mirror of
https://github.com/immich-app/yucca-o11y.git
synced 2026-09-30 13:23:23 +08:00
110 lines
4.7 KiB
TOML
110 lines
4.7 KiB
TOML
monorepo_root = true
|
|
|
|
[monorepo]
|
|
config_roots = ["deployment", "deployment/modules/*/*"]
|
|
|
|
[tools]
|
|
opentofu = "1.12.6"
|
|
terragrunt = "1.1.5"
|
|
python = "3.14.7"
|
|
uv = "0.12.15"
|
|
pipx = "1.17.2"
|
|
"pipx:python-openstackclient" = "10.3.0"
|
|
kubectl = "1.37.0"
|
|
flux2 = "2.9.5"
|
|
"sd" = "1.1.0"
|
|
talosctl = "1.14.0"
|
|
helm = "4.3.0"
|
|
"jq" = "1.8.2"
|
|
gh = "2.100.0"
|
|
yq = "4.53.6"
|
|
"kustomize" = "5.8.1"
|
|
markdownlint-cli2 = "0.23.2"
|
|
"github:home-operations/flate" = "v0.6.5"
|
|
"github:sigstore/cosign" = "v3.1.3"
|
|
|
|
[env]
|
|
TF_VAR_dist_dir = "{{config_root}}/dist"
|
|
|
|
# Maps long env names (development/staging/production) to the short suffixes
|
|
# used by 1Password vault paths (dev/staging/prod).
|
|
ENVIRONMENT_SHORT = "{% set e = get_env(name='ENVIRONMENT', default='development') %}{% if e == 'development' or e == '' %}dev{% elif e == 'production' %}prod{% else %}{{ e }}{% endif %}"
|
|
|
|
# CI authenticates with a service-account token, which op rejects alongside --account.
|
|
# Rendered at the root, so {{config_root}} here is the repo root from any subproject.
|
|
[vars]
|
|
# Shared Grafana dashboards: fetched from upstream and patched for the fleet
|
|
# (cluster variable + filters, Fleet datasource, shared folder) by the
|
|
# VictoriaMetrics sync-job in generate mode; the output is committed.
|
|
sync_job = "docker run --rm -e OUTPUT=- -e CONFIG=/config/sync-job.yaml -e NAMESPACE=o11y -e RELEASE=shared -e OWNER_REFERENCES=false -v {{config_root}}/o11y:/config:ro ghcr.io/victoriametrics/sync-job:v0.0.17"
|
|
# Pin every datasource-type template variable to the Fleet datasource: the
|
|
# sync-job leaves them free, and Grafana would otherwise open a shared board
|
|
# on the default (tenant-scoped) datasource and show only this cluster.
|
|
pin_fleet = "yq '(select(.kind == \"GrafanaDashboard\") | .spec.json) |= (fromjson | .templating.list[] |= (select(.type == \"datasource\") |= (.regex = \"/^VictoriaMetrics Fleet$/\" | .current = {\"text\": \"VictoriaMetrics Fleet\", \"value\": \"VictoriaMetricsFleet\"})) | tojson)'"
|
|
# The sync-job emits the kube-prometheus bundle in map order; sort documents so an unchanged
|
|
# upstream renders byte-identical and the artifact's content layer keeps its digest.
|
|
sort_docs = "yq eval-all '[.] | sort_by(.metadata.name) | .[] | splitDoc'"
|
|
tg = "op run {% if get_env(name='OP_SERVICE_ACCOUNT_TOKEN', default='') == '' %}--account 'team-futo.1password.com' {% endif %}'--env-file={{config_root}}/deployment/.env' -- terragrunt"
|
|
|
|
# Escape hatch for terragrunt subcommands the tasks below don't cover
|
|
# (state rm/import/force-unlock, ...); operates on the caller's directory.
|
|
[tasks.tg]
|
|
run = "{{vars.tg}}"
|
|
description = "Wrapper for terragrunt"
|
|
dir = "{{cwd}}"
|
|
|
|
# Module tasks extend these; each runs in its own module directory. Caller args
|
|
# append after the verb and land in tofu's argv (terragrunt run -- plan -target=...).
|
|
# apply/destroy in the module files carry wait_for mirroring the terragrunt
|
|
# dependency blocks, so wildcard fan-outs like //deployment/modules/...:apply
|
|
# cannot run out of dependency order.
|
|
[task_templates."tg:init"]
|
|
run = "{{vars.tg}} run -- init -reconfigure"
|
|
description = "Init this module"
|
|
|
|
[task_templates."tg:plan"]
|
|
run = "{{vars.tg}} run -- plan"
|
|
description = "Plan this module"
|
|
|
|
[task_templates."tg:apply"]
|
|
run = "{{vars.tg}} run -- apply"
|
|
description = "Apply this module"
|
|
|
|
[task_templates."tg:destroy"]
|
|
run = "{{vars.tg}} run -- destroy"
|
|
description = "Destroy this module"
|
|
|
|
[task_templates."tg:output"]
|
|
run = "{{vars.tg}} run -- output"
|
|
description = "Read outputs from this module"
|
|
|
|
[tasks."md:lint"]
|
|
run = "markdownlint-cli2 'docs/**/*.md' 'README.md'"
|
|
description = "Lint markdown docs"
|
|
|
|
[tasks."md:fix"]
|
|
run = "markdownlint-cli2 --fix 'docs/**/*.md' 'README.md'"
|
|
description = "Auto-fix markdown lint issues where possible"
|
|
|
|
[tasks."o11y:vendor"]
|
|
description = "Fetch upstream boards that need a rewrite before the sync-job sees them (CloudNativePG: its `cluster` means the Postgres cluster; the fleet keeps that under `pg_cluster`)"
|
|
run = """
|
|
mkdir -p {{config_root}}/o11y/vendor
|
|
curl -fsSL https://raw.githubusercontent.com/cloudnative-pg/grafana-dashboards/cluster-v0.0.5/charts/cluster/grafana-dashboard.json \\
|
|
| sd '\\$cluster\\b' '$$pg_cluster' \\
|
|
| sd '\\bcluster(\\s*(?:=~|!~|!=|=)\\s*)' 'pg_cluster$1' \\
|
|
| sd '([(,]\\s*)cluster(\\s*[,)])' '${1}pg_cluster$2' \\
|
|
| sd '"name":\\s*"cluster"' '"name": "pg_cluster"' \\
|
|
| sd -s '\\\\bcluster\\\\b=' '\\\\bpg_cluster\\\\b=' \\
|
|
> {{config_root}}/o11y/vendor/cloudnativepg.json
|
|
"""
|
|
|
|
[tasks."o11y:render"]
|
|
depends = ["o11y:vendor"]
|
|
run = "{{vars.sync_job}} | {{vars.pin_fleet}} | {{vars.sort_docs}} > {{config_root}}/o11y/manifests/dashboards.yaml"
|
|
description = "Render o11y/manifests/dashboards.yaml (git-ignored) from the upstream sources in o11y/sync-job.yaml"
|
|
|
|
[settings]
|
|
experimental = true
|
|
idiomatic_version_file_enable_tools = []
|