Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -13,3 +13,4 @@
/_public

# Additional entries
jsonnetfile.json
56 changes: 11 additions & 45 deletions component/main.jsonnet
Original file line number Diff line number Diff line change
@@ -1,49 +1,10 @@
// main template for loki
local kap = import 'lib/kapitan.libjsonnet';
local kube = import 'lib/kube.libjsonnet';
local prom = import 'lib/prom.libsonnet';
local inv = kap.inventory();
local com = import 'lib/commodore.libjsonnet';

// `prom.libsonnet` (with `generateRules`) is provided by
// component-openshift4-monitoring via a library alias. On non-OpenShift
// clusters fall back to component-prometheus, which exports
// `prometheus.libsonnet`, and reimplement the small `generateRules` helper.
// Keep behaviour identical to the OpenShift `prom.libsonnet`: `generateRules`
// only shapes the rules, the syn labels are stamped later by `patch-alerts`.
local prom =
if std.member(inv.applications, 'openshift4-monitoring') then
import 'lib/prom.libsonnet'
else if std.member(inv.applications, 'prometheus') then
local p = import 'lib/prometheus.libsonnet';
{
generateRules(name, rules): p.PrometheusRule(name) {
spec: {
groups: std.filter(
function(g) std.length(g.rules) > 0,
[
{
name: group_name,
rules: [
local rnamekey = std.splitLimit(rname, ':', 1);
rules[group_name][rname] {
// transform source key into "alert: alertname" or
// "record: recordname"
[rnamekey[0]]: rnamekey[1],
}
for rname in std.objectFields(rules[group_name])
if rules[group_name][rname] != null
],
}
for group_name in std.objectFields(rules)
if rules[group_name] != null
]
),
},
},
}
else
error 'component requires one of component-openshift4-monitoring or component-prometheus to be present';

// The hiera parameters for the component
local params = inv.parameters.loki;

Expand Down Expand Up @@ -121,6 +82,15 @@ local netpols =
},
} else {};

local prometheusRules = prom.generateRules('loki-custom', { 'loki-custom.rules': params.alerts.additionalRules }) {
metadata+: {
namespace: params.namespace.name,
},
};

local has_monitoring = std.member(inv.applications, 'prometheus') || std.member(inv.applications, 'openshift4-monitoring');
local has_alerts = std.length(params.alerts.additionalRules) > 0;

// Define outputs below
{
[if params.namespace.create then '00_namespace']: kube.Namespace(params.namespace.name) {
Expand All @@ -130,10 +100,6 @@ local netpols =
// Empty file to make sure the directory is created. Later used in patching alerts.
'10_helm_loki/loki/templates/monitoring/.keep': {},

'20_prometheus_rule': prom.generateRules('loki-custom', { 'loki-custom.rules': params.alerts.additionalRules }) {
metadata+: {
namespace: params.namespace.name,
},
},
[if has_monitoring && has_alerts then '20_prometheus_rule']: prometheusRules,
[if std.length(netpols) > 0 then '30_network_policies']: netpols,
}
16 changes: 16 additions & 0 deletions jsonnetfile.jsonnet
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
{
version: 1,
dependencies: [
{
source: {
git: {
remote: 'https://github.com/projectsyn/jsonnet-libs',
subdir: '',
},
},
version: 'main',
name: 'syn',
},
],
legacyImports: true,
}
43 changes: 2 additions & 41 deletions postprocess/patch-alerts.jsonnet
Original file line number Diff line number Diff line change
@@ -1,49 +1,10 @@
local com = import 'lib/commodore.libjsonnet';
local inv = com.inventory();
local params = inv.parameters.loki;
local ap = import 'lib/alert-patching.libsonnet';

local dir = std.extVar('output_path');

// `lib/alert-patching.libsonnet` is only provided by
// component-openshift4-monitoring. On non-OpenShift clusters provide a minimal
// fallback that stamps the syn alert labels, prefixes alert names with `SYN_`,
// filters ignored alerts and preserves recording rules. The OpenShift-only
// bits (syn_team lookup, customAnnotations) are intentionally omitted.
local ap =
if std.member(inv.applications, 'openshift4-monitoring') then
import 'lib/alert-patching.libsonnet'
else
local patchRule(rule, patches={}, patchName=true) =
if !std.objectHas(rule, 'alert') then
rule
else
rule {
alert:
if patchName && !std.startsWith(super.alert, 'SYN_') then
'SYN_' + super.alert
else
super.alert,
labels+: {
syn: 'true',
syn_component: inv.parameters._instance,
},
} + com.makeMergeable(std.get(patches, rule.alert, {}));
{
patchRule: patchRule,
filterPatchRules(group, ignoreNames=[], patches={}, preserveRecordingRules=false, patchNames=true):
local ignore = std.set(ignoreNames);
group {
rules: [
patchRule(rule, patches, patchNames)
for rule in super.rules
if (
if std.objectHas(rule, 'alert')
then !std.member(ignore, rule.alert)
else preserveRecordingRules
)
],
},
};

local pt = params.alerts.patchRules;

Expand All @@ -53,7 +14,7 @@ local patch = function(o)
spec+: {
groups: std.map(
function(g)
ap.filterPatchRules(g, pt.ignoreNames, pt.patches, preserveRecordingRules=true)
ap.filterPatchRules(g, com.renderArray(pt.ignoreNames), pt.patches, preserveRecordingRules=true)
, o.spec.groups
),
},
Expand Down
5 changes: 1 addition & 4 deletions tests/defaults.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,8 +5,5 @@ parameters:
kapitan:
dependencies:
- type: https
source: https://raw.githubusercontent.com/appuio/component-openshift4-monitoring/v5.5.1/lib/openshift4-monitoring-alert-patching.libsonnet
source: https://raw.githubusercontent.com/appuio/component-openshift4-monitoring/master/lib/openshift4-monitoring-alert-patching.libsonnet
output_path: vendor/lib/alert-patching.libsonnet
- type: https
source: https://raw.githubusercontent.com/appuio/component-openshift4-monitoring/v5.5.1/lib/openshift4-monitoring-prom.libsonnet
output_path: vendor/lib/prom.libsonnet
6 changes: 2 additions & 4 deletions tests/extra-config.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,15 +6,13 @@ parameters:
kapitan:
dependencies:
- type: https
source: https://raw.githubusercontent.com/appuio/component-openshift4-monitoring/v5.5.1/lib/openshift4-monitoring-alert-patching.libsonnet
source: https://raw.githubusercontent.com/appuio/component-openshift4-monitoring/master/lib/openshift4-monitoring-alert-patching.libsonnet
output_path: vendor/lib/alert-patching.libsonnet
- type: https
source: https://raw.githubusercontent.com/appuio/component-openshift4-monitoring/v5.5.1/lib/openshift4-monitoring-prom.libsonnet
output_path: vendor/lib/prom.libsonnet

facts:
cloud: exoscale
region: ch-dk-2
distribution: openshift4

loki:
images:
Expand Down
10 changes: 0 additions & 10 deletions tests/golden/defaults/defaults/defaults/20_prometheus_rule.yaml

This file was deleted.

Original file line number Diff line number Diff line change
Expand Up @@ -118,13 +118,7 @@ spec:
type: RuntimeDefault
initContainers: []
nodeSelector: {}
securityContext:
fsGroup: 11211
runAsGroup: 11211
runAsNonRoot: true
runAsUser: 11211
seccompProfile:
type: RuntimeDefault
securityContext: null
serviceAccountName: extra-config-loki-memcached
terminationGracePeriodSeconds: 60
tolerations: []
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -115,11 +115,8 @@ spec:
name: temp
enableServiceLinks: true
securityContext:
fsGroup: 10001
fsGroupChangePolicy: OnRootMismatch
runAsGroup: 10001
runAsNonRoot: true
runAsUser: 10001
seccompProfile:
type: RuntimeDefault
serviceAccountName: extra-config-loki
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -118,11 +118,8 @@ spec:
name: temp
enableServiceLinks: true
securityContext:
fsGroup: 10001
fsGroupChangePolicy: OnRootMismatch
runAsGroup: 10001
runAsNonRoot: true
runAsUser: 10001
seccompProfile:
type: RuntimeDefault
serviceAccountName: extra-config-loki
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -204,18 +204,19 @@ data:
t$upstream_addr\\t$upstream_connect_time\\t$upstream_header_time\\t$upstream_response_time\\\
t$request_uri';\n access_log syslog:server=127.0.0.1:8514,nohostname access_log_exporter\
\ if=$track;\n access_log /dev/stderr main;\n\n sendfile on;\n tcp_nopush\
\ on;\n resolver kube-dns.kube-system.svc.cluster.local.;\n\n # if the X-Query-Tags\
\ header is empty, set a noop= without a value as empty values are not logged\n\
\ map $http_x_query_tags $query_tags {\n \"\" \"noop=\"; \
\ # When header is empty, set noop=\n default $http_x_query_tags; # Otherwise,\
\ preserve the original value\n }\n\n server {\n listen 8080;\n\
\ listen [::]:8080;\n auth_basic \"Loki\";\n auth_basic_user_file\
\ /etc/nginx/secrets/.htpasswd;\n\n location = / {\n \n return 200\
\ 'OK';\n auth_basic off;\n }\n\n location = /stub_status {\n \
\ stub_status on;\n satisfy any;\n access_log off;\n allow 127.0.0.1;\n\
\ deny all;\n server_tokens on; # expose nginx version\n }\n\n \
\ ########################################################\n # Configure\
\ backend targets\n location ^~ /ui {\n \n set $backend \"http://extra-config-loki-querier.extra-config.svc.cluster.local:3100\"\
\ on;\n resolver dns-default.openshift-dns.svc.cluster.local.;\n\n # if the\
\ X-Query-Tags header is empty, set a noop= without a value as empty values are\
\ not logged\n map $http_x_query_tags $query_tags {\n \"\" \"noop=\"\
; # When header is empty, set noop=\n default $http_x_query_tags;\
\ # Otherwise, preserve the original value\n }\n\n server {\n listen \
\ 8080;\n listen [::]:8080;\n auth_basic \"\
Loki\";\n auth_basic_user_file /etc/nginx/secrets/.htpasswd;\n\n location\
\ = / {\n \n return 200 'OK';\n auth_basic off;\n }\n\n location\
\ = /stub_status {\n stub_status on;\n satisfy any;\n access_log\
\ off;\n allow 127.0.0.1;\n deny all;\n server_tokens on; # expose\
\ nginx version\n }\n\n ########################################################\n\
\ # Configure backend targets\n location ^~ /ui {\n \n set $backend\
\ \"http://extra-config-loki-querier.extra-config.svc.cluster.local:3100\"\
;\n proxy_pass $backend$request_uri;\n }\n\n # Distributor\n\
\ location = /api/prom/push {\n \n set $backend \"http://extra-config-loki-distributor.extra-config.svc.cluster.local:3100\"\
;\n proxy_pass $backend$request_uri;\n }\n location = /loki/api/v1/push\
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ spec:
template:
metadata:
annotations:
checksum/config: c033b3221c75fb9b6adfe9719712f9b6a3d92aed6568b4115eb36c3aaf691395
checksum/config: 83d350b2361d8681ea3e3708fc909fc9818924d518633174308af18511ae2583
labels:
app.kubernetes.io/component: gateway
app.kubernetes.io/instance: extra-config
Expand Down Expand Up @@ -106,11 +106,7 @@ spec:
capabilities:
drop:
- ALL
privileged: false
readOnlyRootFilesystem: true
runAsGroup: 65532
runAsNonRoot: true
runAsUser: 65532
seccompProfile:
type: RuntimeDefault
volumeMounts:
Expand All @@ -119,10 +115,7 @@ spec:
subPath: access-log-exporter.yaml
enableServiceLinks: true
securityContext:
fsGroup: 101
runAsGroup: 101
runAsNonRoot: true
runAsUser: 101
seccompProfile:
type: RuntimeDefault
serviceAccountName: extra-config-loki-gateway
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -114,11 +114,8 @@ spec:
name: temp
enableServiceLinks: true
securityContext:
fsGroup: 10001
fsGroupChangePolicy: OnRootMismatch
runAsGroup: 10001
runAsNonRoot: true
runAsUser: 10001
seccompProfile:
type: RuntimeDefault
serviceAccountName: extra-config-loki
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,6 @@ spec:
app.kubernetes.io/instance: extra-config
app.kubernetes.io/name: loki
type: ClusterIP
--- null
---
apiVersion: v1
kind: Service
Expand Down Expand Up @@ -104,7 +103,6 @@ spec:
name: ingester-zone-a
rollout-group: ingester
type: ClusterIP
--- null
---
apiVersion: v1
kind: Service
Expand Down Expand Up @@ -142,7 +140,6 @@ spec:
name: ingester-zone-b
rollout-group: ingester
type: ClusterIP
--- null
---
apiVersion: v1
kind: Service
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -131,11 +131,8 @@ spec:
name: temp
enableServiceLinks: true
securityContext:
fsGroup: 10001
fsGroupChangePolicy: OnRootMismatch
runAsGroup: 10001
runAsNonRoot: true
runAsUser: 10001
seccompProfile:
type: RuntimeDefault
serviceAccountName: extra-config-loki
Expand Down Expand Up @@ -299,11 +296,8 @@ spec:
name: temp
enableServiceLinks: true
securityContext:
fsGroup: 10001
fsGroupChangePolicy: OnRootMismatch
runAsGroup: 10001
runAsNonRoot: true
runAsUser: 10001
seccompProfile:
type: RuntimeDefault
serviceAccountName: extra-config-loki
Expand Down Expand Up @@ -467,11 +461,8 @@ spec:
name: temp
enableServiceLinks: true
securityContext:
fsGroup: 10001
fsGroupChangePolicy: OnRootMismatch
runAsGroup: 10001
runAsNonRoot: true
runAsUser: 10001
seccompProfile:
type: RuntimeDefault
serviceAccountName: extra-config-loki
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -113,11 +113,8 @@ spec:
name: temp
enableServiceLinks: true
securityContext:
fsGroup: 10001
fsGroupChangePolicy: OnRootMismatch
runAsGroup: 10001
runAsNonRoot: true
runAsUser: 10001
seccompProfile:
type: RuntimeDefault
serviceAccountName: extra-config-loki
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -106,11 +106,8 @@ spec:
name: temp
enableServiceLinks: true
securityContext:
fsGroup: 10001
fsGroupChangePolicy: OnRootMismatch
runAsGroup: 10001
runAsNonRoot: true
runAsUser: 10001
seccompProfile:
type: RuntimeDefault
serviceAccountName: extra-config-loki
Expand Down
Loading
Loading