Add VictoriaMetrics observability stack + sync catalog for monitoring test

- VM stack 10 charts: victoria-metrics-cluster/auth, victoria-logs-cluster,
  victoria-metrics-agent/alert, opentelemetry-collector, kube-state-metrics,
  prometheus-node-exporter, alertmanager, perses (JWT/OIDC, Infisical-ready)
- ArgoCD ApplicationSet (syncWave) + per-chart dip-values overlays
- doc/victoria-metrics-architecture.md, define-chart-resources updates
- includes pending working-tree changes (mlflow, kubeflow, apisix, CLAUDE.md)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
wbsong111
2026-06-25 11:10:51 +09:00
parent a55427730e
commit 6290322f1b
514 changed files with 68103 additions and 40 deletions
@@ -0,0 +1,30 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/
*.md.gotmpl
CHANGELOG.md
_changelog.md
_index.md
e2e/
lint/
tests/
@@ -0,0 +1,70 @@
# victoria-metrics-agent 버전 갱신 가이드
> **카탈로그 업데이트 방식**: 기존 버전 디렉토리는 유지하고, 신규 버전 디렉토리를 새로 생성한다.
> `manifests/helm/victoria-metrics-agent/<new-version>/` 디렉토리를 직접 추가하는 방식으로 관리한다.
## 1. git 작업 환경 구성
- dip-catalog git 다운로드
```sh
git clone https://github.com/paasup/dip-catalog.git
```
- 작업 브랜치로 체크아웃
```sh
git checkout -b update-victoria-metrics-agent/<new-version>
```
## 2. helm chart 업데이트
### 1) 기존 버전 디렉토리 복사
신규 버전 디렉토리를 기존 버전에서 복사하여 시작한다.
`BUILD-README.md`, `CUSTOM-README.md`, `custom-values.yaml`가 함께 복사된다.
```sh
cd ~/dip-catalog/manifests/helm/victoria-metrics-agent
# 기존 버전에서 신규 버전 디렉토리 복사
cp -r 0.40.0 <new-version>
```
### 2) 업스트림 차트 파일 업데이트
신규 버전 디렉토리에서 업스트림 차트 파일만 교체한다.
`BUILD-README.md`, `CUSTOM-README.md`, `custom-values.yaml`는 유지한다.
```sh
cd ~/dip-catalog/manifests/helm/victoria-metrics-agent
# helm repo 추가
helm repo add victoria-metrics https://victoriametrics.github.io/helm-charts/
helm repo update
# 신규 버전 차트 다운로드 후 압축 해제
helm pull victoria-metrics/victoria-metrics-agent --version="<new-version>"
tar xzvf victoria-metrics-agent-<new-version>.tgz -C <new-version> --strip-components=1
# 불필요한 파일 삭제
rm victoria-metrics-agent-<new-version>.tgz
```
## 3. git push 및 tag 추가
```sh
git add .
git commit -m "update victoria-metrics-agent/<new-version>"
git checkout main
git merge update-victoria-metrics-agent/<new-version>
git push -u origin main
git branch -d update-victoria-metrics-agent/<new-version>
git tag victoria-metrics-agent/<new-version>
git push origin victoria-metrics-agent/<new-version>
```
## 4. 차트 버전 정보
- victoria-metrics-agent/0.40.0
- Chart version: 0.40.0
- App version: v1.144.0
- 업스트림: https://victoriametrics.github.io/helm-charts/
@@ -0,0 +1,53 @@
# vmagent 배포 (Kubernetes 메트릭 수집)
kubelet·cadvisor·kube-state-metrics·node-exporter·파드 annotation을 스크레이핑하여 VictoriaMetrics Cluster로 전송한다.
## 1. 배포 방법
### 사전 준비 — relabel ConfigMap
`remoteWrite`의 `urlRelabelConfig`가 참조하는 ConfigMap을 먼저 생성한다. 네임스페이스 → accountID 분기 규칙을 담는다.
```sh
kubectl create configmap vmagent-relabel-configs -n monitoring \
--from-file=demo01.yaml --from-file=demo02.yaml --from-file=platform.yaml
```
각 파일은 `write_relabel_configs` 규칙(예: 특정 namespace만 통과)을 담는다. 테넌트별 격리가 필요 없으면 fallback(accountID 0) remoteWrite 하나만 남겨도 된다.
```sh
helm upgrade vmagent ./ -f custom-values.yaml --install -n monitoring
```
## 2. custom-values.yaml 설정 설명
### 2.1 remoteWrite (accountID 매핑)
| accountID | 대상 | urlRelabelConfig |
|-----------|------|------------------|
| 1 | demo01 (namespace: demo01-*) | `/relabel/demo01.yaml` |
| 2 | demo02 (namespace: demo02-*) | `/relabel/demo02.yaml` |
| 9000 | platform (kafka-system, kubeflow 등) | `/relabel/platform.yaml` |
| 0 | fallback (미매칭) | 없음 |
> 쓰기 경로는 vmauth를 경유하지 않고 vminsert(`:8480`)에 직접 쓴다. `writeRelabelConfigs`(camelCase)는 CLI 미지원이라 파일 마운트(`urlRelabelConfig`) 방식을 사용한다.
### 2.2 scrape_configs
kubelet / cadvisor / kube-state-metrics / node-exporter / `kubernetes-pods`(annotation 기반) 5개 job을 포함한다. kube-state-metrics·node-exporter는 `monitoring` 네임스페이스의 엔드포인트를 keep 한다.
### 2.3 RBAC
`rbac.extraRules`로 nodes/proxy, nodes/metrics, `/metrics/cadvisor` 등 kubelet 스크레이프 권한을 부여한다.
## 3. 의존 관계
- **전송 대상**: vmcluster vminsert:8480
- **스크레이프 대상**: kube-state-metrics, prometheus-node-exporter (먼저 배포)
## 4. 검증
```sh
kubectl port-forward -n monitoring deploy/vmagent-victoria-metrics-agent 8429:8429
curl -s http://localhost:8429/targets | grep -c 'up' # active target 확인
```
@@ -0,0 +1,6 @@
dependencies:
- name: victoria-metrics-common
repository: oci://ghcr.io/victoriametrics/helm-charts
version: 0.3.0
digest: sha256:cadb4ced35cde20c5f8437f6ff223ded677542490848e1b3a3b5f330f3069ebc
generated: "2026-04-16T10:13:25.270885263Z"
@@ -0,0 +1,46 @@
annotations:
artifacthub.io/category: monitoring-logging
artifacthub.io/changes: |
- bump version of VM components to [v1.144.0](https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.144.0)
artifacthub.io/license: Apache-2.0
artifacthub.io/links: |
- name: Sources
url: https://github.com/VictoriaMetrics/helm-charts/tree/master/charts/victoria-metrics-agent
- name: Charts repo
url: https://victoriametrics.github.io/helm-charts/
- name: Docs
url: https://docs.victoriametrics.com/victoriametrics/vmagent/
- name: Changelog
url: https://docs.victoriametrics.com/victoriametrics/changelog/
artifacthub.io/readme: |
# VictoriaMetrics Agent Helm chart
Chart documentation is available [here](https://docs.victoriametrics.com/helm/victoria-metrics-agent/).
Changelog is [here](https://docs.victoriametrics.com/helm/victoria-metrics-agent/changelog/).
apiVersion: v2
appVersion: v1.144.0
dependencies:
- name: victoria-metrics-common
repository: oci://ghcr.io/victoriametrics/helm-charts
version: 0.3.*
description: VictoriaMetrics Agent - collects metrics from various sources and stores
them to VictoriaMetrics
home: https://github.com/VictoriaMetrics/helm-charts
icon: https://avatars.githubusercontent.com/u/43720803?s=200&v=4
keywords:
- victoriametrics
- vmagent
- agent
- collector
- monitoring
- kubernetes
- observability
- metrics
- timeseries
- servicediscovery
kubeVersion: '>=1.25.0-0'
name: victoria-metrics-agent
sources:
- https://github.com/VictoriaMetrics/helm-charts
type: application
version: 0.40.0
@@ -0,0 +1,4 @@
# VictoriaMetrics Agent Helm chart
Chart documentation is available [here](https://docs.victoriametrics.com/helm/victoria-metrics-agent/).
Changelog is [here](https://docs.victoriametrics.com/helm/victoria-metrics-agent/changelog/).
@@ -0,0 +1,7 @@
# Release notes for version 0.40.0
**Release date:** 25 May 2026
![Helm: v3](https://img.shields.io/badge/Helm-v3.14%2B-informational?color=informational&logo=helm&link=https%3A%2F%2Fgithub.com%2Fhelm%2Fhelm%2Freleases%2Ftag%2Fv3.14.0) ![AppVersion: v1.144.0](https://img.shields.io/badge/v1.144.0-success?logo=VictoriaMetrics&labelColor=gray&link=https%3A%2F%2Fdocs.victoriametrics.com%2Fvictoriametrics%2Fchangelog%2F%23v11440)
- bump version of VM components to [v1.144.0](https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.144.0)
@@ -0,0 +1,26 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/
*.md.gotmpl
CHANGELOG.md
_changelog.md
_index.md
@@ -0,0 +1,3 @@
dependencies: []
digest: sha256:643d5437104296e21d906ecb15b2c96ad278f20cfc4af53b12bb6069bd853726
generated: "2024-11-13T12:10:17.363248379Z"
@@ -0,0 +1,33 @@
annotations:
artifacthub.io/category: monitoring-logging
artifacthub.io/changes: |
- reverted usage of `app` label in `vm.selectorLabels`
artifacthub.io/license: Apache-2.0
artifacthub.io/links: |
- name: Sources
url: https://github.com/VictoriaMetrics/helm-charts/tree/master/charts/victoria-metrics-common
- name: Charts repo
url: https://victoriametrics.github.io/helm-charts/
artifacthub.io/readme: |
# VictoriaMetrics Common Helm chart
Chart documentation is available [here](https://docs.victoriametrics.com/helm/victoria-metrics-common/).
Changelog is [here](https://docs.victoriametrics.com/helm/victoria-metrics-common/changelog/).
apiVersion: v2
description: VictoriaMetrics Common - contains shared templates for all Victoria Metrics
helm charts
keywords:
- victoriametrics
- monitoring
- kubernetes
- observability
- tsdb
- metrics
- metricsql
- timeseries
kubeVersion: '>=1.23.0-0'
name: victoria-metrics-common
sources:
- https://github.com/VictoriaMetrics/helm-charts
type: library
version: 0.3.0
@@ -0,0 +1,4 @@
# VictoriaMetrics Common Helm chart
Chart documentation is available [here](https://docs.victoriametrics.com/helm/victoria-metrics-common/).
Changelog is [here](https://docs.victoriametrics.com/helm/victoria-metrics-common/changelog/).
