feat(authentik): cleanup GUI from unnecessary services/ingresses and add serviceMonitor and prometheusRule (#3961)
* chore(authentik): cleanup services and ingresses. * add service monitor * change port names * default to flase * test metrics enabled * pre-commit * add prometheus rules * bump * lint * revert probe * use standardized metrics ui * mistake * on upgrades there is no "metrics" key yet * one more
This commit is contained in:
@@ -27,7 +27,7 @@ sources:
|
|||||||
- https://github.com/truecharts/charts/tree/master/charts/enterprise/authentik
|
- https://github.com/truecharts/charts/tree/master/charts/enterprise/authentik
|
||||||
- https://github.com/goauthentik/authentik
|
- https://github.com/goauthentik/authentik
|
||||||
- https://goauthentik.io/docs/
|
- https://goauthentik.io/docs/
|
||||||
version: 7.0.2
|
version: 7.1.0
|
||||||
annotations:
|
annotations:
|
||||||
truecharts.org/catagories: |
|
truecharts.org/catagories: |
|
||||||
- authentication
|
- authentication
|
||||||
|
|||||||
@@ -203,18 +203,6 @@ questions:
|
|||||||
description: warning
|
description: warning
|
||||||
- value: error
|
- value: error
|
||||||
description: error
|
description: error
|
||||||
- variable: metrics
|
|
||||||
label: Metrics
|
|
||||||
schema:
|
|
||||||
additional_attrs: true
|
|
||||||
type: dict
|
|
||||||
attrs:
|
|
||||||
- variable: enabled
|
|
||||||
label: Metrics Endpoint
|
|
||||||
description: Enables metrics endpoint for Authentik and embedded outpost
|
|
||||||
schema:
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
- variable: ldap
|
- variable: ldap
|
||||||
label: LDAP
|
label: LDAP
|
||||||
schema:
|
schema:
|
||||||
@@ -298,12 +286,6 @@ questions:
|
|||||||
type: string
|
type: string
|
||||||
required: true
|
required: true
|
||||||
default: ""
|
default: ""
|
||||||
- variable: metrics
|
|
||||||
label: Metrics Endpoint
|
|
||||||
description: Enables metric endpoint in LDAP Outpost
|
|
||||||
schema:
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
- variable: proxy
|
- variable: proxy
|
||||||
label: Proxy
|
label: Proxy
|
||||||
schema:
|
schema:
|
||||||
@@ -368,12 +350,6 @@ questions:
|
|||||||
type: string
|
type: string
|
||||||
required: true
|
required: true
|
||||||
default: ""
|
default: ""
|
||||||
- variable: metrics
|
|
||||||
label: Metrics Endpoint
|
|
||||||
description: Enables metric endpoint in Proxy Outpost
|
|
||||||
schema:
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
- variable: geoip
|
- variable: geoip
|
||||||
group: Container Configuration
|
group: Container Configuration
|
||||||
label: GeoIP Configuration
|
label: GeoIP Configuration
|
||||||
@@ -481,64 +457,6 @@ questions:
|
|||||||
schema:
|
schema:
|
||||||
type: int
|
type: int
|
||||||
default: 9443
|
default: 9443
|
||||||
- variable: http
|
|
||||||
label: http Service
|
|
||||||
description: The http service.
|
|
||||||
schema:
|
|
||||||
additional_attrs: true
|
|
||||||
type: dict
|
|
||||||
attrs:
|
|
||||||
# Include{serviceSelectorLoadBalancer}
|
|
||||||
# Include{serviceSelectorExtras}
|
|
||||||
- variable: http
|
|
||||||
label: http Service Port Configuration
|
|
||||||
schema:
|
|
||||||
additional_attrs: true
|
|
||||||
type: dict
|
|
||||||
attrs:
|
|
||||||
- variable: port
|
|
||||||
label: Port
|
|
||||||
description: This port exposes the container port on the service
|
|
||||||
schema:
|
|
||||||
type: int
|
|
||||||
default: 10230
|
|
||||||
required: true
|
|
||||||
# Include{advancedPortHTTP}
|
|
||||||
- variable: targetPort
|
|
||||||
label: Target Port
|
|
||||||
description: The internal(!) port on the container the Application runs on
|
|
||||||
schema:
|
|
||||||
type: int
|
|
||||||
default: 9000
|
|
||||||
- variable: metrics
|
|
||||||
label: metrics Service
|
|
||||||
description: The metrics service.
