From 360fbdab555a85afd1fe41ac879969a0f4c5826e Mon Sep 17 00:00:00 2001 From: Mukul Sharma Date: Thu, 17 Sep 2026 15:30:49 +0530 Subject: [PATCH] Remove homelab k8s-admin-prd-ase1 overrides from the GCP repo Nothing on GKE reads them: ArgoCD's valueFiles point only at helm-overrides/gke-toolshed-prd-usc1. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01Fn2kUxyYNY4ApytbLiGWeY --- helm-overrides/k8s-admin-prd-ase1/README.md | 3 - .../alertmanager/custom-values.yaml | 269 --- .../alertmanager/migrate_silenced_alerts | 22 - .../alertmanager/silenced_alerts.json | 1 - .../alloy/custom-values.yaml | 49 - .../argocd-admin-prd/custom-values.yaml | 126 - .../athens-proxy/custom-values.yaml | 348 --- .../aurva-dataplane/custom-values.yaml | 675 ------ .../canary-bot-gcp/custom-values.yaml | 25 - .../cert-manager/custom-values.yaml | 129 -- .../conntrack-adjuster/custom-values.yaml | 26 - .../contour-ca-issuer/custom-values.yaml | 17 - .../contour-cert-checker/custom-values.yaml | 28 - .../contour-internal-0/custom-values.yaml | 99 - .../contour/custom-values.yaml | 69 - .../coredns/custom-values.yaml | 27 - .../dind-int/custom-values.yaml | 88 - .../dind/custom-values.yaml | 88 - .../eck-operator/custom-values.yaml | 379 --- .../elastalert2/custom-values.yaml | 472 ---- ...o-launch-eck-observability-monitoring.yaml | 38 - .../elastic-cluster/argo-launch.yaml | 45 - .../elasticsearch.yaml | 63 - .../ingress-es.yaml | 24 - .../ingress-kibana.yaml | 24 - .../kibana-hpa.yaml | 38 - .../eck-observability-monitoring/kibana.yaml | 47 - .../eck-observability-monitoring/sc.yaml | 14 - .../serviceaccount.yaml | 5 - .../eck-observability/apm-hpa.yaml | 38 - .../eck-observability/apm-httpproxy.yaml | 23 - .../eck-observability/apm-server.yaml | 40 - .../eck-observability/elasticsearch.yaml | 181 -- .../es-hot-warm-service.yaml | 19 - .../eck-observability/es-httpproxy.yaml | 21 - .../httpproxy-kibana-oauth.yaml | 35 - .../eck-observability/httpproxy.yaml | 20 - .../eck-observability/ingress-apm.yaml | 27 - .../eck-observability/ingress-es.yaml | 25 - .../eck-observability/ingress-kibana.yaml | 50 - .../ingress-oauth2-proxy.yaml | 25 - .../eck-observability/kibana-hpa.yaml | 38 - .../eck-observability/kibana.yaml | 61 - .../eck-observability/namespace.yaml | 6 - .../eck-observability/oauth2-proxy.yaml | 147 -- .../eck-observability/sc-high-iops.yaml | 15 - .../elastic-cluster/eck-observability/sc.yaml | 14 - .../eck-observability/service-export-apm.yaml | 9 - .../service-export-es-hot-warm.yaml | 5 - .../eck-observability/service-export-es.yaml | 5 - .../eck-observability/serviceaccount.yaml | 7 - .../external-secrets/custom-values.yaml | 37 - .../flagger/custom-values.yaml | 55 - .../fluentd/custom-values.yaml | 679 ------ .../gitea/custom-values.yaml | 108 - .../grafana-edge/custom-values.yaml | 68 - .../grafana-sec/custom-values.yaml | 1333 ----------- .../grafana/custom-values.yaml | 275 --- .../harbor/custom-values.yaml | 112 - .../ingress-nginx-external/custom-values.yaml | 34 - .../ingress-nginx/custom-values.yaml | 32 - .../jenkins/custom-values.yaml | 98 - .../jfrog-public/custom-values.yaml | 2041 ----------------- .../jfrog/custom-values.yaml | 2041 ----------------- .../keda/custom-values.yaml | 26 - .../kube-dns/custom-values.yaml | 2 - .../kube-events/custom-values.yaml | 149 -- .../kube-state-metrics/custom-values.yaml | 478 ---- .../kubectl-mcp-server/custom-values.yaml | 128 -- .../loki-distributed/custom-values.yaml | 272 --- .../alertmanager_config.yaml | 21 - .../mimir-distributed/custom-values.yaml | 406 ---- .../node-exporter/custom-values.yaml | 16 - .../custom-values.yaml | 659 ------ .../custom-values.yaml | 111 - .../paused-container/custom-values.yaml | 73 - .../pmm-mongo/custom-values.yaml | 279 --- .../postgresql/custom-values.yaml | 48 - .../custom-values.yaml | 496 ---- .../custom-values.yaml | 170 -- .../pyroscope/custom-values.yaml | 62 - .../redis/custom-values.yaml | 50 - .../sonarqube-public/custom-values.yaml | 652 ------ .../sonarqube/custom-values.yaml | 650 ------ .../superset/custom-values.yaml | 245 -- .../tempo-distributed/custom-values.yaml | 209 -- .../uptime-kuma/custom-values.yaml | 168 -- .../vault/custom-values.yaml | 67 - .../custom-values.yaml | 296 --- .../custom-values.yaml | 272 --- .../victoria-metrics-agent/custom-values.yaml | 296 --- .../custom-values.yaml | 304 --- .../custom-values.yaml | 286 --- .../custom-values.yaml | 340 --- .../custom-values.yaml | 305 --- .../custom-values.yaml | 340 --- .../victoria-metrics-alert/custom-values.yaml | 305 --- .../victoria-metrics-auth/custom-values.yaml | 345 --- .../custom-values.yaml | 235 -- .../custom-values.yaml | 234 -- .../custom-values.yaml | 234 -- .../victoria-metrics-mcp/custom-values.yaml | 226 -- .../custom-values.yaml | 311 --- .../custom-values.yaml | 311 --- .../custom-values.yaml | 315 --- .../custom-values.yaml | 309 --- .../custom-values.yaml | 302 --- .../custom-values.yaml | 297 --- .../custom-values.yaml | 44 - .../custom-values.yaml | 316 --- .../custom-values.yaml | 316 --- .../custom-values.yaml | 316 --- .../custom-values.yaml | 316 --- .../victoriametrics-agent/custom-values.yaml | 480 ---- .../victoriametrics-insert/custom-values.yaml | 411 ---- .../victoriametrics-select/custom-values.yaml | 468 ---- .../custom-values.yaml | 363 --- .../vm-alert-config/custom-values.yaml | 1 - .../vmagent/custom-values.yaml | 102 - 119 files changed, 25395 deletions(-) delete mode 100644 helm-overrides/k8s-admin-prd-ase1/README.md delete mode 100644 helm-overrides/k8s-admin-prd-ase1/alertmanager/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/alertmanager/migrate_silenced_alerts delete mode 100644 helm-overrides/k8s-admin-prd-ase1/alertmanager/silenced_alerts.json delete mode 100644 helm-overrides/k8s-admin-prd-ase1/alloy/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/argocd-admin-prd/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/athens-proxy/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/aurva-dataplane/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/canary-bot-gcp/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/cert-manager/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/conntrack-adjuster/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/contour-ca-issuer/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/contour-cert-checker/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/contour-internal-0/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/contour/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/coredns/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/dind-int/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/dind/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/eck-operator/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastalert2/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/argo-launch-eck-observability-monitoring.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/argo-launch.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/elasticsearch.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/ingress-es.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/ingress-kibana.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/kibana-hpa.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/kibana.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/sc.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/serviceaccount.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/apm-hpa.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/apm-httpproxy.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/apm-server.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/elasticsearch.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/es-hot-warm-service.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/es-httpproxy.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/httpproxy-kibana-oauth.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/httpproxy.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/ingress-apm.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/ingress-es.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/ingress-kibana.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/ingress-oauth2-proxy.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/kibana-hpa.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/kibana.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/namespace.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/oauth2-proxy.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/sc-high-iops.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/sc.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/service-export-apm.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/service-export-es-hot-warm.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/service-export-es.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/serviceaccount.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/external-secrets/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/flagger/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/fluentd/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/gitea/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/grafana-edge/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/grafana-sec/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/grafana/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/harbor/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/ingress-nginx-external/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/ingress-nginx/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/jenkins/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/jfrog-public/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/jfrog/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/keda/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/kube-dns/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/kube-events/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/kube-state-metrics/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/kubectl-mcp-server/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/loki-distributed/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/mimir-distributed/alertmanager_config.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/mimir-distributed/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/node-exporter/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/opentelemetry-collector/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/opentelemetry-deployment/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/paused-container/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/pmm-mongo/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/postgresql/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/prometheus-node-exporter/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/prometheus-stackdriver-exporter/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/pyroscope/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/redis/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/sonarqube-public/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/sonarqube/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/superset/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/tempo-distributed/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/uptime-kuma/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/vault/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-agent-dr/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-agent-fb/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-agent/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-alert-dr/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-alert-fb/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-alert-secured-stateful/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-alert-secured/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-alert-stateful/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-alert/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-auth/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-insert-dbackup/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-insert-dr/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-insert/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-mcp/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-select-dbackup/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-select-dr/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-select-rs-test1/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-select-test/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-select/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-single-fb/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-single/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-storage-dbackup/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-storage-dr/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-storage-mds-backup/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoria-metrics-storage/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoriametrics-agent/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoriametrics-insert/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoriametrics-select/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/victoriametrics-storage/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/vm-alert-config/custom-values.yaml delete mode 100644 helm-overrides/k8s-admin-prd-ase1/vmagent/custom-values.yaml diff --git a/helm-overrides/k8s-admin-prd-ase1/README.md b/helm-overrides/k8s-admin-prd-ase1/README.md deleted file mode 100644 index 27aeadc..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/README.md +++ /dev/null @@ -1,3 +0,0 @@ -# Cluster-based Custom Values - -This folder contains the custom `values.yaml` files organized based on specific cluster names. Each subdirectory corresponds to a particular cluster and holds the configurations for the applications and tools deployed within that cluster. \ No newline at end of file diff --git a/helm-overrides/k8s-admin-prd-ase1/alertmanager/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/alertmanager/custom-values.yaml deleted file mode 100644 index 52fbeac..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/alertmanager/custom-values.yaml +++ /dev/null @@ -1,269 +0,0 @@ -replicaCount: 5 - -image: - repository: quay.io/prometheus/alertmanager - pullPolicy: IfNotPresent - # Overrides the image tag whose default is the chart appVersion. - tag: "" - -extraArgs: - log.level: debug - cluster.probe-timeout: 1s - cluster.probe-interval: 2s - - -## Additional Alertmanager Secret mounts -# Defines additional mounts with secrets. Secrets must be manually created in the namespace. -extraSecretMounts: [] - # - name: secret-files - # mountPath: /etc/secrets - # subPath: "" - # secretName: alertmanager-secret-files - # readOnly: true - -imagePullSecrets: [] -nameOverride: "" -fullnameOverride: alertmanager-infra-prd -## namespaceOverride overrides the namespace which the resources will be deployed in -namespaceOverride: "" - -configMap: alertmanager-infra-prd-config - -labels: - bu: "infra" - team: "sre" - service: "alertmanager-infra-prd" - env: "prd" - priority: "p0" - type: "alertmanager" - -automountServiceAccountToken: true - -serviceAccount: - # Specifies whether a service account should be created - create: true - # Annotations to add to the service account - annotations: {} - # The name of the service account to use. - # If not set and create is true, a name is generated using the fullname template - name: "" - -# Sets priorityClassName in alertmanager pod -priorityClassName: "" - -podSecurityContext: - fsGroup: 65534 -dnsConfig: {} - # nameservers: - # - 1.2.3.4 - # searches: - # - ns1.svc.cluster-domain.example - # - my.dns.search.suffix - # options: - # - name: ndots - # value: "2" - # - name: edns0 -hostAliases: [] - # - ip: "127.0.0.1" - # hostnames: - # - "foo.local" - # - "bar.local" - # - ip: "10.1.2.3" - # hostnames: - # - "foo.remote" - # - "bar.remote" -securityContext: - # capabilities: - # drop: - # - ALL - # readOnlyRootFilesystem: true - runAsUser: 65534 - runAsNonRoot: true - runAsGroup: 65534 - -additionalPeers: [] - -## Additional InitContainers to initialize the pod -## -extraInitContainers: [] - -## Additional containers to add to the stateful set. This will allow to setup sidecarContainers like a proxy to integrate -## alertmanager with an external tool like teams that has not direct integration. -## -extraContainers: [] - -livenessProbe: - httpGet: - path: / - port: http - -readinessProbe: - httpGet: - path: / - port: http - -service: - annotations: {} - type: ClusterIP - port: 9093 - clusterPort: 9094 - loadBalancerIP: "" # Assign ext IP when Service type is LoadBalancer - loadBalancerSourceRanges: [] # Only allow access to loadBalancerIP from these IPs - # if you want to force a specific nodePort. Must be use with service.type=NodePort - # nodePort: - -ingress: - enabled: true - className: nginx-internal - annotations: {} - # kubernetes.io/ingress.class: nginx - # kubernetes.io/tls-acme: "true" - hosts: - - host: alertmanager-infra-prd.meeshogcp.in - paths: - - path: / - pathType: ImplementationSpecific - tls: [] - # - secretName: chart-example-tls - # hosts: - # - alertmanager.domain.com - -resources: - # We usually recommend not to specify default resources and to leave this as a conscious - # choice for the user. This also increases chances charts run on environments with little - # resources, such as Minikube. If you do want to specify resources, uncomment the following - # lines, adjust them as necessary, and remove the curly braces after 'resources:'. - # limits: - # cpu: 100m - # memory: 128Mi - requests: - cpu: 100m - memory: 150Mi - -nodeSelector: - dedicated: "vmselect-temp" - -tolerations: - - key: "dedicated" - operator: "Equal" - value: "vmselect-temp" - effect: "NoSchedule" -affinity: {} - -## Pod anti-affinity can prevent the scheduler from placing Alertmanager replicas on the same node. -## The default value "soft" means that the scheduler should *prefer* to not schedule two replica pods onto the same node but no guarantee is provided. -## The value "hard" means that the scheduler is *required* to not schedule two replica pods onto the same node. -## The value "" will disable pod anti-affinity so that no anti-affinity rules will be configured. -## -podAntiAffinity: "" - -## If anti-affinity is enabled sets the topologyKey to use for anti-affinity. -## This can be changed to, for example, failure-domain.beta.kubernetes.io/zone -## -podAntiAffinityTopologyKey: kubernetes.io/hostname - -## Topology spread constraints rely on node labels to identify the topology domain(s) that each Node is in. -## Ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/ -topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: DoNotSchedule - labelSelector: - matchLabels: - type: alertmanager - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: DoNotSchedule - labelSelector: - matchLabels: - type: alertmanager - -statefulSet: - annotations: {} - -podAnnotations: {} -podLabels: {} - -# Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/ -podDisruptionBudget: {} - # maxUnavailable: 1 - # minAvailable: 1 - -command: [] - -persistence: - enabled: true - ## Persistent Volume Storage Class - ## If defined, storageClassName: - ## If set to "-", storageClassName: "", which disables dynamic provisioning - ## If undefined (the default) or set to null, no storageClassName spec is - ## set, choosing the default provisioner. - ## - # storageClass: "-" - accessModes: - - ReadWriteOnce - size: 15Gi - -configAnnotations: {} - ## For example if you want to provide private data from a secret vault - ## https://github.com/banzaicloud/bank-vaults/tree/main/charts/vault-secrets-webhook - ## P.s.: Add option `configMapMutation: true` for vault-secrets-webhook - # vault.security.banzaicloud.io/vault-role: "admin" - # vault.security.banzaicloud.io/vault-addr: "https://vault.vault.svc.cluster.local:8200" - # vault.security.banzaicloud.io/vault-skip-verify: "true" - # vault.security.banzaicloud.io/vault-path: "kubernetes" - ## Example for inject secret - # slack_api_url: '${vault:secret/data/slack-hook-alerts#URL}' - -config: {} - -## Monitors ConfigMap changes and POSTs to a URL -## Ref: https://github.com/jimmidyson/configmap-reload -## -configmapReload: - ## If false, the configmap-reload container will not be deployed - ## - enabled: true - - ## configmap-reload container name - ## - name: configmap-reload - - ## configmap-reload container image - ## - image: - repository: jimmidyson/configmap-reload - tag: v0.8.0 - pullPolicy: IfNotPresent - - # containerPort: 9533 - - ## configmap-reload resource requests and limits - ## Ref: http://kubernetes.io/docs/user-guide/compute-resources/ - ## - resources: {} - -templates: {} -# alertmanager.tmpl: |- - -## Optionally specify extra list of additional volumeMounts -extraVolumeMounts: [] - # - name: extras - # mountPath: /usr/share/extras - # readOnly: true - -## Optionally specify extra list of additional volumes -extraVolumes: [] - # - name: extras - # emptyDir: {} - -## Optionally specify extra environment variables to add to alertmanager container -extraEnv: [] - # - name: FOO - # value: BAR - -testFramework: - enabled: false - annotations: - "helm.sh/hook": test-success - # "helm.sh/hook-delete-policy": "before-hook-creation,hook-succeeded" diff --git a/helm-overrides/k8s-admin-prd-ase1/alertmanager/migrate_silenced_alerts b/helm-overrides/k8s-admin-prd-ase1/alertmanager/migrate_silenced_alerts deleted file mode 100644 index 98e6d70..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/alertmanager/migrate_silenced_alerts +++ /dev/null @@ -1,22 +0,0 @@ -Here are the steps on how to migrate silenced alerts from an older Alertmanager to a newer Alertmanager machine: - -1. Stop the old Alertmanager. -2. Export the silenced alerts from the old Alertmanager. You can use the following command: - -amtool -o json --alertmanager.url=http://devops-p-alertmanager-01b.meeshoint.in:9093 silence > silenced_alerts.json - -3. Copy the silenced_alerts.json file to the new Alertmanager machine. - -k cp helm-overrides/prod-ops-cluster/alertmanager/silenced_alerts.json alertmanager/prd-infra-alertmanager-1:/home -c alertmanager - -4. Exec into the new Alertmanager. - -k exec -it prd-infra-alertmanager-1 -c alertmanager -- sh - -5. Import the silenced alerts into the new Alertmanager. You can use the following command: - -amtool --alertmanager.url=https://prd-infra-alertmanager.meesho.com silence import ../home/silenced_alerts.json - - -Note: -1. If you are running alertmanager on K8s as STS, then you only need to import in any 1 of the pods else duplicate silences will be created. \ No newline at end of file diff --git a/helm-overrides/k8s-admin-prd-ase1/alertmanager/silenced_alerts.json b/helm-overrides/k8s-admin-prd-ase1/alertmanager/silenced_alerts.json deleted file mode 100644 index 8f53372..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/alertmanager/silenced_alerts.json +++ /dev/null @@ -1 +0,0 @@ -[{"id":"a4c02ae3-f9a5-4e82-a318-0dc304806aa3","status":{"state":"active"},"updatedAt":"2023-08-10T12:22:19.934Z","comment":"Grafana moved to EKS and this instance has been stopped","createdBy":"amul.kesrani@meesho.com","endsAt":"2023-08-17T12:20:47.423Z","matchers":[{"isRegex":false,"name":"Environment","value":"prod"},{"isRegex":false,"name":"alertgroup","value":"EC2-grafana-Alerts"},{"isRegex":false,"name":"alertname","value":"grafana-Instance-Down"},{"isRegex":false,"name":"alerts","value":"devops-alerts"},{"isRegex":false,"name":"app","value":"grafana"},{"isRegex":false,"name":"bu","value":"infra"},{"isRegex":false,"name":"env","value":"prd"},{"isRegex":false,"name":"instance","value":"172.31.3.68:9100"},{"isRegex":false,"name":"job","value":"node_exporter"},{"isRegex":false,"name":"name","value":"devops-p-grafana-10.0.1"},{"isRegex":false,"name":"pod","value":"backend"},{"isRegex":false,"name":"priority","value":"p0"},{"isRegex":false,"name":"private_ip","value":"172.31.3.68"},{"isRegex":false,"name":"public_ip","value":"52.77.227.80"},{"isRegex":false,"name":"service","value":"grafana"},{"isRegex":false,"name":"severity","value":"critical"},{"isRegex":false,"name":"status","value":"running"},{"isRegex":false,"name":"team","value":"sre"},{"isRegex":false,"name":"type","value":"grafana"}],"startsAt":"2023-08-10T12:22:19.934Z"},{"id":"b2c9d732-1e51-4f7a-b857-c89f836c6919","status":{"state":"active"},"updatedAt":"2023-07-19T18:09:29.936Z","comment":"not required","createdBy":"pavan reddy","endsAt":"2023-08-18T18:08:51.415Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-dp-starburst-Cilium-Alerts"},{"isRegex":false,"name":"alertname","value":"dp-starburst-MapOps-Crossed-Threshold"},{"isRegex":false,"name":"bu","value":"infra"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"env","value":"prd"},{"isRegex":false,"name":"priority","value":"p0"},{"isRegex":false,"name":"service","value":"eks-cilium"},{"isRegex":false,"name":"severity","value":"critical"},{"isRegex":false,"name":"team","value":"devops"}],"startsAt":"2023-07-19T18:09:29.936Z"},{"id":"7672d73f-fafe-4f78-8865-cdc11f2c9f4a","status":{"state":"active"},"updatedAt":"2022-09-01T07:52:45.577Z","comment":"silenced as per sreenivas requested","createdBy":"veera","endsAt":"2023-09-01T07:45:13.705Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"redis-labs-alerts"},{"isRegex":false,"name":"alertname","value":"Throughput Greater Than 200k"},{"isRegex":false,"name":"bdb","value":"11029236"},{"isRegex":false,"name":"cluster","value":"c19268.ap-seast-1-mz.ec2.cloud.rlrcp.com"},{"isRegex":false,"name":"instance","value":"redis-11303.internal.c19268.ap-seast-1-mz.ec2.cloud.rlrcp.com:8070"},{"isRegex":false,"name":"job","value":"redis-enterprise"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2022-09-01T07:52:45.577Z"},{"id":"06be4ce6-75c9-4cb6-b816-5419fd90cfb3","status":{"state":"active"},"updatedAt":"2022-09-01T10:39:17.934Z","comment":"as per devraj confirmation","createdBy":"veera","endsAt":"2023-09-01T10:38:57.570Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"redis-labs-alerts"},{"isRegex":false,"name":"alertname","value":"Throughput Greater Than 200k"},{"isRegex":false,"name":"bdb","value":"11029236"},{"isRegex":false,"name":"cluster","value":"c19268.ap-seast-1-mz.ec2.cloud.rlrcp.com"},{"isRegex":false,"name":"instance","value":"redis-11450.internal.c19268.ap-seast-1-mz.ec2.cloud.rlrcp.com:8070"},{"isRegex":false,"name":"job","value":"redis-enterprise"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2022-09-01T10:39:17.934Z"},{"id":"6c98769a-acdd-4e93-8af4-1f019f4a71a8","status":{"state":"active"},"updatedAt":"2023-08-16T19:56:39.846Z","comment":"Silenced as requested by Shubham Gupta","createdBy":"sai teja","endsAt":"2023-09-15T19:55:26.219Z","matchers":[{"isRegex":false,"name":"alertname","value":"FreeStorageSpace-100G"},{"isRegex":false,"name":"domain_name","value":"platform-p-qwest"},{"isRegex":false,"name":"alertgroup","value":"Elastic-Search-Alerts"}],"startsAt":"2023-08-16T19:56:39.846Z"},{"id":"7f307b76-f507-41df-ab6d-83ff68af4db6","status":{"state":"active"},"updatedAt":"2022-11-30T16:19:23.994Z","comment":"not required as per dev suggestion","createdBy":"Muhilan","endsAt":"2023-09-26T16:18:54.527Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"Target-Group-Alerts"},{"isRegex":false,"name":"alertname","value":"UnhealthyHost"},{"isRegex":false,"name":"job","value":"aws_applicationelb"},{"isRegex":false,"name":"load_balancer","value":"app/bac-p-notification-alb/8fe95c1419cb49e7"},{"isRegex":false,"name":"resource","value":"AWS Target Group"},{"isRegex":false,"name":"severity","value":"critical"},{"isRegex":false,"name":"target_group","value":"targetgroup/bac-p-vision-scheduler/c5d0b5af122d41ef"}],"startsAt":"2022-11-30T16:19:23.994Z"},{"id":"999374f4-4057-46c8-a6de-1ecadacdef0b","status":{"state":"active"},"updatedAt":"2023-05-22T05:22:12.006Z","comment":"sIlenced as requested by Paras","createdBy":"sai teja","endsAt":"2023-10-07T13:46:19.745Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-demand-Pod-Alerts"},{"isRegex":true,"name":"alertname","value":"Pod-Not-in-Ready-State|Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-demand-cluster"},{"isRegex":false,"name":"job","value":"kube-state-metrics-p-demand-cluster"},{"isRegex":false,"name":"label_bu","value":"demand"},{"isRegex":false,"name":"label_env","value":"prod"},{"isRegex":true,"name":"label_team","value":"shopping-platform|discovery-platform"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-05-22T05:22:12.006Z"},{"id":"3b6d483f-abb0-4452-a25f-54549188b331","status":{"state":"active"},"updatedAt":"2023-05-26T05:27:54.485Z","comment":"as per request","createdBy":"Sai Teja","endsAt":"2023-10-13T05:26:38.486Z","matchers":[{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dataplatform-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"druid"},{"isRegex":false,"name":"label_team","value":"data-platform-nrt"},{"isRegex":false,"name":"namespace","value":"prd-druid"},{"isRegex":true,"name":"pod","value":".*historical.*|.*broker.*|.*middle-manager.*"}],"startsAt":"2023-05-26T05:27:54.485Z"},{"id":"742401b6-8781-4949-9799-5adeefa422af","status":{"state":"active"},"updatedAt":"2022-10-28T11:49:47.386Z","comment":"not in live","createdBy":"veera","endsAt":"2023-10-28T11:49:35.700Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"Process_Alert"},{"isRegex":false,"name":"alertname","value":"jusda-shipment-queue-processor"},{"isRegex":false,"name":"app","value":"manifest-worker"},{"isRegex":false,"name":"host","value":"bac-p-manifest-worker-01b-cicd"},{"isRegex":false,"name":"instance","value":"172.31.8.167:9273"},{"isRegex":false,"name":"job","value":"telegraf-exporter"},{"isRegex":false,"name":"name","value":"bac-p-worker-manifest-01b"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2022-10-28T11:49:47.386Z"},{"id":"57ddccaf-2de4-43fa-b45b-7e6564b60611","status":{"state":"active"},"updatedAt":"2023-06-12T06:28:58.984Z","comment":"silenced as requested by Manjeet","createdBy":"sai teja","endsAt":"2023-10-30T06:27:12.335Z","matchers":[{"isRegex":false,"name":"alertname","value":"Pod-CPU-Crossed-80%"},{"isRegex":false,"name":"label_service","value":"di-airflow-service"},{"isRegex":false,"name":"namespace","value":"prd-di-airflow"}],"startsAt":"2023-06-12T06:28:58.984Z"},{"id":"4f5e6bad-70d2-4642-b7e3-9469afedbba4","status":{"state":"active"},"updatedAt":"2023-06-19T04:45:18.103Z","comment":"silenced as requested by Aditya garg","createdBy":"sai teja","endsAt":"2023-11-06T04:41:47.565Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-datascience-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-CPU-Crossed-80%"},{"isRegex":false,"name":"label_bu","value":"datascience"},{"isRegex":true,"name":"label_service","value":".*online-feature-store-consumer.*"}],"startsAt":"2023-06-19T04:45:18.103Z"},{"id":"f6d42fe7-4be7-45e6-9977-d69967642c70","status":{"state":"active"},"updatedAt":"2023-07-05T09:32:56.624Z","comment":"silenced as requested by Aditya garg","createdBy":"sai teja","endsAt":"2023-11-22T09:31:15.517Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-datascience-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-CPU-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-datascience-cluster"},{"isRegex":false,"name":"label_bu","value":"datascience"},{"isRegex":false,"name":"label_env","value":"prod"},{"isRegex":false,"name":"label_service","value":"online-feature-store-read-v3"},{"isRegex":false,"name":"label_team","value":"ml-platform"}],"startsAt":"2023-07-05T09:32:56.624Z"},{"id":"05113e43-2e7a-4add-be2a-276bbebb8ece","status":{"state":"active"},"updatedAt":"2023-08-17T03:50:13.849Z","comment":"Silenced as requested by Aditya garg","createdBy":"sai teja","endsAt":"2023-11-25T04:00:59.478Z","matchers":[{"isRegex":false,"name":"alertname","value":"Pod-CPU-Crossed-80%"},{"isRegex":false,"name":"namespace","value":"prd-online-feature-store-read-v4"},{"isRegex":false,"name":"label_service","value":"online-feature-store-read-v4"},{"isRegex":false,"name":"alertgroup","value":"EKS-datascience-Pod-Alerts"},{"isRegex":false,"name":"label_team","value":"ml-platform"}],"startsAt":"2023-08-17T03:50:13.849Z"},{"id":"67403c43-2e14-4374-92e5-c8f4cedca101","status":{"state":"active"},"updatedAt":"2023-01-30T16:51:05.670Z","comment":"as per dev request ","createdBy":"muhilan","endsAt":"2023-11-26T16:50:38.914Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-pqfvv"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T16:51:05.670Z"},{"id":"b6395f53-4de2-4acd-a564-c520db7cb09d","status":{"state":"active"},"updatedAt":"2023-07-12T09:08:53.149Z","comment":"silenced as requested by Ruthwik","createdBy":"sai teja","endsAt":"2023-11-29T09:08:29.287Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"Elastic-Search-Alerts"},{"isRegex":false,"name":"alertname","value":"Nodes"},{"isRegex":false,"name":"client_id","value":"847438129436"},{"isRegex":false,"name":"domain_name","value":"platform-p-qwest"},{"isRegex":false,"name":"job","value":"aws_es"},{"isRegex":false,"name":"resource","value":"AWS Elastic Search"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-07-12T09:08:53.149Z"},{"id":"eb0404a6-210e-4b23-bb85-bdf29f5fc712","status":{"state":"active"},"updatedAt":"2023-06-19T11:27:45.102Z","comment":"silenced as requested by Milind Lalwani","createdBy":"sai teja","endsAt":"2023-12-11T11:27:05.275Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-dataengg-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prod"},{"isRegex":false,"name":"label_service","value":"ab-service-read"}],"startsAt":"2023-06-19T11:27:45.102Z"},{"id":"fb5995e8-0e35-4b05-9947-c8ee702beb08","status":{"state":"active"},"updatedAt":"2021-08-03T14:39:42.230Z","comment":"sound","createdBy":"sound ","endsAt":"2024-01-20T14:37:35.701Z","matchers":[{"isRegex":false,"name":"alertname","value":"ES_Search_Latency_80ms"},{"isRegex":false,"name":"client_id","value":"847438129436"},{"isRegex":false,"name":"domain_name","value":"platform-p-qwest"},{"isRegex":false,"name":"job","value":"aws_es"},{"isRegex":false,"name":"resource","value":"AWS Elastic Search"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2021-08-03T14:39:42.230Z"},{"id":"fa218e02-dc34-4b36-b1e3-8bd1b98dfc4c","status":{"state":"active"},"updatedAt":"2023-05-20T13:38:33.432Z","comment":"s","createdBy":"sound","endsAt":"2024-01-30T10:00:09.953Z","matchers":[{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"coordinator-54ffb48f4-b9g68"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-05-20T13:38:33.432Z"},{"id":"caff01bd-f9f4-434d-8753-f40861cb6af5","status":{"state":"active"},"updatedAt":"2023-05-20T13:38:17.386Z","comment":"s","createdBy":"sound","endsAt":"2024-01-30T10:01:10.597Z","matchers":[{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-22kss"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-05-20T13:38:17.386Z"},{"id":"5def5b5f-26a2-4e39-a4d8-88e888560006","status":{"state":"active"},"updatedAt":"2023-01-30T10:01:51.184Z","comment":"s","createdBy":"sound","endsAt":"2024-01-30T10:01:42.252Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-22rg5"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T10:01:51.184Z"},{"id":"b550104b-908d-4ab8-8cbc-ca1198c85924","status":{"state":"active"},"updatedAt":"2023-01-30T10:02:55.125Z","comment":"s","createdBy":"sound","endsAt":"2024-01-30T10:02:47.080Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-x5twc"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T10:02:55.125Z"},{"id":"ed3fb908-6e6d-433d-8843-daf12affde64","status":{"state":"active"},"updatedAt":"2023-01-30T10:04:08.785Z","comment":"s","createdBy":"sound","endsAt":"2024-01-30T10:04:02.345Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-CPU-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-x5twc"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T10:04:08.785Z"},{"id":"d29e5b0a-a6ec-4f17-b21b-21445afb4161","status":{"state":"active"},"updatedAt":"2023-01-30T10:16:25.364Z","comment":"s","createdBy":"sound","endsAt":"2024-01-30T10:16:18.791Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-CPU-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-vdmc8"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T10:16:25.364Z"},{"id":"f8175670-1333-4449-b613-cfff4b610ff5","status":{"state":"active"},"updatedAt":"2023-01-30T10:16:55.795Z","comment":"s","createdBy":"sound","endsAt":"2024-01-30T10:16:48.615Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-vdmc8"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T10:16:55.795Z"},{"id":"24bfdca4-17d1-47fc-b45c-41b0659c3660","status":{"state":"active"},"updatedAt":"2023-01-30T10:49:21.803Z","comment":"as per req","createdBy":"nandhiini","endsAt":"2024-01-30T10:48:47.063Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-2rvhl"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T10:49:21.803Z"},{"id":"c1a5b269-10c4-43ed-9eca-564b42ce13fd","status":{"state":"active"},"updatedAt":"2023-01-30T12:03:01.397Z","comment":"s","createdBy":"sound","endsAt":"2024-01-30T12:02:45.532Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-99hcs"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T12:03:01.397Z"},{"id":"24405590-800f-451a-b1d2-fb27801e7d36","status":{"state":"active"},"updatedAt":"2023-01-30T12:03:23.572Z","comment":"s","createdBy":"sound","endsAt":"2024-01-30T12:03:16.755Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-c8jsc"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T12:03:23.572Z"},{"id":"34b9de0c-df63-4424-8bb5-7f21af3d1da8","status":{"state":"active"},"updatedAt":"2023-01-30T12:04:14.772Z","comment":"s","createdBy":"sound","endsAt":"2024-01-30T12:04:08.423Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-c8nnc"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T12:04:14.772Z"},{"id":"ba900961-1e1e-47ae-b820-7d3ff9e2f403","status":{"state":"active"},"updatedAt":"2023-01-30T12:06:10.402Z","comment":"s","createdBy":"sound","endsAt":"2024-01-30T12:06:03.745Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-CPU-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-gclwl"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T12:06:10.402Z"},{"id":"c3d3869a-9a18-40d7-9c7a-ecede5ba43fd","status":{"state":"active"},"updatedAt":"2023-01-30T12:08:38.542Z","comment":"s","createdBy":"sound","endsAt":"2024-01-30T12:08:30.376Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-z44dx"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T12:08:38.542Z"},{"id":"5833d00a-9de6-4c6a-b9e9-d432ed3bd1ec","status":{"state":"active"},"updatedAt":"2023-01-30T12:09:37.871Z","comment":"s","createdBy":"sound","endsAt":"2024-01-30T12:09:30.580Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-CPU-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-45gzk"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T12:09:37.871Z"},{"id":"b505c467-5f76-4792-a21e-2be2c2b20138","status":{"state":"active"},"updatedAt":"2023-01-30T12:10:17.001Z","comment":"s","createdBy":"sound","endsAt":"2024-01-30T12:10:10.698Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-czjk8"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T12:10:17.001Z"},{"id":"7c7edb04-4b5d-42c2-987d-7345a9dd992d","status":{"state":"active"},"updatedAt":"2023-01-30T12:10:52.216Z","comment":"s","createdBy":"sound","endsAt":"2024-01-30T12:10:45.916Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-d7xpb"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T12:10:52.216Z"},{"id":"9c906eb3-ef93-4a2f-afbe-34cd6dc0e62d","status":{"state":"active"},"updatedAt":"2023-01-30T12:11:20.556Z","comment":"s","createdBy":"sound","endsAt":"2024-01-30T12:11:13.232Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-dmddp"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T12:11:20.556Z"},{"id":"dd47c73d-ad0b-4b00-91f0-dc5920cdc33b","status":{"state":"active"},"updatedAt":"2023-01-30T12:11:46.977Z","comment":"s","createdBy":"sound","endsAt":"2024-01-30T12:11:41.008Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-drslj"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T12:11:46.977Z"},{"id":"9cc0b010-05ef-4695-9bb8-9d1a3fc3ff91","status":{"state":"active"},"updatedAt":"2023-01-30T12:13:02.162Z","comment":"f","createdBy":"sound","endsAt":"2024-01-30T12:12:55.564Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-f92v4"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T12:13:02.162Z"},{"id":"c0dc104c-7aa7-47ed-86a9-cf77624b32c4","status":{"state":"active"},"updatedAt":"2023-01-30T12:14:35.992Z","comment":"s","createdBy":"sound","endsAt":"2024-01-30T12:14:30.282Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-g6w6v"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T12:14:35.992Z"},{"id":"381b886f-a42b-4f70-aecf-411af1a3c89c","status":{"state":"active"},"updatedAt":"2023-01-30T12:15:04.806Z","comment":"s","createdBy":"sound","endsAt":"2024-01-30T12:14:59.616Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-gclwl"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T12:15:04.806Z"},{"id":"f2d2661b-702d-4fec-aa1c-e1ceabd6fca0","status":{"state":"active"},"updatedAt":"2023-01-30T12:15:20.357Z","comment":"d","createdBy":"sound","endsAt":"2024-01-30T12:15:14.771Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-ghxs5"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T12:15:20.357Z"},{"id":"3c7ae941-dc1f-4e18-b849-2d623d6f3ca3","status":{"state":"active"},"updatedAt":"2023-01-30T12:22:51.712Z","comment":"s","createdBy":"sound","endsAt":"2024-01-30T12:22:44.510Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-h629q"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T12:22:51.712Z"},{"id":"291f360b-2197-47f6-b21b-8e6d4336e742","status":{"state":"active"},"updatedAt":"2023-01-30T12:23:22.254Z","comment":"s","createdBy":"sound","endsAt":"2024-01-30T12:23:15.757Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-2d4jd"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T12:23:22.254Z"},{"id":"46f5ea1d-2420-4b72-8098-480ec4062519","status":{"state":"active"},"updatedAt":"2023-01-30T12:28:09.926Z","comment":"s","createdBy":"sound","endsAt":"2024-01-30T12:28:02.906Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-5m8s7"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T12:28:09.926Z"},{"id":"0d9dfff5-b9f8-4da8-86a5-1a9483ad839d","status":{"state":"active"},"updatedAt":"2023-01-30T12:39:44.967Z","comment":"d","createdBy":"sound","endsAt":"2024-01-30T12:39:39.429Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-CPU-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-4j6mp"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T12:39:44.967Z"},{"id":"c5e97bff-fdec-4af5-a5a6-1e094cd136a7","status":{"state":"active"},"updatedAt":"2023-01-30T12:40:02.437Z","comment":"s","createdBy":"sound","endsAt":"2024-01-30T12:39:56.170Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-CPU-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-2d4jd"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T12:40:02.437Z"},{"id":"fba51ff6-8372-434a-83e5-22fdf205572a","status":{"state":"active"},"updatedAt":"2023-01-30T12:40:36.417Z","comment":"s","createdBy":"sound","endsAt":"2024-01-30T12:40:30.073Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-CPU-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-5786p"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T12:40:36.417Z"},{"id":"bb5889b4-e27a-4e2c-9ccb-a658c29213a8","status":{"state":"active"},"updatedAt":"2023-01-30T13:09:47.012Z","comment":"silenced","createdBy":"sound","endsAt":"2024-01-30T12:56:10.954Z","matchers":[{"isRegex":false,"name":"alertname","value":"Pod-CPU-Crossed-80%"},{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"}],"startsAt":"2023-01-30T13:09:47.012Z"},{"id":"feb2c03b-d37e-407a-9e91-8b8ac5918d80","status":{"state":"active"},"updatedAt":"2023-01-30T17:00:46.993Z","comment":"as