@@ -0,0 +1,7 @@
# Release notes for version 0.3.0
**Release date:** 16 Apr 2026
![Helm: v3](https://img.shields.io/badge/Helm-v3.14%2B-informational?color=informational&logo=helm&link=https%3A%2F%2Fgithub.com%2Fhelm%2Fhelm%2Freleases%2Ftag%2Fv3.14.0)
- reverted usage of `app` label in `vm.selectorLabels`
@@ -0,0 +1,87 @@
{{- define "vm.license.secret.key" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $plain := (($Values.license).secret).key | default ((($Values.global).license).secret).key -}}
{{- $managed := (($Values.license).keyRef).key | default ((($Values.global).license).keyRef).key }}
{{- if $plain -}}
{{- $plain -}}
{{- else if $managed -}}
{{- $managed -}}
{{- end -}}
{{- end -}}
{{- define "vm.license.secret.name" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $plain := (($Values.license).secret).name | default ((($Values.global).license).secret).name -}}
{{- $managed := (($Values.license).keyRef).name | default ((($Values.global).license).keyRef).name -}}
{{- if $plain -}}
{{- $plain -}}
{{- else if $managed -}}
{{- $managed -}}
{{- end -}}
{{- end -}}
{{- define "vm.license.key" -}}
{{- $Values := (.helm).Values | default .Values }}
{{- ($Values.license).key | default (($Values.global).license).key | default "" -}}
{{- end -}}
{{- define "vm.enterprise.disabled" -}}
{{- $licenseKey := (include "vm.license.key" .) -}}
{{- $licenseSecretKey := (include "vm.license.secret.key" .) -}}
{{- $licenseSecretName := (include "vm.license.secret.name" .) -}}
{{- or .noEnterprise (and (empty $licenseKey) (and (empty $licenseSecretName) (empty $licenseSecretKey))) -}}
{{- end -}}
{{- define "vm.enterprise.only" -}}
{{- if eq (include "vm.enterprise.disabled" .) "true" }}
{{ fail `Pass valid license at .Values.license or .Values.global.license if you have an enterprise license for running this software.
See https://victoriametrics.com/legal/esa/ for details.
Documentation - https://docs.victoriametrics.com/victoriametrics/enterprise/
for more information, visit https://victoriametrics.com/products/enterprise/
To request a trial license, go to https://victoriametrics.com/products/enterprise/trial/` }}
{{- end -}}
{{- end -}}
{{/*
Return license volume mount
*/}}
{{- define "vm.license.volume" -}}
{{- $licenseSecretKey := (include "vm.license.secret.key" .) -}}
{{- $licenseSecretName := (include "vm.license.secret.name" .) -}}
{{- if and $licenseSecretName $licenseSecretKey -}}
- name: license-key
secret:
secretName: {{ $licenseSecretName }}
{{- end -}}
{{- end -}}
{{/*
Return license volume mount for container
*/}}
{{- define "vm.license.mount" -}}
{{- $licenseSecretKey := (include "vm.license.secret.key" .) -}}
{{- $licenseSecretName := (include "vm.license.secret.name" .) -}}
{{- if and $licenseSecretName $licenseSecretKey -}}
- name: license-key
mountPath: /etc/vm-license-key
readOnly: true
{{- end -}}
{{- end -}}
{{/*
Return license flag if necessary.
*/}}
{{- define "vm.license.flag" -}}
{{- $licenseKey := (include "vm.license.key" .) -}}
{{- $licenseSecretKey := (include "vm.license.secret.key" .) -}}
{{- $licenseSecretName := (include "vm.license.secret.name" .) -}}
{{- if $licenseKey -}}
license: {{ $licenseKey }}
{{- else if and $licenseSecretName $licenseSecretKey -}}
{{- $flagName := "licenseFile" -}}
{{- if eq .flagStyle "kebab" }}
{{- $flagName = "license-file" -}}
{{- end -}}
{{- $flagName }}: /etc/vm-license-key/{{ $licenseSecretKey }}
{{- end -}}
{{- end -}}
@@ -0,0 +1,249 @@
{{- define "vm.namespace" -}}
{{- include "vm.validate.args" . -}}
{{- $Release := (.helm).Release | default .Release -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $Values.namespaceOverride | default ($Values.global).namespaceOverride | default $Release.Namespace -}}
{{- end -}}
{{- define "vm.validate.args" -}}
{{- $Chart := (.helm).Chart | default .Chart -}}
{{- $Capabilities := (.helm).Capabilities | default .Capabilities -}}
{{- if semverCompare "<3.14.0" $Capabilities.HelmVersion.Version }}
{{- fail "This chart requires helm version 3.14.0 or higher" }}
{{- end }}
{{- if empty $Chart -}}
{{- fail "invalid template data" -}}
{{- end -}}
{{- end -}}
{{- /* Expand the name of the chart. */ -}}
{{- define "vm.name" -}}
{{- include "vm.validate.args" . -}}
{{- $Chart := (.helm).Chart | default .Chart -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $nameOverride := $Values.nameOverride | default ($Values.global).nameOverride | default $Chart.Name -}}
{{- if or ($Values.global).disableNameTruncation $Values.disableNameTruncation -}}
{{- $nameOverride -}}
{{- else -}}
{{- $nameOverride | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{- /*
Create a default fully qualified app name.
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
If release name contains chart name it will be used as a full name.
*/ -}}
{{- define "vm.fullname" -}}
{{- include "vm.validate.args" . -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $Chart := (.helm).Chart | default .Chart -}}
{{- $Release := (.helm).Release | default .Release -}}
{{- $fullname := "" -}}
{{- if $Values.fullnameOverride -}}
{{- $fullname = $Values.fullnameOverride -}}
{{- else if ($Values.global).fullnameOverride -}}
{{- $fullname = $Values.global.fullnameOverride -}}
{{- else -}}
{{- $name := default $Chart.Name $Values.nameOverride -}}
{{- if contains $name $Release.Name -}}
{{- $fullname = $Release.Name -}}
{{- else -}}
{{- $fullname = (printf "%s-%s" $Release.Name $name) }}
{{- end -}}
{{- end -}}
{{- $fullname = tpl $fullname . -}}
{{- if or ($Values.global).disableNameTruncation $Values.disableNameTruncation -}}
{{- $fullname -}}
{{- else -}}
{{- $fullname | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end }}
{{- define "vm.cr.fullname" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $_ := set . "overrideKey" "name" -}}
{{- $fullname := include "vm.internal.key" . -}}
{{- $_ := unset . "overrideKey" -}}
{{- if empty $fullname -}}
{{- $fullname = include "vm.fullname" . -}}
{{- end -}}
{{- $fullname = tpl $fullname . -}}
{{- if or ($Values.global).disableNameTruncation $Values.disableNameTruncation -}}
{{- $fullname -}}
{{- else -}}
{{- $fullname | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{- define "vm.managed.fullname" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $_ := set . "overrideKey" "name" -}}
{{- $fullname := include "vm.internal.key" . -}}
{{- $_ := unset . "overrideKey" -}}
{{- if empty $fullname -}}
{{- $fullname = include "vm.fullname" . -}}
{{- end -}}
{{- with include "vm.internal.key.default" . -}}
{{- $prefix := ternary . (printf "vm%s" .) (or (hasPrefix "vm" .) (hasPrefix "vl" .)) -}}
{{- $fullname = printf "%s-%s" $prefix $fullname -}}
{{- end -}}
{{- $fullname = tpl $fullname . -}}
{{- if or ($Values.global).disableNameTruncation $Values.disableNameTruncation -}}
{{- $fullname -}}
{{- else -}}
{{- $fullname | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{- define "vm.plain.fullname" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $_ := set . "overrideKey" "fullnameOverride" -}}
{{- $fullname := include "vm.internal.key" . -}}
{{- $_ := unset . "overrideKey" -}}
{{- if empty $fullname -}}
{{- $fullname = include "vm.fullname" . -}}
{{- with include "vm.internal.key.default" . -}}
{{- $fullname = printf "%s-%s" $fullname . -}}
{{- end -}}
{{- end -}}
{{- $fullname = tpl $fullname . -}}
{{- if or ($Values.global).disableNameTruncation $Values.disableNameTruncation -}}
{{- $fullname -}}
{{- else -}}
{{- $fullname | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{- define "vm.internal.key" -}}
{{- include "vm.validate.args" . -}}
{{- $overrideKey := .overrideKey | default "fullnameOverride" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $key := "" -}}
{{- if .appKey -}}
{{- $appKey := ternary (list .appKey) .appKey (kindIs "string" .appKey) -}}
{{- $ctx := . -}}
{{- $values := $Values -}}
{{- range $ak := $appKey }}
{{- $values = ternary (dict) (index $values $ak | default dict) (empty $values) -}}
{{- $ctx = ternary (dict) (index $ctx $ak | default dict) (empty $ctx) -}}
{{- if and (empty $values) (empty $ctx) -}}
{{- fail (printf "No data for appKey %s" (join "->" $appKey)) -}}
{{- end -}}
{{- if and (kindIs "map" $values) (index $values $overrideKey) -}}
{{- $key = index $values $overrideKey -}}
{{- else if and (kindIs "map" $ctx) (index $ctx $overrideKey) -}}
{{- $key = index $ctx $overrideKey -}}
{{- end -}}
{{- end }}
{{- if and (empty $key) .fallback -}}
{{- $key = include "vm.internal.key.default" . -}}
{{- end -}}
{{- end -}}
{{- $key -}}
{{- end -}}
{{- define "vm.internal.key.default" -}}
{{- with .appKey -}}
{{- $key := ternary (list .) . (kindIs "string" .) -}}
{{- last (without $key "spec") -}}
{{- end -}}
{{- end -}}
{{- /* Create chart name and version as used by the chart label. */ -}}
{{- define "vm.chart" -}}
{{- include "vm.validate.args" . -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $Chart := (.helm).Chart | default .Chart -}}
{{- $chart := printf "%s-%s" $Chart.Name $Chart.Version | replace "+" "_" -}}
{{- if or ($Values.global).disableNameTruncation $Values.disableNameTruncation -}}
{{- $chart -}}
{{- else -}}
{{- $chart | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{- end }}
{{- /* Create the name of the service account to use */ -}}
{{- define "vm.sa.name" -}}
{{- include "vm.validate.args" . -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- if $Values.serviceAccount.create }}
{{- default (include "vm.fullname" .) $Values.serviceAccount.name }}
{{- else -}}
{{- default "default" $Values.serviceAccount.name -}}
{{- end }}
{{- end }}
{{- define "vm.metaLabels" -}}
{{- include "vm.validate.args" . -}}
{{- $Release := (.helm).Release | default .Release -}}
{{- $labels := .extraLabels | default dict -}}
{{- $_ := set $labels "helm.sh/chart" (include "vm.chart" .) -}}
{{- $_ := set $labels "app.kubernetes.io/managed-by" $Release.Service -}}
{{- toYaml $labels -}}
{{- end -}}
{{- define "vm.podLabels" -}}
{{- include "vm.validate.args" . -}}
{{- $Release := (.helm).Release | default .Release -}}
{{- $labels := fromYaml (include "vm.selectorLabels" .) -}}
{{- with $labels.app -}}
{{- $_ := set $labels "app.kubernetes.io/component" . -}}
{{- end -}}
{{- $labels = mergeOverwrite $labels (.extraLabels | default dict) -}}
{{- $_ := set $labels "app.kubernetes.io/managed-by" $Release.Service -}}