|
|
||||||
schema:
|
|
||||||
additional_attrs: true
|
|
||||||
type: dict
|
|
||||||
attrs:
|
|
||||||
# Include{serviceSelectorLoadBalancer}
|
|
||||||
# Include{serviceSelectorExtras}
|
|
||||||
- variable: metrics
|
|
||||||
label: metrics Service Port Configuration
|
|
||||||
schema:
|
|
||||||
additional_attrs: true
|
|
||||||
type: dict
|
|
||||||
attrs:
|
|
||||||
- variable: port
|
|
||||||
label: Port
|
|
||||||
description: This port exposes the container port on the service
|
|
||||||
schema:
|
|
||||||
type: int
|
|
||||||
default: 10231
|
|
||||||
required: true
|
|
||||||
# Include{advancedPortHTTP}
|
|
||||||
- variable: targetPort
|
|
||||||
label: Target Port
|
|
||||||
description: The internal(!) port on the container the Application runs on
|
|
||||||
schema:
|
|
||||||
type: int
|
|
||||||
default: 9301
|
|
||||||
- variable: ldapldaps
|
- variable: ldapldaps
|
||||||
label: LDAPS Service
|
label: LDAPS Service
|
||||||
description: The LDAPS service.
|
description: The LDAPS service.
|
||||||
@@ -597,35 +515,6 @@ questions:
|
|||||||
schema:
|
schema:
|
||||||
type: int
|
type: int
|
||||||
default: 3389
|
default: 3389
|
||||||
- variable: ldapmetrics
|
|
||||||
label: LDAP Metrics Service
|
|
||||||
description: The LDAP Metrics service.
|
|
||||||
schema:
|
|
||||||
additional_attrs: true
|
|
||||||
type: dict
|
|
||||||
attrs:
|
|
||||||
# Include{serviceSelectorLoadBalancer}
|
|
||||||
# Include{serviceSelectorExtras}
|
|
||||||
- variable: ldapmetrics
|
|
||||||
label: LDAP Metrics Service Port Configuration
|
|
||||||
schema:
|
|
||||||
additional_attrs: true
|
|
||||||
type: dict
|
|
||||||
attrs:
|
|
||||||
- variable: port
|
|
||||||
label: Port
|
|
||||||
description: This port exposes the container port on the service
|
|
||||||
schema:
|
|
||||||
type: int
|
|
||||||
default: 10232
|
|
||||||
required: true
|
|
||||||
# Include{advancedPortHTTP}
|
|
||||||
- variable: targetPort
|
|
||||||
label: Target Port
|
|
||||||
description: The internal(!) port on the container the Application runs on
|
|
||||||
schema:
|
|
||||||
type: int
|
|
||||||
default: 9302
|
|
||||||
- variable: proxyhttps
|
- variable: proxyhttps
|
||||||
label: Proxy HTTPS Service
|
label: Proxy HTTPS Service
|
||||||
description: The Proxy HTTPS service.
|
description: The Proxy HTTPS service.
|
||||||
@@ -655,64 +544,6 @@ questions:
|
|||||||
schema:
|
schema:
|
||||||
type: int
|
type: int
|
||||||
default: 9444
|
default: 9444
|
||||||
- variable: proxyhttp
|
|
||||||
label: Proxy HTTP Service
|
|
||||||
description: The Proxy HTTP service.
|
|
||||||
schema:
|
|
||||||
additional_attrs: true
|
|
||||||
type: dict
|
|
||||||
attrs:
|
|
||||||
# Include{serviceSelectorLoadBalancer}
|
|
||||||
# Include{serviceSelectorExtras}
|
|
||||||
- variable: proxyhttp
|
|
||||||
label: Proxy HTTP Service Port Configuration
|
|
||||||
schema:
|
|
||||||
additional_attrs: true
|
|
||||||
type: dict
|
|
||||||
attrs:
|
|
||||||
- variable: port
|
|
||||||
label: Port
|
|
||||||
description: This port exposes the container port on the service
|
|
||||||
schema:
|
|
||||||
type: int
|
|
||||||
default: 10234
|
|
||||||
required: true
|
|
||||||
# Include{advancedPortHTTP}
|
|
||||||
- variable: targetPort
|
|
||||||
label: Target Port
|
|
||||||
description: The internal(!) port on the container the Application runs on
|
|
||||||
schema:
|
|
||||||
type: int
|
|
||||||
default: 9001
|
|
||||||
- variable: proxymetrics
|
|
||||||
label: Proxy Metrics Service
|
|
||||||
description: The Proxy HTTP service.
