feat(grafana): shared dashboards rendered from upstream via the VictoriaMetrics sync-job (#323)

Signed-off-by: Devin Buhl <devin@buhl.casa>
This commit is contained in:
Devin Buhl
2026-09-12 21:23:04 -04:00
committed by GitHub
parent f0cd13f5fb
commit 6c5d806d7c
13 changed files with 10419 additions and 0 deletions
+33
View File
@@ -21,6 +21,7 @@ yq = "4.53.6"
"kustomize" = "5.8.1"
markdownlint-cli2 = "0.23.2"
"github:home-operations/flate" = "v0.6.5"
"github:sigstore/cosign" = "v3.1.3"
[env]
TF_VAR_dist_dir = "{{config_root}}/dist"
@@ -32,6 +33,16 @@ ENVIRONMENT_SHORT = "{% set e = get_env(name='ENVIRONMENT', default='development
# CI authenticates with a service-account token, which op rejects alongside --account.
# Rendered at the root, so {{config_root}} here is the repo root from any subproject.
[vars]
# Shared Grafana dashboards: fetched from upstream and patched for the fleet
# (cluster variable + filters, Fleet datasource, shared folder) by the
# VictoriaMetrics sync-job in generate mode; the output is committed.
sync_job = "docker run --rm -e OUTPUT=- -e CONFIG=/config/sync-job.yaml -e NAMESPACE=o11y -e RELEASE=shared -e OWNER_REFERENCES=false -v {{config_root}}/o11y:/config:ro ghcr.io/victoriametrics/sync-job:v0.0.17"
# Pin every datasource-type template variable to the Fleet datasource: the
# sync-job leaves them free, and Grafana would otherwise open a shared board
# on the default (tenant-scoped) datasource and show only this cluster.
pin_fleet = "yq '(select(.kind == \"GrafanaDashboard\") | .spec.json) |= (fromjson | .templating.list[] |= (select(.type == \"datasource\") |= (.regex = \"/^VictoriaMetrics Fleet$/\" | .current = {\"text\": \"VictoriaMetrics Fleet\", \"value\": \"VictoriaMetricsFleet\"})) | tojson)'"
# The sync-job emits the kube-prometheus bundle in map order; sort documents so re-renders diff cleanly.
sort_docs = "yq eval-all '[.] | sort_by(.metadata.name) | .[] | splitDoc'"
tg = "op run {% if get_env(name='OP_SERVICE_ACCOUNT_TOKEN', default='') == '' %}--account 'team-futo.1password.com' {% endif %}'--env-file={{config_root}}/deployment/.env' -- terragrunt"
# Escape hatch for terragrunt subcommands the tasks below don't cover
@@ -74,6 +85,28 @@ description = "Lint markdown docs"
run = "markdownlint-cli2 --fix 'docs/**/*.md' 'README.md'"
description = "Auto-fix markdown lint issues where possible"
[tasks."o11y:vendor"]
description = "Fetch upstream boards that need a rewrite before the sync-job sees them (CloudNativePG: its `cluster` means the Postgres cluster; the fleet keeps that under `pg_cluster`)"
run = """
curl -fsSL https://raw.githubusercontent.com/cloudnative-pg/grafana-dashboards/cluster-v0.0.5/charts/cluster/grafana-dashboard.json \\
| sd '\\$cluster\\b' '$$pg_cluster' \\
| sd '\\bcluster(\\s*(?:=~|!~|!=|=)\\s*)' 'pg_cluster$1' \\
| sd '([(,]\\s*)cluster(\\s*[,)])' '${1}pg_cluster$2' \\
| sd '"name":\\s*"cluster"' '"name": "pg_cluster"' \\
| sd -s '\\\\bcluster\\\\b=' '\\\\bpg_cluster\\\\b=' \\
> {{config_root}}/o11y/vendor/cloudnativepg.json
"""
[tasks."o11y:render"]
depends = ["o11y:vendor"]
run = "{{vars.sync_job}} | {{vars.pin_fleet}} | {{vars.sort_docs}} > {{config_root}}/o11y/manifests/dashboards.yaml"
description = "Re-render o11y/manifests/dashboards.yaml from the upstream sources in o11y/sync-job.yaml"
[tasks."o11y:check"]
depends = ["o11y:vendor"]
run = "{{vars.sync_job}} | {{vars.pin_fleet}} | {{vars.sort_docs}} | diff -u {{config_root}}/o11y/manifests/dashboards.yaml - && echo 'dashboards.yaml is up to date'"
description = "Fail if o11y/manifests/dashboards.yaml differs from a fresh render"
[settings]
experimental = true
idiomatic_version_file_enable_tools = []
+25
View File
@@ -93,6 +93,31 @@ checksum = "sha256:4b1dcefb4613b4c02f3374c8fc8d4082d42d893f4303daa16e24e37d58bcc
url = "https://github.com/home-operations/flate/releases/download/v0.6.5/flate_0.6.5_darwin_amd64.tar.gz"
url_api = "https://api.github.com/repos/home-operations/flate/releases/assets/541337300"
[[tools."github:sigstore/cosign"]]
version = "3.1.3"
backend = "github:sigstore/cosign"
specifiers = ["v3.1.3"]
[tools."github:sigstore/cosign"."platforms.linux-arm64"]
checksum = "sha256:c5d324e091826b0d7a78eb16fef316450b4eb9aaec045611c08ba06f5e73220a"
url = "https://github.com/sigstore/cosign/releases/download/v3.1.3/cosign-linux-arm64"
url_api = "https://api.github.com/repos/sigstore/cosign/releases/assets/503286299"
[tools."github:sigstore/cosign"."platforms.linux-x64"]
checksum = "sha256:4629c757b7618056f8ddd7e2625ae9fdd94c0372a65049520bc7d9df9efc7f71"
url = "https://github.com/sigstore/cosign/releases/download/v3.1.3/cosign-linux-amd64"
url_api = "https://api.github.com/repos/sigstore/cosign/releases/assets/503286005"
[tools."github:sigstore/cosign"."platforms.macos-arm64"]
checksum = "sha256:5cf948c2f4dfe59687bdd0b8523709067383e03982cc543475c8a7dc70e92a76"
url = "https://github.com/sigstore/cosign/releases/download/v3.1.3/cosign-darwin-arm64"
url_api = "https://api.github.com/repos/sigstore/cosign/releases/assets/503286205"
[tools."github:sigstore/cosign"."platforms.macos-x64"]
checksum = "sha256:2347488e5d5b25336644024dfeca5601b190e91197a71a917bda44744aff106c"
url = "https://github.com/sigstore/cosign/releases/download/v3.1.3/cosign-darwin-amd64"
url_api = "https://api.github.com/repos/sigstore/cosign/releases/assets/503286177"
[[tools.helm]]
version = "4.3.0"
backend = "aqua:helm/helm"