per dev request","createdBy":"muhilan","endsAt":"2024-03-05T16:54:03.007Z","matchers":[{"isRegex":false,"name":"alertname","value":"Pod-CPU-Crossed-80%"},{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"severity","value":"critical"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-44k8k"}],"startsAt":"2023-01-30T17:00:46.993Z"},{"id":"9e422509-bfab-4ba4-8be1-3eeb6a206711","status":{"state":"active"},"updatedAt":"2021-08-07T15:49:25.917Z","comment":"as per ramiz confirmation","createdBy":"veera","endsAt":"2024-05-02T15:48:35.233Z","matchers":[{"isRegex":false,"name":"alertname","value":"CPU-High-65%"},{"isRegex":false,"name":"instance","value":"i-033d2c113c6570136"},{"isRegex":false,"name":"job","value":"hadoop"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2021-08-07T15:49:25.917Z"},{"id":"58516156-57a6-4318-904d-1ae26435af41","status":{"state":"active"},"updatedAt":"2021-08-08T10:10:44.477Z","comment":"as per ramiz confirmation","createdBy":"veera","endsAt":"2024-05-03T10:10:22.779Z","matchers":[{"isRegex":false,"name":"alertname","value":"OutOfMemory"},{"isRegex":false,"name":"cluster_id","value":"j-P1RFRSCBQOW9"},{"isRegex":false,"name":"instance","value":"i-00a380329930f3794"},{"isRegex":false,"name":"job","value":"hadoop"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2021-08-08T10:10:44.477Z"},{"id":"74f44b3b-1188-4346-a133-a3c4d8d28ba3","status":{"state":"active"},"updatedAt":"2021-08-08T10:11:02.619Z","comment":"as per ramiz updates","createdBy":"veera","endsAt":"2024-05-03T10:10:49.783Z","matchers":[{"isRegex":false,"name":"alertname","value":"CPU-High-80%"},{"isRegex":false,"name":"instance","value":"i-00a380329930f3794"},{"isRegex":false,"name":"job","value":"hadoop"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2021-08-08T10:11:02.619Z"},{"id":"f8d7b375-71fd-423b-a966-d3464879d544","status":{"state":"active"},"updatedAt":"2021-09-07T08:07:08.597Z","comment":"as per ramiz request","createdBy":"veera","endsAt":"2024-05-03T13:11:59.455Z","matchers":[{"isRegex":false,"name":"alertname","value":"CPU-High-80%"},{"isRegex":false,"name":"job","value":"node_exporter"},{"isRegex":false,"name":"name","value":"dataplatform-p-Prism-ETL"},{"isRegex":false,"name":"severity","value":"critical"},{"isRegex":false,"name":"status","value":"running"},{"isRegex":false,"name":"team","value":"data-platform"}],"startsAt":"2021-09-07T08:07:08.597Z"},{"id":"d26dde76-459c-471f-a3dd-7d42e22a53cd","status":{"state":"active"},"updatedAt":"2023-05-20T14:08:30.617Z","comment":"Not useful","createdBy":"Paras","endsAt":"2024-05-18T14:06:02.284Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-demand-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Not-in-Ready-State"},{"isRegex":false,"name":"cluster","value":"p-demand-cluster"},{"isRegex":false,"name":"job","value":"kube-state-metrics-p-demand-cluster"},{"isRegex":false,"name":"label_bu","value":"demand"},{"isRegex":false,"name":"label_env","value":"prod"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"feed-aggregator"},{"isRegex":false,"name":"label_team","value":"discovery-platform"},{"isRegex":false,"name":"namespace","value":"prd-feed-aggregator"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-05-20T14:08:30.617Z"},{"id":"7c983a95-4612-4588-b2bd-d4953d7ef6a8","status":{"state":"active"},"updatedAt":"2023-05-20T14:09:11.708Z","comment":"not useful","createdBy":"Paras","endsAt":"2024-05-18T14:08:47.308Z","matchers":[{"isRegex":false,"name":"alertname","value":"Pod-Not-in-Ready-State"},{"isRegex":false,"name":"cluster","value":"p-central-cluster"},{"isRegex":false,"name":"instance","value":"kube-state-metrics.kube-system.svc.cluster.local:8080"},{"isRegex":false,"name":"job","value":"kube-state-metrics-p-central-cluster"},{"isRegex":false,"name":"label_bu","value":"central"},{"isRegex":false,"name":"label_env","value":"prod"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"edge-proxy-secondary"},{"isRegex":false,"name":"label_team","value":"shared"},{"isRegex":false,"name":"namespace","value":"prd-edge-proxy-secondary"},{"isRegex":false,"name":"phase","value":"Failed"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-05-20T14:09:11.708Z"},{"id":"e66565a5-e025-466d-87f7-684912d0cf81","status":{"state":"active"},"updatedAt":"2023-05-20T14:10:25.713Z","comment":"not useful","createdBy":"Paras","endsAt":"2024-05-18T14:09:27.083Z","matchers":[{"isRegex":false,"name":"alertname","value":"Pod-Not-in-Ready-State"},{"isRegex":false,"name":"cluster","value":"p-central-cluster"},{"isRegex":false,"name":"instance","value":"kube-state-metrics.kube-system.svc.cluster.local:8080"},{"isRegex":false,"name":"job","value":"kube-state-metrics-p-central-cluster"},{"isRegex":false,"name":"label_bu","value":"central"},{"isRegex":false,"name":"label_env","value":"prod"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"edge-proxy-secondary"},{"isRegex":false,"name":"label_team","value":"shared"},{"isRegex":false,"name":"namespace","value":"prd-edge-proxy-secondary"},{"isRegex":false,"name":"phase","value":"Failed"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-05-20T14:10:25.713Z"},{"id":"bae096c0-dbda-4e4b-8776-73d95a022a32","status":{"state":"active"},"updatedAt":"2023-05-20T14:12:48.730Z","comment":"not useful","createdBy":"Paras","endsAt":"2024-05-18T14:12:33.672Z","matchers":[{"isRegex":false,"name":"alertname","value":"Pod-Not-in-Ready-State"},{"isRegex":false,"name":"cluster","value":"p-central-cluster"},{"isRegex":false,"name":"instance","value":"kube-state-metrics.kube-system.svc.cluster.local:8080"},{"isRegex":false,"name":"job","value":"kube-state-metrics-p-central-cluster"},{"isRegex":false,"name":"label_bu","value":"central"},{"isRegex":false,"name":"label_env","value":"prod"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"edge-proxy"},{"isRegex":false,"name":"label_team","value":"shared"},{"isRegex":false,"name":"namespace","value":"prd-edge-proxy"},{"isRegex":false,"name":"phase","value":"Failed"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-05-20T14:12:48.730Z"},{"id":"fa67846c-ec33-4892-b6a1-e8769dd7e27c","status":{"state":"active"},"updatedAt":"2023-05-24T09:12:00.415Z","comment":"not required","createdBy":"sai teja","endsAt":"2024-05-22T09:11:32.824Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-demand-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-demand-cluster"},{"isRegex":false,"name":"label_bu","value":"demand"},{"isRegex":false,"name":"label_env","value":"prod"},{"isRegex":false,"name":"label_priority","value":"p1"},{"isRegex":false,"name":"label_service","value":"feed-aggregator-search"},{"isRegex":false,"name":"label_team","value":"discovery-platform"},{"isRegex":false,"name":"namespace","value":"prd-feed-aggregator-search"},{"isRegex":false,"name":"pod","value":"prd-feed-aggregator-search-primary-5d65db9747-hqxkq"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-05-24T09:12:00.415Z"},{"id":"1bef22dd-e5b0-4e01-a364-d2955a29bfc4","status":{"state":"active"},"updatedAt":"2023-05-23T07:31:55.807Z","comment":"silencing for a year","createdBy":"ankur malhotra","endsAt":"2024-05-23T07:30:29.558Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"Elastic-Search-Alerts"},{"isRegex":false,"name":"alertname","value":"FreeStorageSpace-100G"},{"isRegex":false,"name":"client_id","value":"847438129436"},{"isRegex":false,"name":"domain_name","value":"platform-p-qwest"},{"isRegex":false,"name":"job","value":"aws_es"},{"isRegex":false,"name":"resource","value":"AWS Elastic Search"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-05-23T07:31:55.807Z"},{"id":"4b06d058-56f9-4f2e-9b7a-84d4c38c2985","status":{"state":"active"},"updatedAt":"2021-10-27T03:44:46.993Z","comment":".","createdBy":"veera","endsAt":"2024-07-22T03:44:36.435Z","matchers":[{"isRegex":false,"name":"alertname","value":"ES_Indexing_Rate_400K"},{"isRegex":false,"name":"client_id","value":"847438129436"},{"isRegex":false,"name":"domain_name","value":"platform-p-graylog"},{"isRegex":false,"name":"job","value":"aws_es"},{"isRegex":false,"name":"node_id","value":"3-gcueANTye5F4QFXRj5OA"},{"isRegex":false,"name":"resource","value":"AWS Elastic Search"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2021-10-27T03:44:46.993Z"},{"id":"8178f7ea-8897-48de-9d19-918a1411f33b","status":{"state":"active"},"updatedAt":"2021-10-27T03:44:59.068Z","comment":".","createdBy":"veera","endsAt":"2024-07-22T03:44:53.314Z","matchers":[{"isRegex":false,"name":"alertname","value":"ES_4xx_20+"},{"isRegex":false,"name":"client_id","value":"847438129436"},{"isRegex":false,"name":"domain_name","value":"platform-p-graylog"},{"isRegex":false,"name":"job","value":"aws_es"},{"isRegex":false,"name":"resource","value":"AWS Elastic Search"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2021-10-27T03:44:59.068Z"},{"id":"4dcfc909-e2af-4003-8375-71ff3cac6c7a","status":{"state":"active"},"updatedAt":"2021-10-27T03:45:13.026Z","comment":".","createdBy":"veera","endsAt":"2024-07-22T03:45:05.568Z","matchers":[{"isRegex":false,"name":"alertname","value":"ES_Indexing_Rate_400K"},{"isRegex":false,"name":"client_id","value":"847438129436"},{"isRegex":false,"name":"domain_name","value":"platform-p-graylog"},{"isRegex":false,"name":"job","value":"aws_es"},{"isRegex":false,"name":"node_id","value":"b4owLQVwR6uCPnxqltwagg"},{"isRegex":false,"name":"resource","value":"AWS Elastic Search"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2021-10-27T03:45:13.026Z"},{"id":"4192100d-d5b2-4f7b-a80d-3abaefc3c686","status":{"state":"active"},"updatedAt":"2021-10-27T03:46:18.960Z","comment":"as per request","createdBy":"veera","endsAt":"2024-07-22T03:46:06.485Z","matchers":[{"isRegex":false,"name":"alertname","value":"ES_Indexing_Rate_400K"},{"isRegex":false,"name":"client_id","value":"847438129436"},{"isRegex":false,"name":"domain_name","value":"platform-p-graylog"},{"isRegex":false,"name":"job","value":"aws_es"},{"isRegex":false,"name":"node_id","value":"VCbu--2BQLiI4XAgA-LBuA"},{"isRegex":false,"name":"resource","value":"AWS Elastic Search"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2021-10-27T03:46:18.960Z"},{"id":"03842e64-ee91-45d0-bc0d-fb0e1e6022bd","status":{"state":"active"},"updatedAt":"2021-10-27T03:47:21.393Z","comment":"as per request","createdBy":"veera","endsAt":"2024-07-22T03:47:09.882Z","matchers":[{"isRegex":false,"name":"alertname","value":"ES_Search_Latency_120ms"},{"isRegex":false,"name":"client_id","value":"847438129436"},{"isRegex":false,"name":"domain_name","value":"platform-p-graylog"},{"isRegex":false,"name":"job","value":"aws_es"},{"isRegex":false,"name":"node_id","value":"iB4LfL-aSdia6RlTKBe4_A"},{"isRegex":false,"name":"resource","value":"AWS Elastic Search"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2021-10-27T03:47:21.393Z"},{"id":"18e293b0-e6ef-42fe-ac99-6d6c9d00edbe","status":{"state":"active"},"updatedAt":"2021-10-27T06:39:39.216Z","comment":"as per request","createdBy":"veera","endsAt":"2024-07-22T06:39:27.088Z","matchers":[{"isRegex":false,"name":"alertname","value":"ES_Search_Latency_120ms"},{"isRegex":false,"name":"client_id","value":"847438129436"},{"isRegex":false,"name":"domain_name","value":"platform-p-graylog"},{"isRegex":false,"name":"job","value":"aws_es"},{"isRegex":false,"name":"node_id","value":"jYLjTGkfQo6Mx7TQ4hp-9g"},{"isRegex":false,"name":"resource","value":"AWS Elastic Search"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2021-10-27T06:39:39.216Z"},{"id":"ca819c28-2287-44d0-b87f-d97f6b379e35","status":{"state":"active"},"updatedAt":"2023-07-29T09:28:20.557Z","comment":"sre","createdBy":"sre","endsAt":"2024-07-28T09:27:53.906Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"VM-Scrape-Alerts"},{"isRegex":false,"name":"alertname","value":"yet-another-cloudwatch-exporter-issue"},{"isRegex":false,"name":"bu","value":"infra"},{"isRegex":false,"name":"env","value":"prd"},{"isRegex":false,"name":"instance","value":"prd-infra-yace-ivs:80"},{"isRegex":false,"name":"job","value":"prd-infra-yace"},{"isRegex":false,"name":"priority","value":"p0"},{"isRegex":false,"name":"service","value":"scrape"},{"isRegex":false,"name":"severity","value":"critical"},{"isRegex":false,"name":"team","value":"sre"}],"startsAt":"2023-07-29T09:28:20.557Z"},{"id":"e4861af0-1fce-4b0f-8f7c-2567224790da","status":{"state":"active"},"updatedAt":"2023-08-01T09:23:09.468Z","comment":"sre","createdBy":"sre","endsAt":"2024-07-31T09:22:55.167Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"VM-Scrape-Alerts"},{"isRegex":false,"name":"alertname","value":"yet-another-cloudwatch-exporter-issue"},{"isRegex":false,"name":"bu","value":"infra"},{"isRegex":false,"name":"env","value":"prd"},{"isRegex":false,"name":"instance","value":"prd-infra-yace-elasticache:80"},{"isRegex":false,"name":"job","value":"prd-infra-yace"},{"isRegex":false,"name":"priority","value":"p0"},{"isRegex":false,"name":"service","value":"scrape"},{"isRegex":false,"name":"severity","value":"critical"},{"isRegex":false,"name":"team","value":"sre"}],"startsAt":"2023-08-01T09:23:09.468Z"},{"id":"f9da9a56-7733-4589-bcae-67f0149eb51e","status":{"state":"active"},"updatedAt":"2021-11-10T16:58:48.046Z","comment":"as per request","createdBy":"veera","endsAt":"2024-08-05T16:58:33.605Z","matchers":[{"isRegex":false,"name":"alertname","value":"Kafka_ReplicationBytes_plus_bytes_in_and_out_200MB+"},{"isRegex":false,"name":"broker_id","value":"4"},{"isRegex":false,"name":"cluster_name","value":"platform-p-graylog"},{"isRegex":false,"name":"job","value":"aws_kafka"},{"isRegex":false,"name":"resource","value":"AWS Kafka"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2021-11-10T16:58:48.046Z"},{"id":"46f6b48e-0fcb-4003-8d41-3932ff152bf5","status":{"state":"active"},"updatedAt":"2022-01-03T06:32:23.810Z","comment":"as per mani ignore","createdBy":"veera","endsAt":"2024-09-28T06:31:59.064Z","matchers":[{"isRegex":false,"name":"alertname","value":"UnhealthyHost"},{"isRegex":false,"name":"job","value":"aws_applicationelb"},{"isRegex":false,"name":"load_balancer","value":"app/bac-p-invoice-internal-alb/454ebc13cc96b16a"},{"isRegex":false,"name":"resource","value":"AWS Target Group"},{"isRegex":false,"name":"severity","value":"critical"},{"isRegex":false,"name":"target_group","value":"targetgroup/bac-p-graylog/98989da7c3e2cfb5"}],"startsAt":"2022-01-03T06:32:23.810Z"},{"id":"31d53e54-7801-48bc-82e9-e7f6cb792e5e","status":{"state":"active"},"updatedAt":"2022-01-03T07:22:45.413Z","comment":"as per ","createdBy":"veera","endsAt":"2024-09-28T07:22:37.599Z","matchers":[{"isRegex":false,"name":"alertname","value":"UnhealthyHost"},{"isRegex":false,"name":"job","value":"aws_applicationelb"},{"isRegex":false,"name":"load_balancer","value":"app/devops-int-alb/5a2b53a26061cca0"},{"isRegex":false,"name":"resource","value":"AWS Target Group"},{"isRegex":false,"name":"severity","value":"critical"},{"isRegex":false,"name":"target_group","value":"targetgroup/platform-p-grafana-old-tg/7729005a6512ef7d"}],"startsAt":"2022-01-03T07:22:45.413Z"},{"id":"b60a2108-b309-4dca-8a8f-2e1eaaab5fc5","status":{"state":"active"},"updatedAt":"2022-12-01T12:00:14.287Z","comment":"migrated this hbase","createdBy":"Muhilan","endsAt":"2025-08-27T11:59:47.117Z","matchers":[{"isRegex":false,"name":"Environment","value":"prod"},{"isRegex":false,"name":"alertgroup","value":"EC2-Alerts"},{"isRegex":false,"name":"alertname","value":"OutOfDiskSpace"},{"isRegex":false,"name":"alerts","value":"fulfilment-alerts"},{"isRegex":false,"name":"app","value":"hbase"},{"isRegex":false,"name":"device","value":"/dev/nvme1n1p1"},{"isRegex":false,"name":"fstype","value":"xfs"},{"isRegex":false,"name":"instance","value":"172.31.23.59:9100"},{"isRegex":false,"name":"job","value":"node_exporter"},{"isRegex":false,"name":"mountpoint","value":"/emr"},{"isRegex":false,"name":"name","value":"bac-p-hbase-communicator"},{"isRegex":false,"name":"priority","value":"p1"},{"isRegex":false,"name":"private_ip","value":"172.31.23.59"},{"isRegex":false,"name":"public_ip","value":"13.212.144.152"},{"isRegex":false,"name":"severity","value":"critical"},{"isRegex":false,"name":"status","value":"running"},{"isRegex":false,"name":"team","value":"backend"}],"startsAt":"2022-12-01T12:00:14.287Z"},{"id":"55e9fb9f-f44a-470c-81d3-d4db43bd2567","status":{"state":"active"},"updatedAt":"2022-12-01T12:00:06.977Z","comment":"migrated this hbase","createdBy":"Muhilan","endsAt":"2025-08-27T11:59:55.590Z","matchers":[{"isRegex":false,"name":"Environment","value":"prod"},{"isRegex":false,"name":"alertgroup","value":"EC2-Alerts"},{"isRegex":false,"name":"alertname","value":"OutOfDiskSpace"},{"isRegex":false,"name":"alerts","value":"fulfilment-alerts"},{"isRegex":false,"name":"app","value":"hbase"},{"isRegex":false,"name":"device","value":"/dev/nvme1n1p1"},{"isRegex":false,"name":"fstype","value":"xfs"},{"isRegex":false,"name":"instance","value":"172.31.18.20:9100"},{"isRegex":false,"name":"job","value":"node_exporter"},{"isRegex":false,"name":"mountpoint","value":"/emr"},{"isRegex":false,"name":"name","value":"post-order-communication-hbase"},{"isRegex":false,"name":"priority","value":"p2"},{"isRegex":false,"name":"private_ip","value":"172.31.18.20"},{"isRegex":false,"name":"public_ip","value":"13.250.114.230"},{"isRegex":false,"name":"severity","value":"critical"},{"isRegex":false,"name":"status","value":"running"},{"isRegex":false,"name":"team","value":"backend"}],"startsAt":"2022-12-01T12:00:06.977Z"},{"id":"82ab7aac-63ad-4fe4-9905-b917ebffb08e","status":{"state":"active"},"updatedAt":"2023-01-03T06:21:37.905Z","comment":"as per dev request !https://meesho.slack.com/archives/C02BFAH2G93/p1672726883009969?thread_ts=1672726649.279399\u0026cid=C02BFAH2G93","createdBy":"muhilan","endsAt":"2025-09-29T06:21:10.775Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"Process_Alert"},{"isRegex":false,"name":"alertname","value":"delhivery-shipment-queue-processor"},{"isRegex":false,"name":"app","value":"manifest-worker"},{"isRegex":false,"name":"host","value":"bac-p-manifest-worker-01b-cicd"},{"isRegex":false,"name":"instance","value":"172.31.8.167:9273"},{"isRegex":false,"name":"job","value":"telegraf-exporter"},{"isRegex":false,"name":"name","value":"bac-p-worker-manifest-01b"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-03T06:21:37.905Z"},{"id":"5138ea7f-d9db-40ab-9988-3f21028d12fe","status":{"state":"active"},"updatedAt":"2023-01-30T13:25:26.588Z","comment":"as per dev request","createdBy":"muhilan","endsAt":"2025-10-26T13:24:59.902Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_service","value":"eks-mb-sec-backend2"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-mb-sec-backend2"},{"isRegex":false,"name":"pod","value":"worker-d69bf6b6f-k66p2"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T13:25:26.588Z"},{"id":"7dc586c8-7309-417a-98b9-9cbce2990d53","status":{"state":"active"},"updatedAt":"2023-01-30T13:25:37.443Z","comment":"ad per dev request","createdBy":"muhilan","endsAt":"2025-10-26T13:25:01.998Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"coordinator-54ffb48f4-lh2d7"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T13:25:37.443Z"},{"id":"3ed71590-3cf4-4ac4-932b-088c1e53ae5e","status":{"state":"active"},"updatedAt":"2023-01-30T13:54:02.875Z","comment":"s","createdBy":"sound","endsAt":"2025-10-26T13:53:56.695Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-hkhnl"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T13:54:02.875Z"},{"id":"4bc3222a-8456-41c1-845a-a6a3ced15f81","status":{"state":"active"},"updatedAt":"2023-01-30T14:06:51.016Z","comment":"s","createdBy":"sound","endsAt":"2025-10-26T14:06:46.287Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-j6229"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T14:06:51.016Z"},{"id":"80f4f238-85f9-4c2b-8837-ffa2d9828106","status":{"state":"active"},"updatedAt":"2023-01-30T14:08:03.181Z","comment":"x","createdBy":"sound","endsAt":"2025-10-26T14:07:47.275Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-j84fg"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T14:08:03.181Z"},{"id":"3bf99b1e-7bdc-4347-8f9e-c3732268a964","status":{"state":"active"},"updatedAt":"2023-01-30T14:08:09.825Z","comment":"d","createdBy":"sound","endsAt":"2025-10-26T14:07:50.116Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-jclpz"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T14:08:09.825Z"},{"id":"5b0cd3fb-d12d-4724-ae81-cb323e6e2eec","status":{"state":"active"},"updatedAt":"2023-01-30T14:08:16.446Z","comment":"d","createdBy":"sound","endsAt":"2025-10-26T14:07:53.119Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-k5kng"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T14:08:16.446Z"},{"id":"a62c9771-cd18-4210-a03f-e09eaa22b4da","status":{"state":"active"},"updatedAt":"2023-01-30T14:08:22.096Z","comment":"s","createdBy":"sound","endsAt":"2025-10-26T14:07:55.247Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-knm6r"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T14:08:22.096Z"},{"id":"2378d662-3860-4039-9f46-fabd01906699","status":{"state":"active"},"updatedAt":"2023-01-30T14:09:27.614Z","comment":"ds","createdBy":"ds","endsAt":"2025-10-26T14:09:20.689Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-CPU-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-demand-cluster"},{"isRegex":false,"name":"label_bu","value":"demand"},{"isRegex":false,"name":"label_env","value":"prod"},{"isRegex":false,"name":"label_priority","value":"p1"},{"isRegex":false,"name":"label_service","value":"merch-merchandising-consumer"},{"isRegex":false,"name":"label_team","value":"product-feed"},{"isRegex":false,"name":"namespace","value":"prd-merch-merchandising-consumer"},{"isRegex":false,"name":"pod","value":"prd-merch-merchandising-consumer-64cc7cbc75-4v6k9"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T14:09:27.614Z"},{"id":"77b915b3-33a7-4480-93fe-4b817e0f350a","status":{"state":"active"},"updatedAt":"2023-01-30T14:09:43.316Z","comment":"as per ds","createdBy":"ds","endsAt":"2025-10-26T14:09:36.073Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-CPU-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-demand-cluster"},{"isRegex":false,"name":"label_bu","value":"demand"},{"isRegex":false,"name":"label_env","value":"prod"},{"isRegex":false,"name":"label_priority","value":"p1"},{"isRegex":false,"name":"label_service","value":"merch-merchandising-consumer"},{"isRegex":false,"name":"label_team","value":"product-feed"},{"isRegex":false,"name":"namespace","value":"prd-merch-merchandising-consumer"},{"isRegex":false,"name":"pod","value":"prd-merch-merchandising-consumer-64cc7cbc75-56z6t"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T14:09:43.316Z"},{"id":"9fd85cbe-9079-4d90-8bd2-e2984761f6ff","status":{"state":"active"},"updatedAt":"2023-01-30T14:09:56.470Z","comment":"s","createdBy":"sound","endsAt":"2025-10-26T14:09:46.219Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-lhtmz"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T14:09:56.470Z"},{"id":"174c7d2b-417c-43db-aed4-18bcfd33ffb2","status":{"state":"active"},"updatedAt":"2023-01-30T14:09:59.533Z","comment":"das per ds","createdBy":"ds","endsAt":"2025-10-26T14:09:48.098Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-CPU-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-demand-cluster"},{"isRegex":false,"name":"label_bu","value":"demand"},{"isRegex":false,"name":"label_env","value":"prod"},{"isRegex":false,"name":"label_priority","value":"p1"},{"isRegex":false,"name":"label_service","value":"merch-merchandising-consumer"},{"isRegex":false,"name":"label_team","value":"product-feed"},{"isRegex":false,"name":"namespace","value":"prd-merch-merchandising-consumer"},{"isRegex":false,"name":"pod","value":"prd-merch-merchandising-consumer-64cc7cbc75-6nj4k"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T14:09:59.533Z"},{"id":"65785124-0239-409e-8c4b-b146726202bc","status":{"state":"active"},"updatedAt":"2023-01-30T14:10:19.351Z","comment":"s","createdBy":"sound","endsAt":"2025-10-26T14:10:13.695Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-ljt8t"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T14:10:19.351Z"},{"id":"fbcf1f3c-3634-432b-b413-48725a59e93e","status":{"state":"active"},"updatedAt":"2023-01-30T14:11:00.400Z","comment":"s","createdBy":"sound","endsAt":"2025-10-26T14:10:34.567Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-mlwbd"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T14:11:00.400Z"},{"id":"17ade3b7-2360-4de2-b4e2-900ea50271cf","status":{"state":"active"},"updatedAt":"2023-01-30T14:11:07.495Z","comment":"s","createdBy":"sound","endsAt":"2025-10-26T14:10:36.760Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-mpswf"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T14:11:07.495Z"},{"id":"a6e0ff3d-4bef-4fc5-b2cd-b92f2cf95b28","status":{"state":"active"},"updatedAt":"2023-01-30T14:11:13.565Z","comment":"s","createdBy":"sound","endsAt":"2025-10-26T14:10:39.513Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-msxsj"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T14:11:13.565Z"},{"id":"17281211-91c3-4893-86db-85190aa8c3af","status":{"state":"active"},"updatedAt":"2023-01-30T14:11:19.916Z","comment":"s","createdBy":"sound","endsAt":"2025-10-26T14:10:41.553Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-mw8bv"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T14:11:19.916Z"},{"id":"866f94e4-b5e1-4ccc-a283-ac8f0ede3013","status":{"state":"active"},"updatedAt":"2023-01-30T14:11:26.551Z","comment":"d","createdBy":"sound","endsAt":"2025-10-26T14:10:51.116Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-x6xg5"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T14:11:26.551Z"},{"id":"d4b3721b-2864-47d7-ad6b-ae79ed75198d","status":{"state":"active"},"updatedAt":"2023-01-30T14:11:32.761Z","comment":"d","createdBy":"sound","endsAt":"2025-10-26T14:10:52.983Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-x7csf"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T14:11:32.761Z"},{"id":"f3b47132-2dae-4512-aaca-394622c46a0d","status":{"state":"active"},"updatedAt":"2023-01-30T14:11:03.954Z","comment":"ds","createdBy":"ds","endsAt":"2025-10-26T14:10:57.777Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-CPU-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-demand-cluster"},{"isRegex":false,"name":"label_bu","value":"demand"},{"isRegex":false,"name":"label_env","value":"prod"},{"isRegex":false,"name":"label_priority","value":"p1"},{"isRegex":false,"name":"label_service","value":"merch-merchandising-consumer"},{"isRegex":false,"name":"label_team","value":"product-feed"},{"isRegex":false,"name":"namespace","value":"prd-merch-merchandising-consumer"},{"isRegex":false,"name":"pod","value":"prd-merch-merchandising-consumer-64cc7cbc75-6stbp"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T14:11:03.954Z"},{"id":"38f4b743-6edc-45e8-a503-d3191a5703f1","status":{"state":"active"},"updatedAt":"2023-01-30T14:11:18.470Z","comment":"as per ds","createdBy":"ds","endsAt":"2025-10-26T14:11:10.059Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-CPU-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-demand-cluster"},{"isRegex":false,"name":"label_bu","value":"demand"},{"isRegex":false,"name":"label_env","value":"prod"},{"isRegex":false,"name":"label_priority","value":"p1"},{"isRegex":false,"name":"label_service","value":"merch-merchandising-consumer"},{"isRegex":false,"name":"label_team","value":"product-feed"},{"isRegex":false,"name":"namespace","value":"prd-merch-merchandising-consumer"},{"isRegex":false,"name":"pod","value":"prd-merch-merchandising-consumer-64cc7cbc75-8lln4"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T14:11:18.470Z"},{"id":"2f156626-fd5c-422b-af43-4782871dc3a3","status":{"state":"active"},"updatedAt":"2023-01-30T14:11:33.186Z","comment":"ds","createdBy":"ds","endsAt":"2025-10-26T14:11:27.032Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-CPU-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-demand-cluster"},{"isRegex":false,"name":"label_bu","value":"demand"},{"isRegex":false,"name":"label_env","value":"prod"},{"isRegex":false,"name":"label_priority","value":"p1"},{"isRegex":false,"name":"label_service","value":"merch-merchandising-consumer"},{"isRegex":false,"name":"label_team","value":"product-feed"},{"isRegex":false,"name":"namespace","value":"prd-merch-merchandising-consumer"},{"isRegex":false,"name":"pod","value":"prd-merch-merchandising-consumer-64cc7cbc75-bpxqk"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T14:11:33.186Z"},{"id":"695cb638-7e2b-41ee-8556-9f5c227e7351","status":{"state":"active"},"updatedAt":"2023-01-30T14:11:48.649Z","comment":"as per ds","createdBy":"ds","endsAt":"2025-10-26T14:11:39.457Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-CPU-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-demand-cluster"},{"isRegex":false,"name":"label_bu","value":"demand"},{"isRegex":false,"name":"label_env","value":"prod"},{"isRegex":false,"name":"label_priority","value":"p1"},{"isRegex":false,"name":"label_service","value":"merch-merchandising-consumer"},{"isRegex":false,"name":"label_team","value":"product-feed"},{"isRegex":false,"name":"namespace","value":"prd-merch-merchandising-consumer"},{"isRegex":false,"name":"pod","value":"prd-merch-merchandising-consumer-64cc7cbc75-bs2pp"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T14:11:48.649Z"},{"id":"8afffc2c-c5ca-4082-ada8-2840f18ed764","status":{"state":"active"},"updatedAt":"2023-01-30T14:13:01.666Z","comment":"ds","createdBy":"ds","endsAt":"2025-10-26T14:12:55.768Z","matchers":[{"isRegex":false,"name":"alertgroup","value":"EKS-Pod-Alerts"},{"isRegex":false,"name":"alertname","value":"Pod-Memory-Crossed-80%"},{"isRegex":false,"name":"cluster","value":"p-dp-starburst-cluster"},{"isRegex":false,"name":"label_bu","value":"dataengg"},{"isRegex":false,"name":"label_env","value":"prd"},{"isRegex":false,"name":"label_priority","value":"p0"},{"isRegex":false,"name":"label_service","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"label_team","value":"data-platform-consumption"},{"isRegex":false,"name":"namespace","value":"eks-model-p1-backend1"},{"isRegex":false,"name":"pod","value":"worker-7879f5c487-xkh5k"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-01-30T14:13:01.666Z"},{"id":"c0dcc9cf-e89e-414e-8ec4-1556d6c5a62b","status":{"state":"active"},"updatedAt":"2023-03-07T20:14:17.289Z","comment":"as per dev request\nhttps://meesho.slack.com/archives/C022MDYQQ0J/p1678218097411749?thread_ts=1678217648.908959\u0026cid=C022MDYQQ0J\n","createdBy":"muhilan","endsAt":"2025-12-01T20:12:40.043Z","matchers":[{"isRegex":false,"name":"alertname","value":"ES_4xx_20+"},{"isRegex":false,"name":"alertgroup","value":"Elastic-Search-Alerts"},{"isRegex":false,"name":"client_id","value":"847438129436"},{"isRegex":false,"name":"client_id","value":"platform-p-qwest-ts-catalogs"},{"isRegex":false,"name":"job","value":"aws_es"},{"isRegex":false,"name":"resource","value":"AWS Elastic Search"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2023-03-07T20:14:17.289Z"},{"id":"694794de-fcba-4ef1-bfd3-bf505d3b79aa","status":{"state":"active"},"updatedAt":"2021-03-02T17:50:07.462Z","comment":"this domain is terminated","createdBy":"Karunya.S","endsAt":"2032-07-29T09:48:13.761Z","matchers":[{"isRegex":false,"name":"alertname","value":"ES_Search_Rate"},{"isRegex":false,"name":"client_id","value":"847438129436"},{"isRegex":false,"name":"domain_name","value":"bac-p-indo-scrape"},{"isRegex":false,"name":"job","value":"aws_es"},{"isRegex":false,"name":"resource","value":"AWS Elastic Search"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2021-03-02T17:50:07.462Z"},{"id":"5285d4b0-50af-4a79-9d63-0c9266609011","status":{"state":"active"},"updatedAt":"2021-09-07T08:07:34.985Z","comment":"as per ramiz confirmation silencing the alert for 2years","createdBy":"veera","endsAt":"2048-12-22T15:27:55.674Z","matchers":[{"isRegex":false,"name":"alertname","value":"CPU-High-80%"},{"isRegex":false,"name":"job","value":"node_exporter"},{"isRegex":false,"name":"name","value":"dataplatform-p-Prism-DeltaLake-Pipelines"},{"isRegex":false,"name":"severity","value":"critical"},{"isRegex":false,"name":"status","value":"running"},{"isRegex":false,"name":"team","value":"data-platform"}],"startsAt":"2021-09-07T08:07:34.985Z"},{"id":"4a87d570-9b90-46d2-91c5-54e1c2e8553c","status":{"state":"active"},"updatedAt":"2021-10-27T03:45:58.954Z","comment":"as per request","createdBy":"veera","endsAt":"2049-03-13T03:45:30.600Z","matchers":[{"isRegex":false,"name":"alertname","value":"ES_Indexing_Rate_400K"},{"isRegex":false,"name":"client_id","value":"847438129436"},{"isRegex":false,"name":"domain_name","value":"platform-p-graylog"},{"isRegex":false,"name":"job","value":"aws_es"},{"isRegex":false,"name":"node_id","value":"kfdaVKiiTSKIGrU4EUZOTg"},{"isRegex":false,"name":"resource","value":"AWS Elastic Search"},{"isRegex":false,"name":"severity","value":"critical"}],"startsAt":"2021-10-27T03:45:58.954Z"},{"id":"53851781-f8e4-4be6-94d4-900e90acc522","status":{"state":"active"},"updatedAt":"2023-06-25T04:07:41.224Z","comment":"renamed this alert","createdBy":"sre-oncall","endsAt":"2123-06-01T04:06:23.753Z","matchers":[{"isRegex":false,"name":"alertname","value":"prod-ops-vmagent-Pod-CPU-Crossed-130%"}],"startsAt":"2023-06-25T04:07:41.224Z"}] diff --git a/helm-overrides/k8s-admin-prd-ase1/alloy/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/alloy/custom-values.yaml deleted file mode 100644 index db5e17f..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/alloy/custom-values.yaml +++ /dev/null @@ -1,49 +0,0 @@ -fullnameOverride: "alloy-infra-prd" - -alloy: - configMap: - configFile: admin.alloy - clustering: - enabled: true - - extraPorts: - - name: "otlp-grpc" - port: 4317 - targetPort: 4317 - protocol: "TCP" - - name: "otlp-http" - port: 4318 - targetPort: 4318 - protocol: "TCP" - - resources: - requests: - cpu: 3 - memory: 12Gi - -configReloader: - enabled: true - -serviceAccount: - annotations: { - iam.gke.io/gcp-service-account: sa-infr-sre-obs-prd@meesho-admin-prd-0622.iam.gserviceaccount.com - } - -controller: - # Must be one of 'daemonset', 'deployment', or 'statefulset'. - type: 'deployment' - - nodeSelector: - dedicated: "alloy" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "alloy" - effect: "NoSchedule" - - autoscaling: - enabled: true - minReplicas: 1 - maxReplicas: 50 - targetCPUUtilizationPercentage: 80 - targetMemoryUtilizationPercentage: 80 \ No newline at end of file diff --git a/helm-overrides/k8s-admin-prd-ase1/argocd-admin-prd/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/argocd-admin-prd/custom-values.yaml deleted file mode 100644 index c9c1c70..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/argocd-admin-prd/custom-values.yaml +++ /dev/null @@ -1,126 +0,0 @@ -argo-cd: - global: - image: - tag: "v2.13.8" - - # Single-node homelab VM (8GB RAM / 6 cores, see claude.md) — no dedicated - # devops node pool here, so the GKE nodeSelector/toleration pair from the - # fleet's admin cluster doesn't apply. Every component below is trimmed to - # a single replica with small resource requests to fit the ~700MB total - # budget claude.md tracks for ArgoCD. - - # SSO deferred per claude.md ("not yet implemented") — Dex stays off until - # that's picked back up. Revisit this file when it is. - dex: - enabled: false - - controller: - replicas: 1 - resources: - requests: - cpu: 200m - memory: 400Mi - limits: - cpu: 500m - memory: 768Mi - - redis-ha: - enabled: false - redis: - resources: - requests: - cpu: 50m - memory: 64Mi - limits: - memory: 128Mi - - repoServer: - replicas: 1 - resources: - requests: - cpu: 100m - memory: 256Mi - limits: - cpu: 300m - memory: 512Mi - - server: - replicas: 1 - extraArgs: - - --insecure - ingress: - enabled: true - ingressClassName: contour - hostname: "argocd.192.168.1.7.nip.io" - # Tailscale nip.io variant, same dual-host pattern as Gitea — chart - # supports this natively via extraHosts (confirmed against the real - # values.yaml, not assumed). - extraHosts: - - name: "argocd.100.90.248.118.nip.io" - path: / - resources: - requests: - cpu: 50m - memory: 128Mi - limits: - cpu: 200m - memory: 256Mi - - # Not used by this repo's Applications (plain Application manifests - # rendered by generic-argo-apps-chart, not the ApplicationSet CRD) and - # notifications has no configured trigger/service — both off to save RAM. - applicationSet: - enabled: false - notifications: - enabled: false - - configs: - cm: - url: "https://argocd.192.168.1.7.nip.io" - timeout.reconciliation: 3m - timeout.reconciliation.jitter: 60s - # ArgoCD's built-in Ingress health check waits for - # status.loadBalancer.ingress to be populated — that only happens - # behind a Service type=LoadBalancer. Contour here is exposed via - # hostPort (MetalLB is installed but not load-bearing, see - # claude.md), so nothing ever writes that status field and every - # Ingress sits "Progressing" forever even though it's actually - # serving traffic fine. Override: an Ingress existing is enough. - resource.customizations.health.networking.k8s.io_Ingress: | - hs = {} - hs.status = "Healthy" - hs.message = "Ingress considered healthy on sight — this cluster's Contour has no LoadBalancer status to wait on (hostPort, not MetalLB)." - return hs - # Scoped account for Jenkins to trigger a sync as the last step of the - # CI/CD pipeline — devops-lib's real deployArgoCD.groovy always closes - # its 4-step ceremony with `argocd app sync --hard-refresh`; without - # this, our pipeline stops at the tag-bump commit and a human has to - # remember to click Sync. Uses apiKey auth (token-based), not the - # admin account — same least-privilege pattern as Harbor's robot - # account. Token itself is generated via CLI (not declarative — see - # bootstrap note in devops-lib's syncArgoApp.groovy) and stored in - # Vault like every other credential here. - accounts.jenkins-ci: apiKey - accounts.jenkins-ci.enabled: "true" - # No custom RBAC policy beyond the jenkins-ci account below: single-user - # homelab, the initial admin secret (kubectl -n argocd get secret - # argocd-initial-admin-secret) is enough for you. The fleet's - # role:admins / role:backend / GitHub-team policy.csv and real teammate - # emails from the source cluster are dropped here. - rbac: - # Scoped to the whole webapp project, not one app name — this is - # exactly what that AppProject exists for (projects/webapp.yaml in - # devops-argo-config). Any future app onboarded into it (project: - # webapp in its Application manifest) is automatically covered by - # jenkins-ci's sync/get access with zero RBAC changes needed here. - # Platform-level apps (argocd, gitea, vault, contour, - # external-secrets, jenkins, harbor) stay on the default project, - # untouched by this policy. - policy.csv: | - p, jenkins-ci, applications, sync, webapp/*, allow - p, jenkins-ci, applications, get, webapp/*, allow - repositories: - devops-infra-helm-charts: - url: http://gitea.192.168.1.7.nip.io/mukul/devops-infra-helm-charts.git - devops-infra-argo-config: - url: http://gitea.192.168.1.7.nip.io/mukul/devops-infra-argo-config.git diff --git a/helm-overrides/k8s-admin-prd-ase1/athens-proxy/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/athens-proxy/custom-values.yaml deleted file mode 100644 index d5ce18d..