|
|
||||||
schema:
|
|
||||||
additional_attrs: true
|
|
||||||
type: dict
|
|
||||||
attrs:
|
|
||||||
# Include{serviceSelectorLoadBalancer}
|
|
||||||
# Include{serviceSelectorExtras}
|
|
||||||
- variable: proxymetrics
|
|
||||||
label: Proxy Metrics Service Port Configuration
|
|
||||||
schema:
|
|
||||||
additional_attrs: true
|
|
||||||
type: dict
|
|
||||||
attrs:
|
|
||||||
- variable: port
|
|
||||||
label: Port
|
|
||||||
description: This port exposes the container port on the service
|
|
||||||
schema:
|
|
||||||
type: int
|
|
||||||
default: 10235
|
|
||||||
required: true
|
|
||||||
# Include{advancedPortHTTP}
|
|
||||||
- variable: targetPort
|
|
||||||
label: Target Port
|
|
||||||
description: The internal(!) port on the container the Application runs on
|
|
||||||
schema:
|
|
||||||
type: int
|
|
||||||
default: 9303
|
|
||||||
# Include{serviceExpertRoot}
|
# Include{serviceExpertRoot}
|
||||||
default: false
|
default: false
|
||||||
# Include{serviceExpert}
|
# Include{serviceExpert}
|
||||||
@@ -765,16 +596,6 @@ questions:
|
|||||||
# Include{ingressDefault}
|
# Include{ingressDefault}
|
||||||
# Include{ingressTLS}
|
# Include{ingressTLS}
|
||||||
# Include{ingressTraefik}
|
# Include{ingressTraefik}
|
||||||
# Include{ingressExpert}
|
|
||||||
- variable: http
|
|
||||||
label: HTTP Ingress
|
|
||||||
schema:
|
|
||||||
additional_attrs: true
|
|
||||||
type: dict
|
|
||||||
attrs:
|
|
||||||
# Include{ingressDefault}
|
|
||||||
# Include{ingressTLS}
|
|
||||||
# Include{ingressTraefik}
|
|
||||||
# Include{ingressExpert}
|
# Include{ingressExpert}
|
||||||
- variable: proxyhttps
|
- variable: proxyhttps
|
||||||
label: Proxy HTTPS Ingress
|
label: Proxy HTTPS Ingress
|
||||||
@@ -785,16 +606,6 @@ questions:
|
|||||||
# Include{ingressDefault}
|
# Include{ingressDefault}
|
||||||
# Include{ingressTLS}
|
# Include{ingressTLS}
|
||||||
# Include{ingressTraefik}
|
# Include{ingressTraefik}
|
||||||
# Include{ingressExpert}
|
|
||||||
- variable: proxyhttp
|
|
||||||
label: Proxy HTTP Ingress
|
|
||||||
schema:
|
|
||||||
additional_attrs: true
|
|
||||||
type: dict
|
|
||||||
attrs:
|
|
||||||
# Include{ingressDefault}
|
|
||||||
# Include{ingressTLS}
|
|
||||||
# Include{ingressTraefik}
|
|
||||||
# Include{ingressExpert}
|
# Include{ingressExpert}
|
||||||
# Include{ingressList}
|
# Include{ingressList}
|
||||||
# Include{security}
|
# Include{security}
|
||||||
@@ -841,6 +652,7 @@ questions:
|
|||||||
default: 568
|
default: 568
|
||||||
# Include{podSecurityContextAdvanced}
|
# Include{podSecurityContextAdvanced}
|
||||||
# Include{resources}
|
# Include{resources}
|
||||||
|
# Include{metrics}
|
||||||
# Include{advanced}
|
# Include{advanced}
|
||||||
# Include{addons}
|
# Include{addons}
|
||||||
# Include{documentation}
|
# Include{documentation}
|
||||||
|
|||||||
@@ -17,7 +17,7 @@ ports:
|
|||||||
name: ldapldaps
|
name: ldapldaps
|
||||||
- containerPort: {{ .Values.service.ldapldap.ports.ldapldap.targetPort }}
|
- containerPort: {{ .Values.service.ldapldap.ports.ldapldap.targetPort }}
|
||||||
name: ldapldap
|
name: ldapldap
|
||||||
{{- if .Values.outposts.ldap.metrics }}
|
{{- if .Values.metrics.enabled }}
|
||||||
- containerPort: {{ .Values.service.ldapmetrics.ports.ldapmetrics.targetPort }}
|
- containerPort: {{ .Values.service.ldapmetrics.ports.ldapmetrics.targetPort }}
|
||||||
name: ldapmetrics
|
name: ldapmetrics
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|||||||
@@ -17,7 +17,7 @@ ports:
|
|||||||
name: proxyhttps
|
name: proxyhttps
|
||||||
- containerPort: {{ .Values.service.proxyhttp.ports.proxyhttp.targetPort }}
|
- containerPort: {{ .Values.service.proxyhttp.ports.proxyhttp.targetPort }}
|
||||||
name: proxyhttp
|
name: proxyhttp
|
||||||
{{- if .Values.outposts.proxy.metrics }}
|
{{- if .Values.metrics.enabled }}
|
||||||
- containerPort: {{ .Values.service.proxymetrics.ports.proxymetrics.targetPort }}
|
- containerPort: {{ .Values.service.proxymetrics.ports.proxymetrics.targetPort }}
