mirror of
https://github.com/immich-app/yucca-o11y.git
synced 2026-09-30 13:23:23 +08:00
feat(grafana): shared dashboards rendered from upstream via the VictoriaMetrics sync-job (#323)
Signed-off-by: Devin Buhl <devin@buhl.casa>
This commit is contained in:
@@ -21,6 +21,7 @@ yq = "4.53.6"
|
||||
"kustomize" = "5.8.1"
|
||||
markdownlint-cli2 = "0.23.2"
|
||||
"github:home-operations/flate" = "v0.6.5"
|
||||
"github:sigstore/cosign" = "v3.1.3"
|
||||
|
||||
[env]
|
||||
TF_VAR_dist_dir = "{{config_root}}/dist"
|
||||
@@ -32,6 +33,16 @@ ENVIRONMENT_SHORT = "{% set e = get_env(name='ENVIRONMENT', default='development
|
||||
# CI authenticates with a service-account token, which op rejects alongside --account.
|
||||
# Rendered at the root, so {{config_root}} here is the repo root from any subproject.
|
||||
[vars]
|
||||
# Shared Grafana dashboards: fetched from upstream and patched for the fleet
|
||||
# (cluster variable + filters, Fleet datasource, shared folder) by the
|
||||
# VictoriaMetrics sync-job in generate mode; the output is committed.
|
||||
sync_job = "docker run --rm -e OUTPUT=- -e CONFIG=/config/sync-job.yaml -e NAMESPACE=o11y -e RELEASE=shared -e OWNER_REFERENCES=false -v {{config_root}}/o11y:/config:ro ghcr.io/victoriametrics/sync-job:v0.0.17"
|
||||
# Pin every datasource-type template variable to the Fleet datasource: the
|
||||
# sync-job leaves them free, and Grafana would otherwise open a shared board
|
||||
# on the default (tenant-scoped) datasource and show only this cluster.
|
||||
pin_fleet = "yq '(select(.kind == \"GrafanaDashboard\") | .spec.json) |= (fromjson | .templating.list[] |= (select(.type == \"datasource\") |= (.regex = \"/^VictoriaMetrics Fleet$/\" | .current = {\"text\": \"VictoriaMetrics Fleet\", \"value\": \"VictoriaMetricsFleet\"})) | tojson)'"
|
||||
# The sync-job emits the kube-prometheus bundle in map order; sort documents so re-renders diff cleanly.
|
||||
sort_docs = "yq eval-all '[.] | sort_by(.metadata.name) | .[] | splitDoc'"
|
||||
tg = "op run {% if get_env(name='OP_SERVICE_ACCOUNT_TOKEN', default='') == '' %}--account 'team-futo.1password.com' {% endif %}'--env-file={{config_root}}/deployment/.env' -- terragrunt"
|
||||
|
||||
# Escape hatch for terragrunt subcommands the tasks below don't cover
|
||||
@@ -74,6 +85,28 @@ description = "Lint markdown docs"
|
||||
run = "markdownlint-cli2 --fix 'docs/**/*.md' 'README.md'"
|
||||
description = "Auto-fix markdown lint issues where possible"
|
||||
|
||||
[tasks."o11y:vendor"]
|
||||
description = "Fetch upstream boards that need a rewrite before the sync-job sees them (CloudNativePG: its `cluster` means the Postgres cluster; the fleet keeps that under `pg_cluster`)"
|
||||
run = """
|
||||
curl -fsSL https://raw.githubusercontent.com/cloudnative-pg/grafana-dashboards/cluster-v0.0.5/charts/cluster/grafana-dashboard.json \\
|
||||
| sd '\\$cluster\\b' '$$pg_cluster' \\
|
||||
| sd '\\bcluster(\\s*(?:=~|!~|!=|=)\\s*)' 'pg_cluster$1' \\
|
||||
| sd '([(,]\\s*)cluster(\\s*[,)])' '${1}pg_cluster$2' \\
|
||||
| sd '"name":\\s*"cluster"' '"name": "pg_cluster"' \\
|
||||
| sd -s '\\\\bcluster\\\\b=' '\\\\bpg_cluster\\\\b=' \\
|
||||
> {{config_root}}/o11y/vendor/cloudnativepg.json
|
||||
"""
|
||||
|
||||
[tasks."o11y:render"]
|
||||
depends = ["o11y:vendor"]
|
||||
run = "{{vars.sync_job}} | {{vars.pin_fleet}} | {{vars.sort_docs}} > {{config_root}}/o11y/manifests/dashboards.yaml"
|
||||
description = "Re-render o11y/manifests/dashboards.yaml from the upstream sources in o11y/sync-job.yaml"
|
||||
|
||||
[tasks."o11y:check"]
|
||||
depends = ["o11y:vendor"]
|
||||
run = "{{vars.sync_job}} | {{vars.pin_fleet}} | {{vars.sort_docs}} | diff -u {{config_root}}/o11y/manifests/dashboards.yaml - && echo 'dashboards.yaml is up to date'"
|
||||
description = "Fail if o11y/manifests/dashboards.yaml differs from a fresh render"
|
||||
|
||||
[settings]
|
||||
experimental = true
|
||||
idiomatic_version_file_enable_tools = []
|
||||
|
||||
@@ -93,6 +93,31 @@ checksum = "sha256:4b1dcefb4613b4c02f3374c8fc8d4082d42d893f4303daa16e24e37d58bcc
|
||||
url = "https://github.com/home-operations/flate/releases/download/v0.6.5/flate_0.6.5_darwin_amd64.tar.gz"
|
||||
url_api = "https://api.github.com/repos/home-operations/flate/releases/assets/541337300"
|
||||
|
||||
[[tools."github:sigstore/cosign"]]
|
||||
version = "3.1.3"
|
||||
backend = "github:sigstore/cosign"
|
||||
specifiers = ["v3.1.3"]
|
||||
|
||||
[tools."github:sigstore/cosign"."platforms.linux-arm64"]
|
||||
checksum = "sha256:c5d324e091826b0d7a78eb16fef316450b4eb9aaec045611c08ba06f5e73220a"
|
||||
url = "https://github.com/sigstore/cosign/releases/download/v3.1.3/cosign-linux-arm64"
|
||||
url_api = "https://api.github.com/repos/sigstore/cosign/releases/assets/503286299"
|
||||
|
||||
[tools."github:sigstore/cosign"."platforms.linux-x64"]
|
||||
checksum = "sha256:4629c757b7618056f8ddd7e2625ae9fdd94c0372a65049520bc7d9df9efc7f71"
|
||||
url = "https://github.com/sigstore/cosign/releases/download/v3.1.3/cosign-linux-amd64"
|
||||
url_api = "https://api.github.com/repos/sigstore/cosign/releases/assets/503286005"
|
||||
|
||||
[tools."github:sigstore/cosign"."platforms.macos-arm64"]
|
||||
checksum = "sha256:5cf948c2f4dfe59687bdd0b8523709067383e03982cc543475c8a7dc70e92a76"
|
||||
url = "https://github.com/sigstore/cosign/releases/download/v3.1.3/cosign-darwin-arm64"
|
||||
url_api = "https://api.github.com/repos/sigstore/cosign/releases/assets/503286205"
|
||||
|
||||
[tools."github:sigstore/cosign"."platforms.macos-x64"]
|
||||
checksum = "sha256:2347488e5d5b25336644024dfeca5601b190e91197a71a917bda44744aff106c"
|
||||
url = "https://github.com/sigstore/cosign/releases/download/v3.1.3/cosign-darwin-amd64"
|
||||
url_api = "https://api.github.com/repos/sigstore/cosign/releases/assets/503286177"
|
||||
|
||||
[[tools.helm]]
|
||||
version = "4.3.0"
|
||||
backend = "aqua:helm/helm"
|
||||
|
||||
Reference in New Issue
Block a user