Add platform infrastructure configuration

This commit is contained in:
donghyeon-ka
2026-08-28 17:35:41 +09:00
parent fa76531e5b
commit 16c337bcc9
302 changed files with 83259 additions and 1 deletions
@@ -0,0 +1,32 @@
# Observability Local PersistentVolumes
This kustomization reserves six workload-specific Local PV binding contracts on
the root SSD. Each owner has a dedicated `kubernetes.io/no-provisioner`
StorageClass with `WaitForFirstConsumer`, `Retain`, and volume expansion
disabled. Every PV is `ReadWriteOnce`, retains its data after claim deletion,
and is affined to `donghyeon-system-product-name`.
| Owner | Host path | Capacity | StorageClass | Directory owner |
| --- | --- | ---: | --- | --- |
| Prometheus | `/srv/k3s/ssd/observability/prometheus` | `20Gi` | `ssd-local-observability-prometheus-retain` | `1000:2000` |
| Grafana | `/srv/k3s/ssd/observability/grafana` | `2Gi` | `ssd-local-observability-grafana-retain` | `472:472` |
| Alertmanager | `/srv/k3s/ssd/observability/alertmanager` | `1Gi` | `ssd-local-observability-alertmanager-retain` | `1000:2000` |
| Alloy | `/srv/k3s/ssd/observability/alloy` | `2Gi` | `ssd-local-observability-alloy-retain` | `473:473` |
| Loki | `/srv/k3s/ssd/observability/loki` | `5Gi` | `ssd-local-observability-loki-retain` | `10001:10001` |
| Tempo | `/srv/k3s/ssd/observability/tempo` | `5Gi` | `ssd-local-observability-tempo-retain` | `10001:10001` |
The declared 35 GiB is a Kubernetes binding contract, not an ext4 directory
quota. Project quota is not active. All six directories share root-filesystem
free space, so the later operational protections remain mandatory:
- Prometheus `retentionSize=16GB` is not a whole-filesystem cap and does not cap
WAL plus head data.
- Loki's 512 MB setting limits WAL replay RAM; it is not a disk quota.
- Loki `disk_full_threshold=0.90` uses `Statfs` on the WAL filesystem.
- Tempo 2.10.7 has no WAL byte limit or disk-full guard.
- Root-filesystem 75%, 85%, and 90% alerts, apply/smoke `du` and `df` caps, and
acceptance of the root-90%-full ingest-stop runbook are still required.
Run `bash scripts/bootstrap/prepare-observability-local-paths.sh` to inspect the
read-only plan. The separately confirmed `--execute` mode prepares the exact
paths at mode `0770`; it does not apply Kubernetes resources.