Add VictoriaMetrics observability stack + sync catalog for monitoring test

- VM stack 10 charts: victoria-metrics-cluster/auth, victoria-logs-cluster,
  victoria-metrics-agent/alert, opentelemetry-collector, kube-state-metrics,
  prometheus-node-exporter, alertmanager, perses (JWT/OIDC, Infisical-ready)
- ArgoCD ApplicationSet (syncWave) + per-chart dip-values overlays
- doc/victoria-metrics-architecture.md, define-chart-resources updates
- includes pending working-tree changes (mlflow, kubeflow, apisix, CLAUDE.md)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
wbsong111
2026-06-25 11:10:51 +09:00
parent a55427730e
commit 6290322f1b
514 changed files with 68103 additions and 40 deletions
@@ -0,0 +1,30 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/
*.md.gotmpl
CHANGELOG.md
_changelog.md
_index.md
e2e/
lint/
tests/
@@ -0,0 +1,70 @@
# victoria-metrics-alert 버전 갱신 가이드
> **카탈로그 업데이트 방식**: 기존 버전 디렉토리는 유지하고, 신규 버전 디렉토리를 새로 생성한다.
> `manifests/helm/victoria-metrics-alert/<new-version>/` 디렉토리를 직접 추가하는 방식으로 관리한다.
## 1. git 작업 환경 구성
- dip-catalog git 다운로드
```sh
git clone https://github.com/paasup/dip-catalog.git
```
- 작업 브랜치로 체크아웃
```sh
git checkout -b update-victoria-metrics-alert/<new-version>
```
## 2. helm chart 업데이트
### 1) 기존 버전 디렉토리 복사
신규 버전 디렉토리를 기존 버전에서 복사하여 시작한다.
`BUILD-README.md`, `CUSTOM-README.md`, `custom-values.yaml`가 함께 복사된다.
```sh
cd ~/dip-catalog/manifests/helm/victoria-metrics-alert
# 기존 버전에서 신규 버전 디렉토리 복사
cp -r 0.41.0 <new-version>
```
### 2) 업스트림 차트 파일 업데이트
신규 버전 디렉토리에서 업스트림 차트 파일만 교체한다.
`BUILD-README.md`, `CUSTOM-README.md`, `custom-values.yaml`는 유지한다.
```sh
cd ~/dip-catalog/manifests/helm/victoria-metrics-alert
# helm repo 추가
helm repo add victoria-metrics https://victoriametrics.github.io/helm-charts/
helm repo update
# 신규 버전 차트 다운로드 후 압축 해제
helm pull victoria-metrics/victoria-metrics-alert --version="<new-version>"
tar xzvf victoria-metrics-alert-<new-version>.tgz -C <new-version> --strip-components=1
# 불필요한 파일 삭제
rm victoria-metrics-alert-<new-version>.tgz
```
## 3. git push 및 tag 추가
```sh
git add .
git commit -m "update victoria-metrics-alert/<new-version>"
git checkout main
git merge update-victoria-metrics-alert/<new-version>
git push -u origin main
git branch -d update-victoria-metrics-alert/<new-version>
git tag victoria-metrics-alert/<new-version>
git push origin victoria-metrics-alert/<new-version>
```
## 4. 차트 버전 정보
- victoria-metrics-alert/0.41.0
- Chart version: 0.41.0
- App version: v1.144.0
- 업스트림: https://victoriametrics.github.io/helm-charts/
@@ -0,0 +1,40 @@
# vmalert 배포 (알림 규칙 평가 엔진)
PromQL 알림 규칙을 주기적으로 평가하고, 발생한 알림을 Alertmanager로 전송한다. ALERTS 메트릭은 다시 VictoriaMetrics에 기록한다.
## 1. 배포 방법
```sh
helm upgrade vmalert ./ -f custom-values.yaml --install -n monitoring
```
사전: vmcluster, alertmanager가 배포되어 있어야 한다.
## 2. custom-values.yaml 설정 설명
| 항목 | 대상 | 비고 |
|------|------|------|
| `datasource.url` | vmselect `/select/multitenant/prometheus` | 클러스터 전체 집계 조회 |
| `remoteWrite.url` | vminsert `/insert/0/prometheus` | ALERTS 메트릭 기록 (`/api/v1/write` 자동 부착) |
| `notifier.url` | alertmanager:9093 | 알림 발송 |
### 인증 — 내부 서비스
vmalert는 **내부 서비스**이므로 vmselect multitenant 엔드포인트에 직접 연결한다(vmauth JWT 미경유). 사용자/외부 접근만 vmauth를 거친다.
> vmauth 경유가 필요하면 datasource를 vmauth(`:8427`)로 바꾸고, Keycloak **service-account 토큰**(bearer)을 datasource 인증에 설정한다. `unauthorized_user`(accountID 0)만으로는 전체 클러스터 메트릭을 볼 수 없으므로 multitenant 또는 적절한 `vm_access` 토큰이 필요하다.
### 알림 규칙 (`server.config.alerts`)
클러스터 헬스 8종: NodeDown, NodeHighCPU, NodeHighMemory, NodeDiskPressure, PodCrashLooping, PodNotReady, DeploymentReplicasMismatch, PVCFillingUp. 평가 주기 30s.
## 3. 의존 관계
vmselect(조회) · vminsert(기록) · alertmanager(발송) · kube-state-metrics/node-exporter(규칙이 참조하는 메트릭 소스)
## 4. 검증
```sh
kubectl port-forward -n monitoring svc/vmalert-victoria-metrics-alert 8880:8880
curl -s http://localhost:8880/api/v1/rules | jq '.data.groups[].name'
```
@@ -0,0 +1,6 @@
dependencies:
- name: victoria-metrics-common
repository: oci://ghcr.io/victoriametrics/helm-charts
version: 0.3.0
digest: sha256:cadb4ced35cde20c5f8437f6ff223ded677542490848e1b3a3b5f330f3069ebc
generated: "2026-04-16T10:13:29.482231209Z"
@@ -0,0 +1,46 @@
annotations:
artifacthub.io/category: monitoring-logging
artifacthub.io/changes: |
- bump version of VM components to [v1.144.0](https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.144.0)
artifacthub.io/license: Apache-2.0
artifacthub.io/links: |
- name: Sources
url: https://github.com/VictoriaMetrics/helm-charts/tree/master/charts/victoria-metrics-alert
- name: Charts repo
url: https://victoriametrics.github.io/helm-charts/
- name: Docs
url: https://docs.victoriametrics.com/victoriametrics/vmalert/
- name: Changelog
url: https://docs.victoriametrics.com/victoriametrics/changelog/
artifacthub.io/readme: |
# VictoriaMetrics Alert Helm chart
Chart documentation is available [here](https://docs.victoriametrics.com/helm/victoria-metrics-alert/).
Changelog is [here](https://docs.victoriametrics.com/helm/victoria-metrics-alert/changelog/).
apiVersion: v2
appVersion: v1.144.0
dependencies:
- name: victoria-metrics-common
repository: oci://ghcr.io/victoriametrics/helm-charts
version: 0.3.*
description: VictoriaMetrics Alert - executes a list of given MetricsQL expressions
(rules) and sends alerts to Alert Manager.
home: https://github.com/VictoriaMetrics/helm-charts
icon: https://avatars.githubusercontent.com/u/43720803?s=200&v=4
keywords:
- victoriametrics
- vmalert
- alerting
- alerts
- monitoring
- kubernetes
- observability
- metrics
- timeseries
- rules
kubeVersion: '>=1.25.0-0'
name: victoria-metrics-alert
sources:
- https://github.com/VictoriaMetrics/helm-charts
type: application
version: 0.41.0
@@ -0,0 +1,4 @@
# VictoriaMetrics Alert Helm chart
Chart documentation is available [here](https://docs.victoriametrics.com/helm/victoria-metrics-alert/).
Changelog is [here](https://docs.victoriametrics.com/helm/victoria-metrics-alert/changelog/).
@@ -0,0 +1,7 @@
# Release notes for version 0.41.0
**Release date:** 25 May 2026
![Helm: v3](https://img.shields.io/badge/Helm-v3.14%2B-informational?color=informational&logo=helm&link=https%3A%2F%2Fgithub.com%2Fhelm%2Fhelm%2Freleases%2Ftag%2Fv3.14.0) ![AppVersion: v1.144.0](https://img.shields.io/badge/v1.144.0-success?logo=VictoriaMetrics&labelColor=gray&link=https%3A%2F%2Fdocs.victoriametrics.com%2Fvictoriametrics%2Fchangelog%2F%23v11440)
- bump version of VM components to [v1.144.0](https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.144.0)
@@ -0,0 +1,26 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/
*.md.gotmpl
CHANGELOG.md
_changelog.md
_index.md
@@ -0,0 +1,3 @@
dependencies: []
digest: sha256:643d5437104296e21d906ecb15b2c96ad278f20cfc4af53b12bb6069bd853726
generated: "2024-11-13T12:10:17.363248379Z"
@@ -0,0 +1,33 @@
annotations:
artifacthub.io/category: monitoring-logging
artifacthub.io/changes: |
- reverted usage of `app` label in `vm.selectorLabels`
artifacthub.io/license: Apache-2.0
artifacthub.io/links: |
- name: Sources
url: https://github.com/VictoriaMetrics/helm-charts/tree/master/charts/victoria-metrics-common
- name: Charts repo
url: https://victoriametrics.github.io/helm-charts/
artifacthub.io/readme: |
# VictoriaMetrics Common Helm chart
Chart documentation is available [here](https://docs.victoriametrics.com/helm/victoria-metrics-common/).
Changelog is [here](https://docs.victoriametrics.com/helm/victoria-metrics-common/changelog/).
apiVersion: v2
description: VictoriaMetrics Common - contains shared templates for all Victoria Metrics
helm charts
keywords:
- victoriametrics
- monitoring
- kubernetes
- observability
- tsdb
- metrics
- metricsql
- timeseries
kubeVersion: '>=1.23.0-0'
name: victoria-metrics-common
sources:
- https://github.com/VictoriaMetrics/helm-charts
type: library
version: 0.3.0
@@ -0,0 +1,4 @@
# VictoriaMetrics Common Helm chart
Chart documentation is available [here](https://docs.victoriametrics.com/helm/victoria-metrics-common/).
Changelog is [here](https://docs.victoriametrics.com/helm/victoria-metrics-common/changelog/).
@@ -0,0 +1,7 @@
# Release notes for version 0.3.0
**Release date:** 16 Apr 2026
![Helm: v3](https://img.shields.io/badge/Helm-v3.14%2B-informational?color=informational&logo=helm&link=https%3A%2F%2Fgithub.com%2Fhelm%2Fhelm%2Freleases%2Ftag%2Fv3.14.0)
- reverted usage of `app` label in `vm.selectorLabels`
@@ -0,0 +1,87 @@
{{- define "vm.license.secret.key" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $plain := (($Values.license).secret).key | default ((($Values.global).license).secret).key -}}
{{- $managed := (($Values.license).keyRef).key | default ((($Values.global).license).keyRef).key }}
{{- if $plain -}}
{{- $plain -}}
{{- else if $managed -}}
{{- $managed -}}
{{- end -}}
{{- end -}}
{{- define "vm.license.secret.name" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $plain := (($Values.license).secret).name | default ((($Values.global).license).secret).name -}}
{{- $managed := (($Values.license).keyRef).name | default ((($Values.global).license).keyRef).name -}}
{{- if $plain -}}
{{- $plain -}}
{{- else if $managed -}}
{{- $managed -}}
{{- end -}}
{{- end -}}
{{- define "vm.license.key" -}}
{{- $Values := (.helm).Values | default .Values }}
{{- ($Values.license).key | default (($Values.global).license).key | default "" -}}
{{- end -}}
{{- define "vm.enterprise.disabled" -}}
{{- $licenseKey := (include "vm.license.key" .) -}}
{{- $licenseSecretKey := (include "vm.license.secret.key" .) -}}
{{- $licenseSecretName := (include "vm.license.secret.name" .) -}}
{{- or .noEnterprise (and (empty $licenseKey) (and (empty $licenseSecretName) (empty $licenseSecretKey))) -}}
{{- end -}}
{{- define "vm.enterprise.only" -}}
{{- if eq (include "vm.enterprise.disabled" .) "true" }}
{{ fail `Pass valid license at .Values.license or .Values.global.license if you have an enterprise license for running this software.