|
||||||
name: proxymetrics
|
name: proxymetrics
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|||||||
@@ -7,11 +7,13 @@
|
|||||||
{{/* Render config */}}
|
{{/* Render config */}}
|
||||||
{{- include "authentik.config" . }}
|
{{- include "authentik.config" . }}
|
||||||
|
|
||||||
{{- if .Values.authentik.metrics.enabled -}}
|
{{- if hasKey .Values "metrics" -}}
|
||||||
|
{{- if .Values.metrics.enabled -}}
|
||||||
{{- $_ := set .Values.podAnnotations "prometheus.io/scrape" "true" -}}
|
{{- $_ := set .Values.podAnnotations "prometheus.io/scrape" "true" -}}
|
||||||
{{- $_ := set .Values.podAnnotations "prometheus.io/path" "/metrics" -}}
|
{{- $_ := set .Values.podAnnotations "prometheus.io/path" "/metrics" -}}
|
||||||
{{- $_ := set .Values.podAnnotations "prometheus.io/port" (.Values.service.metrics.ports.metrics.targetPort | default 9301 | quote) -}}
|
{{- $_ := set .Values.podAnnotations "prometheus.io/port" (.Values.service.metrics.ports.metrics.targetPort | default 9301 | quote) -}}
|
||||||
{{- end -}}
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
{{- if .Values.workerContainer.enabled -}}
|
{{- if .Values.workerContainer.enabled -}}
|
||||||
{{- $_ := set .Values.additionalContainers "worker" (include "authentik.worker" . | fromYaml) -}}
|
{{- $_ := set .Values.additionalContainers "worker" (include "authentik.worker" . | fromYaml) -}}
|
||||||
@@ -23,7 +25,7 @@
|
|||||||
|
|
||||||
{{- if .Values.outposts.ldap.enabled -}}
|
{{- if .Values.outposts.ldap.enabled -}}
|
||||||
{{- $_ := set .Values.additionalContainers "ldap-outpost" (include "authentik.ldap" . | fromYaml) -}}
|
{{- $_ := set .Values.additionalContainers "ldap-outpost" (include "authentik.ldap" . | fromYaml) -}}
|
||||||
{{/* - if .Values.outposts.ldap.metrics - */}}
|
{{/* - if .Values.metrics.enabled - */}}
|
||||||
{{/* https://github.com/prometheus/prometheus/issues/3756 */}}
|
{{/* https://github.com/prometheus/prometheus/issues/3756 */}}
|
||||||
{{/* TODO: Figure how the pipe works to connect it to prometheus operator */}}
|
{{/* TODO: Figure how the pipe works to connect it to prometheus operator */}}
|
||||||
{{/* We can't define multiple ports/endpoints with annotations */}}
|
{{/* We can't define multiple ports/endpoints with annotations */}}
|
||||||
@@ -32,7 +34,7 @@
|
|||||||
|
|
||||||
{{- if .Values.outposts.proxy.enabled -}}
|
{{- if .Values.outposts.proxy.enabled -}}
|
||||||
{{- $_ := set .Values.additionalContainers "proxy-outpost" (include "authentik.proxy" . | fromYaml) -}}
|
{{- $_ := set .Values.additionalContainers "proxy-outpost" (include "authentik.proxy" . | fromYaml) -}}
|
||||||
{{/* - if .Values.outposts.proxy.metrics - */}}
|
{{/* - if .Values.metrics.enabled - */}}
|
||||||
{{/* https://github.com/prometheus/prometheus/issues/3756 */}}
|
{{/* https://github.com/prometheus/prometheus/issues/3756 */}}
|
||||||
{{/* TODO: Figure how the pipe works to connect it to prometheus operator */}}
|
{{/* TODO: Figure how the pipe works to connect it to prometheus operator */}}
|
||||||
{{/* We can't define multiple ports/endpoints with annotations */}}
|
{{/* We can't define multiple ports/endpoints with annotations */}}
|
||||||
|
|||||||
@@ -0,0 +1,160 @@
|
|||||||
|
{{- if hasKey .Values "metrics" }}
|
||||||
|
{{- if and .Values.metrics.enabled .Values.metrics.prometheusRule.enabled }}
|
||||||
|
apiVersion: monitoring.coreos.com/v1
|
||||||
|
kind: PrometheusRule
|
||||||
|
metadata:
|
||||||
|
name: {{ include "tc.common.names.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "tc.common.labels" . | nindent 4 }}
|
||||||
|
{{- with .Values.metrics.prometheusRule.labels }}
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
groups:
|
||||||
|
- name: {{ include "tc.common.names.fullname" . }}
|
||||||
|
rules:
|
||||||
|
{{- with .Values.metrics.prometheusRule.rules }}
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.metrics.prometheusRule.useDefault }}
|
||||||
|