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/athens-proxy/custom-values.yaml +++ /dev/null @@ -1,348 +0,0 @@ -image: - registry: docker.io - repository: gomods/athens - # Override the chart appVersion and use a specific tag - # tag: v0.12.0 - - # -- Specify a imagePullPolicy. - # see http://kubernetes.io/docs/user-guide/images/#pre-pulling-images - pullPolicy: IfNotPresent - - # -- Specify secrets containing credentials for pulling images - pullSecrets: [] - # - name: name-of-secret - - # -- Determine if the image should run as `root` or user `athens` - runAsNonRoot: false - -livenessProbe: - failureThreshold: 3 - periodSeconds: 10 - successThreshold: 1 - timeoutSeconds: 1 - -readinessProbe: - failureThreshold: 3 - periodSeconds: 10 - successThreshold: 1 - timeoutSeconds: 1 - -strategy: - # -- Using RollingUpdate requires a shared storage - type: Recreate - rollingUpdate: - maxSurge: 1 - maxUnavailable: 1 - -service: - # -- Add annotations to the service - annotations: {} - # -- Port as exposed by the service - servicePort: 80 - # -- Type of service; valid values are "ClusterIP", "LoadBalancer", and - # "NodePort". "ClusterIP" is sufficient in the case when the Proxy will be used - # from within the cluster. To expose externally, consider a "NodePort" or "LoadBalancer" service or use an "Ingress". - type: ClusterIP - # Optional configuration if service is of type "NodePort" - # nodePort: - # -- Specify the nodePort in allowable range (e.g. 30000 - 32767 on minikube) - # port: 30080 - -ingress: - # -- Create an Ingress resource for athens - enabled: true - annotations: {} - className: nginx-internal - # -- Provide an array of values for the ingress host mapping - hosts: - - host: athens-prd.meeshogcp.in - paths: - - path: / - pathType: ImplementationSpecific - # Provide a base64 encoded cert for TLS use - tls: [] - # - hosts: - # - athens-proxy.local - # secretName: athens-proxy.local-tls - -storage: - # -- Storage type to use. For a single instance a PVC may be sufficient - type: disk - disk: - storageRoot: "/var/lib/athens" - persistence: - # -- Note if you use disk.persistence.enabled, replicaCount should be set to 1 unless your access mode is - # 'ReadWriteMany' and strategy type must be 'Recreate' - enabled: true - accessMode: ReadWriteOnce - storageClass: "premium-rwo" - size: 10Gi - mongo: - url: "" - s3: - # -- You must set s3 bucket and region when running 'helm install' - region: "" - bucket: "" - useDefaultConfiguration: false - forcePathStyle: false - accessKey: "" - secretKey: "" - sessionToken: "" - minio: - # -- All these variables needs to be set when configuring athens to run with minio backend - endpoint: "" - accessKey: "" - secretKey: "" - bucket: "" - gcp: - # -- For more information, see: - # https://docs.gomods.io/install/install-on-kubernetes/#google-cloud-storage - # you must set gcp projectID and bucket when running 'helm install' - projectID: "meesho-admin-prd-0622" - bucket: "gcs-infr-dvps-athens-prd" - # -- Set serviceAccount to a key which has read/write access to the GCS bucket. - # If you are running Athens inside GCP, you will most likely not need this - # as GCP figures out internal authentication between products for you. - serviceAccount: "" - -singleFlight: - # -- SingleFlight type to use. - # Options are ["memory", "etcd", "redis", "redis-sentinel", "gcp", "azureblob"]. - # see https://docs.gomods.io/configuration/storage/#running-multiple-athens-pointed-at-the-same-storage - type: "" - etcd: - endpoints: "" - redis: - endpoint: "" - password: "" - lockConfig: {} - # ttl: 900 - # timeout: 15 - # maxRetries: 10 - redisSentinel: - endpoints: "" - masterName: "" - sentinelPassword: "" - redisUsername: "" - redisPassword: "" - lockConfig: {} - # ttl: 900 - # timeout: 15 - # maxRetries: 10 - -# -- Priority class for pod scheduling. -# see API reference: https://kubernetes.io/docs/concepts/configuration/pod-priority-preemption/#priorityclass -priorityClassName: "" - -# -- see API reference: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.31/#pod-v1-core. -# the default value is 30 seconds. -terminationGracePeriodSeconds: 30 - -# -- Container security context configuration. -# see API reference: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.28/#securitycontext-v1-core. -# This will override the `image.runAsNonRoot` settings in the specified container if `runAsUser` or `runAsGroup` are set -securityContext: {} - # allowPrivilegeEscalation: false - # runAsNonRoot: true - -# -- Container lifecycle hooks configuration. -# see API reference: https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/ -lifecycle: {} - -# -- Set environment variables to be passed to athens pods -configEnvVars: - - name: ATHENS_DOWNLOAD_MODE - value: sync - -# -- Add extra annotations to the athens pods -annotations: {} - -# -- Add extra labels to all resources -extraLabels: {} - -# HTTP basic auth -basicAuth: - # -- If enabled, it expects to find the username and password in the named secret provided below - enabled: false - # -- Secret name, containing the 'passwordSecretKey' and 'usernameSecretKey' - secretName: athens-proxy-basic-auth - passwordSecretKey: password - usernameSecretKey: username - -netrc: - # -- If enabled, it expects to find the content of a valid '.netrc' file in the named secret provided below - enabled: false - # -- Secret name, containing the '.netrc' file - existingSecret: netrcsecret - -# gitconfig section provides a way to inject git config file to make athens able to fetch modules from private git repos -gitconfig: - # -- If enabled, it expects to find git configuration in the named secret provided below. - # By default, gitconfig is disabled - enabled: true - # -- Name of the kubernetes secret (in the same namespace as athens-proxy) that contains git config - secretName: athens-proxy-gitconfig - # -- Key in the kubernetes secret that contains git config data - secretKey: gitconfig - -upstreamProxy: - # -- This is where you can set the URL for the upstream module repository. - # If 'enabled' is set to true, Athens will try to download modules from the upstream when it doesn't find them in its own storage. - # Here's a non-exhaustive list of options you can set here: - # - # - https://gocenter.io - # - https://proxy.golang.org - enabled: false - url: "https://proxy.golang.org" - -jaeger: - # -- Deploy a jaeger "all-in-one" pod for tracing - enabled: false - annotations: {} - # -- Type of service; valid values are "ClusterIP", "LoadBalancer", and "NodePort". - type: ClusterIP - image: - repository: jaegertracing/all-in-one - tag: latest - # -- Specify the jaeger URL for the environment variable used by athens. - # With default settings, it uses the jaeger-collector-http port of the jaeger service. - url: "" - -tracing: - # -- Set ATHENS_TRACE_EXPORTER* environment variables to point to a tracing deployment. - enabled: false - # -- Value of ATHENS_TRACE_EXPORTER_URL - url: "" - # -- Value of ATHENS_TRACE_EXPORTER, supported values are "jaeger", "datadog", and "stackdriver". - type: "jaeger" - -# -- Configuration for private git servers that will provide ssh and git config to athens in a ConfigMap -sshGitServers: [] - ## Private git servers over ssh - ## to enable uncomment lines with single hash below - ## hostname of the git server - # - host: git.example.com - ## https path, "/scm" for bitbucket - # path: "" - ## ssh username - # user: git - ## ssh private key for the user - # privateKey: | - # -----BEGIN RSA PRIVATE KEY----- - # -----END RSA PRIVATE KEY----- - ## ssh port - # port: 22 - ## ssh private key from the existing secret (to be added separately in "Secret" Resource) - # existingSecret: - # name: ssh-keys - # subPath: secret.id_rsa - -# -- sshGitServers init container security context configuration -initContainerSecurityContext: {} - # allowPrivilegeEscalation: false - # runAsNonRoot: true - -# -- sshGitServers init container resources (deprecated naming, if initContainerResources is defined, that will be used in preference to this value) -intiContainerResources: {} - # limits: - # cpu: 100m - # memory: 64Mi - # requests: - # cpu: 100m - # memory: 64Mi - -# -- sshGitServers init container resources -initContainerResources: {} - # limits: - # cpu: 100m - # memory: 64Mi - # requests: - # cpu: 100m - # memory: 64Mi - -# -- Define extra init containers for athens-proxy -extraInitContainers: [] - # - name: init - # image: busybox:1.28 - # command: ['sh', '-c', "echo 'hello world'"] - -# -- Specify the number of go workers -goGetWorkers: 16 - -metrics: - serviceMonitor: - # -- Create a ServiceMonitor for prometheus - enabled: false - # namespace: "monitoring" - # labels: - # prometheus: default - - serviceScrape: - # -- Create a VMServiceScrape for victoria - enabled: false - # namespace: "monitoring" - -serviceAccount: - # -- Create a ServiceAccount - create: true - annotations: - iam.gke.io/gcp-service-account: jenkins-prd-agent@meesho-devops-admin-0622.iam.gserviceaccount.com - name: "athens-proxy-admin-prd" - -# -- see https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#scheduling -nodeSelector: - dedicated: dind - -# -- see https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#scheduling -tolerations: - - key: "dedicated" - operator: "Equal" - value: "dind" - effect: "NoSchedule" - -# -- see https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#scheduling -affinity: {} - -# -- Add extra volumes to deployment pod -extraVolumes: {} - -# -- Add extra volume mounts to deployment pod primary container -extraVolumeMounts: {} - -# -- Define resources for athens pods. -# see https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#resources -resources: - limits: - cpu: '15' - memory: 8Gi - requests: - cpu: '12' - memory: 6Gi - -# -- Set the number of athens-proxy replicas, unless autoscaling is enabled -replicaCount: 1 - -autoscaling: - # -- Enable Horizontal Pod Autoscaling - enabled: false - minReplicas: 1 - maxReplicas: 3 - targetCPUUtilizationPercentage: 80 - targetMemoryUtilizationPercentage: 80 - # -- Overwrite the API version used for HPA, uses 'autoscaling/v2' by default. - # see https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/horizontal-pod-autoscaler-v2/ - apiVersionOverride: "" - # -- Define scaling behavior for HPA - behavior: {} - # scaleDown: - # stabilizationWindowSeconds: 300 - # policies: - # - type: Pods - # value: 1 - # periodSeconds: 180 - # scaleUp: - # stabilizationWindowSeconds: 300 - # policies: - # - type: Pods - # value: 2 - # periodSeconds: 60 diff --git a/helm-overrides/k8s-admin-prd-ase1/aurva-dataplane/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/aurva-dataplane/custom-values.yaml deleted file mode 100644 index d87a5eb..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/aurva-dataplane/custom-values.yaml +++ /dev/null @@ -1,675 +0,0 @@ -## Aurva Data Plane -## Ref: https://github.com/aurva-io/aurva-charts.git - -postgresql: - enabled: true - fullnameOverride: "aurva-dataplane-database" - volumePermissions: - ## @param volumePermissions.enabled Enable init container that changes the owner and group of the persistent volume - ## - enabled: true - global: - storageClass: pd-standard-retain-dr - postgresql: - auth: - postgresPassword: "aurva" - database: "controller" - # Add toleration to make sure where this postgres db pod should reside (Applicable for production workloads): For more detail ref: https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/ - primary: - extendedConfiguration: | - max_connections = 300 - - #PLACEHOLDER## - tolerations: - - effect: NoSchedule - key: dedicated - operator: Equal - value: devops - - # -- Select nodes to deploy which matches the following labels - nodeSelector: ##PLACEHOLDER## - dedicated: devops - -# -- Provide a name in place of `aurva` -# namespaceOverride: aurva-dataplane - -########################################################## -# Global Configs -########################################################## -global: - aurva_controller: - enabled: true - aurva_fastdet: - enabled: false - aurva_pii_analyzer: - enabled: true - aurva_ocr: - enabled: true - aurva_collector: - enabled: false - - deploymentAnnotations: {} - - priorityClassName: "" - -########################################################## -# Aurva Controller -########################################################## -aurva_controller: - - # -- Additional labels for aurva-controller - additionalLabels: - bu: "admin" - team: "admin-devops" - service: "aurva-admin-prd" - env: "prd" - priority: "p0" - type: "aurva_controller" - - # -- Annotations on aurva-controller - annotations: {} - # "key": "value" - - revisionHistoryLimit: 3 - - # -- no of replicas for aurva controller - replicas: 10 - - # -- Additional label added on pod which is used in Service's Label Selector - podLabels: {} - - # -- Additional Pod Annotations added on pod created by this Deployment - additionalPodAnnotations: {} - # "key": "value" - - # -- Secrets used to pull image - imagePullSecrets: "" - image: - # Image of the app container - repository: asia-south1-docker.pkg.dev/aurva-gcp/aurva-controller/aurva-controller - tag: "v3.20.3" - pullPolicy: IfNotPresent - - # Environment variables to be passed to the app container - env: [] - - # -- If want to mount Envs from configmap or secret - envFrom: - - type: secret - name: aurva-controller-secrets - # - type: configmap - # name: proxy-datasource-config - - # -- Resources to be defined for pod - resources: - limits: - memory: 2Gi - cpu: 2 - requests: - memory: 1Gi - cpu: 1 - - aurvaFastdet: - image: - repository: asia-south1-docker.pkg.dev/aurva-gcp/aurva-fastdet/aurva-fastdet - tag: "v2.30.13" - pullPolicy: IfNotPresent - envFrom: [] - env: [] - resources: - limits: - cpu: 0.5 - memory: 512Mi - requests: - cpu: 0.5 - memory: 512Mi - - nodeSelector: ##PLACEHOLDER## - dedicated: devops - - # -- Taint tolerations for nodes - ##PLACEHOLDER## - tolerations: - - effect: NoSchedule - key: dedicated - operator: Equal - value: devops - - # -- Pod affinity and pod anti-affinity allow you to specify rules about how pods should be placed relative to other pods. - affinity: - # nodeAffinity: - # requiredDuringSchedulingIgnoredDuringExecution: - # nodeSelectorTerms: - # - matchExpressions: - # - key: disktype - # operator: In - # values: - # - ssd - - # -- [DNS configuration] - dnsConfig: {} - # -- Alternative DNS policy for application controller pods - dnsPolicy: "ClusterFirst" - - secret: - name: "aurva-controller-secrets" - # -- Additional Labels on secrets - additionalLabels: - # key: value - # -- Annotations on secrets - annotations: - # key: value - config: - #variables - COMPANY_ID: "65eeb832-67ba-40fb-b95a-30ca9eaa3409" - COMMAND_URL: "command.aurva-prd.meeshogcp.in:80" - DEPLOYMENT_TYPE: "kubernetes" - PG_USERNAME: "postgres" - PG_PASSWORD: "aurva" - PG_DBNAME: "controller" - FLUSHER_WORKER_POOL_SIZE: "1000" - FLUSHER_BATCH_SIZE: "30000" - UNIQUENESS_IDENTIFIER: "k8s-admin-prd-ase1" #Recommendation: should be equal to cluster name - PROVIDER_ACCOUNT_ID: "meesho-admin-prd-0622" # GCP PROJECT ID (not Number) - REGION: "asia-southeast1" #eg: asia-south1 - ENVIRONMENT: "prod" - OCR_ENABLED: "true" - MONITORING_ENABLED: "false" - HYBRID_ONLY_MODE: "false" - FORCE_TLS: "false" - FASTDET_FLAG : "true" - AADHAAR_ENHANCER: "0" - WORKSPACE_EVENT_TRACKING_ENABLED: "false" - ACCESS_IQ_ENABLED: "true" - GRPC_ENFORCE_ALPN_ENABLED: "false" - ENABLE_FASTDET: "true" - FASTDET_MAX_BATCH_SIZE: "100" - HEARTBEAT_INTERVAL: "5m" - #pii data - PII_BUCKET_NAME: "gcs-infra-devop-aurva-admin-prd" - PII_LOG_BUCKET_REGION: "asia-southeast1" - PII_LOG_CRON: "*/5 * * * *" - ENABLE_PII_LOG: "true" - PII_EVIDENCE_UPLOAD_MAX_BLOCKING_TASKS: "50000" - PII_EVIDENCE_UPLOAD_MAX_CONCURRENT_TASKS: "500" - PII_EVIDENCE_MAX_CACHE_WEIGHT: "100" - QUOTA_CLEANUP_CRON: "0 0 * * *" - ENABLE_PII_QUOTA: "true" - MAX_PII_EVIDENCES_PER_KEY_PER_WINDOW: "3" - PII_QUOTA_SYNC_CRON: "*/2 * * * *" - QUOTA_WINDOW_HOURS: "24" - #constants - SKIP_NAMESPACES: "argocd-central-ase1c-prd,argocd-central-prd,argocd-central-prd,argocd-dataengg-prd,argocd-datascience-prd,argocd-demand-prd,argocd-farmiso-prd,argocd-prd,argocd-shared-int,argocd-supply-prd,jenkins" - CLOUD_PROVIDER: "gcp" - LOG_ENV: "production" - RDS_SCANNER_AVAILABILITY : "false" - REDSHIFT_SCANNER_AVAILABILITY : "false" - S3_SCANNER_AVAILABILITY : "false" - DYNAMO_SCANNER_AVAILABILITY: "false" - DOCDB_SCANNER_AVAILABILITY: "false" - OPENSEARCH_SCANNER_AVAILABILITY: "false" - CLOUDSQL_SCANNER_AVAILABILITY: "true" - BIGQUERY_SCANNER_AVAILABILITY: "true" - AWS_SNAPSHOT_SCANNER_AVAILABILITY: "false" - CLOUDSTORAGE_SCANNER_AVAILABILITY: "true" - KEYSPACES_SCANNER_AVAILABILITY: "false" - ALLOYDB_SCANNER_AVAILABILITY: "true" - BIGTABLE_SCANNER_AVAILABILITY: "true" - GCP_BACKUP_AVAILABILITY: "true" - EGRESS_MODE_ONLY: "false" - SENTRY_DSN: "https://fd6738e1ee4a9a9c1f079d09953b43b1@sentry.aurva.io/4" - SCAN_UUID_ENABLED: "true" - - serviceAccount: - # -- Create a service account for the aurva controller - create: true - # -- Service account name - name: aurva-controller-sa - # -- Annotations applied to created service account - annotations: - iam.gke.io/gcp-service-account: sa-admin-prd-aurva-contr@meesho-admin-prd-0622.iam.gserviceaccount.com -# eks.amazonaws.com/role-arn: arn:aws:iam:::role/ - # -- Labels applied to created service account - labels: {} - autoscaling: - enabled: true - minReplicas: 10 - maxReplicas: 15 - metrics: - - type: Resource - resource: - name: cpu - target: - type: Utilization - averageUtilization: 70 - - type: Resource - resource: - name: memory - target: - type: Utilization - averageUtilization: 70 - - -########################################################## -# Aurva OCR -########################################################## -aurva_ocr: - # -- Additional labels for aurva-controller - additionalLabels: - bu: "admin" - team: "admin-devops" - service: "aurva-admin-prd" - env: "prd" - priority: "p0" - type: "aurva_ocr" - - # -- Annotations on aurva-controller - annotations: {} - # "key": "value" - - revisionHistoryLimit: 3 - - # -- no of replicas for aurva controller - replicas: 1 - - # -- Additional label added on pod which is used in Service's Label Selector - podLabels: {} - - # -- Additional Pod Annotations added on pod created by this Deployment - additionalPodAnnotations: {} - # "key": "value" - - # -- Secrets used to pull image - imagePullSecrets: "" - - # Image of the app container - image: - repository: asia-south1-docker.pkg.dev/aurva-gcp/aurva-ocr/aurva-ocr - tag: "v3.20.3" - pullPolicy: IfNotPresent - - # Environment variables to be passed to the app container - env: [] - - # -- If want to mount Envs from configmap or secret - envFrom: - aurva-ocr: - type: secret - name: aurva-ocr-secrets - - # -- Resources to be defined for pod - resources: - limits: - memory: 2Gi - cpu: 1 - requests: - memory: 2Gi - cpu: 1 - - # -- Select nodes to deploy which matches the following labels - - nodeSelector: ##PLACEHOLDER## - dedicated: devops - - ##PLACEHOLDER## - # -- Taint tolerations for nodes - tolerations: - - effect: NoSchedule - key: dedicated - operator: Equal - value: devops - - # -- Pod affinity and pod anti-affinity allow you to specify rules about how pods should be placed relative to other pods. - affinity: - # nodeAffinity: - # requiredDuringSchedulingIgnoredDuringExecution: - # nodeSelectorTerms: - # - matchExpressions: - # - key: disktype - # operator: In - # values: - # - ssd - - # -- [DNS configuration] - dnsConfig: {} - # -- Alternative DNS policy for application controller pods - dnsPolicy: "ClusterFirst" - - secret: - name: "aurva-ocr-secrets" - # -- Additional Labels on secrets - additionalLabels: - # key: value - # -- Annotations on secrets - annotations: - # key: value - - config: - PG_USERNAME: "postgres" - PG_PASSWORD: "aurva" - PG_DBNAME: "controller" - OCR_TIME_LIMIT: "1" - COMPANY_ID: "65eeb832-67ba-40fb-b95a-30ca9eaa3409" - UNIQUENESS_IDENTIFIER: "k8s-admin-prd-ase1" - DEPLOYMENT_TYPE: "kubernetes" - - serviceAccount: - # -- Create a service account for the aurva controller - create: true - # -- Service account name - name: aurva-ocr-sa - # -- Annotations applied to created service account - annotations: - # eks.amazonaws.com/role-arn: arn:aws:iam:::role/ - # iam.gke.io/gcp-service-account: service-account@gcp.iam.gserviceaccount.com - # -- Labels applied to created service account - labels: {} - -########################################################## -# Aurva Collector -########################################################## -aurva_collector: - - # -- Additional labels for aurva-analyzer - additionalLabels: - bu: "admin" - team: "admin-devops" - service: "aurva-admin-prd" - env: "prd" - priority: "p0" - type: "aurva_collector" - - - # -- Annotations on aurva-analyzer - annotations: {} -# "key": "value" - - # -- Additional label added on pod which is used in Service's Label Selector - podLabels: {} - - # -- Additional Pod Annotations added on pod created by this Deployment - additionalPodAnnotations: {} - # "key": "value" - - # -- Secrets used to pull image - imagePullSecrets: "" - - # Image of the app container - image: - repository: asia-south1-docker.pkg.dev/aurva-gcp/aurva-collector/aurva-collector - tag: "v3.20.3" - pullPolicy: IfNotPresent - - # Environment variables to be passed to the app container - env: [] - - # -- If want to mount Envs from configmap or secret - envFrom: - aurva-controller: - type: secret - name: aurva-collector-secrets - - resources: - limits: - cpu: 800m - memory: 800Mi - requests: - cpu: 200m - memory: 512Mi - - podSecurityContext: {} - - securityContext: - privileged: true - capabilities: - add: - # For kernel v5.8 and above we don't need CAP_SYS_ADMIN or CAP_SYS_RESOURCE - # we just need CAP_BPF and CAP_PERFMON. This has been tested on our EKS node - # which is on kernel v5.10.x - # When SSL Tracing is required we need CAP_SYS_ADMIN and CAP_SYS_PTRACE - # on top of the previous capabilities - # So finally these are the 4 possible combinations for capabilies - # 1. Newer Kernels without SSL - # - BPF - # - PERFMON - # 2. Newer Kernels with SSL - - SYS_ADMIN - - SYS_PTRACE - # 3. Older Kernels without SSL - # - SYS_ADMIN - # - SYS_RESOURCE - # 4. Older Kernels with SSL - # - SYS_ADMIN - # - SYS_RESOURCE - # - SYS_PTRACE - # capabilities: - # drop: - # - ALL - # readOnlyRootFilesystem: true - # runAsNonRoot: true - # runAsUser: 1000 - - volumes: - - name: debugfs - mountPath: /sys/kernel/debug - hostPath: /sys/kernel/debug - - name: vmlinux - mountPath: /sys/kernel/btf/vmlinux - hostPath: /sys/kernel/btf/vmlinux - - name: procfs - mountPath: /host/proc - hostPath: /proc - - name: bpffs - mountPath: /sys/fs/bpf - hostPath: /sys/fs/bpf - - # -- Taint tolerations for nodes - tolerations: - # - effect: NoSchedule - # key: dedicated - # operator: Equal - # value: megatetra - - operator: Exists - - # -- Pod affinity and pod anti-affinity allow you to specify rules about how pods should be placed relative to other pods. - affinity: - nodeAffinity: - requiredDuringSchedulingIgnoredDuringExecution: - nodeSelectorTerms: - - matchExpressions: - - key: dedicated - operator: NotIn - values: - - vmstorage - - vmselect - - vmagent - - vminsert - - contour-internal-0 - - contour-internal-1 - - contour-external - - alloy - - preprod-spot-16 - dnsPolicy: "ClusterFirst" - - secret: - name: "aurva-collector-secrets" - # -- Additional Labels on secrets - additionalLabels: - # key: value - # -- Annotations on secrets - annotations: - # key: value - - config: - # variables - COMPANY_ID: "65eeb832-67ba-40fb-b95a-30ca9eaa3409" - UNIQUENESS_IDENTIFIER: "k8s-admin-prd-ase1" - DEPLOYMENT_TYPE: "kubernetes" - TRACE_INTERNAL_SVC: "true" - TRACE_INTERNAL_SVC_HTTP: "true" - INTERNAL_SVC_SAMPLE_INTERVAL: "10m" - LOGS_TTL: "1h" - TRACE_HTTP2: "true" - TRACE_SSL: "false" - TRACE_PSQL: "false" - TRACE_SQLSERVER: "false" - TRACE_MYSQL: "false" - TRACE_EGRESS: "true" - TRACE_GO_TLS: "false" - TRACE_ML_SERVICES: "false" - # constants - LOG_ENV: production - SENTRY_DSN: "https://fd6738e1ee4a9a9c1f079d09953b43b1@sentry.aurva.io/4" - MONITORING_ENABLED: "false" - ENABLE_INGRESS_INFORMER: "false" - ENABLE_SERVICE_INFORMER: "false" - ENABLE_ISTIO_INFORMER: "false" - EXCLUDED_PII_REGEX_TYPES: "ip_address,us_bank_number,us_driver_license,us_itin,us_passport,us_routing,us_mbi,ssn" - AGGREGATOR_MAX_CONNECTIONS: "1000" - - serviceAccount: - # -- Create a service account for the aurva controller - create: true - # -- Service account name - name: aurva-collector-sa - # -- Annotations applied to created service account - annotations: - # eks.amazonaws.com/role-arn: arn:aws:iam:::role/ - # -- Labels applied to created service account - labels: {} - -########################################################## -# Aurva PII Analyzer -########################################################## -aurva_pii_analyzer: - - # -- Additional labels for aurva-controller - additionalLabels: - bu: "admin" - team: "admin-devops" - service: "aurva-admin-prd" - env: "prd" - priority: "p0" - type: "aurva_pii_analyzer" - - # -- Annotations on aurva-controller - annotations: {} - # "key": "value" - - revisionHistoryLimit: 3 - - # -- no of replicas for aurva controller - replicas: 3 - - # -- Additional label added on pod which is used in Service's Label Selector - podLabels: {} - - # -- Additional Pod Annotations added on pod created by this Deployment - additionalPodAnnotations: {} - # "key": "value" - - # -- Secrets used to pull image - imagePullSecrets: "" - - ##PLACEHOLDER## - nodeSelector: - dedicated: devops - - # Image of the app container - image: - repository: asia-south1-docker.pkg.dev/aurva-gcp/aurva-piianalyzer/aurva-piianalyzer - tag: "v3.20.3" - pullPolicy: IfNotPresent - - # Environment variables to be passed to the app container - env: [] - - # -- If want to mount Envs from configmap or secret - envFrom: - aurva-pii-analyzer: - type: secret - name: aurva-pii-analyzer-secrets - - # -- Resources to be defined for pod - resources: - limits: - memory: 4Gi - cpu: 4 - requests: - memory: 2Gi - cpu: 2 - - nodeSelector: ##PLACEHOLDER## - dedicated: devops - - ##PLACEHOLDER## - # -- Taint tolerations for nodes - tolerations: - - effect: NoSchedule - key: dedicated - operator: Equal - value: devops - - # -- Pod affinity and pod anti-affinity allow you to specify rules about how pods should be placed relative to other pods. - affinity: - # nodeAffinity: - # requiredDuringSchedulingIgnoredDuringExecution: - # nodeSelectorTerms: - # - matchExpressions: - # - key: disktype - # operator: In - # values: - # - ssd - - # -- [DNS configuration] - dnsConfig: {} - # -- Alternative DNS policy for application controller pods - dnsPolicy: "ClusterFirst" - - secret: - name: "aurva-pii-analyzer-secrets" - # -- Additional Labels on secrets - additionalLabels: - # key: value - # -- Annotations on secrets - annotations: - # key: value - - config: - PG_USERNAME: "postgres" - PG_PASSWORD: "aurva" - PG_DBNAME: "controller" - SCHEDULER_TIME: "1" - SUPPORTED_REGION: "US" - COMPANY_ID: "65eeb832-67ba-40fb-b95a-30ca9eaa3409" - UNIQUENESS_IDENTIFIER: "k8s-admin-prd-ase1" - DEPLOYMENT_TYPE: "kubernetes" - - serviceAccount: - # -- Create a service account for the aurva controller - create: true - # -- Service account name - name: aurva-pii-analyzer-sa - # -- Annotations applied to created service account - annotations: - # eks.amazonaws.com/role-arn: arn:aws:iam:::role/ - # -- Labels applied to created service account - labels: {} - - autoscaling: - enabled: true - minReplicas: 2 - maxReplicas: 3 - metrics: - - type: Resource - resource: - name: cpu - target: - type: Utilization - averageUtilization: 70 - - type: Resource - resource: - name: memory - target: - type: Utilization - averageUtilization: 70 diff --git a/helm-overrides/k8s-admin-prd-ase1/canary-bot-gcp/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/canary-bot-gcp/custom-values.yaml deleted file mode 100644 index 0edc519..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/canary-bot-gcp/custom-values.yaml +++ /dev/null @@ -1,25 +0,0 @@ -replicaCount: 1 - -labels: - bu: central - team: devops - env: prd - -service: - annotations: - cloud.google.com/neg: '{"exposed_ports": {"5000":{"name": "canary-bot-canary-bot-gcp"}}}' - type: ClusterIP - port: 5000 - -tolerations: - - key: "dedicated" - operator: "Equal" - value: "devops" - effect: "NoSchedule" - -nodeSelector: - dedicated: devops - -externalSecret: - path: prd/devops/canary-bot-secrets -secretRef: canary-bot-gcp diff --git a/helm-overrides/k8s-admin-prd-ase1/cert-manager/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/cert-manager/custom-values.yaml deleted file mode 100644 index 703a7e9..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/cert-manager/custom-values.yaml +++ /dev/null @@ -1,129 +0,0 @@ -global: - logLevel: 2 - rbac: - create: true - priorityClassName: "high-priority" -installCRDs: false - -crds: - enabled: true - keep: true - -# Cert-manager Controller -replicaCount: 1 -image: - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/devops/cert-manager/cert-manager-controller - tag: v1.20.1 - pullPolicy: IfNotPresent - -nodeSelector: - dedicated: devops - -tolerations: - - key: "dedicated" - operator: "Equal" - value: "devops" - effect: "NoSchedule" - -resources: - requests: - cpu: 100m - memory: 128Mi - limits: - cpu: 500m - memory: 512Mi - -# Webhook Configuration -webhook: - replicaCount: 1 - image: - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/devops/cert-manager/cert-manager-webhook - tag: v1.20.1 - pullPolicy: IfNotPresent - - nodeSelector: - dedicated: devops - - tolerations: - - key: "dedicated" - operator: "Equal" - value: "devops" - effect: "NoSchedule" - - resources: - requests: - cpu: 50m - memory: 64Mi - limits: - cpu: 250m - memory: 256Mi - -# CA Injector Configuration -cainjector: - enabled: true - replicaCount: 1 - image: - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/devops/cert-manager/cert-manager-cainjector - tag: v1.20.1 - pullPolicy: IfNotPresent - - nodeSelector: - dedicated: devops - - tolerations: - - key: "dedicated" - operator: "Equal" - value: "devops" - effect: "NoSchedule" - - resources: - requests: - cpu: 50m - memory: 64Mi - limits: - cpu: 250m - memory: 256Mi - -# ACME Solver Configuration -acmesolver: - image: - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/devops/cert-manager/cert-manager-acmesolver - tag: v1.20.1 - pullPolicy: IfNotPresent - -# Startup API Check -startupapicheck: - enabled: true - timeout: 1m - backoffLimit: 4 - image: - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/devops/cert-manager/cert-manager-startupapicheck - tag: v1.20.1 - pullPolicy: IfNotPresent - - nodeSelector: - dedicated: devops - - tolerations: - - key: "dedicated" - operator: "Equal" - value: "devops" - effect: "NoSchedule" - - resources: - requests: - cpu: 10m - memory: 32Mi - limits: - cpu: 50m - memory: 64Mi - -# Prometheus Monitoring -prometheus: - enabled: true - servicemonitor: - enabled: false - interval: 60s - scrapeTimeout: 30s - labels: - prometheus: cert-manager diff --git a/helm-overrides/k8s-admin-prd-ase1/conntrack-adjuster/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/conntrack-adjuster/custom-values.yaml deleted file mode 100644 index 7b64b15..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/conntrack-adjuster/custom-values.yaml +++ /dev/null @@ -1,26 +0,0 @@ -daemonSet: - namespace: prd-conntrack-adjuster - -conntrack: - # Maximum number of conntrack entries - max: 2097152 - # Hash size for conntrack - hashsize: 524288 - # Sleep interval between adjustments (seconds) - sleepInterval: 30 - -# Enable additional matchExpressions -# addExtraMatchExpressions: true - -# Additional matchExpressions to append -# additionalMatchExpressions: -# - key: node-role -# operator: In -# values: -# - "worker" -# - "ingress" -# - key: environment -# operator: In -# values: -# - "production" -# - "staging" \ No newline at end of file diff --git a/helm-overrides/k8s-admin-prd-ase1/contour-ca-issuer/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/contour-ca-issuer/custom-values.yaml deleted file mode 100644 index c18da3b..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/contour-ca-issuer/custom-values.yaml +++ /dev/null @@ -1,17 +0,0 @@ -# ClusterIssuer override for k8s-admin-prd-ase1 (prd admin cluster, ase1a zone). -# ClusterIssuer is a cluster-scoped resource — this file pins the issuer -# identity for this cluster so the name is auditable per-cluster. -# -# Must match the `issuerRef.name` in consuming Certificate CRs (see -# devops-helm-charts/2.0.0/templates/proxyless-grpc-cert.yaml). - -issuerName: contour-admin-prd-ca-issuer -rootCASecretName: contour-admin-ca - -externalSecret: - enabled: true - vaultPath: admin/devops/contour/root-ca - refreshInterval: "0" - secretStoreRef: - name: vault-backend -namespace: cert-manager-admin-prd diff --git a/helm-overrides/k8s-admin-prd-ase1/contour-cert-checker/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/contour-cert-checker/custom-values.yaml deleted file mode 100644 index ed3cb77..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/contour-cert-checker/custom-values.yaml +++ /dev/null @@ -1,28 +0,0 @@ -cronJob: - image: - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/contour-cert-checker - tag: v1.1 - schedule: "0 12 * * *" - args: ["--cluster=k8s-admin-prd-ase1"] - resources: - requests: - memory: "50Mi" - cpu: "50m" - limits: - memory: "100Mi" - cpu: "100m" - nodeSelector: - dedicated: devops - tolerations: - - effect: NoSchedule - key: dedicated - operator: Equal - value: devops - backoffLimit: 3 - historyLimit: - successfulJobs: 7 - failedJobs: 7 - -rbac: - namespace: contour-cert-checker-ns - serviceAccountName: contour-cert-checker-sa diff --git a/helm-overrides/k8s-admin-prd-ase1/contour-internal-0/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/contour-internal-0/custom-values.yaml deleted file mode 100644 index 1272f12..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/contour-internal-0/custom-values.yaml +++ /dev/null @@ -1,99 +0,0 @@ -configInline: - enableExternalNameService: true - timeouts: - connection-idle-timeout: 305s - connection-shutdown-grace-period: 300s - max-connection-duration: 1200s - disablePermitInsecure: false - tls: - fallback-certificate: {} - accesslog-format: envoy - accesslog-level: disabled -contour: - enabled: true - replicaCount: 3 - podLabels: - bu: admin - team: devops - env: prd - manageCRDs: true - resources: - requests: - cpu: 250m - memory: 1024Mi - tolerations: - - effect: NoSchedule - key: dedicated - operator: Equal - value: devops - nodeSelector: - dedicated: devops - service: - type: ClusterIP - ports: - xds: 8001 - metrics: 8000 - ingressClass: - name: "contour-internal-0" - create: true - debug: false - podAnnotations: - prometheus.io/path: /metrics - prometheus.io/port: '8000' - prometheus.io/scrape: 'true' -envoy: - enabled: true - podLabels: - bu: admin - team: devops - env: prd - kind: deployment - tolerations: - - effect: NoSchedule - key: dedicated - operator: Equal - value: devops - nodeSelector: - dedicated: devops - logLevel: error - autoscaling: - enabled: true - minReplicas: 2 - maxReplicas: 250 - targetCPU: "40" - targetMemory: "40" - podAnnotations: - prometheus.io/path: /stats/prometheus - prometheus.io/port: '8002' - prometheus.io/scrape: 'true' - extraArgs: - - '--concurrency 6' - resources: - requests: - cpu: 6 - memory: 3Gi - limits: - cpu: 6 - memory: 29Gi - service: - tcpLB: true - export: - enabled: true - targetPorts: - http: http - https: https - type: ClusterIP - annotations: - cloud.google.com/neg: '{"exposed_ports": {"80":{"name": "envoy-int0-admin-prd"}}}' - ports: - http: 80 - https: 443 - grpc: 8080 - useHostPort: false -defaultBackend: - enabled: false -# Override the chart-default Vault path: the admin cluster stores the contour -# root CA under the admin/ prefix, not the meesho/ prefix used by other clusters. -certManager: - externalSecret: - vaultPath: admin/devops/contour/root-ca diff --git a/helm-overrides/k8s-admin-prd-ase1/contour/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/contour/custom-values.yaml deleted file mode 100644 index 4ac45a9..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/contour/custom-values.yaml +++ /dev/null @@ -1,69 +0,0 @@ -contour: - # This is your live `helm get values contour -n projectcontour` output, - # verbatim. This is the ingress for everything else in this repo - # (Gitea, ArgoCD, Vault all route through it) — don't tune this without - # re-checking those still resolve afterward. - # - # hostPorts, not a Service type=LoadBalancer: claude.md issue #6 — MetalLB - # got a floating IP fine, but this VM's host (VMware Workstation, Bridged - # networking, over Wi-Fi) doesn't do true MAC-level bridging, so the IP - # was never reachable from outside the VM. hostPort on Envoy binds - # directly to the node's real NIC instead. - # - # Correction from an earlier version of this file: the keys below are - # NOT what `helm get values` showed as "user-supplied" on the live - # release (envoy.hostNetworking / envoy.hostPorts.enabled). Checked - # directly against this chart's own values.yaml — this version reads - # envoy.hostNetwork (singular) and envoy.useHostPort.http/https instead. - # Helm doesn't validate unknown keys, so the old ones were silent no-ops. - # hostPort on the live pods is actually coming from the raw `kubectl - # patch` in claude.md issue #7 ("the actual working solution" — that - # title is the tell), applied completely outside Helm. Getting the real - # keys into this file is what finally makes hostPort GitOps-managed - # instead of an unmanaged patch any future plain `helm upgrade` could - # silently wipe. - # - # This is also why ArgoCD's default Ingress health check needed - # overriding (see argocd-admin-prd/custom-values.yaml) — there's no - # Service type=LoadBalancer here to ever populate - # status.loadBalancer.ingress. - - contour: - resources: - limits: - memory: 128Mi - requests: - cpu: 50m - memory: 64Mi - - envoy: - dnsPolicy: ClusterFirstWithHostNet - # Mistake in an earlier version of this file: this was `true`. claude.md - # is explicit that hostPort was chosen specifically INSTEAD of - # hostNetwork ("not full hostNetwork, which is heavier-handed and - # affects pod DNS") — and hostNetwork: true also has a real API - # constraint that broke sync: it requires hostPort == containerPort on - # every port, which isn't the case here (containerPort 8080/8443 vs - # hostPort 80/443). `false` is both what was actually decided and what - # the API requires for this containerPort/hostPort combination. - hostNetwork: false - useHostPort: - http: true - https: true - # Already the chart default (80/443) — pinned explicitly anyway so a - # future chart bump changing its defaults can't silently change this. - hostPorts: - http: 80 - https: 443 - resources: - limits: - memory: 128Mi - requests: - cpu: 50m - memory: 64Mi - service: - type: ClusterIP - # Chart default (Local) pairs with the default type: LoadBalancer — - # only valid for LoadBalancer/NodePort services. Must be cleared for - # ClusterIP, which is what the sync error actually said. - externalTrafficPolicy: "" diff --git a/helm-overrides/k8s-admin-prd-ase1/coredns/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/coredns/custom-values.yaml deleted file mode 100644 index be522d6..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/coredns/custom-values.yaml +++ /dev/null @@ -1,27 +0,0 @@ -replicaCount: 6 - -labels: - bu: admin - team: devops - env: prd - -clusterIP: 10.137.32.2 - - -resources: - limits: - cpu: 100m - memory: 128Mi - requests: - cpu: 100m - memory: 128Mi - -tolerations: - - key: "dedicated" - operator: "Equal" - value: "devops" - effect: "NoSchedule" - -nodeSelector: - dedicated: devops - kubernetes.io/os: linux diff --git a/helm-overrides/k8s-admin-prd-ase1/dind-int/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/dind-int/custom-values.yaml deleted file mode 100644 index ddede22..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/dind-int/custom-values.yaml +++ /dev/null @@ -1,88 +0,0 @@ -deploymentType: "StatefulSet" - -fullNameOverride: "dind-int" - -labels: - bu: infra - team: devops - service: dind-int - env: prd - priority: p0 - type: dind - component: jenkins-agent - -env: - - name: DOCKER_HOST - value: localhost - -replicas: 1 - -image: - repository: docker - tag: 28-dind - imagePullPolicy: Always - -podSecurityContext: - privileged: true - -extraArgs: - mtu: 1460 - tls: false - host: "tcp://0.0.0.0:2375" - max-concurrent-downloads: 20 - max-concurrent-uploads: 20 - # host: "unix:///var/run/docker.sock" - -resources: - requests: - cpu: 12 - memory: 36G - -nodeSelector: - dedicated: dind - -tolerations: - - key: dedicated - operator: Equal - value: dind - effect: NoSchedule - -serviceAccountName: jenkins-prd-agent - -persistentVolume: - enabled: true - storageClass: hyperdisk-balanced - accessModes: - - ReadWriteOnce - size: 1000Gi - mountPath: /var/lib/docker - existingClaim: "" - -service: - port: 2375 - type: ClusterIP - -podDisruptionBudget: - enabled: true - minAvailable: 1 - -probe: - livenessProbe: - failureThreshold: 10 - initialDelaySeconds: 30 - periodSeconds: 30 - successThreshold: 1 - tcpSocket: - port: "{{ .Values.service.port }}" - timeoutSeconds: 5 - - readinessProbe: - failureThreshold: 3 - httpGet: - path: / - port: "{{ .Values.service.port }}" - scheme: HTTP - initialDelaySeconds: 5 - periodSeconds: 15 - successThreshold: 1 - timeoutSeconds: 5 diff --git a/helm-overrides/k8s-admin-prd-ase1/dind/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/dind/custom-values.yaml deleted file mode 100644 index a7dac99..