See https://victoriametrics.com/legal/esa/ for details.
Documentation - https://docs.victoriametrics.com/victoriametrics/enterprise/
for more information, visit https://victoriametrics.com/products/enterprise/
To request a trial license, go to https://victoriametrics.com/products/enterprise/trial/` }}
{{- end -}}
{{- end -}}
{{/*
Return license volume mount
*/}}
{{- define "vm.license.volume" -}}
{{- $licenseSecretKey := (include "vm.license.secret.key" .) -}}
{{- $licenseSecretName := (include "vm.license.secret.name" .) -}}
{{- if and $licenseSecretName $licenseSecretKey -}}
- name: license-key
secret:
secretName: {{ $licenseSecretName }}
{{- end -}}
{{- end -}}
{{/*
Return license volume mount for container
*/}}
{{- define "vm.license.mount" -}}
{{- $licenseSecretKey := (include "vm.license.secret.key" .) -}}
{{- $licenseSecretName := (include "vm.license.secret.name" .) -}}
{{- if and $licenseSecretName $licenseSecretKey -}}
- name: license-key
mountPath: /etc/vm-license-key
readOnly: true
{{- end -}}
{{- end -}}
{{/*
Return license flag if necessary.
*/}}
{{- define "vm.license.flag" -}}
{{- $licenseKey := (include "vm.license.key" .) -}}
{{- $licenseSecretKey := (include "vm.license.secret.key" .) -}}
{{- $licenseSecretName := (include "vm.license.secret.name" .) -}}
{{- if $licenseKey -}}
license: {{ $licenseKey }}
{{- else if and $licenseSecretName $licenseSecretKey -}}
{{- $flagName := "licenseFile" -}}
{{- if eq .flagStyle "kebab" }}
{{- $flagName = "license-file" -}}
{{- end -}}
{{- $flagName }}: /etc/vm-license-key/{{ $licenseSecretKey }}
{{- end -}}
{{- end -}}
@@ -0,0 +1,249 @@
{{- define "vm.namespace" -}}
{{- include "vm.validate.args" . -}}
{{- $Release := (.helm).Release | default .Release -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $Values.namespaceOverride | default ($Values.global).namespaceOverride | default $Release.Namespace -}}
{{- end -}}
{{- define "vm.validate.args" -}}
{{- $Chart := (.helm).Chart | default .Chart -}}
{{- $Capabilities := (.helm).Capabilities | default .Capabilities -}}
{{- if semverCompare "<3.14.0" $Capabilities.HelmVersion.Version }}
{{- fail "This chart requires helm version 3.14.0 or higher" }}
{{- end }}
{{- if empty $Chart -}}
{{- fail "invalid template data" -}}
{{- end -}}
{{- end -}}
{{- /* Expand the name of the chart. */ -}}
{{- define "vm.name" -}}
{{- include "vm.validate.args" . -}}
{{- $Chart := (.helm).Chart | default .Chart -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $nameOverride := $Values.nameOverride | default ($Values.global).nameOverride | default $Chart.Name -}}
{{- if or ($Values.global).disableNameTruncation $Values.disableNameTruncation -}}
{{- $nameOverride -}}
{{- else -}}
{{- $nameOverride | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{- /*
Create a default fully qualified app name.
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
If release name contains chart name it will be used as a full name.
*/ -}}
{{- define "vm.fullname" -}}
{{- include "vm.validate.args" . -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $Chart := (.helm).Chart | default .Chart -}}
{{- $Release := (.helm).Release | default .Release -}}
{{- $fullname := "" -}}
{{- if $Values.fullnameOverride -}}
{{- $fullname = $Values.fullnameOverride -}}
{{- else if ($Values.global).fullnameOverride -}}
{{- $fullname = $Values.global.fullnameOverride -}}
{{- else -}}
{{- $name := default $Chart.Name $Values.nameOverride -}}
{{- if contains $name $Release.Name -}}
{{- $fullname = $Release.Name -}}
{{- else -}}
{{- $fullname = (printf "%s-%s" $Release.Name $name) }}
{{- end -}}
{{- end -}}
{{- $fullname = tpl $fullname . -}}
{{- if or ($Values.global).disableNameTruncation $Values.disableNameTruncation -}}
{{- $fullname -}}
{{- else -}}
{{- $fullname | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end }}
{{- define "vm.cr.fullname" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $_ := set . "overrideKey" "name" -}}
{{- $fullname := include "vm.internal.key" . -}}
{{- $_ := unset . "overrideKey" -}}
{{- if empty $fullname -}}
{{- $fullname = include "vm.fullname" . -}}
{{- end -}}
{{- $fullname = tpl $fullname . -}}
{{- if or ($Values.global).disableNameTruncation $Values.disableNameTruncation -}}
{{- $fullname -}}
{{- else -}}
{{- $fullname | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{- define "vm.managed.fullname" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $_ := set . "overrideKey" "name" -}}
{{- $fullname := include "vm.internal.key" . -}}
{{- $_ := unset . "overrideKey" -}}
{{- if empty $fullname -}}
{{- $fullname = include "vm.fullname" . -}}
{{- end -}}
{{- with include "vm.internal.key.default" . -}}
{{- $prefix := ternary . (printf "vm%s" .) (or (hasPrefix "vm" .) (hasPrefix "vl" .)) -}}
{{- $fullname = printf "%s-%s" $prefix $fullname -}}
{{- end -}}
{{- $fullname = tpl $fullname . -}}
{{- if or ($Values.global).disableNameTruncation $Values.disableNameTruncation -}}
{{- $fullname -}}
{{- else -}}
{{- $fullname | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{- define "vm.plain.fullname" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $_ := set . "overrideKey" "fullnameOverride" -}}
{{- $fullname := include "vm.internal.key" . -}}
{{- $_ := unset . "overrideKey" -}}
{{- if empty $fullname -}}
{{- $fullname = include "vm.fullname" . -}}
{{- with include "vm.internal.key.default" . -}}
{{- $fullname = printf "%s-%s" $fullname . -}}
{{- end -}}
{{- end -}}
{{- $fullname = tpl $fullname . -}}
{{- if or ($Values.global).disableNameTruncation $Values.disableNameTruncation -}}
{{- $fullname -}}
{{- else -}}
{{- $fullname | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{- define "vm.internal.key" -}}
{{- include "vm.validate.args" . -}}
{{- $overrideKey := .overrideKey | default "fullnameOverride" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $key := "" -}}
{{- if .appKey -}}
{{- $appKey := ternary (list .appKey) .appKey (kindIs "string" .appKey) -}}
{{- $ctx := . -}}
{{- $values := $Values -}}
{{- range $ak := $appKey }}
{{- $values = ternary (dict) (index $values $ak | default dict) (empty $values) -}}
{{- $ctx = ternary (dict) (index $ctx $ak | default dict) (empty $ctx) -}}
{{- if and (empty $values) (empty $ctx) -}}
{{- fail (printf "No data for appKey %s" (join "->" $appKey)) -}}
{{- end -}}
{{- if and (kindIs "map" $values) (index $values $overrideKey) -}}
{{- $key = index $values $overrideKey -}}
{{- else if and (kindIs "map" $ctx) (index $ctx $overrideKey) -}}
{{- $key = index $ctx $overrideKey -}}
{{- end -}}
{{- end }}
{{- if and (empty $key) .fallback -}}
{{- $key = include "vm.internal.key.default" . -}}
{{- end -}}
{{- end -}}
{{- $key -}}
{{- end -}}
{{- define "vm.internal.key.default" -}}
{{- with .appKey -}}
{{- $key := ternary (list .) . (kindIs "string" .) -}}
{{- last (without $key "spec") -}}
{{- end -}}
{{- end -}}
{{- /* Create chart name and version as used by the chart label. */ -}}
{{- define "vm.chart" -}}
{{- include "vm.validate.args" . -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $Chart := (.helm).Chart | default .Chart -}}
{{- $chart := printf "%s-%s" $Chart.Name $Chart.Version | replace "+" "_" -}}
{{- if or ($Values.global).disableNameTruncation $Values.disableNameTruncation -}}
{{- $chart -}}
{{- else -}}
{{- $chart | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{- end }}
{{- /* Create the name of the service account to use */ -}}
{{- define "vm.sa.name" -}}
{{- include "vm.validate.args" . -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- if $Values.serviceAccount.create }}
{{- default (include "vm.fullname" .) $Values.serviceAccount.name }}
{{- else -}}
{{- default "default" $Values.serviceAccount.name -}}
{{- end }}
{{- end }}
{{- define "vm.metaLabels" -}}
{{- include "vm.validate.args" . -}}
{{- $Release := (.helm).Release | default .Release -}}
{{- $labels := .extraLabels | default dict -}}
{{- $_ := set $labels "helm.sh/chart" (include "vm.chart" .) -}}
{{- $_ := set $labels "app.kubernetes.io/managed-by" $Release.Service -}}
{{- toYaml $labels -}}
{{- end -}}
{{- define "vm.podLabels" -}}
{{- include "vm.validate.args" . -}}
{{- $Release := (.helm).Release | default .Release -}}
{{- $labels := fromYaml (include "vm.selectorLabels" .) -}}
{{- with $labels.app -}}
{{- $_ := set $labels "app.kubernetes.io/component" . -}}
{{- end -}}
{{- $labels = mergeOverwrite $labels (.extraLabels | default dict) -}}
{{- $_ := set $labels "app.kubernetes.io/managed-by" $Release.Service -}}
{{- toYaml $labels -}}
{{- end -}}
{{- /* Common labels */ -}}
{{- define "vm.labels" -}}
{{- include "vm.validate.args" . -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $globalLabels := deepCopy (($Values.global).extraLabels | default dict) -}}
{{- $labels := fromYaml (include "vm.commonLabels" .) -}}
{{- $labels = mergeOverwrite $globalLabels $labels (fromYaml (include "vm.metaLabels" .)) -}}
{{- with (include "vm.image.tag" .) }}
{{- $_ := set $labels "app.kubernetes.io/version" (regexReplaceAll "(.*)(@sha.*)" . "${1}") -}}
{{- end -}}
{{- toYaml $labels -}}
{{- end -}}
{{- define "vm.release" -}}
{{- include "vm.validate.args" . -}}
{{- $Release := (.helm).Release | default .Release -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $release := default $Release.Name $Values.argocdReleaseOverride -}}
{{- if or ($Values.global).disableNameTruncation $Values.disableNameTruncation -}}
{{- $release -}}
{{- else -}}
{{- $release | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{- define "vm.app.name" -}}
{{- $_ := set . "overrideKey" "name" -}}
{{- $_ := set . "fallback" true -}}
{{- tpl (include "vm.internal.key" .) . -}}
{{- $_ := unset . "overrideKey" -}}
{{- $_ := unset . "fallback" -}}
{{- end -}}
{{- /* Selector labels */ -}}
{{- define "vm.selectorLabels" -}}
{{- $labels := .extraLabels | default dict -}}
{{- $_ := set $labels "app.kubernetes.io/name" (include "vm.name" .) -}}
{{- $_ := set $labels "app.kubernetes.io/instance" (include "vm.release" .) -}}
{{- with (include "vm.app.name" .) -}}
{{- $_ := set $labels "app" . -}}
{{- end -}}
{{- toYaml $labels -}}
{{- end }}
{{- define "vm.commonLabels" -}}
{{- $labels := fromYaml (include "vm.selectorLabels" . ) -}}
{{- with $labels.app -}}
{{- $_ := set $labels "app.kubernetes.io/component" . -}}
{{- $_ := unset $labels "app" -}}
{{- end -}}
{{- toYaml $labels -}}
{{- end -}}
