diff --git a/.gitignore b/.gitignore index f6ff0823..2b897583 100644 --- a/.gitignore +++ b/.gitignore @@ -13,3 +13,4 @@ /_public # Additional entries +jsonnetfile.json diff --git a/component/main.jsonnet b/component/main.jsonnet index a13564a4..296f9a64 100644 --- a/component/main.jsonnet +++ b/component/main.jsonnet @@ -1,49 +1,10 @@ // main template for loki local kap = import 'lib/kapitan.libjsonnet'; local kube = import 'lib/kube.libjsonnet'; +local prom = import 'lib/prom.libsonnet'; local inv = kap.inventory(); local com = import 'lib/commodore.libjsonnet'; -// `prom.libsonnet` (with `generateRules`) is provided by -// component-openshift4-monitoring via a library alias. On non-OpenShift -// clusters fall back to component-prometheus, which exports -// `prometheus.libsonnet`, and reimplement the small `generateRules` helper. -// Keep behaviour identical to the OpenShift `prom.libsonnet`: `generateRules` -// only shapes the rules, the syn labels are stamped later by `patch-alerts`. -local prom = - if std.member(inv.applications, 'openshift4-monitoring') then - import 'lib/prom.libsonnet' - else if std.member(inv.applications, 'prometheus') then - local p = import 'lib/prometheus.libsonnet'; - { - generateRules(name, rules): p.PrometheusRule(name) { - spec: { - groups: std.filter( - function(g) std.length(g.rules) > 0, - [ - { - name: group_name, - rules: [ - local rnamekey = std.splitLimit(rname, ':', 1); - rules[group_name][rname] { - // transform source key into "alert: alertname" or - // "record: recordname" - [rnamekey[0]]: rnamekey[1], - } - for rname in std.objectFields(rules[group_name]) - if rules[group_name][rname] != null - ], - } - for group_name in std.objectFields(rules) - if rules[group_name] != null - ] - ), - }, - }, - } - else - error 'component requires one of component-openshift4-monitoring or component-prometheus to be present'; - // The hiera parameters for the component local params = inv.parameters.loki; @@ -121,6 +82,15 @@ local netpols = }, } else {}; +local prometheusRules = prom.generateRules('loki-custom', { 'loki-custom.rules': params.alerts.additionalRules }) { + metadata+: { + namespace: params.namespace.name, + }, +}; + +local has_monitoring = std.member(inv.applications, 'prometheus') || std.member(inv.applications, 'openshift4-monitoring'); +local has_alerts = std.length(params.alerts.additionalRules) > 0; + // Define outputs below { [if params.namespace.create then '00_namespace']: kube.Namespace(params.namespace.name) { @@ -130,10 +100,6 @@ local netpols = // Empty file to make sure the directory is created. Later used in patching alerts. '10_helm_loki/loki/templates/monitoring/.keep': {}, - '20_prometheus_rule': prom.generateRules('loki-custom', { 'loki-custom.rules': params.alerts.additionalRules }) { - metadata+: { - namespace: params.namespace.name, - }, - }, + [if has_monitoring && has_alerts then '20_prometheus_rule']: prometheusRules, [if std.length(netpols) > 0 then '30_network_policies']: netpols, } diff --git a/jsonnetfile.jsonnet b/jsonnetfile.jsonnet new file mode 100644 index 00000000..b09f90e2 --- /dev/null +++ b/jsonnetfile.jsonnet @@ -0,0 +1,16 @@ +{ + version: 1, + dependencies: [ + { + source: { + git: { + remote: 'https://github.com/projectsyn/jsonnet-libs', + subdir: '', + }, + }, + version: 'main', + name: 'syn', + }, + ], + legacyImports: true, +} diff --git a/postprocess/patch-alerts.jsonnet b/postprocess/patch-alerts.jsonnet index 3c85c1ea..a432a9a8 100644 --- a/postprocess/patch-alerts.jsonnet +++ b/postprocess/patch-alerts.jsonnet @@ -1,49 +1,10 @@ local com = import 'lib/commodore.libjsonnet'; local inv = com.inventory(); local params = inv.parameters.loki; +local ap = import 