{{- toYaml $labels -}}
{{- end -}}
{{- /* Common labels */ -}}
{{- define "vm.labels" -}}
{{- include "vm.validate.args" . -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $globalLabels := deepCopy (($Values.global).extraLabels | default dict) -}}
{{- $labels := fromYaml (include "vm.commonLabels" .) -}}
{{- $labels = mergeOverwrite $globalLabels $labels (fromYaml (include "vm.metaLabels" .)) -}}
{{- with (include "vm.image.tag" .) }}
{{- $_ := set $labels "app.kubernetes.io/version" (regexReplaceAll "(.*)(@sha.*)" . "${1}") -}}
{{- end -}}
{{- toYaml $labels -}}
{{- end -}}
{{- define "vm.release" -}}
{{- include "vm.validate.args" . -}}
{{- $Release := (.helm).Release | default .Release -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $release := default $Release.Name $Values.argocdReleaseOverride -}}
{{- if or ($Values.global).disableNameTruncation $Values.disableNameTruncation -}}
{{- $release -}}
{{- else -}}
{{- $release | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{- define "vm.app.name" -}}
{{- $_ := set . "overrideKey" "name" -}}
{{- $_ := set . "fallback" true -}}
{{- tpl (include "vm.internal.key" .) . -}}
{{- $_ := unset . "overrideKey" -}}
{{- $_ := unset . "fallback" -}}
{{- end -}}
{{- /* Selector labels */ -}}
{{- define "vm.selectorLabels" -}}
{{- $labels := .extraLabels | default dict -}}
{{- $_ := set $labels "app.kubernetes.io/name" (include "vm.name" .) -}}
{{- $_ := set $labels "app.kubernetes.io/instance" (include "vm.release" .) -}}
{{- with (include "vm.app.name" .) -}}
{{- $_ := set $labels "app" . -}}
{{- end -}}
{{- toYaml $labels -}}
{{- end }}
{{- define "vm.commonLabels" -}}
{{- $labels := fromYaml (include "vm.selectorLabels" . ) -}}
{{- with $labels.app -}}
{{- $_ := set $labels "app.kubernetes.io/component" . -}}
{{- $_ := unset $labels "app" -}}
{{- end -}}
{{- toYaml $labels -}}
{{- end -}}
@@ -0,0 +1,61 @@
{{/*
Victoria Metrics Image
*/}}
{{- define "vm.image" -}}
{{- $image := (fromYaml (include "vm.internal.image" .)).image | default dict -}}
{{- $tag := include "vm.image.tag" . -}}
{{- if empty $image.repository -}}
{{- fail "cannot create image without `.repository` defined" -}}
{{- end -}}
{{- $result := tpl (printf "%s:%s" $image.repository $tag) . -}}
{{- with $image.registry | default "" -}}
{{- $result = (printf "%s/%s" . $result) -}}
{{- end -}}
{{- $result -}}
{{- end -}}
{{- define "vm.image.tag" -}}
{{- $Chart := (.helm).Chart | default .Chart -}}
{{- $image := (fromYaml (include "vm.internal.image" .)).image | default dict -}}
{{- $tag := $image.tag -}}
{{- if empty $tag }}
{{- $tag = $Chart.AppVersion -}}
{{- $variant := $image.variant }}
{{- if eq (include "vm.enterprise.disabled" .) "false" -}}
{{- if $variant }}
{{- $variant = printf "enterprise-%s" $variant }}
{{- else }}
{{- $variant = "enterprise" }}
{{- end }}
{{- end -}}
{{- with $variant -}}
{{- $tag = (printf "%s-%s" $tag .) -}}
{{- end -}}
{{- end -}}
{{- $tag -}}
{{- end -}}
{{- define "vm.internal.image" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $values := $Values -}}
{{- $ctx := . -}}
{{- with .appKey -}}
{{- $appKey := ternary (list .) . (kindIs "string" .) -}}
{{- range $ak := $appKey -}}
{{- $values = ternary (dict) (index $values $ak | default dict) (empty $values) -}}
{{- $ctx = ternary (dict) (index $ctx $ak | default dict) (empty $ctx) -}}
{{- if and (empty $values) (empty $ctx) -}}
{{- fail (printf "No data for appKey %s" (join "->" $appKey)) -}}
{{- end -}}
{{- end -}}
{{- end -}}
{{- $image := ternary (deepCopy ($ctx.image | default dict)) (deepCopy ($values.image | default dict)) (hasKey $ctx "image") -}}
{{- if not $image.registry }}
{{- if (($Values.global).image).registry -}}
{{- $_ := set $image "registry" (($Values.global).image).registry -}}
{{- else if hasKey $image "registry" -}}
{{- $_ := unset $image "registry" -}}
{{- end -}}
{{- end -}}
{{- toYaml (dict "image" $image) -}}
{{- end -}}
@@ -0,0 +1,8 @@
{{- define "vm.ingress.port" }}
{{- $port := dict "name" "http" }}
{{- with .port }}
{{- $numberTypes := list "int" "float64" }}
{{- $port = dict (ternary "number" "name" (has (kindOf .) $numberTypes)) . }}
{{- end -}}
{{- toYaml $port -}}
{{- end }}
@@ -0,0 +1,117 @@
{{- define "vm.port.from.flag" -}}
{{- $port := .default -}}
{{- with .flag -}}
{{- $port = regexReplaceAll ".*:(\\d+)" . "${1}" -}}
{{- end -}}
{{- $port -}}
{{- end }}
{{- /*
Return true if the detected platform is Openshift
Usage:
{{- include "vm.isOpenshift" . -}}
*/ -}}
{{- define "vm.isOpenshift" -}}
{{- $Capabilities := (.helm).Capabilities | default .Capabilities -}}
{{- if $Capabilities.APIVersions.Has "security.openshift.io/v1" -}}
{{- true -}}
{{- end -}}
{{- end -}}
{{- /*
Render a compatible securityContext depending on the platform.
Usage:
{{- include "vm.securityContext" (dict "securityContext" .Values.containerSecurityContext "helm" .) -}}
*/ -}}
{{- define "vm.securityContext" -}}
{{- $securityContext := omit .securityContext "enabled" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $adaptMode := (((($Values).global).compatibility).openshift).adaptSecurityContext | default "" -}}
{{- if or (eq $adaptMode "force") (and (eq $adaptMode "auto") (include "vm.isOpenshift" .)) -}}
{{- $securityContext = omit $securityContext "fsGroup" "runAsUser" "runAsGroup" "seLinuxOptions" -}}
{{- end -}}
{{- toYaml $securityContext -}}
{{- end -}}
{{- /*
Render probe
*/ -}}
{{- define "vm.probe" -}}
{{- /* undefined value */ -}}
{{- $null := (fromYaml "value: null").value -}}
{{- $probe := dig .type (dict) .app.probe -}}
{{- $probeType := "" -}}
{{- $defaultProbe := dict -}}
{{- if ne (dig "httpGet" $null $probe) $null -}}
{{- /* httpGet probe */ -}}
{{- $defaultProbe = dict "path" (include "vm.probe.http.path" .) "scheme" (include "vm.probe.http.scheme" .) "port" (include "vm.probe.port" .) -}}
{{- $probeType = "httpGet" -}}
{{- else if ne (dig "tcpSocket" $null $probe) $null -}}
{{- /* tcpSocket probe */ -}}
{{- $defaultProbe = dict "port" (include "vm.probe.port" .) -}}
{{- $probeType = "tcpSocket" -}}
{{- end -}}
{{- $defaultProbe = ternary (dict) (dict $probeType $defaultProbe) (empty $probeType) -}}
{{- $probe = mergeOverwrite $defaultProbe $probe -}}
{{- range $key, $value := $probe -}}
{{- if and (has (kindOf $value) (list "object" "map")) (ne $key $probeType) -}}
{{- $_ := unset $probe $key -}}
{{- end -}}
{{- end -}}
{{- tpl (toYaml $probe) . -}}
{{- end -}}
{{- /*
HTTP GET probe path
*/ -}}
{{- define "vm.probe.http.path" -}}
{{- index .app.extraArgs "http.pathPrefix" | default "" | trimSuffix "/" -}}/health
{{- end -}}
{{- /*
HTTP GET probe scheme
*/ -}}
{{- define "vm.probe.http.scheme" -}}
{{- $isSecure := false -}}
{{- with ((.app).extraArgs).tls -}}
{{- $isSecure = eq (toString .) "true" -}}
{{- end -}}
{{- ternary "HTTPS" "HTTP" $isSecure -}}
{{- end -}}
{{- /*
Net probe port
*/ -}}
{{- define "vm.probe.port" -}}
{{- dig "ports" "name" "http" (.app | dict) -}}
{{- end -}}
{{- define "vm.arg" -}}
{{- if and (empty .value) (kindIs "string" .value) (ne (toString .list) "true") }}
{{- .key -}}
{{- else if eq (toString .value) "true" -}}
-{{ ternary "" "-" (eq (len .key) 1) }}{{ .key }}
{{- else -}}
-{{ ternary "" "-" (eq (len .key) 1) }}{{ .key }}={{ ternary (toJson .value | squote) .value (has (kindOf .value) (list "map" "slice")) }}
{{- end -}}
{{- end -}}
{{- /*
command line arguments
*/ -}}
{{- define "vm.args" -}}
{{- $args := list -}}
{{- range $key, $value := . -}}
{{- if not $key -}}
{{- fail "Empty key in command line args is not allowed" -}}
{{- end -}}
{{- if kindIs "slice" $value -}}
{{- range $v := $value -}}
{{- $args = append $args (include "vm.arg" (dict "key" $key "value" $v "list" true)) -}}
{{- end -}}
{{- else -}}
{{- $args = append $args (include "vm.arg" (dict "key" $key "value" $value)) -}}
{{- end -}}
{{- end -}}
{{- toYaml (dict "args" $args) -}}
{{- end -}}
@@ -0,0 +1,88 @@
{{- /* Create the name for VM service */ -}}
{{- define "vm.service" -}}
{{- include "vm.validate.args" . -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $nameTpl := "" -}}
{{- if eq .style "managed" -}}
{{- $nameTpl = "vm.managed.fullname" }}
{{- else if eq .style "plain" -}}
{{- $nameTpl = "vm.plain.fullname" }}
{{- else -}}
{{- fail ".style argument should be either `plain` or `managed`"}}
{{- end -}}
{{- include $nameTpl . -}}
{{- end }}
{{- define "vm.fqdn" -}}
{{- $name := (include "vm.service" .) -}}
{{- if hasKey . "appIdx" -}}
{{- $name = (printf "%s-%d.%s" $name .appIdx $name) -}}
{{- end -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $ns := (include "vm.namespace" .) -}}
{{- $fqdn := printf "%s.%s.svc" $name $ns -}}
{{- with (($Values.global).cluster).dnsDomain -}}
{{- $fqdn = printf "%s.%s" $fqdn . -}}
{{- end -}}
{{- $fqdn -}}
{{- end -}}
{{- define "vm.host" -}}
{{- $fqdn := (include "vm.fqdn" .) -}}
{{- $port := 80 -}}
{{- $isSecure := ternary false true (empty .appSecure) -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- if .appKey -}}
{{- $appKey := ternary (list .appKey) .appKey (kindIs "string" .appKey) -}}
{{- $values := $Values -}}
{{- $ctx := . -}}
{{- range $ak := $appKey -}}
{{- $values = ternary (dict) (index $values $ak | default dict) (empty $values) -}}
{{- $ctx = ternary (dict) (index $ctx $ak | default dict) (empty $ctx) -}}
{{- end -}}
{{- $spec := dict -}}
{{- if $ctx -}}
{{- $spec = $ctx -}}
{{- else if $values -}}
{{- $spec = $values -}}
{{- end -}}
{{- with ($spec.extraArgs).tls -}}
{{- $isSecure = eq (toString .) "true" -}}
{{- end -}}
{{- $port = (ternary 443 80 $isSecure) -}}
{{- $port = $spec.port | default ($spec.service).servicePort | default ($spec.service).port | default $port -}}
{{- if hasKey . "appIdx" -}}
{{- $port = (include "vm.port.from.flag" (dict "flag" ($spec.extraArgs).httpListenAddr "default" $port)) -}}
{{- end }}
{{- end }}
{{- $fqdn }}:{{ $port }}
{{- end -}}
{{- define "vm.url" -}}
{{- $host := (include "vm.host" .) -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $proto := "http" -}}
{{- $path := .appRoute | default "/" -}}
{{- $isSecure := ternary false true (empty .appSecure) -}}
{{- if .appKey -}}
{{- $appKey := ternary (list .appKey) .appKey (kindIs "string" .appKey) -}}
{{- $values := $Values -}}
{{- $ctx := . -}}
{{- range $ak := $appKey -}}
{{- $values = ternary (dict) (index $values $ak | default dict) (empty $values) -}}