@@ -0,0 +1,61 @@
{{/*
Victoria Metrics Image
*/}}
{{- define "vm.image" -}}
{{- $image := (fromYaml (include "vm.internal.image" .)).image | default dict -}}
{{- $tag := include "vm.image.tag" . -}}
{{- if empty $image.repository -}}
{{- fail "cannot create image without `.repository` defined" -}}
{{- end -}}
{{- $result := tpl (printf "%s:%s" $image.repository $tag) . -}}
{{- with $image.registry | default "" -}}
{{- $result = (printf "%s/%s" . $result) -}}
{{- end -}}
{{- $result -}}
{{- end -}}
{{- define "vm.image.tag" -}}
{{- $Chart := (.helm).Chart | default .Chart -}}
{{- $image := (fromYaml (include "vm.internal.image" .)).image | default dict -}}
{{- $tag := $image.tag -}}
{{- if empty $tag }}
{{- $tag = $Chart.AppVersion -}}
{{- $variant := $image.variant }}
{{- if eq (include "vm.enterprise.disabled" .) "false" -}}
{{- if $variant }}
{{- $variant = printf "enterprise-%s" $variant }}
{{- else }}
{{- $variant = "enterprise" }}
{{- end }}
{{- end -}}
{{- with $variant -}}
{{- $tag = (printf "%s-%s" $tag .) -}}
{{- end -}}
{{- end -}}
{{- $tag -}}
{{- end -}}
{{- define "vm.internal.image" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $values := $Values -}}
{{- $ctx := . -}}
{{- with .appKey -}}
{{- $appKey := ternary (list .) . (kindIs "string" .) -}}
{{- range $ak := $appKey -}}
{{- $values = ternary (dict) (index $values $ak | default dict) (empty $values) -}}
{{- $ctx = ternary (dict) (index $ctx $ak | default dict) (empty $ctx) -}}
{{- if and (empty $values) (empty $ctx) -}}
{{- fail (printf "No data for appKey %s" (join "->" $appKey)) -}}
{{- end -}}
{{- end -}}
{{- end -}}
{{- $image := ternary (deepCopy ($ctx.image | default dict)) (deepCopy ($values.image | default dict)) (hasKey $ctx "image") -}}
{{- if not $image.registry }}
{{- if (($Values.global).image).registry -}}
{{- $_ := set $image "registry" (($Values.global).image).registry -}}
{{- else if hasKey $image "registry" -}}
{{- $_ := unset $image "registry" -}}
{{- end -}}
{{- end -}}
{{- toYaml (dict "image" $image) -}}
{{- end -}}
@@ -0,0 +1,8 @@
{{- define "vm.ingress.port" }}
{{- $port := dict "name" "http" }}
{{- with .port }}
{{- $numberTypes := list "int" "float64" }}
{{- $port = dict (ternary "number" "name" (has (kindOf .) $numberTypes)) . }}
{{- end -}}
{{- toYaml $port -}}
{{- end }}
@@ -0,0 +1,117 @@
{{- define "vm.port.from.flag" -}}
{{- $port := .default -}}
{{- with .flag -}}
{{- $port = regexReplaceAll ".*:(\\d+)" . "${1}" -}}
{{- end -}}
{{- $port -}}
{{- end }}
{{- /*
Return true if the detected platform is Openshift
Usage:
{{- include "vm.isOpenshift" . -}}
*/ -}}
{{- define "vm.isOpenshift" -}}
{{- $Capabilities := (.helm).Capabilities | default .Capabilities -}}
{{- if $Capabilities.APIVersions.Has "security.openshift.io/v1" -}}
{{- true -}}
{{- end -}}
{{- end -}}
{{- /*
Render a compatible securityContext depending on the platform.
Usage:
{{- include "vm.securityContext" (dict "securityContext" .Values.containerSecurityContext "helm" .) -}}
*/ -}}
{{- define "vm.securityContext" -}}
{{- $securityContext := omit .securityContext "enabled" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $adaptMode := (((($Values).global).compatibility).openshift).adaptSecurityContext | default "" -}}
{{- if or (eq $adaptMode "force") (and (eq $adaptMode "auto") (include "vm.isOpenshift" .)) -}}
{{- $securityContext = omit $securityContext "fsGroup" "runAsUser" "runAsGroup" "seLinuxOptions" -}}
{{- end -}}
{{- toYaml $securityContext -}}
{{- end -}}
{{- /*
Render probe
*/ -}}
{{- define "vm.probe" -}}
{{- /* undefined value */ -}}
{{- $null := (fromYaml "value: null").value -}}
{{- $probe := dig .type (dict) .app.probe -}}
{{- $probeType := "" -}}
{{- $defaultProbe := dict -}}
{{- if ne (dig "httpGet" $null $probe) $null -}}
{{- /* httpGet probe */ -}}
{{- $defaultProbe = dict "path" (include "vm.probe.http.path" .) "scheme" (include "vm.probe.http.scheme" .) "port" (include "vm.probe.port" .) -}}
{{- $probeType = "httpGet" -}}
{{- else if ne (dig "tcpSocket" $null $probe) $null -}}
{{- /* tcpSocket probe */ -}}
{{- $defaultProbe = dict "port" (include "vm.probe.port" .) -}}
{{- $probeType = "tcpSocket" -}}
{{- end -}}
{{- $defaultProbe = ternary (dict) (dict $probeType $defaultProbe) (empty $probeType) -}}
{{- $probe = mergeOverwrite $defaultProbe $probe -}}
{{- range $key, $value := $probe -}}
{{- if and (has (kindOf $value) (list "object" "map")) (ne $key $probeType) -}}
{{- $_ := unset $probe $key -}}
{{- end -}}
{{- end -}}
{{- tpl (toYaml $probe) . -}}
{{- end -}}
{{- /*
HTTP GET probe path
*/ -}}
{{- define "vm.probe.http.path" -}}
{{- index .app.extraArgs "http.pathPrefix" | default "" | trimSuffix "/" -}}/health
{{- end -}}
{{- /*
HTTP GET probe scheme
*/ -}}
{{- define "vm.probe.http.scheme" -}}
{{- $isSecure := false -}}
{{- with ((.app).extraArgs).tls -}}
{{- $isSecure = eq (toString .) "true" -}}
{{- end -}}
{{- ternary "HTTPS" "HTTP" $isSecure -}}
{{- end -}}
{{- /*
Net probe port
*/ -}}
{{- define "vm.probe.port" -}}
{{- dig "ports" "name" "http" (.app | dict) -}}
{{- end -}}
{{- define "vm.arg" -}}
{{- if and (empty .value) (kindIs "string" .value) (ne (toString .list) "true") }}
{{- .key -}}
{{- else if eq (toString .value) "true" -}}
-{{ ternary "" "-" (eq (len .key) 1) }}{{ .key }}
{{- else -}}
-{{ ternary "" "-" (eq (len .key) 1) }}{{ .key }}={{ ternary (toJson .value | squote) .value (has (kindOf .value) (list "map" "slice")) }}
{{- end -}}
{{- end -}}
{{- /*
command line arguments
*/ -}}
{{- define "vm.args" -}}
{{- $args := list -}}
{{- range $key, $value := . -}}
{{- if not $key -}}
{{- fail "Empty key in command line args is not allowed" -}}
{{- end -}}
{{- if kindIs "slice" $value -}}
{{- range $v := $value -}}
{{- $args = append $args (include "vm.arg" (dict "key" $key "value" $v "list" true)) -}}
{{- end -}}
{{- else -}}
{{- $args = append $args (include "vm.arg" (dict "key" $key "value" $value)) -}}
{{- end -}}
{{- end -}}
{{- toYaml (dict "args" $args) -}}
{{- end -}}
@@ -0,0 +1,88 @@
{{- /* Create the name for VM service */ -}}
{{- define "vm.service" -}}
{{- include "vm.validate.args" . -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $nameTpl := "" -}}
{{- if eq .style "managed" -}}
{{- $nameTpl = "vm.managed.fullname" }}
{{- else if eq .style "plain" -}}
{{- $nameTpl = "vm.plain.fullname" }}
{{- else -}}
{{- fail ".style argument should be either `plain` or `managed`"}}
{{- end -}}
{{- include $nameTpl . -}}
{{- end }}
{{- define "vm.fqdn" -}}
{{- $name := (include "vm.service" .) -}}
{{- if hasKey . "appIdx" -}}
{{- $name = (printf "%s-%d.%s" $name .appIdx $name) -}}
{{- end -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $ns := (include "vm.namespace" .) -}}
{{- $fqdn := printf "%s.%s.svc" $name $ns -}}
{{- with (($Values.global).cluster).dnsDomain -}}
{{- $fqdn = printf "%s.%s" $fqdn . -}}
{{- end -}}
{{- $fqdn -}}
{{- end -}}
{{- define "vm.host" -}}
{{- $fqdn := (include "vm.fqdn" .) -}}
{{- $port := 80 -}}
{{- $isSecure := ternary false true (empty .appSecure) -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- if .appKey -}}
{{- $appKey := ternary (list .appKey) .appKey (kindIs "string" .appKey) -}}
{{- $values := $Values -}}
{{- $ctx := . -}}
{{- range $ak := $appKey -}}
{{- $values = ternary (dict) (index $values $ak | default dict) (empty $values) -}}
{{- $ctx = ternary (dict) (index $ctx $ak | default dict) (empty $ctx) -}}
{{- end -}}
{{- $spec := dict -}}
{{- if $ctx -}}
{{- $spec = $ctx -}}
{{- else if $values -}}
{{- $spec = $values -}}
{{- end -}}
{{- with ($spec.extraArgs).tls -}}
{{- $isSecure = eq (toString .) "true" -}}
{{- end -}}
{{- $port = (ternary 443 80 $isSecure) -}}
{{- $port = $spec.port | default ($spec.service).servicePort | default ($spec.service).port | default $port -}}
{{- if hasKey . "appIdx" -}}
{{- $port = (include "vm.port.from.flag" (dict "flag" ($spec.extraArgs).httpListenAddr "default" $port)) -}}
{{- end }}
{{- end }}
{{- $fqdn }}:{{ $port }}
{{- end -}}
{{- define "vm.url" -}}
{{- $host := (include "vm.host" .) -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $proto := "http" -}}
{{- $path := .appRoute | default "/" -}}
{{- $isSecure := ternary false true (empty .appSecure) -}}
{{- if .appKey -}}
{{- $appKey := ternary (list .appKey) .appKey (kindIs "string" .appKey) -}}
{{- $values := $Values -}}
{{- $ctx := . -}}
{{- range $ak := $appKey -}}
{{- $values = ternary (dict) (index $values $ak | default dict) (empty $values) -}}
{{- $ctx = ternary (dict) (index $ctx $ak | default dict) (empty $ctx) -}}
{{- end -}}
{{- $spec := dict -}}
{{- if $values -}}
{{- $spec = $values -}}
{{- else if $ctx -}}
{{- $spec = $ctx -}}
{{- end -}}
{{- with ($spec.extraArgs).tls -}}
{{- $isSecure = eq (toString .) "true" -}}
{{- end -}}
{{- $proto = (ternary "https" "http" $isSecure) -}}
{{- $path = dig "http.pathPrefix" $path ($spec.extraArgs | default dict) -}}
{{- end -}}
{{- printf "%s://%s%s" $proto $host (trimSuffix "/" $path) -}}
{{- end -}}
@@ -0,0 +1,110 @@
# =============================================================================
# vmalert — PaaSup 커스텀 오버라이드 (알림 규칙 평가 엔진)
# 차트: victoria-metrics/victoria-metrics-alert
#
# 연동:
# - datasource : vmselect multitenant 엔드포인트 직결 (클러스터 전체 집계 조회)
# vmalert는 내부 서비스이므로 vmauth(JWT)를 경유하지 않는다.
# 사용자/외부 접근만 vmauth JWT를 거친다. vmauth 경유가 필요하면
# Keycloak service-account 토큰(bearer)을 datasource에 설정한다(README 참조).
# - remoteWrite: ALERTS 메트릭 → vminsert accountID 0
# - notifier : Alertmanager:9093
# =============================================================================
server:
datasource:
url: "http://vmcluster-victoria-metrics-cluster-vmselect.monitoring.svc.cluster.local:8481/select/multitenant/prometheus"
# vmalert 차트가 /api/v1/write를 자동으로 붙이므로 URL에 포함하지 않는다.
remoteWrite:
url: "http://vmcluster-victoria-metrics-cluster-vminsert.monitoring.svc.cluster.local:8480/insert/0/prometheus"
notifier:
url: "http://alertmanager.monitoring.svc.cluster.local:9093"
extraArgs:
envflag.enable: "true"
envflag.prefix: VM_
loggerFormat: json
evaluationInterval: 30s
# 클러스터 전체 플랫폼 레벨 알림 규칙
config:
alerts:
groups:
- name: cluster-health
rules:
- alert: NodeDown
expr: kube_node_status_condition{condition="Ready",status="true"} == 0
for: 2m
labels:
severity: critical
annotations:
summary: "Node {{ $labels.node }} is down"
description: "Node {{ $labels.node }} has been unready for more than 2 minutes."