'lib/alert-patching.libsonnet'; local dir = std.extVar('output_path'); -// `lib/alert-patching.libsonnet` is only provided by -// component-openshift4-monitoring. On non-OpenShift clusters provide a minimal -// fallback that stamps the syn alert labels, prefixes alert names with `SYN_`, -// filters ignored alerts and preserves recording rules. The OpenShift-only -// bits (syn_team lookup, customAnnotations) are intentionally omitted. -local ap = - if std.member(inv.applications, 'openshift4-monitoring') then - import 'lib/alert-patching.libsonnet' - else - local patchRule(rule, patches={}, patchName=true) = - if !std.objectHas(rule, 'alert') then - rule - else - rule { - alert: - if patchName && !std.startsWith(super.alert, 'SYN_') then - 'SYN_' + super.alert - else - super.alert, - labels+: { - syn: 'true', - syn_component: inv.parameters._instance, - }, - } + com.makeMergeable(std.get(patches, rule.alert, {})); - { - patchRule: patchRule, - filterPatchRules(group, ignoreNames=[], patches={}, preserveRecordingRules=false, patchNames=true): - local ignore = std.set(ignoreNames); - group { - rules: [ - patchRule(rule, patches, patchNames) - for rule in super.rules - if ( - if std.objectHas(rule, 'alert') - then !std.member(ignore, rule.alert) - else preserveRecordingRules - ) - ], - }, - }; local pt = params.alerts.patchRules; @@ -53,7 +14,7 @@ local patch = function(o) spec+: { groups: std.map( function(g) - ap.filterPatchRules(g, pt.ignoreNames, pt.patches, preserveRecordingRules=true) + ap.filterPatchRules(g, com.renderArray(pt.ignoreNames), pt.patches, preserveRecordingRules=true) , o.spec.groups ), }, diff --git a/tests/defaults.yml b/tests/defaults.yml index 39f5f84f..9de661d1 100644 --- a/tests/defaults.yml +++ b/tests/defaults.yml @@ -5,8 +5,5 @@ parameters: kapitan: dependencies: - type: https - source: https://raw.githubusercontent.com/appuio/component-openshift4-monitoring/v5.5.1/lib/openshift4-monitoring-alert-patching.libsonnet + source: https://raw.githubusercontent.com/appuio/component-openshift4-monitoring/master/lib/openshift4-monitoring-alert-patching.libsonnet output_path: vendor/lib/alert-patching.libsonnet - - type: https - source: https://raw.githubusercontent.com/appuio/component-openshift4-monitoring/v5.5.1/lib/openshift4-monitoring-prom.libsonnet - output_path: vendor/lib/prom.libsonnet diff --git a/tests/extra-config.yml b/tests/extra-config.yml index ae73c080..279d4645 100644 --- a/tests/extra-config.yml +++ b/tests/extra-config.yml @@ -6,15 +6,13 @@ parameters: kapitan: dependencies: - type: https - source: https://raw.githubusercontent.com/appuio/component-openshift4-monitoring/v5.5.1/lib/openshift4-monitoring-alert-patching.libsonnet + source: https://raw.githubusercontent.com/appuio/component-openshift4-monitoring/master/lib/openshift4-monitoring-alert-patching.libsonnet output_path: vendor/lib/alert-patching.libsonnet - - type: https - source: https://raw.githubusercontent.com/appuio/component-openshift4-monitoring/v5.5.1/lib/openshift4-monitoring-prom.libsonnet - output_path: vendor/lib/prom.libsonnet facts: cloud: exoscale region: ch-dk-2 + distribution: openshift4 loki: images: diff --git a/tests/golden/defaults/defaults/defaults/20_prometheus_rule.yaml b/tests/golden/defaults/defaults/defaults/20_prometheus_rule.yaml deleted file mode 100644 index f94aa177..00000000 --- a/tests/golden/defaults/defaults/defaults/20_prometheus_rule.yaml +++ /dev/null @@ -1,10 +0,0 @@ -apiVersion: monitoring.coreos.com/v1 -kind: PrometheusRule -metadata: - annotations: {} - labels: - name: loki-custom - name: loki-custom - namespace: defaults -spec: - groups: [] diff --git a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/chunks-cache/statefulset.yaml