- name: authentik Aggregate request counters
|
||||||
|
rules:
|
||||||
|
- record: job:django_http_requests_before_middlewares_total:sum_rate30s
|
||||||
|
expr: sum(rate(django_http_requests_before_middlewares_total[30s])) by (job)
|
||||||
|
- record: job:django_http_requests_unknown_latency_total:sum_rate30s
|
||||||
|
expr: sum(rate(django_http_requests_unknown_latency_total[30s])) by (job)
|
||||||
|
- record: job:django_http_ajax_requests_total:sum_rate30s
|
||||||
|
expr: sum(rate(django_http_ajax_requests_total[30s])) by (job)
|
||||||
|
- record: job:django_http_responses_before_middlewares_total:sum_rate30s
|
||||||
|
expr: sum(rate(django_http_responses_before_middlewares_total[30s])) by (job)
|
||||||
|
- record: job:django_http_requests_unknown_latency_including_middlewares_total:sum_rate30s
|
||||||
|
expr: sum(rate(django_http_requests_unknown_latency_including_middlewares_total[30s])) by (job)
|
||||||
|
- record: job:django_http_requests_body_total_bytes:sum_rate30s
|
||||||
|
expr: sum(rate(django_http_requests_body_total_bytes[30s])) by (job)
|
||||||
|
- record: job:django_http_responses_streaming_total:sum_rate30s
|
||||||
|
expr: sum(rate(django_http_responses_streaming_total[30s])) by (job)
|
||||||
|
- record: job:django_http_responses_body_total_bytes:sum_rate30s
|
||||||
|
expr: sum(rate(django_http_responses_body_total_bytes[30s])) by (job)
|
||||||
|
- record: job:django_http_requests_total:sum_rate30s
|
||||||
|
expr: sum(rate(django_http_requests_total_by_method[30s])) by (job)
|
||||||
|
- record: job:django_http_requests_total_by_method:sum_rate30s
|
||||||
|
expr: sum(rate(django_http_requests_total_by_method[30s])) by (job,method)
|
||||||
|
- record: job:django_http_requests_total_by_transport:sum_rate30s
|
||||||
|
expr: sum(rate(django_http_requests_total_by_transport[30s])) by (job,transport)
|
||||||
|
- record: job:django_http_requests_total_by_view:sum_rate30s
|
||||||
|
expr: sum(rate(django_http_requests_total_by_view_transport_method[30s])) by (job,view)
|
||||||
|
- record: job:django_http_requests_total_by_view_transport_method:sum_rate30s
|
||||||
|
expr: sum(rate(django_http_requests_total_by_view_transport_method[30s])) by (job,view,transport,method)
|
||||||
|
- record: job:django_http_responses_total_by_templatename:sum_rate30s
|
||||||
|
expr: sum(rate(django_http_responses_total_by_templatename[30s])) by (job,templatename)
|
||||||
|
- record: job:django_http_responses_total_by_status:sum_rate30s
|
||||||
|
expr: sum(rate(django_http_responses_total_by_status[30s])) by (job,status)
|
||||||
|
- record: job:django_http_responses_total_by_status_name_method:sum_rate30s
|
||||||
|
expr: sum(rate(django_http_responses_total_by_status_name_method[30s])) by (job,status,name,method)
|
||||||
|
- record: job:django_http_responses_total_by_charset:sum_rate30s
|
||||||
|
expr: sum(rate(django_http_responses_total_by_charset[30s])) by (job,charset)
|
||||||
|
- record: job:django_http_exceptions_total_by_type:sum_rate30s
|
||||||
|
expr: sum(rate(django_http_exceptions_total_by_type[30s])) by (job,type)
|
||||||
|
- record: job:django_http_exceptions_total_by_view:sum_rate30s
|
||||||
|
expr: sum(rate(django_http_exceptions_total_by_view[30s])) by (job,view)
|
||||||
|
- name: authentik Aggregate latency histograms
|
||||||
|
rules:
|
||||||
|
- record: job:django_http_requests_latency_including_middlewares_seconds:quantile_rate30s
|
||||||
|
expr: histogram_quantile(0.50, sum(rate(django_http_requests_latency_including_middlewares_seconds_bucket[30s])) by (job, le))
|
||||||
|
labels:
|
||||||
|
quantile: "50"
|
||||||
|
- record: job:django_http_requests_latency_including_middlewares_seconds:quantile_rate30s
|
||||||
|
expr: histogram_quantile(0.95, sum(rate(django_http_requests_latency_including_middlewares_seconds_bucket[30s])) by (job, le))
|
||||||
|
labels:
|
||||||
|
quantile: "95"
|
||||||
|
- record: job:django_http_requests_latency_including_middlewares_seconds:quantile_rate30s
|
||||||
|