- alert: NodeHighCPU
expr: avg by(node)(1 - rate(node_cpu_seconds_total{mode="idle"}[5m])) > 0.85
for: 5m
labels:
severity: warning
annotations:
summary: "Node {{ $labels.node }} CPU > 85%"
description: "CPU usage on node {{ $labels.node }} has exceeded 85% for 5 minutes."
- alert: NodeHighMemory
expr: (node_memory_MemTotal_bytes - node_memory_MemAvailable_bytes) / node_memory_MemTotal_bytes > 0.85
for: 5m
labels:
severity: warning
annotations:
summary: "Node {{ $labels.instance }} memory > 85%"
description: "Memory usage on {{ $labels.instance }} has exceeded 85% for 5 minutes."
- alert: NodeDiskPressure
expr: kube_node_status_condition{condition="DiskPressure",status="true"} == 1
for: 2m
labels:
severity: warning
annotations:
summary: "Node {{ $labels.node }} disk pressure"
description: "Node {{ $labels.node }} has been under disk pressure for more than 2 minutes."
- alert: PodCrashLooping
expr: increase(kube_pod_container_status_restarts_total[1h]) > 5
for: 0m
labels:
severity: critical
annotations:
summary: "Pod {{ $labels.namespace }}/{{ $labels.pod }} is crash looping"
description: "Container {{ $labels.container }} in pod {{ $labels.namespace }}/{{ $labels.pod }} restarted more than 5 times in the last hour."
- alert: PodNotReady
expr: |
kube_pod_status_ready{condition="false"} == 1
and on(namespace, pod)
kube_pod_status_phase{phase=~"Running|Pending"} == 1
for: 5m
labels:
severity: warning
annotations:
summary: "Pod {{ $labels.namespace }}/{{ $labels.pod }} not ready"
description: "Pod {{ $labels.namespace }}/{{ $labels.pod }} has been in a non-ready state for more than 5 minutes."
- alert: DeploymentReplicasMismatch
expr: kube_deployment_spec_replicas != kube_deployment_status_available_replicas
for: 5m
labels:
severity: warning
annotations:
summary: "Deployment {{ $labels.namespace }}/{{ $labels.deployment }} replica mismatch"
description: "Deployment {{ $labels.namespace }}/{{ $labels.deployment }} has fewer available replicas than desired for 5 minutes."
- alert: PVCFillingUp
expr: kubelet_volume_stats_used_bytes / kubelet_volume_stats_capacity_bytes > 0.85
for: 5m
labels:
severity: warning
annotations:
summary: "PVC {{ $labels.namespace }}/{{ $labels.persistentvolumeclaim }} > 85%"
description: "PVC {{ $labels.namespace }}/{{ $labels.persistentvolumeclaim }} is using more than 85% of its capacity."
@@ -0,0 +1,174 @@
{{- define "alertmanager.args" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $app := $Values.alertmanager -}}
{{- $args := dict -}}
{{- $_ := set $args "config.file" "/config/alertmanager.yaml" -}}
{{- $_ := set $args "storage.path" (ternary $app.persistentVolume.mountPath "/data" $app.persistentVolume.enabled) -}}
{{- $_ := set $args "data.retention" $app.retention -}}
{{- $_ := set $args "web.listen-address" $app.listenAddress -}}
{{- $_ := set $args "cluster.advertise-address" "[$(POD_IP)]:6783" -}}
{{- with $app.baseURL -}}
{{- $_ := set $args "web.external-url" . -}}
{{- end -}}
{{ with $app.baseURLPrefix }}
{{- $_ := set $args "web.route-prefix" . -}}
{{- end -}}
{{- $replicaCount := $app.replicaCount | default 1 | int }}
{{- if gt $replicaCount 1 }}
{{- $_ := set $args "cluster.listen-address" $app.cluster.listenAddress -}}
{{- $port := include "vm.port.from.flag" (dict "flag" $app.cluster.listenAddress "default" "9094") -}}
{{- $_ := set $args "cluster.advertise-address" (printf "[$(POD_IP)]:%s" $port) -}}
{{- with $app.cluster.pushPullInterval -}}
{{- $_ := set $args "cluster.pushpull-interval" . -}}
{{- end -}}
{{- with $app.cluster.gossipInterval -}}
{{- $_ := set $args "cluster.gossip-interval" . -}}
{{- end -}}
{{- with $app.cluster.peerTimeout -}}
{{- $_ := set $args "cluster.peer-timeout" . -}}
{{- end -}}
{{- with $app.cluster.settleTimeout -}}
{{- $_ := set $args "cluster.settle-timeout" . -}}
{{- end -}}
{{- $ctx := . -}}
{{- if not (hasKey . "helm") -}}
{{- $ctx = dict "helm" . }}
{{- end -}}
{{- $_ := set $ctx "appKey" "alertmanager" -}}
{{- $_ := set $ctx "style" "plain" -}}
{{- $fullname := include "vm.plain.fullname" $ctx -}}
{{- $alertmanager := deepCopy $app }}
{{- $_ := set $alertmanager "fullnameOverride" (printf "%s-headless" $fullname) }}
{{- $_ := set $ctx "headless" (dict "alertmanager" $alertmanager) }}
{{- $_ := set $ctx "appKey" (list "headless" "alertmanager") }}
{{- $port := include "vm.port.from.flag" (dict "flag" $app.cluster.listenAddress "default" "9094") -}}
{{- $peers := list }}
{{- range $idx := (until (int $replicaCount)) }}
{{- $_ := set $ctx "appIdx" $idx }}
{{- $peers = append $peers (printf "%s:%s" (include "vm.fqdn" $ctx) $port) -}}
{{- end }}
{{- $_ := unset $ctx "appIdx" }}
{{- $_ := set $args "cluster.peer" $peers }}
{{- end }}
{{- $args = mergeOverwrite $args $app.extraArgs -}}
{{- toYaml (fromYaml (include "vm.args" $args)).args -}}
{{- end -}}
{{- define "vmalert.fromLegacyArgs" -}}
{{- $result := omit . "basicAuth" "bearer" }}
{{- with .basicAuth }}
{{- with .username }}
{{- $_ := set $result "basicAuth.username" . }}
{{- end }}
{{- with .password }}
{{- $_ := set $result "basicAuth.password" . }}
{{- end }}
{{- end -}}
{{- with .bearer -}}
{{- with .token }}
{{- $_ := set $result "bearerToken" . -}}
{{- end -}}
{{- with .tokenFile -}}
{{- $_ := set $result "bearerTokenFile" . -}}
{{- end -}}
{{- end }}
{{- toYaml $result }}
{{- end -}}
{{- define "vmalert.subargs" }}
{{- $args := .args }}
{{- range $k, $vs := (omit . "args") }}
{{- range $i, $v := $vs }}
{{- with $v }}
{{- if not .url -}}
{{- fail (printf "`url` is not set for `%s` idx %d" $k $i) -}}
{{- end -}}
{{- range $vKey, $vValue := . -}}
{{- if $vValue }}
{{- $key := printf "%s.%s" $k $vKey -}}
{{- $param := index $args $key | default list -}}
{{- range until (int (sub $i (len $param))) }}
{{- $param = append $param "" }}
{{- end }}
{{- if kindIs "map" $vValue }}
{{- $values := list }}
{{- range $mk, $mvs := $vValue }}
{{- $mv := ternary (join "," $mvs | quote) $mvs (kindIs "slice" $mvs) }}
{{- $values = append $values (printf "%s:%s" $mk $mv) }}
{{- end }}
{{- $param = append $param (join "^^" $values | squote) }}
{{- else -}}
{{- $param = append $param $vValue }}
{{- end }}
{{- $_ := set $args $key $param -}}
{{- end }}
{{- end -}}
{{- end -}}
{{- end -}}
{{- end }}
{{- end }}
{{- define "vmalert.args" -}}
{{- $ctx := . }}
{{- $Values := (.helm).Values | default .Values -}}
{{- $app := $Values.server -}}
{{- $datasource := list (include "vmalert.fromLegacyArgs" $app.datasource | fromYaml) -}}
{{- $remoteWrite := list (mergeOverwrite (deepCopy ($app.remoteWrite | default dict)) (include "vmalert.fromLegacyArgs" ($app.remote).write | fromYaml)) -}}
{{- $remoteRead := list (mergeOverwrite (deepCopy ($app.remoteRead | default dict)) (include "vmalert.fromLegacyArgs" ($app.remote).read | fromYaml)) -}}
{{- $notifiers := list }}
{{- range $rawNotifier := ($app.notifiers | default list) }}
{{- $notifier := mergeOverwrite (deepCopy (omit ($rawNotifier | default dict) "alertmanager")) (include "vmalert.fromLegacyArgs" ($rawNotifier).alertmanager | fromYaml) }}
{{- $notifiers = append $notifiers $notifier }}
{{- end }}
{{- $notifier := mergeOverwrite (deepCopy (omit ($app.notifier | default dict) "alertmanager")) (include "vmalert.fromLegacyArgs" ($app.notifier).alertmanager | fromYaml) }}
{{- if $notifier.url }}
{{- if kindIs "slice" $notifier.url }}
{{- $urls := $notifier.url }}
{{- range $urls }}
{{- $_ := set $notifier "url" . }}
{{- $notifiers = append $notifiers $notifier }}
{{- end }}
{{- else }}
{{- $notifiers = append $notifiers $notifier }}
{{- end }}
{{- else if $Values.alertmanager.enabled }}
{{- $alertmanager := deepCopy $Values.alertmanager }}
{{- $_ := set $ctx "style" "plain" -}}
{{- $_ := set $ctx "appKey" "alertmanager" -}}
{{- $appSecure := not (empty ($alertmanager.webConfig).tls_server_config) -}}
{{- $_ := set $ctx "appSecure" $appSecure -}}
{{- $_ := set $ctx "appRoute" $alertmanager.baseURLPrefix -}}
{{- if gt (int ($alertmanager.replicaCount | default 1)) 1 }}
{{- $fullname := include "vm.plain.fullname" $ctx -}}
{{- $_ := set $alertmanager "fullnameOverride" (printf "%s-headless" $fullname) }}
{{- $_ := set $ctx "headless" (dict "alertmanager" $alertmanager) }}
{{- $_ := set $ctx "appKey" (list "headless" "alertmanager") }}
{{- range $idx := (until (int $alertmanager.replicaCount)) }}
{{- $_ := set $ctx "appIdx" $idx }}
{{- $_ := set $notifier "url" (include "vm.url" $ctx) -}}
{{- $notifiers = append $notifiers $notifier }}
{{- end }}
{{- $_ := unset $ctx "appIdx" }}
{{- else }}
{{- $_ := set $notifier "url" (include "vm.url" $ctx) -}}
{{- $notifiers = append $notifiers $notifier }}
{{- end }}
{{- end }}
{{- $args := dict }}
{{- include "vmalert.subargs" (dict "args" $args "datasource" $datasource "remoteWrite" $remoteWrite "remoteRead" $remoteRead "notifier" $notifiers) }}
{{- $args = mergeOverwrite $args (fromYaml (include "vm.license.flag" .)) -}}
{{- $args = mergeOverwrite $args $app.extraArgs -}}
{{- toYaml (fromYaml (include "vm.args" $args)).args -}}
{{- end -}}
{{- define "vmalert.rules.config.name" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $fullname := include "vm.plain.fullname" . -}}
{{- $Values.server.configMap | default (printf "%s-alert-rules-config" $fullname) -}}
{{- end -}}
{{- define "alertmanager.config.name" -}}
{{- $Values := (.helm).Values | default .Values -}}
{{- $fullname := include "vm.plain.fullname" . -}}
{{- $Values.alertmanager.configMap | default (printf "%s-config" $fullname) -}}
{{- end -}}
@@ -0,0 +1,14 @@
{{- $app := .Values.server }}
{{- if empty $app.configMap }}
{{- $ctx := dict "helm" . "appKey" "server" }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ include "vmalert.rules.config.name" $ctx }}
namespace: {{ $ns }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
data:
alert-rules.yaml: |{{ toYaml $app.config.alerts | nindent 4 }}
{{- end }}
@@ -0,0 +1,42 @@
{{- $app := .Values.server }}
{{- $ingress := $app.ingress }}
