Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions src/app_charts/BUILD.bazel
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,6 +7,7 @@ APPS = [
"k8s-relay",
"mission-crd",
"prometheus",
"grafana",
"token-vendor",
"akri",
]
Expand Down
3 changes: 3 additions & 0 deletions src/app_charts/base/cloud/oauth2-proxy.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -181,6 +181,9 @@ spec:
- group: gateway.envoyproxy.io
kind: SecurityPolicy
namespace: app-prometheus
- group: gateway.envoyproxy.io
kind: SecurityPolicy
namespace: app-grafana
to:
- group: ""
kind: Service
Expand Down
35 changes: 35 additions & 0 deletions src/app_charts/grafana/BUILD.bazel
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
load("//bazel:app.bzl", "app")
load("//bazel:app_chart.bzl", "app_chart")
load("//bazel:build_rules/helm_template.bzl", "helm_template")

helm_template(
name = "grafana-operator-chart.cloud",
# We use the kube-prometheus-stack chart instead of the standalone grafana chart
# because it natively bundles all the default Kubernetes mixin dashboards (like node-exporter,
# kubelet, apiserver) as ConfigMaps. We disable the rest of the backend components in the values file.
chart = "//third_party/kube-prometheus-stack:kube-prometheus-stack-87.5.1.tgz",
helm_version = 3,
kube_version = "1.29.0",
# The namespace will later be replaced with the actual one.
namespace = "HELM-NAMESPACE",
# Pick a short release name as it will be used as a prefix for a lot of resources.
release_name = "grafana",
values = "grafana-cloud.values.yaml",
)

app_chart(
name = "grafana-cloud",
# CRITICAL: Do NOT include 00-crds.yaml to prevent ownership collisions with Prometheus
extra_values = ["values-cloud.yaml"],
files = [
":grafana-operator-chart.cloud",
],
)

app(
name = "grafana",
charts = [
":grafana-cloud",
],
visibility = ["//visibility:public"],
)
32 changes: 32 additions & 0 deletions src/app_charts/grafana/cloud/app.yaml

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
apiVersion: app.k8s.io/v1beta1
kind: Application
metadata:
name: "grafana"
labels:
app.kubernetes.io/name: {{ .Chart.Name }}
app.kubernetes.io/version: {{ .Chart.Version }}
spec:
selector:
matchLabels:
app.kubernetes.io/name: {{ .Chart.Name }}
componentKinds:
- group: core
kind: Service
- group: apps
kind: Deployment
- group: apps
kind: Ingress
- group: gateway.networking.k8s.io
kind: HTTPRoute
- group: gateway.envoyproxy.io
kind: SecurityPolicy
descriptor:
type: "grafana"
version: {{ .Chart.Version }}
description: "Grafana provides visualization dashboards"
keywords:
- "dashboard"
- "visualization"
links:
- description: Grafana Dashboard
url: "https://{{ .Values.domain }}/grafana/"
22 changes: 22 additions & 0 deletions src/app_charts/grafana/cloud/grafana-datasources.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: grafana-datasources
labels:
grafana_datasource: "1"
app.kubernetes.io/name: {{ .Chart.Name }}
data:
datasources.yaml: |
apiVersion: 1
{{- if .Values.datasources }}
datasources:
{{ toYaml .Values.datasources | indent 4 }}
{{- else }}
datasources:
- name: Prometheus
type: prometheus
uid: prometheus
url: http://kube-prometheus.{{ .Values.prometheusNamespace | default "app-prometheus" }}.svc.cluster.local:9090
access: proxy
isDefault: true
{{- end }}
Original file line numberDiff line numberDiff line change
Expand Up@@ -23,7 +23,7 @@ spec:
type: ReplacePrefixMatch
replacePrefixMatch: /
backendRefs:
- name: prom-grafana
- name: grafana
port: 80
- matches:
- path:
Expand All@@ -36,7 +36,7 @@ spec:
type: ReplaceFullPath
replaceFullPath: /
backendRefs:
- name: prom-grafana
- name: grafana
port: 80
---
apiVersion: gateway.envoyproxy.io/v1alpha1
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -23,6 +23,6 @@ spec:
pathType: Prefix
backend:
service:
name: prom-grafana
name: grafana
port:
number: 80
25 changes: 25 additions & 0 deletions src/app_charts/grafana/cloud/grafana-operator.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
# This includes all resources expanded from the grafana-operator chart using
# the values in ../grafana-cloud.values.yaml.
# Some pseudo-variables that were inserted there are replaced with actual runtime values.
# NOTE: The order here is important. The domain and project might be part of other values and
# need to be replaced last.
{{- $data := .Files.Get "files/grafana-operator-chart.cloud.yaml" -}}
# Pre-process variables
{{- $data = $data | replace "${CR_GF_INGRESS_AUTH_URL}" .Values.gf_ingress_auth_url -}}
{{- $data = $data | replace "${CR_GF_INGRESS_AUTH_SIGNIN}" .Values.gf_ingress_auth_signin -}}
{{- $data = $data | replace "${CR_GF_INGRESS_ERROR_PAGE_403}" .Values.gf_ingress_error_page_403 -}}
{{- $data = $data | replace "${CR_GF_SERVER_DOMAIN}" .Values.gf_server_domain -}}
{{- $data = $data | replace "${CR_GF_SERVER_ROOT_URL}" .Values.gf_server_root_url -}}
{{- $data = $data | replace "${CR_GF_CSRF_TRUSTED_ORIGINS}" .Values.gf_csrf_trusted_origins -}}
{{- $data = $data | replace "${CR_GF_SMTP_ENABLED}" .Values.gf_smtp_enabled -}}
{{- $data = $data | replace "${CR_GF_SMTP_HOST}" .Values.gf_smtp_host -}}
{{- $data = $data | replace "${CR_GF_SMTP_USER}" .Values.gf_smtp_user -}}
{{- $data = $data | replace "${CR_GF_SMTP_PASSWORD}" .Values.gf_smtp_password -}}
{{- $data = $data | replace "${CR_GF_SMTP_FROM_ADDRESS}" .Values.gf_smtp_from_address -}}
{{- $data = $data | replace "${CR_GF_SMTP_FROM_NAME}" .Values.gf_smtp_from_name -}}
{{- $data = $data | replace "${CR_GF_SMTP_SKIP_VERIFY}" .Values.gf_smtp_skip_verify -}}
{{- $data = $data | replace "HELM-NAMESPACE" .Release.Namespace -}}
{{- $data = $data | replace "${CLOUD_ROBOTICS_DOMAIN}" .Values.domain -}}
{{- $data = $data | replace "${GCP_PROJECT_ID}" .Values.project -}}

{{ $data }}
69 changes: 69 additions & 0 deletions src/app_charts/grafana/grafana-cloud.values.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,69 @@
nameOverride: kube
fullnameOverride: kube

kubeTargetVersionOverride: "1.23.8"

# We use the kube-prometheus-stack chart instead of the standalone grafana chart
# because the stack chart natively bundles and updates a large collection of standard
# kubernetes monitoring dashboards (via kubernetes-mixin, node-exporter-mixin, etc.)
# as ConfigMaps. By disabling the rest of the backend components and keeping only Grafana
# enabled, we get a fully configured standalone Grafana with all the rich Kubernetes
# observability dashboards maintained for us out of the box.
grafana:
# default password used by old releases, deployed behind auth-proxy so this
# is not a secret.
# we could also use "auth proxy authentication" but the second login defends
# against unintentional edits to dashboards.
adminPassword: "prom-operator"
testFramework:
enabled: false
env:
GF_SERVER_DOMAIN: "${CR_GF_SERVER_DOMAIN}"
GF_SERVER_ROOT_URL: "${CR_GF_SERVER_ROOT_URL}"
GF_AUTH_ANONYMOUS_ENABLED: "true"
# Load dashboards from configmaps with a given label across all namespaces.
sidecar:
dashboards:
enabled: true
label: grafana # Label our own legacy grafana-operator uses.
searchNamespace: ALL
multicluster:
global:
enabled: true
etcd:
enabled: true
grafana.ini:
analytics:
check_for_updates: false
security:
csrf_trusted_origins: "${CR_GF_CSRF_TRUSTED_ORIGINS}"
smtp:
enabled: "${CR_GF_SMTP_ENABLED}"
host: "${CR_GF_SMTP_HOST}"
user: "${CR_GF_SMTP_USER}"
password: "${CR_GF_SMTP_PASSWORD}"
from_address: "${CR_GF_SMTP_FROM_ADDRESS}"
from_name: "${CR_GF_SMTP_FROM_NAME}"
skip_verify: "${CR_GF_SMTP_SKIP_VERIFY}"
serviceMonitor:
relabelings:
- sourceLabels: [__meta_kubernetes_pod_node_name]
targetLabel: instance

gf_ingress_auth_url: "${CR_GF_INGRESS_AUTH_URL}"
gf_ingress_auth_signin: "${CR_GF_INGRESS_AUTH_SIGNIN}"
gf_ingress_error_page_403: "${CR_GF_INGRESS_ERROR_PAGE_403}"

# Disable all non-Grafana components
defaultRules:
create: false
alertmanager:
enabled: false
prometheus:
enabled: false
kubeStateMetrics:
enabled: false
nodeExporter:
enabled: false
prometheusOperator:
enabled: false
43 changes: 43 additions & 0 deletions src/app_charts/grafana/values-cloud.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,43 @@
# Enable toggle for the standalone app components
grafana:
enabled: true

# Grafana HTTP configuration
gf_server_domain: "${CLOUD_ROBOTICS_DOMAIN}"
gf_server_root_url: "https://${CLOUD_ROBOTICS_DOMAIN}/grafana"
gf_csrf_trusted_origins: ""
# Grafana Ingress configuration. Does not use the same replace as the values above.
gf_ingress_auth_url: "http://oauth2-proxy.default.svc.cluster.local/apis/core.token-vendor/v1/token.verify"
# Header modification for Istio/HTTPRoutes support.
gf_ingress_auth_url_header: ""
gf_ingress_auth_url_headervalue: ""
gf_ingress_auth_signin: "https://{{ .Values.domain }}/oauth2/start?rd=$escaped_request_uri"
gf_ingress_error_page_403: "https://{{ .Values.domain }}/oauth2/start?rd=$escaped_request_uri"
gf_auth_backend:
protocol: "http"
service: "oauth2-proxy"
namespace: "default"
port: 80
path: "/oauth2/auth"
contextExtensions: {}
authProxy:
authHeaders:
- authorization
- cookie
- x-forwarded-access-token
- x-forwarded-host
- apikey-token
- x-server-name

# Grafana SMTP configuration
# Notes: these need to be all string, since we apply them using the template funtion "replace"
gf_smtp_enabled: "false"
gf_smtp_host: "smtp-host"
gf_smtp_user: "smtp-user"
gf_smtp_password: "smtp-api-key"
gf_smtp_from_address: "from-address@example.com"
gf_smtp_from_name: "from-name"
gf_smtp_skip_verify: "true"

# Fallback prometheus datasource namespace
prometheusNamespace: "app-prometheus"
6 changes: 4 additions & 2 deletions src/app_charts/prometheus/cloud/app.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -21,6 +21,10 @@ spec:
kind: Ingress
- group: apps
kind: StatefulSet
- group: gateway.networking.k8s.io
kind: HTTPRoute
- group: gateway.envoyproxy.io
kind: SecurityPolicy
descriptor:
type: "prometheus"
version: {{ .Chart.Version }}
Expand All@@ -31,5 +35,3 @@ spec:
links:
- description: Prometheus
url: "https://{{ .Values.domain }}/prometheus/"
- description: Grafana Dashboard
url: "https://{{ .Values.domain }}/grafana/"
13 changes: 12 additions & 1 deletion src/app_charts/prometheus/cloud/prometheus-operator.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,7 +7,18 @@
# need to be replaced last.
{{- $data := .Files.Get "files/prometheus-operator-chart.cloud.yaml" -}}
# Pre-process variables
{{- $data = $data | replace "${CR_GF_SERVER_DOMAIN}" .Values.gf_server_domain | replace "${CR_GF_SERVER_ROOT_URL}" .Values.gf_server_root_url | replace "${CR_GF_CSRF_TRUSTED_ORIGINS}" .Values.gf_csrf_trusted_origins | replace "${CR_GF_SMTP_ENABLED}" .Values.gf_smtp_enabled | replace "${CR_GF_SMTP_HOST}" .Values.gf_smtp_host | replace "${CR_GF_SMTP_USER}" .Values.gf_smtp_user | replace "${CR_GF_SMTP_PASSWORD}" .Values.gf_smtp_password | replace "${CR_GF_SMTP_FROM_ADDRESS}" .Values.gf_smtp_from_address | replace "${CR_GF_SMTP_FROM_NAME}" .Values.gf_smtp_from_name | replace "${CR_GF_SMTP_SKIP_VERIFY}" .Values.gf_smtp_skip_verify | replace "${CR_GF_INGRESS_AUTH_URL}" .Values.gf_ingress_auth_url | replace "${CR_GF_INGRESS_AUTH_SIGNIN}" .Values.gf_ingress_auth_signin | replace "${CR_GF_INGRESS_ERROR_PAGE_403}" .Values.gf_ingress_error_page_403 | replace "${CR_PROM_INGRESS_AUTH_URL}" .Values.prom_ingress_auth_url | replace "${CR_PROM_INGRESS_AUTH_SIGNIN}" .Values.prom_ingress_auth_signin | replace "${CR_PROM_INGRESS_ERROR_PAGE_403}" .Values.prom_ingress_error_page_403 | replace "HELM-NAMESPACE" .Release.Namespace | replace "${LIMITS_MEMORY}" .Values.limits.memory | replace "${LIMITS_CPU}" .Values.limits.cpu | replace "${REQUESTS_STORAGE}" .Values.requests.storage | replace "${RETENTION_TIME}" .Values.retention.time | replace "${RETENTION_SIZE}" .Values.retention.size | replace "${EXTERNAL_URL}" .Values.prom_external_url | replace "${CLOUD_ROBOTICS_DOMAIN}" .Values.domain | replace "${GCP_PROJECT_ID}" .Values.project -}}
{{- $data = $data | replace "${CR_PROM_INGRESS_AUTH_URL}" .Values.prom_ingress_auth_url -}}
{{- $data = $data | replace "${CR_PROM_INGRESS_AUTH_SIGNIN}" .Values.prom_ingress_auth_signin -}}
{{- $data = $data | replace "${CR_PROM_INGRESS_ERROR_PAGE_403}" .Values.prom_ingress_error_page_403 -}}
{{- $data = $data | replace "HELM-NAMESPACE" .Release.Namespace -}}
{{- $data = $data | replace "${LIMITS_MEMORY}" .Values.limits.memory -}}
{{- $data = $data | replace "${LIMITS_CPU}" .Values.limits.cpu -}}
{{- $data = $data | replace "${REQUESTS_STORAGE}" .Values.requests.storage -}}
{{- $data = $data | replace "${RETENTION_TIME}" .Values.retention.time -}}
{{- $data = $data | replace "${RETENTION_SIZE}" .Values.retention.size -}}
{{- $data = $data | replace "${EXTERNAL_URL}" .Values.prom_external_url -}}
{{- $data = $data | replace "${CLOUD_ROBOTICS_DOMAIN}" .Values.domain -}}
{{- $data = $data | replace "${GCP_PROJECT_ID}" .Values.project -}}

# Inject the nodeSelector as a pre-formatted YAML block to allow users to define multiple selectors in a dict within values-cloud.yaml while maintaining valid indentation in the output.
{{- $prometheusNodeSelectorMap := .Values.prometheus.prometheusSpec.nodeSelector -}}
Expand Down
44 changes: 1 addition & 43 deletions src/app_charts/prometheus/prometheus-cloud.values.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -182,49 +182,7 @@ nodeExporter:
targetLabel: instance

grafana:
# default password used by old releases, deployed behind auth-proxy so this
# is not a secret.
# we could also use "auth proxy authentication" but the second login defends
# against unintentional edits to dashboards.
adminPassword: "prom-operator"
testFramework:
enabled: false
env:
GF_SERVER_DOMAIN: "${CR_GF_SERVER_DOMAIN}"
GF_SERVER_ROOT_URL: "${CR_GF_SERVER_ROOT_URL}"
GF_AUTH_ANONYMOUS_ENABLED: "true"
# Load dashboards from configmaps with a given label across all namespaces.
sidecar:
dashboards:
enabled: true
label: grafana # Label our own legacy grafana-operator uses.
searchNamespace: ALL
multicluster:
global:
enabled: true
etcd:
enabled: true
grafana.ini:
analytics:
check_for_updates: false
security:
csrf_trusted_origins: "${CR_GF_CSRF_TRUSTED_ORIGINS}"
smtp:
enabled: "${CR_GF_SMTP_ENABLED}"
host: "${CR_GF_SMTP_HOST}"
user: "${CR_GF_SMTP_USER}"
password: "${CR_GF_SMTP_PASSWORD}"
from_address: "${CR_GF_SMTP_FROM_ADDRESS}"
from_name: "${CR_GF_SMTP_FROM_NAME}"
skip_verify: "${CR_GF_SMTP_SKIP_VERIFY}"
serviceMonitor:
relabelings:
- sourceLabels: [__meta_kubernetes_pod_node_name]
targetLabel: instance

gf_ingress_auth_url: "${CR_GF_INGRESS_AUTH_URL}"
gf_ingress_auth_signin: "${CR_GF_INGRESS_AUTH_SIGNIN}"
gf_ingress_error_page_403: "${CR_GF_INGRESS_ERROR_PAGE_403}"
enabled: false

prom_ingress_auth_url: "${CR_PROM_INGRESS_AUTH_URL}"
prom_ingress_auth_signin: "${CR_PROM_INGRESS_AUTH_SIGNIN}"
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions src/app_charts/BUILD.bazel
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,6 +7,7 @@ APPS = [
"k8s-relay",
"mission-crd",
"prometheus",
"grafana",
"token-vendor",
"akri",
]
Expand Down
3 changes: 3 additions & 0 deletions src/app_charts/base/cloud/oauth2-proxy.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -181,6 +181,9 @@ spec:
- group: gateway.envoyproxy.io
kind: SecurityPolicy
namespace: app-prometheus
- group: gateway.envoyproxy.io
kind: SecurityPolicy
namespace: app-grafana
to:
- group: ""
kind: Service
Expand Down
35 changes: 35 additions & 0 deletions src/app_charts/grafana/BUILD.bazel
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
load("//bazel:app.bzl", "app")
load("//bazel:app_chart.bzl", "app_chart")
load("//bazel:build_rules/helm_template.bzl", "helm_template")

helm_template(
name = "grafana-operator-chart.cloud",
# We use the kube-prometheus-stack chart instead of the standalone grafana chart
# because it natively bundles all the default Kubernetes mixin dashboards (like node-exporter,
# kubelet, apiserver) as ConfigMaps. We disable the rest of the backend components in the values file.
chart = "//third_party/kube-prometheus-stack:kube-prometheus-stack-87.5.1.tgz",
helm_version = 3,
kube_version = "1.29.0",
# The namespace will later be replaced with the actual one.
namespace = "HELM-NAMESPACE",
# Pick a short release name as it will be used as a prefix for a lot of resources.
release_name = "grafana",
values = "grafana-cloud.values.yaml",
)

app_chart(
name = "grafana-cloud",
# CRITICAL: Do NOT include 00-crds.yaml to prevent ownership collisions with Prometheus
extra_values = ["values-cloud.yaml"],
files = [
":grafana-operator-chart.cloud",
],
)

app(
name = "grafana",
charts = [
":grafana-cloud",
],
visibility = ["//visibility:public"],
)
32 changes: 32 additions & 0 deletions src/app_charts/grafana/cloud/app.yaml

