . }}
{{- end }}
{{- with $service.ipFamilyPolicy }}
ipFamilyPolicy: {{ . }}
{{- end }}
{{- with $service.ipFamilies }}
ipFamilies: {{ toYaml . | nindent 4 }}
{{- end }}
{{- $portsTpl := printf "%s.ports" $name }}
{{- with include $portsTpl $app }}
ports: {{ . | nindent 4 }}
{{- if and (eq $type "NodePort") $service.nodePort }}
nodePort: {{ $service.nodePort }}
{{- end }}
{{- end }}
selector: {{ include "vm.selectorLabels" $ctx | nindent 4 }}
{{- end }}
{{- end }}
@@ -0,0 +1,17 @@
{{- $sa := .Values.serviceAccount }}
{{- if $sa.create }}
{{- $ctx := dict "helm" . }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
apiVersion: v1
kind: ServiceAccount
metadata:
{{- $_ := set $ctx "extraLabels" $sa.extraLabels }}
labels: {{ include "vm.metaLabels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
{{- with $sa.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
name: {{ tpl ((.Values.serviceAccount).name | default $fullname) $ctx }}
namespace: {{ $ns }}
{{- end }}
@@ -0,0 +1,31 @@
{{- $app := (.Values).vlinsert | default dict }}
{{- $vector := (.Values).vector | default dict }}
{{- $defaultConfig := $vector.customConfigName }}
{{- if and (or $vector.enabled $vector.customConfigNamespace) (has $defaultConfig $vector.existingConfigMaps) }}
{{- $config := ($vector).customConfig | default dict }}
{{- $ctx := dict "helm" . "appKey" "vlinsert" "style" "plain" }}
{{- if $app.enabled }}
{{- $port := int $app.service.servicePort -}}
{{- range $sinkName, $sinkConfig := $config.sinks }}
{{- if and $sinkConfig (eq $sinkConfig.type "elasticsearch") }}
{{ if or (not $sinkConfig.endpoints) (kindIs "string" $sinkConfig.endpoints) }}
{{- $_ := unset $config.sinks $sinkName }}
{{- $url := printf "%s/insert/elasticsearch" (include "vm.url" $ctx) }}
{{- $_ := set $sinkConfig "endpoints" (list $url) }}
{{- $_ := set $config.sinks $sinkName (deepCopy $sinkConfig) }}
{{- end }}
{{- end }}
{{- end }}
{{- end }}
{{- $ns := include "vm.namespace" $ctx }}
{{- $ns = ternary $ns (($vector).customConfigNamespace | default $ns) $vector.enabled }}
---
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ $defaultConfig }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
namespace: {{ $ns }}
data:
{{ include "vm.fullname" $ctx }}-vector.yaml: |{{ tpl (toYaml $config) . | nindent 4 }}
{{- end }}
@@ -0,0 +1,126 @@
{{- $app := merge (deepCopy .Values.vlinsert) (deepCopy .Values.common) -}}
{{- $_ := set .Values "vlinsert" $app }}
{{- if $app.enabled -}}
{{- $ctx := dict "helm" . "appKey" "vlinsert" }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $sa := include "vm.fullname" . }}
{{- $ns := include "vm.namespace" $ctx }}
apiVersion: apps/v1
kind: Deployment
metadata:
{{- with $app.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
{{- $_ := set $ctx "extraLabels" $app.extraLabels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
name: {{ $fullname }}
namespace: {{ $ns }}
spec:
selector:
matchLabels: {{ include "vm.selectorLabels" $ctx | nindent 6 }}
{{- if not $app.horizontalPodAutoscaler.enabled }}
replicas: {{ $app.replicaCount }}
{{- end }}
{{- with $app.strategy }}
strategy: {{ toYaml . | nindent 4 }}
{{- end }}
template:
metadata:
{{- with $app.podAnnotations }}
annotations: {{ toYaml . | nindent 8 }}
{{- end }}
{{- $_ := set $ctx "extraLabels" $app.podLabels }}