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/dind/custom-values.yaml +++ /dev/null @@ -1,88 +0,0 @@ -deploymentType: "StatefulSet" - -fullNameOverride: "dind-prd" - -labels: - bu: infra - team: devops - service: dind-prd - env: prd - priority: p0 - type: dind - component: jenkins-agent - -env: - - name: DOCKER_HOST - value: localhost - -replicas: 1 - -image: - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/devops/docker - tag: 24-dind - imagePullPolicy: Always - -podSecurityContext: - privileged: true - -extraArgs: - mtu: 1460 - tls: false - host: "tcp://0.0.0.0:2375" - max-concurrent-downloads: 20 - max-concurrent-uploads: 20 - # host: "unix:///var/run/docker.sock" - -resources: - requests: - cpu: 12 - memory: 36G - -nodeSelector: - dedicated: dind - -tolerations: - - key: dedicated - operator: Equal - value: dind - effect: NoSchedule - -serviceAccountName: jenkins-prd-agent - -persistentVolume: - enabled: true - storageClass: sc-pd-standard - accessModes: - - ReadWriteOnce - size: 600Gi - mountPath: /var/lib/docker - existingClaim: dind-prd-pvc-hd - -service: - port: 2375 - type: ClusterIP - -podDisruptionBudget: - enabled: true - minAvailable: 1 - -probe: - livenessProbe: - failureThreshold: 10 - initialDelaySeconds: 30 - periodSeconds: 30 - successThreshold: 1 - tcpSocket: - port: "{{ .Values.service.port }}" - timeoutSeconds: 5 - - readinessProbe: - failureThreshold: 3 - httpGet: - path: / - port: "{{ .Values.service.port }}" - scheme: HTTP - initialDelaySeconds: 5 - periodSeconds: 15 - successThreshold: 1 - timeoutSeconds: 5 diff --git a/helm-overrides/k8s-admin-prd-ase1/eck-operator/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/eck-operator/custom-values.yaml deleted file mode 100644 index 8f19573..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/eck-operator/custom-values.yaml +++ /dev/null @@ -1,379 +0,0 @@ -# nameOverride is the short name for the deployment. Leave empty to let Helm generate a name using chart values. -nameOverride: "elastic-operator" - -# fullnameOverride is the full name for the deployment. Leave empty to let Helm generate a name using chart values. -fullnameOverride: "elastic-operator" - -# managedNamespaces is the set of namespaces that the operator manages. Leave empty to manage all namespaces. -managedNamespaces: [] - -# installCRDs determines whether Custom Resource Definitions (CRD) are installed by the chart. -# Note that CRDs are global resources and require cluster admin privileges to install. -# If you are sharing a cluster with other users who may want to install ECK on their own namespaces, setting this to true can have unintended consequences. -# 1. Upgrades will overwrite the global CRDs and could disrupt the other users of ECK who may be running a different version. -# 2. Uninstalling the chart will delete the CRDs and potentially cause Elastic resources deployed by other users to be removed as well. -installCRDs: true - -# replicaCount is the number of operator pods to run. -replicaCount: 1 - -image: - # repository is the container image prefixed by the registry name. - repository: docker.elastic.co/eck/eck-operator - # pullPolicy is the container image pull policy. - pullPolicy: IfNotPresent - # tag is the container image tag. If not defined, defaults to chart appVersion. - tag: null - # fips specifies whether the operator will use a FIPS compliant container image for its own StatefulSet image. - # This setting does not apply to Elastic Stack applications images. - # Can be combined with config.ubiOnly. - fips: false - -# priorityClassName defines the PriorityClass to be used by the operator pods. -priorityClassName: "" - -# imagePullSecrets defines the secrets to use when pulling the operator container image. -imagePullSecrets: [] - -# resources define the container resource limits for the operator. -resources: - requests: - cpu: 100m - memory: 150Mi - -# statefulsetAnnotations define the annotations that should be added to the operator StatefulSet. -statefulsetAnnotations: {} - -# statefulsetLabels define additional labels that should be added to the operator StatefulSet. -statefulsetLabels: {} - -# podAnnotations define the annotations that should be added to the operator pod. -podAnnotations: {} - -## podLabels define additional labels that should be added to the operator pod. -podLabels: {} - -# podSecurityContext defines the pod security context for the operator pod. -podSecurityContext: - runAsNonRoot: true - -# securityContext defines the security context of the operator container. -securityContext: - allowPrivilegeEscalation: false - capabilities: - drop: - - ALL - readOnlyRootFilesystem: true - runAsNonRoot: true - -# nodeSelector defines the node selector for the operator pod. -nodeSelector: - elastic: operator - -# tolerations defines the node tolerations for the operator pod. -tolerations: - - key: elastic - operator: Equal - value: operator - effect: NoSchedule - -# affinity defines the node affinity rules for the operator pod. -affinity: {} - -# podDisruptionBudget configures the minimum or the maxium available pods for voluntary disruptions, -# set to either an integer (e.g. 1) or a percentage value (e.g. 25%). -podDisruptionBudget: - enabled: false - minAvailable: 1 - # maxUnavailable: 3 - -# additional environment variables for the operator container. -env: [] - -# additional volume mounts for the operator container. -volumeMounts: [] - -# additional volumes to add to the operator pod. -volumes: [] - -# createClusterScopedResources determines whether cluster-scoped resources (ClusterRoles, ClusterRoleBindings) should be created. -createClusterScopedResources: true - -# Automount API credentials for the Service Account into the pod. -automountServiceAccountToken: true - -serviceAccount: - # create specifies whether a service account should be created for the operator. - create: true - # Specifies whether a service account should automount API credentials. - automountServiceAccountToken: true - # annotations to add to the service account - annotations: {} - # name of the service account to use. If not set and create is true, a name is generated using the fullname template. - name: "" - -tracing: - # enabled specifies whether APM tracing is enabled for the operator. - enabled: false - # config is a map of APM Server configuration variables that should be set in the environment. - config: - ELASTIC_APM_SERVER_URL: http://localhost:8200 - ELASTIC_APM_SERVER_TIMEOUT: 30s - -refs: - # enforceRBAC specifies whether RBAC should be enforced for cross-namespace associations between resources. - enforceRBAC: false - -webhook: - # enabled determines whether the webhook is installed. - enabled: true - # caBundle is the PEM-encoded CA trust bundle for the webhook certificate. Only required if manageCerts is false and certManagerCert is null. - caBundle: Cg== - # certManagerCert is the name of the cert-manager certificate to use with the webhook. - certManagerCert: null - # certsDir is the directory to mount the certificates. - certsDir: "/tmp/k8s-webhook-server/serving-certs" - # failurePolicy of the webhook. - failurePolicy: Ignore - # manageCerts determines whether the operator manages the webhook certificates automatically. - manageCerts: true - # namespaceSelector corresponds to the namespaceSelector property of the webhook. - # Setting this restricts the webhook to act only on objects submitted to namespaces that match the selector. - namespaceSelector: {} - # objectSelector corresponds to the objectSelector property of the webhook. - # Setting this restricts the webhook to act only on objects that match the selector. - objectSelector: {} - # port is the port that the validating webhook binds to. - port: 9443 - # secret specifies the Kubernetes secret to be mounted into the path designated by the certsDir value to be used for webhook certificates. - certsSecret: "" - -# hostNetwork allows a Pod to use the Node network namespace. -# This is required to allow for communication with the kube API when using some alternate CNIs in conjunction with webhook enabled. -# If hostNetwork is enabled, dnsPolicy defaults to ClusterFirstWithHostNet unless explicitly set. -# CAUTION: Proceed at your own risk. This setting has security concerns such as allowing malicious users to access workloads running on the host. -hostNetwork: false - -# dnsPolicy defines the DNS policy for the operator pod. -# Check https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-s-dns-policy for more details. -dnsPolicy: "" - -# dnsConfig defines the DNS configuration for the operator pod. -# Check https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for more details. -# dnsConfig: -# nameservers: -# - 169.254.20.10 -# searches: -# - svc.cluster.local -# options: -# - name: ndots -# value: "2" -dnsConfig: {} - -softMultiTenancy: - # enabled determines whether the operator is installed with soft multi-tenancy extensions. - # This requires network policies to be enabled on the Kubernetes cluster. - enabled: false - -# kubeAPIServerIP is required when softMultiTenancy is enabled. -kubeAPIServerIP: null - -telemetry: - # disabled determines whether the operator periodically updates ECK telemetry data for Kibana to consume. - disabled: false - # distributionChannel denotes which distribution channel was used to install the operator. - distributionChannel: "helm" - -# config values for the operator. -config: - # logVerbosity defines the logging level. Valid values are as follows: - # -2: Errors only - # -1: Errors and warnings - # 0: Errors, warnings, and information - # number greater than 0: Errors, warnings, information, and debug details. - logVerbosity: "0" - - # (Deprecated: use metrics.port: will be removed in v2.14.0) metricsPort defines the port to expose operator metrics. Set to 0 to disable metrics reporting. - metricsPort: 0 - - metrics: - # port defines the port to expose operator metrics. Set to 0 to disable metrics reporting. - port: "0" - # secureMode contains the options for enabling and configuring RBAC and TLS/HTTPs for the metrics endpoint. - secureMode: - # secureMode.enabled specifies whether to enable RBAC and TLS/HTTPs for the metrics endpoint. - # * This option makes most sense when using a ServiceMonitor to scrape the metrics and is therefore mutually exclusive with the podMonitor.enabled option. - # * This option also requires using cluster scoped resources (ClusterRole, ClusterRoleBinding) to - # grant access to the /metrics endpoint. (createClusterScopedResources: true is required) - # - enabled: false - tls: - # certificateSecret is the name of the tls secret containing the custom TLS certificate and key for the secure metrics endpoint. - # - # * This is an optional setting and is only required if you are using a custom TLS certificate. A self-signed certificate will be generated by default. - # * TLS secret key must be named tls.crt. - # * TLS key's secret key must be named tls.key. - # * It is assumed to be in the same namespace as the ServiceMonitor. - # - # example: kubectl create secret tls eck-metrics-tls-certificate -n elastic-system \ - # --cert=/path/to/tls.crt --key=/path/to/tls.key - certificateSecret: "" - - # containerRegistry to use for pulling Elasticsearch and other application container images. - containerRegistry: docker.elastic.co - - # containerRepository to use for pulling Elasticsearch and other application container images. - # containerRepository: "" - - # containerSuffix suffix to be appended to container images by default. Cannot be combined with -ubiOnly flag - # containerSuffix: "" - - # maxConcurrentReconciles is the number of concurrent reconciliation operations to perform per controller. - maxConcurrentReconciles: "3" - - # caValidity defines the validity period of the CA certificates generated by the operator. - caValidity: 876000h - - # caRotateBefore defines when to rotate a CA certificate that is due to expire. - caRotateBefore: 720h - - # caDir defines the directory containing a CA certificate (tls.crt) and its associated private key (tls.key) to be used for all managed resources. - # Setting this makes caRotateBefore and caValidity values ineffective. - caDir: "" - - # certificatesValidity defines the validity period of certificates generated by the operator. - certificatesValidity: 876000h - - # certificatesRotateBefore defines when to rotate a certificate that is due to expire. - certificatesRotateBefore: 720h - - # disableConfigWatch specifies whether the operator watches the configuration file for changes. - disableConfigWatch: false - - # exposedNodeLabels is an array of regular expressions of node labels which are allowed to be copied as annotations on Elasticsearch Pods. - exposedNodeLabels: - ["topology.kubernetes.io/.*", "failure-domain.beta.kubernetes.io/.*"] - - # ipFamily specifies the IP family to use. Possible values: IPv4, IPv6 and "" (auto-detect) - ipFamily: "" - - # setDefaultSecurityContext determines whether a default security context is set on application containers created by the operator. - # *note* that the default option now is "auto-detect" to attempt to set this properly automatically when both running - # in an openshift cluster, and a standard kubernetes cluster. Valid values are as follows: - # "auto-detect" : auto detect - # "true" : set pod security context when creating resources. - # "false" : do not set pod security context when creating resources. - setDefaultSecurityContext: "auto-detect" - - # kubeClientTimeout sets the request timeout for Kubernetes API calls made by the operator. - kubeClientTimeout: 60s - - # elasticsearchClientTimeout sets the request timeout for Elasticsearch API calls made by the operator. - elasticsearchClientTimeout: 180s - - # policies contains policies for the operator, currently only password generation policies are supported. - policies: {} - # passwords: - # length: 24 - - # validateStorageClass specifies whether storage classes volume expansion support should be verified. - # Can be disabled if cluster-wide storage class RBAC access is not available. - validateStorageClass: true - - # enableLeaderElection specifies whether leader election should be enabled - enableLeaderElection: true - - # Interval between observations of Elasticsearch health, non-positive values disable asynchronous observation. - elasticsearchObservationInterval: 10s - - # ubiOnly specifies whether the operator will use only UBI container images to deploy Elastic Stack applications as well as for its own StatefulSet image. UBI images are only available from 7.10.0 onward. - # Cannot be combined with the containerSuffix value. - ubiOnly: false - -# Prometheus PodMonitor configuration -# Reference: https://github.com/prometheus-operator/prometheus-operator/blob/master/Documentation/api.md#podmonitor -podMonitor: - # enabled determines whether a podMonitor should deployed to scrape the eck metrics. - # This requires the prometheus operator and the config.metrics.port not to be 0 - enabled: false - - # labels adds additional labels to the podMonitor - labels: {} - - # annotations adds additional annotations to the podMonitor - annotations: {} - - # namespace determines in which namespace the podMonitor will be deployed. - # If not set the podMonitor will be created in the namespace where the Helm release is installed into - # namespace: monitoring - - # interval specifies the interval at which metrics should be scraped - interval: 5m - - # scrapeTimeout specifies the timeout after which the scrape is ended - scrapeTimeout: 30s - - # podTargetLabels transfers labels on the Kubernetes Pod onto the target. - podTargetLabels: [] - - # podMetricsEndpointConfig allows to add an extended configuration to the podMonitor - podMetricsEndpointConfig: {} - # honorTimestamps: true - -# Prometheus ServiceMonitor configuration -# Only used when config.enableSecureMetrics is true -# Reference: https://github.com/prometheus-operator/prometheus-operator/blob/master/Documentation/api.md#servicemonitor -serviceMonitor: - # This option requires the following settings within Prometheus to function: - # 1. RBAC settings for the Prometheus instance to access the metrics endpoint. - # - # - nonResourceURLs: - # - /metrics - # verbs: - # - get - # - # 2. If using the Prometheus Operator and your Prometheus instance is not in the same namespace as the operator you will need - # the Prometheus Operator configured with the following Helm values: - # - # prometheus: - # prometheusSpec: - # serviceMonitorNamespaceSelector: {} - # serviceMonitorSelectorNilUsesHelmValues: false - # - # allows to disable the serviceMonitor, enabled by default for backwards compatibility - enabled: true - # namespace determines in which namespace the serviceMonitor will be deployed. - # If not set the serviceMonitor will be created in the namespace where the Helm release is installed into - # namespace: monitoring - # caSecret is the name of the secret containing the custom CA certificate used to generate the custom TLS certificate for the secure metrics endpoint. - # - # * This *must* be the name of the secret containing the CA certificate used to sign the custom TLS certificate for the metrics endpoint. - # * This secret *must* be in the same namespace as the Prometheus instance that will scrape the metrics. - # * If using the Prometheus operator this secret must be within the `spec.secrets` field of the `Prometheus` custom resource such that it is mounted into the Prometheus pod at `caMountDirectory`, which defaults to /etc/prometheus/secrets/{secret-name}. - # * This is an optional setting and is only required if you are using a custom TLS certificate. - # * Key must be named ca.crt. - # - # example: kubectl create secret generic eck-metrics-tls-ca -n monitoring \ - # --from-file=ca.crt=/path/to/ca.pem - caSecret: "" - # caMountDirectory is the directory at which the CA certificate is mounted within the Prometheus pod. - # - # * You should only need to adjust this if you are *not* using the Prometheus operator. - caMountDirectory: "/etc/prometheus/secrets/" - # insecureSkipVerify specifies whether to skip verification of the TLS certificate for the secure metrics endpoint. - # - # * If this setting is set to false, then the following settings are required: - # - certificateSecret - # - caSecret - insecureSkipVerify: true - -# Globals meant for internal use only -global: - # manifestGen specifies whether the chart is running under manifest generator. - # This is used for tasks specific to generating the all-in-one.yaml file. - manifestGen: false - # createOperatorNamespace defines whether the operator namespace manifest should be generated when in manifestGen mode. - # Usually we do want that to happen (e.g. all-in-one.yaml) but, sometimes we don't (e.g. E2E tests). - createOperatorNamespace: true - # kubeVersion is the effective Kubernetes version we target when generating the all-in-one.yaml. - kubeVersion: 1.21.0 diff --git a/helm-overrides/k8s-admin-prd-ase1/elastalert2/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/elastalert2/custom-values.yaml deleted file mode 100644 index 21a9dd9..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastalert2/custom-values.yaml +++ /dev/null @@ -1,472 +0,0 @@ -## Chart information -nameOverride: "" -fullnameOverride: "" -namespaceOverride: "elastalert-prd" -commonLabels: {} -commonAnnotations: {} -appKubernetesIoComponent: elastalert2 - -# Folder where Helm can find local rules prior to deployment to the k8s cluster. By default, -# 'rules' folder must be located in the root of the chart directory. Note that this setting -# will override the rules and secretRulesName values. Again, these rules are only read -# during the time of the chart deployment (installation) into the cluster. -# rootRulesFolder: "rules" -# enabledRules: ["deadman_slack", "deadman_pagerduty"] - -# number of replicas to run -replicaCount: 1 - -# update strategy to use (default : RollingUpdate) but can be Recreate -updateStrategy: - type: RollingUpdate - rollingUpdate: {} - -# number of helm release revisions to retain -revisionHistoryLimit: 5 - -# number of seconds for which a newly created Pod should be ready without any of its containers crashing, for it to be considered available. -minReadySeconds: 5 - -# Default internal between alert checks against the elasticsearch datasource, in minutes -runIntervalMins: 1 - -# Location of directory where rules reside -rulesFolder: "/opt/elastalert/rules" - -# Enable/disabe subdirectory scanning for rules -scanSubdirectories: true - -# Default rule buffer duration, in minutes -bufferTimeMins: 15 - -# Amount of time to retry and deliver failed alerts (1440 minutes per day) -alertRetryLimitMins: 2880 - -# Default time before realerting, in minutes -realertIntervalMins: "" - -# For ES 5: The name of the index which stores elastalert 2 statuses, typically elastalert_status -# For ES 6: The prefix of the names of indices which store elastalert 2 statuses, typically elastalert -# -writebackIndex: elastalert - -image: - # docker image - repository: jertel/elastalert2 - # docker image tag - tag: 2.29.0 - pullPolicy: IfNotPresent - pullSecret: "" - -resources: - requests: - memory: 8Gi - cpu: "1" - limits: - memory: 10Gi - cpu: "3" - -# Annotations to be added to deployment -deploymentAnnotations: {} - -# Annotations to be added to pods -podAnnotations: {} - -elasticsearch: - # ECK-managed ES service: -es-http..svc.cluster.local - host: eck-observability-prd-es-http.eck-observability-prd.svc.cluster.local - # elasticsearch port - port: 9200 - # whether or not to connect to es_host using TLS - # TLS is disabled on the ES HTTP layer (selfSignedCertificate.disabled: true in elasticsearch.yaml) - useSsl: "False" - # Username if authenticating to ES with basic auth - username: "elastic" - # Password if authenticating to ES with basic auth - # Get from: kubectl get secret eck-observability-stg-es-elastic-user -n eck-observability-stg -o jsonpath='{.data.elastic}' | base64 -d - password: "qT448rgRqJkIesBerfrcAXH2" - # Specifies an existing secret to be used for the ES username/password - credentialsSecret: "" - # The key in elasticsearch.credentialsSecret that stores the ES password - credentialsSecretUsernameKey: "" - # The key in elasticsearch.credentialsSecret that stores the ES username - credentialsSecretPasswordKey: "" - # whether or not to verify TLS certificates - # False because TLS is disabled on this cluster - verifyCerts: "False" - # Enable certificate based authentication - # path to a PEM certificate to use as the client certificate - # clientCert: "/certs/client.pem" - # path to a private key file to use as the client key - # clientKey: "/certs/client-key.pem" - # path to a CA cert bundle to use to verify SSL connections - # caCerts: "/certs/ca.pem" - # # certs volumes, required to mount ssl certificates when elasticsearch has tls enabled - # certsVolumes: - # - name: es-certs - # secret: - # defaultMode: 420 - # secretName: es-certs - # # mount certs volumes, required to mount ssl certificates when elasticsearch has tls enabled - # certsVolumeMounts: - # - name: es-certs - # mountPath: /certs - # readOnly: true - -# Optional env variables for the pod -optEnv: [] - -## Specify optional additional containers to run alongside the Elastalert2 container. -extraContainers: [] - -## Specify optional additional initContainers to run prior to the Elastalert2 container. -extraInitContainers: [] - -extraConfigOptions: {} - # # Options to propagate to all rules, e.g. a common slack_webhook_url or kibana_url - # # Please note at the time of implementing this value, it will not work for required_locals - # # Which MUST be set at the rule level, these are: ['alert', 'type', 'name', 'index'] - # kibana_url: https://kibana.yourdomain.com - # slack_webhook_url: dummy - -# To load ElastAlert 2 config via secret, uncomment the line below -# secretConfigName: elastalert-config-secret - -# Example of a secret config - -#apiVersion: v1 -#kind: Secret -#metadata: -# name: elastalert-config-secret -#type: Opaque -#stringData: -# elastalert_config: |- -# rules_folder: /opt/elastalert/rules -# scan_subdirectories: false -# run_every: -# minutes: 1 -# buffer_time: -# minutes: 15 -# es_host: elasticsearch -# es_port: 9200 -# writeback_index: elastalert -# use_ssl: False -# verify_certs: True -# alert_time_limit: -# minutes: 2880 -# slack_webhook_url: https://hooks.slack.com/services/xxxx -# slack_channel_override: '#alerts' - - -# To load ElastAlert's rules via secret, uncomment the line below -#secretRulesName: elastalert-rules-secret - -# Additionally, you must specificy which rules to load from the secret -#secretRulesList: [ "rule_1", "rule_2" ] - -# Example of secret rules - -#apiVersion: v1 -#kind: Secret -#metadata: -# name: elastalert-rules-secret -# namespace: elastic-system -#type: Opaque -#stringData: -# rule_1: |- -# name: Rule 1 -# type: frequency -# index: index1-* -# num_events: 3 -# timeframe: -# minutes: 1 -# alert: -# - "slack" -# rule_2: |- -# name: Rule 2 -# type: frequency -# index: index2-* -# num_events: 5 -# timeframe: -# minutes: 10 -# alert: -# - "slack" - -# Command and args override for container e.g. (https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/) -# command: ["YOUR_CUSTOM_COMMAND"] -# args: ["YOUR", "CUSTOM", "ARGS"] - -# specifies the rules volume to be used -rulesVolumeName: "rules" - -# additional rule configurations e.g. (http://elastalert2.readthedocs.io/en/latest/) -rules: - multi_index_doc_count_threshold: |- - --- - name: "High Doc Count Alert - GCP and GKE Indices" - type: frequency - - # 1. Target Index Selection: Combines all indices with these prefixes - index: "gcp-prd-*,gcp-kubeevents-*,gke-mcs-*" - - # 2. Threshold: Total count across all matched indices - num_events: 950000000 - timeframe: - hours: 1 - - # 3. Optimization: Essential for Basic Tier and high doc counts - use_count_query: true - doc_type: "_doc" - - # 4. Filter: Count everything in those indices - filter: - - query: - match_all: {} - - # 5. PagerDuty Action (Configured per your requirements) - alert: - - "pagerduty" - - # Routing and Severity - pagerduty_service_key: "63386d7276d24c08d0b795122bfea0b1" - pagerduty_severity: "critical" - - # Client and Description - pagerduty_client_name: "high doc alert" - pagerduty_description: "High Document Count Alert: Total count across gcp-prd, gcp-kubeevents, and gke-mcs has exceeded 950,000,000." - - # Deduplication Key (to avoid multiple pages for the same spike) - pagerduty_incident_key: "high-doc-count-gcp" - # deadman_slack: |- - # --- - # name: Deadman Switch Slack - # type: frequency - # index: containers-* - # num_events: 3 - # timeframe: - # minutes: 3 - # filter: - # - term: - # message: "deadmanslack" - # alert: - # - "slack" - # slack: - # slack_webhook_url: dummy - # deadman_pagerduty: |- - # --- - # name: Deadman Switch PagerDuty - # type: frequency - # index: containers-* - # num_events: 3 - # timeframe: - # minutes: 3 - # filter: - # - term: - # message: "deadmanpd" - # alert: - # - "pagerduty" - # pagerduty: - # pagerduty_service_key: dummy - # pagerduty_client_name: ElastAlert Deadman Switch - -# Probes configuration -livenessProbe: - enabled: false -readinessProbe: - enabled: false - -serviceAccount: - # Specifies whether a service account should be created - create: true - # Annotations to add to the service account - annotations: {} - # The name of the service account to use. - # If not set and create is true, a name is generated using the fullname template - name: - -# Enable pod security policy -# https://kubernetes.io/docs/concepts/policy/pod-security-policy/ -# DEPRECATED in Kubernetes 1.21 (https://kubernetes.io/blog/2021/04/06/podsecuritypolicy-deprecation-past-present-and-future/) -podSecurityPolicy: - create: false - -securityContext: - runAsNonRoot: true - runAsUser: 1000 - -podSecurityContext: - fsGroup: 1000 - runAsUser: 1000 - runAsGroup: 1000 - -# Support using node selectors and tolerations -nodeSelector: - cloud.google.com/gke-nodepool: np-admin-default-v131-prd-ase1 - team: shared - -# Specify node affinity or anti-affinity specifications -affinity: {} - -# Autoscaling configuration -autoscaling: - enabled: true - minReplicas: 2 - maxReplicas: 5 - targetCPUUtilizationPercentage: 80 - targetMemoryUtilizationPercentage: 80 - -# Optional automatic SMTP mail server credential management. -# smtp_auth: -# username: "" -# password: "" - -extraVolumes: [] - # - name: smtp-auth - # secret: - # secretName: elastalert-smtp-auth - # items: - # - key: smtp_auth.yaml - # path: smtp_auth.yaml - # mode: 0400 - -extraVolumeMounts: [] - # - name: smtp-auth - # mountPath: /opt/elastalert/config-smtp/smtp_auth.yaml - # subPath: smtp_auth.yaml - # readOnly: true - - -## @section Metrics parameters - -## Prometheus metrics -## -metrics: - ## @param metrics.enabled Enable the export of Prometheus metrics - ## - enabled: false - prometheusPort: 8080 - prometheusPortName: http-alt - # Prometheus Exporter defined by port: - prometheusScrapeAnnotations: - prometheus.io/scrape: "true" - prometheus.io/path: "/" - - service: - type: ClusterIP - # clusterIP: "" - # externalTrafficPolicy: Cluster - # loadBalancerIP: "" - # loadBalancerSourceRanges: {} - # nodePorts: "" - - ## Prometheus Operator ServiceMonitor configuration - ## - serviceMonitor: - ## @param metrics.serviceMonitor.enabled Specify if a ServiceMonitor will be deployed for Prometheus Operator - ## - enabled: false - - ## @param metrics.serviceMonitor.namespace Namespace in which Prometheus is running - ## - namespace: "" - - ## @param metrics.serviceMonitor.labels Extra labels for the ServiceMonitor - ## Normally used for prometheus operator to detect the servicemonitor if deployed to different namespace - ## labels: - ## release: prometheus-operator - labels: {} - - ## @param metrics.serviceMonitor.jobLabel The name of the label on the target service to use as the job name in Prometheus - ## - jobLabel: "" - - ## @param metrics.serviceMonitor.interval How frequently to scrape metrics - ## e.g: - ## interval: 10s - ## - interval: "" - ## @param metrics.serviceMonitor.scrapeTimeout Timeout after which the scrape is ended - ## e.g: - ## scrapeTimeout: 10s - ## - scrapeTimeout: "" - ## @param metrics.serviceMonitor.metricRelabelings [array] Specify additional relabeling of metrics - ## metricRelabelings: - ## # Drop GO metrics - ## - sourceLabels: [__name__] - ## regex: go_.* - ## action: drop - ## # Drop python_gc metrics - ## - sourceLabels: [__name__] - ## regex: python_gc.* - ## action: drop - ## # Normalise POD names - ## - sourceLabels: [pod] - ## regex: (.+elastalert2)\-([\w\d]+)\-([\w\d]+) - ## replacement: $1 - ## targetLabel: pod - metricRelabelings: [] - - ## @param metrics.serviceMonitor.relabelings [array] Specify general relabeling - ## - relabelings: [] - ## @param metrics.serviceMonitor.selector Prometheus instance selector labels - ## ref: https://github.com/bitnami/charts/tree/master/bitnami/prometheus-operator#prometheus-configuration - ## - selector: {} - - ## PrometheusRule CRD configuration - ## - prometheusRule: - ## @param metrics.prometheusRule.enabled If `true`, creates a Prometheus Operator PrometheusRule (also requires `metrics.enabled` to be `true`) - ## - enabled: false - ## @param metrics.prometheusRule.namespace Namespace in which the PrometheusRule CRD is created - ## - namespace: "" - - ## @param metrics.prometheusRule.additionalLabels Additional labels for the prometheusRule - ## to be detected by prometheus-operator - ## additionalLabels: - ## release: prometheus-operator - additionalLabels: {} - - ## @param metrics.prometheusRule.rules Prometheus Rules for ElastAlert 2. - ## These are just examples rules, please adapt them to your needs. - ## rules: |- - ## groups: - ## - name: elastalert - ## rules: - ## - alert: elastalert Pod down - ## annotations: - ## description: Prometheus is unable to scrape metrics service. Check pod logs for details - ## summary: elastalert POD is down - ## expr: up{service="{{ template "common.names.servicename" . }}",container="elastalert"} == 0 - ## for: 5m - ## labels: - ## severity: critical - ## production: 'True' - ## - alert: elastalert file descriptors use - ## annotations: - ## description: Elastalert pod nearly exhausting file descriptors - ## summary: too many file descriptors used - ## expr: |- - ## process_open_fds{service="{{ template "common.names.servicename" . }}",container="elastalert"} - ## / - ## process_max_fds{service="{{ template "common.names.servicename" . }}",container="elastalert"} - ## > 0.9 - ## for: 3m - ## labels: - ## severity: critical - ## production: 'True' - ## - alert: elastalert scrapes failing - ## annotations: - ## description: Elastalert is not scraping for a rule {{ "{{" }} $labels.rule_name {{ "}}" }} - ## summary: scrapes for rule stalled {{ "{{" }} $labels.rule_name {{ "}}" }} - ## expr: |- - ## rate(elastalert_scrapes_total{service="{{ template "common.names.servicename" . }}",container="elastalert"}[1m]) == 0 - ## for: 5m - ## labels: - ## severity: critical - ## production: 'True' - rules: [] diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/argo-launch-eck-observability-monitoring.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/argo-launch-eck-observability-monitoring.yaml deleted file mode 100644 index 28cf14a..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/argo-launch-eck-observability-monitoring.yaml +++ /dev/null @@ -1,38 +0,0 @@ -# Argo CD Application: dedicated monitoring ES + Kibana for Stack Monitoring (metrics store). -# Deploy after ECK operator; same namespace as main observability (eck-observability-prd) ---- -apiVersion: argoproj.io/v1alpha1 -kind: Application -metadata: - name: eck-observability-monitoring-k8s-admin-prd-ase1 - namespace: argocd-prd - finalizers: - - resources-finalizer.argocd.argoproj.io - labels: - bu: infra - team: devops - env: prd - cluster: k8s-admin-prd-ase1 -spec: - project: default - source: - repoURL: https://github.com/Meesho/devops-infra-helm-charts - path: helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring - targetRevision: main - directory: - recurse: false - include: "*.yaml" - destination: - server: "" - name: k8s-admin-prd-ase1 - namespace: eck-observability-prd - syncPolicy: - syncOptions: - - CreateNamespace=true - - ServerSideApply=true - retry: - limit: 5 - backoff: - duration: 5s - factor: 2 - maxDuration: 3m diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/argo-launch.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/argo-launch.yaml deleted file mode 100644 index ed2e94b..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/argo-launch.yaml +++ /dev/null @@ -1,45 +0,0 @@ -# Argo CD Application: ECK observability manifests (Elasticsearch, Kibana, APM, HTTPProxy, SA, Namespace). -# Deploys to cluster: k8s-admin-prd-ase1 -# -# Apply: -# kubectl apply -f argo-launch.yaml -n argocd -# -# (ECK operator Helm chart is separate — install elastic-system operator before this app syncs.) ---- -apiVersion: argoproj.io/v1alpha1 -kind: Application -metadata: - name: eck-observability-k8s-admin-prd-ase1 - namespace: argocd-prd - finalizers: - - resources-finalizer.argocd.argoproj.io - labels: - bu: infra - team: devops - env: prd - cluster: k8s-admin-prd-ase1 -spec: - project: default - source: - repoURL: https://github.com/Meesho/devops-infra-helm-charts - path: helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability - targetRevision: main - directory: - recurse: false - include: "*.yaml" - # Example secret is not applied from git; create the real Secret separately - exclude: "*example.yaml" - destination: - server: "" - name: k8s-admin-prd-ase1 - namespace: eck-observability-prd - syncPolicy: - syncOptions: - - CreateNamespace=true - - ServerSideApply=true - retry: - limit: 5 - backoff: - duration: 5s - factor: 2 - maxDuration: 3m diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/elasticsearch.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/elasticsearch.yaml deleted file mode 100644 index 71bafd5..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/elasticsearch.yaml +++ /dev/null @@ -1,63 +0,0 @@ -# Dedicated monitoring Elasticsearch for Stack Monitoring metrics (ECK observability workload). -# Namespace: prd-eck-observability (same as main observability stack). -# Pattern mirrors eck-monitoring (single nodeSet); 3 nodes × 90Gi SSD (gke-pd-ssd). -# Align nodeSelector/tolerations with your GKE pool (same as prd-eck-observability by default). -apiVersion: elasticsearch.k8s.elastic.co/v1 -kind: Elasticsearch -metadata: - name: eck-observability-monitoring-prd - namespace: eck-observability-prd -spec: - version: 9.3.1 - nodeSets: - - name: default - count: 3 - volumeClaimTemplates: - - metadata: - name: elasticsearch-data - spec: - storageClassName: gke-pd-ssd - accessModes: - - ReadWriteOnce - resources: - requests: - storage: 500Gi - podTemplate: - metadata: - labels: - elasticsearch.k8s.elastic.co/service-account: eck-observability-monitoring-es-sa-prd - app: elasticsearch-monitoring - tier: monitoring - annotations: - cluster-autoscaler.kubernetes.io/safe-to-evict: "false" - spec: - serviceAccountName: eck-observability-monitoring-es-sa-prd - tolerations: - - effect: NoSchedule - key: elastic-observability-monitoring-nodes - operator: Equal - value: "true" - nodeSelector: - elastic-observability-monitoring-nodes: "true" - initContainers: - - name: sysctl - securityContext: - privileged: true - runAsUser: 0 - command: ["sh", "-c", "sysctl -w vm.max_map_count=262144"] - containers: - - name: elasticsearch - env: - - name: ES_JAVA_OPTS - value: "-Xms22g -Xmx22g" - resources: - requests: - memory: 107Gi - cpu: "20" - limits: - memory: 107Gi - cpu: "25" - http: - tls: - selfSignedCertificate: - disabled: true diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/ingress-es.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/ingress-es.yaml deleted file mode 100644 index 0e150c4..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/ingress-es.yaml +++ /dev/null @@ -1,24 +0,0 @@ -apiVersion: networking.k8s.io/v1 -kind: Ingress -metadata: - name: es-prd-observability-monitoring-nginx - namespace: eck-observability-prd - annotations: - kubernetes.io/ingress.class: nginx-internal - nginx.ingress.kubernetes.io/ssl-redirect: "false" - nginx.ingress.kubernetes.io/proxy-read-timeout: "300" - nginx.ingress.kubernetes.io/proxy-send-timeout: "300" - nginx.ingress.kubernetes.io/proxy-body-size: "0" -spec: - ingressClassName: nginx-internal - rules: - - host: es-prd-observability-monitoring.prd.meesho.int - http: - paths: - - path: / - pathType: Prefix - backend: - service: - name: eck-observability-monitoring-prd-es-http - port: - number: 9200 diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/ingress-kibana.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/ingress-kibana.yaml deleted file mode 100644 index 7cc8e1d..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/ingress-kibana.yaml +++ /dev/null @@ -1,24 +0,0 @@ -apiVersion: networking.k8s.io/v1 -kind: Ingress -metadata: - name: kibana-prd-observability-monitoring-nginx - namespace: eck-observability-prd - annotations: - kubernetes.io/ingress.class: nginx-internal - nginx.ingress.kubernetes.io/ssl-redirect: "false" - nginx.ingress.kubernetes.io/proxy-read-timeout: "300" - nginx.ingress.kubernetes.io/proxy-send-timeout: "300" - nginx.ingress.kubernetes.io/proxy-body-size: "0" -spec: - ingressClassName: nginx-internal - rules: - - host: kibana-prd-observability-monitoring.prd.meesho.int - http: - paths: - - path: / - pathType: Prefix - backend: - service: - name: kibana-observability-monitoring-prd-kb-http - port: - number: 5601 diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/kibana-hpa.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/kibana-hpa.yaml deleted file mode 100644 index 930905d..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/kibana-hpa.yaml +++ /dev/null @@ -1,38 +0,0 @@ -apiVersion: autoscaling/v2 -kind: HorizontalPodAutoscaler -metadata: - name: kibana-observability-monitoring-prd-hpa - namespace: eck-observability-prd -spec: - scaleTargetRef: - apiVersion: apps/v1 - kind: Deployment - name: kibana-observability-monitoring-prd-kb - minReplicas: 1 - maxReplicas: 5 - metrics: - - type: Resource - resource: - name: cpu - target: - type: Utilization - averageUtilization: 70 - - type: Resource - resource: - name: memory - target: - type: Utilization - averageUtilization: 80 - behavior: - scaleDown: - stabilizationWindowSeconds: 300 - policies: - - type: Percent - value: 50 - periodSeconds: 60 - scaleUp: - stabilizationWindowSeconds: 30 - policies: - - type: Percent - value: 100 - periodSeconds: 30 diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/kibana.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/kibana.yaml deleted file mode 100644 index d15e622..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/kibana.yaml +++ /dev/null @@ -1,47 +0,0 @@ -# Kibana for the monitoring cluster (Stack Monitoring UI / metrics exploration). -apiVersion: kibana.k8s.elastic.co/v1 -kind: Kibana -metadata: - name: kibana-observability-monitoring-prd - namespace: eck-observability-prd -spec: - version: 9.3.1 - config: - server.publicBaseUrl: http://kibana-prd-observability-monitoring.prd.meesho.int - monitoring.ui.ccs.enabled: false - count: 1 - elasticsearchRef: - name: eck-observability-monitoring-prd - podTemplate: - metadata: - annotations: - cluster-autoscaler.kubernetes.io/safe-to-evict: "false" - spec: - tolerations: - - effect: NoSchedule - key: elastic-observability-monitoring-common - operator: Equal - value: "true" - nodeSelector: - elastic-observability-monitoring-common: "true" - containers: - - name: kibana - readinessProbe: - httpGet: - path: /api/status - port: 5601 - initialDelaySeconds: 30 - periodSeconds: 10 - failureThreshold: 3 - resources: - requests: - memory: 40Gi - cpu: "9" - limits: - memory: 40Gi - cpu: "12" - - http: - tls: - selfSignedCertificate: - disabled: true diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/sc.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/sc.yaml deleted file mode 100644 index 87bb490..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/sc.yaml +++ /dev/null @@ -1,14 +0,0 @@ -# pd-ssd - SSD-class block storage on GKE (pd.csi.storage.gke.io). -# Apply once per cluster before Elasticsearch PVCs. -# See: https://cloud.google.com/kubernetes-engine/docs/concepts/persistent-volumes -apiVersion: storage.k8s.io/v1 -kind: StorageClass -metadata: - name: gke-pd-ssd -provisioner: pd.csi.storage.gke.io -parameters: - type: pd-ssd - replication-type: none -volumeBindingMode: WaitForFirstConsumer -allowVolumeExpansion: true -reclaimPolicy: Retain diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/serviceaccount.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/serviceaccount.yaml deleted file mode 100644 index 52a8bba..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability-monitoring/serviceaccount.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: v1 -kind: ServiceAccount -metadata: - name: eck-observability-monitoring-es-sa-prd - namespace: eck-observability-prd diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/apm-hpa.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/apm-hpa.yaml deleted file mode 100644 index 08ba172..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/apm-hpa.yaml +++ /dev/null @@ -1,38 +0,0 @@ -apiVersion: autoscaling/v2 -kind: HorizontalPodAutoscaler -metadata: - name: apm-eck-observability-prd-hpa - namespace: eck-observability-prd -spec: - scaleTargetRef: - apiVersion: apps/v1 - kind: Deployment - name: apm-eck-observability-prd-apm-server - minReplicas: 3 - maxReplicas: 5 - metrics: - - type: Resource - resource: - name: cpu - target: - type: Utilization - averageUtilization: 70 - - type: Resource - resource: - name: memory - target: - type: Utilization - averageUtilization: 80 - behavior: - scaleDown: - stabilizationWindowSeconds: 300 - policies: - - type: Percent - value: 50 - periodSeconds: 60 - scaleUp: - stabilizationWindowSeconds: 30 - policies: - - type: Percent - value: 100 - periodSeconds: 30 diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/apm-httpproxy.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/apm-httpproxy.yaml deleted file mode 100644 index 7e0ffda..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/apm-httpproxy.yaml +++ /dev/null @@ -1,23 +0,0 @@ -# APM Server (HTTP + OTLP/gRPC on 8200) — Contour HTTPProxy. -# For OTLP gRPC, uses protocol h2c (HTTP/2 Cleartext); works with both gRPC and HTTP agents. -apiVersion: projectcontour.io/v1 -kind: HTTPProxy -metadata: - name: apm-prd-observability - namespace: eck-observability-prd - annotations: - projectcontour.io/ingress.class: contour-internal -spec: - ingressClassName: contour-internal - virtualhost: - fqdn: apm-eck-observability.prd.meesho.int - routes: - - conditions: - - prefix: / - services: - - name: apm-eck-observability-prd-apm-http - port: 8200 - protocol: h2c - timeoutPolicy: - response: "300s" - idle: "300s" diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/apm-server.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/apm-server.yaml deleted file mode 100644 index f80b1f1..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/apm-server.yaml +++ /dev/null @@ -1,40 +0,0 @@ -# APM Server for eck-observability-prd: traces and APM data land in this Elasticsearch cluster. -apiVersion: apm.k8s.elastic.co/v1 -kind: ApmServer -metadata: - name: apm-eck-observability-prd - namespace: eck-observability-prd -spec: - version: 9.3.1 - count: 3 - elasticsearchRef: - name: eck-observability-prd - namespace: eck-observability-prd - kibanaRef: - name: kibana-eck-observability-prd - namespace: eck-observability-prd - podTemplate: - metadata: - annotations: - cluster-autoscaler.kubernetes.io/safe-to-evict: "false" - spec: - nodeSelector: - elastic-observability-common-nodes: "true" - tolerations: - - effect: NoSchedule - key: elastic-observability-common-nodes - operator: Equal - value: "true" - containers: - - name: apm-server - resources: - requests: - memory: 50Gi - cpu: 26 - limits: - memory: 50Gi - cpu: 29 - http: - tls: - selfSignedCertificate: - disabled: true diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/elasticsearch.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/elasticsearch.yaml deleted file mode 100644 index 1c011d5..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/elasticsearch.yaml +++ /dev/null @@ -1,181 +0,0 @@ -# Elasticsearch for observability: logs, traces (via APM), hot/warm tiers. -# Stack monitoring: metrics + logs ship to eck-observability-monitoring-prd (ECK-managed ref). -# Topology: 3× (master + data_hot + ingest), 2× (data_warm + ingest), 6g heap, 500Gi disk per node. -# Tolerations: align with your GKE node pool taint (key/value below). -# ILM: configure index templates to route hot → warm (data_hot / data_warm) in Kibana / API. -# SSO: Google login is handled at nginx + oauth2-proxy (ingress), not Elasticsearch OIDC (Platinum). -apiVersion: elasticsearch.k8s.elastic.co/v1 -kind: Elasticsearch -metadata: - name: eck-observability-prd - namespace: eck-observability-prd -spec: - version: 9.3.1 - monitoring: - metrics: - elasticsearchRefs: - - name: eck-observability-monitoring-prd - namespace: eck-observability-prd - logs: - elasticsearchRefs: - - name: eck-observability-monitoring-prd - namespace: eck-observability-prd - nodeSets: - # 3 nodes: master-eligible + data_hot + ingest (schedule on tainted pool) - - name: hot - count: 9 - config: - node.roles: ["data_hot", "ingest", "data_content", "transform"] - volumeClaimTemplates: - - metadata: - name: elasticsearch-data - spec: - storageClassName: gke-hyperdisk-balanced-35k - accessModes: - - ReadWriteOnce - resources: - requests: - storage: 4Ti - podTemplate: - metadata: - labels: - elasticsearch.k8s.elastic.co/service-account: eck-observability-es-sa-prd - elasticsearch.k8s.elastic.co/nodeset: hot - elasticsearch.k8s.elastic.co/tier: hot-warm-data - elasticsearch.k8s.elastic.co/tier22: hot-warm-data-22 - annotations: - cluster-autoscaler.kubernetes.io/safe-to-evict: "false" - spec: - serviceAccountName: eck-observability-es-sa-prd - # Tolerations for dedicated ES node pool (edit key/value to match your taint) - tolerations: - - effect: NoSchedule - key: elastic-observability-hot-nodes - operator: Equal - value: "true" - nodeSelector: - elastic-observability-hot-nodes: "true" - initContainers: - - name: sysctl - securityContext: - privileged: true - runAsUser: 0 - command: ['sh', '-c', 'sysctl -w vm.max_map_count=262144'] - containers: - - name: elasticsearch - env: - - name: ES_JAVA_OPTS - value: "-Xms31g -Xmx31g" - resources: - requests: - memory: 110Gi - cpu: "26" - limits: - memory: 110Gi - cpu: "28" - - # 2 nodes: data_warm + ingest (schedule on tainted pool) - - name: warm - count: 6 - config: - node.roles: ["data_warm", "ingest", "data_content"] - volumeClaimTemplates: - - metadata: - name: elasticsearch-data - spec: - storageClassName: gke-hyperdisk-ssd - accessModes: - - ReadWriteOnce - resources: - requests: - storage: 6.5Ti - podTemplate: - metadata: - labels: - elasticsearch.k8s.elastic.co/service-account: eck-observability-es-sa-prd - elasticsearch.k8s.elastic.co/nodeset: warm - elasticsearch.k8s.elastic.co/tier: hot-warm-data - annotations: - cluster-autoscaler.kubernetes.io/safe-to-evict: "false" - spec: - serviceAccountName: eck-observability-es-sa-prd - tolerations: - - effect: NoSchedule - key: elastic-observability-warm-nodes - operator: Equal - value: "true" - nodeSelector: - elastic-observability-warm-nodes: "true" - initContainers: - - name: sysctl - securityContext: - privileged: true - runAsUser: 0 - command: ['sh', '-c', 'sysctl -w vm.max_map_count=262144'] - containers: - - name: elasticsearch - env: - - name: ES_JAVA_OPTS - value: "-Xms31g -Xmx31g" - resources: - requests: - memory: 107Gi - cpu: "24" - limits: - memory: 107Gi - cpu: "26" - - # 3 nodes: master-only (dedicated cluster state management) - - name: master - count: 3 - config: - node.roles: ["master"] - volumeClaimTemplates: - - metadata: - name: elasticsearch-data - spec: - storageClassName: gke-hyperdisk-ssd - accessModes: - - ReadWriteOnce - resources: - requests: - storage: 200Gi - podTemplate: - metadata: - labels: - elasticsearch.k8s.elastic.co/service-account: eck-observability-es-sa-prd - elasticsearch.k8s.elastic.co/nodeset: master - annotations: - cluster-autoscaler.kubernetes.io/safe-to-evict: "false" - spec: - serviceAccountName: eck-observability-es-sa-prd - tolerations: - - effect: NoSchedule - key: elastic-observability-master-nodes - operator: Equal - value: "true" - nodeSelector: - elastic-observability-master-nodes: "true" - initContainers: - - name: sysctl - securityContext: - privileged: true - runAsUser: 0 - command: ['sh', '-c', 'sysctl -w vm.max_map_count=262144'] - containers: - - name: elasticsearch - env: - - name: ES_JAVA_OPTS - value: "-Xms5g -Xmx5g" - resources: - requests: - memory: 10Gi - cpu: "5" - limits: - memory: 10Gi - cpu: "6" - - http: - tls: - selfSignedCertificate: - disabled: true diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/es-hot-warm-service.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/es-hot-warm-service.yaml deleted file mode 100644 index 7d5cd5a..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/es-hot-warm-service.yaml +++ /dev/null @@ -1,19 +0,0 @@ -apiVersion: v1 -kind: Service -metadata: - name: eck-observability-prd-es-hot-warm - namespace: eck-observability-prd - labels: - app: elasticsearch - elasticsearch.k8s.elastic.co/cluster-name: eck-observability-prd - elasticsearch.k8s.elastic.co/tier: hot-warm-data -spec: - type: ClusterIP - ports: - - port: 9200 - targetPort: 9200 - protocol: TCP - name: http - selector: - elasticsearch.k8s.elastic.co/cluster-name: eck-observability-prd - elasticsearch.k8s.elastic.co/tier: hot-warm-data diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/es-httpproxy.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/es-httpproxy.yaml deleted file mode 100644 index 95e0ccd..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/es-httpproxy.yaml +++ /dev/null @@ -1,21 +0,0 @@ -apiVersion: projectcontour.io/v1 -kind: HTTPProxy -metadata: - name: es-prd-observability - namespace: eck-observability-prd - annotations: - projectcontour.io/ingress.class: contour-internal -spec: - ingressClassName: contour-internal - virtualhost: - fqdn: es-prd-observability.prd.meesho.int - routes: - - conditions: - - prefix: / - services: - # Unified ES HTTP service (no dedicated coordinating/client node set) - - name: eck-observability-prd-es-http - port: 9200 - timeoutPolicy: - response: "300s" - idle: "300s" diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/httpproxy-kibana-oauth.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/httpproxy-kibana-oauth.yaml deleted file mode 100644 index e7df30d..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/httpproxy-kibana-oauth.yaml +++ /dev/null @@ -1,35 +0,0 @@ -# HTTPProxy for Kibana + OAuth2-proxy -# Routes /oauth2/* to oauth2-proxy (auth endpoints) -# Routes all other paths to Kibana -apiVersion: projectcontour.io/v1 -kind: HTTPProxy -metadata: - name: kibana-prd-observability-oauth - namespace: eck-observability-prd - annotations: - projectcontour.io/ingress.class: contour-internal -spec: - ingressClassName: contour-internal - virtualhost: - fqdn: kibana-prd-observability.prd.meesho.int - - routes: - # Route 1: OAuth2-proxy auth endpoints (/oauth2/auth, /oauth2/start, /oauth2/callback) - - conditions: - - prefix: /oauth2 - services: - - name: oauth2-proxy-kibana - port: 4180 - timeoutPolicy: - response: "30s" - idle: "30s" - - # Route 2: All other routes go to Kibana - - conditions: - - prefix: / - services: - - name: kibana-eck-observability-prd-kb-http - port: 5601 - timeoutPolicy: - response: "300s" - idle: "300s" diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/httpproxy.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/httpproxy.yaml deleted file mode 100644 index 60c7a04..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/httpproxy.yaml +++ /dev/null @@ -1,20 +0,0 @@ -apiVersion: projectcontour.io/v1 -kind: HTTPProxy -metadata: - name: kibana-prd-observability - namespace: eck-observability-prd - annotations: - projectcontour.io/ingress.class: contour-internal -spec: - ingressClassName: contour-internal - virtualhost: - fqdn: kibana-prd-observability.prd.meesho.int - routes: - - conditions: - - prefix: / - services: - - name: kibana-eck-observability-prd-kb-http - port: 5601 - timeoutPolicy: - response: "300s" - idle: "300s" diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/ingress-apm.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/ingress-apm.yaml deleted file mode 100644 index 7099bd9..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/ingress-apm.yaml +++ /dev/null @@ -1,27 +0,0 @@ -# APM Server (HTTP + OTLP/gRPC on 8200) — nginx-internal (alternative to Contour HTTPProxy). -# For OTLP gRPC, nginx ingress may require backend-protocol GRPC; tune if agents use HTTP only. -apiVersion: networking.k8s.io/v1 -kind: Ingress -metadata: - name: apm-prd-observability-nginx - namespace: eck-observability-prd - annotations: - kubernetes.io/ingress.class: nginx-internal - nginx.ingress.kubernetes.io/ssl-redirect: "false" - nginx.ingress.kubernetes.io/backend-protocol: "GRPC" - nginx.ingress.kubernetes.io/proxy-read-timeout: "300" - nginx.ingress.kubernetes.io/proxy-send-timeout: "300" - nginx.ingress.kubernetes.io/proxy-body-size: "0" -spec: - ingressClassName: nginx-internal - rules: - - host: apm-eck-observability.prd.meesho.int - http: - paths: - - path: / - pathType: Prefix - backend: - service: - name: apm-eck-observability-prd-apm-http - port: - number: 8200 diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/ingress-es.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/ingress-es.yaml deleted file mode 100644 index 19f6d54..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/ingress-es.yaml +++ /dev/null @@ -1,25 +0,0 @@ -# Elasticsearch HTTP API — nginx-internal (alternative to Contour HTTPProxy). -apiVersion: networking.k8s.io/v1 -kind: Ingress -metadata: - name: es-prd-observability-nginx - namespace: eck-observability-prd - annotations: - kubernetes.io/ingress.class: nginx-internal - nginx.ingress.kubernetes.io/ssl-redirect: "false" - nginx.ingress.kubernetes.io/proxy-read-timeout: "300" - nginx.ingress.kubernetes.io/proxy-send-timeout: "300" - nginx.ingress.kubernetes.io/proxy-body-size: "0" -spec: - ingressClassName: nginx-internal - rules: - - host: es-prd-observability.prd.meesho.int - http: - paths: - - path: / - pathType: Prefix - backend: - service: - name: eck-observability-prd-es-http - port: - number: 9200 diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/ingress-kibana.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/ingress-kibana.yaml deleted file mode 100644 index 318bc05..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/ingress-kibana.yaml +++ /dev/null @@ -1,50 +0,0 @@ -# Kibana — nginx-internal with Google OAuth via oauth2-proxy. -# Ref: https://medium.com/@hrlimaye/google-oauth2-with-kubernetes-nginx-controller-d7a0a3e62e1b -# -# nginx auth_request flow: -# 1. Request hits this ingress for path / -# 2. nginx makes internal subrequest to auth-url (cluster-internal DNS, always resolvable from nginx pod) -# 3. oauth2-proxy returns 202 (valid cookie) -> request passes to Kibana -# oauth2-proxy returns 401 (no/bad cookie) -> nginx redirects browser to auth-signin -# 4. auth-signin uses $host (browser redirect, not internal subrequest - $host is fine here) -# -> oauth2-proxy starts Google login flow -> /oauth2/callback -> sets cookie -> back to Kibana -# -# Why auth-url uses cluster DNS (not $host): -# auth-url is an nginx internal subrequest - nginx tries to resolve it from inside the pod. -# External hostnames like prd.meesho.int may not resolve from within the nginx controller pod. -# auth-signin is a browser redirect, so $host works fine there. -# -# Requires: -# - Secret oauth2-proxy-google applied (oauth2-proxy-secret.example.yaml) -# - oauth2-proxy Deployment + Service (oauth2-proxy.yaml) -# - /oauth2 Ingress on same host (ingress-oauth2-proxy.yaml) -apiVersion: networking.k8s.io/v1 -kind: Ingress -metadata: - name: kibana-prd-observability-nginx - namespace: eck-observability-prd - annotations: - kubernetes.io/ingress.class: nginx-internal - nginx.ingress.kubernetes.io/ssl-redirect: "false" - nginx.ingress.kubernetes.io/proxy-read-timeout: "300" - nginx.ingress.kubernetes.io/proxy-send-timeout: "300" - nginx.ingress.kubernetes.io/proxy-body-size: "0" - nginx.ingress.kubernetes.io/proxy-buffer-size: "16k" - # auth-url: cluster-internal DNS so nginx can always reach oauth2-proxy for the subrequest. - nginx.ingress.kubernetes.io/auth-url: "http://oauth2-proxy-kibana.eck-observability-prd.svc.cluster.local:4180/oauth2/auth" - # auth-signin: browser redirect — $host resolves to the request Host header in the browser. - nginx.ingress.kubernetes.io/auth-signin: "http://$host/oauth2/start?rd=$escaped_request_uri" - nginx.ingress.kubernetes.io/auth-response-headers: "X-Auth-Request-Email, X-Auth-Request-User" -spec: - ingressClassName: nginx-internal - rules: - - host: kibana-prd-observability.prd.meesho.int - http: - paths: - - path: / - pathType: Prefix - backend: - service: - name: kibana-eck-observability-prd-kb-http - port: - number: 5601 diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/ingress-oauth2-proxy.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/ingress-oauth2-proxy.yaml deleted file mode 100644 index f0f4d23..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/ingress-oauth2-proxy.yaml +++ /dev/null @@ -1,25 +0,0 @@ -# oauth2-proxy routes (/oauth2/*) on the same host as Kibana. -# No auth_request on this Ingress — otherwise the /oauth2/start and /oauth2/callback -# paths would loop trying to authenticate themselves. -# Ref: https://medium.com/@hrlimaye/google-oauth2-with-kubernetes-nginx-controller-d7a0a3e62e1b -apiVersion: networking.k8s.io/v1 -kind: Ingress -metadata: - name: oauth2-proxy-kibana-nginx - namespace: eck-observability-prd - annotations: - kubernetes.io/ingress.class: nginx-internal - nginx.ingress.kubernetes.io/ssl-redirect: "false" -spec: - ingressClassName: nginx-internal - rules: - - host: kibana-prd-observability.prd.meesho.int - http: - paths: - - path: /oauth2 - pathType: Prefix - backend: - service: - name: oauth2-proxy-kibana - port: - number: 4180 diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/kibana-hpa.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/kibana-hpa.yaml deleted file mode 100644 index 322a093..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/kibana-hpa.yaml +++ /dev/null @@ -1,38 +0,0 @@ -apiVersion: autoscaling/v2 -kind: HorizontalPodAutoscaler -metadata: - name: kibana-eck-observability-prd-hpa - namespace: eck-observability-prd -spec: - scaleTargetRef: - apiVersion: apps/v1 - kind: Deployment - name: kibana-eck-observability-prd-kb - minReplicas: 1 - maxReplicas: 5 - metrics: - - type: Resource - resource: - name: cpu - target: - type: Utilization - averageUtilization: 70 - - type: Resource - resource: - name: memory - target: - type: Utilization - averageUtilization: 80 - behavior: - scaleDown: - stabilizationWindowSeconds: 300 - policies: - - type: Percent - value: 50 - periodSeconds: 60 - scaleUp: - stabilizationWindowSeconds: 30 - policies: - - type: Percent - value: 100 - periodSeconds: 30 diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/kibana.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/kibana.yaml deleted file mode 100644 index 70ffd86..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/kibana.yaml +++ /dev/null @@ -1,61 +0,0 @@ -# Anonymous auth: Kibana logs into ES as credentials.username using the password from Secret -# kibana-anonymous-sso (required; anonymous cannot work without it). Must match that ES user. -# Google SSO is only at the ingress (oauth2-proxy). See kibana-anonymous-sso.example.yaml. -apiVersion: kibana.k8s.elastic.co/v1 -kind: Kibana -metadata: - name: kibana-eck-observability-prd - namespace: eck-observability-prd -spec: - version: 9.3.1 - secureSettings: - - secretName: kibana-anonymous-sso - config: - server.publicBaseUrl: http://kibana-prd-observability.prd.meesho.int - monitoring.ui.ccs.enabled: false - xpack.security.authc.providers: - anonymous.anonymous1: - order: 0 - credentials: - username: kibana-anonymous-viewer - password: "${xpack.security.authc.providers.anonymous.anonymous1.credentials.password}" - basic.basic1: - order: 1 - count: 1 - elasticsearchRef: - name: eck-observability-prd - podTemplate: - metadata: - annotations: - cluster-autoscaler.kubernetes.io/safe-to-evict: "false" - spec: - tolerations: - - effect: NoSchedule - key: elastic-observability-common-nodes - operator: Equal - value: "true" - nodeSelector: - elastic-observability-common-nodes: "true" - containers: - - name: kibana - # Override ECK's default readiness probe (/login → 404 when anonymous auth is enabled). - # /api/status returns 200 whenever Kibana is healthy, regardless of auth config. - readinessProbe: - httpGet: - path: /api/status - port: 5601 - initialDelaySeconds: 30 - periodSeconds: 10 - failureThreshold: 3 - resources: - requests: - memory: 25Gi - cpu: 10 - limits: - memory: 25Gi - cpu: 13 - - http: - tls: - selfSignedCertificate: - disabled: true diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/namespace.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/namespace.yaml deleted file mode 100644 index 419f901..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/namespace.yaml +++ /dev/null @@ -1,6 +0,0 @@ -# apiVersion: v1 -# kind: Namespace -# metadata: -# name: eck-observability-prd -# annotations: -# argocd.argoproj.io/sync-wave: "-1" diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/oauth2-proxy.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/oauth2-proxy.yaml deleted file mode 100644 index 86ade68..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/oauth2-proxy.yaml +++ /dev/null @@ -1,147 +0,0 @@ -# oauth2-proxy: Google OAuth at the nginx ingress layer. -# Ref: https://medium.com/@hrlimaye/google-oauth2-with-kubernetes-nginx-controller-d7a0a3e62e1b -# -# Flow: -# 1. Request hits nginx ingress for Kibana (ingress-kibana.yaml). -# 2. nginx calls auth-url -> oauth2-proxy /oauth2/auth (200 = pass, 401 = redirect to signin). -# 3. On 401, nginx redirects to auth-signin (oauth2-proxy /oauth2/start) -> Google login. -# 4. Google redirects back to /oauth2/callback (served by ingress-oauth2-proxy.yaml). -# 5. Authenticated request proceeds to Kibana. -# -# Requires Secret "oauth2-proxy-google" (see oauth2-proxy-secret.example.yaml). -# Google OAuth app: Authorized redirect URI must be set to: -# http://kibana-prd-observability.prd.meesho.int/oauth2/callback -apiVersion: v1 -kind: Service -metadata: - name: oauth2-proxy-kibana - namespace: eck-observability-prd - labels: - app: oauth2-proxy-kibana -spec: - type: ClusterIP - ports: - - name: http - port: 4180 - targetPort: 4180 - selector: - app: oauth2-proxy-kibana ---- -apiVersion: apps/v1 -kind: Deployment -metadata: - name: oauth2-proxy-kibana - namespace: eck-observability-prd - labels: - app: oauth2-proxy-kibana -spec: - replicas: 1 - selector: - matchLabels: - app: oauth2-proxy-kibana - template: - metadata: - labels: - app: oauth2-proxy-kibana - annotations: - cluster-autoscaler.kubernetes.io/safe-to-evict: "false" - spec: - tolerations: - - effect: NoSchedule - key: elastic-observability-common-nodes - operator: Equal - value: "true" - nodeSelector: - elastic-observability-common-nodes: "true" - containers: - - name: oauth2-proxy - image: quay.io/oauth2-proxy/oauth2-proxy:v7.6.0 - args: - - --provider=google - - --http-address=0.0.0.0:4180 - # upstream=static://200 means oauth2-proxy only handles /oauth2/* paths; - # actual proxying to Kibana is done by nginx, not oauth2-proxy. - - --upstream=static://200 - - --skip-provider-button=true - # Allow any Google-authenticated user; restrict by setting --email-domain=meesho.com - - --email-domain=* - - --cookie-secure=false - - --set-xauthrequest=true - - --pass-access-token=false - - --redirect-url=http://kibana-prd-observability.prd.meesho.int/oauth2/callback - envFrom: - - secretRef: - name: oauth2-proxy-google - ports: - - name: http - containerPort: 4180 - readinessProbe: - httpGet: - path: /ping - port: 4180 - initialDelaySeconds: 5 - periodSeconds: 10 - resources: - requests: - cpu: 9 - memory: 25Gi - limits: - cpu: 13 - memory: 25Gi ---- -# HorizontalPodAutoscaler for oauth2-proxy-kibana Deployment -apiVersion: autoscaling/v2 -kind: HorizontalPodAutoscaler -metadata: - name: oauth2-proxy-kibana-hpa - namespace: eck-observability-prd -spec: - scaleTargetRef: - apiVersion: apps/v1 - kind: Deployment - name: oauth2-proxy-kibana - minReplicas: 1 - maxReplicas: 10 - metrics: - # CPU-based scaling: target 70% CPU utilization - - type: Resource - resource: - name: cpu - target: - type: Utilization - averageUtilization: 70 - # Memory-based scaling: target 80% memory utilization - - type: Resource - resource: - name: memory - target: - type: Utilization - averageUtilization: 80 - behavior: - scaleDown: - stabilizationWindowSeconds: 300 - policies: - - type: Percent - value: 50 - periodSeconds: 60 - scaleUp: - stabilizationWindowSeconds: 30 - policies: - - type: Percent - value: 100 - periodSeconds: 30 - - type: Pods - value: 2 - periodSeconds: 60 - - -# kubectl exec -it eck-observability-prd-es-hot-0 -n eck-observability-prd \ -# -- curl -s -u "elastic:$(kubectl get secret eck-observability-prd-es-elastic-user -n eck-observability-prd -o jsonpath='{.data.elastic}' | base64 -d)" \ -# -X POST "http://localhost:9200/_security/user/kibana-anonymous-viewer" \ -# -H "Content-Type: application/json" \ -# -d '{ -# "password": "ViewerPass@2026", -# "roles": ["viewer"], -# "full_name": "Kibana Anonymous Viewer", -# "enabled": true -# }' \ No newline at end of file diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/sc-high-iops.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/sc-high-iops.yaml deleted file mode 100644 index be247ee..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/sc-high-iops.yaml +++ /dev/null @@ -1,15 +0,0 @@ -# Hyperdisk Balanced with 35k IOPS — High performance SSD on GKE (pd.csi.storage.gke.io). -# Apply once per cluster before Elasticsearch PVCs. Requires GKE version that supports Hyperdisk. -# See: https://cloud.google.com/kubernetes-engine/docs/how-to/persistent-volumes/hyperdisk -apiVersion: storage.k8s.io/v1 -kind: StorageClass -metadata: - name: gke-hyperdisk-balanced-35k -provisioner: pd.csi.storage.gke.io -parameters: - type: hyperdisk-balanced - provisioned-throughput-on-create: "2000Mi" - provisioned-iops-on-create: "35000" -volumeBindingMode: WaitForFirstConsumer -allowVolumeExpansion: true -reclaimPolicy: Retain diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/sc.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/sc.yaml deleted file mode 100644 index 059cb5c..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/sc.yaml +++ /dev/null @@ -1,14 +0,0 @@ -# Hyperdisk Balanced — SSD-class block storage on GKE (pd.csi.storage.gke.io). -# Apply once per cluster before Elasticsearch PVCs. Requires GKE version that supports Hyperdisk. -# See: https://cloud.google.com/kubernetes-engine/docs/how-to/persistent-volumes/hyperdisk -apiVersion: storage.k8s.io/v1 -kind: StorageClass -metadata: - name: gke-hyperdisk-ssd -provisioner: pd.csi.storage.gke.io -parameters: - type: hyperdisk-balanced - replication-type: none -volumeBindingMode: WaitForFirstConsumer -allowVolumeExpansion: true -reclaimPolicy: Retain diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/service-export-apm.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/service-export-apm.yaml deleted file mode 100644 index ccdec5a..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/service-export-apm.yaml +++ /dev/null @@ -1,9 +0,0 @@ -apiVersion: net.gke.io/v1 -kind: ServiceExport -metadata: - name: apm-eck-observability-prd-apm-http - namespace: eck-observability-prd - - -#apm-eck-observability-prd-apm-http.eck-observability-prd.svc.clusterset.local -#eck-observability-prd-es-hot-warm.eck-observability-prd.svc.clusterset.local diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/service-export-es-hot-warm.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/service-export-es-hot-warm.yaml deleted file mode 100644 index a0fa405..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/service-export-es-hot-warm.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: net.gke.io/v1 -kind: ServiceExport -metadata: - name: eck-observability-prd-es-hot-warm - namespace: eck-observability-prd diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/service-export-es.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/service-export-es.yaml deleted file mode 100644 index a96418c..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/service-export-es.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: net.gke.io/v1 -kind: ServiceExport -metadata: - name: eck-observability-prd-es-http - namespace: eck-observability-prd diff --git a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/serviceaccount.yaml b/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/serviceaccount.yaml deleted file mode 100644 index f9fdb4c..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/serviceaccount.yaml +++ /dev/null @@ -1,7 +0,0 @@ -apiVersion: v1 -kind: ServiceAccount -metadata: - name: eck-observability-es-sa-prd - namespace: eck-observability-prd - annotations: - iam.gke.io/gcp-service-account: eck-prd@meesho-admin-dev-0622.iam.gserviceaccount.com diff --git a/helm-overrides/k8s-admin-prd-ase1/external-secrets/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/external-secrets/custom-values.yaml deleted file mode 100644 index b4b4d39..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/external-secrets/custom-values.yaml +++ /dev/null @@ -1,37 +0,0 @@ -external-secrets: - # Fresh install — nothing runs this today, so no adoption gotchas here - # (unlike gitea/vault/contour). Replaces the Vault Agent Injector as the - # path for getting secrets into pods (see the injector.enabled: false - # note in ../vault/custom-values.yaml) — nothing is wired to a - # SecretStore/ClusterSecretStore backend yet, that's a separate step - # once this controller itself is up and healthy. - # - # installCRDs defaults to true — leaving it, this is a fresh cluster - # with no existing SecretStore/ExternalSecret CRs whose schema this - # could clobber. - # - # All three components (controller, webhook, cert-controller) default - # to unbounded resources — every other app in this repo gets trimmed - # requests/limits for the same reason, staying consistent here. - resources: - requests: - cpu: 25m - memory: 32Mi - limits: - memory: 128Mi - - webhook: - resources: - requests: - cpu: 25m - memory: 32Mi - limits: - memory: 64Mi - - certController: - resources: - requests: - cpu: 25m - memory: 32Mi - limits: - memory: 64Mi diff --git a/helm-overrides/k8s-admin-prd-ase1/flagger/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/flagger/custom-values.yaml deleted file mode 100644 index f7d9727..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/flagger/custom-values.yaml +++ /dev/null @@ -1,55 +0,0 @@ -# Default values for flagger. - -image: - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/flagger - tag: hpa-changes-26 - -# accepted values are debug, info, warning, error (defaults to info) -logLevel: info - - -podAnnotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8080" - appmesh.k8s.aws/sidecarInjectorWebhook: disabled - -crd: - # crd.create: `true` if custom resource definitions should be created - create: false - -resources: - limits: - memory: "1024Mi" - cpu: "2" - requests: - memory: "512Mi" - cpu: "500m" - -nodeSelector: - dedicated: devops - -tolerations: - - effect: NoSchedule - key: dedicated - operator: Equal - value: devops - -prometheus: - install: false - image: docker.io/prom/prometheus:v2.39.1 - pullSecret: - retention: 2h - securityContext: - enabled: false - context: - readOnlyRootFilesystem: true - runAsUser: 10001 - -podDisruptionBudget: - enabled: false - minAvailable: 1 - -podLabels: - env: prd - team: devops - bu: infra diff --git a/helm-overrides/k8s-admin-prd-ase1/fluentd/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/fluentd/custom-values.yaml deleted file mode 100644 index 0c3b59d..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/fluentd/custom-values.yaml +++ /dev/null @@ -1,679 +0,0 @@ -nameOverride: "" -fullnameOverride: "" - -# DaemonSet, Deployment or StatefulSet -kind: "DaemonSet" -# azureblob, cloudwatch, elasticsearch7, elasticsearch8, gcs, graylog , kafka, kafka2, kinesis, opensearch -variant: gcs -# # Only applicable for Deployment or StatefulSet -# replicaCount: 1 - -image: - repository: "asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/fluentd-v2" - pullPolicy: "Always" - tag: "edge-debian" - -## Optional array of imagePullSecrets containing private registry credentials -## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ -imagePullSecrets: [] - -serviceAccount: - create: true - annotations: { - iam.gke.io/gcp-service-account: sa-admn-adsre-fluentd-prd@meesho-admin-prd-0622.iam.gserviceaccount.com - } - name: null - -rbac: - create: true - -# from Kubernetes 1.25, PSP is deprecated -# See: https://kubernetes.io/blog/2022/08/23/kubernetes-v1-25-release/#pod-security-changes -# We automatically disable PSP if Kubernetes version is 1.25 or higher -podSecurityPolicy: - enabled: true - annotations: {} - -## Security Context policies for controller pods -## See https://kubernetes.io/docs/tasks/administer-cluster/sysctl-cluster/ for -## notes on enabling and using sysctls -## -podSecurityContext: {} - # seLinuxOptions: - # type: "spc_t" - -securityContext: {} - # capabilities: - # drop: - # - ALL - # readOnlyRootFilesystem: true - # runAsNonRoot: true - # runAsUser: 1000 - -# Configure the livecycle -# Ref: https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/ -lifecycle: {} - # preStop: - # exec: - # command: ["/bin/sh", "-c", "sleep 20"] - -# Configure the livenessProbe -# Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/ -#livenessProbe: -# httpGet: -# path: /metrics -# port: metrics - # initialDelaySeconds: 0 - # periodSeconds: 10 - # timeoutSeconds: 1 - # successThreshold: 1 - # failureThreshold: 3 - -# Configure the readinessProbe -# Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/ -#readinessProbe: -# httpGet: -# path: /metrics -# port: metrics - # initialDelaySeconds: 0 - # periodSeconds: 10 - # timeoutSeconds: 1 - # successThreshold: 1 - # failureThreshold: 3 - -resources: - requests: - cpu: 100m - memory: 50Mi - limits: - memory: 2000Mi - cpu: 2000m - -## only available if kind is Deployment -autoscaling: - enabled: false - minReplicas: 1 - maxReplicas: 100 - targetCPUUtilizationPercentage: 80 - # targetMemoryUtilizationPercentage: 80 - ## see https://kubernetes.io/docs/tasks/run-application/horizontal-pod-autoscale-walkthrough/#autoscaling-on-multiple-metrics-and-custom-metrics - customRules: [] - # - type: Pods - # pods: - # metric: - # name: packets-per-second - # target: - # type: AverageValue - # averageValue: 1k - ## see https://kubernetes.io/docs/tasks/run-application/horizontal-pod-autoscale/#support-for-configurable-scaling-behavior - # behavior: - # scaleDown: - # policies: - # - type: Pods - # value: 4 - # periodSeconds: 60 - # - type: Percent - # value: 10 - # periodSeconds: 60 - - -priorityClassName: "system-node-critical" - -nodeSelector: {} - -## Node tolerations for server scheduling to nodes with taints -## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/ -## -tolerations: - - operator: Exists - -## Affinity and anti-affinity -## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity -## -affinity: {} - -## Annotations to be added to fluentd DaemonSet/Deployment -## -annotations: {} - -## Labels to be added to fluentd DaemonSet/Deployment -## -labels: - bu: admin - team: sre - type: fluentd - service: fluentd-admin-prd - priority: p0 - env: prd - -## Annotations to be added to fluentd pods -## -podAnnotations: {} - -## Labels to be added to fluentd pods -## -podLabels: - bu: admin - team: sre - type: fluentd - service: fluentd-admin-prd - priority: p0 - env: prd - - -## How long (in seconds) a pods needs to be stable before progressing the deployment -## -minReadySeconds: - -## How long (in seconds) a pod may take to exit (useful with lifecycle hooks to ensure lb deregistration is done) -## -terminationGracePeriodSeconds: - -## Deployment strategy / DaemonSet updateStrategy -## -updateStrategy: - type: RollingUpdate - rollingUpdate: - maxUnavailable: 25% - maxSurge: 0 - -## Additional environment variables to set for fluentd pods -## Additional environment variables to set for fluentd pods -env: -- name: APP_NAME - value: namespace_name -- name: SUB_SYSTEM - value: container_name -# - name: FLUENTD_CONF -# value: "../../etc/fluent/fluent.conf" -- name: APP_NAME_SYSTEMD - value: systemd -- name: SUB_SYSTEM_SYSTEMD - value: kubelet.service -- name: ENDPOINT - value: ingress.coralogixsg.com -- name: LOG_LEVEL - value: error -- name: TZ - value: "Asia/Kolkata" -- name: K8S_NODE_NAME - valueFrom: - fieldRef: - fieldPath: spec.nodeName - -externalSecret: - secretStoreRef: - name: vault-backend - path: prd/admin/coralogix-keys - -# externalSecret: -# enabled: true -# key: dev/devops/coralogix -# secretStoreRef: -# name: vault-backend - -envFrom: -- secretRef: - name: integrations-privatekey -- secretRef: - name: es-password - -initContainers: [] - -## Name of the configMap containing a custom fluentd.conf configuration file to use instead of the default. -# mainConfigMapNameOverride: "" - -## Name of the configMap containing files to be placed under /etc/fluent/config.d/ -## NOTE: This will replace ALL default files in the aforementioned path! -# extraFilesConfigMapNameOverride: "" - -mountVarLogDirectory: true -mountDockerContainersDirectory: true - -volumes: [] -# - name: varlog -# hostPath: -# path: /var/log -# - name: varlibdockercontainers -# hostPath: -# path: /var/lib/docker/containers -# - name: etcfluentd-main -# configMap: -# name: fluentd-main -# defaultMode: 0777 -# - name: etcfluentd-config -# configMap: -# name: fluentd-config -# defaultMode: 0777 - -volumeMounts: [] -# - name: varlog -# mountPath: /var/log -# - name: varlibdockercontainers -# mountPath: /var/lib/docker/containers -# readOnly: true -# - name: etcfluentd-main -# mountPath: /etc/fluent -# - name: etcfluentd-config -# mountPath: /etc/fluent/config.d/ - -## Only available if kind is StatefulSet -## Fluentd persistence -## -persistence: - enabled: false - storageClass: "" - accessMode: ReadWriteOnce - size: 10Gi - -## Fluentd service -## -service: - enabled: true - type: "ClusterIP" - annotations: {} - # loadBalancerIP: - # externalTrafficPolicy: Local - ports: [] - # - name: "forwarder" - # protocol: TCP - # containerPort: 24224 - -## Prometheus Monitoring -## -metrics: - serviceMonitor: - enabled: false - additionalLabels: - release: prometheus-operator - namespace: "" - namespaceSelector: {} - ## metric relabel configs to apply to samples before ingestion. - ## - metricRelabelings: [] - # - sourceLabels: [__name__] - # separator: ; - # regex: ^fluentd_output_status_buffer_(oldest|newest)_.+ - # replacement: $1 - # action: drop - ## relabel configs to apply to samples after ingestion. - ## - relabelings: [] - # - sourceLabels: [__meta_kubernetes_pod_node_name] - # separator: ; - # regex: ^(.*)$ - # targetLabel: nodename - # replacement: $1 - # action: replace - ## Additional serviceMonitor config - ## - # jobLabel: fluentd - # scrapeInterval: 30s - # scrapeTimeout: 5s - # honorLabels: true - - prometheusRule: - enabled: false - additionalLabels: {} - namespace: "" - rules: [] - # - alert: FluentdDown - # expr: up{job="fluentd"} == 0 - # for: 5m - # labels: - # context: fluentd - # severity: warning - # annotations: - # summary: "Fluentd Down" - # description: "{{ $labels.pod }} on {{ $labels.nodename }} is down" - # - alert: FluentdScrapeMissing - # expr: absent(up{job="fluentd"} == 1) - # for: 15m - # labels: - # context: fluentd - # severity: warning - # annotations: - # summary: "Fluentd Scrape Missing" - # description: "Fluentd instance has disappeared from Prometheus target discovery" - -## Grafana Monitoring Dashboard -## -dashboards: - enabled: "true" - namespace: "" - labels: - grafana_dashboard: '"1"' - -## Fluentd list of plugins to install -## -plugins: [] -# - fluent-plugin-out-http - -## Add fluentd config files from K8s configMaps -## -configMapConfigs: [] -# - fluentd-prometheus-conf -# - fluentd-systemd-conf - -## Fluentd configurations: -## -fileConfigs: - 01_sources.conf: |- - - @type systemd - path /var/log/journal - tag sys-log - read_from_head true - - - @id fluentd-containers.log - @type tail - encoding utf-8 - path /var/log/containers/*.log - pos_file /var/log/containers.log.pos - exclude_path ["/var/log/containers/*telegraf*.log"] - path_key filename - tag raw.containers.* - read_from_head true - - @type multi_format - - format json - time_key time - time_format %Y-%m-%dT%H:%M:%S.%NZ - keep_time_key true - - - format /^(? - - format /^(?fsp\s+.+)$/ - ignorecase false - multiline false - - - - - @id raw.containers - @type detect_exceptions - remove_tag_prefix raw - message log - stream stream - multiline_flush_interval 5 - max_bytes 500000 - max_lines 1000 - - - - @type kubernetes_metadata - - - - @type record_transformer - enable_ruby true - - container_id ${record.dig("docker", "container_id")} - - - - - @type rewrite_tag_filter - - key $.kubernetes.namespace_name - pattern ^(.+)$ - tag $1.${tag} - - - - 02_filters.conf: |- - - 03_dispatch.conf: |- - - @type "relabel" - @label @NOCONCATDISPATCH - - - @type "relabel" - @label @CONCATDISPATCH - - - - - - - - - - - - 04_outputs.conf: |- diff --git a/helm-overrides/k8s-admin-prd-ase1/gitea/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/gitea/custom-values.yaml deleted file mode 100644 index 6d370af..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/gitea/custom-values.yaml +++ /dev/null @@ -1,108 +0,0 @@ -gitea: - # Adopting the standalone install from localvm-kubernetes-setup's - # deploy_gitea.sh (helm release "gitea", namespace "gitea") — same - # config, translated to values so it's GitOps-managed from here on. - # See devops-infra-argo-config values/admin/incubator-infra-k8s-admin-prd-ase1-values.yaml - # for the nameOverride that makes Argo's render match the existing - # release/object names instead of creating a second Gitea. - # - # sqlite + valkey/postgres disabled: sqlite is enough for a lab, and - # the valkey-cluster pod was stuck Pending until the StorageClass was - # fixed (claude.md issue #2/#3) — disabling it avoids that dependency. - # persistence.size must stay 10Gi to match the already-bound PVC — - # local-path-provisioner doesn't support volume expansion. - - # Chart default is RollingUpdate with maxUnavailable: 0 — the new pod - # always comes up before the old one terminates. On a real multi-node - # cluster with real RWO block storage that's fine (the new pod just - # can't mount until the old one releases). On this single-node cluster, - # local-path-provisioner's hostPath-style volume doesn't block a second - # same-node mount, so old+new pods briefly run concurrently against the - # same /data — and Gitea's LevelDB-backed queue holds an exclusive file - # lock, so the new pod crashes with "unable to lock level db ... - # resource temporarily unavailable". Recreate forces the old pod to - # fully terminate (and release the lock) before the new one starts. - strategy: - type: Recreate - - # Scopes Replace=true to ONLY the Deployment (not the whole Application — - # see the note in devops-infra-argo-config's values file for why that - # broke the PVC). The `configure-gitea` init container's - # GITEA_ADMIN_USERNAME/PASSWORD env vars still carry plaintext `value` - # fields on the live object from the original imperative install; ours - # switch those to `valueFrom: secretKeyRef` (below), and a patch can't - # clear the old field while adding the new one. A full PUT of just this - # one resource sidesteps that. Safe to remove once the live Deployment - # no longer carries the old `value` fields — after that first successful - # sync, plain patching is fine again. - deployment: - annotations: - argocd.argoproj.io/sync-options: Replace=true - - persistence: - size: 10Gi - - postgresql: - enabled: false - postgresql-ha: - enabled: false - valkey: - enabled: false - valkey-cluster: - enabled: false - - resources: - requests: - cpu: 100m - memory: 300Mi - limits: - memory: 500Mi - - gitea: - config: - database: - DB_TYPE: sqlite3 - actions: - ENABLED: true - security: - # Gitea's own SSRF protection blocks outbound webhook calls to - # private/internal IPs by default — hit this trying to fire a - # webhook at jenkins.192.168.1.7.nip.io ("webhook can only call - # allowed HTTP servers"). Everything on this homelab lives on a - # private LAN, so a narrow allowlist would just mean editing - # this every time a new *.192.168.1.7.nip.io/*.100.90.248.118.nip.io - # host needs webhook access — matches the lightweight security - # posture already used elsewhere here (ArgoCD --insecure, plain - # HTTP throughout). - ALLOWED_HOST_LIST: "*" - admin: - username: gitadmin - # The running install set this via a plaintext --set-string flag at - # install time. Correction from an earlier version of this comment: - # this is NOT install-time only — the `configure-gitea` init - # container re-runs GITEA_ADMIN_PASSWORD_MODE: keepUpdated on every - # pod (re)start, actively syncing the admin password from whatever - # this env var resolves to. That's what caused the value->valueFrom - # migration conflict fixed above — this Secret must exist and be - # correct before the Deployment syncs. - # - # As of the Vault + External Secrets Operator migration, this Secret - # is no longer manually kubectl-created — it's managed by the - # ExternalSecret at devops-infra-argo-config/secretstores/gitea-admin-credentials.yaml, - # sourced from Vault path secret/gitea/admin. Rotate the password via - # `vault kv put secret/gitea/admin ...`, not kubectl, from here on. - existingSecret: gitea-admin-credentials - email: "admin@local.lab" - - ingress: - enabled: true - className: contour - hosts: - - host: gitea.192.168.1.7.nip.io - paths: - - path: / - pathType: Prefix - - host: gitea.100.90.248.118.nip.io - paths: - - path: / - pathType: Prefix diff --git a/helm-overrides/k8s-admin-prd-ase1/grafana-edge/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/grafana-edge/custom-values.yaml deleted file mode 100644 index 4be7855..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/grafana-edge/custom-values.yaml +++ /dev/null @@ -1,68 +0,0 @@ -fullnameOverride: grafana-edge-infra-prd - -replicas: 1 - -image: - tag: "11.3.1" - -ingress: - enabled: true - ingressClassName: nginx-internal - annotations: - nginx.ingress.kubernetes.io/ssl-redirect: "false" - nginx.ingress.kubernetes.io/force-ssl-redirect: "false" - nginx.ingress.kubernetes.io/client_header_buffer_size: "512k" - nginx.ingress.kubernetes.io/large_client_header_buffers: "4 512k" - nginx.ingress.kubernetes.io/proxy-body-size: "0" - path: / - pathType: Prefix - hosts: - - grafana-edge-prd.meeshogcp.in - -resources: - limits: - cpu: 7 - memory: 6Gi - requests: - cpu: 3.5 - memory: 3Gi - -nodeSelector: - dedicated: "grafana" - -tolerations: - - key: "dedicated" - operator: "Equal" - value: "grafana" - effect: "NoSchedule" - -adminUser: admin - -externalSecrets: - refreshInterval: "150s" - secretStoreRef: - name: vault-backend - kind: ClusterSecretStore - dataFrom: - secretKey: "admin/common-infra/grafana-edge-infra-prd" - -envFromSecrets: - - name: grafana-edge-infra-prd-secret - optional: false - -grafana.ini: - server: - root_url: "https://{{ if (and .Values.ingress.enabled .Values.ingress.hosts) }}{{ .Values.ingress.hosts | first }}{{ else }}''{{ end }}" - enable_gzip: true - users: - auto_assign_org_role: "Editor" - auth.proxy: - enabled: true - header_name: "X-WEBAUTH-USER" - header_property: "username" - metrics: - enabled: true - disable_total_stats: false - -plugins: - - yesoreyeram-infinity-datasource \ No newline at end of file diff --git a/helm-overrides/k8s-admin-prd-ase1/grafana-sec/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/grafana-sec/custom-values.yaml deleted file mode 100644 index d0710bf..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/grafana-sec/custom-values.yaml +++ /dev/null @@ -1,1333 +0,0 @@ -global: - # To help compatibility with other charts which use global.imagePullSecrets. - # Allow either an array of {name: pullSecret} maps (k8s-style), or an array of strings (more common helm-style). - # Can be tempalted. - # global: - # imagePullSecrets: - # - name: pullSecret1 - # - name: pullSecret2 - # or - # global: - # imagePullSecrets: - # - pullSecret1 - # - pullSecret2 - imagePullSecrets: [] - -fullnameOverride: grafana-secured-infra-prd -rbac: - create: true - ## Use an existing ClusterRole/Role (depending on rbac.namespaced false/true) - # useExistingRole: name-of-some-(cluster)role - pspEnabled: false - pspUseAppArmor: false - namespaced: false - extraRoleRules: [] - # - apiGroups: [] - # resources: [] - # verbs: [] - extraClusterRoleRules: [] - # - apiGroups: [] - # resources: [] - # verbs: [] -serviceAccount: - create: true - name: - nameTest: - ## ServiceAccount labels. - labels: {} -## Service account annotations. Can be templated. - annotations: {} - autoMount: true - -replicas: 2 -dedicatedValue: false - -## Create a headless service for the deployment -headlessService: true - -## Create HorizontalPodAutoscaler object for deployment type -# -autoscaling: - enabled: true - minReplicas: 2 - maxReplicas: 20 - targetCPU: "60" - targetMemory: "" - behavior: {} - -## See `kubectl explain poddisruptionbudget.spec` for more -## ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/ -podDisruptionBudget: - minAvailable: 1 -# minAvailable: 1 -# maxUnavailable: 1 - -## See `kubectl explain deployment.spec.strategy` for more -## ref: https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#strategy -deploymentStrategy: - type: RollingUpdate - -readinessProbe: - httpGet: - path: /api/health - port: 3000 - -livenessProbe: - httpGet: - path: /api/health - port: 3000 - initialDelaySeconds: 60 - timeoutSeconds: 30 - failureThreshold: 10 - -## Use an alternate scheduler, e.g. "stork". -## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/ -## -# schedulerName: "default-scheduler" - -image: - repository: docker.io/grafana/grafana - # Overrides the Grafana image tag whose default is the chart appVersion - tag: "" - sha: "" - pullPolicy: IfNotPresent - - ## Optionally specify an array of imagePullSecrets. - ## Secrets must be manually created in the namespace. - ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ - ## Can be templated. - ## - pullSecrets: [] - # - myRegistrKeySecretName - -testFramework: - enabled: true - image: docker.io/bats/bats - tag: "v1.4.1" - imagePullPolicy: IfNotPresent - securityContext: {} - -securityContext: - runAsNonRoot: true - runAsUser: 472 - runAsGroup: 472 - fsGroup: 472 - -containerSecurityContext: - allowPrivilegeEscalation: false - capabilities: - drop: - - ALL - seccompProfile: - type: RuntimeDefault - -# Enable creating the grafana configmap -createConfigmap: true - -# Extra configmaps to mount in grafana pods -# Values are templated. -extraConfigmapMounts: [] - # - name: certs-configmap - # mountPath: /etc/grafana/ssl/ - # subPath: certificates.crt # (optional) - # configMap: certs-configmap - # readOnly: true - - -extraEmptyDirMounts: [] - # - name: provisioning-notifiers - # mountPath: /etc/grafana/provisioning/notifiers - - -# Apply extra labels to common labels. -extraLabels: - bu: "infra" - team: "sre" - service: "grafana-secured-infra-prd" - env: "prd" - priority: "p0" - type: "grafana" - - -## Assign a PriorityClassName to pods if set -# priorityClassName: - -downloadDashboardsImage: - repository: docker.io/curlimages/curl - tag: 7.85.0 - sha: "" - pullPolicy: IfNotPresent - -downloadDashboards: - env: {} - envFromSecret: "" - resources: {} - securityContext: - allowPrivilegeEscalation: false - capabilities: - drop: - - ALL - seccompProfile: - type: RuntimeDefault - envValueFrom: {} - # ENV_NAME: - # configMapKeyRef: - # name: configmap-name - # key: value_key - -## Pod Annotations -# podAnnotations: {} - -## Pod Labels -podLabels: - bu: "infra" - team: "sre" - service: "grafana-secured-infra-prd" - env: "prd" - priority: "p0" - type: "grafana" - - -podPortName: grafana -gossipPortName: gossip -## Deployment annotations -# annotations: {} - -## Expose the grafana service to be accessed from outside the cluster (LoadBalancer service). -## or access it from within the cluster (ClusterIP service). Set the service type and the port to serve it. -## ref: http://kubernetes.io/docs/user-guide/services/ -## -service: - enabled: true - type: ClusterIP - port: 80 - targetPort: 3000 - # targetPort: 4181 To be used with a proxy extraContainer - ## Service annotations. Can be templated. - annotations: {} - labels: {} - portName: service - # Adds the appProtocol field to the service. This allows to work with istio protocol selection. Ex: "http" or "tcp" - appProtocol: "" - -serviceMonitor: - ## If true, a ServiceMonitor CRD is created for a prometheus operator - ## https://github.com/coreos/prometheus-operator - ## - enabled: false - path: /metrics - # namespace: monitoring (defaults to use the namespace this chart is deployed to) - labels: {} - interval: 1m - scheme: http - tlsConfig: {} - scrapeTimeout: 30s - relabelings: [] - targetLabels: [] - -extraExposePorts: [] - # - name: keycloak - # port: 8080 - # targetPort: 8080 - # type: ClusterIP - -# overrides pod.spec.hostAliases in the grafana deployment's pods -hostAliases: [] - # - ip: "1.2.3.4" - # hostnames: - # - "my.host.com" - -ingress: - enabled: true - # For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName - # See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress - ingressClassName: nginx-internal - # Values can be templated - annotations: - nginx.ingress.kubernetes.io/force-ssl-redirect: "false" - nginx.ingress.kubernetes.io/ssl-redirect: "false" - nginx.ingress.kubernetes.io/client_header_buffer_size: "512k" - nginx.ingress.kubernetes.io/large_client_header_buffers: "4 512k" - nginx.ingress.kubernetes.io/proxy-body-size: "0" - - # kubernetes.io/ingress.class: nginx - # kubernetes.io/tls-acme: "true" - labels: {} - path: / - - # pathType is only for k8s >= 1.1= - pathType: Prefix - - hosts: - - grafana-secured-prd.meeshogcp.in - ## Extra paths to prepend to every host configuration. This is useful when working with annotation based services. - extraPaths: [] - # - path: /* - # backend: - # serviceName: ssl-redirect - # servicePort: use-annotation - ## Or for k8s > 1.19 - # - path: /* - # pathType: Prefix - # backend: - # service: - # name: ssl-redirect - # port: - # name: use-annotation - - - tls: [] - # - secretName: chart-example-tls - # hosts: - # - chart-example.local - -resources: - # limits: - # cpu: 3 - # memory: 50Gi - requests: - cpu: 4 - memory: 16Gi - -# ## Node labels for pod assignment -# ## ref: https://kubernetes.io/docs/user-guide/node-selection/ -# # -# nodeSelector: {} - -# ## Tolerations for pod assignment -# ## ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/ -# ## -# tolerations: [] - -nodeSelector: - dedicated: "sre-shared-tmp" - -tolerations: - - key: "dedicated" - operator: "Equal" - value: "sre-shared-tmp" - effect: "NoSchedule" - -## Affinity for pod assignment (evaluated as template) -## ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity -## -affinity: {} - -## Topology Spread Constraints -## ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/ -## -topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: grafana - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: DoNotSchedule - labelSelector: - matchLabels: - type: grafana - -## Additional init containers (evaluated as template) -## ref: https://kubernetes.io/docs/concepts/workloads/pods/init-containers/ -## -extraInitContainers: [] - -## Enable an Specify container in extraContainers. This is meant to allow adding an authentication proxy to a grafana pod -extraContainers: "" -# extraContainers: | -# - name: proxy -# image: quay.io/gambol99/keycloak-proxy:latest -# args: -# - -provider=github -# - -client-id= -# - -client-secret= -# - -github-org= -# - -email-domain=* -# - -cookie-secret= -# - -http-address=http://0.0.0.0:4181 -# - -upstream-url=http://127.0.0.1:3000 -# ports: -# - name: proxy-web -# containerPort: 4181 - -## Volumes that can be used in init containers that will not be mounted to deployment pods -extraContainerVolumes: [] -# - name: volume-from-secret -# secret: -# secretName: secret-to-mount -# - name: empty-dir-volume -# emptyDir: {} - -## Enable persistence using Persistent Volume Claims -## ref: http://kubernetes.io/docs/user-guide/persistent-volumes/ -## -persistence: - type: pvc - enabled: false - # storageClassName: default - accessModes: - - ReadWriteOnce - size: 10Gi - # annotations: {} - finalizers: - - kubernetes.io/pvc-protection - # selectorLabels: {} - ## Sub-directory of the PV to mount. Can be templated. - # subPath: "" - ## Name of an existing PVC. Can be templated. - # existingClaim: - ## Extra labels to apply to a PVC. - extraPvcLabels: {} - - ## If persistence is not enabled, this allows to mount the - ## local storage in-memory to improve performance - ## - inMemory: - enabled: false - ## The maximum usage on memory medium EmptyDir would be - ## the minimum value between the SizeLimit specified - ## here and the sum of memory limits of all containers in a pod - ## - # sizeLimit: 300Mi - -initChownData: - ## If false, data ownership will not be reset at startup - ## This allows the grafana-server to be run with an arbitrary user - ## - enabled: true - - ## initChownData container image - ## - image: - repository: docker.io/library/busybox - tag: "1.31.1" - sha: "" - pullPolicy: IfNotPresent - - ## initChownData resource requests and limits - ## Ref: http://kubernetes.io/docs/user-guide/compute-resources/ - ## - resources: {} - # limits: - # cpu: 100m - # memory: 128Mi - # requests: - # cpu: 100m - # memory: 128Mi - securityContext: - runAsNonRoot: false - runAsUser: 0 - seccompProfile: - type: RuntimeDefault - capabilities: - add: - - CHOWN - -# Administrator credentials when not using an existing secret (see below) -adminUser: admin -# adminPassword: strongpassword - -# Use an existing secret for the admin user. -admin: - ## Name of the secret. Can be templated. - existingSecret: "" - userKey: admin-user - passwordKey: admin-password - -## For Vault Configuration -externalSecrets: - refreshInterval: "150s" - secretStoreRef: - name: vault-backend - kind: ClusterSecretStore - dataFrom: - secretKey: "admin/common-infra/grafana-secured-infra-prd" - - -## Define command to be executed at startup by grafana container -## Needed if using `vault-env` to manage secrets (ref: https://banzaicloud.com/blog/inject-secrets-into-pods-vault/) -## Default is "run.sh" as defined in grafana's Dockerfile -# command: -# - "sh" -# - "/run.sh" - -## Optionally define args if command is used -## Needed if using `hashicorp/envconsul` to manage secrets -## By default no arguments are set -# args: -# - "-secret" -# - "secret/grafana" -# - "./grafana" - -## Extra environment variables that will be pass onto deployment pods -## -## to provide grafana with access to CloudWatch on AWS EKS: -## 1. create an iam role of type "Web identity" with provider oidc.eks.* (note the provider for later) -## 2. edit the "Trust relationships" of the role, add a line inside the StringEquals clause using the -## same oidc eks provider as noted before (same as the existing line) -## also, replace NAMESPACE and prometheus-operator-grafana with the service account namespace and name -## -## "oidc.eks.us-east-1.amazonaws.com/id/XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX:sub": "system:serviceaccount:NAMESPACE:prometheus-operator-grafana", -## -## 3. attach a policy to the role, you can use a built in policy called CloudWatchReadOnlyAccess -## 4. use the following env: (replace 123456789000 and iam-role-name-here with your aws account number and role name) -## -## env: -## AWS_ROLE_ARN: arn:aws:iam::123456789000:role/iam-role-name-here -## AWS_WEB_IDENTITY_TOKEN_FILE: /var/run/secrets/eks.amazonaws.com/serviceaccount/token -## AWS_REGION: us-east-1 -## -## 5. uncomment the EKS section in extraSecretMounts: below -## 6. uncomment the annotation section in the serviceAccount: above -## make sure to replace arn:aws:iam::123456789000:role/iam-role-name-here with your role arn - -env: {} - -## "valueFrom" environment variable references that will be added to deployment pods. Name is templated. -## ref: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.19/#envvarsource-v1-core -## Renders in container spec as: -## env: -## ... -## - name: -## valueFrom: -## -envValueFrom: {} - # ENV_NAME: - # configMapKeyRef: - # name: configmap-name - # key: value_key - -## The name of a secret in the same kubernetes namespace which contain values to be added to the environment -## This can be useful for auth tokens, etc. Value is templated. -envFromSecret: "" - -## Sensible environment variables that will be rendered as new secret object -## This can be useful for auth tokens, etc. -## If the secret values contains "{{", they'll need to be properly escaped so that they are not interpreted by Helm -## ref: https://helm.sh/docs/howto/charts_tips_and_tricks/#using-the-tpl-function -envRenderSecret: {} - -## The names of secrets in the same kubernetes namespace which contain values to be added to the environment -## Each entry should contain a name key, and can optionally specify whether the secret must be defined with an optional key. -## Name is templated. -envFromSecrets: - - name: grafana-secured-infra-prd-secret - optional: false -## - name: secret-name -## optional: true - -## The names of conifgmaps in the same kubernetes namespace which contain values to be added to the environment -## Each entry should contain a name key, and can optionally specify whether the configmap must be defined with an optional key. -## Name is templated. -## ref: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.23/#configmapenvsource-v1-core -envFromConfigMaps: [] -## - name: configmap-name -## optional: true - -# Inject Kubernetes services as environment variables. -# See https://kubernetes.io/docs/concepts/services-networking/connect-applications-service/#environment-variables -enableServiceLinks: true - -## Additional grafana server secret mounts -# Defines additional mounts with secrets. Secrets must be manually created in the namespace. -extraSecretMounts: [] - # - name: secret-files - # mountPath: /etc/secrets - # secretName: grafana-secret-files - # readOnly: true - # subPath: "" - # - # for AWS EKS (cloudwatch) use the following (see also instruction in env: above) - # - name: aws-iam-token - # mountPath: /var/run/secrets/eks.amazonaws.com/serviceaccount - # readOnly: true - # projected: - # defaultMode: 420 - # sources: - # - serviceAccountToken: - # audience: sts.amazonaws.com - # expirationSeconds: 86400 - # path: token - # - # for CSI e.g. Azure Key Vault use the following - # - name: secrets-store-inline - # mountPath: /run/secrets - # readOnly: true - # csi: - # driver: secrets-store.csi.k8s.io - # readOnly: true - # volumeAttributes: - # secretProviderClass: "akv-grafana-spc" - # nodePublishSecretRef: # Only required when using service principal mode - # name: grafana-akv-creds # Only required when using service principal mode - -## Additional grafana server volume mounts -# Defines additional volume mounts. -extraVolumeMounts: [] - # - name: extra-volume-0 - # mountPath: /mnt/volume0 - # readOnly: true - # existingClaim: volume-claim - # - name: extra-volume-1 - # mountPath: /mnt/volume1 - # readOnly: true - # hostPath: /usr/shared/ - # - name: grafana-secrets - # mountPath: /mnt/volume2 - # csi: true - # data: - # driver: secrets-store.csi.k8s.io - # readOnly: true - # volumeAttributes: - # secretProviderClass: "grafana-env-spc" - -## Container Lifecycle Hooks. Execute a specific bash command or make an HTTP request -lifecycleHooks: {} - # postStart: - # exec: - # command: [] - -## Pass the plugins you want installed as a list. -## -plugins: - - grafana-piechart-panel - - grafana-googlesheets-datasource - - jeanbaptistewatenberg-percent-panel - - camptocamp-prometheus-alertmanager-datasource - - grafana-clock-panel - - marcusolsson-csv-datasource - # - digrich-bubblechart-panel - # - grafana-clock-panel - ## You can also use other plugin download URL, as long as they are valid zip files, - ## and specify the name of the plugin after the semicolon. Like this: - # - https://grafana.com/api/plugins/marcusolsson-json-datasource/versions/1.3.2/download;marcusolsson-json-datasource - -## Configure grafana datasources -## ref: http://docs.grafana.org/administration/provisioning/#datasources -## -datasources: {} -# datasources.yaml: -# apiVersion: 1 -# datasources: -# - name: Prometheus -# type: prometheus -# url: http://prometheus-prometheus-server -# access: proxy -# isDefault: true -# - name: CloudWatch -# type: cloudwatch -# access: proxy -# uid: cloudwatch -# editable: false -# jsonData: -# authType: default -# defaultRegion: us-east-1 -# deleteDatasources: [] -# - name: Prometheus - -## Configure grafana alerting (can be templated) -## ref: http://docs.grafana.org/administration/provisioning/#alerting -## -alerting: {} - # rules.yaml: - # apiVersion: 1 - # groups: - # - orgId: 1 - # name: '{{ .Chart.Name }}_my_rule_group' - # folder: my_first_folder - # interval: 60s - # rules: - # - uid: my_id_1 - # title: my_first_rule - # condition: A - # data: - # - refId: A - # datasourceUid: '-100' - # model: - # conditions: - # - evaluator: - # params: - # - 3 - # type: gt - # operator: - # type: and - # query: - # params: - # - A - # reducer: - # type: last - # type: query - # datasource: - # type: __expr__ - # uid: '-100' - # expression: 1==0 - # intervalMs: 1000 - # maxDataPoints: 43200 - # refId: A - # type: math - # dashboardUid: my_dashboard - # panelId: 123 - # noDataState: Alerting - # for: 60s - # annotations: - # some_key: some_value - # labels: - # team: sre_team_1 - # contactpoints.yaml: - # apiVersion: 1 - # contactPoints: - # - orgId: 1 - # name: cp_1 - # receivers: - # - uid: first_uid - # type: pagerduty - # settings: - # integrationKey: XXX - # severity: critical - # class: ping failure - # component: Grafana - # group: app-stack - # summary: | - # {{ `{{ include "default.message" . }}` }} - -## Configure notifiers -## ref: http://docs.grafana.org/administration/provisioning/#alert-notification-channels -## -notifiers: {} -# notifiers.yaml: -# notifiers: -# - name: email-notifier -# type: email -# uid: email1 -# # either: -# org_id: 1 -# # or -# org_name: Main Org. -# is_default: true -# settings: -# addresses: an_email_address@example.com -# delete_notifiers: - -## Configure grafana dashboard providers -## ref: http://docs.grafana.org/administration/provisioning/#dashboards -## -## `path` must be /var/lib/grafana/dashboards/ -## -dashboardProviders: {} -# dashboardproviders.yaml: -# apiVersion: 1 -# providers: -# - name: 'default' -# orgId: 1 -# folder: '' -# type: file -# disableDeletion: false -# editable: true -# options: -# path: /var/lib/grafana/dashboards/default - -## Configure grafana dashboard to import -## NOTE: To use dashboards you must also enable/configure dashboardProviders -## ref: https://grafana.com/dashboards -## -## dashboards per provider, use provider name as key. -## -dashboards: {} - # default: - # some-dashboard: - # json: | - # $RAW_JSON - # custom-dashboard: - # file: dashboards/custom-dashboard.json - # prometheus-stats: - # gnetId: 2 - # revision: 2 - # datasource: Prometheus - # local-dashboard: - # url: https://example.com/repository/test.json - # token: '' - # local-dashboard-base64: - # url: https://example.com/repository/test-b64.json - # token: '' - # b64content: true - # local-dashboard-gitlab: - # url: https://example.com/repository/test-gitlab.json - # gitlabToken: '' - # local-dashboard-bitbucket: - # url: https://example.com/repository/test-bitbucket.json - # bearerToken: '' - # local-dashboard-azure: - # url: https://example.com/repository/test-azure.json - # basic: '' - # acceptHeader: '*/*' - -## Reference to external ConfigMap per provider. Use provider name as key and ConfigMap name as value. -## A provider dashboards must be defined either by external ConfigMaps or in values.yaml, not in both. -## ConfigMap data example: -## -## data: -## example-dashboard.json: | -## RAW_JSON -## -dashboardsConfigMaps: {} -# default: "" - -## Grafana's primary configuration -## NOTE: values in map will be converted to ini format -## ref: http://docs.grafana.org/installation/configuration/ -## -grafana.ini: - paths: - data: /var/lib/grafana/ - logs: /var/log/grafana - plugins: /var/lib/grafana/plugins - provisioning: /etc/grafana/provisioning - analytics: - check_for_updates: true - log: - mode: console - grafana_net: - url: https://grafana.net - database: - max_idle_conn: 5 - dataproxy: - timeout: 300 - keep_alive_seconds: 60 - dashboards: - min_refresh_interval: 60s - security: - allow_embedding: true - server: - domain: "{{ if (and .Values.ingress.enabled .Values.ingress.hosts) }}{{ .Values.ingress.hosts | first }}{{ else }}''{{ end }}" - http_addr: "0.0.0.0" - root_url: "https://{{ if (and .Values.ingress.enabled .Values.ingress.hosts) }}{{ .Values.ingress.hosts | first }}{{ else }}''{{ end }}" - enable_gzip: true - users: - auto_assign_org_role: "Editor" - auth.proxy: - enabled: true - header_name: "X-WEBAUTH-USER" - header_property: "username" - unified_alerting: - enabled: true - ha_peers: grafana-secured-infra-prd-headless:9094 - ha_listen_address: ${POD_IP}:9094 - ha_advertise_address: ${POD_IP}:9094 - alerting: - enabled: false -## grafana Authentication can be enabled with the following values on grafana.ini - # server: - # The full public facing url you use in browser, used for redirects and emails - # root_url: - # https://grafana.com/docs/grafana/latest/auth/github/#enable-github-in-grafana - # auth.github: - # enabled: false - # allow_sign_up: false - # scopes: user:email,read:org - # auth_url: https://github.com/login/oauth/authorize - # token_url: https://github.com/login/oauth/access_token - # api_url: https://api.github.com/user - # team_ids: - # allowed_organizations: - # client_id: - # client_secret: -## LDAP Authentication can be enabled with the following values on grafana.ini -## NOTE: Grafana will fail to start if the value for ldap.toml is invalid - # auth.ldap: - # enabled: true - # allow_sign_up: true - # config_file: /etc/grafana/ldap.toml - -## Grafana's LDAP configuration -## Templated by the template in _helpers.tpl -## NOTE: To enable the grafana.ini must be configured with auth.ldap.enabled -## ref: http://docs.grafana.org/installation/configuration/#auth-ldap -## ref: http://docs.grafana.org/installation/ldap/#configuration -ldap: - enabled: false - # `existingSecret` is a reference to an existing secret containing the ldap configuration - # for Grafana in a key `ldap-toml`. - existingSecret: "" - # `config` is the content of `ldap.toml` that will be stored in the created secret - config: "" - # config: |- - # verbose_logging = true - - # [[servers]] - # host = "my-ldap-server" - # port = 636 - # use_ssl = true - # start_tls = false - # ssl_skip_verify = false - # bind_dn = "uid=%s,ou=users,dc=myorg,dc=com" - -## Grafana's SMTP configuration -## NOTE: To enable, grafana.ini must be configured with smtp.enabled -## ref: http://docs.grafana.org/installation/configuration/#smtp -smtp: - # `existingSecret` is a reference to an existing secret containing the smtp configuration - # for Grafana. - existingSecret: "" - userKey: "user" - passwordKey: "password" - -## Sidecars that collect the configmaps with specified label and stores the included files them into the respective folders -## Requires at least Grafana 5 to work and can't be used together with parameters dashboardProviders, datasources and dashboards -sidecar: - image: - repository: quay.io/kiwigrid/k8s-sidecar - tag: 1.24.6 - sha: "" - imagePullPolicy: IfNotPresent - resources: {} -# limits: -# cpu: 100m -# memory: 100Mi -# requests: -# cpu: 50m -# memory: 50Mi - securityContext: - allowPrivilegeEscalation: false - capabilities: - drop: - - ALL - seccompProfile: - type: RuntimeDefault - # skipTlsVerify Set to true to skip tls verification for kube api calls - # skipTlsVerify: true - enableUniqueFilenames: false - readinessProbe: {} - livenessProbe: {} - # Log level default for all sidecars. Can be one of: DEBUG, INFO, WARN, ERROR, CRITICAL. Defaults to INFO - # logLevel: INFO - alerts: - enabled: false - # Additional environment variables for the alerts sidecar - env: {} - # Do not reprocess already processed unchanged resources on k8s API reconnect. - # ignoreAlreadyProcessed: true - # label that the configmaps with alert are marked with - label: grafana_alert - # value of label that the configmaps with alert are set to - labelValue: "" - # Log level. Can be one of: DEBUG, INFO, WARN, ERROR, CRITICAL. - # logLevel: INFO - # If specified, the sidecar will search for alert config-maps inside this namespace. - # Otherwise the namespace in which the sidecar is running will be used. - # It's also possible to specify ALL to search in all namespaces - searchNamespace: null - # Method to use to detect ConfigMap changes. With WATCH the sidecar will do a WATCH requests, with SLEEP it will list all ConfigMaps, then sleep for 60 seconds. - watchMethod: WATCH - # search in configmap, secret or both - resource: both - # watchServerTimeout: request to the server, asking it to cleanly close the connection after that. - # defaults to 60sec; much higher values like 3600 seconds (1h) are feasible for non-Azure K8S - # watchServerTimeout: 3600 - # - # watchClientTimeout: is a client-side timeout, configuring your local socket. - # If you have a network outage dropping all packets with no RST/FIN, - # this is how long your client waits before realizing & dropping the connection. - # defaults to 66sec (sic!) - # watchClientTimeout: 60 - # - # Endpoint to send request to reload alerts - reloadURL: "http://localhost:3000/api/admin/provisioning/alerting/reload" - # Absolute path to shell script to execute after a alert got reloaded - script: null - skipReload: false - # Deploy the alert sidecar as an initContainer in addition to a container. - # Additional alert sidecar volume mounts - extraMounts: [] - # Sets the size limit of the alert sidecar emptyDir volume - sizeLimit: {} - dashboards: - enabled: false - # Additional environment variables for the dashboards sidecar - env: {} - # Do not reprocess already processed unchanged resources on k8s API reconnect. - # ignoreAlreadyProcessed: true - SCProvider: true - # label that the configmaps with dashboards are marked with - label: grafana_dashboard - # value of label that the configmaps with dashboards are set to - labelValue: "" - # Log level. Can be one of: DEBUG, INFO, WARN, ERROR, CRITICAL. - # logLevel: INFO - # folder in the pod that should hold the collected dashboards (unless `defaultFolderName` is set) - folder: /tmp/dashboards - # The default folder name, it will create a subfolder under the `folder` and put dashboards in there instead - defaultFolderName: null - # Namespaces list. If specified, the sidecar will search for config-maps/secrets inside these namespaces. - # Otherwise the namespace in which the sidecar is running will be used. - # It's also possible to specify ALL to search in all namespaces. - searchNamespace: null - # Method to use to detect ConfigMap changes. With WATCH the sidecar will do a WATCH requests, with SLEEP it will list all ConfigMaps, then sleep for 60 seconds. - watchMethod: WATCH - # search in configmap, secret or both - resource: both - # If specified, the sidecar will look for annotation with this name to create folder and put graph here. - # You can use this parameter together with `provider.foldersFromFilesStructure`to annotate configmaps and create folder structure. - folderAnnotation: null - # Endpoint to send request to reload alerts - reloadURL: "http://localhost:3000/api/admin/provisioning/dashboards/reload" - # Absolute path to shell script to execute after a configmap got reloaded - script: null - skipReload: false - # watchServerTimeout: request to the server, asking it to cleanly close the connection after that. - # defaults to 60sec; much higher values like 3600 seconds (1h) are feasible for non-Azure K8S - # watchServerTimeout: 3600 - # - # watchClientTimeout: is a client-side timeout, configuring your local socket. - # If you have a network outage dropping all packets with no RST/FIN, - # this is how long your client waits before realizing & dropping the connection. - # defaults to 66sec (sic!) - # watchClientTimeout: 60 - # - # provider configuration that lets grafana manage the dashboards - provider: - # name of the provider, should be unique - name: sidecarProvider - # orgid as configured in grafana - orgid: 1 - # folder in which the dashboards should be imported in grafana - folder: '' - # type of the provider - type: file - # disableDelete to activate a import-only behaviour - disableDelete: false - # allow updating provisioned dashboards from the UI - allowUiUpdates: false - # allow Grafana to replicate dashboard structure from filesystem - foldersFromFilesStructure: false - # Additional dashboard sidecar volume mounts - extraMounts: [] - # Sets the size limit of the dashboard sidecar emptyDir volume - sizeLimit: {} - datasources: - enabled: false - # Additional environment variables for the datasourcessidecar - env: {} - # Do not reprocess already processed unchanged resources on k8s API reconnect. - # ignoreAlreadyProcessed: true - # label that the configmaps with datasources are marked with - label: grafana_datasource - # value of label that the configmaps with datasources are set to - labelValue: "" - # Log level. Can be one of: DEBUG, INFO, WARN, ERROR, CRITICAL. - # logLevel: INFO - # If specified, the sidecar will search for datasource config-maps inside this namespace. - # Otherwise the namespace in which the sidecar is running will be used. - # It's also possible to specify ALL to search in all namespaces - searchNamespace: null - # Method to use to detect ConfigMap changes. With WATCH the sidecar will do a WATCH requests, with SLEEP it will list all ConfigMaps, then sleep for 60 seconds. - watchMethod: WATCH - # search in configmap, secret or both - resource: both - # watchServerTimeout: request to the server, asking it to cleanly close the connection after that. - # defaults to 60sec; much higher values like 3600 seconds (1h) are feasible for non-Azure K8S - # watchServerTimeout: 3600 - # - # watchClientTimeout: is a client-side timeout, configuring your local socket. - # If you have a network outage dropping all packets with no RST/FIN, - # this is how long your client waits before realizing & dropping the connection. - # defaults to 66sec (sic!) - # watchClientTimeout: 60 - # - # Endpoint to send request to reload datasources - reloadURL: "http://localhost:3000/api/admin/provisioning/datasources/reload" - # Absolute path to shell script to execute after a datasource got reloaded - script: null - skipReload: false - # Deploy the datasource sidecar as an initContainer in addition to a container. - # This is needed if skipReload is true, to load any datasources defined at startup time. - initDatasources: false - # Sets the size limit of the datasource sidecar emptyDir volume - sizeLimit: {} - plugins: - enabled: false - # Additional environment variables for the plugins sidecar - env: {} - # Do not reprocess already processed unchanged resources on k8s API reconnect. - # ignoreAlreadyProcessed: true - # label that the configmaps with plugins are marked with - label: grafana_plugin - # value of label that the configmaps with plugins are set to - labelValue: "" - # Log level. Can be one of: DEBUG, INFO, WARN, ERROR, CRITICAL. - # logLevel: INFO - # If specified, the sidecar will search for plugin config-maps inside this namespace. - # Otherwise the namespace in which the sidecar is running will be used. - # It's also possible to specify ALL to search in all namespaces - searchNamespace: null - # Method to use to detect ConfigMap changes. With WATCH the sidecar will do a WATCH requests, with SLEEP it will list all ConfigMaps, then sleep for 60 seconds. - watchMethod: WATCH - # search in configmap, secret or both - resource: both - # watchServerTimeout: request to the server, asking it to cleanly close the connection after that. - # defaults to 60sec; much higher values like 3600 seconds (1h) are feasible for non-Azure K8S - # watchServerTimeout: 3600 - # - # watchClientTimeout: is a client-side timeout, configuring your local socket. - # If you have a network outage dropping all packets with no RST/FIN, - # this is how long your client waits before realizing & dropping the connection. - # defaults to 66sec (sic!) - # watchClientTimeout: 60 - # - # Endpoint to send request to reload plugins - reloadURL: "http://localhost:3000/api/admin/provisioning/plugins/reload" - # Absolute path to shell script to execute after a plugin got reloaded - script: null - skipReload: false - # Deploy the datasource sidecar as an initContainer in addition to a container. - # This is needed if skipReload is true, to load any plugins defined at startup time. - initPlugins: false - # Sets the size limit of the plugin sidecar emptyDir volume - sizeLimit: {} - notifiers: - enabled: false - # Additional environment variables for the notifierssidecar - env: {} - # Do not reprocess already processed unchanged resources on k8s API reconnect. - # ignoreAlreadyProcessed: true - # label that the configmaps with notifiers are marked with - label: grafana_notifier - # value of label that the configmaps with notifiers are set to - labelValue: "" - # Log level. Can be one of: DEBUG, INFO, WARN, ERROR, CRITICAL. - # logLevel: INFO - # If specified, the sidecar will search for notifier config-maps inside this namespace. - # Otherwise the namespace in which the sidecar is running will be used. - # It's also possible to specify ALL to search in all namespaces - searchNamespace: null - # Method to use to detect ConfigMap changes. With WATCH the sidecar will do a WATCH requests, with SLEEP it will list all ConfigMaps, then sleep for 60 seconds. - watchMethod: WATCH - # search in configmap, secret or both - resource: both - # watchServerTimeout: request to the server, asking it to cleanly close the connection after that. - # defaults to 60sec; much higher values like 3600 seconds (1h) are feasible for non-Azure K8S - # watchServerTimeout: 3600 - # - # watchClientTimeout: is a client-side timeout, configuring your local socket. - # If you have a network outage dropping all packets with no RST/FIN, - # this is how long your client waits before realizing & dropping the connection. - # defaults to 66sec (sic!) - # watchClientTimeout: 60 - # - # Endpoint to send request to reload notifiers - reloadURL: "http://localhost:3000/api/admin/provisioning/notifications/reload" - # Absolute path to shell script to execute after a notifier got reloaded - script: null - skipReload: false - # Deploy the notifier sidecar as an initContainer in addition to a container. - # This is needed if skipReload is true, to load any notifiers defined at startup time. - initNotifiers: false - # Sets the size limit of the notifier sidecar emptyDir volume - sizeLimit: {} - -## Override the deployment namespace -## -namespaceOverride: "" - -## Number of old ReplicaSets to retain -## -revisionHistoryLimit: 10 - -## Add a seperate remote image renderer deployment/service -imageRenderer: - deploymentStrategy: {} - # Enable the image-renderer deployment & service - enabled: false - replicas: 2 - autoscaling: - enabled: false - minReplicas: 2 - maxReplicas: 5 - targetCPU: "60" - targetMemory: "" - behavior: {} - image: - # image-renderer Image repository - repository: docker.io/grafana/grafana-image-renderer - # image-renderer Image tag - tag: latest - # image-renderer Image sha (optional) - sha: "" - # image-renderer ImagePullPolicy - pullPolicy: Always - # extra environment variables - env: - HTTP_HOST: "0.0.0.0" - # RENDERING_ARGS: --no-sandbox,--disable-gpu,--window-size=1280x758 - # RENDERING_MODE: clustered - # IGNORE_HTTPS_ERRORS: true - - ## "valueFrom" environment variable references that will be added to deployment pods. Name is templated. - ## ref: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.19/#envvarsource-v1-core - ## Renders in container spec as: - ## env: - ## ... - ## - name: - ## valueFrom: - ## - envValueFrom: {} - # ENV_NAME: - # configMapKeyRef: - # name: configmap-name - # key: value_key - - # image-renderer deployment serviceAccount - serviceAccountName: "" - # image-renderer deployment securityContext - securityContext: {} - # image-renderer deployment container securityContext - containerSecurityContext: - seccompProfile: - type: RuntimeDefault - capabilities: - drop: ['ALL'] - allowPrivilegeEscalation: false - readOnlyRootFilesystem: true - # image-renderer deployment Host Aliases - hostAliases: [] - # image-renderer deployment priority class - priorityClassName: '' - service: - # Enable the image-renderer service - enabled: true - # image-renderer service port name - portName: 'http' - # image-renderer service port used by both service and deployment - port: 8081 - targetPort: 8081 - # Adds the appProtocol field to the image-renderer service. This allows to work with istio protocol selection. Ex: "http" or "tcp" - appProtocol: "" - serviceMonitor: - ## If true, a ServiceMonitor CRD is created for a prometheus operator - ## https://github.com/coreos/prometheus-operator - ## - enabled: false - path: /metrics - # namespace: monitoring (defaults to use the namespace this chart is deployed to) - labels: {} - interval: 1m - scheme: http - tlsConfig: {} - scrapeTimeout: 30s - relabelings: [] - # See: https://doc.crds.dev/github.com/prometheus-operator/kube-prometheus/monitoring.coreos.com/ServiceMonitor/v1@v0.11.0#spec-targetLabels - targetLabels: [] - # - targetLabel1 - # - targetLabel2 - # If https is enabled in Grafana, this needs to be set as 'https' to correctly configure the callback used in Grafana - grafanaProtocol: http - # In case a sub_path is used this needs to be added to the image renderer callback - grafanaSubPath: "" - # name of the image-renderer port on the pod - podPortName: http - # number of image-renderer replica sets to keep - revisionHistoryLimit: 10 - networkPolicy: - # Enable a NetworkPolicy to limit inbound traffic to only the created grafana pods - limitIngress: true - # Enable a NetworkPolicy to limit outbound traffic to only the created grafana pods - limitEgress: false - # Allow additional services to access image-renderer (eg. Prometheus operator when ServiceMonitor is enabled) - extraIngressSelectors: [] - resources: {} -# limits: -# cpu: 100m -# memory: 100Mi -# requests: -# cpu: 50m -# memory: 50Mi - ## Node labels for pod assignment - ## ref: https://kubernetes.io/docs/user-guide/node-selection/ - # - nodeSelector: {} - - ## Tolerations for pod assignment - ## ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/ - ## - tolerations: [] - - ## Affinity for pod assignment (evaluated as template) - ## ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity - ## - affinity: {} - - ## Use an alternate scheduler, e.g. "stork". - ## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/ - ## - # schedulerName: "default-scheduler" - -networkPolicy: - ## @param networkPolicy.enabled Enable creation of NetworkPolicy resources. Only Ingress traffic is filtered for now. - ## - enabled: false - ## @param networkPolicy.allowExternal Don't require client label for connections - ## The Policy model to apply. When set to false, only pods with the correct - ## client label will have network access to grafana port defined. - ## When true, grafana will accept connections from any source - ## (with the correct destination port). - ## - ingress: true - ## @param networkPolicy.ingress When true enables the creation - ## an ingress network policy - ## - allowExternal: true - ## @param networkPolicy.explicitNamespacesSelector A Kubernetes LabelSelector to explicitly select namespaces from which traffic could be allowed - ## If explicitNamespacesSelector is missing or set to {}, only client Pods that are in the networkPolicy's namespace - ## and that match other criteria, the ones that have the good label, can reach the grafana. - ## But sometimes, we want the grafana to be accessible to clients from other namespaces, in this case, we can use this - ## LabelSelector to select these namespaces, note that the networkPolicy's namespace should also be explicitly added. - ## - ## Example: - ## explicitNamespacesSelector: - ## matchLabels: - ## role: frontend - ## matchExpressions: - ## - {key: role, operator: In, values: [frontend]} - ## - explicitNamespacesSelector: {} - ## - ## - ## - ## - ## - ## - egress: - ## @param networkPolicy.egress.enabled When enabled, an egress network policy will be - ## created allowing grafana to connect to external data sources from kubernetes cluster. - enabled: false - ## - ## @param networkPolicy.egress.ports Add individual ports to be allowed by the egress - ports: [] - ## Add ports to the egress by specifying - port: - ## E.X. - ## ports: - ## - port: 80 - ## - port: 443 - ## - ## - ## - ## - ## - ## - -# Enable backward compatibility of kubernetes where version below 1.13 doesn't have the enableServiceLinks option -enableKubeBackwardCompatibility: false -useStatefulSet: false -# Create a dynamic manifests via values: -extraObjects: [] - # - apiVersion: "kubernetes-client.io/v1" - # kind: ExternalSecret - # metadata: - # name: grafana-secrets - # spec: - # backendType: gcpSecretsManager - # data: - # - key: grafana-admin-password - # name: adminPassword diff --git a/helm-overrides/k8s-admin-prd-ase1/grafana/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/grafana/custom-values.yaml deleted file mode 100644 index c11797b..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/grafana/custom-values.yaml +++ /dev/null @@ -1,275 +0,0 @@ -grafana: - # From Vault via ExternalSecret (devops-infra-argo-config/secretstores/ - # grafana-admin-credentials.yaml), same pattern as gitea/harbor/jenkins - # admin credentials elsewhere in this project — never a plaintext - # adminPassword in this file. - admin: - existingSecret: grafana-admin-credentials - userKey: username - passwordKey: password - - persistence: - # local-path-provisioner, this cluster's default StorageClass — - # installed right after Cilium precisely because kubeadm ships no - # default (unlike k3s). 1Gi, not the chart's 10Gi default: this is - # dashboards, folders and Grafana's own sqlite state, not metric - # data — VictoriaMetrics holds that. Not resizable in place with - # this provisioner, so sized deliberately rather than grown later. - enabled: true - storageClassName: local-path - size: 1Gi - - resources: - requests: - cpu: 50m - memory: 128Mi - limits: - memory: 384Mi - - # Provisioned at boot, not clicked through in the UI — the same reason - # every other credential/config in this project is committed rather - # than set by hand: it survives a pod restart and a fresh install gets - # it automatically. VictoriaMetrics speaks Prometheus's own query API, - # so `type: prometheus` here is correct even though the URL is VM's — - # see this repo's victoria-metrics-single chart for why. - datasources: - datasources.yaml: - apiVersion: 1 - datasources: - - name: VictoriaMetrics - # Fixed uid, not left to auto-generate — the provisioned - # dashboard below references this datasource by uid, and an - # auto-generated one would only exist after Grafana's first - # boot, too late for a dashboard provisioned in the same boot. - uid: victoriametrics - type: prometheus - access: proxy - url: http://victoria-metrics-single-server.monitoring.svc.cluster.local:8428 - isDefault: true - - # Dashboard provisioning. Provisioned rather than built by hand in the - # UI for the same reason the datasource above is: it survives a pod - # restart (this deployment has no persistent Grafana database beyond - # the 1Gi PVC, and even with one, a fresh install should not start - # with an empty dashboard list) and a `git diff` shows what changed. - dashboardProviders: - dashboardproviders.yaml: - apiVersion: 1 - providers: - - name: default - orgId: 1 - folder: "" - type: file - disableDeletion: false - editable: true - options: - path: /var/lib/grafana/dashboards/default - - # "Homelab Overview" — total Envoy/Contour RPS, per-namespace CPU and - # memory (the $namespace template variable filters every relevant - # panel), cluster-wide utilization against actual node capacity, and a - # total-resources row (cores/memory/pods/disk). Envoy and node-exporter - # metrics both required their own vmagent scrape job — see - # helm-overrides/.../vmagent/custom-values.yaml for why neither was - # reachable through the chart's own defaults in this cluster. - # - # Every panel except "Disk free" was run against the live deployment - # (vmui, over Tailscale) before being written in here — RPS, per- - # namespace CPU/memory, machine_cpu_cores/machine_memory_bytes all - # returned real data. "Disk free" depends on the node-exporter scrape - # job added alongside this same change, which had not been live yet to - # verify against — worth checking once this actually deploys, same as - # everything else in this repo that gets a `helm template` check but - # cannot get a live one before the first sync. - dashboards: - default: - homelab: - json: | - { - "title": "Homelab Overview", - "uid": "homelab-overview", - "schemaVersion": 39, - "editable": true, - "timezone": "browser", - "time": { "from": "now-1h", "to": "now" }, - "refresh": "30s", - "templating": { - "list": [ - { - "name": "namespace", - "type": "query", - "datasource": { "type": "prometheus", "uid": "victoriametrics" }, - "query": "label_values(container_memory_working_set_bytes{container!=\"\", container!=\"POD\"}, namespace)", - "refresh": 2, - "multi": true, - "includeAll": true, - "current": { "selected": true, "text": "All", "value": "$__all" } - } - ] - }, - "panels": [ - { "type": "row", "title": "Ingress (Envoy / Contour)", "gridPos": { "h": 1, "w": 24, "x": 0, "y": 0 }, "id": 100 }, - - { - "type": "stat", "title": "Total RPS", "id": 1, - "gridPos": { "h": 6, "w": 6, "x": 0, "y": 1 }, - "datasource": { "type": "prometheus", "uid": "victoriametrics" }, - "targets": [{ "expr": "sum(rate(envoy_http_downstream_rq_total{namespace=\"projectcontour\"}[5m]))", "legendFormat": "rps" }], - "fieldConfig": { "defaults": { "unit": "reqps", "decimals": 2 }, "overrides": [] }, - "options": { "reduceOptions": { "calcs": ["lastNotNull"] }, "graphMode": "area" } - }, - { - "type": "stat", "title": "Active downstream connections", "id": 2, - "gridPos": { "h": 6, "w": 6, "x": 6, "y": 1 }, - "datasource": { "type": "prometheus", "uid": "victoriametrics" }, - "targets": [{ "expr": "sum(envoy_http_downstream_cx_active{namespace=\"projectcontour\"})", "legendFormat": "connections" }], - "fieldConfig": { "defaults": { "unit": "short" }, "overrides": [] } - }, - { - "type": "timeseries", "title": "Requests by response class", "id": 3, - "gridPos": { "h": 6, "w": 12, "x": 12, "y": 1 }, - "datasource": { "type": "prometheus", "uid": "victoriametrics" }, - "targets": [{ - "expr": "sum by (envoy_response_code_class) (rate(envoy_http_downstream_rq_xx{namespace=\"projectcontour\"}[5m]))", - "legendFormat": "{{envoy_response_code_class}}xx" - }], - "fieldConfig": { "defaults": { "unit": "reqps" }, "overrides": [] }, - "options": { "legend": { "displayMode": "list", "placement": "bottom" } } - }, - - { "type": "row", "title": "Service level (by namespace)", "gridPos": { "h": 1, "w": 24, "x": 0, "y": 7 }, "id": 101 }, - - { - "type": "timeseries", "title": "CPU usage by namespace", "id": 10, - "gridPos": { "h": 8, "w": 12, "x": 0, "y": 8 }, - "datasource": { "type": "prometheus", "uid": "victoriametrics" }, - "targets": [{ - "expr": "sum by (namespace) (rate(container_cpu_usage_seconds_total{namespace=~\"$namespace\", container!=\"\", container!=\"POD\"}[5m]))", - "legendFormat": "{{namespace}}" - }], - "fieldConfig": { "defaults": { "unit": "short", "custom": { "fillOpacity": 10, "stacking": { "mode": "normal" } } }, "overrides": [] }, - "options": { "legend": { "displayMode": "table", "placement": "right", "calcs": ["mean", "max"] } } - }, - { - "type": "timeseries", "title": "Memory usage by namespace", "id": 11, - "gridPos": { "h": 8, "w": 12, "x": 12, "y": 8 }, - "datasource": { "type": "prometheus", "uid": "victoriametrics" }, - "targets": [{ - "expr": "sum by (namespace) (container_memory_working_set_bytes{namespace=~\"$namespace\", container!=\"\", container!=\"POD\"})", - "legendFormat": "{{namespace}}" - }], - "fieldConfig": { "defaults": { "unit": "bytes", "custom": { "fillOpacity": 10, "stacking": { "mode": "normal" } } }, "overrides": [] }, - "options": { "legend": { "displayMode": "table", "placement": "right", "calcs": ["mean", "max"] } } - }, - { - "type": "table", "title": "Current usage per namespace", "id": 12, - "gridPos": { "h": 8, "w": 24, "x": 0, "y": 16 }, - "datasource": { "type": "prometheus", "uid": "victoriametrics" }, - "targets": [ - { "expr": "sum by (namespace) (rate(container_cpu_usage_seconds_total{namespace=~\"$namespace\", container!=\"\", container!=\"POD\"}[5m]))", "format": "table", "instant": true, "refId": "A" }, - { "expr": "sum by (namespace) (container_memory_working_set_bytes{namespace=~\"$namespace\", container!=\"\", container!=\"POD\"})", "format": "table", "instant": true, "refId": "B" }, - { "expr": "count by (namespace) (count by (namespace, pod) (container_memory_working_set_bytes{namespace=~\"$namespace\", container!=\"\", container!=\"POD\"}))", "format": "table", "instant": true, "refId": "C" } - ], - "transformations": [ - { "id": "merge", "options": {} }, - { "id": "organize", "options": { - "excludeByName": { "Time": true, "Time 1": true, "Time 2": true, "Time 3": true }, - "renameByName": { "Value #A": "CPU (cores)", "Value #B": "Memory", "Value #C": "Pods" } - } } - ], - "fieldConfig": { "defaults": {}, "overrides": [ - { "matcher": { "id": "byName", "options": "Memory" }, "properties": [{ "id": "unit", "value": "bytes" }] }, - { "matcher": { "id": "byName", "options": "CPU (cores)" }, "properties": [{ "id": "unit", "value": "short" }, { "id": "decimals", "value": 3 }] } - ] } - }, - - { "type": "row", "title": "Cluster utilization", "gridPos": { "h": 1, "w": 24, "x": 0, "y": 24 }, "id": 102 }, - - { - "type": "gauge", "title": "CPU utilization", "id": 20, - "gridPos": { "h": 7, "w": 6, "x": 0, "y": 25 }, - "datasource": { "type": "prometheus", "uid": "victoriametrics" }, - "targets": [{ "expr": "100 * sum(rate(container_cpu_usage_seconds_total{container!=\"\", container!=\"POD\"}[5m])) / sum(machine_cpu_cores)" }], - "fieldConfig": { "defaults": { "unit": "percent", "min": 0, "max": 100, - "thresholds": { "mode": "absolute", "steps": [ - { "color": "green", "value": null }, { "color": "yellow", "value": 70 }, { "color": "red", "value": 90 } - ] } }, "overrides": [] } - }, - { - "type": "gauge", "title": "Memory utilization", "id": 21, - "gridPos": { "h": 7, "w": 6, "x": 6, "y": 25 }, - "datasource": { "type": "prometheus", "uid": "victoriametrics" }, - "targets": [{ "expr": "100 * sum(container_memory_working_set_bytes{container!=\"\", container!=\"POD\"}) / sum(machine_memory_bytes)" }], - "fieldConfig": { "defaults": { "unit": "percent", "min": 0, "max": 100, - "thresholds": { "mode": "absolute", "steps": [ - { "color": "green", "value": null }, { "color": "yellow", "value": 70 }, { "color": "red", "value": 90 } - ] } }, "overrides": [] } - }, - { - "type": "timeseries", "title": "Cluster CPU utilization over time", "id": 22, - "gridPos": { "h": 7, "w": 12, "x": 12, "y": 25 }, - "datasource": { "type": "prometheus", "uid": "victoriametrics" }, - "targets": [ - { "expr": "100 * sum(rate(container_cpu_usage_seconds_total{container!=\"\", container!=\"POD\"}[5m])) / sum(machine_cpu_cores)", "legendFormat": "CPU %" }, - { "expr": "100 * sum(container_memory_working_set_bytes{container!=\"\", container!=\"POD\"}) / sum(machine_memory_bytes)", "legendFormat": "Memory %" } - ], - "fieldConfig": { "defaults": { "unit": "percent", "min": 0 }, "overrides": [] } - }, - - { "type": "row", "title": "Total resources", "gridPos": { "h": 1, "w": 24, "x": 0, "y": 32 }, "id": 103 }, - - { - "type": "stat", "title": "Node CPU capacity", "id": 30, - "gridPos": { "h": 5, "w": 4, "x": 0, "y": 33 }, - "datasource": { "type": "prometheus", "uid": "victoriametrics" }, - "targets": [{ "expr": "max(machine_cpu_cores)" }], - "fieldConfig": { "defaults": { "unit": "short", "displayName": "cores" }, "overrides": [] } - }, - { - "type": "stat", "title": "Node memory capacity", "id": 31, - "gridPos": { "h": 5, "w": 4, "x": 4, "y": 33 }, - "datasource": { "type": "prometheus", "uid": "victoriametrics" }, - "targets": [{ "expr": "max(machine_memory_bytes)" }], - "fieldConfig": { "defaults": { "unit": "bytes" }, "overrides": [] } - }, - { - "type": "stat", "title": "CPU used (cluster)", "id": 32, - "gridPos": { "h": 5, "w": 4, "x": 8, "y": 33 }, - "datasource": { "type": "prometheus", "uid": "victoriametrics" }, - "targets": [{ "expr": "sum(rate(container_cpu_usage_seconds_total{container!=\"\", container!=\"POD\"}[5m]))" }], - "fieldConfig": { "defaults": { "unit": "short", "displayName": "cores", "decimals": 2 }, "overrides": [] } - }, - { - "type": "stat", "title": "Memory used (cluster)", "id": 33, - "gridPos": { "h": 5, "w": 4, "x": 12, "y": 33 }, - "datasource": { "type": "prometheus", "uid": "victoriametrics" }, - "targets": [{ "expr": "sum(container_memory_working_set_bytes{container!=\"\", container!=\"POD\"})" }], - "fieldConfig": { "defaults": { "unit": "bytes" }, "overrides": [] } - }, - { - "type": "stat", "title": "Running pods", "id": 34, - "gridPos": { "h": 5, "w": 4, "x": 16, "y": 33 }, - "datasource": { "type": "prometheus", "uid": "victoriametrics" }, - "targets": [{ "expr": "count(count by (namespace, pod) (container_memory_working_set_bytes{container!=\"\", container!=\"POD\"}))" }], - "fieldConfig": { "defaults": { "unit": "short" }, "overrides": [] } - }, - { - "type": "stat", "title": "Disk free (root)", "id": 35, - "gridPos": { "h": 5, "w": 4, "x": 20, "y": 33 }, - "datasource": { "type": "prometheus", "uid": "victoriametrics" }, - "targets": [{ "expr": "node_filesystem_avail_bytes{mountpoint=\"/\"}" }], - "fieldConfig": { "defaults": { "unit": "bytes", - "thresholds": { "mode": "absolute", "steps": [ - { "color": "red", "value": null }, { "color": "yellow", "value": 5000000000 }, { "color": "green", "value": 15000000000 } - ] } }, "overrides": [] } - } - ] - } - - ingress: - enabled: true - ingressClassName: contour - path: / - hosts: - - grafana.192.168.1.7.nip.io - - grafana.100.90.248.118.nip.io diff --git a/helm-overrides/k8s-admin-prd-ase1/harbor/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/harbor/custom-values.yaml deleted file mode 100644 index 02041e9..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/harbor/custom-values.yaml +++ /dev/null @@ -1,112 +0,0 @@ -harbor: - # Fresh install (helm list -n harbor came back empty — claude.md's "Just - # installed this session" note was stale). Minimal footprint by request: - # Trivy disabled (Notary/ChartMuseum aren't even in this chart anymore — - # dropped upstream, not something to disable), database/redis are - # Harbor's own required internal state (not optional the way Trivy is, - # despite what I initially suggested), everything else trimmed. - # - # Plain HTTP, matching every other app here (Vault tls_disable, ArgoCD - # --insecure, etc.) — avoids cert-manager entirely for this homelab. - # Note: this only affects the ingress. Jenkins pushing images should go - # through Harbor's internal cluster-DNS service (harbor-core.harbor.svc.cluster.local) - # instead, per claude.md's own plan — pod-to-pod traffic never touches - # the ingress, so no client-side insecure-registry config needed for CI. - # Pulling/pushing from outside the cluster (e.g. your laptop) through the - # ingress WOULD need Docker configured to treat this host as an insecure - # registry, since there's no TLS here. - expose: - type: ingress - tls: - enabled: false - ingress: - hosts: - core: "harbor.192.168.1.7.nip.io" - className: contour - - externalURL: "http://harbor.192.168.1.7.nip.io" - - # Vault-backed from the start, same pattern as jenkins-admin-credentials. - # See devops-infra-argo-config/secretstores/harbor-admin-credentials.yaml - # and vault kv path secret/harbor/admin. - existingSecretAdminPassword: harbor-admin-credentials - existingSecretAdminPasswordKey: HARBOR_ADMIN_PASSWORD - - trivy: - enabled: false - - persistence: - enabled: true - resourcePolicy: "keep" - persistentVolumeClaim: - registry: - storageClass: local-path - size: 5Gi - jobservice: - jobLog: - storageClass: local-path - size: 1Gi - database: - storageClass: local-path - size: 1Gi - redis: - storageClass: local-path - size: 1Gi - - portal: - resources: - requests: - cpu: 50m - memory: 128Mi - limits: - memory: 256Mi - - core: - resources: - requests: - cpu: 100m - memory: 256Mi - limits: - memory: 512Mi - - jobservice: - resources: - requests: - cpu: 50m - memory: 128Mi - limits: - memory: 256Mi - - registry: - registry: - resources: - requests: - cpu: 100m - memory: 128Mi - limits: - memory: 256Mi - controller: - resources: - requests: - cpu: 50m - memory: 64Mi - limits: - memory: 128Mi - - database: - internal: - resources: - requests: - cpu: 100m - memory: 256Mi - limits: - memory: 512Mi - - redis: - internal: - resources: - requests: - cpu: 50m - memory: 64Mi - limits: - memory: 128Mi diff --git a/helm-overrides/k8s-admin-prd-ase1/ingress-nginx-external/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/ingress-nginx-external/custom-values.yaml deleted file mode 100644 index 07fa139..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/ingress-nginx-external/custom-values.yaml +++ /dev/null @@ -1,34 +0,0 @@ -ingress-nginx: - controller: - metrics: - enabled: true - podAnnotations: - prometheus.io/port: "10254" - prometheus.io/scrape: "true" - resources: - requests: - cpu: 200m - memory: 512Mi - autoscaling: - enabled: true - minReplicas: 4 - maxReplicas: 30 - targetCPUUtilizationPercentage: 60 - targetMemoryUtilizationPercentage: 60 - ingressClass: nginx-external - ingressClassByName: true - watchIngressWithoutClass: false - ingressClassResource: - controllerValue: k8s.io/ingress-nginx-external - name: nginx-external - service: - type: ClusterIP - annotations: - cloud.google.com/neg: '{"exposed_ports": {"80":{"name": "nginx-ext-admin-prd"}}}' - nodeSelector: - dedicated: devops - tolerations: - - key: "dedicated" - operator: "Equal" - value: "devops" - effect: "NoSchedule" diff --git a/helm-overrides/k8s-admin-prd-ase1/ingress-nginx/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/ingress-nginx/custom-values.yaml deleted file mode 100644 index abb4c0f..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/ingress-nginx/custom-values.yaml +++ /dev/null @@ -1,32 +0,0 @@ -ingress-nginx: - controller: - config: - proxy-body-size: "50g" - metrics: - enabled: true - podAnnotations: - prometheus.io/port: "10254" - prometheus.io/scrape: "true" - resources: - requests: - cpu: 200m - memory: 512Mi - autoscaling: - enabled: true - minReplicas: 4 - maxReplicas: 30 - targetCPUUtilizationPercentage: 60 - targetMemoryUtilizationPercentage: 60 - ingressClassResource: - name: nginx-internal - service: - type: ClusterIP - annotations: - cloud.google.com/neg: '{"exposed_ports": {"80":{"name": "nginx-admin-prd"}}}' - nodeSelector: - dedicated: devops - tolerations: - - key: "dedicated" - operator: "Equal" - value: "devops" - effect: "NoSchedule" diff --git a/helm-overrides/k8s-admin-prd-ase1/jenkins/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/jenkins/custom-values.yaml deleted file mode 100644 index f0bd318..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/jenkins/custom-values.yaml +++ /dev/null @@ -1,98 +0,0 @@ -jenkins: - # Fresh install. Dynamic Kubernetes build agents come from agent.enabled - # (chart default, not overridden here) — agent pods only exist during - # builds, matching claude.md's "idle cost is just the controller" note. - # Trimmed agent pod resources below anyway, since they still compete for - # the same 8GB box while a build is running. - - controller: - image: - # Chart's default (unset here) falls back to appVersion 2.504.2 — - # but the chart's own bundled default plugin list (kubernetes, - # credentials, workflow-*, git, etc.) requires Jenkins core - # >= 2.504.3. Upstream inconsistency between the chart's pinned - # image tag and its own default plugins.txt, not our config — - # bumping the core image is the fix, not trimming plugins (several - # of them, especially `kubernetes`, are what dynamic build agents - # actually depend on). - tag: "2.504.3-jdk21" - # Chart default installPlugins list pins configuration-as-code at - # 1971.vf9280461ea_89, but kubernetes/git/credentials — also in that - # same default list — need 2006.v001a_2ca_6b_574. Another upstream - # chart-defaults inconsistency, same category as the image tag one - # above. Lists replace wholesale in Helm, not merge, so this is the - # chart's full default list with just that one version corrected — - # not a hand-picked subset. - # - # kubernetes-client-api added explicitly (not part of the chart's - # default list) — kubernetes originally pinned at 4353.vb_47977da_9417 - # required kubernetes-client-api >= 7.3.1-256.v788a_0b_787114 - # (confirmed via https://plugins.jenkins.io/kubernetes/dependencies/), - # but left unpinned it resolved to an older version at image-build - # time, producing `NoSuchMethodError: - # ConfigBuilder.withMasterUrl(String)` on every agent launch attempt - # — pods provisioned fine but the controller crashed trying to - # actually connect the agent (Reaper.preLaunch -> KubernetesCloud.connect - # -> KubernetesFactoryAdapter.createClient), so builds hung forever at - # "Still waiting to schedule task". kubernetes itself later bumped to - # 4437.v3a_18554d3f32 (updated via the Jenkins UI, then pinned here - # to match so a future restart doesn't silently revert it) — same - # kubernetes-client-api floor, and this exact pairing is what got a - # real build through checkout successfully. - installPlugins: - - kubernetes:4437.v3a_18554d3f32 - - kubernetes-client-api:7.3.1-256.v788a_0b_787114 - - workflow-aggregator:608.v67378e9d3db_1 - - git:5.7.0 - - configuration-as-code:2006.v001a_2ca_6b_574 - # readYaml (loadConfig.groovy's config.yaml parsing) and any future - # writeYaml/readJSON-type usage — not part of the chart's default - # list at all, missing entirely rather than version-mismatched like - # kubernetes-client-api above. - - pipeline-utility-steps:3.810.va_7672d206740 - resources: - requests: - cpu: 100m - memory: 512Mi - limits: - cpu: 500m - memory: 1Gi - admin: - # Vault-backed from the start (unlike gitea, which started as a - # plain kubectl secret and got migrated later) — see - # devops-infra-argo-config/secretstores/jenkins-admin-credentials.yaml - # and vault kv path secret/jenkins/admin. - existingSecret: jenkins-admin-credentials - userKey: jenkins-admin-user - passwordKey: jenkins-admin-password - ingress: - enabled: true - hostName: "jenkins.192.168.1.7.nip.io" - ingressClassName: contour - # This chart's primary ingress only supports one hostName — no - # extraHosts like argo-cd. secondaryingress renders a whole second - # Ingress object at the same backend (confirmed against the actual - # template, not assumed) — that's the supported way to get a second - # hostname here. paths must be set explicitly: the template just - # renders zero routes if left at the chart's own default `[]`, unlike - # the primary ingress. - secondaryingress: - enabled: true - hostName: "jenkins.100.90.248.118.nip.io" - ingressClassName: contour - paths: - - / - - agent: - resources: - requests: - cpu: 250m - memory: 256Mi - limits: - cpu: 500m - memory: 512Mi - - persistence: - enabled: true - storageClass: local-path - size: 5Gi diff --git a/helm-overrides/k8s-admin-prd-ase1/jfrog-public/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/jfrog-public/custom-values.yaml deleted file mode 100644 index b578c1f..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/jfrog-public/custom-values.yaml +++ /dev/null @@ -1,2041 +0,0 @@ -# Default values for artifactory. -# This is a YAML-formatted file. - -# Beware when changing values here. You should know what you are doing! -# Access the values with {{ .Values.key.subkey }} - -global: - # imageRegistry: releases-docker.jfrog.io - # imagePullSecrets: - # - myRegistryKeySecretName - ## Chart.AppVersion can be overidden using global.versions.artifactory or .Values.artifactory.image.tag - ## Note: Order of preference is 1) global.versions 2) .Values.artifactory.image.tag 3) Chart.AppVersion - ## This applies also for nginx images (.Values.nginx.image.tag) - versions: {} - # artifactory: - # joinKey: - # masterKey: - # joinKeySecretName: 'jfrog-public-prd-secret' - masterKeySecretName: 'jfrog-public-prd-secret' - - ## Note: tags customInitContainersBegin,customInitContainers,customVolumes,customVolumeMounts,customSidecarContainers can be used both from global and application level simultaneously - # customInitContainersBegin: | - - # customInitContainers: | - - # customVolumes: | - - # customVolumeMounts: | - - # customSidecarContainers: | - - ## certificates added to this secret will be copied to $JFROG_HOME/artifactory/var/etc/security/keys/trusted directory - customCertificates: - enabled: false - # certificateSecretName: - ## Applies to artifactory and nginx pods - nodeSelector: {} -## String to partially override artifactory.fullname template (will maintain the release name) -## -# nameOverride: - -## String to fully override artifactory.fullname template -## -fullnameOverride: jfrog-public-prd -initContainerImage: releases-docker.jfrog.io/ubi9/ubi-minimal:9.2.750.1697534106 -# Init containers -initContainers: - resources: - requests: - memory: "50Mi" - cpu: "10m" - limits: - memory: "1Gi" - cpu: "1" -installer: - platform: art-oss-helm -installerInfo: '{"productId": "Helm_artifactory-oss/{{ .Chart.Version }}", "features": [ { "featureId": "Platform/{{ default "kubernetes" .Values.installer.platform }}"}]}' -# For supporting pulling from private registries -# imagePullSecrets: -# - myRegistryKeySecretName - -## Artifactory systemYaml override -## This is for advanced usecases where users wants to provide their own systemYaml for configuring artifactory -## Refer: https://www.jfrog.com/confluence/display/JFROG/Artifactory+System+YAML -## Note: This will override existing (default) .Values.artifactory.systemYaml in values.yaml -## Alternatively, systemYaml can be overidden via customInitContainers using external sources like vaults, external repositories etc. Please refer customInitContainer section below for an example. -## Note: Order of preference is 1) customInitContainers 2) systemYamlOverride existingSecret 3) default systemYaml in values.yaml -systemYamlOverride: - ## You can use a pre-existing secret by specifying existingSecret - existingSecret: - ## The dataKey should be the name of the secret data key created. - dataKey: -## Role Based Access Control -## Ref: https://kubernetes.io/docs/admin/authorization/rbac/ -rbac: - create: false - role: - ## Rules to create. It follows the role specification - rules: - - apiGroups: - - '' - resources: - - services - - endpoints - - pods - verbs: - - get - - watch - - list -## Service Account -## Ref: https://kubernetes.io/docs/admin/service-accounts-admin/ -## -serviceAccount: - create: false - ## The name of the ServiceAccount to use. - ## If not set and create is true, a name is generated using the fullname template - name: - ## Service Account annotations - annotations: {} - ## Explicitly mounts the API credentials for the Service Account - automountServiceAccountToken: false - -externalSecret: - enabled: true - key: 'prd/admin/jfrog-public' - secretStoreRef: - name: 'vault-backend' - -ingress: - enabled: true - defaultBackend: - enabled: true - # Used to create an Ingress record. - hosts: ["jfrog-public-prd.infr-h1.meeshogcp.in"] - routerPath: / - artifactoryPath: /artifactory/ - rtfsPath: /artifactory/service/rtfs/ - className: "nginx-external" - annotations: - nginx.ingress.kubernetes.io/proxy-body-size: "0" - # kubernetes.io/ingress.class: nginx - # nginx.ingress.kubernetes.io/configuration-snippet: | - # proxy_pass_header Server; - # proxy_set_header X-JFrog-Override-Base-Url https://; - # kubernetes.io/tls-acme: "true" - # nginx.ingress.kubernetes.io/proxy-body-size: "0" - labels: {} - # traffic-type: external - # traffic-type: internal - tls: [] - # Secrets must be manually created in the namespace. - # - secretName: chart-example-tls - # hosts: - # - artifactory.domain.example - - # Additional ingress rules - additionalRules: [] -## Allows to add custom ingress -customIngress: "" -networkpolicy: [] -# Allows all ingress and egress -# - name: artifactory -# podSelector: -# matchLabels: -# app: artifactory -# egress: -# - {} -# ingress: -# - {} -# Uncomment to allow only artifactory pods to communicate with postgresql (if postgresql.enabled is true) -# - name: postgresql -# podSelector: -# matchLabels: -# app: postgresql -# ingress: -# - from: -# - podSelector: -# matchLabels: -# app: artifactory - -## Apply horizontal pod auto scaling on artifactory pods -## Ref: https://kubernetes.io/docs/tasks/run-application/horizontal-pod-autoscale/ -autoscaling: - enabled: false - minReplicas: 1 - maxReplicas: 3 - targetCPUUtilizationPercentage: 70 -logger: - image: - registry: releases-docker.jfrog.io - repository: jfrog/artifactory-oss - tag: 9.2.750.1697534106 -## You can use a pre-existing secret with keys license_token and iam_role by specifying licenseConfigSecretName -## Example : Create a generic secret using `kubectl create secret generic --from-literal=license_token=${TOKEN} --from-literal=iam_role=${ROLE_ARN}` -aws: - license: - enabled: false - licenseConfigSecretName: - region: us-east-1 -## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container -containerSecurityContext: - enabled: true - runAsNonRoot: false - allowPrivilegeEscalation: true - seccompProfile: - type: RuntimeDefault - # capabilities: - # drop: - # - ALL -## The following router settings are to configure only when splitServicesToContainers set to true -## splitServicesToContainers (by default it is false) -router: - name: router - image: - registry: releases-docker.jfrog.io - repository: jfrog/router - tag: 7.81.0 - imagePullPolicy: IfNotPresent - serviceRegistry: - ## Service registry (Access) TLS verification skipped if enabled - insecure: false - internalPort: 8082 - externalPort: 8082 - tlsEnabled: false - ## Extra environment variables that can be used to tune router to your needs. - ## Uncomment and set value as needed - extraEnvironmentVariables: - # - name: MY_ENV_VAR - # value: "" - resources: {} - # requests: - # memory: "100Mi" - # cpu: "100m" - # limits: - # memory: "1Gi" - # cpu: "1" - - # Add lifecycle hooks for router container - lifecycle: - # From Artifactory versions 7.52.x, Wait for Artifactory to complete any open uploads or downloads before terminating - preStop: - exec: - command: ["sh", "-c", "while [[ $(curl --fail --silent --connect-timeout 2 http://localhost:8081/artifactory/api/v1/system/liveness) =~ OK ]]; do echo Artifactory is still alive; sleep 2; done"] - # postStart: - # exec: - # command: ["/bin/sh", "-c", "echo Hello from the postStart handler"] - ## Add custom volumesMounts - customVolumeMounts: "" - # - name: custom-script - # mountPath: /scripts/script.sh - # subPath: script.sh - - livenessProbe: - enabled: true - config: | - exec: - command: - - sh - - -c - - curl -s -k --fail --max-time {{ .Values.probes.timeoutSeconds }} {{ include "artifactory.scheme" . }}://localhost:{{ .Values.router.internalPort }}/router/api/v1/system/liveness - initialDelaySeconds: {{ if semverCompare " 1. This is only supported in Artifactory 7.25.x (appVersions) and above. - replicaCount: 1 - # minAvailable: 1 - - # Note that by default we use appVersion to get image tag/version - image: - registry: releases-docker.jfrog.io - repository: jfrog/artifactory-oss - # tag: - pullPolicy: IfNotPresent - labels: - bu: "infra" - team: "devops" - service: "jfrog-public-prd" - env: "prd" - priority: "p0" - type: "jfrog" - updateStrategy: - type: RollingUpdate - ## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/ - schedulerName: - # Create a priority class for the Artifactory pod or use an existing one - # NOTE - Maximum allowed value of a user defined priority is 1000000000 - priorityClass: - create: false - value: 1000000000 - ## Override default name - # name: - ## Use an existing priority class - # existingPriorityClass: - # Spread Artifactory pods evenly across your nodes or some other topology - topologySpreadConstraints: [] - # - maxSkew: 1 - # topologyKey: kubernetes.io/hostname - # whenUnsatisfiable: DoNotSchedule - # labelSelector: - # matchLabels: - # app: '{{ template "artifactory.name" . }}' - # role: '{{ template "artifactory.name" . }}' - # release: "{{ .Release.Name }}" - - # Delete the db.properties file in ARTIFACTORY_HOME/etc/db.properties - deleteDBPropertiesOnStartup: true - # certificates added to this secret will be copied to $JFROG_HOME/artifactory/var/etc/security/keys/trusted directory - customCertificates: - enabled: false - # certificateSecretName: - database: - maxOpenConnections: 80 - tomcat: - maintenanceConnector: - port: 8091 - connector: - maxThreads: 200 - sendReasonPhrase: false - extraConfig: 'acceptCount="400"' - # Support for open metrics is only available for Artifactory 7.7.x (appVersions) and above. - # To enable set `.Values.artifactory.openMetrics.enabled` to `true` - # Refer - https://www.jfrog.com/confluence/display/JFROG/Open+Metrics - openMetrics: - enabled: false - ## Settings for pushing metrics to Insight - enable filebeat to true - filebeat: - enabled: false - log: - enabled: false - ## Log level for filebeat. Possible values: debug, info, warning, or error. - level: "info" - ## Elasticsearch details for filebeat to connect - elasticsearch: - url: "Elasticsearch url where JFrog Insight is installed For example, http://:8082" - username: "" - password: "" - # Support for Cold Artifact Storage - # set 'coldStorage.enabled' to 'true' only for Artifactory instance that you are designating as the Cold instance - # Refer - https://jfrog.com/help/r/jfrog-platform-administration-documentation/setting-up-cold-artifact-storage - coldStorage: - enabled: false - # This directory is