expr: histogram_quantile(0.99, sum(rate(django_http_requests_latency_including_middlewares_seconds_bucket[30s])) by (job, le))
|
||||||
|
labels:
|
||||||
|
quantile: "99"
|
||||||
|
- record: job:django_http_requests_latency_including_middlewares_seconds:quantile_rate30s
|
||||||
|
expr: histogram_quantile(0.999, sum(rate(django_http_requests_latency_including_middlewares_seconds_bucket[30s])) by (job, le))
|
||||||
|
labels:
|
||||||
|
quantile: "99.9"
|
||||||
|
- record: job:django_http_requests_latency_seconds:quantile_rate30s
|
||||||
|
expr: histogram_quantile(0.50, sum(rate(django_http_requests_latency_seconds_bucket[30s])) by (job, le))
|
||||||
|
labels:
|
||||||
|
quantile: "50"
|
||||||
|
- record: job:django_http_requests_latency_seconds:quantile_rate30s
|
||||||
|
expr: histogram_quantile(0.95, sum(rate(django_http_requests_latency_seconds_bucket[30s])) by (job, le))
|
||||||
|
labels:
|
||||||
|
quantile: "95"
|
||||||
|
- record: job:django_http_requests_latency_seconds:quantile_rate30s
|
||||||
|
expr: histogram_quantile(0.99, sum(rate(django_http_requests_latency_seconds_bucket[30s])) by (job, le))
|
||||||
|
labels:
|
||||||
|
quantile: "99"
|
||||||
|
- record: job:django_http_requests_latency_seconds:quantile_rate30s
|
||||||
|
expr: histogram_quantile(0.999, sum(rate(django_http_requests_latency_seconds_bucket[30s])) by (job, le))
|
||||||
|
labels:
|
||||||
|
quantile: "99.9"
|
||||||
|
- name: authentik Aggregate model operations
|
||||||
|
rules:
|
||||||
|
- record: job:django_model_inserts_total:sum_rate1m
|
||||||
|
expr: sum(rate(django_model_inserts_total[1m])) by (job, model)
|
||||||
|
- record: job:django_model_updates_total:sum_rate1m
|
||||||
|
expr: sum(rate(django_model_updates_total[1m])) by (job, model)
|
||||||
|
- record: job:django_model_deletes_total:sum_rate1m
|
||||||
|
expr: sum(rate(django_model_deletes_total[1m])) by (job, model)
|
||||||
|
- name: authentik Aggregate database operations
|
||||||
|
rules:
|
||||||
|
- record: job:django_db_new_connections_total:sum_rate30s
|
||||||
|
expr: sum(rate(django_db_new_connections_total[30s])) by (alias, vendor)
|
||||||
|
- record: job:django_db_new_connection_errors_total:sum_rate30s
|
||||||
|
expr: sum(rate(django_db_new_connection_errors_total[30s])) by (alias, vendor)
|
||||||
|
- record: job:django_db_execute_total:sum_rate30s
|
||||||
|
expr: sum(rate(django_db_execute_total[30s])) by (alias, vendor)
|
||||||
|
- record: job:django_db_execute_many_total:sum_rate30s
|
||||||
|
expr: sum(rate(django_db_execute_many_total[30s])) by (alias, vendor)
|
||||||
|
- record: job:django_db_errors_total:sum_rate30s
|
||||||
|
expr: sum(rate(django_db_errors_total[30s])) by (alias, vendor, type)
|
||||||
|
- name: authentik Aggregate migrations
|
||||||
|
rules:
|
||||||
|
- record: job:django_migrations_applied_total:max
|
||||||
|
expr: max(django_migrations_applied_total) by (job, connection)
|
||||||
|
- record: job:django_migrations_unapplied_total:max
|
||||||
|
expr: max(django_migrations_unapplied_total) by (job, connection)
|
||||||
|
- name: authentik Alerts
|
||||||
|
rules:
|
||||||
|
- alert: NoWorkersConnected
|
||||||
|
expr: max without (pid) (authentik_admin_workers) < 1
|
||||||
|
annotations:
|
||||||
|
message: |
|
||||||
|
authentik instance {{ printf "{{ $labels.instance }}" }}'s worker are either not running or not connected.
|
||||||
|
summary: No workers connected
|
||||||
|
for: 10m
|
||||||
|
labels:
|
||||||
|
severity: critical
|
||||||
|
- alert: PendingMigrations
|
||||||
|
expr: max without (pid) (django_migrations_unapplied_total) > 0
|
||||||
|
annotations:
|
||||||
|
message: |
|
||||||
|
authentik instance {{ printf "{{ $labels.instance }}" }} has pending database migrations
|
||||||
|
summary: Pending database migrations
|
||||||
|
for: 10m
|
||||||
|
labels:
|
||||||
|
severity: critical
|
||||||
|
- alert: FailedSystemTasks
|
||||||
|
expr: sum(increase(authentik_system_tasks{status="TaskResultStatus.ERROR"}[2h])) > 0