{{- $ctx = ternary (dict) (index $ctx $ak | default dict) (empty $ctx) -}}
{{- end -}}
{{- $spec := dict -}}
{{- if $values -}}
{{- $spec = $values -}}
{{- else if $ctx -}}
{{- $spec = $ctx -}}
{{- end -}}
{{- with ($spec.extraArgs).tls -}}
{{- $isSecure = eq (toString .) "true" -}}
{{- end -}}
{{- $proto = (ternary "https" "http" $isSecure) -}}
{{- $path = dig "http.pathPrefix" $path ($spec.extraArgs | default dict) -}}
{{- end -}}
{{- printf "%s://%s%s" $proto $host (trimSuffix "/" $path) -}}
{{- end -}}
@@ -0,0 +1,142 @@
# =============================================================================
# vmagent — PaaSup 커스텀 오버라이드 (Kubernetes 메트릭 수집)
# 차트: victoria-metrics/victoria-metrics-agent
# 역할: kubelet / cadvisor / kube-state-metrics / node-exporter / 파드 annotation scrape
# 전송 대상: VictoriaMetrics Cluster vminsert:8480 (쓰기 경로는 vmauth 미경유)
#
# accountID 매핑(예시): 0=플랫폼 공통(fallback) / 1=demo01 / 2=demo02 / 9000=platform
# 네임스페이스별 분기는 urlRelabelConfig(ConfigMap: vmagent-relabel-configs) 마운트로 처리.
# 해당 ConfigMap은 온보딩 시 별도 생성한다(CUSTOM-README 참조).
# =============================================================================
# remoteWrite — 최소 1개 필요. accountID별 엔드포인트 + urlRelabelConfig 파일 분기
remoteWrite:
- url: "http://vmcluster-victoria-metrics-cluster-vminsert.monitoring.svc.cluster.local:8480/insert/1/prometheus/api/v1/write"
urlRelabelConfig: /relabel/demo01.yaml
- url: "http://vmcluster-victoria-metrics-cluster-vminsert.monitoring.svc.cluster.local:8480/insert/2/prometheus/api/v1/write"
urlRelabelConfig: /relabel/demo02.yaml
- url: "http://vmcluster-victoria-metrics-cluster-vminsert.monitoring.svc.cluster.local:8480/insert/9000/prometheus/api/v1/write"
urlRelabelConfig: /relabel/platform.yaml
- url: "http://vmcluster-victoria-metrics-cluster-vminsert.monitoring.svc.cluster.local:8480/insert/0/prometheus/api/v1/write"
extraVolumes:
- name: relabel-configs
configMap:
name: vmagent-relabel-configs
extraVolumeMounts:
- name: relabel-configs
mountPath: /relabel
resources:
requests:
cpu: 50m
memory: 128Mi
limits:
cpu: 500m
memory: 512Mi
# 스크레이프 설정 — kubelet/cadvisor/exporters/파드 annotation
config:
global:
scrape_interval: 30s
external_labels:
cluster: local
scrape_configs:
- job_name: kubelet
scheme: https
tls_config:
ca_file: /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
insecure_skip_verify: true
authorization:
credentials_file: /var/run/secrets/kubernetes.io/serviceaccount/token
kubernetes_sd_configs:
- role: node
relabel_configs:
- target_label: __address__
replacement: kubernetes.default.svc:443
- source_labels: [__meta_kubernetes_node_name]
regex: (.+)
target_label: __metrics_path__
replacement: /api/v1/nodes/$1/proxy/metrics
- source_labels: [__meta_kubernetes_node_name]
target_label: node
- job_name: cadvisor
scheme: https
tls_config:
ca_file: /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
insecure_skip_verify: true
authorization:
credentials_file: /var/run/secrets/kubernetes.io/serviceaccount/token
kubernetes_sd_configs:
- role: node
relabel_configs:
- target_label: __address__
replacement: kubernetes.default.svc:443
- source_labels: [__meta_kubernetes_node_name]
regex: (.+)
target_label: __metrics_path__
replacement: /api/v1/nodes/$1/proxy/metrics/cadvisor
- source_labels: [__meta_kubernetes_node_name]
target_label: node
- job_name: kube-state-metrics
honor_labels: true
kubernetes_sd_configs:
- role: endpoints
namespaces:
names: [monitoring]
relabel_configs:
- source_labels: [__meta_kubernetes_service_label_app_kubernetes_io_name]
regex: kube-state-metrics
action: keep
- source_labels: [__meta_kubernetes_endpoint_port_name]
regex: http
action: keep
- job_name: node-exporter
kubernetes_sd_configs:
- role: endpoints
namespaces:
names: [monitoring]
relabel_configs:
- source_labels: [__meta_kubernetes_service_label_app_kubernetes_io_name]
regex: prometheus-node-exporter
action: keep
- source_labels: [__meta_kubernetes_endpoint_port_name]
regex: metrics
action: keep
- source_labels: [__meta_kubernetes_pod_node_name]
target_label: node
- job_name: kubernetes-pods
kubernetes_sd_configs:
- role: pod
relabel_configs:
- source_labels: [__meta_kubernetes_pod_annotation_prometheus_io_scrape]
regex: "true"
action: keep
- source_labels: [__meta_kubernetes_pod_annotation_prometheus_io_path]
regex: (.+)
target_label: __metrics_path__
- source_labels: [__address__, __meta_kubernetes_pod_annotation_prometheus_io_port]
regex: ([^:]+)(?::\d+)?;(\d+)
replacement: $1:$2
target_label: __address__
- source_labels: [__meta_kubernetes_namespace]
target_label: namespace
- source_labels: [__meta_kubernetes_pod_name]
target_label: pod
- source_labels: [__meta_kubernetes_pod_label_app]
target_label: app
# RBAC — kubelet/cadvisor/엔드포인트 접근 권한
rbac:
create: true
extraRules:
- apiGroups: [""]
resources: [nodes, nodes/proxy, nodes/metrics, pods, services, endpoints, namespaces]
verbs: [get, list, watch]
- nonResourceURLs: [/metrics, /metrics/cadvisor]
verbs: [get]
@@ -0,0 +1,58 @@
{{- define "vmagent.args" -}}
{{- $args := dict -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- if empty $Values.remoteWrite -}}
{{- fail "Please define at least one remoteWrite" -}}
{{- end -}}
{{- $_ := set $args "promscrape.config" "/config/scrape/scrape.yml" -}}
{{- $_ := set $args "remoteWrite.tmpDataPath" "/tmpData" -}}
{{- range $i, $rw := $Values.remoteWrite -}}
{{- if not $rw.url -}}
{{- fail (printf "`url` is not set for `remoteWrite` idx %d" $i) -}}
{{- end -}}
{{- range $rwKey, $rwValue := $rw -}}
{{- $key := printf "remoteWrite.%s" $rwKey -}}
{{- $param := index $args $key | default list -}}
{{- range until (int (sub $i (len $param))) }}
{{- $param = append $param "" }}
{{- end }}
{{- if or (kindIs "slice" $rwValue) (kindIs "map" $rwValue) -}}
{{- $param = append $param (printf "/config/rw/%d-%s.yaml" $i $rwKey) }}
{{- else -}}
{{- $param = append $param $rwValue }}
{{- end -}}
{{- $_ := set $args $key $param -}}
{{- end -}}
{{- end -}}
{{- $args = mergeOverwrite $args (fromYaml (include "vm.license.flag" .)) -}}
{{- $args = mergeOverwrite $args $Values.extraArgs -}}
{{- if and (eq $Values.mode "statefulSet") $Values.statefulSet.clusterMode }}
{{- $_ := set $args "promscrape.cluster.membersCount" $Values.replicaCount -}}
{{- $_ := set $args "promscrape.cluster.replicationFactor" $Values.statefulSet.replicationFactor -}}
{{- $_ := set $args "promscrape.cluster.memberNum" "$(POD_NAME)" -}}
{{- end -}}
{{- toYaml (fromYaml (include "vm.args" $args)).args -}}
{{- end -}}
{{- define "vmagent.rw.config" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $rwcm := dict }}
{{- range $i, $rw := $Values.remoteWrite }}
{{- range $rwKey, $rwValue := $rw }}
{{- if or (kindIs "slice" $rwValue) (kindIs "map" $rwValue) }}
{{- $rwContent := toYaml $rwValue }}
{{- if $Values.config.useTpl }}
{{- $rwContent = tpl $rwContent $ | trim }}
{{- end }}
{{- $_ := set $rwcm (printf "%d-%s.yaml" $i $rwKey) $rwContent }}
{{- end -}}
{{- end -}}
{{- end -}}
{{- toYaml $rwcm -}}
{{- end -}}
{{- define "vmagent.scrape.config.name" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $fullname := include "vm.plain.fullname" . -}}
{{- $Values.configMap | default (printf "%s-config" $fullname) -}}
{{- end -}}
@@ -0,0 +1,40 @@
{{- $ctx := dict "helm" . }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
{{- if and (empty .Values.configMap) .Values.config }}
{{- $cfg := deepCopy .Values.config }}
{{- if .Values.extraScrapeConfigs }}
{{- $_ := set $cfg "scrape_configs" (concat (.Values.config.scrape_configs | default list) .Values.extraScrapeConfigs) }}
{{- end }}
{{- $data := toYaml (omit $cfg "useTpl") }}
{{- if $cfg.useTpl }}
{{- $data = tpl $data . }}
{{- end }}
---
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ include "vmagent.scrape.config.name" $ctx }}
namespace: {{ $ns }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
data:
scrape.yml: |{{ $data | nindent 4 }}
{{- end }}
{{- $rwcm := dict }}
{{- range $i, $rw := .Values.remoteWrite }}
{{- range $rwKey, $rwValue := $rw }}
{{- if or (kindIs "slice" $rwValue) (kindIs "map" $rwValue) }}
{{- $_ := set $rwcm (printf "%d-%s.yaml" $i $rwKey) (toYaml $rwValue) }}
{{- end -}}
{{- end -}}
{{- end -}}
{{- with (include "vmagent.rw.config" .) }}
---
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ $fullname }}-rw
namespace: {{ $ns }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
data: {{ . | nindent 2 }}
{{- end }}
@@ -0,0 +1,4 @@
{{ range .Values.extraObjects }}
---
{{ tpl (ternary . (toYaml .) (typeIs "string" .)) $ }}
{{ end }}
@@ -0,0 +1,25 @@
{{- $hpa := .Values.horizontalPodAutoscaler }}
{{- if $hpa.enabled }}
{{- $ctx := dict "helm" . }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
apiVersion: autoscaling/v2
kind: HorizontalPodAutoscaler
metadata:
{{- $_ := set $ctx "extraLabels" .Values.extraLabels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
name: {{ $fullname }}
namespace: {{ $ns }}
spec:
maxReplicas: {{ $hpa.maxReplicas }}
minReplicas: {{ $hpa.minReplicas }}
scaleTargetRef:
apiVersion: apps/v1
kind: {{ title .Values.mode }}
name: {{ $fullname }}
metrics: {{ toYaml $hpa.metrics | nindent 4 }}
{{- with $hpa.behavior }}
behavior: {{ toYaml . | nindent 4 }}
{{- end -}}
{{- end -}}
@@ -0,0 +1,45 @@
{{- $app := .Values }}
{{- $ingress := $app.ingress }}
{{- if $ingress.enabled }}
{{- if not $app.service.enabled }}
