diff --git a/charts/authentik/README.md b/charts/authentik/README.md index 53ca898e..a2ad4748 100644 --- a/charts/authentik/README.md +++ b/charts/authentik/README.md @@ -216,6 +216,7 @@ The secret `authentik-postgres-credentials` must have `username` and `password` | prometheus.rules.annotations | object | `{}` | PrometheusRule annotations | | prometheus.rules.enabled | bool | `false` | | | prometheus.rules.labels | object | `{}` | PrometheusRule labels | +| prometheus.rules.migrations.enabled | bool | `false` | Emit the migration recording rules and the `PendingMigrations` alert. Off by default: the default deployment applies migrations during startup, before metrics are served, so `django_migrations_unapplied_total` is never exported and the alert can never fire. Enable it if you run migrations as a separate step, where authentik can serve against a database whose migrations have not been applied yet. | | prometheus.rules.namespace | string | `""` | PrometheusRule namespace | | prometheus.rules.selector | object | `{}` | PrometheusRule selector | | server.affinity | object | `{}` (defaults to the global.affinity preset) | Assign custom [affinity] rules to the deployment | diff --git a/charts/authentik/templates/prometheusrule.yaml b/charts/authentik/templates/prometheusrule.yaml index da710ecf..5c3b8a8c 100644 --- a/charts/authentik/templates/prometheusrule.yaml +++ b/charts/authentik/templates/prometheusrule.yaml @@ -131,6 +131,7 @@ spec: - record: job:django_db_errors_total:sum_rate30s expr: sum(rate(django_db_errors_total[30s])) by (alias, vendor, type) + {{- if .Values.prometheus.rules.migrations.enabled }} - name: authentik Aggregate migrations {{- if .Values.prometheus.rules.additionalRuleGroupAnnotations }} annotations: @@ -141,6 +142,7 @@ spec: expr: max(django_migrations_applied_total) by (job, connection) - record: job:django_migrations_unapplied_total:max expr: max(django_migrations_unapplied_total) by (job, connection) + {{- end }} - name: authentik Alerts {{- if .Values.prometheus.rules.additionalRuleGroupAnnotations }} @@ -160,6 +162,7 @@ spec: `}} + {{- if .Values.prometheus.rules.migrations.enabled }} - alert: PendingMigrations labels: severity: critical @@ -170,6 +173,7 @@ spec: summary: Pending database migrations message: authentik instance {{ $labels.instance }} has pending database migrations `}} + {{- end }} - alert: FailedSystemTasks labels: diff --git a/charts/authentik/values.yaml b/charts/authentik/values.yaml index d96c4260..f5d64f21 100644 --- a/charts/authentik/values.yaml +++ b/charts/authentik/values.yaml @@ -1074,6 +1074,13 @@ geoip: prometheus: rules: enabled: false + migrations: + # -- Emit the migration recording rules and the `PendingMigrations` alert. Off by default: + # the default deployment applies migrations during startup, before metrics are served, so + # `django_migrations_unapplied_total` is never exported and the alert can never fire. Enable + # it if you run migrations as a separate step, where authentik can serve against a database + # whose migrations have not been applied yet. + enabled: false # -- PrometheusRule namespace namespace: "" # -- PrometheusRule selector