b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/chunks-cache/statefulset.yaml index f61ddb01..3fb10914 100644 --- a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/chunks-cache/statefulset.yaml +++ b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/chunks-cache/statefulset.yaml @@ -118,13 +118,7 @@ spec: type: RuntimeDefault initContainers: [] nodeSelector: {} - securityContext: - fsGroup: 11211 - runAsGroup: 11211 - runAsNonRoot: true - runAsUser: 11211 - seccompProfile: - type: RuntimeDefault + securityContext: null serviceAccountName: extra-config-loki-memcached terminationGracePeriodSeconds: 60 tolerations: [] diff --git a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/compactor/workload.yaml b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/compactor/workload.yaml index d636597c..b55e6cb4 100644 --- a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/compactor/workload.yaml +++ b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/compactor/workload.yaml @@ -115,11 +115,8 @@ spec: name: temp enableServiceLinks: true securityContext: - fsGroup: 10001 fsGroupChangePolicy: OnRootMismatch - runAsGroup: 10001 runAsNonRoot: true - runAsUser: 10001 seccompProfile: type: RuntimeDefault serviceAccountName: extra-config-loki diff --git a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/distributor/workload.yaml b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/distributor/workload.yaml index cdf3d499..914b2ace 100644 --- a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/distributor/workload.yaml +++ b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/distributor/workload.yaml @@ -118,11 +118,8 @@ spec: name: temp enableServiceLinks: true securityContext: - fsGroup: 10001 fsGroupChangePolicy: OnRootMismatch - runAsGroup: 10001 runAsNonRoot: true - runAsUser: 10001 seccompProfile: type: RuntimeDefault serviceAccountName: extra-config-loki diff --git a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/gateway/configmap.yaml b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/gateway/configmap.yaml index 541e17ef..40ace037 100644 --- a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/gateway/configmap.yaml +++ b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/gateway/configmap.yaml @@ -204,18 +204,19 @@ data: t$upstream_addr\\t$upstream_connect_time\\t$upstream_header_time\\t$upstream_response_time\\\ t$request_uri';\n access_log syslog:server=127.0.0.1:8514,nohostname access_log_exporter\ \ if=$track;\n access_log /dev/stderr main;\n\n sendfile on;\n tcp_nopush\ - \ on;\n resolver kube-dns.kube-system.svc.cluster.local.;\n\n # if the X-Query-Tags\ - \ header is empty, set a noop= without a value as empty values are not logged\n\ - \ map $http_x_query_tags $query_tags {\n \"\" \"noop=\"; \ - \ # When header is empty, set noop=\n default $http_x_query_tags; # Otherwise,\ - \ preserve the original value\n }\n\n server {\n listen 8080;\n\ - \ listen [::]:8080;\n auth_basic \"Loki\";\n auth_basic_user_file\ - \ /etc/nginx/secrets/.htpasswd;\n\n location = / {\n \n return 200\ - \ 'OK';\n auth_basic off;\n }\n\n location = /stub_status {\n \ - \ stub_status on;\n satisfy any;\n access_log off;\n allow 127.0.0.1;\n\ - \ deny all;\n server_tokens on; # expose nginx version\n }\n\n \ - \ ########################################################\n # Configure\ - \ backend targets\n location ^~ /ui {\n \n set $backend \"http://extra-config-loki-querier.extra-config.svc.cluster.local:3100\"\ + \ on;\n resolver dns-default.openshift-dns.svc.cluster.local.;\n\n # if the\ + \ X-Query-Tags header is empty, set a noop= without a value as empty values are\ + \ not logged\n map $http_x_query_tags $query_tags {\n \"\" \"noop=\"\ + ; # When header is empty, set noop=\n default $http_x_query_tags;\ + \ # Otherwise, preserve the original value\n }\n\n server {\n listen \ + \ 8080;\n listen [::]:8080;\n auth_basic \"\ + Loki\";\n auth_basic_user_file /etc/nginx/secrets/.htpasswd;\n\n location\ + \ = / {\n \n return 200 'OK';\n auth_basic off;\n }\n\n location\ + \ = /stub_status {\n stub_status on;\n satisfy any;\n access_log\ + \ off;\n allow 127.0.0.1;\n deny all;\n server_tokens on; # expose\ + \ nginx version\n }\n\n ########################################################\n\ + \ # Configure backend targets\n location ^~ /ui {\n \n set $backend\ + \ \"http://extra-config-loki-querier.extra-config.svc.cluster.local:3100\"\ ;\n proxy_pass $backend$request_uri;\n }\n\n # Distributor\n\ \ location = /api/prom/push {\n \n set $backend \"http://extra-config-loki-distributor.extra-config.svc.cluster.local:3100\"\ ;\n proxy_pass $backend$request_uri;\n }\n location = /loki/api/v1/push\ diff --git a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/gateway/deployment.yaml b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/gateway/deployment.yaml index 5f87a5d3..b943dd19 100644 --- a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/gateway/deployment.yaml +++ b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/gateway/deployment.yaml @@ -22,7 +22,7 @@ spec: template: metadata: annotations: - checksum/config: c033b3221c75fb9b6adfe9719712f9b6a3d92aed6568b4115eb36c3aaf691395 + checksum/config: 83d350b2361d8681ea3e3708fc909fc9818924d518633174308af18511ae2583 labels: app.kubernetes.io/component: gateway app.kubernetes.io/instance: extra-config @@ -106,11 +106,7 @@ spec: capabilities: drop: - ALL - privileged: false readOnlyRootFilesystem: true - runAsGroup: 65532 - runAsNonRoot: true - runAsUser: 65532 seccompProfile: type: RuntimeDefault volumeMounts: @@ -119,10 +115,7 @@ spec: subPath: access-log-exporter.yaml enableServiceLinks: true securityContext: - fsGroup: 101 - runAsGroup: 101 runAsNonRoot: true - runAsUser: 101 seccompProfile: type: RuntimeDefault serviceAccountName: extra-config-loki-gateway diff --git a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/index-gateway/workload.yaml b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/index-gateway/workload.yaml index a6161474..6c2e2fd7 100644 --- a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/index-gateway/workload.yaml +++ b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/index-gateway/workload.yaml @@ -114,11 +114,8 @@ spec: name: temp enableServiceLinks: true securityContext: - fsGroup: 10001 fsGroupChangePolicy: OnRootMismatch - runAsGroup: 10001 runAsNonRoot: true - runAsUser: 10001 seccompProfile: type: RuntimeDefault serviceAccountName: extra-config-loki diff --git a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/ingester/service.yaml b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/ingester/service.yaml index 0ca0d493..75801880 100644 --- a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/ingester/service.yaml +++ b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/ingester/service.yaml @@ -66,7 +66,6 @@ spec: app.kubernetes.io/instance: extra-config app.kubernetes.io/name: loki type: ClusterIP ---- null --- apiVersion: v1 kind: Service @@ -104,7 +103,6 @@ spec: name: ingester-zone-a rollout-group: ingester type: ClusterIP ---- null --- apiVersion: v1 kind: Service @@ -142,7 +140,6 @@ spec: name: ingester-zone-b rollout-group: ingester type: ClusterIP ---- null --- apiVersion: v1 kind: Service diff --git a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/ingester/workload.yaml b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/ingester/workload.yaml