{{- fail "It's required to set .Values.service.enabled: true when .Values.ingress.enabled: true"}}
{{- end }}
{{- $ctx := dict "helm" . }}
{{- $fullname := include "vm.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
{{- with $ingress.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
{{- $_ := set $ctx "extraLabels" $app.ingress.extraLabels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
name: {{ $fullname }}
namespace: {{ $ns }}
spec:
{{- with $ingress.ingressClassName }}
ingressClassName: {{ . }}
{{- end }}
{{- with $ingress.tls }}
tls: {{ tpl (toYaml .) $ | nindent 4 }}
{{- end }}
rules:
{{- range $host := $ingress.hosts }}
{{- $paths := ternary (list $host.path) $host.path (kindIs "string" $host.path) }}
- host: {{ tpl .name $ | quote }}
http:
paths:
{{- range $path := $paths }}
- path: {{ $path }}
{{- with $ingress.pathType }}
pathType: {{ . }}
{{- end }}
backend:
service:
name: {{ $fullname }}
port: {{ include "vm.ingress.port" $host | nindent 18 }}
{{- end }}
{{- end }}
{{- end }}
@@ -0,0 +1,51 @@
{{- $serviceMonitor := .Values.serviceMonitor -}}
{{- if $serviceMonitor.enabled -}}
{{- $ctx := dict "helm" . }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
apiVersion: monitoring.coreos.com/v1
kind: ServiceMonitor
metadata:
{{- with $serviceMonitor.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
{{- $_ := set $ctx "extraLabels" $serviceMonitor.extraLabels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
name: {{ $fullname }}
{{- with $serviceMonitor.namespace }}
namespace: {{ . }}
{{- end }}
spec:
namespaceSelector:
matchNames:
- {{ $ns }}
selector:
matchLabels: {{ include "vm.commonLabels" $ctx | nindent 6 }}
endpoints:
- port: http
{{- with $serviceMonitor.basicAuth }}
basicAuth: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $serviceMonitor.scheme }}
scheme: {{ . }}
{{- end }}
{{- with $serviceMonitor.interval }}
interval: {{ . }}
{{- end }}
{{- with $serviceMonitor.scrapeTimeout }}
scrapeTimeout: {{ . }}
{{- end }}
{{- with $serviceMonitor.tlsConfig }}
tlsConfig: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $serviceMonitor.relabelings }}
relabelings: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $serviceMonitor.metricRelabelings }}
metricRelabelings: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $serviceMonitor.targetPort }}
targetPort: {{ . }}
{{- end }}
{{- end }}
@@ -0,0 +1,26 @@
{{- $pdb := .Values.podDisruptionBudget }}
{{- if $pdb.enabled }}
{{- $ctx := dict "helm" . }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
apiVersion: policy/v1
kind: PodDisruptionBudget
metadata:
name: {{ $fullname }}
namespace: {{ $ns }}
{{- $_ := set $ctx "extraLabels" $pdb.labels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
spec:
{{- with $pdb.minAvailable }}
minAvailable: {{ . }}
{{- end }}
{{- with $pdb.maxUnavailable }}
maxUnavailable: {{ . }}
{{- end }}
{{- with $pdb.unhealthyPodEvictionPolicy }}
unhealthyPodEvictionPolicy: {{ . }}
{{- end }}
selector:
matchLabels: {{ include "vm.selectorLabels" $ctx | nindent 6 }}
{{- end }}
@@ -0,0 +1,36 @@
{{- $app := .Values }}
{{- $pvc := $app.persistentVolume }}
{{- if and $pvc.enabled (not $pvc.existingClaim) (eq $app.mode "deployment") }}
{{- $ctx := dict "helm" . }}
{{- $fullname := include "vm.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
---
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: {{ tpl ($pvc.name | default $fullname) $ctx }}
namespace: {{ $ns }}
{{- $_ := set $ctx "extraLabels" $pvc.extraLabels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
{{- with $pvc.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
spec:
{{- with $pvc.accessModes }}
accessModes: {{ toYaml . | nindent 4 }}
{{- end }}
{{- with $pvc.volumeAttributeClassName }}
volumeAttributesClassName: {{ . }}
{{- end }}
resources:
requests:
storage: {{ $pvc.size }}
{{- with $pvc.storageClassName }}
storageClassName: {{ . }}
{{- end -}}
{{- with $pvc.matchLabels }}
selector:
matchLabels: {{ toYaml . | nindent 6 }}
{{- end }}
{{- end }}
@@ -0,0 +1,71 @@
{{- if .Values.rbac.create -}}
{{- $ctx := dict "helm" . }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $namespaced := .Values.rbac.namespaced }}
{{- $ns := include "vm.namespace" $ctx }}
---
apiVersion: rbac.authorization.k8s.io/v1
kind: {{ ternary "RoleBinding" "ClusterRoleBinding" $namespaced }}
metadata:
name: {{ $fullname }}
{{- if $namespaced }}
namespace: {{ $ns }}
{{- end }}
{{- $_ := set $ctx "extraLabels" .Values.rbac.extraLabels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
{{- with .Values.rbac.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: {{ ternary "Role" "ClusterRole" $namespaced }}
name: {{ $fullname }}
subjects:
- kind: ServiceAccount
name: {{ (.Values.serviceAccount).name | default $fullname }}
namespace: {{ $ns }}
---
apiVersion: rbac.authorization.k8s.io/v1
kind: {{ ternary "Role" "ClusterRole" $namespaced }}
metadata:
name: {{ $fullname }}
{{- if $namespaced }}
namespace: {{ include "vm.namespace" $ctx }}
{{- end }}
{{- $_ := set $ctx "extraLabels" .Values.rbac.extraLabels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
{{- with .Values.rbac.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
rules:
- apiGroups:
- discovery.k8s.io
resources:
- endpointslices
verbs: ["get", "list", "watch"]
- apiGroups: [""]
resources:
- services
- endpoints
- pods
verbs: ["get", "list", "watch"]
- apiGroups:
- networking.k8s.io
resources:
- ingresses
verbs: ["get", "list", "watch"]
{{- with .Values.rbac.extraRules }}
{{ toYaml . }}
{{- end }}
{{- if not $namespaced }}
- apiGroups: [""]
resources:
- nodes
- nodes/metrics
verbs: ["get", "list", "watch"]
- nonResourceURLs: {{ toYaml .Values.allowedMetricsEndpoints | nindent 2 }}
verbs: ["get"]
{{- end }}
{{- end -}}
@@ -0,0 +1,43 @@
{{- $app := .Values }}
{{- $route := $app.route }}
{{- if $route.enabled }}
{{- $ctx := dict "helm" . }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
---
apiVersion: {{ $route.apiVersion | default "gateway.networking.k8s.io/v1" }}
kind: {{ $route.kind | default "HTTPRoute" }}
metadata:
name: {{ $fullname }}
namespace: {{ $ns }}
{{- $_ := set $ctx "extraLabels" $app.route.extraLabels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
{{- with $route.annotations }}
annotations: {{ tpl (toYaml .) $ | nindent 4 }}
{{- end }}
spec:
{{- with $route.parentRefs }}
parentRefs: {{ toYaml . | nindent 4 }}
{{- end }}
{{- with $route.hostnames }}
hostnames: {{ tpl (toYaml .) $ | nindent 4 }}
{{- end }}
rules:
{{- with $route.extraRules }}
{{- tpl (toYaml .) $ | nindent 4 }}
{{- end }}
- backendRefs:
- name: {{ $fullname }}
port: {{ $route.port | default (include "vm.port.from.flag" (dict "flag" ($app.extraArgs).httpListenAddr)) }}
group: ''
kind: Service
weight: 1
{{- with $route.filters }}
filters: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $route.matches }}
matches: {{ tpl (toYaml .) $ | nindent 8 }}
{{- end }}
{{- end }}
@@ -0,0 +1,235 @@
{{- $storageName := "tmpdata" }}
{{- $app := .Values }}
{{- $pvc := $app.persistentVolume }}
{{- $mode := $app.mode }}
{{- if and $mode (hasKey $app $mode) }}
{{- $modeOpts := index $app $mode }}
{{- $ctx := dict "helm" . }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
apiVersion: apps/v1
kind: {{ title $mode }}
metadata:
name: {{ $fullname }}
namespace: {{ $ns }}
{{- $_ := set $ctx "extraLabels" $app.extraLabels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
{{- with .Values.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
spec:
{{- with $modeOpts.spec }}
{{- toYaml . | nindent 2 }}
{{- end }}
{{- $hpa := $app.horizontalPodAutoscaling | default $app.horizontalPodAutoscaler }}
{{- if and (not $hpa.enabled) (ne $mode "daemonSet") }}
replicas: {{ $app.replicaCount }}
{{- end }}
{{- if eq $mode "statefulSet" }}
serviceName: {{ $fullname }}
{{- end }}
selector:
{{- $_ := set $ctx "extraLabels" .Values.selectorLabels }}
matchLabels: {{ include "vm.selectorLabels" $ctx | nindent 6 }}
{{- $_ := unset $ctx "extraLabels" }}
template:
metadata:
{{- $_ := set $ctx "extraLabels" $app.podLabels }}
labels: {{ include "vm.podLabels" $ctx | nindent 8 }}
{{- $_ := unset $ctx "extraLabels" }}
{{- $annotations := merge (dict "checksum/config" (include (print .Template.BasePath "/configmap.yaml") . | sha256sum)) (deepCopy $app.podAnnotations) }}
annotations: {{ toYaml $annotations | nindent 8 }}
spec:
{{- with $app.priorityClassName }}
priorityClassName: {{ . }}
{{- end }}
{{- with $app.schedulerName }}
schedulerName: {{ . }}
{{- end }}
{{- if or (.Values.serviceAccount).name (.Values.serviceAccount).create }}
serviceAccountName: {{ tpl ((.Values.serviceAccount).name | default $fullname) $ctx }}
automountServiceAccountToken: {{ .Values.serviceAccount.automountToken }}
{{- end }}
{{- if $app.podSecurityContext.enabled }}
securityContext: {{ include "vm.securityContext" (dict "securityContext" $app.podSecurityContext "helm" .) | nindent 8 }}
{{- end }}
{{- with $app.initContainers }}
initContainers: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with ($app.imagePullSecrets | default .Values.global.imagePullSecrets) }}
imagePullSecrets: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $app.hostAliases }}
hostAliases: {{ toYaml . | nindent 8 }}
{{- end }}
containers:
- name: vmagent
{{- if $app.securityContext.enabled }}
securityContext: {{ include "vm.securityContext" (dict "securityContext" $app.securityContext "helm" .) | nindent 12 }}