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
apiVersion: app.k8s.io/v1beta1
kind: Application
metadata:
name: "grafana"
labels:
app.kubernetes.io/name: {{ .Chart.Name }}
app.kubernetes.io/version: {{ .Chart.Version }}
spec:
selector:
matchLabels:
app.kubernetes.io/name: {{ .Chart.Name }}
componentKinds:
- group: core
kind: Service
- group: apps
kind: Deployment
- group: apps
kind: Ingress
- group: gateway.networking.k8s.io
kind: HTTPRoute
- group: gateway.envoyproxy.io
kind: SecurityPolicy
descriptor:
type: "grafana"
version: {{ .Chart.Version }}
description: "Grafana provides visualization dashboards"
keywords:
- "dashboard"
- "visualization"
links:
- description: Grafana Dashboard
url: "https://{{ .Values.domain }}/grafana/"
22 changes: 22 additions & 0 deletions src/app_charts/grafana/cloud/grafana-datasources.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: grafana-datasources
labels:
grafana_datasource: "1"
app.kubernetes.io/name: {{ .Chart.Name }}
data:
datasources.yaml: |
apiVersion: 1
{{- if .Values.datasources }}
datasources:
{{ toYaml .Values.datasources | indent 4 }}
{{- else }}
datasources:
- name: Prometheus
type: prometheus
uid: prometheus
url: http://kube-prometheus.{{ .Values.prometheusNamespace | default "app-prometheus" }}.svc.cluster.local:9090
access: proxy
isDefault: true
{{- end }}
Original file line numberDiff line numberDiff line change
Expand Up@@ -23,7 +23,7 @@ spec:
type: ReplacePrefixMatch
replacePrefixMatch: /
backendRefs:
- name: prom-grafana
- name: grafana
port: 80
- matches:
- path:
Expand All@@ -36,7 +36,7 @@ spec:
type: ReplaceFullPath
replaceFullPath: /
backendRefs:
- name: prom-grafana
- name: grafana
port: 80
---
apiVersion: gateway.envoyproxy.io/v1alpha1
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -23,6 +23,6 @@ spec:
pathType: Prefix
backend:
service:
name: prom-grafana
name: grafana
port:
number: 80
25 changes: 25 additions & 0 deletions src/app_charts/grafana/cloud/grafana-operator.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
# This includes all resources expanded from the grafana-operator chart using
# the values in ../grafana-cloud.values.yaml.
# Some pseudo-variables that were inserted there are replaced with actual runtime values.
# NOTE: The order here is important. The domain and project might be part of other values and
# need to be replaced last.
{{- $data := .Files.Get "files/grafana-operator-chart.cloud.yaml" -}}
# Pre-process variables
{{- $data = $data | replace "${CR_GF_INGRESS_AUTH_URL}" .Values.gf_ingress_auth_url -}}
{{- $data = $data | replace "${CR_GF_INGRESS_AUTH_SIGNIN}" .Values.gf_ingress_auth_signin -}}
{{- $data = $data | replace "${CR_GF_INGRESS_ERROR_PAGE_403}" .Values.gf_ingress_error_page_403 -}}
{{- $data = $data | replace "${CR_GF_SERVER_DOMAIN}" .Values.gf_server_domain -}}
{{- $data = $data | replace "${CR_GF_SERVER_ROOT_URL}" .Values.gf_server_root_url -}}
{{- $data = $data | replace "${CR_GF_CSRF_TRUSTED_ORIGINS}" .Values.gf_csrf_trusted_origins -}}
{{- $data = $data | replace "${CR_GF_SMTP_ENABLED}" .Values.gf_smtp_enabled -}}
{{- $data = $data | replace "${CR_GF_SMTP_HOST}" .Values.gf_smtp_host -}}
{{- $data = $data | replace "${CR_GF_SMTP_USER}" .Values.gf_smtp_user -}}
{{- $data = $data | replace "${CR_GF_SMTP_PASSWORD}" .Values.gf_smtp_password -}}
{{- $data = $data | replace "${CR_GF_SMTP_FROM_ADDRESS}" .Values.gf_smtp_from_address -}}
{{- $data = $data | replace "${CR_GF_SMTP_FROM_NAME}" .Values.gf_smtp_from_name -}}
{{- $data = $data | replace "${CR_GF_SMTP_SKIP_VERIFY}" .Values.gf_smtp_skip_verify -}}
{{- $data = $data | replace "HELM-NAMESPACE" .Release.Namespace -}}
{{- $data = $data | replace "${CLOUD_ROBOTICS_DOMAIN}" .Values.domain -}}
{{- $data = $data | replace "${GCP_PROJECT_ID}" .Values.project -}}

{{ $data }}
69 changes: 69 additions & 0 deletions src/app_charts/grafana/grafana-cloud.values.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,69 @@
nameOverride: kube
fullnameOverride: kube

kubeTargetVersionOverride: "1.23.8"

# We use the kube-prometheus-stack chart instead of the standalone grafana chart
# because the stack chart natively bundles and updates a large collection of standard
# kubernetes monitoring dashboards (via kubernetes-mixin, node-exporter-mixin, etc.)
# as ConfigMaps. By disabling the rest of the backend components and keeping only Grafana
# enabled, we get a fully configured standalone Grafana with all the rich Kubernetes
# observability dashboards maintained for us out of the box.
grafana:
# default password used by old releases, deployed behind auth-proxy so this
# is not a secret.
# we could also use "auth proxy authentication" but the second login defends
# against unintentional edits to dashboards.
adminPassword: "prom-operator"
testFramework:
enabled: false
env:
GF_SERVER_DOMAIN: "${CR_GF_SERVER_DOMAIN}"
GF_SERVER_ROOT_URL: "${CR_GF_SERVER_ROOT_URL}"
GF_AUTH_ANONYMOUS_ENABLED: "true"
# Load dashboards from configmaps with a given label across all namespaces.
sidecar:
dashboards:
enabled: true
label: grafana # Label our own legacy grafana-operator uses.
searchNamespace: ALL
multicluster:
global:
enabled: true
etcd:
enabled: true
grafana.ini:
analytics:
check_for_updates: false
security:
csrf_trusted_origins: "${CR_GF_CSRF_TRUSTED_ORIGINS}"
smtp:
enabled: "${CR_GF_SMTP_ENABLED}"
host: "${CR_GF_SMTP_HOST}"
user: "${CR_GF_SMTP_USER}"
password: "${CR_GF_SMTP_PASSWORD}"
from_address: "${CR_GF_SMTP_FROM_ADDRESS}"
from_name: "${CR_GF_SMTP_FROM_NAME}"
skip_verify: "${CR_GF_SMTP_SKIP_VERIFY}"
serviceMonitor:
relabelings:
- sourceLabels: [__meta_kubernetes_pod_node_name]
targetLabel: instance

gf_ingress_auth_url: "${CR_GF_INGRESS_AUTH_URL}"
gf_ingress_auth_signin: "${CR_GF_INGRESS_AUTH_SIGNIN}"
gf_ingress_error_page_403: "${CR_GF_INGRESS_ERROR_PAGE_403}"

# Disable all non-Grafana components
defaultRules:
create: false
alertmanager:
enabled: false
prometheus:
enabled: false
kubeStateMetrics:
enabled: false
nodeExporter:
enabled: false
prometheusOperator:
enabled: false
43 changes: 43 additions & 0 deletions src/app_charts/grafana/values-cloud.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,43 @@
# Enable toggle for the standalone app components
grafana:
enabled: true

# Grafana HTTP configuration
gf_server_domain: "${CLOUD_ROBOTICS_DOMAIN}"
gf_server_root_url: "https://${CLOUD_ROBOTICS_DOMAIN}/grafana"
gf_csrf_trusted_origins: ""
# Grafana Ingress configuration. Does not use the same replace as the values above.
gf_ingress_auth_url: "http://oauth2-proxy.default.svc.cluster.local/apis/core.token-vendor/v1/token.verify"
# Header modification for Istio/HTTPRoutes support.
gf_ingress_auth_url_header: ""
gf_ingress_auth_url_headervalue: ""
gf_ingress_auth_signin: "https://{{ .Values.domain }}/oauth2/start?rd=$escaped_request_uri"
gf_ingress_error_page_403: "https://{{ .Values.domain }}/oauth2/start?rd=$escaped_request_uri"
gf_auth_backend:
protocol: "http"
service: "oauth2-proxy"
namespace: "default"
port: 80
path: "/oauth2/auth"
contextExtensions: {}
authProxy:
authHeaders:
- authorization
- cookie
- x-forwarded-access-token
- x-forwarded-host
- apikey-token
- x-server-name

# Grafana SMTP configuration
# Notes: these need to be all string, since we apply them using the template funtion "replace"
gf_smtp_enabled: "false"
gf_smtp_host: "smtp-host"
gf_smtp_user: "smtp-user"
gf_smtp_password: "smtp-api-key"
gf_smtp_from_address: "from-address@example.com"
gf_smtp_from_name: "from-name"
gf_smtp_skip_verify: "true"

# Fallback prometheus datasource namespace
prometheusNamespace: "app-prometheus"
6 changes: 4 additions & 2 deletions src/app_charts/prometheus/cloud/app.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -21,6 +21,10 @@ spec:
kind: Ingress
- group: apps
kind: StatefulSet
- group: gateway.networking.k8s.io
kind: HTTPRoute
- group: gateway.envoyproxy.io
kind: SecurityPolicy
descriptor:
type: "prometheus"
version: {{ .Chart.Version }}
Expand All@@ -31,5 +35,3 @@ spec:
links:
- description: Prometheus
url: "https://{{ .Values.domain }}/prometheus/"
- description: Grafana Dashboard
url: "https://{{ .Values.domain }}/grafana/"
13 changes: 12 additions & 1 deletion src/app_charts/prometheus/cloud/prometheus-operator.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,7 +7,18 @@
# need to be replaced last.
{{- $data := .Files.Get "files/prometheus-operator-chart.cloud.yaml" -}}
# Pre-process variables
{{- $data = $data | replace "${CR_GF_SERVER_DOMAIN}" .Values.gf_server_domain | replace "${CR_GF_SERVER_ROOT_URL}" .Values.gf_server_root_url | replace "${CR_GF_CSRF_TRUSTED_ORIGINS}" .Values.gf_csrf_trusted_origins | replace "${CR_GF_SMTP_ENABLED}" .Values.gf_smtp_enabled | replace "${CR_GF_SMTP_HOST}" .Values.gf_smtp_host | replace "${CR_GF_SMTP_USER}" .Values.gf_smtp_user | replace "${CR_GF_SMTP_PASSWORD}" .Values.gf_smtp_password | replace "${CR_GF_SMTP_FROM_ADDRESS}" .Values.gf_smtp_from_address | replace "${CR_GF_SMTP_FROM_NAME}" .Values.gf_smtp_from_name | replace "${CR_GF_SMTP_SKIP_VERIFY}" .Values.gf_smtp_skip_verify | replace "${CR_GF_INGRESS_AUTH_URL}" .Values.gf_ingress_auth_url | replace "${CR_GF_INGRESS_AUTH_SIGNIN}" .Values.gf_ingress_auth_signin | replace "${CR_GF_INGRESS_ERROR_PAGE_403}" .Values.gf_ingress_error_page_403 | replace "${CR_PROM_INGRESS_AUTH_URL}" .Values.prom_ingress_auth_url | replace "${CR_PROM_INGRESS_AUTH_SIGNIN}" .Values.prom_ingress_auth_signin | replace "${CR_PROM_INGRESS_ERROR_PAGE_403}" .Values.prom_ingress_error_page_403 | replace "HELM-NAMESPACE" .Release.Namespace | replace "${LIMITS_MEMORY}" .Values.limits.memory | replace "${LIMITS_CPU}" .Values.limits.cpu | replace "${REQUESTS_STORAGE}" .Values.requests.storage | replace "${RETENTION_TIME}" .Values.retention.time | replace "${RETENTION_SIZE}" .Values.retention.size | replace "${EXTERNAL_URL}" .Values.prom_external_url | replace "${CLOUD_ROBOTICS_DOMAIN}" .Values.domain | replace "${GCP_PROJECT_ID}" .Values.project -}}
{{- $data = $data | replace "${CR_PROM_INGRESS_AUTH_URL}" .Values.prom_ingress_auth_url -}}
{{- $data = $data | replace "${CR_PROM_INGRESS_AUTH_SIGNIN}" .Values.prom_ingress_auth_signin -}}
{{- $data = $data | replace "${CR_PROM_INGRESS_ERROR_PAGE_403}" .Values.prom_ingress_error_page_403 -}}
{{- $data = $data | replace "HELM-NAMESPACE" .Release.Namespace -}}
{{- $data = $data | replace "${LIMITS_MEMORY}" .Values.limits.memory -}}
{{- $data = $data | replace "${LIMITS_CPU}" .Values.limits.cpu -}}
{{- $data = $data | replace "${REQUESTS_STORAGE}" .Values.requests.storage -}}
{{- $data = $data | replace "${RETENTION_TIME}" .Values.retention.time -}}
{{- $data = $data | replace "${RETENTION_SIZE}" .Values.retention.size -}}
{{- $data = $data | replace "${EXTERNAL_URL}" .Values.prom_external_url -}}
{{- $data = $data | replace "${CLOUD_ROBOTICS_DOMAIN}" .Values.domain -}}
{{- $data = $data | replace "${GCP_PROJECT_ID}" .Values.project -}}

# Inject the nodeSelector as a pre-formatted YAML block to allow users to define multiple selectors in a dict within values-cloud.yaml while maintaining valid indentation in the output.
{{- $prometheusNodeSelectorMap := .Values.prometheus.prometheusSpec.nodeSelector -}}
Expand Down
44 changes: 1 addition & 43 deletions src/app_charts/prometheus/prometheus-cloud.values.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -182,49 +182,7 @@ nodeExporter:
targetLabel: instance

grafana:
# default password used by old releases, deployed behind auth-proxy so this
# is not a secret.
# we could also use "auth proxy authentication" but the second login defends
# against unintentional edits to dashboards.
adminPassword: "prom-operator"
testFramework:
enabled: false
env:
GF_SERVER_DOMAIN: "${CR_GF_SERVER_DOMAIN}"
GF_SERVER_ROOT_URL: "${CR_GF_SERVER_ROOT_URL}"
GF_AUTH_ANONYMOUS_ENABLED: "true"
# Load dashboards from configmaps with a given label across all namespaces.
sidecar:
dashboards:
enabled: true
label: grafana # Label our own legacy grafana-operator uses.
searchNamespace: ALL
multicluster:
global:
enabled: true
etcd:
enabled: true
grafana.ini:
analytics:
check_for_updates: false
security:
csrf_trusted_origins: "${CR_GF_CSRF_TRUSTED_ORIGINS}"
smtp:
enabled: "${CR_GF_SMTP_ENABLED}"
host: "${CR_GF_SMTP_HOST}"
user: "${CR_GF_SMTP_USER}"
password: "${CR_GF_SMTP_PASSWORD}"
from_address: "${CR_GF_SMTP_FROM_ADDRESS}"
from_name: "${CR_GF_SMTP_FROM_NAME}"
skip_verify: "${CR_GF_SMTP_SKIP_VERIFY}"
serviceMonitor:
relabelings:
- sourceLabels: [__meta_kubernetes_pod_node_name]
targetLabel: instance

gf_ingress_auth_url: "${CR_GF_INGRESS_AUTH_URL}"
gf_ingress_auth_signin: "${CR_GF_INGRESS_AUTH_SIGNIN}"
gf_ingress_error_page_403: "${CR_GF_INGRESS_ERROR_PAGE_403}"
enabled: false

prom_ingress_auth_url: "${CR_PROM_INGRESS_AUTH_URL}"
prom_ingress_auth_signin: "${CR_PROM_INGRESS_AUTH_SIGNIN}"
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions src/app_charts/BUILD.bazel
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,6 +7,7 @@ APPS = [
"k8s-relay",
"mission-crd",
"prometheus",
"grafana",
"token-vendor",
"akri",
]
Expand Down
3 changes: 3 additions & 0 deletions src/app_charts/base/cloud/oauth2-proxy.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -181,6 +181,9 @@ spec:
- group: gateway.envoyproxy.io
kind: SecurityPolicy
namespace: app-prometheus
- group: gateway.envoyproxy.io
kind: SecurityPolicy
namespace: app-grafana
to:
- group: ""
kind: Service
Expand Down
35 changes: 35 additions & 0 deletions src/app_charts/grafana/BUILD.bazel
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
load("//bazel:app.bzl", "app")
load("//bazel:app_chart.bzl", "app_chart")
load("//bazel:build_rules/helm_template.bzl", "helm_template")

helm_template(
name = "grafana-operator-chart.cloud",
# We use the kube-prometheus-stack chart instead of the standalone grafana chart
# because it natively bundles all the default Kubernetes mixin dashboards (like node-exporter,
# kubelet, apiserver) as ConfigMaps. We disable the rest of the backend components in the values file.
chart = "//third_party/kube-prometheus-stack:kube-prometheus-stack-87.5.1.tgz",
helm_version = 3,
kube_version = "1.29.0",
# The namespace will later be replaced with the actual one.
namespace = "HELM-NAMESPACE",
# Pick a short release name as it will be used as a prefix for a lot of resources.
release_name = "grafana",
values = "grafana-cloud.values.yaml",
)

app_chart(
name = "grafana-cloud",
# CRITICAL: Do NOT include 00-crds.yaml to prevent ownership collisions with Prometheus
extra_values = ["values-cloud.yaml"],
files = [
":grafana-operator-chart.cloud",
],
)

app(
name = "grafana",
charts = [
":grafana-cloud",
],
visibility = ["//visibility:public"],
)
32 changes: 32 additions & 0 deletions src/app_charts/grafana/cloud/app.yaml