index d9858c00..454e3b04 100644 --- a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/ingester/workload.yaml +++ b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/ingester/workload.yaml @@ -131,11 +131,8 @@ spec: name: temp enableServiceLinks: true securityContext: - fsGroup: 10001 fsGroupChangePolicy: OnRootMismatch - runAsGroup: 10001 runAsNonRoot: true - runAsUser: 10001 seccompProfile: type: RuntimeDefault serviceAccountName: extra-config-loki @@ -299,11 +296,8 @@ spec: name: temp enableServiceLinks: true securityContext: - fsGroup: 10001 fsGroupChangePolicy: OnRootMismatch - runAsGroup: 10001 runAsNonRoot: true - runAsUser: 10001 seccompProfile: type: RuntimeDefault serviceAccountName: extra-config-loki @@ -467,11 +461,8 @@ spec: name: temp enableServiceLinks: true securityContext: - fsGroup: 10001 fsGroupChangePolicy: OnRootMismatch - runAsGroup: 10001 runAsNonRoot: true - runAsUser: 10001 seccompProfile: type: RuntimeDefault serviceAccountName: extra-config-loki diff --git a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/overrides-exporter/workload.yaml b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/overrides-exporter/workload.yaml index 58a844fd..ea47d681 100644 --- a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/overrides-exporter/workload.yaml +++ b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/overrides-exporter/workload.yaml @@ -113,11 +113,8 @@ spec: name: temp enableServiceLinks: true securityContext: - fsGroup: 10001 fsGroupChangePolicy: OnRootMismatch - runAsGroup: 10001 runAsNonRoot: true - runAsUser: 10001 seccompProfile: type: RuntimeDefault serviceAccountName: extra-config-loki diff --git a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/pattern-ingester/workload.yaml b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/pattern-ingester/workload.yaml index bb8fff5e..f713dc37 100644 --- a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/pattern-ingester/workload.yaml +++ b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/pattern-ingester/workload.yaml @@ -106,11 +106,8 @@ spec: name: temp enableServiceLinks: true securityContext: - fsGroup: 10001 fsGroupChangePolicy: OnRootMismatch - runAsGroup: 10001 runAsNonRoot: true - runAsUser: 10001 seccompProfile: type: RuntimeDefault serviceAccountName: extra-config-loki diff --git a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/querier/workload.yaml b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/querier/workload.yaml index 5e342223..95beee7c 100644 --- a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/querier/workload.yaml +++ b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/querier/workload.yaml @@ -119,11 +119,8 @@ spec: name: temp enableServiceLinks: true securityContext: - fsGroup: 10001 fsGroupChangePolicy: OnRootMismatch - runAsGroup: 10001 runAsNonRoot: true - runAsUser: 10001 seccompProfile: type: RuntimeDefault serviceAccountName: extra-config-loki diff --git a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/query-frontend/workload.yaml b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/query-frontend/workload.yaml index 7ac51aca..7f7ab77d 100644 --- a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/query-frontend/workload.yaml +++ b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/query-frontend/workload.yaml @@ -118,11 +118,8 @@ spec: name: temp enableServiceLinks: true securityContext: - fsGroup: 10001 fsGroupChangePolicy: OnRootMismatch - runAsGroup: 10001 runAsNonRoot: true - runAsUser: 10001 seccompProfile: type: RuntimeDefault serviceAccountName: extra-config-loki diff --git a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/query-scheduler/workload.yaml