fix(meta): log x-forwarded for IP address (#512)

This commit is contained in:
Antoine Lecompte
2026-08-20 14:34:26 +00:00
committed by GitHub
parent 833cbcb896
commit a3b42946d5
3 changed files with 49 additions and 2 deletions
@@ -0,0 +1,38 @@
{{- /*
Replaces the image's stock conf.d/default.conf: the same static server, but
the access log is JSON — victoria-logs-collector parses it into fields — and
records X-Forwarded-For, since behind the gateway $remote_addr is only the
envoy pod. Unlike the well-known ConfigMap, nginx reads config only at
startup, so edits here need a rollout to take effect.
*/}}
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ include "yucca-common.fullname" . }}-nginx
labels:
{{- include "yucca-common.labels" . | nindent 4 }}
data:
default.conf: |
log_format access_json escape=json '{'
'"time":"$time_iso8601",'
'"message":"$request",'
'"remote_addr":"$remote_addr",'
'"x_forwarded_for":"$http_x_forwarded_for",'
'"method":"$request_method",'
'"uri":"$request_uri",'
'"status":$status,'
'"size":$body_bytes_sent,'
'"user_agent":"$http_user_agent"'
'}';
server {
listen 8080;
server_name _;
access_log /var/log/nginx/access.log access_json;
location / {
root /usr/share/nginx/html;
index index.html;
}
}
+9
View File
@@ -58,6 +58,9 @@ volumes:
- name: well-known
configMap:
name: yucca-meta
- name: nginx-conf
configMap:
name: yucca-meta-nginx
# nginx-unprivileged keeps its temp paths in /tmp (already an emptyDir from
# the library chart), but the image still creates /var/cache/nginx and the
# rootfs is read-only. A tmpfs here keeps startup quiet.
@@ -68,6 +71,12 @@ volumeMounts:
- name: well-known
mountPath: /usr/share/nginx/html/.well-known
readOnly: true
# Shadows the whole conf.d — default.conf is the only file the image ships
# there, replaced wholesale by templates/nginx-configmap.yaml (JSON access
# log).
- name: nginx-conf
mountPath: /etc/nginx/conf.d
readOnly: true
- name: cache
mountPath: /var/cache/nginx
+2 -2
View File
@@ -753,7 +753,7 @@
"uid": "$logs_datasource"
},
"refId": "A",
"expr": "{kubernetes.container_name=\"meta\"} cluster:=\"$cluster\" _msg:~`HTTP/1.[01]\" 5\\d\\d ` | stats count()",
"expr": "{kubernetes.container_name=\"meta\"} cluster:=\"$cluster\" status:>=500 | stats count()",
"queryType": "statsRange",
"legendFormat": "5xx"
}
@@ -837,7 +837,7 @@
"uid": "$logs_datasource"
},
"refId": "A",
"expr": "{kubernetes.container_name=\"meta\"} cluster:=\"$cluster\" _msg:~`HTTP/1.[01]\" 4\\d\\d ` | stats count()",
"expr": "{kubernetes.container_name=\"meta\"} cluster:=\"$cluster\" status:>=400 status:<500 | stats count()",
"queryType": "statsRange",
"legendFormat": "4xx"
}