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
apiVersion: app.k8s.io/v1beta1
kind: Application
metadata:
name: "grafana"
labels:
app.kubernetes.io/name: {{ .Chart.Name }}
app.kubernetes.io/version: {{ .Chart.Version }}
spec:
selector:
matchLabels:
app.kubernetes.io/name: {{ .Chart.Name }}
componentKinds:
- group: core
kind: Service
- group: apps
kind: Deployment
- group: apps
kind: Ingress
- group: gateway.networking.k8s.io
kind: HTTPRoute
- group: gateway.envoyproxy.io
kind: SecurityPolicy
descriptor:
type: "grafana"
version: {{ .Chart.Version }}
description: "Grafana provides visualization dashboards"
keywords:
- "dashboard"
- "visualization"
links:
- description: Grafana Dashboard
url: "https://{{ .Values.domain }}/grafana/"
22 changes: 22 additions & 0 deletions src/app_charts/grafana/cloud/grafana-datasources.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: grafana-datasources
labels:
grafana_datasource: "1"
app.kubernetes.io/name: {{ .Chart.Name }}
data:
datasources.yaml: |
apiVersion: 1
{{- if .Values.datasources }}
datasources:
{{ toYaml .Values.datasources | indent 4 }}
{{- else }}
datasources:
- name: Prometheus
type: prometheus
uid: prometheus
url: http://kube-prometheus.{{ .Values.prometheusNamespace | default "app-prometheus" }}.svc.cluster.local:9090
access: proxy
isDefault: true
{{- end }}
Original file line numberDiff line numberDiff line change
Expand Up@@ -23,7 +23,7 @@ spec:
type: ReplacePrefixMatch
replacePrefixMatch: /
backendRefs:
- name: prom-grafana
- name: grafana
port: 80
- matches:
- path:
Expand All@@ -36,7 +36,7 @@ spec:
type: ReplaceFullPath
replaceFullPath: /
backendRefs:
- name: prom-grafana
- name: grafana
port: 80
---
apiVersion: gateway.envoyproxy.io/v1alpha1
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -23,6 +23,6 @@ spec:
pathType: Prefix
backend:
service:
name: prom-grafana
name: grafana
port:
number: 80
25 changes: 25 additions & 0 deletions src/app_charts/grafana/cloud/grafana-operator.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
# This includes all resources expanded from the grafana-operator chart using
# the values in ../grafana-cloud.values.yaml.
# Some pseudo-variables that were inserted there are replaced with actual runtime values.
# NOTE: The order here is important. The domain and project might be part of other values and
# need to be replaced last.
{{- $data := .Files.Get "files/grafana-operator-chart.cloud.yaml" -}}
# Pre-process variables
{{- $data = $data | replace "${CR_GF_INGRESS_AUTH_URL}" .Values.gf_ingress_auth_url -}}
{{- $data = $data | replace "${CR_GF_INGRESS_AUTH_SIGNIN}" .Values.gf_ingress_auth_signin -}}
{{- $data = $data | replace "${CR_GF_INGRESS_ERROR_PAGE_403}" .Values.gf_ingress_error_page_403 -}}
{{- $data = $data | replace "${CR_GF_SERVER_DOMAIN}" .Values.gf_server_domain -}}
{{- $data = $data | replace "${CR_GF_SERVER_ROOT_URL}" .Values.gf_server_root_url -}}
{{- $data = $data | replace "${CR_GF_CSRF_TRUSTED_ORIGINS}" .Values.gf_csrf_trusted_origins -}}
{{- $data = $data | replace "${CR_GF_SMTP_ENABLED}" .Values.gf_smtp_enabled -}}
{{- $data = $data | replace "${CR_GF_SMTP_HOST}" .Values.gf_smtp_host -}}
{{- $data = $data | replace "${CR_GF_SMTP_USER}" .Values.gf_smtp_user -}}
{{- $data = $data | replace "${CR_GF_SMTP_PASSWORD}" .Values.gf_smtp_password -}}
{{- $data = $data | replace "${CR_GF_SMTP_FROM_ADDRESS}" .Values.gf_smtp_from_address -}}
{{- $data = $data | replace "${CR_GF_SMTP_FROM_NAME}" .Values.gf_smtp_from_name -}}
{{- $data = $data | replace "${CR_GF_SMTP_SKIP_VERIFY}" .Values.gf_smtp_skip_verify -}}
{{- $data = $data | replace "HELM-NAMESPACE" .Release.Namespace -}}
{{- $data = $data | replace "${CLOUD_ROBOTICS_DOMAIN}" .Values.domain -}}
{{- $data = $data | replace "${GCP_PROJECT_ID}" .Values.project -}}

{{ $data }}
69 changes: 69 additions & 0 deletions src/app_charts/grafana/grafana-cloud.values.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,69 @@
nameOverride: kube
fullnameOverride: kube

kubeTargetVersionOverride: "1.23.8"

# We use the kube-prometheus-stack chart instead of the standalone grafana chart
# because the stack chart natively bundles and updates a large collection of standard
# kubernetes monitoring dashboards (via kubernetes-mixin, node-exporter-mixin, etc.)
# as ConfigMaps. By disabling the rest of the backend components and keeping only Grafana
# enabled, we get a fully configured standalone Grafana with all the rich Kubernetes
# observability dashboards maintained for us out of the box.
grafana:
# default password used by old releases, deployed behind auth-proxy so this
# is not a secret.
# we could also use "auth proxy authentication" but the second login defends
# against unintentional edits to dashboards.
adminPassword: "prom-operator"
testFramework:
enabled: false
env:
GF_SERVER_DOMAIN: "${CR_GF_SERVER_DOMAIN}"
GF_SERVER_ROOT_URL: "${CR_GF_SERVER_ROOT_URL}"
GF_AUTH_ANONYMOUS_ENABLED: "true"
# Load dashboards from configmaps with a given label across all namespaces.
sidecar:
dashboards:
enabled: true
label: grafana # Label our own legacy grafana-operator uses.
searchNamespace: ALL
multicluster:
global:
enabled: true
etcd:
enabled: true
grafana.ini:
analytics:
check_for_updates: false
security:
csrf_trusted_origins: "${CR_GF_CSRF_TRUSTED_ORIGINS}"
smtp:
enabled: "${CR_GF_SMTP_ENABLED}"
host: "${CR_GF_SMTP_HOST}"
user: "${CR_GF_SMTP_USER}"
password: "${CR_GF_SMTP_PASSWORD}"
from_address: "${CR_GF_SMTP_FROM_ADDRESS}"
from_name: "${CR_GF_SMTP_FROM_NAME}"
skip_verify: "${CR_GF_SMTP_SKIP_VERIFY}"
serviceMonitor:
relabelings:
- sourceLabels: [__meta_kubernetes_pod_node_name]
targetLabel: instance

gf_ingress_auth_url: "${CR_GF_INGRESS_AUTH_URL}"
gf_ingress_auth_signin: "${CR_GF_INGRESS_AUTH_SIGNIN}"
gf_ingress_error_page_403: "${CR_GF_INGRESS_ERROR_PAGE_403}"

# Disable all non-Grafana components
defaultRules:
create: false
alertmanager:
enabled: false
prometheus:
enabled: false
kubeStateMetrics:
enabled: false
nodeExporter:
enabled: false
prometheusOperator:
enabled: false
43 changes: 43 additions & 0 deletions src/app_charts/grafana/values-cloud.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,43 @@
# Enable toggle for the standalone app components
grafana:
enabled: true

# Grafana HTTP configuration
gf_server_domain: "${CLOUD_ROBOTICS_DOMAIN}"
gf_server_root_url: "https://${CLOUD_ROBOTICS_DOMAIN}/grafana"
gf_csrf_trusted_origins: ""
# Grafana Ingress configuration. Does not use the same replace as the values above.
gf_ingress_auth_url: "http://oauth2-proxy.default.svc.cluster.local/apis/core.token-vendor/v1/token.verify"
# Header modification for Istio/HTTPRoutes support.
gf_ingress_auth_url_header: ""
gf_ingress_auth_url_headervalue: ""
gf_ingress_auth_signin: "https://{{ .Values.domain }}/oauth2/start?rd=$escaped_request_uri"
gf_ingress_error_page_403: "https://{{ .Values.domain }}/oauth2/start?rd=$escaped_request_uri"
gf_auth_backend:
protocol: "http"
service: "oauth2-proxy"
namespace: "default"
port: 80
path: "/oauth2/auth"
contextExtensions: {}
authProxy:
authHeaders:
- authorization
- cookie
- x-forwarded-access-token
- x-forwarded-host
- apikey-token
- x-server-name

# Grafana SMTP configuration
# Notes: these need to be all string, since we apply them using the template funtion "replace"
gf_smtp_enabled: "false"
gf_smtp_host: "smtp-host"
gf_smtp_user: "smtp-user"
gf_smtp_password: "smtp-api-key"
gf_smtp_from_address: "from-address@example.com"
gf_smtp_from_name: "from-name"
gf_smtp_skip_verify: "true"

# Fallback prometheus datasource namespace
prometheusNamespace: "app-prometheus"
6 changes: 4 additions & 2 deletions src/app_charts/prometheus/cloud/app.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -21,6 +21,10 @@ spec:
kind: Ingress
- group: apps
kind: StatefulSet
- group: gateway.networking.k8s.io
kind: HTTPRoute
- group: gateway.envoyproxy.io
kind: SecurityPolicy
descriptor:
type: "prometheus"
version: {{ .Chart.Version }}
Expand All@@ -31,5 +35,3 @@ spec:
links:
- description: Prometheus
url: "https://{{ .Values.domain }}/prometheus/"
- description: Grafana Dashboard
url: "https://{{ .Values.domain }}/grafana/"
13 changes: 12 additions & 1 deletion src/app_charts/prometheus/cloud/prometheus-operator.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,7 +7,18 @@
# need to be replaced last.
{{- $data := .Files.Get "files/prometheus-operator-chart.cloud.yaml" -}}
# Pre-process variables
{{- $data = $data | replace "${CR_GF_SERVER_DOMAIN}" .Values.gf_server_domain | replace "${CR_GF_SERVER_ROOT_URL}" .Values.gf_server_root_url | replace "${CR_GF_CSRF_TRUSTED_ORIGINS}" .Values.gf_csrf_trusted_origins | replace "${CR_GF_SMTP_ENABLED}" .Values.gf_smtp_enabled | replace "${CR_GF_SMTP_HOST}" .Values.gf_smtp_host | replace "${CR_GF_SMTP_USER}" .Values.gf_smtp_user | replace "${CR_GF_SMTP_PASSWORD}" .Values.gf_smtp_password | replace "${CR_GF_SMTP_FROM_ADDRESS}" .Values.gf_smtp_from_address | replace "${CR_GF_SMTP_FROM_NAME}" .Values.gf_smtp_from_name | replace "${CR_GF_SMTP_SKIP_VERIFY}" .Values.gf_smtp_skip_verify | replace "${CR_GF_INGRESS_AUTH_URL}" .Values.gf_ingress_auth_url | replace "${CR_GF_INGRESS_AUTH_SIGNIN}" .Values.gf_ingress_auth_signin | replace "${CR_GF_INGRESS_ERROR_PAGE_403}" .Values.gf_ingress_error_page_403 | replace "${CR_PROM_INGRESS_AUTH_URL}" .Values.prom_ingress_auth_url | replace "${CR_PROM_INGRESS_AUTH_SIGNIN}" .Values.prom_ingress_auth_signin | replace "${CR_PROM_INGRESS_ERROR_PAGE_403}" .Values.prom_ingress_error_page_403 | replace "HELM-NAMESPACE" .Release.Namespace | replace "${LIMITS_MEMORY}" .Values.limits.memory | replace "${LIMITS_CPU}" .Values.limits.cpu | replace "${REQUESTS_STORAGE}" .Values.requests.storage | replace "${RETENTION_TIME}" .Values.retention.time | replace "${RETENTION_SIZE}" .Values.retention.size | replace "${EXTERNAL_URL}" .Values.prom_external_url | replace "${CLOUD_ROBOTICS_DOMAIN}" .Values.domain | replace "${GCP_PROJECT_ID}" .Values.project -}}
{{- $data = $data | replace "${CR_PROM_INGRESS_AUTH_URL}" .Values.prom_ingress_auth_url -}}
{{- $data = $data | replace "${CR_PROM_INGRESS_AUTH_SIGNIN}" .Values.prom_ingress_auth_signin -}}
{{- $data = $data | replace "${CR_PROM_INGRESS_ERROR_PAGE_403}" .Values.prom_ingress_error_page_403 -}}
{{- $data = $data | replace "HELM-NAMESPACE" .Release.Namespace -}}
{{- $data = $data | replace "${LIMITS_MEMORY}" .Values.limits.memory -}}
{{- $data = $data | replace "${LIMITS_CPU}" .Values.limits.cpu -}}
{{- $data = $data | replace "${REQUESTS_STORAGE}" .Values.requests.storage -}}
{{- $data = $data | replace "${RETENTION_TIME}" .Values.retention.time -}}
{{- $data = $data | replace "${RETENTION_SIZE}" .Values.retention.size -}}
{{- $data = $data | replace "${EXTERNAL_URL}" .Values.prom_external_url -}}
{{- $data = $data | replace "${CLOUD_ROBOTICS_DOMAIN}" .Values.domain -}}
{{- $data = $data | replace "${GCP_PROJECT_ID}" .Values.project -}}

# Inject the nodeSelector as a pre-formatted YAML block to allow users to define multiple selectors in a dict within values-cloud.yaml while maintaining valid indentation in the output.
{{- $prometheusNodeSelectorMap := .Values.prometheus.prometheusSpec.nodeSelector -}}
Expand Down
44 changes: 1 addition & 43 deletions src/app_charts/prometheus/prometheus-cloud.values.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -182,49 +182,7 @@ nodeExporter:
targetLabel: instance

grafana:
# default password used by old releases, deployed behind auth-proxy so this
# is not a secret.
# we could also use "auth proxy authentication" but the second login defends
# against unintentional edits to dashboards.
adminPassword: "prom-operator"
testFramework:
enabled: false
env:
GF_SERVER_DOMAIN: "${CR_GF_SERVER_DOMAIN}"
GF_SERVER_ROOT_URL: "${CR_GF_SERVER_ROOT_URL}"
GF_AUTH_ANONYMOUS_ENABLED: "true"
# Load dashboards from configmaps with a given label across all namespaces.
sidecar:
dashboards:
enabled: true
label: grafana # Label our own legacy grafana-operator uses.
searchNamespace: ALL
multicluster:
global:
enabled: true
etcd:
enabled: true
grafana.ini:
analytics:
check_for_updates: false
security:
csrf_trusted_origins: "${CR_GF_CSRF_TRUSTED_ORIGINS}"
smtp:
enabled: "${CR_GF_SMTP_ENABLED}"
host: "${CR_GF_SMTP_HOST}"
user: "${CR_GF_SMTP_USER}"
password: "${CR_GF_SMTP_PASSWORD}"
from_address: "${CR_GF_SMTP_FROM_ADDRESS}"
from_name: "${CR_GF_SMTP_FROM_NAME}"
skip_verify: "${CR_GF_SMTP_SKIP_VERIFY}"
serviceMonitor:
relabelings:
- sourceLabels: [__meta_kubernetes_pod_node_name]
targetLabel: instance

gf_ingress_auth_url: "${CR_GF_INGRESS_AUTH_URL}"
gf_ingress_auth_signin: "${CR_GF_INGRESS_AUTH_SIGNIN}"
gf_ingress_error_page_403: "${CR_GF_INGRESS_ERROR_PAGE_403}"
enabled: false

prom_ingress_auth_url: "${CR_PROM_INGRESS_AUTH_URL}"
prom_ingress_auth_signin: "${CR_PROM_INGRESS_AUTH_SIGNIN}"
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions src/app_charts/BUILD.bazel
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,6 +7,7 @@ APPS = [
"k8s-relay",
"mission-crd",
"prometheus",
"grafana",
"token-vendor",
"akri",
]
Expand Down
3 changes: 3 additions & 0 deletions src/app_charts/base/cloud/oauth2-proxy.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -181,6 +181,9 @@ spec:
- group: gateway.envoyproxy.io
kind: SecurityPolicy
namespace: app-prometheus
- group: gateway.envoyproxy.io
kind: SecurityPolicy
namespace: app-grafana
to:
- group: ""
kind: Service
Expand Down
35 changes: 35 additions & 0 deletions src/app_charts/grafana/BUILD.bazel
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
load("//bazel:app.bzl", "app")
load("//bazel:app_chart.bzl", "app_chart")
load("//bazel:build_rules/helm_template.bzl", "helm_template")

helm_template(
name = "grafana-operator-chart.cloud",
# We use the kube-prometheus-stack chart instead of the standalone grafana chart
# because it natively bundles all the default Kubernetes mixin dashboards (like node-exporter,
# kubelet, apiserver) as ConfigMaps. We disable the rest of the backend components in the values file.
chart = "//third_party/kube-prometheus-stack:kube-prometheus-stack-87.5.1.tgz",
helm_version = 3,
kube_version = "1.29.0",
# The namespace will later be replaced with the actual one.
namespace = "HELM-NAMESPACE",
# Pick a short release name as it will be used as a prefix for a lot of resources.
release_name = "grafana",
values = "grafana-cloud.values.yaml",
)

app_chart(
name = "grafana-cloud",
# CRITICAL: Do NOT include 00-crds.yaml to prevent ownership collisions with Prometheus
extra_values = ["values-cloud.yaml"],
files = [
":grafana-operator-chart.cloud",
],
)

app(
name = "grafana",
charts = [
":grafana-cloud",
],
visibility = ["//visibility:public"],
)
32 changes: 32 additions & 0 deletions src/app_charts/grafana/cloud/app.yaml

