Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions charts/authentik/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -216,6 +216,7 @@ The secret `authentik-postgres-credentials` must have `username` and `password`
| prometheus.rules.annotations | object | `{}` | PrometheusRule annotations |
| prometheus.rules.enabled | bool | `false` | |
| prometheus.rules.labels | object | `{}` | PrometheusRule labels |
| prometheus.rules.migrations.enabled | bool | `false` | Emit the migration recording rules and the `PendingMigrations` alert. Off by default: the default deployment applies migrations during startup, before metrics are served, so `django_migrations_unapplied_total` is never exported and the alert can never fire. Enable it if you run migrations as a separate step, where authentik can serve against a database whose migrations have not been applied yet. |
| prometheus.rules.namespace | string | `""` | PrometheusRule namespace |
| prometheus.rules.selector | object | `{}` | PrometheusRule selector |
| server.affinity | object | `{}` (defaults to the global.affinity preset) | Assign custom [affinity] rules to the deployment |
Expand Down
4 changes: 4 additions & 0 deletions charts/authentik/templates/prometheusrule.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -131,6 +131,7 @@ spec:
- record: job:django_db_errors_total:sum_rate30s
expr: sum(rate(django_db_errors_total[30s])) by (alias, vendor, type)

{{- if .Values.prometheus.rules.migrations.enabled }}
- name: authentik Aggregate migrations
{{- if .Values.prometheus.rules.additionalRuleGroupAnnotations }}
annotations:
Expand All @@ -141,6 +142,7 @@ spec:
expr: max(django_migrations_applied_total) by (job, connection)
- record: job:django_migrations_unapplied_total:max
expr: max(django_migrations_unapplied_total) by (job, connection)
{{- end }}

- name: authentik Alerts
{{- if .Values.prometheus.rules.additionalRuleGroupAnnotations }}
Expand All @@ -160,6 +162,7 @@ spec:
`}}


{{- if .Values.prometheus.rules.migrations.enabled }}
- alert: PendingMigrations
labels:
severity: critical
Expand All @@ -170,6 +173,7 @@ spec:
summary: Pending database migrations
message: authentik instance {{ $labels.instance }} has pending database migrations
`}}
{{- end }}

- alert: FailedSystemTasks
labels:
Expand Down
7 changes: 7 additions & 0 deletions charts/authentik/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -1074,6 +1074,13 @@ geoip:
prometheus:
rules:
enabled: false
migrations:
# -- Emit the migration recording rules and the `PendingMigrations` alert. Off by default:
# the default deployment applies migrations during startup, before metrics are served, so
# `django_migrations_unapplied_total` is never exported and the alert can never fire. Enable
# it if you run migrations as a separate step, where authentik can serve against a database
# whose migrations have not been applied yet.
enabled: false
# -- PrometheusRule namespace
namespace: ""
# -- PrometheusRule selector
Expand Down