|
||||||
|
annotations:
|
||||||
|
message: |
|
||||||
|
System task {{ printf "{{ $labels.task_name }}" }} has failed
|
||||||
|
summary: Failed system tasks
|
||||||
|
for: 2h
|
||||||
|
labels:
|
||||||
|
severity: critical
|
||||||
|
- alert: DisconnectedOutposts
|
||||||
|
expr: sum by (outpost) (max without (pid) (authentik_outposts_connected{uid!~"specific.*"})) < 1
|
||||||
|
annotations:
|
||||||
|
message: |
|
||||||
|
Outpost {{ printf "{{ $labels.outpost }}" }} has at least 1 disconnected instance
|
||||||
|
summary: Disconnected outpost
|
||||||
|
for: 30m
|
||||||
|
labels:
|
||||||
|
severity: critical
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,44 @@
|
|||||||
|
{{- if hasKey .Values "metrics" }}
|
||||||
|
{{- if .Values.metrics.enabled }}
|
||||||
|
apiVersion: monitoring.coreos.com/v1
|
||||||
|
kind: ServiceMonitor
|
||||||
|
metadata:
|
||||||
|
name: {{ include "tc.common.names.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "tc.common.labels" . | nindent 4 }}
|
||||||
|
{{- with .Values.metrics.serviceMonitor.labels }}
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "tc.common.labels.selectorLabels" . | nindent 6 }}
|
||||||
|
endpoints:
|
||||||
|
- port: metrics
|
||||||
|
{{- with .Values.metrics.serviceMonitor.interval }}
|
||||||
|
interval: {{ . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.metrics.serviceMonitor.scrapeTimeout }}
|
||||||
|
scrapeTimeout: {{ . }}
|
||||||
|
{{- end }}
|
||||||
|
path: /metrics
|
||||||
|
|
||||||
|
- port: ldapmetrics
|
||||||
|
{{- with .Values.metrics.serviceMonitor.interval }}
|
||||||
|
interval: {{ . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.metrics.serviceMonitor.scrapeTimeout }}
|
||||||
|
scrapeTimeout: {{ . }}
|
||||||
|
{{- end }}
|
||||||
|
path: /metrics
|
||||||
|
|
||||||
|
- port: proxymetrics
|
||||||
|
{{- with .Values.metrics.serviceMonitor.interval }}
|
||||||
|
interval: {{ . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.metrics.serviceMonitor.scrapeTimeout }}
|
||||||
|
scrapeTimeout: {{ . }}
|
||||||
|
{{- end }}
|
||||||
|
path: /metrics
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -62,9 +62,6 @@ authentik:
|
|||||||
log_level: "info"
|
log_level: "info"
|
||||||
ldap:
|
ldap:
|
||||||
tls_ciphers: "null"
|
tls_ciphers: "null"
|
||||||
metrics:
|
|
||||||
enabled: true
|
|
||||||
|
|
||||||
geoip:
|
geoip:
|
||||||
enabled: false
|
enabled: false
|
||||||
account_id: ""
|
account_id: ""
|
||||||
@@ -89,7 +86,6 @@ outposts:
|
|||||||
# insecure: false
|
# insecure: false
|
||||||
# -- Token is only needed if you accidentally deleted the token within the UI
|
# -- Token is only needed if you accidentally deleted the token within the UI
|
||||||
# token: ""
|
# token: ""
|
||||||
metrics: false
|
|
||||||
proxy:
|
proxy:
|
||||||
# -- First you have to create an Outpost in the GUI. Applications > Outposts
|
# -- First you have to create an Outpost in the GUI. Applications > Outposts
|
||||||
enabled: false
|
enabled: false
|
||||||
@@ -101,7 +97,34 @@ outposts:
|
|||||||
# host: ""
|
# host: ""
|
||||||
# -- Token is only needed if you accidentally deleted the token within the UI
|
# -- Token is only needed if you accidentally deleted the token within the UI
|
||||||
# token: ""
|
# token: ""
|
||||||
metrics: false
|
|
||||||
|
metrics:
|
||||||
|
# -- Enable and configure a Prometheus serviceMonitor for the chart under this key.
|
||||||
|
# @default -- See values.yaml
|
||||||
|
enabled: false
|
||||||
|
serviceMonitor:
|
||||||
|
interval: 1m
|
||||||
|
scrapeTimeout: 30s
|
||||||
|
labels: {}
|
||||||
|
# -- Enable and configure Prometheus Rules for the chart under this key.
|
||||||
|
# @default -- See values.yaml
|
||||||
|
prometheusRule:
|
||||||
|
enabled: false
|
||||||
|
useDefault: true
|
||||||
|
labels: {}
|
||||||
|
# -- Configure additional rules for the chart under this key.
|
||||||
|
# @default -- See prometheusrules.yaml
|
||||||
|
rules:
|
||||||
|
[]