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
apiVersion: app.k8s.io/v1beta1
kind: Application
metadata:
name: "grafana"
labels:
app.kubernetes.io/name: {{ .Chart.Name }}
app.kubernetes.io/version: {{ .Chart.Version }}
spec:
selector:
matchLabels:
app.kubernetes.io/name: {{ .Chart.Name }}
componentKinds:
- group: core
kind: Service
- group: apps
kind: Deployment
- group: apps
kind: Ingress
- group: gateway.networking.k8s.io
kind: HTTPRoute
- group: gateway.envoyproxy.io
kind: SecurityPolicy
descriptor:
type: "grafana"
version: {{ .Chart.Version }}
description: "Grafana provides visualization dashboards"
keywords:
- "dashboard"
- "visualization"
links:
- description: Grafana Dashboard
url: "https://{{ .Values.domain }}/grafana/"
22 changes: 22 additions & 0 deletions src/app_charts/grafana/cloud/grafana-datasources.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: grafana-datasources
labels:
grafana_datasource: "1"
app.kubernetes.io/name: {{ .Chart.Name }}
data:
datasources.yaml: |
apiVersion: 1
{{- if .Values.datasources }}
datasources:
{{ toYaml .Values.datasources | indent 4 }}
{{- else }}
datasources:
- name: Prometheus
type: prometheus
uid: prometheus
url: http://kube-prometheus.{{ .Values.prometheusNamespace | default "app-prometheus" }}.svc.cluster.local:9090
access: proxy
isDefault: true
{{- end }}
Original file line numberDiff line numberDiff line change
Expand Up@@ -23,7 +23,7 @@ spec:
type: ReplacePrefixMatch
replacePrefixMatch: /
backendRefs:
- name: prom-grafana
- name: grafana
port: 80
- matches:
- path:
Expand All@@ -36,7 +36,7 @@ spec:
type: ReplaceFullPath
replaceFullPath: /
backendRefs:
- name: prom-grafana
- name: grafana
port: 80
---
apiVersion: gateway.envoyproxy.io/v1alpha1
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -23,6 +23,6 @@ spec:
pathType: Prefix
backend:
service:
name: prom-grafana
name: grafana
port:
number: 80
25 changes: 25 additions & 0 deletions src/app_charts/grafana/cloud/grafana-operator.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
# This includes all resources expanded from the grafana-operator chart using
# the values in ../grafana-cloud.values.yaml.
# Some pseudo-variables that were inserted there are replaced with actual runtime values.
# NOTE: The order here is important. The domain and project might be part of other values and
# need to be replaced last.
{{- $data := .Files.Get "files/grafana-operator-chart.cloud.yaml" -}}
# Pre-process variables
{{- $data = $data | replace "${CR_GF_INGRESS_AUTH_URL}" .Values.gf_ingress_auth_url -}}
{{- $data = $data | replace "${CR_GF_INGRESS_AUTH_SIGNIN}" .Values.gf_ingress_auth_signin -}}
{{- $data = $data | replace "${CR_GF_INGRESS_ERROR_PAGE_403}" .Values.gf_ingress_error_page_403 -}}
{{- $data = $data | replace "${CR_GF_SERVER_DOMAIN}" .Values.gf_server_domain -}}
{{- $data = $data | replace "${CR_GF_SERVER_ROOT_URL}" .Values.gf_server_root_url -}}
{{- $data = $data | replace "${CR_GF_CSRF_TRUSTED_ORIGINS}" .Values.gf_csrf_trusted_origins -}}
{{- $data = $data | replace "${CR_GF_SMTP_ENABLED}" .Values.gf_smtp_enabled -}}
{{- $data = $data | replace "${CR_GF_SMTP_HOST}" .Values.gf_smtp_host -}}
{{- $data = $data | replace "${CR_GF_SMTP_USER}" .Values.gf_smtp_user -}}
{{- $data = $data | replace "${CR_GF_SMTP_PASSWORD}" .Values.gf_smtp_password -}}
{{- $data = $data | replace "${CR_GF_SMTP_FROM_ADDRESS}" .Values.gf_smtp_from_address -}}
{{- $data = $data | replace "${CR_GF_SMTP_FROM_NAME}" .Values.gf_smtp_from_name -}}
{{- $data = $data | replace "${CR_GF_SMTP_SKIP_VERIFY}" .Values.gf_smtp_skip_verify -}}
{{- $data = $data | replace "HELM-NAMESPACE" .Release.Namespace -}}
{{- $data = $data | replace "${CLOUD_ROBOTICS_DOMAIN}" .Values.domain -}}
{{- $data = $data | replace "${GCP_PROJECT_ID}" .Values.project -}}

{{ $data }}
69 changes: 69 additions & 0 deletions src/app_charts/grafana/grafana-cloud.values.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,69 @@
nameOverride: kube
fullnameOverride: kube

kubeTargetVersionOverride: "1.23.8"

# We use the kube-prometheus-stack chart instead of the standalone grafana chart
# because the stack chart natively bundles and updates a large collection of standard
# kubernetes monitoring dashboards (via kubernetes-mixin, node-exporter-mixin, etc.)
# as ConfigMaps. By disabling the rest of the backend components and keeping only Grafana
# enabled, we get a fully configured standalone Grafana with all the rich Kubernetes
# observability dashboards maintained for us out of the box.
grafana:
# default password used by old releases, deployed behind auth-proxy so this
# is not a secret.
# we could also use "auth proxy authentication" but the second login defends
# against unintentional edits to dashboards.
adminPassword: "prom-operator"
testFramework:
enabled: false
env:
GF_SERVER_DOMAIN: "${CR_GF_SERVER_DOMAIN}"
GF_SERVER_ROOT_URL: "${CR_GF_SERVER_ROOT_URL}"
GF_AUTH_ANONYMOUS_ENABLED: "true"
# Load dashboards from configmaps with a given label across all namespaces.
sidecar:
dashboards:
enabled: true
label: grafana # Label our own legacy grafana-operator uses.
searchNamespace: ALL
multicluster:
global:
enabled: true
etcd:
enabled: true
grafana.ini:
analytics:
check_for_updates: false
security:
csrf_trusted_origins: "${CR_GF_CSRF_TRUSTED_ORIGINS}"
smtp:
enabled: "${CR_GF_SMTP_ENABLED}"
host: "${CR_GF_SMTP_HOST}"
user: "${CR_GF_SMTP_USER}"
password: "${CR_GF_SMTP_PASSWORD}"
from_address: "${CR_GF_SMTP_FROM_ADDRESS}"
from_name: "${CR_GF_SMTP_FROM_NAME}"
skip_verify: "${CR_GF_SMTP_SKIP_VERIFY}"
serviceMonitor:
relabelings:
- sourceLabels: [__meta_kubernetes_pod_node_name]
targetLabel: instance

gf_ingress_auth_url: "${CR_GF_INGRESS_AUTH_URL}"
gf_ingress_auth_signin: "${CR_GF_INGRESS_AUTH_SIGNIN}"
gf_ingress_error_page_403: "${CR_GF_INGRESS_ERROR_PAGE_403}"

# Disable all non-Grafana components
defaultRules:
create: false
alertmanager:
enabled: false
prometheus:
enabled: false
kubeStateMetrics:
enabled: false
nodeExporter:
enabled: false
prometheusOperator:
enabled: false
43 changes: 43 additions & 0 deletions src/app_charts/grafana/values-cloud.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,43 @@
# Enable toggle for the standalone app components
grafana:
enabled: true

# Grafana HTTP configuration
gf_server_domain: "${CLOUD_ROBOTICS_DOMAIN}"
gf_server_root_url: "https://${CLOUD_ROBOTICS_DOMAIN}/grafana"
gf_csrf_trusted_origins: ""
# Grafana Ingress configuration. Does not use the same replace as the values above.
gf_ingress_auth_url: "http://oauth2-proxy.default.svc.cluster.local/apis/core.token-vendor/v1/token.verify"
# Header modification for Istio/HTTPRoutes support.
gf_ingress_auth_url_header: ""
gf_ingress_auth_url_headervalue: ""
gf_ingress_auth_signin: "https://{{ .Values.domain }}/oauth2/start?rd=$escaped_request_uri"
gf_ingress_error_page_403: "https://{{ .Values.domain }}/oauth2/start?rd=$escaped_request_uri"
gf_auth_backend:
protocol: "http"
service: "oauth2-proxy"
namespace: "default"
port: 80
path: "/oauth2/auth"
contextExtensions: {}
authProxy:
authHeaders:
- authorization
- cookie
- x-forwarded-access-token
- x-forwarded-host
- apikey-token
- x-server-name

# Grafana SMTP configuration
# Notes: these need to be all string, since we apply them using the template funtion "replace"
gf_smtp_enabled: "false"
gf_smtp_host: "smtp-host"
gf_smtp_user: "smtp-user"
gf_smtp_password: "smtp-api-key"
gf_smtp_from_address: "from-address@example.com"
gf_smtp_from_name: "from-name"
gf_smtp_skip_verify: "true"

# Fallback prometheus datasource namespace
prometheusNamespace: "app-prometheus"
6 changes: 4 additions & 2 deletions src/app_charts/prometheus/cloud/app.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -21,6 +21,10 @@ spec:
kind: Ingress
- group: apps
kind: StatefulSet
- group: gateway.networking.k8s.io
kind: HTTPRoute
- group: gateway.envoyproxy.io
kind: SecurityPolicy
descriptor:
type: "prometheus"
version: {{ .Chart.Version }}
Expand All@@ -31,5 +35,3 @@ spec:
links:
- description: Prometheus
url: "https://{{ .Values.domain }}/prometheus/"
- description: Grafana Dashboard
url: "https://{{ .Values.domain }}/grafana/"
13 changes: 12 additions & 1 deletion src/app_charts/prometheus/cloud/prometheus-operator.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,7 +7,18 @@
# need to be replaced last.
{{- $data := .Files.Get "files/prometheus-operator-chart.cloud.yaml" -}}
# Pre-process variables
{{- $data = $data | replace "${CR_GF_SERVER_DOMAIN}" .Values.gf_server_domain | replace "${CR_GF_SERVER_ROOT_URL}" .Values.gf_server_root_url | replace "${CR_GF_CSRF_TRUSTED_ORIGINS}" .Values.gf_csrf_trusted_origins | replace "${CR_GF_SMTP_ENABLED}" .Values.gf_smtp_enabled | replace "${CR_GF_SMTP_HOST}" .Values.gf_smtp_host | replace "${CR_GF_SMTP_USER}" .Values.gf_smtp_user | replace "${CR_GF_SMTP_PASSWORD}" .Values.gf_smtp_password | replace "${CR_GF_SMTP_FROM_ADDRESS}" .Values.gf_smtp_from_address | replace "${CR_GF_SMTP_FROM_NAME}" .Values.gf_smtp_from_name | replace "${CR_GF_SMTP_SKIP_VERIFY}" .Values.gf_smtp_skip_verify | replace "${CR_GF_INGRESS_AUTH_URL}" .Values.gf_ingress_auth_url | replace "${CR_GF_INGRESS_AUTH_SIGNIN}" .Values.gf_ingress_auth_signin | replace "${CR_GF_INGRESS_ERROR_PAGE_403}" .Values.gf_ingress_error_page_403 | replace "${CR_PROM_INGRESS_AUTH_URL}" .Values.prom_ingress_auth_url | replace "${CR_PROM_INGRESS_AUTH_SIGNIN}" .Values.prom_ingress_auth_signin | replace "${CR_PROM_INGRESS_ERROR_PAGE_403}" .Values.prom_ingress_error_page_403 | replace "HELM-NAMESPACE" .Release.Namespace | replace "${LIMITS_MEMORY}" .Values.limits.memory | replace "${LIMITS_CPU}" .Values.limits.cpu | replace "${REQUESTS_STORAGE}" .Values.requests.storage | replace "${RETENTION_TIME}" .Values.retention.time | replace "${RETENTION_SIZE}" .Values.retention.size | replace "${EXTERNAL_URL}" .Values.prom_external_url | replace "${CLOUD_ROBOTICS_DOMAIN}" .Values.domain | replace "${GCP_PROJECT_ID}" .Values.project -}}
{{- $data = $data | replace "${CR_PROM_INGRESS_AUTH_URL}" .Values.prom_ingress_auth_url -}}
{{- $data = $data | replace "${CR_PROM_INGRESS_AUTH_SIGNIN}" .Values.prom_ingress_auth_signin -}}
{{- $data = $data | replace "${CR_PROM_INGRESS_ERROR_PAGE_403}" .Values.prom_ingress_error_page_403 -}}
{{- $data = $data | replace "HELM-NAMESPACE" .Release.Namespace -}}
{{- $data = $data | replace "${LIMITS_MEMORY}" .Values.limits.memory -}}
{{- $data = $data | replace "${LIMITS_CPU}" .Values.limits.cpu -}}
{{- $data = $data | replace "${REQUESTS_STORAGE}" .Values.requests.storage -}}
{{- $data = $data | replace "${RETENTION_TIME}" .Values.retention.time -}}
{{- $data = $data | replace "${RETENTION_SIZE}" .Values.retention.size -}}
{{- $data = $data | replace "${EXTERNAL_URL}" .Values.prom_external_url -}}
{{- $data = $data | replace "${CLOUD_ROBOTICS_DOMAIN}" .Values.domain -}}
{{- $data = $data | replace "${GCP_PROJECT_ID}" .Values.project -}}

# Inject the nodeSelector as a pre-formatted YAML block to allow users to define multiple selectors in a dict within values-cloud.yaml while maintaining valid indentation in the output.
{{- $prometheusNodeSelectorMap := .Values.prometheus.prometheusSpec.nodeSelector -}}
Expand Down
44 changes: 1 addition & 43 deletions src/app_charts/prometheus/prometheus-cloud.values.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -182,49 +182,7 @@ nodeExporter:
targetLabel: instance

grafana:
# default password used by old releases, deployed behind auth-proxy so this
# is not a secret.
# we could also use "auth proxy authentication" but the second login defends
# against unintentional edits to dashboards.
adminPassword: "prom-operator"
testFramework:
enabled: false
env:
GF_SERVER_DOMAIN: "${CR_GF_SERVER_DOMAIN}"
GF_SERVER_ROOT_URL: "${CR_GF_SERVER_ROOT_URL}"
GF_AUTH_ANONYMOUS_ENABLED: "true"
# Load dashboards from configmaps with a given label across all namespaces.
sidecar:
dashboards:
enabled: true
label: grafana # Label our own legacy grafana-operator uses.
searchNamespace: ALL
multicluster:
global:
enabled: true
etcd:
enabled: true
grafana.ini:
analytics:
check_for_updates: false
security:
csrf_trusted_origins: "${CR_GF_CSRF_TRUSTED_ORIGINS}"
smtp:
enabled: "${CR_GF_SMTP_ENABLED}"
host: "${CR_GF_SMTP_HOST}"
user: "${CR_GF_SMTP_USER}"
password: "${CR_GF_SMTP_PASSWORD}"
from_address: "${CR_GF_SMTP_FROM_ADDRESS}"
from_name: "${CR_GF_SMTP_FROM_NAME}"
skip_verify: "${CR_GF_SMTP_SKIP_VERIFY}"
serviceMonitor:
relabelings:
- sourceLabels: [__meta_kubernetes_pod_node_name]
targetLabel: instance

gf_ingress_auth_url: "${CR_GF_INGRESS_AUTH_URL}"
gf_ingress_auth_signin: "${CR_GF_INGRESS_AUTH_SIGNIN}"
gf_ingress_error_page_403: "${CR_GF_INGRESS_ERROR_PAGE_403}"
enabled: false

prom_ingress_auth_url: "${CR_PROM_INGRESS_AUTH_URL}"
prom_ingress_auth_signin: "${CR_PROM_INGRESS_AUTH_SIGNIN}"
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions src/app_charts/BUILD.bazel
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,6 +7,7 @@ APPS = [
"k8s-relay",
"mission-crd",
"prometheus",
"grafana",
"token-vendor",
"akri",
]
Expand Down
3 changes: 3 additions & 0 deletions src/app_charts/base/cloud/oauth2-proxy.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -181,6 +181,9 @@ spec:
- group: gateway.envoyproxy.io
kind: SecurityPolicy
namespace: app-prometheus
- group: gateway.envoyproxy.io
kind: SecurityPolicy
namespace: app-grafana
to:
- group: ""
kind: Service
Expand Down
35 changes: 35 additions & 0 deletions src/app_charts/grafana/BUILD.bazel
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
load("//bazel:app.bzl", "app")
load("//bazel:app_chart.bzl", "app_chart")
load("//bazel:build_rules/helm_template.bzl", "helm_template")

helm_template(
name = "grafana-operator-chart.cloud",
# We use the kube-prometheus-stack chart instead of the standalone grafana chart
# because it natively bundles all the default Kubernetes mixin dashboards (like node-exporter,
# kubelet, apiserver) as ConfigMaps. We disable the rest of the backend components in the values file.
chart = "//third_party/kube-prometheus-stack:kube-prometheus-stack-87.5.1.tgz",
helm_version = 3,
kube_version = "1.29.0",
# The namespace will later be replaced with the actual one.
namespace = "HELM-NAMESPACE",
# Pick a short release name as it will be used as a prefix for a lot of resources.
release_name = "grafana",
values = "grafana-cloud.values.yaml",
)

app_chart(
name = "grafana-cloud",
# CRITICAL: Do NOT include 00-crds.yaml to prevent ownership collisions with Prometheus
extra_values = ["values-cloud.yaml"],
files = [
":grafana-operator-chart.cloud",
],
)

app(
name = "grafana",
charts = [
":grafana-cloud",
],
visibility = ["//visibility:public"],
)
32 changes: 32 additions & 0 deletions src/app_charts/grafana/cloud/app.yaml