{{- if $ingress.enabled }}
{{- $ctx := dict "helm" . "appKey" "server" }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
{{- with $ingress.annotations }}
annotations: {{ toYaml .| nindent 4 }}
{{- end }}
{{- $_ := set $ctx "extraLabels" $ingress.extraLabels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
name: {{ $fullname }}
namespace: {{ $ns }}
spec:
{{- with $ingress.ingressClassName }}
ingressClassName: {{ . }}
{{- end }}
{{- with $ingress.tls }}
tls: {{ tpl (toYaml .) $ | nindent 4 }}
{{- end }}
rules:
{{- range $host := $ingress.hosts }}
{{- $paths := ternary (list $host.path) $host.path (kindIs "string" $host.path) }}
- host: {{ tpl $host.name $ | quote }}
http:
paths:
{{- range $path := $paths }}
- path: {{ $path }}
{{- with $ingress.pathType }}
pathType: {{ . }}
{{- end }}
backend:
service:
name: {{ $fullname }}
port: {{ include "vm.ingress.port" $host | nindent 18 }}
{{- end }}
{{- end }}
{{- end }}
@@ -0,0 +1,27 @@
{{- $app := .Values.server }}
{{- $pdb := $app.podDisruptionBudget }}
{{- if $pdb.enabled }}
{{- $ctx := dict "helm" . "appKey" "server" }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
apiVersion: policy/v1
kind: PodDisruptionBudget
metadata:
name: {{ $fullname }}
namespace: {{ $ns }}
{{- $_ := set $ctx "extraLabels" $pdb.labels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
spec:
{{- with $pdb.minAvailable }}
minAvailable: {{ . }}
{{- end }}
{{- with $pdb.maxUnavailable }}
maxUnavailable: {{ . }}
{{- end }}
{{- with $pdb.unhealthyPodEvictionPolicy }}
unhealthyPodEvictionPolicy: {{ . }}
{{- end }}
selector:
matchLabels: {{ include "vm.selectorLabels" $ctx | nindent 6 }}
{{- end }}
@@ -0,0 +1,43 @@
{{- $app := .Values.server }}
{{- $route := $app.route }}
{{- if $route.enabled }}
{{- $ctx := dict "helm" . "appKey" "server" }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
---
apiVersion: {{ $route.apiVersion | default "gateway.networking.k8s.io/v1" }}
kind: {{ $route.kind | default "HTTPRoute" }}
metadata:
name: {{ $fullname }}
namespace: {{ $ns }}
{{- $_ := set $ctx "extraLabels" $app.route.extraLabels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
{{- with $route.annotations }}
annotations: {{ tpl (toYaml .) $ | nindent 4 }}
{{- end }}
spec:
{{- with $route.parentRefs }}
parentRefs: {{ toYaml . | nindent 4 }}
{{- end }}
{{- with $route.hostnames }}
hostnames: {{ tpl (toYaml .) $ | nindent 4 }}
{{- end }}
rules:
{{- with $route.extraRules }}
{{- tpl (toYaml .) $ | nindent 4 }}
{{- end }}
- backendRefs:
- name: {{ $fullname }}
port: {{ $route.port | default (include "vm.port.from.flag" (dict "flag" ($app.extraArgs).httpListenAddr)) }}
group: ''
kind: Service
weight: 1
{{- with $route.filters }}
filters: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $route.matches }}
matches: {{ tpl (toYaml .) $ | nindent 8 }}
{{- end }}
{{- end }}
@@ -0,0 +1,139 @@
{{- $app := .Values.server }}
{{- if not $app.extraArgs.rule }}
{{- if and (empty $app.configMap) (empty $app.config.alerts.groups) -}}
{{- fail "at least one item in `.server.config.alerts.groups` or `.server.extraArgs.rule` must be set " -}}
{{- end -}}
{{- end -}}
{{- if empty $app.datasource.url -}}
{{- fail "server.datasource.url datasource URL must be specified" -}}
{{- end }}
{{- $ctx := dict "helm" . "appKey" "server" }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
{{- $sa := include "vm.fullname" . }}
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ $fullname }}
namespace: {{ $ns }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- with $app.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
spec:
minReadySeconds: {{ $app.minReadySeconds }}
replicas: {{ $app.replicaCount }}
selector:
matchLabels: {{ include "vm.selectorLabels" $ctx | nindent 6 }}
{{- with $app.strategy }}
strategy: {{ toYaml . | nindent 4 }}
{{- end }}
template:
metadata:
{{- $_ := set $ctx "extraLabels" $app.podLabels }}
labels: {{ include "vm.podLabels" $ctx | nindent 8 }}
{{- $_ := unset $ctx "extraLabels" }}
{{- $annotations := dict "checksum/config" (include (print .Template.BasePath "/alert-configmap.yaml") . | sha256sum) }}
{{- $annotations = merge $annotations $app.podAnnotations }}
annotations: {{ toYaml $annotations | nindent 8 }}
spec:
{{- if or (.Values.serviceAccount).name (.Values.serviceAccount).create }}
serviceAccountName: {{ tpl ((.Values.serviceAccount).name | default $sa) $ctx }}
automountServiceAccountToken: {{ .Values.serviceAccount.automountToken }}
{{- end }}
{{- if $app.podSecurityContext.enabled }}
securityContext: {{ include "vm.securityContext" (dict "securityContext" $app.podSecurityContext "helm" .) | nindent 8 }}
{{- end }}
{{- with ($app.imagePullSecrets | default .Values.global.imagePullSecrets) }}
imagePullSecrets: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $app.initContainers }}
initContainers: {{ toYaml . | nindent 8 }}
{{- end }}
containers:
- name: vmalert
{{- if $app.securityContext.enabled }}
securityContext: {{ include "vm.securityContext" (dict "securityContext" $app.securityContext "helm" .) | nindent 12 }}
{{- end }}
image: {{ include "vm.image" $ctx }}
args: {{ include "vmalert.args" $ctx | nindent 12 }}
imagePullPolicy: {{ $app.image.pullPolicy }}
{{- with $app.envFrom }}
envFrom: {{ toYaml . | nindent 12 }}
{{- end }}
{{- with $app.env }}
env: {{ toYaml . | nindent 12 }}
{{- end }}
ports:
- name: http
containerPort: {{ include "vm.port.from.flag" (dict "flag" $app.extraArgs.httpListenAddr "default" "8880") }}
{{- with (fromYaml (include "vm.probe" (dict "app" $app "type" "readiness"))) }}
readinessProbe: {{ toYaml . | nindent 12 }}
{{- end }}
{{- with (fromYaml (include "vm.probe" (dict "app" $app "type" "liveness"))) }}
livenessProbe: {{ toYaml . | nindent 12 }}
{{- end }}
{{- with (fromYaml (include "vm.probe" (dict "app" $app "type" "startup"))) }}
startupProbe: {{ toYaml . | nindent 12 }}
{{- end }}
volumeMounts:
- name: alerts-config
mountPath: /config
{{- range $app.extraHostPathMounts }}
- name: {{ .name }}
mountPath: {{ .mountPath }}
{{- with .subPath }}
subPath: {{ . }}
{{- end }}
{{- with .readOnly }}
readOnly: {{ . }}
{{- end }}
{{- end }}
{{- range $app.extraVolumeMounts }}
- name: {{ .name }}
{{- toYaml (omit . "name") | nindent 14 }}
{{- end }}
{{- include "vm.license.mount" . | nindent 12 }}
{{- with $app.resources }}
resources: {{ toYaml . | nindent 12 }}
{{- end }}
{{- with $app.extraContainers }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with $app.nodeSelector }}
nodeSelector: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $app.priorityClassName }}
priorityClassName: {{ . }}
{{- end }}
{{- with $app.affinity }}
affinity: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $app.topologySpreadConstraints }}
topologySpreadConstraints:
{{- range $constraint := . }}
- {{ toYaml $constraint | nindent 10 | trim }}
{{- if not $constraint.labelSelector }}
labelSelector:
matchLabels: {{ include "vm.selectorLabels" $ctx | nindent 14 }}
{{- end }}
{{- end }}
{{- end }}
{{- with $app.tolerations }}
tolerations: {{ toYaml . | nindent 8 }}
{{- end }}
{{- $_ := set $ctx "appKey" "server" }}
volumes:
- name: alerts-config
configMap:
name: {{ include "vmalert.rules.config.name" $ctx }}
{{- range $app.extraHostPathMounts }}
- name: {{ .name }}
hostPath:
path: {{ .hostPath }}
{{- end }}
{{- range $app.extraVolumes }}
- name: {{ .name }}
{{- toYaml (omit . "name") | nindent 10 }}
{{- end }}
{{- include "vm.license.volume" . | nindent 8 }}
@@ -0,0 +1,54 @@
{{- $app := .Values.server }}
{{- $service := $app.service }}
{{- $ctx := dict "helm" . "appKey" "server" }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
apiVersion: v1
kind: Service
metadata:
namespace: {{ $ns }}
{{- with $service.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
{{- $_ := set $ctx "extraLabels" $app.service.labels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
name: {{ $fullname }}
spec:
{{- with $service.trafficDistribution }}
trafficDistribution: {{ . }}
{{- end }}
{{- with $service.clusterIP }}
clusterIP: {{ . }}
{{- end }}
{{- with $service.externalIPs }}
externalIPs: {{ toYaml . | nindent 4 }}
{{- end }}
{{- with $service.loadBalancerIP }}
loadBalancerIP: {{ . }}
{{- end }}
{{- with $service.loadBalancerSourceRanges }}
loadBalancerSourceRanges: {{ toYaml . | nindent 4 }}
{{- end }}
type: {{ $service.type }}
{{- with $service.healthCheckNodePort }}
healthCheckNodePort: {{ . }}
{{- end }}
{{- with $service.externalTrafficPolicy }}
externalTrafficPolicy: {{ . }}
{{- end }}
{{- with $service.ipFamilyPolicy }}
ipFamilyPolicy: {{ . }}
{{- end }}
{{- with $service.ipFamilies }}
ipFamilies: {{ toYaml . | nindent 4 }}
{{- end }}
ports:
- name: http
port: {{ $service.servicePort }}
targetPort: http
protocol: TCP
{{- with $service.nodePort }}
nodePort: {{ . }}
{{- end }}
selector: {{ include "vm.selectorLabels" $ctx | nindent 4 }}
@@ -0,0 +1,20 @@
{{- $app := .Values.alertmanager }}
{{- if and $app.enabled (empty $app.configMap) }}
{{- $ctx := dict "helm" . "appKey" "alertmanager" }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ include "alertmanager.config.name" $ctx }}
namespace: {{ $ns }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
data:
alertmanager.yaml: |{{ toYaml $app.config | nindent 4 }}
{{- range $key, $value := $app.templates }}
{{ $key }}: |{{ $value | nindent 4 }}
{{- end }}
{{- with $app.webconfig }}
webconfig.yaml: |{{ toYaml . | nindent 4 }}
{{- end }}
{{- end }}
@@ -0,0 +1,42 @@
{{- $app := .Values.alertmanager }}
{{- $ingress := $app.ingress }}
{{- if and $app.enabled $ingress.enabled }}
{{- $ctx := dict "helm" . "appKey" "alertmanager" }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
{{- with $ingress.annotations }}
annotations: {{ toYaml .| nindent 4 }}
{{- end }}
{{- $_ := set $ctx "extraLabels" $app.ingress.extraLabels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
name: {{ $fullname }}
namespace: {{ $ns }}
spec:
{{- with $ingress.ingressClassName }}