{{- end }}
{{- $_ := set $ctx "app" $app }}
image: {{ include "vm.image" $ctx }}
imagePullPolicy: {{ $app.image.pullPolicy }}
{{- with $app.containerWorkingDir }}
workingDir: {{ . }}
{{- end }}
args: {{ include "vmagent.args" $ctx | nindent 12 }}
{{- with $app.envFrom }}
envFrom: {{ toYaml . | nindent 12 }}
{{- end }}
env:
- name: POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
{{- with $app.env }}
{{ toYaml .| nindent 12 }}
{{- end }}
ports:
- name: http
containerPort: {{ include "vm.port.from.flag" (dict "flag" $app.extraArgs.httpListenAddr "default" "8429") }}
{{- with $app.extraArgs.graphiteListenAddr }}
- name: graphite-tcp
protocol: TCP
containerPort: {{ include "vm.port.from.flag" (dict "flag" .) }}
- name: graphite-udp
protocol: UDP
containerPort: {{ include "vm.port.from.flag" (dict "flag" .) }}
{{- end }}
{{- with $app.extraArgs.influxListenAddr }}
- name: influx-tcp
protocol: TCP
containerPort: {{ include "vm.port.from.flag" (dict "flag" .) }}
- name: influx-udp
protocol: UDP
containerPort: {{ include "vm.port.from.flag" (dict "flag" .) }}
{{- end }}
{{- with $app.extraArgs.opentsdbHTTPListenAddr }}
- name: opentsdbhttp
protocol: TCP
containerPort: {{ include "vm.port.from.flag" (dict "flag" .) }}
{{- end }}
{{- with $app.extraArgs.opentsdbListenAddr }}
- name: opentsdb-tcp
protocol: TCP
containerPort: {{ include "vm.port.from.flag" (dict "flag" .) }}
- name: opentsdb-udp
protocol: UDP
containerPort: {{ include "vm.port.from.flag" (dict "flag" .) }}
{{- end }}
{{- with (fromYaml (include "vm.probe" (dict "app" $app "type" "readiness"))) }}
readinessProbe: {{ toYaml . | nindent 12 }}
{{- end }}
{{- with (fromYaml (include "vm.probe" (dict "app" $app "type" "liveness"))) }}
livenessProbe: {{ toYaml . | nindent 12 }}
{{- end }}
{{- with (fromYaml (include "vm.probe" (dict "app" $app "type" "startup"))) }}
startupProbe: {{ toYaml . | nindent 12 }}
{{- end }}
{{- with $app.resources }}
resources: {{ toYaml . | nindent 12 }}
{{- end }}
volumeMounts:
- name: {{ $storageName }}
mountPath: /tmpData
- name: scrape-config
mountPath: /config/scrape
{{- with (include "vmagent.rw.config" .) }}
- name: rw-config
mountPath: /config/rw
{{- end }}
{{- range $app.extraHostPathMounts }}
- name: {{ .name }}
mountPath: {{ .mountPath }}
{{- with .subPath }}
subPath: {{ . }}
{{- end }}
{{- with .readOnly }}
readOnly: {{ . }}
{{- end }}
{{- end }}
{{- with $app.extraVolumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- include "vm.license.mount" . | nindent 12 }}
{{- with $app.extraContainers }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with $app.nodeSelector }}
nodeSelector: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $app.affinity }}
affinity: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $app.tolerations }}
tolerations: {{ toYaml . | nindent 8 }}
{{- end }}
{{- if and ($app.hostNetwork) (eq $mode "daemonSet") }}
hostNetwork: true
{{- end }}
{{- with $app.topologySpreadConstraints }}
topologySpreadConstraints:
{{- range $constraint := . }}
- {{ toYaml $constraint | nindent 10 | trim }}
{{- if not $constraint.labelSelector }}
labelSelector:
matchLabels: {{ include "vm.selectorLabels" $ctx | nindent 14 }}
{{- end }}
{{- end }}
{{- end }}
volumes:
{{- if or (eq $mode "deployment") (not $pvc.enabled) $pvc.existingClaim }}
- name: {{ $storageName }}
{{- if or (and (eq $mode "deployment") $pvc.enabled) $pvc.existingClaim }}
persistentVolumeClaim:
claimName: {{ tpl ($pvc.existingClaim | default $pvc.name | default $fullname) $ctx }}
{{- else }}
emptyDir: {{ toYaml $app.emptyDir | nindent 12 }}
{{- end }}
{{- end }}
{{- with (include "vmagent.rw.config" .) }}
- name: rw-config
configMap:
name: {{ $fullname -}}-rw
{{- end }}
- name: scrape-config
configMap:
name: {{ include "vmagent.scrape.config.name" $ctx }}
{{- range $app.extraHostPathMounts }}
- name: {{ .name }}
hostPath:
path: {{ .hostPath }}
{{- end }}
{{- with $app.extraVolumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- include "vm.license.volume" . | nindent 8 }}
{{- if and (eq $mode "statefulSet") $pvc.enabled (not $pvc.existingClaim) }}
volumeClaimTemplates:
- apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: {{ tpl ($pvc.name | default $storageName) $ctx }}
{{- with $pvc.extraLabels }}
labels: {{ toYaml . | nindent 10 }}
{{- end }}
{{- with $pvc.annotations }}
annotations: {{ toYaml . | nindent 10 }}
{{- end }}
spec:
{{- with $pvc.accessModes }}
accessModes: {{ toYaml . | nindent 10 }}
{{- end }}
{{- with $pvc.storageClassName }}
storageClassName: {{ . }}
{{- end }}
{{- with $pvc.matchLabels }}
selector:
matchLabels: {{ toYaml . | nindent 12 }}
{{- end }}
resources:
requests:
storage: {{ $pvc.size }}
{{- end }}
{{- end }}
@@ -0,0 +1,97 @@
{{- $app := .Values }}
{{- $service := $app.service }}
{{- if $service.enabled -}}
{{- $ctx := dict "helm" . }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
---
apiVersion: v1
kind: Service
metadata:
{{- with $service.annotations }}
annotations: {{ toYaml . | nindent 4}}
{{- end }}
{{- $_ := set $ctx "extraLabels" $service.extraLabels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
name: {{ $fullname }}
namespace: {{ $ns }}
spec:
{{- with $service.clusterIP }}
clusterIP: {{ . }}
{{- end }}
{{- with $service.externalIPs }}
externalIPs: {{ toYaml . | nindent 4 }}
{{- end }}
{{- with $service.loadBalancerIP }}
loadBalancerIP: {{ . }}
{{- end }}
{{- with $service.loadBalancerSourceRanges }}
loadBalancerSourceRanges: {{ toYaml . | nindent 4 }}
{{- end }}
type: {{ $service.type }}
{{- with $service.healthCheckNodePort }}
healthCheckNodePort: {{ . }}
{{- end }}
{{- with $service.externalTrafficPolicy }}
externalTrafficPolicy: {{ . }}
{{- end }}
{{- with $service.internalTrafficPolicy }}
internalTrafficPolicy: {{ . }}
{{- end }}
{{- with $service.ipFamilyPolicy }}
ipFamilyPolicy: {{ . }}
{{- end }}
{{- with $service.ipFamilies }}
ipFamilies: {{ toYaml . | nindent 4 }}
{{- end }}
{{- with $service.trafficDistribution }}
trafficDistribution: {{ . }}
{{- end }}
ports:
- name: http
port: {{ $service.servicePort }}
protocol: TCP
targetPort: {{ $service.targetPort }}
{{- with $service.nodePort }}
nodePort: {{ . }}
{{- end }}
{{- with .Values.extraArgs.graphiteListenAddr }}
- name: graphite-tcp
protocol: TCP
port: {{ include "vm.port.from.flag" (dict "flag" .) }}
targetPort: graphite-tcp
- name: graphite-udp
protocol: UDP
port: {{ include "vm.port.from.flag" (dict "flag" .) }}
targetPort: graphite-udp
{{- end }}
{{- with .Values.extraArgs.influxListenAddr }}
- name: influx-tcp
protocol: TCP
port: {{ include "vm.port.from.flag" (dict "flag" .) }}
targetPort: influx-tcp
- name: influx-udp
protocol: UDP
port: {{ include "vm.port.from.flag" (dict "flag" .) }}
targetPort: influx-udp
{{- end }}
{{- with .Values.extraArgs.opentsdbHTTPListenAddr }}
- name: opentsdbhttp
port: {{ include "vm.port.from.flag" (dict "flag" .) }}
targetPort: opentsdbhttp
{{- end }}
{{- with .Values.extraArgs.opentsdbListenAddr }}
- name: opentsdb-udp
protocol: UDP
port: {{ include "vm.port.from.flag" (dict "flag" .) }}
targetPort: opentsdb-udp
- name: opentsdb-tcp
protocol: TCP
port: {{ include "vm.port.from.flag" (dict "flag" .) }}
targetPort: opentsdb-tcp
{{- end }}
{{- $_ := set $ctx "extraLabels" (mergeOverwrite (deepCopy .Values.selectorLabels) (deepCopy $service.selectorLabels)) }}
selector: {{ include "vm.selectorLabels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
{{- end }}
@@ -0,0 +1,14 @@
{{- if .Values.serviceAccount.create -}}
{{- $ctx := dict "helm" . }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
apiVersion: v1
kind: ServiceAccount
metadata:
name: {{ tpl ((.Values.serviceAccount).name | default $fullname) $ctx }}
namespace: {{ $ns }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- with .Values.serviceAccount.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
{{- end -}}
@@ -0,0 +1,28 @@
{{- $vpa := .Values.verticalPodAutoscaling | default .Values.verticalPodAutoscaler }}
{{- if and (.Capabilities.APIVersions.Has "autoscaling.k8s.io/v1") $vpa.enabled }}
{{- $ctx := dict "helm" . }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
apiVersion: autoscaling.k8s.io/v1
kind: VerticalPodAutoscaler
metadata:
{{- $_ := set $ctx "extraLabels" .Values.extraLabels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
name: {{ $fullname }}
namespace: {{ $ns }}
spec:
{{- with $vpa.recommenders }}
recommenders: {{ toYaml . | nindent 4 }}
{{- end }}
targetRef:
apiVersion: apps/v1
kind: {{ title .Values.mode }}
name: {{ $fullname }}
{{- with $vpa.updatePolicy }}
updatePolicy: {{ toYaml . | nindent 4 }}
{{- end }}
{{- with $vpa.resourcePolicy }}
resourcePolicy: {{ toYaml . | nindent 4 }}
{{- end }}
{{- end }}
@@ -0,0 +1,805 @@
# Default values for victoria-metrics-agent.
# This is a YAML-formatted file.
# Declare variables to be passed into your templates.
global:
# -- Image pull secrets, that can be shared across multiple helm charts
imagePullSecrets: []
image:
# -- Image registry, that can be shared across multiple helm charts
registry: ""
# -- Openshift security context compatibility configuration
compatibility:
openshift:
adaptSecurityContext: "auto"
cluster:
# -- K8s cluster domain suffix, uses for building storage pods' FQDN. Details are [here](https://kubernetes.io/docs/tasks/administer-cluster/dns-custom-nameservers/)
dnsDomain: cluster.local.