b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/query-scheduler/workload.yaml index 3afcf0f7..b78a65af 100644 --- a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/query-scheduler/workload.yaml +++ b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/query-scheduler/workload.yaml @@ -110,11 +110,8 @@ spec: name: temp enableServiceLinks: true securityContext: - fsGroup: 10001 fsGroupChangePolicy: OnRootMismatch - runAsGroup: 10001 runAsNonRoot: true - runAsUser: 10001 seccompProfile: type: RuntimeDefault serviceAccountName: extra-config-loki diff --git a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/results-cache/statefulset.yaml b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/results-cache/statefulset.yaml index 75951b61..250502cd 100644 --- a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/results-cache/statefulset.yaml +++ b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/results-cache/statefulset.yaml @@ -118,13 +118,7 @@ spec: type: RuntimeDefault initContainers: [] nodeSelector: {} - securityContext: - fsGroup: 11211 - runAsGroup: 11211 - runAsNonRoot: true - runAsUser: 11211 - seccompProfile: - type: RuntimeDefault + securityContext: null serviceAccountName: extra-config-loki-memcached terminationGracePeriodSeconds: 60 tolerations: [] diff --git a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/ruler/workload.yaml b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/ruler/workload.yaml index 3a533f52..c7169779 100644 --- a/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/ruler/workload.yaml +++ b/tests/golden/extra-config/extra-config/extra-config/10_helm_loki/loki/templates/ruler/workload.yaml @@ -114,11 +114,8 @@ spec: name: temp enableServiceLinks: true securityContext: - fsGroup: 10001 fsGroupChangePolicy: OnRootMismatch - runAsGroup: 10001 runAsNonRoot: true - runAsUser: 10001 seccompProfile: type: RuntimeDefault serviceAccountName: extra-config-loki diff --git a/tests/golden/extra-config/extra-config/extra-config/20_prometheus_rule.yaml b/tests/golden/extra-config/extra-config/extra-config/20_prometheus_rule.yaml deleted file mode 100644 index 468881da..00000000 --- a/tests/golden/extra-config/extra-config/extra-config/20_prometheus_rule.yaml +++ /dev/null @@ -1,10 +0,0 @@ -apiVersion: monitoring.coreos.com/v1 -kind: PrometheusRule -metadata: - annotations: {} - labels: - name: loki-custom - name: loki-custom - namespace: extra-config -spec: - groups: [] diff --git a/tests/golden/legacy/legacy/legacy/10_helm_loki/loki/templates/chunks-cache/statefulset.yaml b/tests/golden/legacy/legacy/legacy/10_helm_loki/loki/templates/chunks-cache/statefulset.yaml index 36743513..228a34d1 100644 --- a/tests/golden/legacy/legacy/legacy/10_helm_loki/loki/templates/chunks-cache/statefulset.yaml +++ b/tests/golden/legacy/legacy/legacy/10_helm_loki/loki/templates/chunks-cache/statefulset.yaml @@ -119,13 +119,7 @@ spec: initContainers: [] nodeSelector: appuio.io/node-class: plus - securityContext: - fsGroup: 11211 - runAsGroup: 11211 - runAsNonRoot: true - runAsUser: 11211 - seccompProfile: - type: RuntimeDefault + securityContext: null serviceAccountName: legacy-loki-memcached terminationGracePeriodSeconds: 60 tolerations: [] diff --git a/tests/golden/legacy/legacy/legacy/10_helm_loki/loki/templates/gateway/configmap.yaml b/tests/golden/legacy/legacy/legacy/10_helm_loki/loki/templates/gateway/configmap.yaml index dee194bc..e376afd5 100644 --- a/tests/golden/legacy/legacy/legacy/10_helm_loki/loki/templates/gateway/configmap.yaml +++ b/tests/golden/legacy/legacy/legacy/10_helm_loki/loki/templates/gateway/configmap.yaml @@ -204,14 +204,14 @@ data: t$upstream_addr\\t$upstream_connect_time\\t$upstream_header_time\\t$upstream_response_time\\\ t$request_uri';\n access_log syslog:server=127.0.0.1:8514,nohostname access_log_exporter\ \ if=$track;\n access_log /dev/stderr main;\n\n sendfile on;\n tcp_nopush\ - \ on;\n resolver kube-dns.kube-system.svc.cluster.local.;\n\n # if the X-Query-Tags\ - \ header is empty, set a noop= without a value as empty values are not logged\n\ - \ map $http_x_query_tags $query_tags {\n \"\" \"noop=\"; \ - \ # When header is empty, set noop=\n default $http_x_query_tags; # Otherwise,\ - \ preserve the original value\n }\n\n server {\n listen 8080;\n\ - \ listen [::]:8080;\n\n location = / {\n \n return\ - \ 200 'OK';\n auth_basic off;\n }\n\n location = /stub_status {\n \ - \ stub_status on;\n satisfy any;\n access_log off;\n allow\ + \ on;\n resolver dns-default.openshift-dns.svc.cluster.local.;\n\n # if the\ + \ X-Query-Tags header is empty, set a noop= without a value as empty values are\ + \ not logged\n map $http_x_query_tags $query_tags {\n \"\" \"noop=\"\ + ; # When header is empty, set noop=\n default $http_x_query_tags;\ + \ # Otherwise, preserve the original value\n }\n\n server {\n listen \ + \ 8080;\n listen [::]:8080;\n\n location = / {\n \ + \ \n return 200 'OK';\n auth_basic off;\n }\n\n location = /stub_status\ + \ {\n stub_status on;\n satisfy any;\n access_log off;\n allow\ \ 127.0.0.1;\n deny all;\n server_tokens on; # expose nginx version\n\ \ }\n\n ########################################################\n #\ \ Configure backend targets\n location ^~ /ui {\n \n set $backend\ diff --git a/tests/golden/legacy/legacy/legacy/10_helm_loki/loki/templates/gateway/deployment.yaml b/tests/golden/legacy/legacy/legacy/10_helm_loki/loki/templates/gateway/deployment.yaml index 2a414789..73cc9a26 100644 --- a/tests/golden/legacy/legacy/legacy/10_helm_loki/loki/templates/gateway/deployment.yaml +++ b/tests/golden/legacy/legacy/legacy/10_helm_loki/loki/templates/gateway/deployment.yaml @@ -22,7 +22,7 @@ spec: template: metadata: annotations: - checksum/config: c4d6e784251df14cc0030fb879b89e13f22af4961a5fde94e662af9d7a51419b + checksum/config: a58a96ad62c673d3fa0143544e2c7ab8d5cecd30b357caf3b9df3fc599abf6d2 labels: app.kubernetes.io/component: gateway app.kubernetes.io/instance: legacy @@ -104,11 +104,7 @@ spec: capabilities: drop: - ALL - privileged: false readOnlyRootFilesystem: true - runAsGroup: 65532 - runAsNonRoot: true - runAsUser: 65532 seccompProfile: type: RuntimeDefault volumeMounts: @@ -119,10 +115,7 @@ spec: nodeSelector: appuio.io/node-class: plus securityContext: - fsGroup: 101 - runAsGroup: 101 runAsNonRoot: true - runAsUser: 101 seccompProfile: type: RuntimeDefault serviceAccountName: legacy-loki-gateway diff --git a/tests/golden/legacy/legacy/legacy/10_helm_loki/loki/templates/results-cache/statefulset.yaml b/tests/golden/legacy/legacy/legacy/10_helm_loki/loki/templates/results-cache/statefulset.yaml index 4fa15de4..6f0afbde 100644 --- a/tests/golden/legacy/legacy/legacy/10_helm_loki/loki/templates/results-cache/statefulset.yaml +++ b/tests/golden/legacy/legacy/legacy/10_helm_loki/loki/templates/results-cache/statefulset.yaml @@ -119,13 +119,7 @@ spec: initContainers: [] nodeSelector: appuio.io/node-class: plus - securityContext: - fsGroup: 11211 - runAsGroup: 11211 - runAsNonRoot: true - runAsUser: 11211 - seccompProfile: - type: RuntimeDefault + securityContext: null serviceAccountName: legacy-loki-memcached terminationGracePeriodSeconds: 60 tolerations: [] diff --git a/tests/golden/legacy/legacy/legacy/20_prometheus_rule.yaml b/tests/golden/legacy/legacy/legacy/20_prometheus_rule.yaml deleted file mode 100644 index c2bf10be..00000000 --- a/tests/golden/legacy/legacy/legacy/20_prometheus_rule.yaml +++ /dev/null @@ -1,10 +0,0 @@ -apiVersion: monitoring.coreos.com/v1 -kind: PrometheusRule -metadata: - annotations: {} - labels: - name: loki-custom - name: loki-custom - namespace: legacy -spec: - groups: [] diff --git a/tests/golden/openshift/openshift/openshift/20_prometheus_rule.yaml b/tests/golden/openshift/openshift/openshift/20_prometheus_rule.yaml deleted file mode 100644 index bd18ce98..00000000 --- a/tests/golden/openshift/openshift/openshift/20_prometheus_rule.yaml +++ /dev/null @@ -1,10 +0,0 @@ -apiVersion: monitoring.coreos.com/v1 -kind: PrometheusRule -metadata: - annotations: {} - labels: - name: loki-custom - name: loki-custom - namespace: openshift -spec: - groups: [] diff --git a/tests/golden/prometheus/prometheus/prometheus/20_prometheus_rule.yaml b/tests/golden/prometheus/prometheus/prometheus/20_prometheus_rule.yaml index ddf8486a..4cc64b26 100644 --- a/tests/golden/prometheus/prometheus/prometheus/20_prometheus_rule.yaml +++ b/tests/golden/prometheus/prometheus/prometheus/20_prometheus_rule.yaml @@ -1,7 +1,6 @@ apiVersion: monitoring.coreos.com/v1 kind: PrometheusRule metadata: - annotations: {} labels: monitoring.syn.tools/enabled: 'true' name: loki-custom @@ -18,3 +17,5 @@ spec: for: 5m labels: severity: warning + syn: 'true' + syn_component: prometheus diff --git a/tests/legacy.yml b/tests/legacy.yml index f6440986..224881fc 100644 --- a/tests/legacy.yml +++ b/tests/legacy.yml @@ -5,11 +5,11 @@ parameters: kapitan: dependencies: - type: https - source: https://raw.githubusercontent.com/appuio/component-openshift4-monitoring/v5.5.1/lib/openshift4-monitoring-alert-patching.libsonnet + source: https://raw.githubusercontent.com/appuio/component-openshift4-monitoring/master/lib/openshift4-monitoring-alert-patching.libsonnet output_path: vendor/lib/alert-patching.libsonnet - - type: https - source: https://raw.githubusercontent.com/appuio/component-openshift4-monitoring/v5.5.1/lib/openshift4-monitoring-prom.libsonnet - output_path: vendor/lib/prom.libsonnet + + facts: + distribution: openshift4 loki: globalNodeSelector: diff --git a/tests/openshift.yml b/tests/openshift.yml index 74b1b826..f6de11e7 100644 --- a/tests/openshift.yml +++ b/tests/openshift.yml @@ -5,11 +5,8 @@ parameters: kapitan: dependencies: - type: https - source: https://raw.githubusercontent.com/appuio/component-openshift4-monitoring/v5.5.1/lib/openshift4-monitoring-alert-patching.libsonnet + source: https://raw.githubusercontent.com/appuio/component-openshift4-monitoring/master/lib/openshift4-monitoring-alert-patching.libsonnet output_path: vendor/lib/alert-patching.libsonnet - - type: https - source: https://raw.githubusercontent.com/appuio/component-openshift4-monitoring/v5.5.1/lib/openshift4-monitoring-prom.libsonnet - output_path: vendor/lib/prom.libsonnet facts: distribution: openshift4 diff --git a/tests/prometheus.yml b/tests/prometheus.yml index eaddb18b..f28325fd 100644 --- a/tests/prometheus.yml +++ b/tests/prometheus.yml @@ -5,8 +5,18 @@ parameters: kapitan: dependencies: - type: https - source: https://raw.githubusercontent.com/projectsyn/component-prometheus/v2.15.0/lib/prometheus.libsonnet + source: https://raw.githubusercontent.com/projectsyn/component-prometheus/master/lib/prometheus.libsonnet output_path: vendor/lib/prometheus.libsonnet + - type: https + source: https://raw.githubusercontent.com/projectsyn/component-prometheus/master/lib/prometheus-prom.libsonnet + output_path: vendor/lib/prom.libsonnet + - type: https + source: https://raw.githubusercontent.com/projectsyn/component-prometheus/master/lib/prometheus-alert-patching.libsonnet + output_path: vendor/lib/alert-patching.libsonnet + + prometheus: + alerts: + ignoreNames: [] loki: alerts: