diff --git a/charts/enterprise/authentik/Chart.yaml b/charts/enterprise/authentik/Chart.yaml index 8aba7b62227..6eaf6aa4845 100644 --- a/charts/enterprise/authentik/Chart.yaml +++ b/charts/enterprise/authentik/Chart.yaml @@ -27,7 +27,7 @@ sources: - https://github.com/truecharts/charts/tree/master/charts/enterprise/authentik - https://github.com/goauthentik/authentik - https://goauthentik.io/docs/ -version: 7.0.2 +version: 7.1.0 annotations: truecharts.org/catagories: | - authentication diff --git a/charts/enterprise/authentik/questions.yaml b/charts/enterprise/authentik/questions.yaml index 7954954034f..18c68c39fa4 100644 --- a/charts/enterprise/authentik/questions.yaml +++ b/charts/enterprise/authentik/questions.yaml @@ -203,18 +203,6 @@ questions: description: warning - value: error description: error - - variable: metrics - label: Metrics - schema: - additional_attrs: true - type: dict - attrs: - - variable: enabled - label: Metrics Endpoint - description: Enables metrics endpoint for Authentik and embedded outpost - schema: - type: boolean - default: false - variable: ldap label: LDAP schema: @@ -298,12 +286,6 @@ questions: type: string required: true default: "" - - variable: metrics - label: Metrics Endpoint - description: Enables metric endpoint in LDAP Outpost - schema: - type: boolean - default: false - variable: proxy label: Proxy schema: @@ -368,12 +350,6 @@ questions: type: string required: true default: "" - - variable: metrics - label: Metrics Endpoint - description: Enables metric endpoint in Proxy Outpost - schema: - type: boolean - default: false - variable: geoip group: Container Configuration label: GeoIP Configuration @@ -481,64 +457,6 @@ questions: schema: type: int default: 9443 - - variable: http - label: http Service - description: The http service. - schema: - additional_attrs: true - type: dict - attrs: -# Include{serviceSelectorLoadBalancer} -# Include{serviceSelectorExtras} - - variable: http - label: http Service Port Configuration - schema: - additional_attrs: true - type: dict - attrs: - - variable: port - label: Port - description: This port exposes the container port on the service - schema: - type: int - default: 10230 - required: true -# Include{advancedPortHTTP} - - variable: targetPort - label: Target Port - description: The internal(!) port on the container the Application runs on - schema: - type: int - default: 9000 - - variable: metrics - label: metrics Service - description: The metrics service. - schema: - additional_attrs: true - type: dict - attrs: -# Include{serviceSelectorLoadBalancer} -# Include{serviceSelectorExtras} - - variable: metrics - label: metrics Service Port Configuration - schema: - additional_attrs: true - type: dict - attrs: - - variable: port - label: Port - description: This port exposes the container port on the service - schema: - type: int - default: 10231 - required: true -# Include{advancedPortHTTP} - - variable: targetPort - label: Target Port - description: The internal(!) port on the container the Application runs on - schema: - type: int - default: 9301 - variable: ldapldaps label: LDAPS Service description: The LDAPS service. @@ -597,35 +515,6 @@ questions: schema: type: int default: 3389 - - variable: ldapmetrics - label: LDAP Metrics Service - description: The LDAP Metrics service. - schema: - additional_attrs: true - type: dict - attrs: -# Include{serviceSelectorLoadBalancer} -# Include{serviceSelectorExtras} - - variable: ldapmetrics - label: LDAP Metrics Service Port Configuration - schema: - additional_attrs: true - type: dict - attrs: - - variable: port - label: Port - description: This port exposes the container port on the service - schema: - type: int - default: 10232 - required: true -# Include{advancedPortHTTP} - - variable: targetPort - label: Target Port - description: The internal(!) port on the container the Application runs on - schema: - type: int - default: 9302 - variable: proxyhttps label: Proxy HTTPS Service description: The Proxy HTTPS service. @@ -655,64 +544,6 @@ questions: schema: type: int default: 9444 - - variable: proxyhttp - label: Proxy HTTP Service - description: The Proxy HTTP service. - schema: - additional_attrs: true - type: dict - attrs: -# Include{serviceSelectorLoadBalancer} -# Include{serviceSelectorExtras} - - variable: proxyhttp - label: Proxy HTTP Service Port Configuration - schema: - additional_attrs: true - type: dict - attrs: - - variable: port - label: Port - description: This port exposes the container port on the service - schema: - type: int - default: 10234 - required: true -# Include{advancedPortHTTP} - - variable: targetPort - label: Target Port - description: The internal(!) port on the container the Application runs on - schema: - type: int - default: 9001 - - variable: proxymetrics - label: Proxy Metrics Service - description: The Proxy HTTP service. - schema: - additional_attrs: true - type: dict - attrs: -# Include{serviceSelectorLoadBalancer} -# Include{serviceSelectorExtras} - - variable: proxymetrics - label: Proxy Metrics Service Port Configuration - schema: - additional_attrs: true - type: dict - attrs: - - variable: port - label: Port - description: This port exposes the container port on the service - schema: - type: int - default: 10235 - required: true -# Include{advancedPortHTTP} - - variable: targetPort - label: Target Port - description: The internal(!) port on the container the Application runs on - schema: - type: int - default: 9303 # Include{serviceExpertRoot} default: false # Include{serviceExpert} @@ -765,16 +596,6 @@ questions: # Include{ingressDefault} # Include{ingressTLS} # Include{ingressTraefik} -# Include{ingressExpert} - - variable: http - label: HTTP Ingress - schema: - additional_attrs: true - type: dict - attrs: -# Include{ingressDefault} -# Include{ingressTLS} -# Include{ingressTraefik} # Include{ingressExpert} - variable: proxyhttps label: Proxy HTTPS Ingress @@ -785,16 +606,6 @@ questions: # Include{ingressDefault} # Include{ingressTLS} # Include{ingressTraefik} -# Include{ingressExpert} - - variable: proxyhttp - label: Proxy HTTP Ingress - schema: - additional_attrs: true - type: dict - attrs: -# Include{ingressDefault} -# Include{ingressTLS} -# Include{ingressTraefik} # Include{ingressExpert} # Include{ingressList} # Include{security} @@ -841,6 +652,7 @@ questions: default: 568 # Include{podSecurityContextAdvanced} # Include{resources} +# Include{metrics} # Include{advanced} # Include{addons} # Include{documentation} diff --git a/charts/enterprise/authentik/templates/_ldap.tpl b/charts/enterprise/authentik/templates/_ldap.tpl index 57f48995377..0d8f42742b1 100644 --- a/charts/enterprise/authentik/templates/_ldap.tpl +++ b/charts/enterprise/authentik/templates/_ldap.tpl @@ -17,7 +17,7 @@ ports: name: ldapldaps - containerPort: {{ .Values.service.ldapldap.ports.ldapldap.targetPort }} name: ldapldap -{{- if .Values.outposts.ldap.metrics }} +{{- if .Values.metrics.enabled }} - containerPort: {{ .Values.service.ldapmetrics.ports.ldapmetrics.targetPort }} name: ldapmetrics {{- end }} diff --git a/charts/enterprise/authentik/templates/_proxy.tpl b/charts/enterprise/authentik/templates/_proxy.tpl index c056b344cd6..c28161c585c 100644 --- a/charts/enterprise/authentik/templates/_proxy.tpl +++ b/charts/enterprise/authentik/templates/_proxy.tpl @@ -17,7 +17,7 @@ ports: name: proxyhttps - containerPort: {{ .Values.service.proxyhttp.ports.proxyhttp.targetPort }} name: proxyhttp -{{- if .Values.outposts.proxy.metrics }} +{{- if .Values.metrics.enabled }} - containerPort: {{ .Values.service.proxymetrics.ports.proxymetrics.targetPort }} name: proxymetrics {{- end }} diff --git a/charts/enterprise/authentik/templates/common.yaml b/charts/enterprise/authentik/templates/common.yaml index a095675325f..8d610c2e55e 100644 --- a/charts/enterprise/authentik/templates/common.yaml +++ b/charts/enterprise/authentik/templates/common.yaml @@ -7,11 +7,13 @@ {{/* Render config */}} {{- include "authentik.config" . }} -{{- if .Values.authentik.metrics.enabled -}} +{{- if hasKey .Values "metrics" -}} +{{- if .Values.metrics.enabled -}} {{- $_ := set .Values.podAnnotations "prometheus.io/scrape" "true" -}} {{- $_ := set .Values.podAnnotations "prometheus.io/path" "/metrics" -}} {{- $_ := set .Values.podAnnotations "prometheus.io/port" (.Values.service.metrics.ports.metrics.targetPort | default 9301 | quote) -}} {{- end -}} +{{- end -}} {{- if .Values.workerContainer.enabled -}} {{- $_ := set .Values.additionalContainers "worker" (include "authentik.worker" . | fromYaml) -}} @@ -23,7 +25,7 @@ {{- if .Values.outposts.ldap.enabled -}} {{- $_ := set .Values.additionalContainers "ldap-outpost" (include "authentik.ldap" . | fromYaml) -}} -{{/* - if .Values.outposts.ldap.metrics - */}} +{{/* - if .Values.metrics.enabled - */}} {{/* https://github.com/prometheus/prometheus/issues/3756 */}} {{/* TODO: Figure how the pipe works to connect it to prometheus operator */}} {{/* We can't define multiple ports/endpoints with annotations */}} @@ -32,7 +34,7 @@ {{- if .Values.outposts.proxy.enabled -}} {{- $_ := set .Values.additionalContainers "proxy-outpost" (include "authentik.proxy" . | fromYaml) -}} -{{/* - if .Values.outposts.proxy.metrics - */}} +{{/* - if .Values.metrics.enabled - */}} {{/* https://github.com/prometheus/prometheus/issues/3756 */}} {{/* TODO: Figure how the pipe works to connect it to prometheus operator */}} {{/* We can't define multiple ports/endpoints with annotations */}} diff --git a/charts/enterprise/authentik/templates/prometheusrules.yaml b/charts/enterprise/authentik/templates/prometheusrules.yaml new file mode 100644 index 00000000000..b3a37c57c21 --- /dev/null +++ b/charts/enterprise/authentik/templates/prometheusrules.yaml @@ -0,0 +1,160 @@ +{{- if hasKey .Values "metrics" }} +{{- if and .Values.metrics.enabled .Values.metrics.prometheusRule.enabled }} +apiVersion: monitoring.coreos.com/v1 +kind: PrometheusRule +metadata: + name: {{ include "tc.common.names.fullname" . }} + labels: + {{- include "tc.common.labels" . | nindent 4 }} + {{- with .Values.metrics.prometheusRule.labels }} + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + groups: + - name: {{ include "tc.common.names.fullname" . }} + rules: + {{- with .Values.metrics.prometheusRule.rules }} + {{- toYaml . | nindent 8 }} + {{- end }} + {{- if .Values.metrics.prometheusRule.useDefault }} + - name: authentik Aggregate request counters + rules: + - record: job:django_http_requests_before_middlewares_total:sum_rate30s + expr: sum(rate(django_http_requests_before_middlewares_total[30s])) by (job) + - record: job:django_http_requests_unknown_latency_total:sum_rate30s + expr: sum(rate(django_http_requests_unknown_latency_total[30s])) by (job) + - record: job:django_http_ajax_requests_total:sum_rate30s + expr: sum(rate(django_http_ajax_requests_total[30s])) by (job) + - record: job:django_http_responses_before_middlewares_total:sum_rate30s + expr: sum(rate(django_http_responses_before_middlewares_total[30s])) by (job) + - record: job:django_http_requests_unknown_latency_including_middlewares_total:sum_rate30s + expr: sum(rate(django_http_requests_unknown_latency_including_middlewares_total[30s])) by (job) + - record: job:django_http_requests_body_total_bytes:sum_rate30s + expr: sum(rate(django_http_requests_body_total_bytes[30s])) by (job) + - record: job:django_http_responses_streaming_total:sum_rate30s + expr: sum(rate(django_http_responses_streaming_total[30s])) by (job) + - record: job:django_http_responses_body_total_bytes:sum_rate30s + expr: sum(rate(django_http_responses_body_total_bytes[30s])) by (job) + - record: job:django_http_requests_total:sum_rate30s + expr: sum(rate(django_http_requests_total_by_method[30s])) by (job) + - record: job:django_http_requests_total_by_method:sum_rate30s + expr: sum(rate(django_http_requests_total_by_method[30s])) by (job,method) + - record: job:django_http_requests_total_by_transport:sum_rate30s + expr: sum(rate(django_http_requests_total_by_transport[30s])) by (job,transport) + - record: job:django_http_requests_total_by_view:sum_rate30s + expr: sum(rate(django_http_requests_total_by_view_transport_method[30s])) by (job,view) + - record: job:django_http_requests_total_by_view_transport_method:sum_rate30s + expr: sum(rate(django_http_requests_total_by_view_transport_method[30s])) by (job,view,transport,method) + - record: job:django_http_responses_total_by_templatename:sum_rate30s + expr: sum(rate(django_http_responses_total_by_templatename[30s])) by (job,templatename) + - record: job:django_http_responses_total_by_status:sum_rate30s + expr: sum(rate(django_http_responses_total_by_status[30s])) by (job,status) + - record: job:django_http_responses_total_by_status_name_method:sum_rate30s + expr: sum(rate(django_http_responses_total_by_status_name_method[30s])) by (job,status,name,method) + - record: job:django_http_responses_total_by_charset:sum_rate30s + expr: sum(rate(django_http_responses_total_by_charset[30s])) by (job,charset) + - record: job:django_http_exceptions_total_by_type:sum_rate30s + expr: sum(rate(django_http_exceptions_total_by_type[30s])) by (job,type) + - record: job:django_http_exceptions_total_by_view:sum_rate30s + expr: sum(rate(django_http_exceptions_total_by_view[30s])) by (job,view) + - name: authentik Aggregate latency histograms + rules: + - record: job:django_http_requests_latency_including_middlewares_seconds:quantile_rate30s + expr: histogram_quantile(0.50, sum(rate(django_http_requests_latency_including_middlewares_seconds_bucket[30s])) by (job, le)) + labels: + quantile: "50" + - record: job:django_http_requests_latency_including_middlewares_seconds:quantile_rate30s + expr: histogram_quantile(0.95, sum(rate(django_http_requests_latency_including_middlewares_seconds_bucket[30s])) by (job, le)) + labels: + quantile: "95" + - record: job:django_http_requests_latency_including_middlewares_seconds:quantile_rate30s + expr: histogram_quantile(0.99, sum(rate(django_http_requests_latency_including_middlewares_seconds_bucket[30s])) by (job, le)) + labels: + quantile: "99" + - record: job:django_http_requests_latency_including_middlewares_seconds:quantile_rate30s + expr: histogram_quantile(0.999, sum(rate(django_http_requests_latency_including_middlewares_seconds_bucket[30s])) by (job, le)) + labels: + quantile: "99.9" + - record: job:django_http_requests_latency_seconds:quantile_rate30s + expr: histogram_quantile(0.50, sum(rate(django_http_requests_latency_seconds_bucket[30s])) by (job, le)) + labels: + quantile: "50" + - record: job:django_http_requests_latency_seconds:quantile_rate30s + expr: histogram_quantile(0.95, sum(rate(django_http_requests_latency_seconds_bucket[30s])) by (job, le)) + labels: + quantile: "95" + - record: job:django_http_requests_latency_seconds:quantile_rate30s + expr: histogram_quantile(0.99, sum(rate(django_http_requests_latency_seconds_bucket[30s])) by (job, le)) + labels: + quantile: "99" + - record: job:django_http_requests_latency_seconds:quantile_rate30s + expr: histogram_quantile(0.999, sum(rate(django_http_requests_latency_seconds_bucket[30s])) by (job, le)) + labels: + quantile: "99.9" + - name: authentik Aggregate model operations + rules: + - record: job:django_model_inserts_total:sum_rate1m + expr: sum(rate(django_model_inserts_total[1m])) by (job, model) + - record: job:django_model_updates_total:sum_rate1m + expr: sum(rate(django_model_updates_total[1m])) by (job, model) + - record: job:django_model_deletes_total:sum_rate1m + expr: sum(rate(django_model_deletes_total[1m])) by (job, model) + - name: authentik Aggregate database operations + rules: + - record: job:django_db_new_connections_total:sum_rate30s + expr: sum(rate(django_db_new_connections_total[30s])) by (alias, vendor) + - record: job:django_db_new_connection_errors_total:sum_rate30s + expr: sum(rate(django_db_new_connection_errors_total[30s])) by (alias, vendor) + - record: job:django_db_execute_total:sum_rate30s + expr: sum(rate(django_db_execute_total[30s])) by (alias, vendor) + - record: job:django_db_execute_many_total:sum_rate30s + expr: sum(rate(django_db_execute_many_total[30s])) by (alias, vendor) + - record: job:django_db_errors_total:sum_rate30s + expr: sum(rate(django_db_errors_total[30s])) by (alias, vendor, type) + - name: authentik Aggregate migrations + rules: + - record: job:django_migrations_applied_total:max + expr: max(django_migrations_applied_total) by (job, connection) + - record: job:django_migrations_unapplied_total:max + expr: max(django_migrations_unapplied_total) by (job, connection) + - name: authentik Alerts + rules: + - alert: NoWorkersConnected + expr: max without (pid) (authentik_admin_workers) < 1 + annotations: + message: | + authentik instance {{ printf "{{ $labels.instance }}" }}'s worker are either not running or not connected. + summary: No workers connected + for: 10m + labels: + severity: critical + - alert: PendingMigrations + expr: max without (pid) (django_migrations_unapplied_total) > 0 + annotations: + message: | + authentik instance {{ printf "{{ $labels.instance }}" }} has pending database migrations + summary: Pending database migrations + for: 10m + labels: + severity: critical + - alert: FailedSystemTasks + expr: sum(increase(authentik_system_tasks{status="TaskResultStatus.ERROR"}[2h])) > 0 + annotations: + message: | + System task {{ printf "{{ $labels.task_name }}" }} has failed + summary: Failed system tasks + for: 2h + labels: + severity: critical + - alert: DisconnectedOutposts + expr: sum by (outpost) (max without (pid) (authentik_outposts_connected{uid!~"specific.*"})) < 1 + annotations: + message: | + Outpost {{ printf "{{ $labels.outpost }}" }} has at least 1 disconnected instance + summary: Disconnected outpost + for: 30m + labels: + severity: critical + {{- end }} +{{- end }} +{{- end }} diff --git a/charts/enterprise/authentik/templates/servicemonitor.yaml b/charts/enterprise/authentik/templates/servicemonitor.yaml new file mode 100644 index 00000000000..afa560ff34e --- /dev/null +++ b/charts/enterprise/authentik/templates/servicemonitor.yaml @@ -0,0 +1,44 @@ +{{- if hasKey .Values "metrics" }} +{{- if .Values.metrics.enabled }} +apiVersion: monitoring.coreos.com/v1 +kind: ServiceMonitor +metadata: + name: {{ include "tc.common.names.fullname" . }} + labels: + {{- include "tc.common.labels" . | nindent 4 }} + {{- with .Values.metrics.serviceMonitor.labels }} + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + selector: + matchLabels: + {{- include "tc.common.labels.selectorLabels" . | nindent 6 }} + endpoints: + - port: metrics + {{- with .Values.metrics.serviceMonitor.interval }} + interval: {{ . }} + {{- end }} + {{- with .Values.metrics.serviceMonitor.scrapeTimeout }} + scrapeTimeout: {{ . }} + {{- end }} + path: /metrics + + - port: ldapmetrics + {{- with .Values.metrics.serviceMonitor.interval }} + interval: {{ . }} + {{- end }} + {{- with .Values.metrics.serviceMonitor.scrapeTimeout }} + scrapeTimeout: {{ . }} + {{- end }} + path: /metrics + + - port: proxymetrics + {{- with .Values.metrics.serviceMonitor.interval }} + interval: {{ . }} + {{- end }} + {{- with .Values.metrics.serviceMonitor.scrapeTimeout }} + scrapeTimeout: {{ . }} + {{- end }} + path: /metrics +{{- end }} +{{- end }} diff --git a/charts/enterprise/authentik/values.yaml b/charts/enterprise/authentik/values.yaml index a3b93f2e695..f869883d908 100644 --- a/charts/enterprise/authentik/values.yaml +++ b/charts/enterprise/authentik/values.yaml @@ -62,9 +62,6 @@ authentik: log_level: "info" ldap: tls_ciphers: "null" - metrics: - enabled: true - geoip: enabled: false account_id: "" @@ -89,7 +86,6 @@ outposts: # insecure: false # -- Token is only needed if you accidentally deleted the token within the UI # token: "" - metrics: false proxy: # -- First you have to create an Outpost in the GUI. Applications > Outposts enabled: false @@ -101,7 +97,34 @@ outposts: # host: "" # -- Token is only needed if you accidentally deleted the token within the UI # token: "" - metrics: false + +metrics: + # -- Enable and configure a Prometheus serviceMonitor for the chart under this key. + # @default -- See values.yaml + enabled: false + serviceMonitor: + interval: 1m + scrapeTimeout: 30s + labels: {} + # -- Enable and configure Prometheus Rules for the chart under this key. + # @default -- See values.yaml + prometheusRule: + enabled: false + useDefault: true + labels: {} + # -- Configure additional rules for the chart under this key. + # @default -- See prometheusrules.yaml + rules: + [] + # - alert: UnifiPollerAbsent + # annotations: + # description: Unifi Poller has disappeared from Prometheus service discovery. + # summary: Unifi Poller is down. + # expr: | + # absent(up{job=~".*unifi-poller.*"} == 1) + # for: 5m + # labels: + # severity: critical envFrom: - secretRef: @@ -113,17 +136,17 @@ envFrom: probes: liveness: - type: HTTP + type: HTTPS path: /-/health/live/ - port: "{{ .Values.service.http.ports.http.targetPort }}" + port: "{{ .Values.service.main.ports.main.targetPort }}" readiness: - type: HTTP + type: HTTPS path: /-/health/ready/ - port: "{{ .Values.service.http.ports.http.targetPort }}" + port: "{{ .Values.service.main.ports.main.targetPort }}" startup: - type: HTTP + type: HTTPS path: /-/health/ready/ - port: "{{ .Values.service.http.ports.http.targetPort }}" + port: "{{ .Values.service.main.ports.main.targetPort }}" service: main: @@ -134,23 +157,16 @@ service: targetPort: 9443 http: enabled: true + type: ClusterIP ports: http: enabled: true protocol: HTTP port: 10230 targetPort: 9000 - metrics: - enabled: true - ports: - metrics: - enabled: true - protocol: HTTP - port: 10231 - targetPort: 9301 + # LDAP Outpost Services ldapldaps: enabled: true - type: ClusterIP ports: ldapldaps: enabled: true @@ -158,24 +174,14 @@ service: targetPort: 6636 ldapldap: enabled: true - type: ClusterIP ports: ldapldap: enabled: true port: 389 targetPort: 3389 - ldapmetrics: - enabled: true - type: ClusterIP - ports: - ldapmetrics: - enabled: true - port: 10232 - protocol: HTTP - targetPort: 9302 + # Proxy Outpost Services proxyhttps: enabled: true - type: ClusterIP ports: proxyhttps: enabled: true @@ -189,8 +195,27 @@ service: proxyhttp: enabled: true port: 10234 - protocl: HTTP + protocol: HTTP targetPort: 9001 + # Metrics Services + metrics: + enabled: true + type: ClusterIP + ports: + metrics: + enabled: true + protocol: HTTP + port: 10231 + targetPort: 9301 + ldapmetrics: + enabled: true + type: ClusterIP + ports: + ldapmetrics: + enabled: true + port: 10232 + protocol: HTTP + targetPort: 9302 proxymetrics: enabled: true type: ClusterIP @@ -202,12 +227,8 @@ service: targetPort: 9303 ingress: - http: - autoLink: true proxyhttps: autoLink: true - proxyhttp: - autoLink: true persistence: media: