Files

263 lines
6.0 KiB
YAML

replicas: 1
extraLabels:
observability.hyeonworks.com/instance: home
deploymentStrategy:
type: Recreate
revisionHistoryLimit: 3
automountServiceAccountToken: false
enableServiceLinks: false
rbac:
create: false
serviceAccount:
create: true
name: grafana
automountServiceAccountToken: false
image:
registry: docker.io
repository: grafana/grafana
tag: 13.1.1
sha: f33c692ba1a5ee15724cf6b22db65e9de39dde14d80f7d73a9546e3fc917270b
pullPolicy: IfNotPresent
testFramework:
enabled: false
securityContext:
runAsNonRoot: true
runAsUser: 472
runAsGroup: 472
fsGroup: 472
fsGroupChangePolicy: OnRootMismatch
seccompProfile:
type: RuntimeDefault
containerSecurityContext:
allowPrivilegeEscalation: false
privileged: false
capabilities:
drop:
- ALL
seccompProfile:
type: RuntimeDefault
resources:
requests:
cpu: 100m
memory: 256Mi
limits:
cpu: 500m
memory: 512Mi
initChownData:
enabled: false
persistence:
type: pvc
enabled: true
storageClassName: ssd-local-observability-grafana-retain
volumeName: observability-grafana-local-pv
lookupVolumeName: false
accessModes:
- ReadWriteOnce
size: 2Gi
finalizers:
- kubernetes.io/pvc-protection
admin:
existingSecret: grafana-admin
userKey: admin-user
passwordKey: admin-password
envValueFrom:
GF_AUTH_GENERIC_OAUTH_CLIENT_ID:
secretKeyRef:
name: grafana-keycloak-oidc
key: client-id
GF_AUTH_GENERIC_OAUTH_CLIENT_SECRET:
secretKeyRef:
name: grafana-keycloak-oidc
key: client-secret
service:
enabled: true
type: ClusterIP
port: 80
targetPort: 3000
portName: service
serviceMonitor:
enabled: true
interval: 30s
path: /metrics
ingress:
enabled: true
annotations: {}
path: /
pathType: Prefix
hosts:
- grafana.learn.hyeonworks.com
tls: []
grafana.ini:
paths:
data: /var/lib/grafana/
logs: /var/log/grafana
plugins: /var/lib/grafana/plugins
provisioning: /etc/grafana/provisioning
analytics:
check_for_updates: false
check_for_plugin_updates: false
reporting_enabled: false
plugins:
preinstall_disabled: true
server:
domain: grafana.learn.hyeonworks.com
root_url: https://grafana.learn.hyeonworks.com/
enforce_domain: true
security:
cookie_secure: true
cookie_samesite: lax
auth:
disable_login_form: false
oauth_auto_login: false
login_maximum_lifetime_duration: 8h
login_maximum_inactive_lifetime_duration: 30m
auth.anonymous:
enabled: false
auth.basic:
enabled: true
auth.generic_oauth:
enabled: true
name: Keycloak
allow_sign_up: true
use_pkce: true
scopes: openid profile email
groups_attribute_path: groups
allowed_groups: /platform-observability-admins /platform-observability-viewers
role_attribute_strict: true
allow_assign_grafana_admin: false
skip_org_role_sync: false
validate_id_token: true
use_refresh_token: true
role_attribute_path: "contains(groups[*], '/platform-observability-admins') && 'Admin' || contains(groups[*], '/platform-observability-viewers') && 'Viewer' || null"
auth_url: https://id.learn.hyeonworks.com/realms/hyeonworks/protocol/openid-connect/auth
token_url: https://id.learn.hyeonworks.com/realms/hyeonworks/protocol/openid-connect/token
api_url: https://id.learn.hyeonworks.com/realms/hyeonworks/protocol/openid-connect/userinfo
signout_redirect_url: https://id.learn.hyeonworks.com/realms/hyeonworks/protocol/openid-connect/logout
datasources:
datasources.yaml:
apiVersion: 1
deleteDatasources:
- name: Prometheus
orgId: 1
- name: Loki
orgId: 1
- name: Tempo
orgId: 1
datasources:
- name: Prometheus
uid: prometheus
type: prometheus
access: proxy
url: http://observability-core-kube-pr-prometheus.observability.svc.cluster.local:9090
isDefault: true
editable: false
jsonData:
httpMethod: POST
timeInterval: 30s
- name: Loki
uid: loki
type: loki
access: proxy
url: http://loki.observability.svc.cluster.local:3100
isDefault: false
editable: false
jsonData:
derivedFields:
- name: trace_id
matcherRegex: '"trace_id"[[:space:]]*:[[:space:]]*"([0-9a-f]{32})"'
datasourceUid: tempo
url: '$${__value.raw}'
- name: Tempo
uid: tempo
type: tempo
access: proxy
url: http://tempo.observability.svc.cluster.local:3200
isDefault: false
editable: false
jsonData:
httpMethod: GET
nodeGraph:
enabled: true
serviceMap:
datasourceUid: prometheus
tracesToLogsV2:
datasourceUid: loki
spanStartTimeShift: -1m
spanEndTimeShift: 1m
tags:
- key: k8s.namespace.name
value: namespace
- key: k8s.pod.name
value: pod
filterByTraceID: true
filterBySpanID: false
sidecar:
image:
registry: quay.io
repository: kiwigrid/k8s-sidecar
tag: 2.10.0
sha: 129877c81acf2bc8c3fa000e89a62e020eb89d41ceb94767c657aef5bb0cc0d3
imagePullPolicy: IfNotPresent
resources:
requests:
cpu: 25m
memory: 64Mi
limits:
cpu: 100m
memory: 128Mi
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop:
- ALL
seccompProfile:
type: RuntimeDefault
dashboards:
enabled: true
label: grafana_dashboard
labelValue: "1"
searchNamespace:
- observability
resource: configmap
watchMethod: WATCH
skipReload: true
provider:
name: sidecarProvider
orgid: 1
folder: ""
folderUid: ""
type: file
disableDelete: false
allowUiUpdates: false
foldersFromFilesStructure: false
imageRenderer:
enabled: false
networkPolicy:
enabled: false
assertNoLeakedSecrets: true