ingressClassName: {{ . }}
{{- end }}
{{- with $ingress.tls }}
tls: {{ tpl (toYaml .) $ | nindent 4 }}
{{- end }}
rules:
{{- range $host := $ingress.hosts }}
{{- $paths := ternary (list $host.path) $host.path (kindIs "string" $host.path) }}
- host: {{ tpl $host.name $ | quote }}
http:
paths:
{{- range $path := $paths }}
- path: {{ $path }}
{{- with $ingress.pathType }}
pathType: {{ . }}
{{- end }}
backend:
service:
name: {{ $fullname }}
port: {{ include "vm.ingress.port" $host | nindent 18 }}
{{- end }}
{{- end }}
{{- end }}
@@ -0,0 +1,35 @@
{{- $app := .Values.alertmanager }}
{{- $pvc := $app.persistentVolume }}
{{- if and $pvc.enabled (not $pvc.existingClaim) (eq $app.mode "deployment") -}}
{{- $ctx := dict "helm" . "appKey" "alertmanager" }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: {{ tpl ($pvc.name | default $fullname) $ctx }}
namespace: {{ $ns }}
{{- $_ := set $ctx "extraLabels" $pvc.extraLabels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
{{- with $pvc.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
spec:
{{- with $pvc.accessModes }}
accessModes: {{ toYaml . | nindent 4 }}
{{- end }}
{{- with $pvc.volumeAttributeClassName }}
volumeAttributesClassName: {{ . }}
{{- end }}
resources:
requests:
storage: {{ $pvc.size }}
{{- with $pvc.storageClassName }}
storageClassName: {{ . }}
{{- end }}
{{- with $pvc.matchLabels }}
selector:
matchLabels: {{ toYaml . | nindent 6 }}
{{- end }}
{{- end }}
@@ -0,0 +1,43 @@
{{- $app := .Values.alertmanager }}
{{- $route := $app.route }}
{{- if $route.enabled }}
{{- $ctx := dict "helm" . "appKey" "alertmanager" }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
---
apiVersion: {{ $route.apiVersion | default "gateway.networking.k8s.io/v1" }}
kind: {{ $route.kind | default "HTTPRoute" }}
metadata:
name: {{ $fullname }}
namespace: {{ $ns }}
{{- $_ := set $ctx "extraLabels" $app.route.extraLabels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
{{- with $route.annotations }}
annotations: {{ tpl (toYaml .) $ | nindent 4 }}
{{- end }}
spec:
{{- with $route.parentRefs }}
parentRefs: {{ toYaml . | nindent 4 }}
{{- end }}
{{- with $route.hostnames }}
hostnames: {{ tpl (toYaml .) $ | nindent 4 }}
{{- end }}
rules:
{{- with $route.extraRules }}
{{- tpl (toYaml .) $ | nindent 4 }}
{{- end }}
- backendRefs:
- name: {{ $fullname }}
port: {{ $route.port | default $app.service.port }}
group: ''
kind: Service
weight: 1
{{- with $route.filters }}
filters: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $route.matches }}
matches: {{ tpl (toYaml .) $ | nindent 8 }}
{{- end }}
{{- end }}
@@ -0,0 +1,184 @@
{{- $storageName := "server-volume" }}
{{- $app := .Values.alertmanager }}
{{- $pvc := $app.persistentVolume }}
{{- $mode := $app.mode }}
{{- if and $mode $app.enabled (hasKey $app $mode) -}}
{{- $modeOpts := index $app $mode }}
{{- $ctx := dict "helm" . "appKey" "alertmanager" }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
{{- $sa := include "vm.fullname" . }}
{{- if and (ne $mode "statefulSet") (gt (int $app.replicaCount) 1) }}
{{- fail "Alertmanager HA mode is not supported for Deployment. Consider switching to statefulset instead using `alertmanager.mode: statefulSet`" -}}
{{- end }}
apiVersion: apps/v1
kind: {{ title $mode }}
metadata:
name: {{ $fullname }}
namespace: {{ $ns }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
spec:
{{- with $modeOpts.spec }}
{{- toYaml . | nindent 2 }}
{{- end }}
replicas: {{ $app.replicaCount | default 1 }}
{{- if eq $mode "statefulSet" }}
serviceName: {{ $fullname }}
{{- end }}
selector:
matchLabels: {{ include "vm.selectorLabels" $ctx | nindent 6 }}
template:
metadata:
{{- $_ := set $ctx "extraLabels" $app.podLabels }}
labels: {{ include "vm.podLabels" $ctx | nindent 8 }}
{{- $_ := unset $ctx "extraLabels" }}
{{- $annotations := dict "checksum/config" (include (print .Template.BasePath "/alertmanager-configmap.yaml") . | sha256sum) }}
{{- $annotations = merge $annotations (deepCopy $app.podAnnotations) }}
annotations: {{ toYaml $annotations | nindent 8 }}
spec:
{{- if or (.Values.serviceAccount).name (.Values.serviceAccount).create }}
serviceAccountName: {{ tpl ((.Values.serviceAccount).name | default $sa) $ctx }}
automountServiceAccountToken: {{ .Values.serviceAccount.automountToken }}
{{- end }}
{{- if $app.podSecurityContext.enabled }}
securityContext: {{ include "vm.securityContext" (dict "securityContext" $app.podSecurityContext "helm" .) | nindent 8 }}
{{- end }}
{{- with ($app.imagePullSecrets | default .Values.global.imagePullSecrets) }}
imagePullSecrets: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $app.initContainers }}
initContainers: {{ toYaml . | nindent 8 }}
{{- end }}
containers:
- name: alertmanager
{{- if $app.securityContext.enabled }}
securityContext: {{ include "vm.securityContext" (dict "securityContext" $app.securityContext "helm" .) | nindent 12 }}
{{- end }}
image: {{ include "vm.image" $ctx }}
args: {{ include "alertmanager.args" $ctx | nindent 12 }}
ports:
- name: web
containerPort: {{ include "vm.port.from.flag" (dict "flag" $app.listenAddress "default" "9093") }}
{{- if gt (int $app.replicaCount) 1 }}
- name: cluster-tcp
containerPort: {{ include "vm.port.from.flag" (dict "flag" $app.cluster.listenAddress "default" "9094") }}
protocol: TCP
- name: cluster-udp
containerPort: {{ include "vm.port.from.flag" (dict "flag" $app.cluster.listenAddress "default" "9094") }}
protocol: UDP
{{- end }}
{{- with $app.envFrom }}
envFrom: {{ toYaml . | nindent 12 }}
{{- end }}
env:
- name: POD_IP
valueFrom:
fieldRef:
apiVersion: v1
fieldPath: status.podIP
{{- with (fromYaml (include "vm.probe" (dict "app" $app "type" "readiness"))) }}
readinessProbe: {{ toYaml . | nindent 12 }}
{{- end }}
{{- with (fromYaml (include "vm.probe" (dict "app" $app "type" "liveness"))) }}
livenessProbe: {{ toYaml . | nindent 12 }}
{{- end }}
{{- with (fromYaml (include "vm.probe" (dict "app" $app "type" "startup"))) }}
startupProbe: {{ toYaml . | nindent 12 }}
{{- end }}
volumeMounts:
- name: {{ $storageName }}
mountPath: {{ ternary $pvc.mountPath "/data" $pvc.enabled }}
- name: config
mountPath: /config
readOnly: true
{{- range $app.extraHostPathMounts }}
- name: {{ .name }}
mountPath: {{ .mountPath }}
{{- with .subPath }}
subPath: {{ . }}
{{- end }}
{{- with .readOnly }}
readOnly: {{ . }}
{{- end }}
{{- end }}
{{- with $app.extraVolumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with $app.resources }}
resources: {{ toYaml . | nindent 12 }}
{{- end }}
{{- with $app.extraContainers }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with $app.nodeSelector }}
nodeSelector: {{ toYaml . | nindent 8 }}
{{- end }}
{{- if $app.priorityClassName }}
priorityClassName: {{ $app.priorityClassName | quote }}
{{- end }}
{{- with $app.affinity }}
affinity: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $app.topologySpreadConstraints }}
topologySpreadConstraints:
{{- range $constraint := . }}
- {{ toYaml $constraint | nindent 10 | trim }}
{{- if not $constraint.labelSelector }}
labelSelector:
matchLabels: {{ include "vm.selectorLabels" $ctx | nindent 14 }}
{{- end }}
{{- end }}
{{- end }}
{{- with $app.tolerations }}
tolerations: {{ toYaml . | nindent 8 }}
{{ end }}
volumes:
{{- $_ := set $ctx "appKey" "alertmanager" }}
- name: config
configMap:
name: {{ include "alertmanager.config.name" $ctx }}
{{- range $app.extraHostPathMounts }}
- name: {{ .name }}
hostPath:
path: {{ .hostPath }}
{{- end }}
{{- with $app.extraVolumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if or (eq $mode "deployment") (not $pvc.enabled) $pvc.existingClaim }}
- name: {{ $storageName }}
{{- if or (and (eq $mode "deployment") $pvc.enabled) $pvc.existingClaim }}
persistentVolumeClaim:
claimName: {{ tpl ($pvc.existingClaim | default $pvc.name | default $fullname) $ctx }}
{{- else }}
emptyDir: {{ toYaml $app.emptyDir | nindent 12 }}
{{- end }}
{{- end }}
{{- if and (eq $mode "statefulSet") $pvc.enabled (not $pvc.existingClaim) }}
volumeClaimTemplates:
- apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: {{ tpl ($pvc.name | default $storageName) $ctx }}
{{- with $pvc.annotations }}
annotations: {{ toYaml . | nindent 10 }}
{{- end }}
{{- with $pvc.extraLabels }}
labels: {{ toYaml . | nindent 10 }}
{{- end }}
spec:
{{- with $pvc.accessModes }}
accessModes: {{ toYaml . | nindent 10 }}
{{- end }}
resources:
requests:
storage: {{ $pvc.size }}
{{- with $pvc.storageClassName }}
storageClassName: {{ ternary "" . (eq "-" .) }}
{{- end }}
{{- with $pvc.matchLabels }}
selector:
matchLabels: {{ toYaml . | nindent 12 }}
{{- end }}
{{- end }}
{{- end -}}
@@ -0,0 +1,87 @@
{{- $app := .Values.alertmanager }}
{{- $mode := $app.mode }}
{{- $service := $app.service }}
{{- $ctx := dict "helm" . "appKey" "alertmanager" }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
{{- if $app.enabled -}}
---
apiVersion: v1
kind: Service
metadata:
namespace: {{ $ns }}
{{- with $service.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
{{- $_ := set $ctx "extraLabels" $app.service.labels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
name: {{ $fullname }}
spec:
{{- with $service.trafficDistribution }}
trafficDistribution: {{ . }}
{{- end }}
type: {{ $service.type }}
{{- with $service.clusterIP }}
clusterIP: {{ . }}
{{- end }}
{{- with $service.externalIPs }}
externalIPs: {{ toYaml . | nindent 4 }}
{{- end }}
{{- with $service.loadBalancerIP }}
loadBalancerIP: {{ . }}
{{- end }}
{{- with $service.loadBalancerSourceRanges }}
loadBalancerSourceRanges: {{ toYaml . | nindent 4 }}
{{- end }}
{{- with $service.healthCheckNodePort }}
healthCheckNodePort: {{ . }}
{{- end }}
{{- with $service.externalTrafficPolicy }}
externalTrafficPolicy: {{ . }}
{{- end }}
{{- with $service.ipFamilyPolicy }}
ipFamilyPolicy: {{ . }}
{{- end }}
{{- with $service.ipFamilies }}
ipFamilies: {{ toYaml . | nindent 4 }}
{{- end }}
ports:
- name: web
port: {{ $service.servicePort }}
targetPort: web
protocol: TCP
selector: {{ include "vm.selectorLabels" $ctx | nindent 4 }}
{{- end }}
{{- if and (eq $mode "statefulSet") (gt (int $app.replicaCount) 1) }}
---
apiVersion: v1
kind: Service
metadata:
namespace: {{ $ns }}
{{- with $service.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
{{- $_ := set $ctx "extraLabels" $app.service.labels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
name: {{ $fullname }}-headless
spec:
clusterIP: None
ports:
- name: web
port: {{ $service.servicePort }}
targetPort: web
protocol: TCP
{{- if gt (int $app.replicaCount) 1 }}
- port: {{ include "vm.port.from.flag" (dict "flag" $app.cluster.listenAddress "default" "9094") }}
targetPort: cluster-tcp
protocol: TCP
name: cluster-tcp
- port: {{ include "vm.port.from.flag" (dict "flag" $app.cluster.listenAddress "default" "9094") }}
targetPort: cluster-udp
protocol: UDP
name: cluster-udp
{{- end }}
selector: {{ include "vm.selectorLabels" $ctx | nindent 4 }}
{{- end }}
@@ -0,0 +1,4 @@
{{ range .Values.extraObjects }}
---
{{ tpl (ternary . (toYaml .) (typeIs "string" .)) $ }}
{{ end }}
@@ -0,0 +1,48 @@
{{- if .Values.serviceMonitor.enabled -}}
{{- $serviceMonitor := .Values.serviceMonitor -}}
{{- $ctx := dict "helm" . "appKey" "server" }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
apiVersion: monitoring.coreos.com/v1
kind: ServiceMonitor
metadata:
{{- with $serviceMonitor.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
{{- $_ := set $ctx "extraLabels" $serviceMonitor.extraLabels }}
labels: {{ include "vm.labels" $ctx | nindent 4 }}
{{- $_ := unset $ctx "extraLabels" }}
name: {{ $fullname }}
{{- with $serviceMonitor.namespace }}
namespace: {{ . }}
{{- end }}
spec:
namespaceSelector:
matchNames:
- {{ $ns }}
selector:
matchLabels: {{ include "vm.commonLabels" $ctx | nindent 6 }}
endpoints:
- port: http
{{- with $serviceMonitor.basicAuth }}
basicAuth: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $serviceMonitor.scheme }}
scheme: {{ . }}
{{- end }}
{{- with $serviceMonitor.interval }}
interval: {{ . }}
{{- end }}
{{- with $serviceMonitor.scrapeTimeout }}
scrapeTimeout: {{ . }}
{{- end }}
{{- with $serviceMonitor.tlsConfig }}
tlsConfig: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $serviceMonitor.relabelings }}
relabelings: {{ toYaml . | nindent 8 }}
{{- end }}
{{- with $serviceMonitor.metricRelabelings }}
metricRelabelings: {{ toYaml . | nindent 8 }}
{{- end }}
{{- end }}
@@ -0,0 +1,14 @@
{{- if .Values.serviceAccount.create -}}
{{- $ctx := dict "helm" . }}
{{- $fullname := include "vm.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
apiVersion: v1
kind: ServiceAccount
metadata:
name: {{ tpl ((.Values.serviceAccount).name | default $fullname) $ctx }}
namespace: {{ $ns }}
labels: {{ include "vm.metaLabels" $ctx | nindent 4 }}
{{- with .Values.serviceAccount.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
{{- end -}}
@@ -0,0 +1,25 @@
{{- $vpa := .Values.server.verticalPodAutoscaler }}
{{- if and (.Capabilities.APIVersions.Has "autoscaling.k8s.io/v1") $vpa.enabled }}
{{- $ctx := dict "helm" . "appKey" "server" }}
{{- $fullname := include "vm.plain.fullname" $ctx }}
{{- $ns := include "vm.namespace" $ctx }}
apiVersion: autoscaling.k8s.io/v1
kind: VerticalPodAutoscaler
metadata:
name: {{ $fullname }}
namespace: {{ $ns }}
spec:
{{- with $vpa.recommenders }}
recommenders: {{ toYaml . | nindent 4 }}
{{- end }}
targetRef:
apiVersion: apps/v1
kind: Deployment
name: {{ $fullname }}
{{- with $vpa.updatePolicy }}
updatePolicy: {{ toYaml . | nindent 4 }}
{{- end }}
{{- with $vpa.resourcePolicy }}
resourcePolicy: {{ toYaml . | nindent 4 }}
{{- end }}
{{- end }}
@@ -0,0 +1,673 @@
# Default values for victoria-metrics-alert.
# This is a YAML-formatted file.
# Declare variables to be passed into your templates.
global:
# -- Image pull secrets, that can be shared across multiple helm charts
imagePullSecrets: []
image:
# -- Image registry, that can be shared across multiple helm charts
registry: ""
# -- Openshift security context compatibility configuration
compatibility:
openshift:
adaptSecurityContext: "auto"
cluster:
# -- K8s cluster domain suffix, uses for building storage pods' FQDN. Details are [here](https://kubernetes.io/docs/tasks/administer-cluster/dns-custom-nameservers/)
dnsDomain: cluster.local.
serviceAccount:
# -- Specifies whether a service account should be created
create: true
# -- Annotations to add to the service account
annotations: {}
# -- The name of the service account to use.
# If not set and create is true, a name is generated using the fullname template
name:
# -- Mount API token to pod directly
automountToken: true
# -- Override chart name
nameOverride: ""
server:
# -- Override default `app` label name
name: ""
# -- VMAlert image configuration
image:
registry: ""
repository: victoriametrics/vmalert
tag: "" # rewrites Chart.AppVersion
# Variant of the image to use.
# e.g. enterprise, scratch
variant: ""
pullPolicy: IfNotPresent
# -- Override vmalert resources fullname
fullnameOverride: ""
# -- Image pull secrets
imagePullSecrets: []
# -- See `kubectl explain poddisruptionbudget.spec` for more. Or check [docs](https://kubernetes.io/docs/tasks/run-application/configure-pdb/)
podDisruptionBudget:
enabled: false
# -- min number or percentage of pods that can be unavailable
minAvailable: 0
# -- max number or percentage of pods that can be unavailable
maxUnavailable: 0
# -- Defines criteria when unhealthy pods should be considered for eviction
unhealthyPodEvictionPolicy:
labels: {}
# -- Additional environment variables (ex.: secret tokens, flags). Check [here](https://docs.victoriametrics.com/victoriametrics/#environment-variables) for details.
env:
[]
# - name: VM_remoteWrite_basicAuth_password
# valueFrom:
# secretKeyRef:
# name: auth_secret
# key: password
# -- Specify alternative source for env variables
envFrom:
[]
#- configMapRef:
# name: special-config
probe:
# -- Readiness probe
readiness:
httpGet: {}
initialDelaySeconds: 5
periodSeconds: 15
timeoutSeconds: 5
failureThreshold: 3
# -- Liveness probe
liveness:
tcpSocket: {}
initialDelaySeconds: 5
periodSeconds: 15
timeoutSeconds: 5
failureThreshold: 3
# -- Startup probe
startup: {}
# -- Replica count
replicaCount: 1
# -- Pod topologySpreadConstraints
topologySpreadConstraints: []
# - maxSkew: 1
# topologyKey: topology.kubernetes.io/zone
# whenUnsatisfiable: DoNotSchedule
# -- Deployment strategy, set to standard k8s default
strategy:
type: RollingUpdate
rollingUpdate:
maxSurge: 25%
maxUnavailable: 25%
# -- Specifies the minimum number of seconds for which a newly created Pod should be ready without any of its containers crashing/terminating
# 0 is the standard k8s default
minReadySeconds: 0
# -- VMAlert reads metrics from source, next section represents its configuration. It can be any service which supports
# MetricsQL or PromQL.
datasource:
url: ""
# -- Basic auth username for remote write
basicAuth.username: ""
# -- Basic auth password for remote write
basicAuth.password: ""
# -- Auth based on Bearer token for remote write
bearerToken: ""
# -- Auth based on Bearer token file path for remote write
bearerTokenFile: ""
# -- HTTP headers for remote write
headers: {}
# -- VMAlert remote write configuration
remoteWrite: {}
# url: ""
# basicAuth.username: ""
# basicAuth.password: ""
# bearerToken: ""
# bearerTokenFile: ""
# headers: {}
# -- VMAlert remote read configuration
remoteRead: {}
# url: ""
# basicAuth.username: ""
# basicAuth.password: ""
# bearerToken: ""
# bearerTokenFile: ""
# headers: {}
# -- Default VMAlertmanager notifier configuration.
notifier: {}
# url: ""
# basicAuth.username: ""
# basicAuth.password: ""
# bearerToken: ""
# bearerTokenFile: ""
# -- Additional notifiers to use for alerts
notifiers: []
# - url: ""
# basicAuth.username: ""
# basicAuth.password: ""
# bearerToken: ""
# bearerTokenFile: ""
# -- Extra command line arguments for container of component
extraArgs:
envflag.enable: true
envflag.prefix: VM_
loggerFormat: json
httpListenAddr: :8880
# Enable IPv6 support. Useful for running in IPv6-only Kubernetes clusters
# enableTCP6: true
rule:
- /config/alert-rules.yaml
# -- Additional hostPath mounts
extraHostPathMounts: []
# - name: certs-dir
# mountPath: /etc/kubernetes/certs
# subPath: ""
# hostPath: /etc/kubernetes/certs
# readOnly: true
# -- Extra Volumes for the pod
extraVolumes: []
# - name: example
# configMap:
# name: example
# -- Extra Volume Mounts for the container.
# Expects a lice of [volume mounts](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.26/#volumemount-v1-core)
extraVolumeMounts: []
# - name: example
# mountPath: /example
# subPath: ""
# -- Additional containers to run in the same pod
extraContainers:
[]
#- name: config-reloader
# image: reloader-image
service:
# -- Service traffic distribution. Details are [here](https://kubernetes.io/docs/concepts/services-networking/service/#traffic-distribution)
trafficDistribution: ""
# -- Service annotations
annotations: {}
# -- Service labels
labels: {}
# -- Service ClusterIP
clusterIP: "None"
# -- Service external IPs. Check [here](https://kubernetes.io/docs/concepts/services-networking/service/#external-ips) for details
externalIPs: []
# -- Service load balancer IP
loadBalancerIP: ""
# -- Load balancer source range
loadBalancerSourceRanges: []
# -- Service port
servicePort: 8880
# nodePort: 30000
# -- Service type
type: ClusterIP
# -- Service external traffic policy. Check [here](https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip) for details
externalTrafficPolicy: ""
# -- Health check node port for a service. Check [here](https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip) for details
healthCheckNodePort: ""
# -- Service IP family policy. Check [here](https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services) for details.
ipFamilyPolicy: ""
# -- List of service IP families. Check [here](https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services) for details.