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
apiVersion: app.k8s.io/v1beta1
kind: Application
metadata:
name: "grafana"
labels:
app.kubernetes.io/name: {{ .Chart.Name }}
app.kubernetes.io/version: {{ .Chart.Version }}
spec:
selector:
matchLabels:
app.kubernetes.io/name: {{ .Chart.Name }}
componentKinds:
- group: core
kind: Service
- group: apps
kind: Deployment
- group: apps
kind: Ingress
- group: gateway.networking.k8s.io
kind: HTTPRoute
- group: gateway.envoyproxy.io
kind: SecurityPolicy
descriptor:
type: "grafana"
version: {{ .Chart.Version }}
description: "Grafana provides visualization dashboards"
keywords:
- "dashboard"
- "visualization"
links:
- description: Grafana Dashboard
url: "https://{{ .Values.domain }}/grafana/"
22 changes: 22 additions & 0 deletions src/app_charts/grafana/cloud/grafana-datasources.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: grafana-datasources
labels:
grafana_datasource: "1"
app.kubernetes.io/name: {{ .Chart.Name }}
data:
datasources.yaml: |
apiVersion: 1
{{- if .Values.datasources }}
datasources:
{{ toYaml .Values.datasources | indent 4 }}
{{- else }}
datasources:
- name: Prometheus
type: prometheus
uid: prometheus
url: http://kube-prometheus.{{ .Values.prometheusNamespace | default "app-prometheus" }}.svc.cluster.local:9090
access: proxy
isDefault: true
{{- end }}
Original file line numberDiff line numberDiff line change
Expand Up@@ -23,7 +23,7 @@ spec:
type: ReplacePrefixMatch
replacePrefixMatch: /
backendRefs:
- name: prom-grafana
- name: grafana
port: 80
- matches:
- path:
Expand All@@ -36,7 +36,7 @@ spec:
type: ReplaceFullPath
replaceFullPath: /
backendRefs:
- name: prom-grafana
- name: grafana
port: 80
---
apiVersion: gateway.envoyproxy.io/v1alpha1
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -23,6 +23,6 @@ spec:
pathType: Prefix
backend:
service:
name: prom-grafana
name: grafana
port:
number: 80
25 changes: 25 additions & 0 deletions src/app_charts/grafana/cloud/grafana-operator.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
# This includes all resources expanded from the grafana-operator chart using
# the values in ../grafana-cloud.values.yaml.
# Some pseudo-variables that were inserted there are replaced with actual runtime values.
# NOTE: The order here is important. The domain and project might be part of other values and
# need to be replaced last.
{{- $data := .Files.Get "files/grafana-operator-chart.cloud.yaml" -}}
# Pre-process variables
{{- $data = $data | replace "${CR_GF_INGRESS_AUTH_URL}" .Values.gf_ingress_auth_url -}}
{{- $data = $data | replace "${CR_GF_INGRESS_AUTH_SIGNIN}" .Values.gf_ingress_auth_signin -}}
{{- $data = $data | replace "${CR_GF_INGRESS_ERROR_PAGE_403}" .Values.gf_ingress_error_page_403 -}}
{{- $data = $data | replace "${CR_GF_SERVER_DOMAIN}" .Values.gf_server_domain -}}
{{- $data = $data | replace "${CR_GF_SERVER_ROOT_URL}" .Values.gf_server_root_url -}}
{{- $data = $data | replace "${CR_GF_CSRF_TRUSTED_ORIGINS}" .Values.gf_csrf_trusted_origins -}}
{{- $data = $data | replace "${CR_GF_SMTP_ENABLED}" .Values.gf_smtp_enabled -}}
{{- $data = $data | replace "${CR_GF_SMTP_HOST}" .Values.gf_smtp_host -}}
{{- $data = $data | replace "${CR_GF_SMTP_USER}" .Values.gf_smtp_user -}}
{{- $data = $data | replace "${CR_GF_SMTP_PASSWORD}" .Values.gf_smtp_password -}}
{{- $data = $data | replace "${CR_GF_SMTP_FROM_ADDRESS}" .Values.gf_smtp_from_address -}}
{{- $data = $data | replace "${CR_GF_SMTP_FROM_NAME}" .Values.gf_smtp_from_name -}}
{{- $data = $data | replace "${CR_GF_SMTP_SKIP_VERIFY}" .Values.gf_smtp_skip_verify -}}
{{- $data = $data | replace "HELM-NAMESPACE" .Release.Namespace -}}
{{- $data = $data | replace "${CLOUD_ROBOTICS_DOMAIN}" .Values.domain -}}
{{- $data = $data | replace "${GCP_PROJECT_ID}" .Values.project -}}

{{ $data }}
69 changes: 69 additions & 0 deletions src/app_charts/grafana/grafana-cloud.values.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,69 @@
nameOverride: kube
fullnameOverride: kube

kubeTargetVersionOverride: "1.23.8"

# We use the kube-prometheus-stack chart instead of the standalone grafana chart
# because the stack chart natively bundles and updates a large collection of standard
# kubernetes monitoring dashboards (via kubernetes-mixin, node-exporter-mixin, etc.)
# as ConfigMaps. By disabling the rest of the backend components and keeping only Grafana
# enabled, we get a fully configured standalone Grafana with all the rich Kubernetes
# observability dashboards maintained for us out of the box.
grafana:
# default password used by old releases, deployed behind auth-proxy so this
# is not a secret.
# we could also use "auth proxy authentication" but the second login defends
# against unintentional edits to dashboards.
adminPassword: "prom-operator"
testFramework:
enabled: false
env:
GF_SERVER_DOMAIN: "${CR_GF_SERVER_DOMAIN}"
GF_SERVER_ROOT_URL: "${CR_GF_SERVER_ROOT_URL}"
GF_AUTH_ANONYMOUS_ENABLED: "true"
# Load dashboards from configmaps with a given label across all namespaces.
sidecar:
dashboards:
enabled: true
label: grafana # Label our own legacy grafana-operator uses.
searchNamespace: ALL
multicluster:
global:
enabled: true
etcd:
enabled: true
grafana.ini:
analytics:
check_for_updates: false
security:
csrf_trusted_origins: "${CR_GF_CSRF_TRUSTED_ORIGINS}"
smtp:
enabled: "${CR_GF_SMTP_ENABLED}"
host: "${CR_GF_SMTP_HOST}"
user: "${CR_GF_SMTP_USER}"
password: "${CR_GF_SMTP_PASSWORD}"
from_address: "${CR_GF_SMTP_FROM_ADDRESS}"
from_name: "${CR_GF_SMTP_FROM_NAME}"
skip_verify: "${CR_GF_SMTP_SKIP_VERIFY}"
serviceMonitor:
relabelings:
- sourceLabels: [__meta_kubernetes_pod_node_name]
targetLabel: instance

gf_ingress_auth_url: "${CR_GF_INGRESS_AUTH_URL}"
gf_ingress_auth_signin: "${CR_GF_INGRESS_AUTH_SIGNIN}"
gf_ingress_error_page_403: "${CR_GF_INGRESS_ERROR_PAGE_403}"

# Disable all non-Grafana components
defaultRules:
create: false
alertmanager:
enabled: false
prometheus:
enabled: false
kubeStateMetrics:
enabled: false
nodeExporter:
enabled: false
prometheusOperator:
enabled: false
43 changes: 43 additions & 0 deletions src/app_charts/grafana/values-cloud.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,43 @@
# Enable toggle for the standalone app components
grafana:
enabled: true

# Grafana HTTP configuration
gf_server_domain: "${CLOUD_ROBOTICS_DOMAIN}"
gf_server_root_url: "https://${CLOUD_ROBOTICS_DOMAIN}/grafana"
gf_csrf_trusted_origins: ""
# Grafana Ingress configuration. Does not use the same replace as the values above.
gf_ingress_auth_url: "http://oauth2-proxy.default.svc.cluster.local/apis/core.token-vendor/v1/token.verify"
# Header modification for Istio/HTTPRoutes support.
gf_ingress_auth_url_header: ""
gf_ingress_auth_url_headervalue: ""
gf_ingress_auth_signin: "https://{{ .Values.domain }}/oauth2/start?rd=$escaped_request_uri"
gf_ingress_error_page_403: "https://{{ .Values.domain }}/oauth2/start?rd=$escaped_request_uri"
gf_auth_backend:
protocol: "http"
service: "oauth2-proxy"
namespace: "default"
port: 80
path: "/oauth2/auth"
contextExtensions: {}
authProxy:
authHeaders:
- authorization
- cookie
- x-forwarded-access-token
- x-forwarded-host
- apikey-token
- x-server-name

# Grafana SMTP configuration
# Notes: these need to be all string, since we apply them using the template funtion "replace"
gf_smtp_enabled: "false"
gf_smtp_host: "smtp-host"
gf_smtp_user: "smtp-user"
gf_smtp_password: "smtp-api-key"
gf_smtp_from_address: "from-address@example.com"
gf_smtp_from_name: "from-name"
gf_smtp_skip_verify: "true"

# Fallback prometheus datasource namespace
prometheusNamespace: "app-prometheus"
6 changes: 4 additions & 2 deletions src/app_charts/prometheus/cloud/app.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -21,6 +21,10 @@ spec:
kind: Ingress
- group: apps
kind: StatefulSet
- group: gateway.networking.k8s.io
kind: HTTPRoute
- group: gateway.envoyproxy.io
kind: SecurityPolicy
descriptor:
type: "prometheus"
version: {{ .Chart.Version }}
Expand All@@ -31,5 +35,3 @@ spec:
links:
- description: Prometheus
url: "https://{{ .Values.domain }}/prometheus/"
- description: Grafana Dashboard
url: "https://{{ .Values.domain }}/grafana/"
13 changes: 12 additions & 1 deletion src/app_charts/prometheus/cloud/prometheus-operator.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,7 +7,18 @@
# need to be replaced last.
{{- $data := .Files.Get "files/prometheus-operator-chart.cloud.yaml" -}}
# Pre-process variables
{{- $data = $data | replace "${CR_GF_SERVER_DOMAIN}" .Values.gf_server_domain | replace "${CR_GF_SERVER_ROOT_URL}" .Values.gf_server_root_url | replace "${CR_GF_CSRF_TRUSTED_ORIGINS}" .Values.gf_csrf_trusted_origins | replace "${CR_GF_SMTP_ENABLED}" .Values.gf_smtp_enabled | replace "${CR_GF_SMTP_HOST}" .Values.gf_smtp_host | replace "${CR_GF_SMTP_USER}" .Values.gf_smtp_user | replace "${CR_GF_SMTP_PASSWORD}" .Values.gf_smtp_password | replace "${CR_GF_SMTP_FROM_ADDRESS}" .Values.gf_smtp_from_address | replace "${CR_GF_SMTP_FROM_NAME}" .Values.gf_smtp_from_name | replace "${CR_GF_SMTP_SKIP_VERIFY}" .Values.gf_smtp_skip_verify | replace "${CR_GF_INGRESS_AUTH_URL}" .Values.gf_ingress_auth_url | replace "${CR_GF_INGRESS_AUTH_SIGNIN}" .Values.gf_ingress_auth_signin | replace "${CR_GF_INGRESS_ERROR_PAGE_403}" .Values.gf_ingress_error_page_403 | replace "${CR_PROM_INGRESS_AUTH_URL}" .Values.prom_ingress_auth_url | replace "${CR_PROM_INGRESS_AUTH_SIGNIN}" .Values.prom_ingress_auth_signin | replace "${CR_PROM_INGRESS_ERROR_PAGE_403}" .Values.prom_ingress_error_page_403 | replace "HELM-NAMESPACE" .Release.Namespace | replace "${LIMITS_MEMORY}" .Values.limits.memory | replace "${LIMITS_CPU}" .Values.limits.cpu | replace "${REQUESTS_STORAGE}" .Values.requests.storage | replace "${RETENTION_TIME}" .Values.retention.time | replace "${RETENTION_SIZE}" .Values.retention.size | replace "${EXTERNAL_URL}" .Values.prom_external_url | replace "${CLOUD_ROBOTICS_DOMAIN}" .Values.domain | replace "${GCP_PROJECT_ID}" .Values.project -}}
{{- $data = $data | replace "${CR_PROM_INGRESS_AUTH_URL}" .Values.prom_ingress_auth_url -}}
{{- $data = $data | replace "${CR_PROM_INGRESS_AUTH_SIGNIN}" .Values.prom_ingress_auth_signin -}}
{{- $data = $data | replace "${CR_PROM_INGRESS_ERROR_PAGE_403}" .Values.prom_ingress_error_page_403 -}}
{{- $data = $data | replace "HELM-NAMESPACE" .Release.Namespace -}}
{{- $data = $data | replace "${LIMITS_MEMORY}" .Values.limits.memory -}}
{{- $data = $data | replace "${LIMITS_CPU}" .Values.limits.cpu -}}
{{- $data = $data | replace "${REQUESTS_STORAGE}" .Values.requests.storage -}}
{{- $data = $data | replace "${RETENTION_TIME}" .Values.retention.time -}}
{{- $data = $data | replace "${RETENTION_SIZE}" .Values.retention.size -}}
{{- $data = $data | replace "${EXTERNAL_URL}" .Values.prom_external_url -}}
{{- $data = $data | replace "${CLOUD_ROBOTICS_DOMAIN}" .Values.domain -}}
{{- $data = $data | replace "${GCP_PROJECT_ID}" .Values.project -}}

# Inject the nodeSelector as a pre-formatted YAML block to allow users to define multiple selectors in a dict within values-cloud.yaml while maintaining valid indentation in the output.
{{- $prometheusNodeSelectorMap := .Values.prometheus.prometheusSpec.nodeSelector -}}
Expand Down
44 changes: 1 addition & 43 deletions src/app_charts/prometheus/prometheus-cloud.values.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -182,49 +182,7 @@ nodeExporter:
targetLabel: instance

grafana:
# default password used by old releases, deployed behind auth-proxy so this
# is not a secret.
# we could also use "auth proxy authentication" but the second login defends
# against unintentional edits to dashboards.
adminPassword: "prom-operator"
testFramework:
enabled: false
env:
GF_SERVER_DOMAIN: "${CR_GF_SERVER_DOMAIN}"
GF_SERVER_ROOT_URL: "${CR_GF_SERVER_ROOT_URL}"
GF_AUTH_ANONYMOUS_ENABLED: "true"
# Load dashboards from configmaps with a given label across all namespaces.
sidecar:
dashboards:
enabled: true
label: grafana # Label our own legacy grafana-operator uses.
searchNamespace: ALL
multicluster:
global:
enabled: true
etcd:
enabled: true
grafana.ini:
analytics:
check_for_updates: false
security:
csrf_trusted_origins: "${CR_GF_CSRF_TRUSTED_ORIGINS}"
smtp:
enabled: "${CR_GF_SMTP_ENABLED}"
host: "${CR_GF_SMTP_HOST}"
user: "${CR_GF_SMTP_USER}"
password: "${CR_GF_SMTP_PASSWORD}"
from_address: "${CR_GF_SMTP_FROM_ADDRESS}"
from_name: "${CR_GF_SMTP_FROM_NAME}"
skip_verify: "${CR_GF_SMTP_SKIP_VERIFY}"
serviceMonitor:
relabelings:
- sourceLabels: [__meta_kubernetes_pod_node_name]
targetLabel: instance

gf_ingress_auth_url: "${CR_GF_INGRESS_AUTH_URL}"
gf_ingress_auth_signin: "${CR_GF_INGRESS_AUTH_SIGNIN}"
gf_ingress_error_page_403: "${CR_GF_INGRESS_ERROR_PAGE_403}"
enabled: false

prom_ingress_auth_url: "${CR_PROM_INGRESS_AUTH_URL}"
prom_ingress_auth_signin: "${CR_PROM_INGRESS_AUTH_SIGNIN}"
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions src/app_charts/BUILD.bazel
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,6 +7,7 @@ APPS = [
"k8s-relay",
"mission-crd",
"prometheus",
"grafana",
"token-vendor",
"akri",
]
Expand Down
3 changes: 3 additions & 0 deletions src/app_charts/base/cloud/oauth2-proxy.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -181,6 +181,9 @@ spec:
- group: gateway.envoyproxy.io
kind: SecurityPolicy
namespace: app-prometheus
- group: gateway.envoyproxy.io
kind: SecurityPolicy
namespace: app-grafana
to:
- group: ""
kind: Service
Expand Down
35 changes: 35 additions & 0 deletions src/app_charts/grafana/BUILD.bazel
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
load("//bazel:app.bzl", "app")
load("//bazel:app_chart.bzl", "app_chart")
load("//bazel:build_rules/helm_template.bzl", "helm_template")

helm_template(
name = "grafana-operator-chart.cloud",
# We use the kube-prometheus-stack chart instead of the standalone grafana chart
# because it natively bundles all the default Kubernetes mixin dashboards (like node-exporter,
# kubelet, apiserver) as ConfigMaps. We disable the rest of the backend components in the values file.
chart = "//third_party/kube-prometheus-stack:kube-prometheus-stack-87.5.1.tgz",
helm_version = 3,
kube_version = "1.29.0",
# The namespace will later be replaced with the actual one.
namespace = "HELM-NAMESPACE",
# Pick a short release name as it will be used as a prefix for a lot of resources.
release_name = "grafana",
values = "grafana-cloud.values.yaml",
)

app_chart(
name = "grafana-cloud",
# CRITICAL: Do NOT include 00-crds.yaml to prevent ownership collisions with Prometheus
extra_values = ["values-cloud.yaml"],
files = [
":grafana-operator-chart.cloud",
],
)

app(
name = "grafana",
charts = [
":grafana-cloud",
],
visibility = ["//visibility:public"],
)
32 changes: 32 additions & 0 deletions src/app_charts/grafana/cloud/app.yaml

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
apiVersion: app.k8s.io/v1beta1
kind: Application
metadata:
name: "grafana"
labels:
app.kubernetes.io/name: {{ .Chart.Name }}
app.kubernetes.io/version: {{ .Chart.Version }}
spec:
selector:
matchLabels:
app.kubernetes.io/name: {{ .Chart.Name }}
componentKinds:
- group: core
kind: Service
- group: apps
kind: Deployment
- group: apps
kind: Ingress
- group: gateway.networking.k8s.io
kind: HTTPRoute
- group: gateway.envoyproxy.io
kind: SecurityPolicy
descriptor:
type: "grafana"
version: {{ .Chart.Version }}
description: "Grafana provides visualization dashboards"
keywords:
- "dashboard"
- "visualization"
links:
- description: Grafana Dashboard
url: "https://{{ .Values.domain }}/grafana/"
22 changes: 22 additions & 0 deletions src/app_charts/grafana/cloud/grafana-datasources.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: grafana-datasources
labels:
grafana_datasource: "1"
app.kubernetes.io/name: {{ .Chart.Name }}
data:
datasources.yaml: |
apiVersion: 1
{{- if .Values.datasources }}
datasources:
{{ toYaml .Values.datasources | indent 4 }}
{{- else }}
datasources:
- name: Prometheus
type: prometheus
uid: prometheus
url: http://kube-prometheus.{{ .Values.prometheusNamespace | default "app-prometheus" }}.svc.cluster.local:9090
access: proxy
isDefault: true
{{- end }}
Original file line numberDiff line numberDiff line change
Expand Up@@ -23,7 +23,7 @@ spec:
type: ReplacePrefixMatch
replacePrefixMatch: /
backendRefs:
- name: prom-grafana
- name: grafana
port: 80
- matches:
- path:
Expand All@@ -36,7 +36,7 @@ spec:
type: ReplaceFullPath
replaceFullPath: /
backendRefs:
- name: prom-grafana
- name: grafana
port: 80
---
apiVersion: gateway.envoyproxy.io/v1alpha1
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -23,6 +23,6 @@ spec:
pathType: Prefix
backend:
service:
name: prom-grafana
name: grafana
port:
number: 80
25 changes: 25 additions & 0 deletions src/app_charts/grafana/cloud/grafana-operator.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
# This includes all resources expanded from the grafana-operator chart using
# the values in ../grafana-cloud.values.yaml.
# Some pseudo-variables that were inserted there are replaced with actual runtime values.
# NOTE: The order here is important. The domain and project might be part of other values and
# need to be replaced last.
{{- $data := .Files.Get "files/grafana-operator-chart.cloud.yaml" -}}
# Pre-process variables
{{- $data = $data | replace "${CR_GF_INGRESS_AUTH_URL}" .Values.gf_ingress_auth_url -}}
{{- $data = $data | replace "${CR_GF_INGRESS_AUTH_SIGNIN}" .Values.gf_ingress_auth_signin -}}
{{- $data = $data | replace "${CR_GF_INGRESS_ERROR_PAGE_403}" .Values.gf_ingress_error_page_403 -}}
{{- $data = $data | replace "${CR_GF_SERVER_DOMAIN}" .Values.gf_server_domain -}}
{{- $data = $data | replace "${CR_GF_SERVER_ROOT_URL}" .Values.gf_server_root_url -}}
{{- $data = $data | replace "${CR_GF_CSRF_TRUSTED_ORIGINS}" .Values.gf_csrf_trusted_origins -}}
{{- $data = $data | replace "${CR_GF_SMTP_ENABLED}" .Values.gf_smtp_enabled -}}
{{- $data = $data | replace "${CR_GF_SMTP_HOST}" .Values.gf_smtp_host -}}
{{- $data = $data | replace "${CR_GF_SMTP_USER}" .Values.gf_smtp_user -}}
{{- $data = $data | replace "${CR_GF_SMTP_PASSWORD}" .Values.gf_smtp_password -}}
{{- $data = $data | replace "${CR_GF_SMTP_FROM_ADDRESS}" .Values.gf_smtp_from_address -}}
{{- $data = $data | replace "${CR_GF_SMTP_FROM_NAME}" .Values.gf_smtp_from_name -}}
{{- $data = $data | replace "${CR_GF_SMTP_SKIP_VERIFY}" .Values.gf_smtp_skip_verify -}}
{{- $data = $data | replace "HELM-NAMESPACE" .Release.Namespace -}}
{{- $data = $data | replace "${CLOUD_ROBOTICS_DOMAIN}" .Values.domain -}}
{{- $data = $data | replace "${GCP_PROJECT_ID}" .Values.project -}}

{{ $data }}
69 changes: 69 additions & 0 deletions src/app_charts/grafana/grafana-cloud.values.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,69 @@
nameOverride: kube
fullnameOverride: kube

kubeTargetVersionOverride: "1.23.8"

# We use the kube-prometheus-stack chart instead of the standalone grafana chart
# because the stack chart natively bundles and updates a large collection of standard
# kubernetes monitoring dashboards (via kubernetes-mixin, node-exporter-mixin, etc.)
# as ConfigMaps. By disabling the rest of the backend components and keeping only Grafana
# enabled, we get a fully configured standalone Grafana with all the rich Kubernetes
# observability dashboards maintained for us out of the box.
grafana:
# default password used by old releases, deployed behind auth-proxy so this
# is not a secret.
# we could also use "auth proxy authentication" but the second login defends
# against unintentional edits to dashboards.
adminPassword: "prom-operator"
testFramework:
enabled: false
env:
GF_SERVER_DOMAIN: "${CR_GF_SERVER_DOMAIN}"
GF_SERVER_ROOT_URL: "${CR_GF_SERVER_ROOT_URL}"
GF_AUTH_ANONYMOUS_ENABLED: "true"
# Load dashboards from configmaps with a given label across all namespaces.
sidecar:
dashboards:
enabled: true
label: grafana # Label our own legacy grafana-operator uses.
searchNamespace: ALL
multicluster:
global:
enabled: true
etcd:
enabled: true
grafana.ini:
analytics:
check_for_updates: false
security:
csrf_trusted_origins: "${CR_GF_CSRF_TRUSTED_ORIGINS}"
smtp:
enabled: "${CR_GF_SMTP_ENABLED}"
host: "${CR_GF_SMTP_HOST}"
user: "${CR_GF_SMTP_USER}"
password: "${CR_GF_SMTP_PASSWORD}"
from_address: "${CR_GF_SMTP_FROM_ADDRESS}"
from_name: "${CR_GF_SMTP_FROM_NAME}"
skip_verify: "${CR_GF_SMTP_SKIP_VERIFY}"
serviceMonitor:
relabelings:
- sourceLabels: [__meta_kubernetes_pod_node_name]
targetLabel: instance

gf_ingress_auth_url: "${CR_GF_INGRESS_AUTH_URL}"
gf_ingress_auth_signin: "${CR_GF_INGRESS_AUTH_SIGNIN}"
gf_ingress_error_page_403: "${CR_GF_INGRESS_ERROR_PAGE_403}"

# Disable all non-Grafana components
defaultRules:
create: false
alertmanager:
enabled: false
prometheus:
enabled: false
kubeStateMetrics:
enabled: false
nodeExporter:
enabled: false
prometheusOperator:
enabled: false
43 changes: 43 additions & 0 deletions src/app_charts/grafana/values-cloud.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,43 @@
# Enable toggle for the standalone app components
grafana:
enabled: true

# Grafana HTTP configuration
gf_server_domain: "${CLOUD_ROBOTICS_DOMAIN}"
gf_server_root_url: "https://${CLOUD_ROBOTICS_DOMAIN}/grafana"
gf_csrf_trusted_origins: ""
# Grafana Ingress configuration. Does not use the same replace as the values above.
gf_ingress_auth_url: "http://oauth2-proxy.default.svc.cluster.local/apis/core.token-vendor/v1/token.verify"
# Header modification for Istio/HTTPRoutes support.
gf_ingress_auth_url_header: ""
gf_ingress_auth_url_headervalue: ""
gf_ingress_auth_signin: "https://{{ .Values.domain }}/oauth2/start?rd=$escaped_request_uri"
gf_ingress_error_page_403: "https://{{ .Values.domain }}/oauth2/start?rd=$escaped_request_uri"
gf_auth_backend:
protocol: "http"
service: "oauth2-proxy"
namespace: "default"
port: 80
path: "/oauth2/auth"
contextExtensions: {}
authProxy:
authHeaders:
- authorization
- cookie
- x-forwarded-access-token
- x-forwarded-host
- apikey-token
- x-server-name

# Grafana SMTP configuration
# Notes: these need to be all string, since we apply them using the template funtion "replace"
gf_smtp_enabled: "false"
gf_smtp_host: "smtp-host"
gf_smtp_user: "smtp-user"
gf_smtp_password: "smtp-api-key"
gf_smtp_from_address: "from-address@example.com"
gf_smtp_from_name: "from-name"
gf_smtp_skip_verify: "true"

# Fallback prometheus datasource namespace
prometheusNamespace: "app-prometheus"
6 changes: 4 additions & 2 deletions src/app_charts/prometheus/cloud/app.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -21,6 +21,10 @@ spec:
kind: Ingress
- group: apps
kind: StatefulSet
- group: gateway.networking.k8s.io
kind: HTTPRoute
- group: gateway.envoyproxy.io
kind: SecurityPolicy
descriptor:
type: "prometheus"
version: {{ .Chart.Version }}
Expand All@@ -31,5 +35,3 @@ spec:
links:
- description: Prometheus
url: "https://{{ .Values.domain }}/prometheus/"
- description: Grafana Dashboard
url: "https://{{ .Values.domain }}/grafana/"
13 changes: 12 additions & 1 deletion src/app_charts/prometheus/cloud/prometheus-operator.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,7 +7,18 @@
# need to be replaced last.
{{- $data := .Files.Get "files/prometheus-operator-chart.cloud.yaml" -}}
# Pre-process variables
{{- $data = $data | replace "${CR_GF_SERVER_DOMAIN}" .Values.gf_server_domain | replace "${CR_GF_SERVER_ROOT_URL}" .Values.gf_server_root_url | replace "${CR_GF_CSRF_TRUSTED_ORIGINS}" .Values.gf_csrf_trusted_origins | replace "${CR_GF_SMTP_ENABLED}" .Values.gf_smtp_enabled | replace "${CR_GF_SMTP_HOST}" .Values.gf_smtp_host | replace "${CR_GF_SMTP_USER}" .Values.gf_smtp_user | replace "${CR_GF_SMTP_PASSWORD}" .Values.gf_smtp_password | replace "${CR_GF_SMTP_FROM_ADDRESS}" .Values.gf_smtp_from_address | replace "${CR_GF_SMTP_FROM_NAME}" .Values.gf_smtp_from_name | replace "${CR_GF_SMTP_SKIP_VERIFY}" .Values.gf_smtp_skip_verify | replace "${CR_GF_INGRESS_AUTH_URL}" .Values.gf_ingress_auth_url | replace "${CR_GF_INGRESS_AUTH_SIGNIN}" .Values.gf_ingress_auth_signin | replace "${CR_GF_INGRESS_ERROR_PAGE_403}" .Values.gf_ingress_error_page_403 | replace "${CR_PROM_INGRESS_AUTH_URL}" .Values.prom_ingress_auth_url | replace "${CR_PROM_INGRESS_AUTH_SIGNIN}" .Values.prom_ingress_auth_signin | replace "${CR_PROM_INGRESS_ERROR_PAGE_403}" .Values.prom_ingress_error_page_403 | replace "HELM-NAMESPACE" .Release.Namespace | replace "${LIMITS_MEMORY}" .Values.limits.memory | replace "${LIMITS_CPU}" .Values.limits.cpu | replace "${REQUESTS_STORAGE}" .Values.requests.storage | replace "${RETENTION_TIME}" .Values.retention.time | replace "${RETENTION_SIZE}" .Values.retention.size | replace "${EXTERNAL_URL}" .Values.prom_external_url | replace "${CLOUD_ROBOTICS_DOMAIN}" .Values.domain | replace "${GCP_PROJECT_ID}" .Values.project -}}
{{- $data = $data | replace "${CR_PROM_INGRESS_AUTH_URL}" .Values.prom_ingress_auth_url -}}
{{- $data = $data | replace "${CR_PROM_INGRESS_AUTH_SIGNIN}" .Values.prom_ingress_auth_signin -}}
{{- $data = $data | replace "${CR_PROM_INGRESS_ERROR_PAGE_403}" .Values.prom_ingress_error_page_403 -}}
{{- $data = $data | replace "HELM-NAMESPACE" .Release.Namespace -}}
{{- $data = $data | replace "${LIMITS_MEMORY}" .Values.limits.memory -}}
{{- $data = $data | replace "${LIMITS_CPU}" .Values.limits.cpu -}}
{{- $data = $data | replace "${REQUESTS_STORAGE}" .Values.requests.storage -}}
{{- $data = $data | replace "${RETENTION_TIME}" .Values.retention.time -}}
{{- $data = $data | replace "${RETENTION_SIZE}" .Values.retention.size -}}
{{- $data = $data | replace "${EXTERNAL_URL}" .Values.prom_external_url -}}
{{- $data = $data | replace "${CLOUD_ROBOTICS_DOMAIN}" .Values.domain -}}
{{- $data = $data | replace "${GCP_PROJECT_ID}" .Values.project -}}

# Inject the nodeSelector as a pre-formatted YAML block to allow users to define multiple selectors in a dict within values-cloud.yaml while maintaining valid indentation in the output.
{{- $prometheusNodeSelectorMap := .Values.prometheus.prometheusSpec.nodeSelector -}}
Expand Down
44 changes: 1 addition & 43 deletions src/app_charts/prometheus/prometheus-cloud.values.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -182,49 +182,7 @@ nodeExporter:
targetLabel: instance

grafana:
# default password used by old releases, deployed behind auth-proxy so this
# is not a secret.
# we could also use "auth proxy authentication" but the second login defends
# against unintentional edits to dashboards.
adminPassword: "prom-operator"
testFramework:
enabled: false
env:
GF_SERVER_DOMAIN: "${CR_GF_SERVER_DOMAIN}"
GF_SERVER_ROOT_URL: "${CR_GF_SERVER_ROOT_URL}"
GF_AUTH_ANONYMOUS_ENABLED: "true"
# Load dashboards from configmaps with a given label across all namespaces.
sidecar:
dashboards:
enabled: true
label: grafana # Label our own legacy grafana-operator uses.
searchNamespace: ALL
multicluster:
global:
enabled: true
etcd:
enabled: true
grafana.ini:
analytics:
check_for_updates: false
security:
csrf_trusted_origins: "${CR_GF_CSRF_TRUSTED_ORIGINS}"
smtp:
enabled: "${CR_GF_SMTP_ENABLED}"
host: "${CR_GF_SMTP_HOST}"
user: "${CR_GF_SMTP_USER}"
password: "${CR_GF_SMTP_PASSWORD}"
from_address: "${CR_GF_SMTP_FROM_ADDRESS}"
from_name: "${CR_GF_SMTP_FROM_NAME}"
skip_verify: "${CR_GF_SMTP_SKIP_VERIFY}"
serviceMonitor:
relabelings:
- sourceLabels: [__meta_kubernetes_pod_node_name]
targetLabel: instance

gf_ingress_auth_url: "${CR_GF_INGRESS_AUTH_URL}"
gf_ingress_auth_signin: "${CR_GF_INGRESS_AUTH_SIGNIN}"
gf_ingress_error_page_403: "${CR_GF_INGRESS_ERROR_PAGE_403}"
enabled: false

prom_ingress_auth_url: "${CR_PROM_INGRESS_AUTH_URL}"
prom_ingress_auth_signin: "${CR_PROM_INGRESS_AUTH_SIGNIN}"
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions src/app_charts/BUILD.bazel
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,6 +7,7 @@ APPS = [
"k8s-relay",
"mission-crd",
"prometheus",
"grafana",
"token-vendor",
"akri",
]
Expand Down
3 changes: 3 additions & 0 deletions src/app_charts/base/cloud/oauth2-proxy.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -181,6 +181,9 @@ spec:
- group: gateway.envoyproxy.io
kind: SecurityPolicy
namespace: app-prometheus
- group: gateway.envoyproxy.io
kind: SecurityPolicy
namespace: app-grafana
to:
- group: ""
kind: Service
Expand Down
35 changes: 35 additions & 0 deletions src/app_charts/grafana/BUILD.bazel
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
load("//bazel:app.bzl", "app")
load("//bazel:app_chart.bzl", "app_chart")
load("//bazel:build_rules/helm_template.bzl", "helm_template")

helm_template(
name = "grafana-operator-chart.cloud",
# We use the kube-prometheus-stack chart instead of the standalone grafana chart
# because it natively bundles all the default Kubernetes mixin dashboards (like node-exporter,
# kubelet, apiserver) as ConfigMaps. We disable the rest of the backend components in the values file.
chart = "//third_party/kube-prometheus-stack:kube-prometheus-stack-87.5.1.tgz",
helm_version = 3,
kube_version = "1.29.0",
# The namespace will later be replaced with the actual one.
namespace = "HELM-NAMESPACE",
# Pick a short release name as it will be used as a prefix for a lot of resources.
release_name = "grafana",
values = "grafana-cloud.values.yaml",
)

app_chart(
name = "grafana-cloud",
# CRITICAL: Do NOT include 00-crds.yaml to prevent ownership collisions with Prometheus
extra_values = ["values-cloud.yaml"],
files = [
":grafana-operator-chart.cloud",
],
)

app(
name = "grafana",
charts = [
":grafana-cloud",
],
visibility = ["//visibility:public"],
)
32 changes: 32 additions & 0 deletions src/app_charts/grafana/cloud/app.yaml

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
apiVersion: app.k8s.io/v1beta1
kind: Application
metadata:
name: "grafana"
labels:
app.kubernetes.io/name: {{ .Chart.Name }}
app.kubernetes.io/version: {{ .Chart.Version }}
spec:
selector:
matchLabels:
app.kubernetes.io/name: {{ .Chart.Name }}
componentKinds:
- group: core
kind: Service
- group: apps
kind: Deployment
- group: apps
kind: Ingress
- group: gateway.networking.k8s.io
kind: HTTPRoute
- group: gateway.envoyproxy.io
kind: SecurityPolicy
descriptor:
type: "grafana"
version: {{ .Chart.Version }}
description: "Grafana provides visualization dashboards"
keywords:
- "dashboard"
- "visualization"
links:
- description: Grafana Dashboard
url: "https://{{ .Values.domain }}/grafana/"
22 changes: 22 additions & 0 deletions src/app_charts/grafana/cloud/grafana-datasources.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: grafana-datasources
labels:
grafana_datasource: "1"
app.kubernetes.io/name: {{ .Chart.Name }}
data:
datasources.yaml: |
apiVersion: 1
{{- if .Values.datasources }}
datasources:
{{ toYaml .Values.datasources | indent 4 }}
{{- else }}
datasources:
- name: Prometheus
type: prometheus
uid: prometheus
url: http://kube-prometheus.{{ .Values.prometheusNamespace | default "app-prometheus" }}.svc.cluster.local:9090
access: proxy
isDefault: true
{{- end }}
Original file line numberDiff line numberDiff line change
Expand Up@@ -23,7 +23,7 @@ spec:
type: ReplacePrefixMatch
replacePrefixMatch: /
backendRefs:
- name: prom-grafana
- name: grafana
port: 80
- matches:
- path:
Expand All@@ -36,7 +36,7 @@ spec:
type: ReplaceFullPath
replaceFullPath: /
backendRefs:
- name: prom-grafana
- name: grafana
port: 80
---
apiVersion: gateway.envoyproxy.io/v1alpha1
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -23,6 +23,6 @@ spec:
pathType: Prefix
backend:
service:
name: prom-grafana
name: grafana
port:
number: 80
25 changes: 25 additions & 0 deletions src/app_charts/grafana/cloud/grafana-operator.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
# This includes all resources expanded from the grafana-operator chart using
# the values in ../grafana-cloud.values.yaml.
# Some pseudo-variables that were inserted there are replaced with actual runtime values.
# NOTE: The order here is important. The domain and project might be part of other values and
# need to be replaced last.
{{- $data := .Files.Get "files/grafana-operator-chart.cloud.yaml" -}}
# Pre-process variables
{{- $data = $data | replace "${CR_GF_INGRESS_AUTH_URL}" .Values.gf_ingress_auth_url -}}
{{- $data = $data | replace "${CR_GF_INGRESS_AUTH_SIGNIN}" .Values.gf_ingress_auth_signin -}}
{{- $data = $data | replace "${CR_GF_INGRESS_ERROR_PAGE_403}" .Values.gf_ingress_error_page_403 -}}
{{- $data = $data | replace "${CR_GF_SERVER_DOMAIN}" .Values.gf_server_domain -}}
{{- $data = $data | replace "${CR_GF_SERVER_ROOT_URL}" .Values.gf_server_root_url -}}
{{- $data = $data | replace "${CR_GF_CSRF_TRUSTED_ORIGINS}" .Values.gf_csrf_trusted_origins -}}
{{- $data = $data | replace "${CR_GF_SMTP_ENABLED}" .Values.gf_smtp_enabled -}}
{{- $data = $data | replace "${CR_GF_SMTP_HOST}" .Values.gf_smtp_host -}}
{{- $data = $data | replace "${CR_GF_SMTP_USER}" .Values.gf_smtp_user -}}
{{- $data = $data | replace "${CR_GF_SMTP_PASSWORD}" .Values.gf_smtp_password -}}
{{- $data = $data | replace "${CR_GF_SMTP_FROM_ADDRESS}" .Values.gf_smtp_from_address -}}
{{- $data = $data | replace "${CR_GF_SMTP_FROM_NAME}" .Values.gf_smtp_from_name -}}
{{- $data = $data | replace "${CR_GF_SMTP_SKIP_VERIFY}" .Values.gf_smtp_skip_verify -}}
{{- $data = $data | replace "HELM-NAMESPACE" .Release.Namespace -}}
{{- $data = $data | replace "${CLOUD_ROBOTICS_DOMAIN}" .Values.domain -}}
{{- $data = $data | replace "${GCP_PROJECT_ID}" .Values.project -}}

{{ $data }}
69 changes: 69 additions & 0 deletions src/app_charts/grafana/grafana-cloud.values.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,69 @@
nameOverride: kube
fullnameOverride: kube

kubeTargetVersionOverride: "1.23.8"

# We use the kube-prometheus-stack chart instead of the standalone grafana chart
# because the stack chart natively bundles and updates a large collection of standard
# kubernetes monitoring dashboards (via kubernetes-mixin, node-exporter-mixin, etc.)
# as ConfigMaps. By disabling the rest of the backend components and keeping only Grafana
# enabled, we get a fully configured standalone Grafana with all the rich Kubernetes
# observability dashboards maintained for us out of the box.
grafana:
# default password used by old releases, deployed behind auth-proxy so this
# is not a secret.
# we could also use "auth proxy authentication" but the second login defends
# against unintentional edits to dashboards.
adminPassword: "prom-operator"
testFramework:
enabled: false
env:
GF_SERVER_DOMAIN: "${CR_GF_SERVER_DOMAIN}"
GF_SERVER_ROOT_URL: "${CR_GF_SERVER_ROOT_URL}"
GF_AUTH_ANONYMOUS_ENABLED: "true"
# Load dashboards from configmaps with a given label across all namespaces.
sidecar:
dashboards:
enabled: true
label: grafana # Label our own legacy grafana-operator uses.
searchNamespace: ALL
multicluster:
global:
enabled: true
etcd:
enabled: true
grafana.ini:
analytics:
check_for_updates: false
security:
csrf_trusted_origins: "${CR_GF_CSRF_TRUSTED_ORIGINS}"
smtp:
enabled: "${CR_GF_SMTP_ENABLED}"
host: "${CR_GF_SMTP_HOST}"
user: "${CR_GF_SMTP_USER}"
password: "${CR_GF_SMTP_PASSWORD}"
from_address: "${CR_GF_SMTP_FROM_ADDRESS}"
from_name: "${CR_GF_SMTP_FROM_NAME}"
skip_verify: "${CR_GF_SMTP_SKIP_VERIFY}"
serviceMonitor:
relabelings:
- sourceLabels: [__meta_kubernetes_pod_node_name]
targetLabel: instance

gf_ingress_auth_url: "${CR_GF_INGRESS_AUTH_URL}"
gf_ingress_auth_signin: "${CR_GF_INGRESS_AUTH_SIGNIN}"
gf_ingress_error_page_403: "${CR_GF_INGRESS_ERROR_PAGE_403}"

# Disable all non-Grafana components
defaultRules:
create: false
alertmanager:
enabled: false
prometheus:
enabled: false
kubeStateMetrics:
enabled: false
nodeExporter:
enabled: false
prometheusOperator:
enabled: false
43 changes: 43 additions & 0 deletions src/app_charts/grafana/values-cloud.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,43 @@
# Enable toggle for the standalone app components
grafana:
enabled: true

# Grafana HTTP configuration
gf_server_domain: "${CLOUD_ROBOTICS_DOMAIN}"
gf_server_root_url: "https://${CLOUD_ROBOTICS_DOMAIN}/grafana"
gf_csrf_trusted_origins: ""
# Grafana Ingress configuration. Does not use the same replace as the values above.
gf_ingress_auth_url: "http://oauth2-proxy.default.svc.cluster.local/apis/core.token-vendor/v1/token.verify"
# Header modification for Istio/HTTPRoutes support.
gf_ingress_auth_url_header: ""
gf_ingress_auth_url_headervalue: ""
gf_ingress_auth_signin: "https://{{ .Values.domain }}/oauth2/start?rd=$escaped_request_uri"
gf_ingress_error_page_403: "https://{{ .Values.domain }}/oauth2/start?rd=$escaped_request_uri"
gf_auth_backend:
protocol: "http"
service: "oauth2-proxy"
namespace: "default"
port: 80
path: "/oauth2/auth"
contextExtensions: {}
authProxy:
authHeaders:
- authorization
- cookie
- x-forwarded-access-token
- x-forwarded-host
- apikey-token
- x-server-name

# Grafana SMTP configuration
# Notes: these need to be all string, since we apply them using the template funtion "replace"
gf_smtp_enabled: "false"
gf_smtp_host: "smtp-host"
gf_smtp_user: "smtp-user"
gf_smtp_password: "smtp-api-key"
gf_smtp_from_address: "from-address@example.com"
gf_smtp_from_name: "from-name"
gf_smtp_skip_verify: "true"

# Fallback prometheus datasource namespace
prometheusNamespace: "app-prometheus"
6 changes: 4 additions & 2 deletions src/app_charts/prometheus/cloud/app.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -21,6 +21,10 @@ spec:
kind: Ingress
- group: apps
kind: StatefulSet
- group: gateway.networking.k8s.io
kind: HTTPRoute
- group: gateway.envoyproxy.io
kind: SecurityPolicy
descriptor:
type: "prometheus"
version: {{ .Chart.Version }}
Expand All@@ -31,5 +35,3 @@ spec:
links:
- description: Prometheus
url: "https://{{ .Values.domain }}/prometheus/"
- description: Grafana Dashboard
url: "https://{{ .Values.domain }}/grafana/"
13 changes: 12 additions & 1 deletion src/app_charts/prometheus/cloud/prometheus-operator.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,7 +7,18 @@
# need to be replaced last.
{{- $data := .Files.Get "files/prometheus-operator-chart.cloud.yaml" -}}
# Pre-process variables
{{- $data = $data | replace "${CR_GF_SERVER_DOMAIN}" .Values.gf_server_domain | replace "${CR_GF_SERVER_ROOT_URL}" .Values.gf_server_root_url | replace "${CR_GF_CSRF_TRUSTED_ORIGINS}" .Values.gf_csrf_trusted_origins | replace "${CR_GF_SMTP_ENABLED}" .Values.gf_smtp_enabled | replace "${CR_GF_SMTP_HOST}" .Values.gf_smtp_host | replace "${CR_GF_SMTP_USER}" .Values.gf_smtp_user | replace "${CR_GF_SMTP_PASSWORD}" .Values.gf_smtp_password | replace "${CR_GF_SMTP_FROM_ADDRESS}" .Values.gf_smtp_from_address | replace "${CR_GF_SMTP_FROM_NAME}" .Values.gf_smtp_from_name | replace "${CR_GF_SMTP_SKIP_VERIFY}" .Values.gf_smtp_skip_verify | replace "${CR_GF_INGRESS_AUTH_URL}" .Values.gf_ingress_auth_url | replace "${CR_GF_INGRESS_AUTH_SIGNIN}" .Values.gf_ingress_auth_signin | replace "${CR_GF_INGRESS_ERROR_PAGE_403}" .Values.gf_ingress_error_page_403 | replace "${CR_PROM_INGRESS_AUTH_URL}" .Values.prom_ingress_auth_url | replace "${CR_PROM_INGRESS_AUTH_SIGNIN}" .Values.prom_ingress_auth_signin | replace "${CR_PROM_INGRESS_ERROR_PAGE_403}" .Values.prom_ingress_error_page_403 | replace "HELM-NAMESPACE" .Release.Namespace | replace "${LIMITS_MEMORY}" .Values.limits.memory | replace "${LIMITS_CPU}" .Values.limits.cpu | replace "${REQUESTS_STORAGE}" .Values.requests.storage | replace "${RETENTION_TIME}" .Values.retention.time | replace "${RETENTION_SIZE}" .Values.retention.size | replace "${EXTERNAL_URL}" .Values.prom_external_url | replace "${CLOUD_ROBOTICS_DOMAIN}" .Values.domain | replace "${GCP_PROJECT_ID}" .Values.project -}}
{{- $data = $data | replace "${CR_PROM_INGRESS_AUTH_URL}" .Values.prom_ingress_auth_url -}}
{{- $data = $data | replace "${CR_PROM_INGRESS_AUTH_SIGNIN}" .Values.prom_ingress_auth_signin -}}
{{- $data = $data | replace "${CR_PROM_INGRESS_ERROR_PAGE_403}" .Values.prom_ingress_error_page_403 -}}
{{- $data = $data | replace "HELM-NAMESPACE" .Release.Namespace -}}
{{- $data = $data | replace "${LIMITS_MEMORY}" .Values.limits.memory -}}
{{- $data = $data | replace "${LIMITS_CPU}" .Values.limits.cpu -}}
{{- $data = $data | replace "${REQUESTS_STORAGE}" .Values.requests.storage -}}
{{- $data = $data | replace "${RETENTION_TIME}" .Values.retention.time -}}
{{- $data = $data | replace "${RETENTION_SIZE}" .Values.retention.size -}}
{{- $data = $data | replace "${EXTERNAL_URL}" .Values.prom_external_url -}}
{{- $data = $data | replace "${CLOUD_ROBOTICS_DOMAIN}" .Values.domain -}}
{{- $data = $data | replace "${GCP_PROJECT_ID}" .Values.project -}}

# Inject the nodeSelector as a pre-formatted YAML block to allow users to define multiple selectors in a dict within values-cloud.yaml while maintaining valid indentation in the output.
{{- $prometheusNodeSelectorMap := .Values.prometheus.prometheusSpec.nodeSelector -}}
Expand Down
44 changes: 1 addition & 43 deletions src/app_charts/prometheus/prometheus-cloud.values.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -182,49 +182,7 @@ nodeExporter:
targetLabel: instance

grafana:
# default password used by old releases, deployed behind auth-proxy so this
# is not a secret.
# we could also use "auth proxy authentication" but the second login defends
# against unintentional edits to dashboards.
adminPassword: "prom-operator"
testFramework:
enabled: false
env:
GF_SERVER_DOMAIN: "${CR_GF_SERVER_DOMAIN}"
GF_SERVER_ROOT_URL: "${CR_GF_SERVER_ROOT_URL}"
GF_AUTH_ANONYMOUS_ENABLED: "true"
# Load dashboards from configmaps with a given label across all namespaces.
sidecar:
dashboards:
enabled: true
label: grafana # Label our own legacy grafana-operator uses.
searchNamespace: ALL
multicluster:
global:
enabled: true
etcd:
enabled: true
grafana.ini:
analytics:
check_for_updates: false
security:
csrf_trusted_origins: "${CR_GF_CSRF_TRUSTED_ORIGINS}"
smtp:
enabled: "${CR_GF_SMTP_ENABLED}"
host: "${CR_GF_SMTP_HOST}"
user: "${CR_GF_SMTP_USER}"
password: "${CR_GF_SMTP_PASSWORD}"
from_address: "${CR_GF_SMTP_FROM_ADDRESS}"
from_name: "${CR_GF_SMTP_FROM_NAME}"
skip_verify: "${CR_GF_SMTP_SKIP_VERIFY}"
serviceMonitor:
relabelings:
- sourceLabels: [__meta_kubernetes_pod_node_name]
targetLabel: instance

gf_ingress_auth_url: "${CR_GF_INGRESS_AUTH_URL}"
gf_ingress_auth_signin: "${CR_GF_INGRESS_AUTH_SIGNIN}"
gf_ingress_error_page_403: "${CR_GF_INGRESS_ERROR_PAGE_403}"
enabled: false

prom_ingress_auth_url: "${CR_PROM_INGRESS_AUTH_URL}"
prom_ingress_auth_signin: "${CR_PROM_INGRESS_AUTH_SIGNIN}"
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions src/app_charts/BUILD.bazel
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,6 +7,7 @@ APPS = [
"k8s-relay",
"mission-crd",
"prometheus",
"grafana",
"token-vendor",
"akri",
]
Expand Down
3 changes: 3 additions & 0 deletions src/app_charts/base/cloud/oauth2-proxy.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -181,6 +181,9 @@ spec:
- group: gateway.envoyproxy.io
kind: SecurityPolicy
namespace: app-prometheus
- group: gateway.envoyproxy.io
kind: SecurityPolicy
namespace: app-grafana
to:
- group: ""
kind: Service
Expand Down
35 changes: 35 additions & 0 deletions src/app_charts/grafana/BUILD.bazel
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
load("//bazel:app.bzl", "app")
load("//bazel:app_chart.bzl", "app_chart")
load("//bazel:build_rules/helm_template.bzl", "helm_template")

helm_template(
name = "grafana-operator-chart.cloud",
# We use the kube-prometheus-stack chart instead of the standalone grafana chart
# because it natively bundles all the default Kubernetes mixin dashboards (like node-exporter,
# kubelet, apiserver) as ConfigMaps. We disable the rest of the backend components in the values file.
chart = "//third_party/kube-prometheus-stack:kube-prometheus-stack-87.5.1.tgz",
helm_version = 3,
kube_version = "1.29.0",
# The namespace will later be replaced with the actual one.
namespace = "HELM-NAMESPACE",
# Pick a short release name as it will be used as a prefix for a lot of resources.
release_name = "grafana",
values = "grafana-cloud.values.yaml",
)

app_chart(
name = "grafana-cloud",
# CRITICAL: Do NOT include 00-crds.yaml to prevent ownership collisions with Prometheus
extra_values = ["values-cloud.yaml"],
files = [
":grafana-operator-chart.cloud",
],
)

app(
name = "grafana",
charts = [
":grafana-cloud",
],
visibility = ["//visibility:public"],
)
32 changes: 32 additions & 0 deletions src/app_charts/grafana/cloud/app.yaml

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
apiVersion: app.k8s.io/v1beta1
kind: Application
metadata:
name: "grafana"
labels:
app.kubernetes.io/name: {{ .Chart.Name }}
app.kubernetes.io/version: {{ .Chart.Version }}
spec:
selector:
matchLabels:
app.kubernetes.io/name: {{ .Chart.Name }}
componentKinds:
- group: core
kind: Service
- group: apps
kind: Deployment
- group: apps
kind: Ingress
- group: gateway.networking.k8s.io
kind: HTTPRoute
- group: gateway.envoyproxy.io
kind: SecurityPolicy
descriptor:
type: "grafana"
version: {{ .Chart.Version }}
description: "Grafana provides visualization dashboards"
keywords:
- "dashboard"
- "visualization"
links:
- description: Grafana Dashboard
url: "https://{{ .Values.domain }}/grafana/"
22 changes: 22 additions & 0 deletions src/app_charts/grafana/cloud/grafana-datasources.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: grafana-datasources
labels:
grafana_datasource: "1"
app.kubernetes.io/name: {{ .Chart.Name }}
data:
datasources.yaml: |
apiVersion: 1
{{- if .Values.datasources }}
datasources:
{{ toYaml .Values.datasources | indent 4 }}
{{- else }}
datasources:
- name: Prometheus
type: prometheus
uid: prometheus
url: http://kube-prometheus.{{ .Values.prometheusNamespace | default "app-prometheus" }}.svc.cluster.local:9090
access: proxy
isDefault: true
{{- end }}
Original file line numberDiff line numberDiff line change
Expand Up@@ -23,7 +23,7 @@ spec:
type: ReplacePrefixMatch
replacePrefixMatch: /
backendRefs:
- name: prom-grafana
- name: grafana
port: 80
- matches:
- path:
Expand All@@ -36,7 +36,7 @@ spec:
type: ReplaceFullPath
replaceFullPath: /
backendRefs:
- name: prom-grafana
- name: grafana
port: 80
---
apiVersion: gateway.envoyproxy.io/v1alpha1
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -23,6 +23,6 @@ spec:
pathType: Prefix
backend:
service:
name: prom-grafana
name: grafana
port:
number: 80
25 changes: 25 additions & 0 deletions src/app_charts/grafana/cloud/grafana-operator.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
# This includes all resources expanded from the grafana-operator chart using
# the values in ../grafana-cloud.values.yaml.
# Some pseudo-variables that were inserted there are replaced with actual runtime values.
# NOTE: The order here is important. The domain and project might be part of other values and
# need to be replaced last.
{{- $data := .Files.Get "files/grafana-operator-chart.cloud.yaml" -}}
# Pre-process variables
{{- $data = $data | replace "${CR_GF_INGRESS_AUTH_URL}" .Values.gf_ingress_auth_url -}}
{{- $data = $data | replace "${CR_GF_INGRESS_AUTH_SIGNIN}" .Values.gf_ingress_auth_signin -}}
{{- $data = $data | replace "${CR_GF_INGRESS_ERROR_PAGE_403}" .Values.gf_ingress_error_page_403 -}}
{{- $data = $data | replace "${CR_GF_SERVER_DOMAIN}" .Values.gf_server_domain -}}
{{- $data = $data | replace "${CR_GF_SERVER_ROOT_URL}" .Values.gf_server_root_url -}}
{{- $data = $data | replace "${CR_GF_CSRF_TRUSTED_ORIGINS}" .Values.gf_csrf_trusted_origins -}}
{{- $data = $data | replace "${CR_GF_SMTP_ENABLED}" .Values.gf_smtp_enabled -}}
{{- $data = $data | replace "${CR_GF_SMTP_HOST}" .Values.gf_smtp_host -}}
{{- $data = $data | replace "${CR_GF_SMTP_USER}" .Values.gf_smtp_user -}}
{{- $data = $data | replace "${CR_GF_SMTP_PASSWORD}" .Values.gf_smtp_password -}}
{{- $data = $data | replace "${CR_GF_SMTP_FROM_ADDRESS}" .Values.gf_smtp_from_address -}}
{{- $data = $data | replace "${CR_GF_SMTP_FROM_NAME}" .Values.gf_smtp_from_name -}}
{{- $data = $data | replace "${CR_GF_SMTP_SKIP_VERIFY}" .Values.gf_smtp_skip_verify -}}
{{- $data = $data | replace "HELM-NAMESPACE" .Release.Namespace -}}
{{- $data = $data | replace "${CLOUD_ROBOTICS_DOMAIN}" .Values.domain -}}
{{- $data = $data | replace "${GCP_PROJECT_ID}" .Values.project -}}

{{ $data }}
69 changes: 69 additions & 0 deletions src/app_charts/grafana/grafana-cloud.values.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,69 @@
nameOverride: kube
fullnameOverride: kube

kubeTargetVersionOverride: "1.23.8"

# We use the kube-prometheus-stack chart instead of the standalone grafana chart
# because the stack chart natively bundles and updates a large collection of standard
# kubernetes monitoring dashboards (via kubernetes-mixin, node-exporter-mixin, etc.)
# as ConfigMaps. By disabling the rest of the backend components and keeping only Grafana
# enabled, we get a fully configured standalone Grafana with all the rich Kubernetes
# observability dashboards maintained for us out of the box.
grafana:
# default password used by old releases, deployed behind auth-proxy so this
# is not a secret.
# we could also use "auth proxy authentication" but the second login defends
# against unintentional edits to dashboards.
adminPassword: "prom-operator"
testFramework:
enabled: false
env:
GF_SERVER_DOMAIN: "${CR_GF_SERVER_DOMAIN}"
GF_SERVER_ROOT_URL: "${CR_GF_SERVER_ROOT_URL}"
GF_AUTH_ANONYMOUS_ENABLED: "true"
# Load dashboards from configmaps with a given label across all namespaces.
sidecar:
dashboards:
enabled: true
label: grafana # Label our own legacy grafana-operator uses.
searchNamespace: ALL
multicluster:
global:
enabled: true
etcd:
enabled: true
grafana.ini:
analytics:
check_for_updates: false
security:
csrf_trusted_origins: "${CR_GF_CSRF_TRUSTED_ORIGINS}"
smtp:
enabled: "${CR_GF_SMTP_ENABLED}"
host: "${CR_GF_SMTP_HOST}"
user: "${CR_GF_SMTP_USER}"
password: "${CR_GF_SMTP_PASSWORD}"
from_address: "${CR_GF_SMTP_FROM_ADDRESS}"
from_name: "${CR_GF_SMTP_FROM_NAME}"
skip_verify: "${CR_GF_SMTP_SKIP_VERIFY}"
serviceMonitor:
relabelings:
- sourceLabels: [__meta_kubernetes_pod_node_name]
targetLabel: instance

gf_ingress_auth_url: "${CR_GF_INGRESS_AUTH_URL}"
gf_ingress_auth_signin: "${CR_GF_INGRESS_AUTH_SIGNIN}"
gf_ingress_error_page_403: "${CR_GF_INGRESS_ERROR_PAGE_403}"

# Disable all non-Grafana components
defaultRules:
create: false
alertmanager:
enabled: false
prometheus:
enabled: false
kubeStateMetrics:
enabled: false
nodeExporter:
enabled: false
prometheusOperator:
enabled: false
43 changes: 43 additions & 0 deletions src/app_charts/grafana/values-cloud.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,43 @@
# Enable toggle for the standalone app components
grafana:
enabled: true

# Grafana HTTP configuration
gf_server_domain: "${CLOUD_ROBOTICS_DOMAIN}"
gf_server_root_url: "https://${CLOUD_ROBOTICS_DOMAIN}/grafana"
gf_csrf_trusted_origins: ""
# Grafana Ingress configuration. Does not use the same replace as the values above.
gf_ingress_auth_url: "http://oauth2-proxy.default.svc.cluster.local/apis/core.token-vendor/v1/token.verify"
# Header modification for Istio/HTTPRoutes support.
gf_ingress_auth_url_header: ""
gf_ingress_auth_url_headervalue: ""
gf_ingress_auth_signin: "https://{{ .Values.domain }}/oauth2/start?rd=$escaped_request_uri"
gf_ingress_error_page_403: "https://{{ .Values.domain }}/oauth2/start?rd=$escaped_request_uri"
gf_auth_backend:
protocol: "http"
service: "oauth2-proxy"
namespace: "default"
port: 80
path: "/oauth2/auth"
contextExtensions: {}
authProxy:
authHeaders:
- authorization
- cookie
- x-forwarded-access-token
- x-forwarded-host
- apikey-token
- x-server-name

# Grafana SMTP configuration
# Notes: these need to be all string, since we apply them using the template funtion "replace"
gf_smtp_enabled: "false"
gf_smtp_host: "smtp-host"
gf_smtp_user: "smtp-user"
gf_smtp_password: "smtp-api-key"
gf_smtp_from_address: "from-address@example.com"
gf_smtp_from_name: "from-name"
gf_smtp_skip_verify: "true"

# Fallback prometheus datasource namespace
prometheusNamespace: "app-prometheus"
6 changes: 4 additions & 2 deletions src/app_charts/prometheus/cloud/app.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -21,6 +21,10 @@ spec:
kind: Ingress
- group: apps
kind: StatefulSet
- group: gateway.networking.k8s.io
kind: HTTPRoute
- group: gateway.envoyproxy.io
kind: SecurityPolicy
descriptor:
type: "prometheus"
version: {{ .Chart.Version }}
Expand All@@ -31,5 +35,3 @@ spec:
links:
- description: Prometheus
url: "https://{{ .Values.domain }}/prometheus/"
- description: Grafana Dashboard
url: "https://{{ .Values.domain }}/grafana/"
13 changes: 12 additions & 1 deletion src/app_charts/prometheus/cloud/prometheus-operator.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,7 +7,18 @@
# need to be replaced last.
{{- $data := .Files.Get "files/prometheus-operator-chart.cloud.yaml" -}}
# Pre-process variables
{{- $data = $data | replace "${CR_GF_SERVER_DOMAIN}" .Values.gf_server_domain | replace "${CR_GF_SERVER_ROOT_URL}" .Values.gf_server_root_url | replace "${CR_GF_CSRF_TRUSTED_ORIGINS}" .Values.gf_csrf_trusted_origins | replace "${CR_GF_SMTP_ENABLED}" .Values.gf_smtp_enabled | replace "${CR_GF_SMTP_HOST}" .Values.gf_smtp_host | replace "${CR_GF_SMTP_USER}" .Values.gf_smtp_user | replace "${CR_GF_SMTP_PASSWORD}" .Values.gf_smtp_password | replace "${CR_GF_SMTP_FROM_ADDRESS}" .Values.gf_smtp_from_address | replace "${CR_GF_SMTP_FROM_NAME}" .Values.gf_smtp_from_name | replace "${CR_GF_SMTP_SKIP_VERIFY}" .Values.gf_smtp_skip_verify | replace "${CR_GF_INGRESS_AUTH_URL}" .Values.gf_ingress_auth_url | replace "${CR_GF_INGRESS_AUTH_SIGNIN}" .Values.gf_ingress_auth_signin | replace "${CR_GF_INGRESS_ERROR_PAGE_403}" .Values.gf_ingress_error_page_403 | replace "${CR_PROM_INGRESS_AUTH_URL}" .Values.prom_ingress_auth_url | replace "${CR_PROM_INGRESS_AUTH_SIGNIN}" .Values.prom_ingress_auth_signin | replace "${CR_PROM_INGRESS_ERROR_PAGE_403}" .Values.prom_ingress_error_page_403 | replace "HELM-NAMESPACE" .Release.Namespace | replace "${LIMITS_MEMORY}" .Values.limits.memory | replace "${LIMITS_CPU}" .Values.limits.cpu | replace "${REQUESTS_STORAGE}" .Values.requests.storage | replace "${RETENTION_TIME}" .Values.retention.time | replace "${RETENTION_SIZE}" .Values.retention.size | replace "${EXTERNAL_URL}" .Values.prom_external_url | replace "${CLOUD_ROBOTICS_DOMAIN}" .Values.domain | replace "${GCP_PROJECT_ID}" .Values.project -}}
{{- $data = $data | replace "${CR_PROM_INGRESS_AUTH_URL}" .Values.prom_ingress_auth_url -}}
{{- $data = $data | replace "${CR_PROM_INGRESS_AUTH_SIGNIN}" .Values.prom_ingress_auth_signin -}}
{{- $data = $data | replace "${CR_PROM_INGRESS_ERROR_PAGE_403}" .Values.prom_ingress_error_page_403 -}}
{{- $data = $data | replace "HELM-NAMESPACE" .Release.Namespace -}}
{{- $data = $data | replace "${LIMITS_MEMORY}" .Values.limits.memory -}}
{{- $data = $data | replace "${LIMITS_CPU}" .Values.limits.cpu -}}
{{- $data = $data | replace "${REQUESTS_STORAGE}" .Values.requests.storage -}}
{{- $data = $data | replace "${RETENTION_TIME}" .Values.retention.time -}}
{{- $data = $data | replace "${RETENTION_SIZE}" .Values.retention.size -}}
{{- $data = $data | replace "${EXTERNAL_URL}" .Values.prom_external_url -}}
{{- $data = $data | replace "${CLOUD_ROBOTICS_DOMAIN}" .Values.domain -}}
{{- $data = $data | replace "${GCP_PROJECT_ID}" .Values.project -}}

# Inject the nodeSelector as a pre-formatted YAML block to allow users to define multiple selectors in a dict within values-cloud.yaml while maintaining valid indentation in the output.
{{- $prometheusNodeSelectorMap := .Values.prometheus.prometheusSpec.nodeSelector -}}
Expand Down
44 changes: 1 addition & 43 deletions src/app_charts/prometheus/prometheus-cloud.values.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -182,49 +182,7 @@ nodeExporter:
targetLabel: instance

grafana:
# default password used by old releases, deployed behind auth-proxy so this
# is not a secret.
# we could also use "auth proxy authentication" but the second login defends
# against unintentional edits to dashboards.
adminPassword: "prom-operator"
testFramework:
enabled: false
env:
GF_SERVER_DOMAIN: "${CR_GF_SERVER_DOMAIN}"
GF_SERVER_ROOT_URL: "${CR_GF_SERVER_ROOT_URL}"
GF_AUTH_ANONYMOUS_ENABLED: "true"
# Load dashboards from configmaps with a given label across all namespaces.
sidecar:
dashboards:
enabled: true
label: grafana # Label our own legacy grafana-operator uses.
searchNamespace: ALL
multicluster:
global:
enabled: true
etcd:
enabled: true
grafana.ini:
analytics:
check_for_updates: false
security:
csrf_trusted_origins: "${CR_GF_CSRF_TRUSTED_ORIGINS}"
smtp:
enabled: "${CR_GF_SMTP_ENABLED}"
host: "${CR_GF_SMTP_HOST}"
user: "${CR_GF_SMTP_USER}"
password: "${CR_GF_SMTP_PASSWORD}"
from_address: "${CR_GF_SMTP_FROM_ADDRESS}"
from_name: "${CR_GF_SMTP_FROM_NAME}"
skip_verify: "${CR_GF_SMTP_SKIP_VERIFY}"
serviceMonitor:
relabelings:
- sourceLabels: [__meta_kubernetes_pod_node_name]
targetLabel: instance

gf_ingress_auth_url: "${CR_GF_INGRESS_AUTH_URL}"
gf_ingress_auth_signin: "${CR_GF_INGRESS_AUTH_SIGNIN}"
gf_ingress_error_page_403: "${CR_GF_INGRESS_ERROR_PAGE_403}"
enabled: false

prom_ingress_auth_url: "${CR_PROM_INGRESS_AUTH_URL}"
prom_ingress_auth_signin: "${CR_PROM_INGRESS_AUTH_SIGNIN}"
Expand Down
Loading
Loading