|
||||||
|
# - alert: UnifiPollerAbsent
|
||||||
|
# annotations:
|
||||||
|
# description: Unifi Poller has disappeared from Prometheus service discovery.
|
||||||
|
# summary: Unifi Poller is down.
|
||||||
|
# expr: |
|
||||||
|
# absent(up{job=~".*unifi-poller.*"} == 1)
|
||||||
|
# for: 5m
|
||||||
|
# labels:
|
||||||
|
# severity: critical
|
||||||
|
|
||||||
envFrom:
|
envFrom:
|
||||||
- secretRef:
|
- secretRef:
|
||||||
@@ -113,17 +136,17 @@ envFrom:
|
|||||||
|
|
||||||
probes:
|
probes:
|
||||||
liveness:
|
liveness:
|
||||||
type: HTTP
|
type: HTTPS
|
||||||
path: /-/health/live/
|
path: /-/health/live/
|
||||||
port: "{{ .Values.service.http.ports.http.targetPort }}"
|
port: "{{ .Values.service.main.ports.main.targetPort }}"
|
||||||
readiness:
|
readiness:
|
||||||
type: HTTP
|
type: HTTPS
|
||||||
path: /-/health/ready/
|
path: /-/health/ready/
|
||||||
port: "{{ .Values.service.http.ports.http.targetPort }}"
|
port: "{{ .Values.service.main.ports.main.targetPort }}"
|
||||||
startup:
|
startup:
|
||||||
type: HTTP
|
type: HTTPS
|
||||||
path: /-/health/ready/
|
path: /-/health/ready/
|
||||||
port: "{{ .Values.service.http.ports.http.targetPort }}"
|
port: "{{ .Values.service.main.ports.main.targetPort }}"
|
||||||
|
|
||||||
service:
|
service:
|
||||||
main:
|
main:
|
||||||
@@ -134,23 +157,16 @@ service:
|
|||||||
targetPort: 9443
|
targetPort: 9443
|
||||||
http:
|
http:
|
||||||
enabled: true
|
enabled: true
|
||||||
|
type: ClusterIP
|
||||||
ports:
|
ports:
|
||||||
http:
|
http:
|
||||||
enabled: true
|
enabled: true
|
||||||
protocol: HTTP
|
protocol: HTTP
|
||||||
port: 10230
|
port: 10230
|
||||||
targetPort: 9000
|
targetPort: 9000
|
||||||
metrics:
|
# LDAP Outpost Services
|
||||||
enabled: true
|
|
||||||
ports:
|
|
||||||
metrics:
|
|
||||||
enabled: true
|
|
||||||
protocol: HTTP
|
|
||||||
port: 10231
|
|
||||||
targetPort: 9301
|
|
||||||
ldapldaps:
|
ldapldaps:
|
||||||
enabled: true
|
enabled: true
|
||||||
type: ClusterIP
|
|
||||||
ports:
|
ports:
|
||||||
ldapldaps:
|
ldapldaps:
|
||||||
enabled: true
|
enabled: true
|
||||||
@@ -158,24 +174,14 @@ service:
|
|||||||
targetPort: 6636
|
targetPort: 6636
|
||||||
ldapldap:
|
ldapldap:
|
||||||
enabled: true
|
enabled: true
|
||||||
type: ClusterIP
|
|
||||||
ports:
|
ports:
|
||||||
ldapldap:
|
ldapldap:
|
||||||
enabled: true
|
enabled: true
|
||||||
port: 389
|
port: 389
|
||||||
targetPort: 3389
|
targetPort: 3389
|
||||||
ldapmetrics:
|
# Proxy Outpost Services
|
||||||
enabled: true
|
|
||||||
type: ClusterIP
|
|
||||||
ports:
|
|
||||||
ldapmetrics:
|
|
||||||
enabled: true
|
|
||||||
port: 10232
|
|
||||||
protocol: HTTP
|
|
||||||
targetPort: 9302
|
|
||||||
proxyhttps:
|
proxyhttps:
|
||||||
enabled: true
|
enabled: true
|
||||||
type: ClusterIP
|
|
||||||
ports:
|
ports:
|
||||||
proxyhttps:
|
proxyhttps:
|
||||||
enabled: true
|
enabled: true
|
||||||
@@ -189,8 +195,27 @@ service:
|
|||||||
proxyhttp:
|
proxyhttp:
|
||||||
enabled: true
|
enabled: true
|
||||||
port: 10234
|
port: 10234
|
||||||
protocl: HTTP
|
protocol: HTTP
|
||||||
targetPort: 9001
|
targetPort: 9001
|
||||||
|
# Metrics Services
|
||||||
|
metrics:
|
||||||
|
enabled: true
|
||||||
|
type: ClusterIP
|
||||||
|
ports:
|
||||||
|
metrics:
|
||||||
|
enabled: true
|
||||||
|
protocol: HTTP
|
||||||
|
port: 10231
|
||||||
|
targetPort: 9301
|
||||||
|
ldapmetrics:
|
||||||
|
enabled: true
|
||||||
|
type: ClusterIP
|
||||||
|
ports:
|
||||||
|
ldapmetrics:
|
||||||
|
enabled: true
|
||||||
|
port: 10232
|
||||||
|
protocol: HTTP
|
||||||
|
targetPort: 9302
|
||||||
proxymetrics:
|
proxymetrics:
|
||||||
enabled: true
|
enabled: true
|
||||||
type: ClusterIP
|
type: ClusterIP
|
||||||
@@ -202,12 +227,8 @@ service:
|
|||||||
targetPort: 9303
|
targetPort: 9303
|
||||||
|
|
||||||
ingress:
|
ingress:
|
||||||
http:
|
|
||||||
autoLink: true
|
|
||||||
proxyhttps:
|
proxyhttps:
|
||||||
autoLink: true
|
autoLink: true
|
||||||
proxyhttp:
|
|
||||||
autoLink: true
|
|
||||||
|
|
||||||
persistence:
|
persistence:
|
||||||
media:
|
media:
|
||||||
|
|||||||
Reference in New Issue
Block a user