# -- Replica count
replicaCount: 1
# -- Specify pod lifecycle
lifecycle: {}
# -- Use an alternate scheduler, e.g. "stork". Check details [here](https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/)
schedulerName: ""
# -- VMAgent mode: daemonSet, deployment, statefulSet
mode: deployment
# -- [K8s DaemonSet](https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/) specific variables
daemonSet:
spec: {}
# -- [K8s Deployment](https://kubernetes.io/docs/concepts/workloads/controllers/deployment/) specific variables
deployment:
spec:
# -- Deployment strategy. Check [here](https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#strategy) for details
strategy: {}
# rollingUpdate:
# maxSurge: 25%
# maxUnavailable: 25%
# type: RollingUpdate
# -- [K8s StatefulSet](https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/) specific variables
statefulSet:
# -- create cluster of vmagents. Check [here](https://docs.victoriametrics.com/victoriametrics/vmagent/#scraping-big-number-of-targets)
# available since [v1.77.2](https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.77.2)
clusterMode: false
# -- replication factor for vmagent in cluster mode
replicationFactor: 1
spec:
# -- StatefulSet update strategy. Check [here](https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#update-strategies) for details.
updateStrategy: {}
# type: RollingUpdate
image:
# -- Image registry
registry: ""
# -- Image repository
repository: victoriametrics/vmagent
# -- Image tag, set to `Chart.AppVersion` by default
tag: "" # rewrites Chart.AppVersion
# -- Variant of the image to use.
# e.g. enterprise, scratch
variant: ""
# -- Image pull policy
pullPolicy: IfNotPresent
# -- Image pull secrets
imagePullSecrets: []
# -- Add additional DNS entries to pods hosts file. Check [official documentation](https://kubernetes.io/docs/tasks/network/customize-hosts-file-for-pods/)
hostAliases: []
# - ip: 192.168.1.1
# hostNames:
# - test.example.com
# - another.example.net
# -- Override chart name
nameOverride: ""
# -- Override resources fullname
fullnameOverride: ""
# -- Container working directory
containerWorkingDir: "/"
rbac:
# -- Enables Role/RoleBinding creation
create: true
# -- Role/RoleBinding annotations
annotations: {}
# -- Role/RoleBinding labels
extraLabels: {}
# -- If true and `rbac.enabled`, will deploy a Role/RoleBinding instead of a ClusterRole/ClusterRoleBinding
namespaced: false
# -- additional rules for a role
extraRules: []
serviceAccount:
# -- Specifies whether a service account should be created
create: true
# -- Annotations to add to the service account
annotations: {}
# -- The name of the service account to use.
# If not set and create is true, a name is generated using the fullname template
name:
# -- mount API token to pod directly
automountToken: true
# -- See `kubectl explain poddisruptionbudget.spec` for more or check [official documentation](https://kubernetes.io/docs/tasks/run-application/configure-pdb/)
podDisruptionBudget:
enabled: false
# -- min number or percentage of pods that can be unavailable
minAvailable: 0
# -- max number or percentage of pods that can be unavailable
maxUnavailable: 0
# -- Defines criteria when unhealthy pods should be considered for eviction
unhealthyPodEvictionPolicy:
labels: {}
# -- Generates `remoteWrite.*` flags and config maps with value content for values, that are of type list of map.
# Each item should contain `url` param to pass validation.
remoteWrite: []
# - url: http://vm-insert:8480/insert/0/prometheus
# urlRelabelConfig:
# - action: keep
# source_labels: [env]
# regex: "dev"
# - url: http://prometheus:8480/insert/0/prometheus
# -- VMAgent extra command line arguments
extraArgs:
envflag.enable: true
envflag.prefix: VM_
loggerFormat: json
httpListenAddr: :8429
# Enable IPv6 support. Useful for running in IPv6-only Kubernetes clusters
# enableTCP6: true
# promscrape.maxScrapeSize: "167772160"
# Uncomment and specify the port if you want to support any of the protocols:
# https://docs.victoriametrics.com/victoriametrics/vmagent/#features
# graphiteListenAddr: ":2003"
# influxListenAddr: ":8189"
# opentsdbHTTPListenAddr: ":4242"
# opentsdbListenAddr: ":4242"
# -- Additional environment variables (ex.: secret tokens, flags). Check [here](https://docs.victoriametrics.com/victoriametrics/#environment-variables) for more details.
env:
[]
# - name: VM_remoteWrite_basicAuth_password
# valueFrom:
# secretKeyRef:
# name: auth-secret
# key: password
# -- Specify alternative source for env variables
envFrom:
[]
#- configMapRef:
# name: special-config
# -- Extra labels for Deployment and Statefulset
extraLabels: {}
# -- Extra labels for Pods only
podLabels: {}
# -- Extra selector labels common for pod and service
selectorLabels: {}
# -- Additional hostPath mounts
extraHostPathMounts:
[]
# - name: certs-dir
# mountPath: /etc/kubernetes/certs
# subPath: ""
# hostPath: /etc/kubernetes/certs
# readOnly: true
# -- Extra Volumes for the pod
extraVolumes:
[]
# - name: example
# configMap:
# name: example
# -- Extra Volume Mounts for the container
extraVolumeMounts:
[]
# - name: example
# mountPath: /example
# -- Extra containers to run in a pod with vmagent
extraContainers: []
# - name: config-reloader
# image: reloader-image
# -- Init containers for vmagent
initContainers:
[]
# - name: example
# image: example-image
# -- Security context to be added to pod
podSecurityContext:
enabled: true
# fsGroup: 2000
# -- Security context to be added to pod's containers
securityContext:
enabled: true
# capabilities:
# drop:
# - ALL
# readOnlyRootFilesystem: true
# runAsNonRoot: true
# runAsUser: 1000
service:
# -- Enable agent service
enabled: false
# -- Service annotations
annotations: {}
# -- Service labels
extraLabels: {}
# -- Service ClusterIP
clusterIP: ""
# -- Service external IPs. Check [here](https://kubernetes.io/docs/concepts/services-networking/service/#external-ips) for details
externalIPs: []
# -- Service load balancer IP
loadBalancerIP: ""
# -- Load balancer source range
loadBalancerSourceRanges: []
# -- Service port
servicePort: 8429
# -- Target port
targetPort: http
# nodePort: 30000
# -- Service type
type: ClusterIP
# -- Service IP family policy. Check [here](https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services) for details.
ipFamilyPolicy: ""
# -- List of service IP families. Check [here](https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services) for details.
ipFamilies: []
# -- Service external traffic policy. Check [here](https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip) for details
externalTrafficPolicy: ""
# -- Service internal traffic policy. Check [here](https://kubernetes.io/docs/concepts/services-networking/service/#internal-traffic-policy) for details
internalTrafficPolicy: ""
# -- Health check node port for a service. Check [here](https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip) for details
healthCheckNodePort: ""
# -- Traffic Distribution. Check [Traffic distribution](https://kubernetes.io/docs/concepts/services-networking/service/#traffic-distribution)
trafficDistribution: ""
# -- Extra selector labels common for service only
selectorLabels: {}
route:
# -- Enable deployment of HTTPRoute for VMAgent
enabled: false
# -- HTTPRoute annotations
annotations: {}
# -- HTTPRoute extra labels
extraLabels: {}
# -- HTTPGateway objects refs
parentRefs: []
# -- Array of hostnames
hostnames: []
# -- Extra rules to prepend to route. This is useful when working with annotation based services.
extraRules: []
# -- Filters for a default rule in HTTPRoute
filters: []
# -- Matches for a default rule in HTTPRoute
matches:
- path:
type: PathPrefix
value: /
ingress:
# -- Enable deployment of ingress for agent
enabled: false
# -- Ingress annotations
annotations: {}
# kubernetes.io/ingress.class: nginx
# kubernetes.io/tls-acme: 'true'
# -- Ingress extra labels
extraLabels: {}
# -- Array of host objects
hosts:
- name: vmagent.local
path:
- /
port: http
# -- Array of TLS objects
tls: []
# - secretName: vmagent-ingress-tls
# hosts:
# - vmagent.local
# -- Ingress controller class name
ingressClassName: ""
# -- Ingress path type
pathType: Prefix
# -- Resource object. Details are [here](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/)
resources:
{}
# We usually recommend not to specify default resources and to leave this as a conscious
# choice for the user. This also increases chances charts run on environments with little
# resources, such as Minikube. If you do want to specify resources, uncomment the following
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
# limits:
# cpu: 100m
# memory: 128Mi
# requests:
# cpu: 100m
# memory: 128Mi
# -- Annotations to be added to the deployment
annotations: {}
# -- Annotations to be added to pod
podAnnotations: {}
# -- Pod's node selector. Details are [here](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
nodeSelector: {}
# -- Node tolerations for server scheduling to nodes with taints. Details are [here](https://kubernetes.io/docs/concepts/configuration/assign-pod-node/)
tolerations: []
# -- Pod topologySpreadConstraints
topologySpreadConstraints: []
# - maxSkew: 1
# topologyKey: topology.kubernetes.io/zone
# whenUnsatisfiable: DoNotSchedule
# -- Pod affinity
affinity: {}
# -- VMAgent [scraping configuration](https://docs.victoriametrics.com/victoriametrics/vmagent/#how-to-collect-metrics-in-prometheus-format)
# use existing configmap if specified
# otherwise .config values will be used
configMap: ""
# -- Priority class to be assigned to the pod(s)
priorityClassName: ""
# -- Enable the host network
hostNetwork: false
serviceMonitor:
# -- Enable deployment of Service Monitor for server component. This is Prometheus operator object
enabled: false
# -- Service Monitor labels
extraLabels: {}
# -- Service Monitor annotations
annotations: {}
# -- Service Monitor relabelings
relabelings: []
# -- Basic auth params for Service Monitor
basicAuth: {}
# -- Service Monitor metricRelabelings
metricRelabelings: []
# -- Service Monitor targetPort
targetPort: http
# interval: 15s
# scrapeTimeout: 5s
# -- Commented. HTTP scheme to use for scraping.
# scheme: https
# -- Commented. TLS configuration to use when scraping the endpoint
# tlsConfig:
# insecureSkipVerify: true
# -- Empty dir configuration for a case, when persistence is disabled
emptyDir: {}
persistentVolume:
# -- Create/use Persistent Volume Claim for server component. Empty dir if false
enabled: false
# -- Override Persistent Volume Claim name
name: ""
# -- StorageClass to use for persistent volume. Requires server.persistentVolume.enabled: true. If defined, PVC created automatically
storageClassName: ""
# -- Array of access modes. Must match those of existing PV or dynamic provisioner. Details are [here](https://kubernetes.io/docs/concepts/storage/persistent-volumes/)
accessModes:
- ReadWriteOnce
# -- VolumeClassAttribute to user for persistent volume
volumeAttributesClassName:
# -- Size of the volume. Should be calculated based on the logs you send and retention policy you set.
size: 10Gi
# -- Persistent volume annotations
annotations: {}
# -- Persistent volume additional labels
extraLabels: {}
# -- Existing Claim name. If defined, PVC must be created manually before volume will be bound
existingClaim: ""
# -- Bind Persistent Volume by labels. Must match all labels of targeted PV.
matchLabels: {}
# -- Horizontal Pod Autoscaler.
# Note that it is not intended to be used for vmagents which perform scraping.
# In order to scale scraping vmagents check [here](https://docs.victoriametrics.com/victoriametrics/vmagent/#scraping-big-number-of-targets)
horizontalPodAutoscaler:
# -- Use HPA for vmagent
enabled: false
# -- Maximum replicas for HPA to use to to scale vmagent
maxReplicas: 10
# -- Minimum replicas for HPA to use to scale vmagent
minReplicas: 1
# -- Metric for HPA to use to scale vmagent
metrics: []
# -- Vertical Pod Autoscaler.
# Requires VPA CRD (`autoscaling.k8s.io/v1`) to be installed in the cluster.
# Note that VPA should not be used together with HPA on the same resource metrics (CPU/memory).
verticalPodAutoscaler:
# -- Use VPA for vmagent
enabled: false
# -- List of custom recommenders to use
# recommenders:
# - name: 'alternative'
# -- Update policy for VPA
# updatePolicy:
# updateMode: "Auto"
# minReplicas: 1
# -- Resource policy for VPA
# resourcePolicy:
# containerPolicies:
# - containerName: '*'
# minAllowed:
# cpu: 100m
# memory: 128Mi
# maxAllowed:
# cpu: 1
# memory: 500Mi
# controlledResources: ["cpu", "memory"]
# -- VMAgent scrape configuration
config:
# -- Enable config templating
useTpl: false
global:
scrape_interval: 10s
scrape_configs:
- job_name: vmagent
static_configs:
- targets: ["localhost:8429"]
## COPY from Prometheus helm chart https://github.com/helm/charts/blob/master/stable/prometheus/values.yaml
# Scrape config for API servers.
#
# Kubernetes exposes API servers as endpoints to the default/kubernetes
# service so this uses `endpoints` role and uses relabelling to only keep
# the endpoints associated with the default/kubernetes service using the
# default named port `https`. This works for single API server deployments as
# well as HA API server deployments.
- job_name: "kubernetes-apiservers"
kubernetes_sd_configs:
- role: endpoints
# Default to scraping over https. If required, just disable this or change to
# `http`.
scheme: https
# This TLS & bearer token file config is used to connect to the actual scrape
# endpoints for cluster components. This is separate to discovery auth
# configuration because discovery & scraping are two separate concerns in
# Prometheus. The discovery auth config is automatic if Prometheus runs inside
# the cluster. Otherwise, more config options have to be provided within the
# <kubernetes_sd_config>.
tls_config:
ca_file: /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
# If your node certificates are self-signed or use a different CA to the
# master CA, then you need to disable certificate verification. Note that
# certificate verification is an integral part of a secure infrastructure
# so this should only be disabled in a controlled environment. You can
# enable certificate verification by commenting the line below.
#
insecure_skip_verify: true
bearer_token_file: /var/run/secrets/kubernetes.io/serviceaccount/token
# Keep only the default/kubernetes service endpoints for the https port. This
# will add targets for each API server which Kubernetes adds an endpoint to
# the default/kubernetes service.
relabel_configs:
- source_labels:
[
__meta_kubernetes_namespace,
__meta_kubernetes_service_name,
__meta_kubernetes_endpoint_port_name,
]
action: keep
regex: default;kubernetes;https
- job_name: "kubernetes-nodes"
# Default to scraping over https. If required, just disable this or change to
# `http`.
scheme: https
# This TLS & bearer token file config is used to connect to the actual scrape
# endpoints for cluster components. This is separate to discovery auth
# configuration because discovery & scraping are two separate concerns in
# Prometheus. The discovery auth config is automatic if Prometheus runs inside
# the cluster. Otherwise, more config options have to be provided within the
# <kubernetes_sd_config>.
tls_config:
ca_file: /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
# If your node certificates are self-signed or use a different CA to the
# master CA, then you need to disable certificate verification. Note that
# certificate verification is an integral part of a secure infrastructure
# so this should only be disabled in a controlled environment. You can
# enable certificate verification by commenting the line below.
#
insecure_skip_verify: true
bearer_token_file: /var/run/secrets/kubernetes.io/serviceaccount/token
kubernetes_sd_configs:
- role: node
relabel_configs:
- action: labelmap
regex: __meta_kubernetes_node_label_(.+)
- job_name: "kubernetes-nodes-cadvisor"
# Default to scraping over https. If required, just disable this or change to
# `http`.
scheme: https
# This TLS & bearer token file config is used to connect to the actual scrape
# endpoints for cluster components. This is separate to discovery auth
# configuration because discovery & scraping are two separate concerns in
# Prometheus. The discovery auth config is automatic if Prometheus runs inside
# the cluster. Otherwise, more config options have to be provided within the
# <kubernetes_sd_config>.
tls_config:
ca_file: /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
# If your node certificates are self-signed or use a different CA to the
# master CA, then you need to disable certificate verification. Note that
# certificate verification is an integral part of a secure infrastructure
# so this should only be disabled in a controlled environment. You can
# enable certificate verification by commenting the line below.
#
insecure_skip_verify: true
bearer_token_file: /var/run/secrets/kubernetes.io/serviceaccount/token
kubernetes_sd_configs:
- role: node
# This configuration will work only on kubelet 1.7.3+
# As the scrape endpoints for cAdvisor have changed
# if you are using older version you need to change the replacement to
# replacement: /api/v1/nodes/$1:4194/proxy/metrics
# more info here https://github.com/coreos/prometheus-operator/issues/633
metrics_path: /metrics/cadvisor
relabel_configs:
- action: labelmap
regex: __meta_kubernetes_node_label_(.+)
# ignore timestamps of cadvisor's metrics by default
# more info here https://github.com/VictoriaMetrics/VictoriaMetrics/issues/4697#issuecomment-1656540535
honor_timestamps: false
# Scrape config for service endpoints.
#
# The relabeling allows the actual service scrape endpoint to be configured
# via the following annotations:
#
# * `prometheus.io/scrape`: Only scrape services that have a value of `true`
# * `prometheus.io/scheme`: If the metrics endpoint is secured then you will need
# to set this to `https` & most likely set the `tls_config` of the scrape config.
# * `prometheus.io/path`: If the metrics path is not `/metrics` override this.
# * `prometheus.io/port`: If the metrics are exposed on a different port to the
# service then set this appropriately.
#
- job_name: "kubernetes-service-endpoints"
kubernetes_sd_configs:
- role: endpointslices
relabel_configs:
- action: drop
source_labels: [__meta_kubernetes_pod_container_init]
regex: true
- action: keep_if_equal
source_labels: [__meta_kubernetes_service_annotation_prometheus_io_port, __meta_kubernetes_pod_container_port_number]
- source_labels:
[__meta_kubernetes_service_annotation_prometheus_io_scrape]
action: keep
regex: true
- source_labels:
[__meta_kubernetes_service_annotation_prometheus_io_scheme]
action: replace
target_label: __scheme__
regex: (https?)
- source_labels:
[__meta_kubernetes_service_annotation_prometheus_io_path]
action: replace
target_label: __metrics_path__
regex: (.+)
- source_labels:
[
__address__,
__meta_kubernetes_service_annotation_prometheus_io_port,
]
action: replace
target_label: __address__
regex: ([^:]+)(?::\d+)?;(\d+)
replacement: $1:$2
- action: labelmap
regex: __meta_kubernetes_service_label_(.+)
- source_labels: [__meta_kubernetes_pod_name]
target_label: pod
- source_labels: [__meta_kubernetes_pod_container_name]
target_label: container
- source_labels: [__meta_kubernetes_namespace]
target_label: namespace
- source_labels: [__meta_kubernetes_service_name]
target_label: service
- source_labels: [__meta_kubernetes_service_name]
target_label: job
replacement: ${1}
- source_labels: [__meta_kubernetes_pod_node_name]
action: replace
target_label: node
# Scrape config for slow service endpoints; same as above, but with a larger
# timeout and a larger interval
#
# The relabeling allows the actual service scrape endpoint to be configured
# via the following annotations:
#
# * `prometheus.io/scrape-slow`: Only scrape services that have a value of `true`
# * `prometheus.io/scheme`: If the metrics endpoint is secured then you will need
# to set this to `https` & most likely set the `tls_config` of the scrape config.
# * `prometheus.io/path`: If the metrics path is not `/metrics` override this.
# * `prometheus.io/port`: If the metrics are exposed on a different port to the
# service then set this appropriately.
#
- job_name: "kubernetes-service-endpoints-slow"
scrape_interval: 5m
scrape_timeout: 30s
kubernetes_sd_configs:
- role: endpointslices
relabel_configs:
- action: drop
source_labels: [__meta_kubernetes_pod_container_init]
regex: true
- action: keep_if_equal
source_labels: [__meta_kubernetes_service_annotation_prometheus_io_port, __meta_kubernetes_pod_container_port_number]
- source_labels:
[__meta_kubernetes_service_annotation_prometheus_io_scrape_slow]
action: keep
regex: true
- source_labels:
[__meta_kubernetes_service_annotation_prometheus_io_scheme]
action: replace
target_label: __scheme__
regex: (https?)
- source_labels:
[__meta_kubernetes_service_annotation_prometheus_io_path]
action: replace
target_label: __metrics_path__
regex: (.+)
- source_labels:
[
__address__,
__meta_kubernetes_service_annotation_prometheus_io_port,
]
action: replace
target_label: __address__
regex: ([^:]+)(?::\d+)?;(\d+)
replacement: $1:$2
- action: labelmap
regex: __meta_kubernetes_service_label_(.+)
- source_labels: [__meta_kubernetes_pod_name]
target_label: pod
- source_labels: [__meta_kubernetes_pod_container_name]
target_label: container
- source_labels: [__meta_kubernetes_namespace]
target_label: namespace
- source_labels: [__meta_kubernetes_service_name]
target_label: service
- source_labels: [__meta_kubernetes_service_name]
target_label: job
replacement: ${1}
- source_labels: [__meta_kubernetes_pod_node_name]
action: replace
target_label: node
# Example scrape config for probing services via the Blackbox Exporter.
#
# The relabeling allows the actual service scrape endpoint to be configured
# via the following annotations:
#
# * `prometheus.io/probe`: Only probe services that have a value of `true`
#
- job_name: "kubernetes-services"
metrics_path: /probe
params:
module: [http_2xx]
kubernetes_sd_configs:
- role: service
relabel_configs:
- source_labels:
[__meta_kubernetes_service_annotation_prometheus_io_probe]
action: keep
regex: true
- source_labels: [__address__]
target_label: __param_target
- target_label: __address__
replacement: blackbox
- source_labels: [__param_target]
target_label: instance
- action: labelmap
regex: __meta_kubernetes_service_label_(.+)
- source_labels: [__meta_kubernetes_namespace]
target_label: namespace
- source_labels: [__meta_kubernetes_service_name]
target_label: service
# Example scrape config for pods
#
# The relabeling allows the actual pod scrape endpoint to be configured via the
# following annotations:
#
# * `prometheus.io/scrape`: Only scrape pods that have a value of `true`
# * `prometheus.io/path`: If the metrics path is not `/metrics` override this.
# * `prometheus.io/port`: Scrape the pod on the indicated port instead of the default of `9102`.
#
- job_name: "kubernetes-pods"
kubernetes_sd_configs:
- role: pod
relabel_configs:
- action: drop
source_labels: [__meta_kubernetes_pod_container_init]
regex: true
- action: keep_if_equal
source_labels: [__meta_kubernetes_pod_annotation_prometheus_io_port, __meta_kubernetes_pod_container_port_number]
- source_labels: [__meta_kubernetes_pod_annotation_prometheus_io_scrape]
action: keep
regex: true
- source_labels: [__meta_kubernetes_pod_annotation_prometheus_io_path]
action: replace
target_label: __metrics_path__
regex: (.+)
- source_labels:
[__address__, __meta_kubernetes_pod_annotation_prometheus_io_port]
action: replace
regex: ([^:]+)(?::\d+)?;(\d+)
replacement: $1:$2
target_label: __address__
- action: labelmap
regex: __meta_kubernetes_pod_label_(.+)
- source_labels: [__meta_kubernetes_pod_name]
target_label: pod
- source_labels: [__meta_kubernetes_pod_container_name]
target_label: container
- source_labels: [__meta_kubernetes_namespace]
target_label: namespace
- source_labels: [__meta_kubernetes_pod_node_name]
action: replace
target_label: node
## End of COPY
# -- Extra scrape configs that will be appended to `config`
extraScrapeConfigs: []
probe:
# -- Readiness probe
readiness:
httpGet: {}
initialDelaySeconds: 5
periodSeconds: 15
# -- Liveness probe
liveness:
tcpSocket: {}
initialDelaySeconds: 5
periodSeconds: 15
timeoutSeconds: 5
# -- Startup probe
startup: {}
# -- Add extra specs dynamically to this chart
extraObjects: []
allowedMetricsEndpoints:
- /metrics
# -- Enterprise license key configuration for VictoriaMetrics enterprise.
# Required only for VictoriaMetrics enterprise. Check docs [here](https://docs.victoriametrics.com/victoriametrics/enterprise/),
# for more information, visit [site](https://victoriametrics.com/products/enterprise/).
# Request a trial license [here](https://victoriametrics.com/products/enterprise/trial/)
# Supported starting from VictoriaMetrics v1.94.0
license:
# -- License key
key: ""
# -- Use existing secret with license key
secret:
# -- Existing secret name
name: ""
# -- Key in secret with license key
key: ""