ipFamilies: []
route:
# -- Enable deployment of HTTPRoute for VMAlert
enabled: false
# -- HTTPRoute annotations
annotations: {}
# -- HTTPRoute extra labels
extraLabels: {}
# -- HTTPGateway objects refs
parentRefs: []
# -- Array of hostnames
hostnames: []
# -- Extra rules to prepend to route. This is useful when working with annotation based services.
extraRules: []
# -- Filters for a default rule in HTTPRoute
filters: []
# -- Matches for a default rule in HTTPRoute
matches:
- path:
type: PathPrefix
value: /
ingress:
# -- Enable deployment of ingress for vmalert component
enabled: false
# -- Ingress annotations
annotations: {}
# kubernetes.io/ingress.class: nginx
# kubernetes.io/tls-acme: 'true'
# -- Ingress extra labels
extraLabels: {}
# -- Array of host objects
hosts:
- name: vmalert.local
path:
- /
port: http
# -- Array of TLS objects
tls: []
# - secretName: vmselect-ingress-tls
# hosts:
# - vmselect.local
# -- Ingress controller class name
ingressClassName: ""
# -- Ingress path type
pathType: Prefix
# -- Pod's security context. Details are [here](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/)
podSecurityContext:
enabled: true
# fsGroup: 2000
# -- Security context to be added to server pods
securityContext:
enabled: true
# capabilities:
# drop:
# - ALL
# readOnlyRootFilesystem: true
# runAsNonRoot: true
# runAsUser: 1000
# -- Resource object. Details are [here](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/)
resources:
{}
# We usually recommend not to specify default resources and to leave this as a conscious
# choice for the user. This also increases chances charts run on environments with little
# resources, such as Minikube. If you do want to specify resources, uncomment the following
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
# limits:
# cpu: 100m
# memory: 128Mi
# requests:
# cpu: 100m
# memory: 128Mi
# -- Annotations to be added to the deployment
annotations: {}
# -- Labels to be added to the deployment
labels: {}
# -- Annotations to be added to pod
podAnnotations: {}
# -- Pod's additional labels
podLabels: {}
# -- Pod's node selector. Details are [here](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
nodeSelector: {}
# -- Name of Priority Class
priorityClassName: ""
# -- Node tolerations for server scheduling to nodes with taints. Details are [here](https://kubernetes.io/docs/concepts/configuration/assign-pod-node/)
tolerations: []
# -- Pod affinity
affinity: {}
# -- VMAlert alert rules configuration.
# Use existing configmap if specified
configMap: ""
# -- VMAlert configuration
config:
alerts:
groups: []
# -- Vertical Pod Autoscaler
verticalPodAutoscaler:
# -- Use VPA for vmalert
enabled: false
# recommenders:
# - name: 'alternative'
# updatePolicy:
# updateMode: "Auto"
# minReplicas: 1
# resourcePolicy:
# containerPolicies:
# - containerName: '*'
# minAllowed:
# cpu: 100m
# memory: 128Mi
# maxAllowed:
# cpu: 1
# memory: 500Mi
# controlledResources: ["cpu", "memory"]
# -- Additional initContainers to initialize the pod
initContainers: []
serviceMonitor:
# -- Enable deployment of Service Monitor for server component. This is Prometheus operator object
enabled: false
# -- Service Monitor labels
extraLabels: {}
# -- Service Monitor annotations
annotations: {}
# -- Service Monitor relabelings
relabelings: []
# -- Basic auth params for Service Monitor
basicAuth: {}
# -- Service Monitor metricRelabelings
metricRelabelings: []
# interval: 15s
# scrapeTimeout: 5s
# -- Commented. HTTP scheme to use for scraping.
# scheme: https
# -- Commented. TLS configuration to use when scraping the endpoint
# tlsConfig:
# insecureSkipVerify: true
alertmanager:
# -- Create alertmanager resources
enabled: false
# -- Alertmanager Pod labels
podLabels: {}
# -- Override Alertmanager resources fullname
fullnameOverride: ""
# -- Alertmanager Pod annotations
podAnnotations: {}
# -- Alertmanager mode: deployment, statefulSet
mode: deployment
# -- [K8s Deployment](https://kubernetes.io/docs/concepts/workloads/controllers/deployment/) specific variables
deployment:
spec:
strategy:
type: Recreate
# -- [K8s StatefulSet](https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/) specific variables
statefulSet:
spec:
# -- Deploy order policy for StatefulSet pods
podManagementPolicy: OrderedReady
# -- StatefulSet update strategy. Check [here](https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#update-strategies) for details.
updateStrategy: {}
# type: RollingUpdate
# -- Alertmanager image configuration
image:
registry: ""
repository: prom/alertmanager
tag: v0.32.1
# -- Alertmanager retention
retention: 120h
# -- Replica count
replicaCount: 1
# -- Cluster configuration for alertmanager
cluster:
# -- Cluster listen address
listenAddress: "0.0.0.0:9094"
# -- Cluster push/pull interval
pushPullInterval: 60s
# -- Cluster gossip interval
gossipInterval: 200ms
# -- Cluster peer timeout
peerTimeout: 15s
# -- Cluster settle timeout
settleTimeout: 1m
# -- Pod's node selector. Details are [here](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
nodeSelector: {}
# -- Name of Priority Class
priorityClassName: ""
# -- Resource object. Details are [here](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/)
resources: {}
# -- Node tolerations for server scheduling to nodes with taints. Details are [here](https://kubernetes.io/docs/concepts/configuration/assign-pod-node/)
tolerations: []
# -- Image pull secrets
imagePullSecrets: []
probe:
# -- Readiness probe
readiness:
httpGet:
path: '{{ ternary "" .app.baseURLPrefix (empty .app.baseURLPrefix) }}/-/ready'
port: web
# -- Liveness probe
liveness:
httpGet:
path: '{{ ternary "" .app.baseURLPrefix (empty .app.baseURLPrefix) }}/-/healthy'
port: web
# -- Startup probe
startup:
httpGet:
path: '{{ ternary "" .app.baseURLPrefix (empty .app.baseURLPrefix) }}/-/ready'
port: web
# -- Pod's security context. Details are [here](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/)
podSecurityContext:
enabled: false
# -- Security context to be added to server pods
securityContext:
enabled: false
# -- Pod topologySpreadConstraints
topologySpreadConstraints: []
# - maxSkew: 1
# topologyKey: topology.kubernetes.io/zone
# whenUnsatisfiable: DoNotSchedule
# -- Alertmanager listen address
listenAddress: "0.0.0.0:9093"
# -- Extra command line arguments for container of component
extraArgs: {}
# -- Specify alternative source for env variables
envFrom: []
# -- External URL, that alertmanager will expose to receivers
baseURL: ""
# -- External URL Prefix, Prefix for the internal routes of web endpoints
baseURLPrefix: ""
# -- Use existing configmap if specified
# otherwise .config values will be used
configMap: ""
# -- Alertmanager web configuration
webConfig: {}
# -- Alertmanager configuration
config:
global:
resolve_timeout: 5m
route:
# default receiver
receiver: devnull
# tag to group by
group_by: ["alertname"]
# How long to initially wait to send a notification for a group of alerts
group_wait: 30s
# How long to wait before sending a notification about new alerts that are added to a group
group_interval: 10s
# How long to wait before sending a notification again if it has already been sent successfully for an alert
repeat_interval: 24h
receivers:
- name: devnull
# -- Alertmanager extra templates
templates: {}
# alertmanager.tmpl: |-
service:
# -- Service traffic distribution. Details are [here](https://kubernetes.io/docs/concepts/services-networking/service/#traffic-distribution)
trafficDistribution: ""
# -- Service annotations
annotations: {}
# -- Service labels
labels: {}
# -- Service ClusterIP
clusterIP: ""
# -- Service external IPs. Check [here](https://kubernetes.io/docs/concepts/services-networking/service/#external-ips) for details
externalIPs: []
# -- Service load balancer IP
loadBalancerIP: ""
# -- Load balancer source range
loadBalancerSourceRanges: []
# -- Service port
servicePort: 9093
# nodePort: 30000
# -- Service type
type: ClusterIP
# -- Service external traffic policy. Check [here](https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip) for details
externalTrafficPolicy: ""
# -- Health check node port for a service. Check [here](https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip) for details
healthCheckNodePort: ""
# -- Service IP family policy. Check [here](https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services) for details.
ipFamilyPolicy: ""
# -- List of service IP families. Check [here](https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services) for details.
ipFamilies: []
route:
# -- Enable deployment of HTTPRoute for VMAlertmanager
enabled: false
# -- HTTPRoute annotations
annotations: {}
# -- HTTPRoute extra labels
extraLabels: {}
# -- HTTPGateway objects refs
parentRefs: []
# -- Array of hostnames
hostnames: []
# -- Extra rules to prepend to route. This is useful when working with annotation based services.
extraRules: []
# -- Filters for a default rule in HTTPRoute
filters: []
# -- Matches for a default rule in HTTPRoute
matches:
- path:
type: PathPrefix
value: /
ingress:
# -- Enable deployment of ingress for alertmanager component
enabled: false
# -- Ingress annotations
annotations: {}
# kubernetes.io/ingress.class: nginx
# kubernetes.io/tls-acme: 'true'
# -- Ingress extra labels
extraLabels: {}
# -- Array of host objects
hosts:
- name: alertmanager.local
path:
- /
port: web
# -- Array of TLS objects
tls: []
# - secretName: alertmanager-ingress-tls
# hosts:
# - alertmanager.local
# -- Ingress controller class name
ingressClassName: ""
# -- Ingress path type
pathType: Prefix
# -- Empty dir configuration if persistence is disabled for Alertmanager
emptyDir: {}
persistentVolume:
# -- Create/use Persistent Volume Claim for alertmanager component. Empty dir if false
enabled: false
# -- Override Persistent Volume Claim name
name: ""
# -- Array of access modes. Must match those of existing PV or dynamic provisioner. Details are [here](https://kubernetes.io/docs/concepts/storage/persistent-volumes/)
accessModes:
- ReadWriteOnce
# -- VolumeClassAttribute to user for persistent volume
volumeAttributesClassName:
# -- Persistent volume annotations
annotations: {}
# -- PVC extra labels
extraLabels: {}
# -- StorageClass to use for persistent volume. Requires alertmanager.persistentVolume.enabled: true. If defined, PVC created automatically
storageClassName: ""
# -- Existing Claim name. If defined, PVC must be created manually before volume will be bound
existingClaim: ""
# -- Mount path. Alertmanager data Persistent Volume mount root path.
mountPath: /data
# -- Mount subpath
subPath: ""
# -- Size of the volume. Better to set the same as resource limit memory property.
size: 50Mi
# -- Additional hostPath mounts
extraHostPathMounts:
[]
# - name: certs-dir
# mountPath: /etc/kubernetes/certs
# subPath: ""
# hostPath: /etc/kubernetes/certs
# readOnly: true
# -- Extra Volumes for the pod
extraVolumes:
[]
#- name: example
# configMap:
# name: example
# -- Extra Volume Mounts for the container
extraVolumeMounts:
[]
# - name: example
# mountPath: /example
# -- Extra containers to run in a pod with alertmanager
extraContainers:
[]
#- name: config-reloader
# image: reloader-image
# -- Additional initContainers to initialize the pod
initContainers: []
# -- Add extra specs dynamically to this chart
extraObjects: []
# -- Enterprise license key configuration for VictoriaMetrics enterprise.
# Required only for VictoriaMetrics enterprise. Check docs [here](https://docs.victoriametrics.com/victoriametrics/enterprise/),
# for more information, visit [site](https://victoriametrics.com/products/enterprise/).
# Request a trial license [here](https://victoriametrics.com/products/enterprise/trial/)
# Supported starting from VictoriaMetrics v1.94.0
license:
# -- License key
key: ""
# -- Use existing secret with license key
secret:
# -- Existing secret name
name: ""
# -- Key in secret with license key
key: ""