Files
yucca-o11y/.mise/config.toml
T

110 lines
4.7 KiB
TOML

monorepo_root = true
[monorepo]
config_roots = ["deployment", "deployment/modules/*/*"]
[tools]
opentofu = "1.12.6"
terragrunt = "1.1.4"
python = "3.14.7"
uv = "0.12.13"
pipx = "1.17.2"
"pipx:python-openstackclient" = "10.3.0"
kubectl = "1.37.0"
flux2 = "2.9.5"
"sd" = "1.1.0"
talosctl = "1.14.0"
helm = "4.3.0"
"jq" = "1.8.2"
gh = "2.100.0"
yq = "4.53.6"
"kustomize" = "5.8.1"
markdownlint-cli2 = "0.23.2"
"github:home-operations/flate" = "v0.6.5"
"github:sigstore/cosign" = "v3.1.3"
[env]
TF_VAR_dist_dir = "{{config_root}}/dist"
# Maps long env names (development/staging/production) to the short suffixes
# used by 1Password vault paths (dev/staging/prod).
ENVIRONMENT_SHORT = "{% set e = get_env(name='ENVIRONMENT', default='development') %}{% if e == 'development' or e == '' %}dev{% elif e == 'production' %}prod{% else %}{{ e }}{% endif %}"
# CI authenticates with a service-account token, which op rejects alongside --account.
# Rendered at the root, so {{config_root}} here is the repo root from any subproject.
[vars]
# Shared Grafana dashboards: fetched from upstream and patched for the fleet
# (cluster variable + filters, Fleet datasource, shared folder) by the
# VictoriaMetrics sync-job in generate mode; the output is committed.
sync_job = "docker run --rm -e OUTPUT=- -e CONFIG=/config/sync-job.yaml -e NAMESPACE=o11y -e RELEASE=shared -e OWNER_REFERENCES=false -v {{config_root}}/o11y:/config:ro ghcr.io/victoriametrics/sync-job:v0.0.17"
# Pin every datasource-type template variable to the Fleet datasource: the
# sync-job leaves them free, and Grafana would otherwise open a shared board
# on the default (tenant-scoped) datasource and show only this cluster.
pin_fleet = "yq '(select(.kind == \"GrafanaDashboard\") | .spec.json) |= (fromjson | .templating.list[] |= (select(.type == \"datasource\") |= (.regex = \"/^VictoriaMetrics Fleet$/\" | .current = {\"text\": \"VictoriaMetrics Fleet\", \"value\": \"VictoriaMetricsFleet\"})) | tojson)'"
# The sync-job emits the kube-prometheus bundle in map order; sort documents so an unchanged
# upstream renders byte-identical and the published artifact keeps its digest.
sort_docs = "yq eval-all '[.] | sort_by(.metadata.name) | .[] | splitDoc'"
tg = "op run {% if get_env(name='OP_SERVICE_ACCOUNT_TOKEN', default='') == '' %}--account 'team-futo.1password.com' {% endif %}'--env-file={{config_root}}/deployment/.env' -- terragrunt"
# Escape hatch for terragrunt subcommands the tasks below don't cover
# (state rm/import/force-unlock, ...); operates on the caller's directory.
[tasks.tg]
run = "{{vars.tg}}"
description = "Wrapper for terragrunt"
dir = "{{cwd}}"
# Module tasks extend these; each runs in its own module directory. Caller args
# append after the verb and land in tofu's argv (terragrunt run -- plan -target=...).
# apply/destroy in the module files carry wait_for mirroring the terragrunt
# dependency blocks, so wildcard fan-outs like //deployment/modules/...:apply
# cannot run out of dependency order.
[task_templates."tg:init"]
run = "{{vars.tg}} run -- init -reconfigure"
description = "Init this module"
[task_templates."tg:plan"]
run = "{{vars.tg}} run -- plan"
description = "Plan this module"
[task_templates."tg:apply"]
run = "{{vars.tg}} run -- apply"
description = "Apply this module"
[task_templates."tg:destroy"]
run = "{{vars.tg}} run -- destroy"
description = "Destroy this module"
[task_templates."tg:output"]
run = "{{vars.tg}} run -- output"
description = "Read outputs from this module"
[tasks."md:lint"]
run = "markdownlint-cli2 'docs/**/*.md' 'README.md'"
description = "Lint markdown docs"
[tasks."md:fix"]
run = "markdownlint-cli2 --fix 'docs/**/*.md' 'README.md'"
description = "Auto-fix markdown lint issues where possible"
[tasks."o11y:vendor"]
description = "Fetch upstream boards that need a rewrite before the sync-job sees them (CloudNativePG: its `cluster` means the Postgres cluster; the fleet keeps that under `pg_cluster`)"
run = """
mkdir -p {{config_root}}/o11y/vendor
curl -fsSL https://raw.githubusercontent.com/cloudnative-pg/grafana-dashboards/cluster-v0.0.5/charts/cluster/grafana-dashboard.json \\
| sd '\\$cluster\\b' '$$pg_cluster' \\
| sd '\\bcluster(\\s*(?:=~|!~|!=|=)\\s*)' 'pg_cluster$1' \\
| sd '([(,]\\s*)cluster(\\s*[,)])' '${1}pg_cluster$2' \\
| sd '"name":\\s*"cluster"' '"name": "pg_cluster"' \\
| sd -s '\\\\bcluster\\\\b=' '\\\\bpg_cluster\\\\b=' \\
> {{config_root}}/o11y/vendor/cloudnativepg.json
"""
[tasks."o11y:render"]
depends = ["o11y:vendor"]
run = "{{vars.sync_job}} | {{vars.pin_fleet}} | {{vars.sort_docs}} > {{config_root}}/o11y/manifests/dashboards.yaml"
description = "Render o11y/manifests/dashboards.yaml (git-ignored) from the upstream sources in o11y/sync-job.yaml"
[settings]
experimental = true
idiomatic_version_file_enable_tools = []