intended for use with NFS eventual configuration for HA - haDataDir: - enabled: false - path: - haBackupDir: - enabled: false - path: - # Files to copy to ARTIFACTORY_HOME/ on each Artifactory startup - # Note : From 107.46.x chart versions, copyOnEveryStartup is not needed for binarystore.xml, it is always copied via initContainers - copyOnEveryStartup: - # # Absolute path - # - source: /artifactory_bootstrap/artifactory.lic - # # Relative to ARTIFACTORY_HOME/ - # target: etc/artifactory/ - - # Sidecar containers for tailing Artifactory logs - loggers: [] - # - access-audit.log - # - access-request.log - # - access-security-audit.log - # - access-service.log - # - artifactory-access.log - # - artifactory-event.log - # - artifactory-import-export.log - # - artifactory-request.log - # - artifactory-service.log - # - frontend-request.log - # - frontend-service.log - # - metadata-request.log - # - metadata-service.log - # - router-request.log - # - router-service.log - # - router-traefik.log - # - derby.log - - # Loggers containers resources - loggersResources: {} - # requests: - # memory: "10Mi" - # cpu: "10m" - # limits: - # memory: "100Mi" - # cpu: "50m" - - # Sidecar containers for tailing Tomcat (catalina) logs - catalinaLoggers: [] - # - tomcat-catalina.log - # - tomcat-localhost.log - - # Tomcat (catalina) loggers resources - catalinaLoggersResources: {} - # requests: - # memory: "10Mi" - # cpu: "10m" - # limits: - # memory: "100Mi" - # cpu: "50m" - - # Migration support from 6.x to 7.x - migration: - enabled: false - timeoutSeconds: 3600 - ## Extra pre-start command in migration Init Container to install JDBC driver for MySql/MariaDb/Oracle - # preStartCommand: "mkdir -p /opt/jfrog/artifactory/var/bootstrap/artifactory/tomcat/lib; cd /opt/jfrog/artifactory/var/bootstrap/artifactory/tomcat/lib && curl -o /opt/jfrog/artifactory/var/bootstrap/artifactory/tomcat/lib/mysql-connector-java-5.1.41.jar https://jcenter.bintray.com/mysql/mysql-connector-java/5.1.41/mysql-connector-java-5.1.41.jar" - ## Add custom init containers execution before predefined init containers - customInitContainersBegin: "" - # - name: "custom-setup" - # image: "{{ .Values.initContainerImage }}" - # imagePullPolicy: "{{ .Values.artifactory.image.pullPolicy }}" - # securityContext: - # runAsNonRoot: true - # allowPrivilegeEscalation: false - # capabilities: - # drop: - # - NET_RAW - # command: - # - 'sh' - # - '-c' - # - 'touch {{ .Values.artifactory.persistence.mountPath }}/example-custom-setup' - # volumeMounts: - # - mountPath: "{{ .Values.artifactory.persistence.mountPath }}" - # name: artifactory-volume - - ## Add custom init containers execution after predefined init containers - customInitContainers: "" - # - name: "custom-systemyaml-setup" - # image: "{{ .Values.initContainerImage }}" - # imagePullPolicy: "{{ .Values.artifactory.image.pullPolicy }}" - # securityContext: - # runAsNonRoot: true - # allowPrivilegeEscalation: false - # capabilities: - # drop: - # - NET_RAW - # command: - # - 'sh' - # - '-c' - # - 'curl -o {{ .Values.artifactory.persistence.mountPath }}/etc/system.yaml https:///systemyaml' - # volumeMounts: - # - mountPath: "{{ .Values.artifactory.persistence.mountPath }}" - # name: artifactory-volume - - ## Add custom sidecar containers - # - The provided example uses a custom volume (customVolumes) - customSidecarContainers: "" - # - name: "sidecar-list-etc" - # image: "{{ .Values.initContainerImage }}" - # imagePullPolicy: "{{ .Values.artifactory.image.pullPolicy }}" - # securityContext: - # runAsNonRoot: true - # allowPrivilegeEscalation: false - # capabilities: - # drop: - # - NET_RAW - # command: - # - 'sh' - # - '-c' - # - 'sh /scripts/script.sh' - # volumeMounts: - # - mountPath: "{{ .Values.artifactory.persistence.mountPath }}" - # name: artifactory-volume - # - mountPath: "/scripts/script.sh" - # name: custom-script - # subPath: script.sh - # resources: - # requests: - # memory: "32Mi" - # cpu: "50m" - # limits: - # memory: "128Mi" - # cpu: "100m" - - ## Add custom volumes - # If .Values.artifactory.unifiedSecretInstallation is true then secret name should be '{{ template "artifactory.name" . }}-unified-secret' - customVolumes: "" - # - name: custom-script - # configMap: - # name: custom-script - - ## Add custom volumesMounts - customVolumeMounts: "" - # - name: custom-script - # mountPath: "/scripts/script.sh" - # subPath: script.sh - # - name: posthook-start - # mountPath: "/scripts/posthoook-start.sh" - # subPath: posthoook-start.sh - # - name: prehook-start - # mountPath: "/scripts/prehook-start.sh" - # subPath: prehook-start.sh - - # Add custom persistent volume mounts - Available to the entire namespace - customPersistentVolumeClaim: {} - # name: - # mountPath: - # accessModes: - # - "-" - # size: - # storageClassName: - - ## Artifactory license. - license: - ## licenseKey is the license key in plain text. Use either this or the license.secret setting - licenseKey: - ## If artifactory.license.secret is passed, it will be mounted as - ## ARTIFACTORY_HOME/etc/artifactory.lic and loaded at run time. - secret: - ## The dataKey should be the name of the secret data key created. - dataKey: - ## Create configMap with artifactory.config.import.xml and security.import.xml and pass name of configMap in following parameter - configMapName: - # Add any list of configmaps to Artifactory - configMaps: "" - # posthook-start.sh: |- - # echo "This is a post start script" - # posthook-end.sh: |- - # echo "This is a post end script" - - ## List of secrets for Artifactory user plugins. - ## One Secret per plugin's files. - userPluginSecrets: - # - archive-old-artifacts - # - build-cleanup - # - webhook - # - '{{ template "my-chart.fullname" . }}' - - ## Artifactory requires a unique master key. - ## You can generate one with the command: "openssl rand -hex 32" - ## An initial one is auto generated by Artifactory on first startup. - # masterKey: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF - ## Alternatively, you can use a pre-existing secret with a key called master-key by specifying masterKeySecretName - # masterKeySecretName: - - ## Join Key to connect other services to Artifactory - ## IMPORTANT: Setting this value overrides the existing joinKey - ## IMPORTANT: You should NOT use the example joinKey for a production deployment! - # joinKey: EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE - ## Alternatively, you can use a pre-existing secret with a key called join-key by specifying joinKeySecretName - # joinKeySecretName: - - ## Registration Token for JFConnect - # jfConnectToken: - ## Alternatively, you can use a pre-existing secret with a key called jfconnect-token by specifying jfConnectTokenSecretName - # jfConnectTokenSecretName: - - # Add custom secrets - secret per file - # If .Values.artifactory.unifiedSecretInstallation is true then secret name should be '{{ template "artifactory.name" . }}-unified-secret' common to all secrets - customSecrets: - # - name: custom-secret - # key: custom-secret.yaml - # data: > - # custom_secret_config: - # parameter1: value1 - # parameter2: value2 - # - name: custom-secret2 - # key: custom-secret2.config - # data: | - # here the custom secret 2 config - - ## If false, all service console logs will not redirect to a common console.log - consoleLog: false - ## admin allows to set the password for the default admin user. - ## See: https://www.jfrog.com/confluence/display/JFROG/Users+and+Groups#UsersandGroups-RecreatingtheDefaultAdminUserrecreate - admin: - ip: "127.0.0.1" - username: "admin" - password: - secret: - dataKey: - ## Extra pre-start command to install JDBC driver for MySql/MariaDb/Oracle - # preStartCommand: "mkdir -p /opt/jfrog/artifactory/var/bootstrap/artifactory/tomcat/lib; cd /opt/jfrog/artifactory/var/bootstrap/artifactory/tomcat/lib && curl -o /opt/jfrog/artifactory/var/bootstrap/artifactory/tomcat/lib/mysql-connector-java-5.1.41.jar https://jcenter.bintray.com/mysql/mysql-connector-java/5.1.41/mysql-connector-java-5.1.41.jar" - - # Add lifecycle hooks for artifactory container - lifecycle: {} - # postStart: - # exec: - # command: ["/bin/sh", "-c", "echo Hello from the postStart handler"] - # preStop: - # exec: - # command: ["/bin/sh","-c","echo Hello from the preStop handler"] - - ## Extra environment variables that can be used to tune Artifactory to your needs. - ## Uncomment and set value as needed - extraEnvironmentVariables: - # - name: SERVER_XML_ARTIFACTORY_PORT - # value: "8081" - # - name: SERVER_XML_ARTIFACTORY_MAX_THREADS - # value: "200" - # - name: SERVER_XML_ACCESS_MAX_THREADS - # value: "50" - # - name: SERVER_XML_ARTIFACTORY_EXTRA_CONFIG - # value: "" - # - name: SERVER_XML_ACCESS_EXTRA_CONFIG - # value: "" - # - name: SERVER_XML_EXTRA_CONNECTOR - # value: "" - # - name: DB_POOL_MAX_ACTIVE - # value: "100" - # - name: DB_POOL_MAX_IDLE - # value: "10" - # - name: MY_SECRET_ENV_VAR - # valueFrom: - # secretKeyRef: - # name: my-secret-name - # key: my-secret-key - - systemYaml: | - router: - serviceRegistry: - insecure: {{ .Values.router.serviceRegistry.insecure }} - shared: - {{- if .Values.artifactory.coldStorage.enabled }} - jfrogColdStorage: - coldInstanceEnabled: true - {{- end }} - {{- if .Values.artifactory.openMetrics.enabled }} - metrics: - enabled: true - {{- if .Values.artifactory.openMetrics.filebeat.enabled }} - filebeat: {{ toYaml .Values.artifactory.openMetrics.filebeat | nindent 6 }} - {{- end }} - {{- end }} - logging: - consoleLog: - enabled: {{ .Values.artifactory.consoleLog }} - extraJavaOpts: > - -Dartifactory.graceful.shutdown.max.request.duration.millis={{ mul .Values.artifactory.terminationGracePeriodSeconds 1000 }} - -Dartifactory.access.client.max.connections={{ .Values.access.tomcat.connector.maxThreads }} - {{- with .Values.artifactory.javaOpts }} - {{- if .corePoolSize }} - -Dartifactory.async.corePoolSize={{ .corePoolSize }} - {{- end }} - {{- if .xms }} - -Xms{{ .xms }} - {{- end }} - {{- if .xmx }} - -Xmx{{ .xmx }} - {{- end }} - {{- if .jmx.enabled }} - -Dcom.sun.management.jmxremote - -Dcom.sun.management.jmxremote.port={{ .jmx.port }} - -Dcom.sun.management.jmxremote.rmi.port={{ .jmx.port }} - -Dcom.sun.management.jmxremote.ssl={{ .jmx.ssl }} - {{- if .jmx.host }} - -Djava.rmi.server.hostname={{ tpl .jmx.host $ }} - {{- else }} - -Djava.rmi.server.hostname={{ template "artifactory.fullname" $ }} - {{- end }} - {{- if .jmx.authenticate }} - -Dcom.sun.management.jmxremote.authenticate=true - -Dcom.sun.management.jmxremote.access.file={{ .jmx.accessFile }} - -Dcom.sun.management.jmxremote.password.file={{ .jmx.passwordFile }} - {{- else }} - -Dcom.sun.management.jmxremote.authenticate=false - {{- end }} - {{- end }} - {{- if .other }} - {{ .other }} - {{- end }} - {{- end }} - {{- if or .Values.database.type .Values.postgresql.enabled }} - database: - {{- if .Values.postgresql.enabled }} - type: postgresql - url: "jdbc:postgresql://{{ .Release.Name }}-postgresql:{{ .Values.postgresql.service.port }}/{{ .Values.postgresql.postgresqlDatabase }}" - driver: org.postgresql.Driver - username: "{{ .Values.postgresql.postgresqlUsername }}" - {{- else }} - type: "{{ .Values.database.type }}" - driver: "{{ .Values.database.driver }}" - {{- end }} - {{- end }} - artifactory: - {{- if or .Values.artifactory.haDataDir.enabled .Values.artifactory.haBackupDir.enabled }} - node: - {{- if .Values.artifactory.haDataDir.path }} - haDataDir: {{ .Values.artifactory.haDataDir.path }} - {{- end }} - {{- if .Values.artifactory.haBackupDir.path }} - haBackupDir: {{ .Values.artifactory.haBackupDir.path }} - {{- end }} - {{- end }} - database: - maxOpenConnections: {{ .Values.artifactory.database.maxOpenConnections }} - tomcat: - maintenanceConnector: - port: {{ .Values.artifactory.tomcat.maintenanceConnector.port }} - connector: - maxThreads: {{ .Values.artifactory.tomcat.connector.maxThreads }} - sendReasonPhrase: {{ .Values.artifactory.tomcat.connector.sendReasonPhrase }} - extraConfig: {{ .Values.artifactory.tomcat.connector.extraConfig }} - frontend: - session: - timeMinutes: {{ .Values.frontend.session.timeoutMinutes | quote }} - access: - database: - maxOpenConnections: {{ .Values.access.database.maxOpenConnections }} - tomcat: - connector: - maxThreads: {{ .Values.access.tomcat.connector.maxThreads }} - sendReasonPhrase: {{ .Values.access.tomcat.connector.sendReasonPhrase }} - extraConfig: {{ .Values.access.tomcat.connector.extraConfig }} - {{- if .Values.mc.enabled }} - mc: - enabled: true - database: - maxOpenConnections: {{ .Values.mc.database.maxOpenConnections }} - idgenerator: - maxOpenConnections: {{ .Values.mc.idgenerator.maxOpenConnections }} - tomcat: - connector: - maxThreads: {{ .Values.mc.tomcat.connector.maxThreads }} - sendReasonPhrase: {{ .Values.mc.tomcat.connector.sendReasonPhrase }} - extraConfig: {{ .Values.mc.tomcat.connector.extraConfig }} - {{- end }} - metadata: - database: - maxOpenConnections: {{ .Values.metadata.database.maxOpenConnections }} - {{- if .Values.artifactory.replicator.enabled }} - replicator: - enabled: true - {{- end }} - {{- if and .Values.jfconnect.enabled (not (regexMatch "^.*(oss|cpp-ce|jcr).*$" .Values.artifactory.image.repository)) }} - jfconnect: - enabled: true - {{- else }} - jfconnect: - enabled: false - jfconnect_service: - enabled: false - {{- end }} - {{- if and .Values.federation.enabled (not (regexMatch "^.*(oss|cpp-ce|jcr).*$" .Values.artifactory.image.repository)) }} - federation: - enabled: true - extraJavaOpts: {{ .Values.federation.extraJavaOpts }} - port: {{ .Values.federation.internalPort }} - rtfs: - database: - driver: org.postgresql.Driver - type: postgresql - username: {{ .Values.federation.database.username }} - password: {{ .Values.federation.database.password }} - url: jdbc:postgresql://{{ .Values.federation.database.host }}:{{ .Values.federation.database.port }}/{{ .Values.federation.database.name }} - {{- else }} - federation: - enabled: false - {{- end }} - {{- if .Values.event.webhooks }} - event: - webhooks: {{ toYaml .Values.event.webhooks | nindent 6 }} - {{- end }} - annotations: {} - service: - name: artifactory - type: ClusterIP - ## For supporting whitelist on the Artifactory service (useful if setting service.type=LoadBalancer) - ## Set this to a list of IP CIDR ranges - ## Example: loadBalancerSourceRanges: ['10.10.10.5/32', '10.11.10.5/32'] - ## or pass from helm command line - ## Example: helm install ... --set nginx.service.loadBalancerSourceRanges='{10.10.10.5/32,10.11.10.5/32}' - loadBalancerSourceRanges: [] - annotations: {} - ## If the type is NodePort you can set a fixed port - # nodePort: 32082 - statefulset: - annotations: {} - ## The following setting are to configure a dedicated Ingress object for Replicator service - replicator: - name: replicator - enabled: false - ## Extra environment variables that can be used to tune replicator to your needs. - ## Uncomment and set value as needed - extraEnvironmentVariables: - # - name: MY_ENV_VAR - # value: "" - resources: {} - # requests: - # memory: "100Mi" - # cpu: "100m" - # limits: - # memory: "1Gi" - # cpu: "1" - - # Add lifecycle hooks for replicator container - lifecycle: {} - # postStart: - # exec: - # command: ["/bin/sh", "-c", "echo Hello from the postStart handler"] - # preStop: - # exec: - # command: ["/bin/sh","-c","echo Hello from the preStop handler"] - - ingress: - enabled: true - name: - hosts: [] - className: "" - annotations: {} - # kubernetes.io/ingress.class: nginx - # nginx.ingress.kubernetes.io/proxy-buffering: "off" - # nginx.ingress.kubernetes.io/configuration-snippet: | - # chunked_transfer_encoding on; - tls: [] - # Secrets must be manually created in the namespace. - # - hosts: - # - artifactory.domain.example - # secretName: chart-example-tls-secret - ## When replicator is enabled and want to use tracker feature, trackerIngress.enabled flag should be set to true - ## Please refer - https://www.jfrog.com/confluence/display/JFROG/JFrog+Peer-to-Peer+%28P2P%29+Downloads - trackerIngress: - enabled: false - name: - hosts: [] - className: "" - annotations: {} - # kubernetes.io/ingress.class: nginx - # nginx.ingress.kubernetes.io/proxy-buffering: "off" - # nginx.ingress.kubernetes.io/configuration-snippet: | - # chunked_transfer_encoding on; - tls: [] - # Secrets must be manually created in the namespace. - # - hosts: - # - artifactory.domain.example - # secretName: chart-example-tls-secret - ## IMPORTANT: If overriding artifactory.internalPort: - ## DO NOT use port lower than 1024 as Artifactory runs as non-root and cannot bind to ports lower than 1024! - externalPort: 8082 - internalPort: 8082 - externalArtifactoryPort: 8081 - internalArtifactoryPort: 8081 - uid: 0 - gid: 0 - # fsGroupChangePolicy: "Always" - # seLinuxOptions: {} - terminationGracePeriodSeconds: 30 - ## By default, the Artifactory StatefulSet is created with a securityContext that sets the `runAsUser` and the `fsGroup` to the `artifactory.uid` value. - ## If you want to disable the securityContext for the Artifactory StatefulSet, set this tag to false - setSecurityContext: true - livenessProbe: - enabled: true - config: | - exec: - command: - - sh - - -c - - curl -s -k --fail --max-time {{ .Values.probes.timeoutSeconds }} http://localhost:{{ .Values.artifactory.tomcat.maintenanceConnector.port }}/artifactory/api/v1/system/liveness - initialDelaySeconds: {{ if semverCompare "", - # "private_key_id": "?????", - # "private_key": "-----BEGIN PRIVATE KEY-----\n????????==\n-----END PRIVATE KEY-----\n", - # "client_email": "???@j.iam.gserviceaccount.com", - # "client_id": "???????", - # "auth_uri": "https://accounts.google.com/o/oauth2/auth", - # "token_uri": "https://oauth2.googleapis.com/token", - # "auth_provider_x509_cert_url": "https://www.googleapis.com/oauth2/v1/certs", - # "client_x509_cert_url": "https://www.googleapis.com/robot/v1....." - # } - endpoint: commondatastorage.googleapis.com - httpsOnly: false - # Set a unique bucket name - bucketName: "artifactory-gcp" - ## GCP Bucket Authentication with Identity and Credential is deprecated. - ## identity: - ## credential: - path: "artifactory/filestore" - bucketExists: false - useInstanceCredentials: false - enableSignedUrlRedirect: false - ## For artifactory.persistence.type aws-s3-v3, s3-storage-v3-direct, cluster-s3-storage-v3, s3-storage-v3-archive - awsS3V3: - testConnection: false - identity: - credential: - region: - bucketName: artifactory-aws - path: artifactory/filestore - endpoint: - port: - useHttp: - maxConnections: 50 - kmsServerSideEncryptionKeyId: - kmsKeyRegion: - kmsCryptoMode: - useInstanceCredentials: true - usePresigning: false - signatureExpirySeconds: 300 - signedUrlExpirySeconds: 30 - cloudFrontDomainName: - cloudFrontKeyPairId: - cloudFrontPrivateKey: - enableSignedUrlRedirect: false - enablePathStyleAccess: false - multiPartLimit: - multipartElementSize: - ## For artifactory.persistence.type azure-blob, azure-blob-storage-direct, cluster-azure-blob-storage - azureBlob: - accountName: - accountKey: - endpoint: - containerName: - multiPartLimit: 100000000 - multipartElementSize: 50000000 - testConnection: false - ## artifactory data Persistent Volume Storage Class - ## If defined, storageClassName: - ## If set to "-", storageClassName: "", which disables dynamic provisioning - ## If undefined (the default) or set to null, no storageClassName spec is - ## set, choosing the default provisioner. (gp2 on AWS, standard on - ## GKE, AWS & OpenStack) - ## - # storageClassName: "-" - ## Annotations for the Persistent Volume Claim - annotations: {} - ## Uncomment the following resources definitions or pass them from command line - ## to control the cpu and memory resources allocated by the Kubernetes cluster - resources: - requests: - memory: "16Gi" - cpu: "4" - limits: - memory: "32Gi" - cpu: "8" - ## The following Java options are passed to the java process running Artifactory. - ## You should set them according to the resources set above - javaOpts: - # xms: "1g" - # xmx: "2g" - jmx: - enabled: false - port: 9010 - host: - ssl: false - # When authenticate is true, accessFile and passwordFile are required - authenticate: false - accessFile: - passwordFile: - # corePoolSize: 24 - # other: "" - - nodeSelector: - dedicated: "jfrog" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "jfrog" - effect: "NoSchedule" - affinity: {} - ## Only used if "affinity" is empty - podAntiAffinity: - ## Valid values are "soft" or "hard"; any other value indicates no anti-affinity - type: "soft" - topologyKey: "kubernetes.io/hostname" - ssh: - enabled: false - internalPort: 1339 - externalPort: 1339 -frontend: - name: frontend - enabled: true - internalPort: 8070 - ## Extra environment variables that can be used to tune frontend to your needs. - ## Uncomment and set value as needed - extraEnvironmentVariables: - # - name: MY_ENV_VAR - # value: "" - resources: {} - # requests: - # memory: "100Mi" - # cpu: "100m" - # limits: - # memory: "1Gi" - # cpu: "1" - - # Add lifecycle hooks for frontend container - lifecycle: {} - # postStart: - # exec: - # command: ["/bin/sh", "-c", "echo Hello from the postStart handler"] - # preStop: - # exec: - # command: ["/bin/sh","-c","echo Hello from the preStop handler"] - - ## Session settings - session: - ## Time in minutes after which the frontend token will need to be refreshed - timeoutMinutes: '30' - ## The following settings are to configure the frequency of the liveness and startup probes when splitServicesToContainers set to true - livenessProbe: - enabled: true - config: | - exec: - command: - - sh - - -c - - curl --fail --max-time {{ .Values.probes.timeoutSeconds }} http://localhost:{{ .Values.frontend.internalPort }}/api/v1/system/liveness - initialDelaySeconds: {{ if semverCompare " --cert=ca.crt --key=ca.private.key` - # customCertificatesSecretName: - - ## When resetAccessCAKeys is true, Access will regenerate the CA certificate and matching private key - # resetAccessCAKeys: false - database: - maxOpenConnections: 80 - tomcat: - connector: - maxThreads: 50 - sendReasonPhrase: false - extraConfig: 'acceptCount="100"' -metadata: - name: metadata - enabled: false - internalPort: 8086 - database: - maxOpenConnections: 80 - ## Extra environment variables that can be used to tune metadata to your needs. - ## Uncomment and set value as needed - extraEnvironmentVariables: - # - name: MY_ENV_VAR - # value: "" - resources: {} - # requests: - # memory: "100Mi" - # cpu: "100m" - # limits: - # memory: "1Gi" - # cpu: "1" - - # Add lifecycle hooks for metadata container - lifecycle: {} - # postStart: - # exec: - # command: ["/bin/sh", "-c", "echo Hello from the postStart handler"] - # preStop: - # exec: - # command: ["/bin/sh","-c","echo Hello from the preStop handler"] - - ## The following settings are to configure the frequency of the liveness and startup probes when splitServicesToContainers set to true - livenessProbe: - enabled: true - config: | - exec: - command: - - sh - - -c - - curl --fail --max-time {{ .Values.probes.timeoutSeconds }} http://localhost:{{ .Values.metadata.internalPort }}/api/v1/system/liveness - initialDelaySeconds: {{ if semverCompare " /var/opt/jfrog/nginx/message"] - # preStop: - # exec: - # command: ["/bin/sh","-c","nginx -s quit; while killall -0 nginx; do sleep 1; done"] - - # Sidecar containers for tailing Nginx logs - loggers: [] - # - access.log - # - error.log - - # Loggers containers resources - loggersResources: {} - # requests: - # memory: "64Mi" - # cpu: "25m" - # limits: - # memory: "128Mi" - # cpu: "50m" - - # Logs options - logs: - stderr: false - level: warn - ## A list of custom ports to expose on the NGINX pod. Follows the conventional Kubernetes yaml syntax for container ports. - customPorts: [] - # customPorts: - # - containerPort: 8066 - # name: docker - - mainConf: | - # Main Nginx configuration file - worker_processes 4; - - {{ if .Values.nginx.logs.stderr }} - error_log stderr {{ .Values.nginx.logs.level }}; - {{- else -}} - error_log {{ .Values.nginx.persistence.mountPath }}/logs/error.log {{ .Values.nginx.logs.level }}; - {{- end }} - pid /tmp/nginx.pid; - - {{- if .Values.artifactory.ssh.enabled }} - ## SSH Server Configuration - stream { - server { - listen {{ .Values.nginx.ssh.internalPort }}; - proxy_pass {{ include "artifactory.fullname" . }}:{{ .Values.artifactory.ssh.externalPort }}; - } - } - {{- end }} - - events { - worker_connections 1024; - } - - - http { - include /etc/nginx/mime.types; - default_type application/octet-stream; - - variables_hash_max_size 1024; - variables_hash_bucket_size 64; - server_names_hash_max_size 4096; - server_names_hash_bucket_size 128; - types_hash_max_size 2048; - types_hash_bucket_size 64; - proxy_read_timeout 2400s; - client_header_timeout 2400s; - client_body_timeout 2400s; - proxy_connect_timeout 75s; - proxy_send_timeout 2400s; - proxy_buffer_size 128k; - proxy_buffers 40 128k; - proxy_busy_buffers_size 128k; - proxy_temp_file_write_size 250m; - proxy_http_version 1.1; - client_body_buffer_size 128k; - - log_format main '$remote_addr - $remote_user [$time_local] "$request" ' - '$status $body_bytes_sent "$http_referer" ' - '"$http_user_agent" "$http_x_forwarded_for"'; - - log_format timing 'ip = $remote_addr ' - 'user = \"$remote_user\" ' - 'local_time = \"$time_local\" ' - 'host = $host ' - 'request = \"$request\" ' - 'status = $status ' - 'bytes = $body_bytes_sent ' - 'upstream = \"$upstream_addr\" ' - 'upstream_time = $upstream_response_time ' - 'request_time = $request_time ' - 'referer = \"$http_referer\" ' - 'UA = \"$http_user_agent\"'; - - access_log {{ .Values.nginx.persistence.mountPath }}/logs/access.log timing; - - sendfile on; - #tcp_nopush on; - - keepalive_timeout 65; - - #gzip on; - - include /etc/nginx/conf.d/*.conf; - - } - artifactoryConf: | - {{- if .Values.nginx.https.enabled }} - ssl_protocols TLSv1 TLSv1.1 TLSv1.2 TLSv1.3; - ssl_certificate {{ .Values.nginx.persistence.mountPath }}/ssl/tls.crt; - ssl_certificate_key {{ .Values.nginx.persistence.mountPath }}/ssl/tls.key; - ssl_session_cache shared:SSL:1m; - ssl_prefer_server_ciphers on; - {{- end }} - ## server configuration - server { - {{- if .Values.nginx.internalPortHttps }} - listen {{ .Values.nginx.internalPortHttps }} ssl; - {{- else -}} - {{- if .Values.nginx.https.enabled }} - listen {{ .Values.nginx.https.internalPort }} ssl; - {{- end }} - {{- end }} - {{- if .Values.nginx.internalPortHttp }} - listen {{ .Values.nginx.internalPortHttp }}; - {{- else -}} - {{- if .Values.nginx.http.enabled }} - listen {{ .Values.nginx.http.internalPort }}; - {{- end }} - {{- end }} - server_name ~(?.+)\.{{ include "artifactory.fullname" . }} {{ include "artifactory.fullname" . }} - {{- range .Values.ingress.hosts -}} - {{- if contains "." . -}} - {{ "" | indent 0 }} ~(?.+)\.{{ . }} - {{- end -}} - {{- end -}}; - - if ($http_x_forwarded_proto = '') { - set $http_x_forwarded_proto $scheme; - } - ## Application specific logs - ## access_log /var/log/nginx/artifactory-access.log timing; - ## error_log /var/log/nginx/artifactory-error.log; - rewrite ^/artifactory/?$ / redirect; - if ( $repo != "" ) { - rewrite ^/(v1|v2)/(.*) /artifactory/api/docker/$repo/$1/$2 break; - } - chunked_transfer_encoding on; - client_max_body_size 0; - - location / { - proxy_read_timeout 900; - proxy_pass_header Server; - proxy_cookie_path ~*^/.* /; - proxy_pass {{ include "artifactory.scheme" . }}://{{ include "artifactory.fullname" . }}:{{ .Values.artifactory.externalPort }}/; - {{- if .Values.nginx.service.ssloffload}} - proxy_set_header X-JFrog-Override-Base-Url $http_x_forwarded_proto://$host; - {{- else }} - proxy_set_header X-JFrog-Override-Base-Url $http_x_forwarded_proto://$host:$server_port; - proxy_set_header X-Forwarded-Port $server_port; - {{- end }} - proxy_set_header X-Forwarded-Proto $http_x_forwarded_proto; - proxy_set_header Host $http_host; - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; - {{- if .Values.nginx.disableProxyBuffering}} - proxy_http_version 1.1; - proxy_request_buffering off; - proxy_buffering off; - {{- end }} - add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always; - - location /artifactory/ { - if ( $request_uri ~ ^/artifactory/(.*)$ ) { - proxy_pass http://{{ include "artifactory.fullname" . }}:{{ .Values.artifactory.externalArtifactoryPort }}/artifactory/$1; - } - proxy_pass http://{{ include "artifactory.fullname" . }}:{{ .Values.artifactory.externalArtifactoryPort }}/artifactory/; - } - location /pipelines/ { - proxy_http_version 1.1; - proxy_set_header Upgrade $http_upgrade; - proxy_set_header Connection "upgrade"; - proxy_set_header Host $http_host; - {{- if .Values.router.tlsEnabled }} - proxy_pass https://{{ include "artifactory.fullname" . }}:{{ .Values.router.internalPort }}; - {{- else }} - proxy_pass http://{{ include "artifactory.fullname" . }}:{{ .Values.router.internalPort }}; - {{- end }} - } - } - } - customInitContainers: "" - customSidecarContainers: "" - customVolumes: "" - customVolumeMounts: "" - customCommand: - ## allows overwriting the command for the nginx container. - ## defaults to [ 'nginx', '-g', 'daemon off;' ] - - service: - ## For minikube, set this to NodePort, elsewhere use LoadBalancer - type: LoadBalancer - ssloffload: false - ## For supporting whitelist on the Nginx LoadBalancer service - ## Set this to a list of IP CIDR ranges - ## Example: loadBalancerSourceRanges: ['10.10.10.5/32', '10.11.10.5/32'] - ## or pass from helm command line - ## Example: helm install ... --set nginx.service.loadBalancerSourceRanges='{10.10.10.5/32,10.11.10.5/32}' - loadBalancerSourceRanges: [] - annotations: {} - ## Provide static ip address - loadBalancerIP: - ## There are two available options: “Cluster” (default) and “Local”. - externalTrafficPolicy: Cluster - ## If the type is NodePort you can set a fixed port - # nodePort: 32082 - ## A list of custom ports to be exposed on nginx service. Follows the conventional Kubernetes yaml syntax for service ports. - customPorts: [] - # - port: 8066 - # targetPort: 8066 - # protocol: TCP - # name: docker - http: - enabled: true - externalPort: 80 - internalPort: 80 - https: - enabled: true - externalPort: 443 - internalPort: 443 - ssh: - internalPort: 1339 - externalPort: 1339 - # DEPRECATED: The following will be removed in a future release - # externalPortHttp: 80 - # internalPortHttp: 80 - # externalPortHttps: 443 - # internalPortHttps: 443 - - ## The following settings are to configure the frequency of the liveness and readiness probes. - livenessProbe: - enabled: true - config: | - exec: - command: - - sh - - -c - - curl -s -k --fail --max-time {{ .Values.probes.timeoutSeconds }} {{ include "nginx.scheme" . }}://localhost:{{ include "nginx.port" . }}/ - initialDelaySeconds: {{ if semverCompare " - ## If set to "-", storageClassName: "", which disables dynamic provisioning - ## If undefined (the default) or set to null, no storageClassName spec is - ## set, choosing the default provisioner. (gp2 on AWS, standard on - ## GKE, AWS & OpenStack) - ## - # storageClassName: "-" - resources: {} - # requests: - # memory: "250Mi" - # cpu: "100m" - # limits: - # memory: "250Mi" - # cpu: "500m" - nodeSelector: {} - tolerations: [] - affinity: {} -## Database configurations -## Use the wait-for-db init container. Set to false to skip -waitForDatabase: true - -## Configuration values for the PostgreSQL dependency sub-chart -## ref: https://github.com/bitnami/charts/blob/master/bitnami/postgresql/README.md -postgresql: - enabled: false - image: - registry: releases-docker.jfrog.io - repository: bitnami/postgresql - tag: 13.10.0-debian-11-r14 - postgresqlUsername: artifactory - postgresqlPassword: "admin" - postgresqlDatabase: artifactory - postgresqlExtendedConf: - listenAddresses: "*" - maxConnections: "1500" - persistence: - enabled: true - size: 10Gi - # existingClaim: - service: - port: 5432 - primary: - labels: - bu: "infra" - team: "devops" - service: "jfrog-public-prd" - env: "prd" - priority: "p0" - type: "jfrog-psql-master" - podLabels: - bu: "infra" - team: "devops" - service: "jfrog-public-prd" - env: "prd" - priority: "p0" - type: "jfrog-psql-master" - nodeSelector: - dedicated: "jfrog" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "jfrog" - effect: "NoSchedule" - affinity: {} - readReplicas: - labels: - bu: "infra" - team: "devops" - service: "jfrog-public-prd" - env: "prd" - priority: "p0" - type: "jfrog-psql-slave" - podLabels: - bu: "infra" - team: "devops" - service: "jfrog-public-prd" - env: "prd" - priority: "p0" - type: "jfrog-psql-slave" - affinity: {} - nodeSelector: - dedicated: "jfrog" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "jfrog" - effect: "NoSchedule" - resources: {} - securityContext: - enabled: true - containerSecurityContext: - enabled: true - runAsNonRoot: true - allowPrivilegeEscalation: false - seccompProfile: - type: RuntimeDefault - capabilities: - drop: - - ALL - # requests: - # memory: "512Mi" - # cpu: "100m" - # limits: - # memory: "1Gi" - # cpu: "500m" -## If NOT using the PostgreSQL in this chart (postgresql.enabled=false), -## specify custom database details here or leave empty and Artifactory will use embedded derby - -database: - type: postgresql - driver: org.postgresql.Driver - ## If you set the url, leave host and port empty - url: - ## If you would like this chart to create the secret containing the db - ## password, use these values - user: - password: - ## If you have existing Kubernetes secrets containing db credentials, use - ## these values - secrets: - user: - name: "jfrog-public-prd-secret" - key: "db-user" - password: - name: "jfrog-public-prd-secret" - key: "db-password" - url: - name: "jfrog-public-prd-secret" - key: "db-url" - -# Filebeat Sidecar container -## The provided filebeat configuration is for Artifactory logs. It assumes you have a logstash installed and configured properly. -filebeat: - enabled: false - name: artifactory-filebeat - image: - repository: "docker.elastic.co/beats/filebeat" - version: 7.16.2 - logstashUrl: "logstash:5044" - livenessProbe: - exec: - command: - - sh - - -c - - | - #!/usr/bin/env bash -e - curl --fail 127.0.0.1:5066 - failureThreshold: 3 - initialDelaySeconds: 10 - periodSeconds: 10 - timeoutSeconds: 5 - readinessProbe: - exec: - command: - - sh - - -c - - | - #!/usr/bin/env bash -e - filebeat test output - failureThreshold: 3 - initialDelaySeconds: 10 - periodSeconds: 10 - timeoutSeconds: 5 - resources: {} - # requests: - # memory: "100Mi" - # cpu: "100m" - # limits: - # memory: "100Mi" - # cpu: "100m" - - filebeatYml: | - logging.level: info - path.data: {{ .Values.artifactory.persistence.mountPath }}/log/filebeat - name: artifactory-filebeat - queue.spool: - file: - permissions: 0760 - filebeat.inputs: - - type: log - enabled: true - close_eof: ${CLOSE:false} - paths: - - {{ .Values.artifactory.persistence.mountPath }}/log/*.log - fields: - service: "jfrt" - log_type: "artifactory" - output: - logstash: - hosts: ["{{ .Values.filebeat.logstashUrl }}"] -## Allows to add additional kubernetes resources -## Use --- as a separator between multiple resources -## For an example, refer - https://github.com/jfrog/log-analytics-prometheus/blob/master/artifactory-values.yaml -additionalResources: "" -# Adding entries to a Pod's /etc/hosts file -# For an example, refer - https://kubernetes.io/docs/concepts/services-networking/add-entries-to-pod-etc-hosts-with-host-aliases -hostAliases: [] -# - ip: "127.0.0.1" -# hostnames: -# - "foo.local" -# - "bar.local" -# - ip: "10.1.2.3" -# hostnames: -# - "foo.remote" -# - "bar.remote" - -## Toggling this feature is seamless and requires helm upgrade -## will enable all microservices to run in different containers in a single pod (by default it is true) -splitServicesToContainers: true -## Specify common probes parameters -probes: - timeoutSeconds: 5 diff --git a/helm-overrides/k8s-admin-prd-ase1/jfrog/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/jfrog/custom-values.yaml deleted file mode 100644 index daa34c1..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/jfrog/custom-values.yaml +++ /dev/null @@ -1,2041 +0,0 @@ -# Default values for artifactory. -# This is a YAML-formatted file. - -# Beware when changing values here. You should know what you are doing! -# Access the values with {{ .Values.key.subkey }} - -global: - # imageRegistry: releases-docker.jfrog.io - # imagePullSecrets: - # - myRegistryKeySecretName - ## Chart.AppVersion can be overidden using global.versions.artifactory or .Values.artifactory.image.tag - ## Note: Order of preference is 1) global.versions 2) .Values.artifactory.image.tag 3) Chart.AppVersion - ## This applies also for nginx images (.Values.nginx.image.tag) - versions: {} - # artifactory: - # joinKey: - # masterKey: - # joinKeySecretName: 'jfrog-prd-secret' - masterKeySecretName: 'jfrog-prd-secret' - - ## Note: tags customInitContainersBegin,customInitContainers,customVolumes,customVolumeMounts,customSidecarContainers can be used both from global and application level simultaneously - # customInitContainersBegin: | - - # customInitContainers: | - - # customVolumes: | - - # customVolumeMounts: | - - # customSidecarContainers: | - - ## certificates added to this secret will be copied to $JFROG_HOME/artifactory/var/etc/security/keys/trusted directory - customCertificates: - enabled: false - # certificateSecretName: - ## Applies to artifactory and nginx pods - nodeSelector: {} -## String to partially override artifactory.fullname template (will maintain the release name) -## -# nameOverride: - -## String to fully override artifactory.fullname template -## -fullnameOverride: jfrog-prd -initContainerImage: releases-docker.jfrog.io/ubi9/ubi-minimal:9.2.750.1697534106 -# Init containers -initContainers: - resources: - requests: - memory: "50Mi" - cpu: "10m" - limits: - memory: "1Gi" - cpu: "1" -installer: - platform: art-oss-helm -installerInfo: '{"productId": "Helm_artifactory-oss/{{ .Chart.Version }}", "features": [ { "featureId": "Platform/{{ default "kubernetes" .Values.installer.platform }}"}]}' -# For supporting pulling from private registries -# imagePullSecrets: -# - myRegistryKeySecretName - -## Artifactory systemYaml override -## This is for advanced usecases where users wants to provide their own systemYaml for configuring artifactory -## Refer: https://www.jfrog.com/confluence/display/JFROG/Artifactory+System+YAML -## Note: This will override existing (default) .Values.artifactory.systemYaml in values.yaml -## Alternatively, systemYaml can be overidden via customInitContainers using external sources like vaults, external repositories etc. Please refer customInitContainer section below for an example. -## Note: Order of preference is 1) customInitContainers 2) systemYamlOverride existingSecret 3) default systemYaml in values.yaml -systemYamlOverride: - ## You can use a pre-existing secret by specifying existingSecret - existingSecret: - ## The dataKey should be the name of the secret data key created. - dataKey: -## Role Based Access Control -## Ref: https://kubernetes.io/docs/admin/authorization/rbac/ -rbac: - create: false - role: - ## Rules to create. It follows the role specification - rules: - - apiGroups: - - '' - resources: - - services - - endpoints - - pods - verbs: - - get - - watch - - list -## Service Account -## Ref: https://kubernetes.io/docs/admin/service-accounts-admin/ -## -serviceAccount: - create: false - ## The name of the ServiceAccount to use. - ## If not set and create is true, a name is generated using the fullname template - name: - ## Service Account annotations - annotations: {} - ## Explicitly mounts the API credentials for the Service Account - automountServiceAccountToken: false - -externalSecret: - enabled: true - key: 'prd/admin/jfrog' - secretStoreRef: - name: 'vault-backend' - -ingress: - enabled: true - defaultBackend: - enabled: true - # Used to create an Ingress record. - hosts: ["jfrog-prd.meeshogcp.in"] - routerPath: / - artifactoryPath: /artifactory/ - rtfsPath: /artifactory/service/rtfs/ - className: "nginx-internal" - annotations: - nginx.ingress.kubernetes.io/proxy-body-size: "0" - # kubernetes.io/ingress.class: nginx - # nginx.ingress.kubernetes.io/configuration-snippet: | - # proxy_pass_header Server; - # proxy_set_header X-JFrog-Override-Base-Url https://; - # kubernetes.io/tls-acme: "true" - # nginx.ingress.kubernetes.io/proxy-body-size: "0" - labels: {} - # traffic-type: external - # traffic-type: internal - tls: [] - # Secrets must be manually created in the namespace. - # - secretName: chart-example-tls - # hosts: - # - artifactory.domain.example - - # Additional ingress rules - additionalRules: [] -## Allows to add custom ingress -customIngress: "" -networkpolicy: [] -# Allows all ingress and egress -# - name: artifactory -# podSelector: -# matchLabels: -# app: artifactory -# egress: -# - {} -# ingress: -# - {} -# Uncomment to allow only artifactory pods to communicate with postgresql (if postgresql.enabled is true) -# - name: postgresql -# podSelector: -# matchLabels: -# app: postgresql -# ingress: -# - from: -# - podSelector: -# matchLabels: -# app: artifactory - -## Apply horizontal pod auto scaling on artifactory pods -## Ref: https://kubernetes.io/docs/tasks/run-application/horizontal-pod-autoscale/ -autoscaling: - enabled: false - minReplicas: 1 - maxReplicas: 3 - targetCPUUtilizationPercentage: 70 -logger: - image: - registry: releases-docker.jfrog.io - repository: jfrog/artifactory-oss - tag: 9.2.750.1697534106 -## You can use a pre-existing secret with keys license_token and iam_role by specifying licenseConfigSecretName -## