mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 13:33:00 +08:00
fix(meta): log x-forwarded for IP address (#512)
This commit is contained in:
@@ -0,0 +1,38 @@
|
||||
{{- /*
|
||||
Replaces the image's stock conf.d/default.conf: the same static server, but
|
||||
the access log is JSON — victoria-logs-collector parses it into fields — and
|
||||
records X-Forwarded-For, since behind the gateway $remote_addr is only the
|
||||
envoy pod. Unlike the well-known ConfigMap, nginx reads config only at
|
||||
startup, so edits here need a rollout to take effect.
|
||||
*/}}
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: {{ include "yucca-common.fullname" . }}-nginx
|
||||
labels:
|
||||
{{- include "yucca-common.labels" . | nindent 4 }}
|
||||
data:
|
||||
default.conf: |
|
||||
log_format access_json escape=json '{'
|
||||
'"time":"$time_iso8601",'
|
||||
'"message":"$request",'
|
||||
'"remote_addr":"$remote_addr",'
|
||||
'"x_forwarded_for":"$http_x_forwarded_for",'
|
||||
'"method":"$request_method",'
|
||||
'"uri":"$request_uri",'
|
||||
'"status":$status,'
|
||||
'"size":$body_bytes_sent,'
|
||||
'"user_agent":"$http_user_agent"'
|
||||
'}';
|
||||
|
||||
server {
|
||||
listen 8080;
|
||||
server_name _;
|
||||
|
||||
access_log /var/log/nginx/access.log access_json;
|
||||
|
||||
location / {
|
||||
root /usr/share/nginx/html;
|
||||
index index.html;
|
||||
}
|
||||
}
|
||||
@@ -58,6 +58,9 @@ volumes:
|
||||
- name: well-known
|
||||
configMap:
|
||||
name: yucca-meta
|
||||
- name: nginx-conf
|
||||
configMap:
|
||||
name: yucca-meta-nginx
|
||||
# nginx-unprivileged keeps its temp paths in /tmp (already an emptyDir from
|
||||
# the library chart), but the image still creates /var/cache/nginx and the
|
||||
# rootfs is read-only. A tmpfs here keeps startup quiet.
|
||||
@@ -68,6 +71,12 @@ volumeMounts:
|
||||
- name: well-known
|
||||
mountPath: /usr/share/nginx/html/.well-known
|
||||
readOnly: true
|
||||
# Shadows the whole conf.d — default.conf is the only file the image ships
|
||||
# there, replaced wholesale by templates/nginx-configmap.yaml (JSON access
|
||||
# log).
|
||||
- name: nginx-conf
|
||||
mountPath: /etc/nginx/conf.d
|
||||
readOnly: true
|
||||
- name: cache
|
||||
mountPath: /var/cache/nginx
|
||||
|
||||
|
||||
@@ -753,7 +753,7 @@
|
||||
"uid": "$logs_datasource"
|
||||
},
|
||||
"refId": "A",
|
||||
"expr": "{kubernetes.container_name=\"meta\"} cluster:=\"$cluster\" _msg:~`HTTP/1.[01]\" 5\\d\\d ` | stats count()",
|
||||
"expr": "{kubernetes.container_name=\"meta\"} cluster:=\"$cluster\" status:>=500 | stats count()",
|
||||
"queryType": "statsRange",
|
||||
"legendFormat": "5xx"
|
||||
}
|
||||
@@ -837,7 +837,7 @@
|
||||
"uid": "$logs_datasource"
|
||||
},
|
||||
"refId": "A",
|
||||
"expr": "{kubernetes.container_name=\"meta\"} cluster:=\"$cluster\" _msg:~`HTTP/1.[01]\" 4\\d\\d ` | stats count()",
|
||||
"expr": "{kubernetes.container_name=\"meta\"} cluster:=\"$cluster\" status:>=400 status:<500 | stats count()",
|
||||
"queryType": "statsRange",
|
||||
"legendFormat": "4xx"
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user