labels: {{ include "vm.podLabels" $ctx | nindent 8 }}
spec:
{{- with $app.priorityClassName }}
priorityClassName: {{ . }}
{{- end }}
{{- with $app.initContainers }}
initContainers: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with ($app.imagePullSecrets | default .Values.global.imagePullSecrets) }}
imagePullSecrets: {{ toYaml . | nindent 8 }}
{{- end }}
containers:
- name: vlinsert
image: {{ include "vm.image" $ctx }}
imagePullPolicy: {{ $app.image.pullPolicy }}
{{- with $app.lifecycle }}
lifecycle: {{ . | toYaml | nindent 12 }}
{{- end }}
{{- with $app.containerWorkingDir }}
workingDir: {{ . }}
{{- end }}
{{- if $app.securityContext.enabled }}
securityContext: {{ include "vm.securityContext" (dict "securityContext" $app.securityContext "helm" .) | nindent 12 }}
{{- end }}
args: {{ include "vlinsert.args" $ctx | nindent 12 }}
{{- with $app.envFrom }}
envFrom: {{ tpl (toYaml .) $ctx | nindent 12 }}
{{- end }}
{{- with $app.env }}
env: {{ tpl (toYaml .) $ctx | nindent 12 }}
{{- end }}
ports:
- name: {{ $app.ports.name | default "http" }}
containerPort: {{ include "vm.port.from.flag" (dict "flag" $app.extraArgs.httpListenAddr "default" "9481") }}
{{- with (fromYaml (include "vm.probe" (dict "app" $app "type" "readiness"))) }}
readinessProbe: {{ toYaml . | nindent 12 }}
{{- end }}
{{- with (fromYaml (include "vm.probe" (dict "app" $app "type" "liveness"))) }}
livenessProbe: {{ toYaml . | nindent 12 }}
{{- end }}
{{- with (fromYaml (include "vm.probe" (dict "app" $app "type" "startup"))) }}
startupProbe: {{ toYaml . | nindent 12 }}
{{- end }}
{{- $license := include "vm.license.mount" . }}
{{- if or $app.extraVolumeMounts $license }}
volumeMounts:
{{- with $app.extraVolumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- $license | nindent 12 }}
{{- end }}
{{- with $app.resources }}
resources: {{ toYaml . | nindent 12 }}
{{- end }}
{{- with $app.extraContainers }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with $app.nodeSelector }}
nodeSelector: {{ toYaml . | nindent 8 }}
{{- end }}
{{- if $app.podSecurityContext.enabled }}
securityContext: {{ include "vm.securityContext" (dict "securityContext" $app.podSecurityContext "helm" .) | nindent 8 }}
{{- end }}
{{- if or (.Values.serviceAccount).name (.Values.serviceAccount).create }}
serviceAccountName: {{ tpl ((.Values.serviceAccount).name | default $sa) $ctx }}
automountServiceAccountToken: {{ .Values.serviceAccount.automountToken }}
{{- end }}
{{- with $app.tolerations }}
tolerations: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $app.affinity }}
affinity: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $app.topologySpreadConstraints }}
topologySpreadConstraints:
{{- range $constraint := . }}
- {{ toYaml $constraint | nindent 10 | trim }}
{{- if not $constraint.labelSelector }}
labelSelector:
matchLabels: {{ include "vm.selectorLabels" $ctx | nindent 14 }}
{{- end }}
{{- end }}
{{- end }}
terminationGracePeriodSeconds: {{ $app.terminationGracePeriodSeconds }}
{{- $license := include "vm.license.volume" . }}
{{- if or $app.extraVolumes $license }}
volumes:
{{- with $app.extraVolumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- $license | nindent 8 }}
{{- end }}
{{- end }}
@@ -0,0 +1,126 @@
{{- $app := merge (deepCopy .Values.vlselect) (deepCopy .Values.common) -}}
{{- $_ := set .Values "vlselect" $app }}
{{- if $app.enabled -}}
{{- $ctx := dict "helm" . "appKey" "vlselect" }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $sa := include "vm.fullname" . }}
{{- $ns := include "vm.namespace" $ctx }}
apiVersion: apps/v1
kind: Deployment
metadata:
{{- with $app.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
{{- $_ := set $ctx "extraLabels" $app.extraLabels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
name: {{ $fullname }}
namespace: {{ $ns }}
spec:
selector:
matchLabels: {{ include "vm.selectorLabels" $ctx | nindent 6 }}
{{- if not $app.horizontalPodAutoscaler.enabled }}
replicas: {{ $app.replicaCount }}
{{- end }}
{{- with $app.strategy }}
strategy: {{ toYaml . | nindent 4 }}
{{- end }}
template:
metadata:
{{- with $app.podAnnotations }}
annotations: {{ toYaml . | nindent 8 }}
{{- end }}
{{- $_ := set $ctx "extraLabels" $app.podLabels }}
labels: {{ include "vm.podLabels" $ctx | nindent 8 }}
spec:
{{- with $app.priorityClassName }}
priorityClassName: {{ . }}
{{- end }}
{{- with $app.initContainers }}
initContainers: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with ($app.imagePullSecrets | default .Values.global.imagePullSecrets) }}
imagePullSecrets: {{ toYaml . | nindent 8 }}
{{- end }}
containers:
- name: vlselect
image: {{ include "vm.image" $ctx }}
imagePullPolicy: {{ $app.image.pullPolicy }}
{{- with $app.lifecycle }}
lifecycle: {{ . | toYaml | nindent 12 }}
{{- end }}
{{- with $app.containerWorkingDir }}
workingDir: {{ . }}
{{- end }}
{{- if $app.securityContext.enabled }}
securityContext: {{ include "vm.securityContext" (dict "securityContext" $app.securityContext "helm" .) | nindent 12 }}
{{- end }}
args: {{ include "vlselect.args" $ctx | nindent 12 }}
{{- with $app.envFrom }}
envFrom: {{ tpl (toYaml .) $ctx | nindent 12 }}
{{- end }}
{{- with $app.env }}
env: {{ tpl (toYaml .) $ctx | nindent 12 }}
{{- end }}
ports:
- name: {{ $app.ports.name | default "http" }}
containerPort: {{ include "vm.port.from.flag" (dict "flag" $app.extraArgs.httpListenAddr "default" "9481") }}
{{- with (fromYaml (include "vm.probe" (dict "app" $app "type" "readiness"))) }}
readinessProbe: {{ toYaml . | nindent 12 }}
{{- end }}
{{- with (fromYaml (include "vm.probe" (dict "app" $app "type" "liveness"))) }}
livenessProbe: {{ toYaml . | nindent 12 }}
{{- end }}
{{- with (fromYaml (include "vm.probe" (dict "app" $app "type" "startup"))) }}
startupProbe: {{ toYaml . | nindent 12 }}
{{- end }}
{{- $license := include "vm.license.mount" . }}
{{- if or $app.extraVolumeMounts $license }}
volumeMounts:
{{- with $app.extraVolumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- $license | nindent 12 }}
{{- end }}
{{- with $app.resources }}
resources: {{ toYaml . | nindent 12 }}
{{- end }}
{{- with $app.extraContainers }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with $app.nodeSelector }}
nodeSelector: {{ toYaml . | nindent 8 }}
{{- end }}
{{- if $app.podSecurityContext.enabled }}
securityContext: {{ include "vm.securityContext" (dict "securityContext" $app.podSecurityContext "helm" .) | nindent 8 }}
{{- end }}
{{- if or (.Values.serviceAccount).name (.Values.serviceAccount).create }}
serviceAccountName: {{ tpl ((.Values.serviceAccount).name | default $sa) $ctx }}
automountServiceAccountToken: {{ .Values.serviceAccount.automountToken }}
{{- end }}
{{- with $app.tolerations }}
tolerations: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $app.affinity }}
affinity: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $app.topologySpreadConstraints }}
topologySpreadConstraints:
{{- range $constraint := . }}
- {{ toYaml $constraint | nindent 10 | trim }}
{{- if not $constraint.labelSelector }}
labelSelector:
matchLabels: {{ include "vm.selectorLabels" $ctx | nindent 14 }}
{{- end }}
{{- end }}
{{- end }}
terminationGracePeriodSeconds: {{ $app.terminationGracePeriodSeconds }}
{{- $license := include "vm.license.volume" . }}
{{- if or $app.extraVolumes $license }}
volumes:
{{- with $app.extraVolumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- $license | nindent 8 }}
{{- end }}
{{- end }}
@@ -0,0 +1,165 @@
{{- $app := merge (deepCopy .Values.vlstorage) (deepCopy .Values.common) -}}
{{- $pvc := $app.persistentVolume }}
{{- $_ := set .Values "vlstorage" $app }}
{{- if $app.enabled -}}
{{- $ctx := dict "helm" . "appKey" "vlstorage" }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $sa := include "vm.fullname" . }}
{{- $ns := include "vm.namespace" $ctx }}
apiVersion: apps/v1
kind: StatefulSet
metadata:
{{- with $app.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
{{- $_ := set $ctx "extraLabels" $app.extraLabels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
name: {{ $fullname }}
namespace: {{ $ns }}
spec:
serviceName: {{ $fullname }}
selector:
matchLabels: {{ include "vm.selectorLabels" $ctx | nindent 6 }}
replicas: {{ $app.replicaCount }}
podManagementPolicy: {{ $app.podManagementPolicy }}
template:
metadata:
{{- with $app.podAnnotations }}
annotations: {{ toYaml . | nindent 8 }}
{{- end }}
{{- $_ := set $ctx "extraLabels" $app.podLabels }}
labels: {{ include "vm.podLabels" $ctx | nindent 8 }}
spec:
{{- with $app.priorityClassName }}
priorityClassName: {{ . }}
{{- end }}
{{- with $app.initContainers }}
initContainers: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with ($app.imagePullSecrets | default .Values.global.imagePullSecrets) }}
imagePullSecrets: {{ toYaml . | nindent 8 }}
{{- end }}
containers:
- name: vlstorage
{{- $_ := set $ctx "appKey" "vlstorage" }}
image: {{ include "vm.image" $ctx }}
imagePullPolicy: {{ $app.image.pullPolicy }}
{{- with $app.containerWorkingDir }}
workingDir: {{ . }}
{{- end }}
{{- if $app.securityContext.enabled }}
securityContext: {{ include "vm.securityContext" (dict "securityContext" $app.securityContext "helm" .) | nindent 12 }}
{{- end }}
{{- with $app.lifecycle }}
lifecycle: {{ . | toYaml | nindent 12 }}
{{- end }}
args: {{ include "vlstorage.args" $ctx | nindent 12 }}
ports:
- name: {{ $app.ports.name | default "http" }}
containerPort: {{ include "vm.port.from.flag" (dict "flag" $app.extraArgs.httpListenAddr "default" "9491") }}
{{- with $app.envFrom }}
envFrom: {{ tpl (toYaml .) $ctx | nindent 12 }}
{{- end }}
{{- with $app.env }}
env: {{ tpl (toYaml .) $ctx | nindent 12 }}
{{- end }}
{{- with (fromYaml (include "vm.probe" (dict "app" $app "type" "readiness"))) }}
readinessProbe: {{ toYaml . | nindent 12 }}
{{- end }}
{{- with (fromYaml (include "vm.probe" (dict "app" $app "type" "liveness"))) }}
livenessProbe: {{ toYaml . | nindent 12 }}
{{- end }}
{{- with (fromYaml (include "vm.probe" (dict "app" $app "type" "startup"))) }}
startupProbe: {{ toYaml . | nindent 12 }}
{{- end }}
{{- with $app.resources }}
resources: {{ toYaml . | nindent 12 }}
{{- end }}
volumeMounts:
{{- with $pvc }}
- name: {{ .name }}
mountPath: {{ .mountPath }}
{{- with .subPath }}
subPath: {{ . }}
{{- end }}
{{- end }}
{{- with $app.extraVolumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- include "vm.license.mount" . | nindent 12 }}
{{- with $app.extraContainers }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with $app.nodeSelector }}
nodeSelector: {{ toYaml . | nindent 8 }}
{{- end }}
{{- if $app.podSecurityContext.enabled }}
securityContext: {{ include "vm.securityContext" (dict "securityContext" $app.podSecurityContext "helm" .) | nindent 8 }}
{{- end }}
{{- if or (.Values.serviceAccount).name (.Values.serviceAccount).create }}
serviceAccountName: {{ tpl ((.Values.serviceAccount).name | default $sa) $ctx }}
automountServiceAccountToken: {{ .Values.serviceAccount.automountToken }}
{{- end }}
{{- with $app.tolerations }}
tolerations: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $app.affinity }}
affinity: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $app.topologySpreadConstraints }}
topologySpreadConstraints:
{{- range $constraint := . }}
- {{ toYaml $constraint | nindent 10 | trim }}
{{- if not $constraint.labelSelector }}
labelSelector:
matchLabels: {{ include "vm.selectorLabels" $ctx | nindent 14 }}
{{- end }}
{{- end }}
{{- end }}
terminationGracePeriodSeconds: {{ $app.terminationGracePeriodSeconds }}
{{- $license := include "vm.license.volume" . }}
{{- if or $app.extraVolumes (not $pvc.enabled) $pvc.existingClaim $license }}
volumes:
{{- with $app.extraVolumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if or (not $pvc.enabled) $pvc.existingClaim }}
- name: vlstorage-volume
{{- if $pvc.enabled }}
persistentVolumeClaim:
claimName: {{ $pvc.existingClaim }}
{{- else }}
emptyDir: {{ toYaml $app.emptyDir | nindent 12 }}
{{- end }}
{{- end }}
{{- $license | nindent 8 }}
{{- end }}
minReadySeconds: {{ $app.minReadySeconds }}
{{- if and $pvc.enabled (not $pvc.existingClaim) }}
volumeClaimTemplates:
- apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: {{ tpl $pvc.name $ctx }}
{{- with $pvc.annotations }}
annotations: {{ toYaml . | nindent 10 }}
{{- end }}
{{- with $pvc.extraLabels }}
labels: {{ toYaml . | nindent 10 }}
{{- end }}
spec:
{{- with $pvc.accessModes }}
accessModes: {{ toYaml . | nindent 10 }}
{{- end }}
{{- with $pvc.volumeAttributeClassName }}
volumeAttributesClassName: {{ . }}
{{- end }}
resources:
requests:
storage: {{ $pvc.size }}
{{- with $pvc.storageClassName }}
storageClassName: {{ ternary "" . (eq "-" .) }}
{{- end }}
{{- end }}
{{- end }}
@@ -0,0 +1,37 @@
{{- if and (empty .Values.vmauth.configSecretName) .Values.vmauth.enabled }}
{{- $ctx := dict "helm" . "appKey" "vmauth" "style" "plain" }}
apiVersion: v1
kind: Secret
metadata:
name: {{ include "vm.plain.fullname" $ctx }}
namespace: {{ include "vm.namespace" $ctx }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
type: Opaque
data:
{{- $config := .Values.vmauth.config }}
{{- $_ := set . "style" "plain" }}
{{- $_ := set . "appKey" "vlinsert" -}}
{{- $writeURL := urlParse (include "vm.url" .) -}}
{{- $_ := set $writeURL "path" (printf "%s/insert" $writeURL.path) -}}
{{- $_ := set . "appKey" "vlselect" -}}
{{- $readURL := urlParse (include "vm.url" .) -}}
{{- $_ := set $readURL "path" (printf "%s/select" $readURL.path) -}}
{{- $_ := set . "vm" (dict "read" $readURL "write" $writeURL) -}}
{{- if or (empty $config) $config.unauthorized_user }}
{{- $urlMap := ($config.unauthorized_user).url_map | default list }}
{{- if empty $urlMap }}
{{- if $.Values.vlselect.service.enabled }}
{{- $readPaths := list (printf "%s/.*" $readURL.path) }}
{{- $readPrefix := urlJoin (omit .vm.read "path") }}
{{- $urlMap = append $urlMap (dict "src_paths" $readPaths "url_prefix" $readPrefix "discover_backend_ips" true) }}
{{- end }}
{{- if $.Values.vlinsert.service.enabled }}
{{- $writePaths := list (printf "%s/.*" $writeURL.path) }}
{{- $writePrefix := urlJoin (omit .vm.write "path") }}
{{- $urlMap = append $urlMap (dict "src_paths" $writePaths "url_prefix" $writePrefix "discover_backend_ips" true) }}
{{- end }}
{{- $_ := set $config "unauthorized_user" (dict "url_map" $urlMap) }}
{{- end }}
{{- end }}
auth.yml: | {{ tpl (toYaml $config) . | b64enc | nindent 4 }}
{{- end }}
@@ -0,0 +1,127 @@
{{- $app := merge (deepCopy .Values.vmauth) (deepCopy .Values.common) -}}
{{- $_ := set .Values "vmauth" $app }}
{{- if $app.enabled -}}
{{- $ctx := dict "helm" . "appKey" "vmauth" }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $sa := include "vm.fullname" . }}
{{- $ns := include "vm.namespace" $ctx }}
apiVersion: apps/v1
kind: Deployment
metadata:
{{- with $app.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
{{- $_ := set $ctx "extraLabels" $app.extraLabels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
name: {{ $fullname }}
namespace: {{ $ns }}
spec:
selector:
matchLabels: {{ include "vm.selectorLabels" $ctx | nindent 6 }}
{{- if not $app.horizontalPodAutoscaler.enabled }}
replicas: {{ $app.replicaCount }}
{{- end }}
{{- with $app.strategy }}
strategy: {{ toYaml . | nindent 4 }}
{{- end }}
template:
metadata:
annotations:
{{- with $app.podAnnotations }}
{{- toYaml . | nindent 8 }}
{{- end }}
checksum/config: {{ include (print $.Template.BasePath "/vmauth-config.yaml") . | sha256sum }}
{{- $_ := set $ctx "extraLabels" $app.podLabels }}
labels: {{ include "vm.podLabels" $ctx | nindent 8 }}
{{- $_ := unset $ctx "extraLabels" }}
spec:
{{- with $app.priorityClassName }}
priorityClassName: {{ . }}
{{- end }}
{{- if or (.Values.serviceAccount).name (.Values.serviceAccount).create }}
serviceAccountName: {{ tpl ((.Values.serviceAccount).name | default $sa) $ctx }}
automountServiceAccountToken: {{ .Values.serviceAccount.automountToken }}
{{- end }}
{{- with $app.initContainers }}
initContainers: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with ($app.imagePullSecrets | default .Values.global.imagePullSecrets) }}
imagePullSecrets: {{ toYaml . | nindent 8 }}
{{- end }}
containers:
- name: vmauth
image: {{ include "vm.image" $ctx }}
imagePullPolicy: {{ $app.image.pullPolicy }}
{{- with $app.lifecycle }}
lifecycle: {{ . | toYaml | nindent 12 }}
{{- end }}
{{- with $app.containerWorkingDir }}
workingDir: {{ . }}
{{- end }}
{{- if $app.securityContext.enabled }}
securityContext: {{ include "vm.securityContext" (dict "securityContext" $app.securityContext "helm" .) | nindent 12 }}
{{- end }}
args: {{ include "vmauth.args" $ctx | nindent 12 }}
{{- with $app.envFrom }}
envFrom: {{ tpl (toYaml .) $ctx | nindent 12 }}
{{- end }}
{{- with $app.env }}
env: {{ tpl (toYaml .) $ctx | nindent 12 }}
{{- end }}
ports:
- name: {{ $app.ports.name | default "http" }}
containerPort: {{ include "vm.port.from.flag" (dict "flag" $app.extraArgs.httpListenAddr "default" "8427") }}
{{- with (fromYaml (include "vm.probe" (dict "app" $app "type" "readiness"))) }}
readinessProbe: {{ toYaml . | nindent 12 }}
{{- end }}
{{- with (fromYaml (include "vm.probe" (dict "app" $app "type" "liveness"))) }}
livenessProbe: {{ toYaml . | nindent 12 }}
{{- end }}
{{- with (fromYaml (include "vm.probe" (dict "app" $app "type" "startup"))) }}
startupProbe: {{ toYaml . | nindent 12 }}
{{- end }}
volumeMounts:
- name: config
mountPath: /config
{{- with $app.extraVolumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- include "vm.license.mount" . | nindent 12 }}
{{- with $app.resources }}
resources: {{ toYaml . | nindent 12 }}
{{- end }}
{{- with $app.extraContainers }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with $app.nodeSelector }}
nodeSelector: {{ toYaml . | nindent 8 }}
{{- end }}
{{- if $app.podSecurityContext.enabled }}
securityContext: {{ include "vm.securityContext" (dict "securityContext" $app.podSecurityContext "helm" .) | nindent 8 }}
{{- end }}
{{- with $app.tolerations }}
tolerations: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $app.affinity }}
affinity: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $app.topologySpreadConstraints }}
topologySpreadConstraints:
{{- range $constraint := . }}
- {{ toYaml $constraint | nindent 10 | trim }}
{{- if not $constraint.labelSelector }}
labelSelector:
matchLabels: {{ include "vm.selectorLabels" $ctx | nindent 14 }}
{{- end }}
{{- end }}
{{- end }}
volumes:
- name: config
secret:
secretName: {{ ternary $fullname $app.configSecretName (empty $app.configSecretName) }}
{{- with $app.extraVolumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- include "vm.license.volume" . | nindent 8 }}
{{- end }}
@@ -0,0 +1,32 @@
{{- $ctx := dict "helm" . }}
{{- $ns := include "vm.namespace" . }}
{{- range $name, $app := .Values }}
{{- if and ($.Capabilities.APIVersions.Has "autoscaling.k8s.io/v1") (kindIs "map" $app) $app.enabled ($app.verticalPodAutoscaler).enabled }}
{{- $isStatefulSet := eq $name "vlstorage" }}
{{- $vpa := $app.verticalPodAutoscaler }}
{{- $_ := set $ctx "extraLabels" $app.extraLabels }}
{{- $_ := set $ctx "appKey" $name }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
---
apiVersion: autoscaling.k8s.io/v1
kind: VerticalPodAutoscaler
metadata:
labels: {{ include "vm.labels" $ctx | nindent 4 }}
name: {{ $fullname }}
namespace: {{ $ns }}
spec:
{{- with $vpa.recommenders }}
recommenders: {{ toYaml . | nindent 4 }}
{{- end }}
targetRef:
apiVersion: apps/v1
kind: {{ ternary "StatefulSet" "Deployment" $isStatefulSet }}
name: {{ $fullname }}
{{- with $vpa.updatePolicy }}
updatePolicy: {{ toYaml . | nindent 4 }}
{{- end }}
{{- with $vpa.resourcePolicy }}
resourcePolicy: {{ toYaml . | nindent 4 }}
{{- end }}
{{- end }}
{{- end }}
File diff suppressed because it is too large Load Diff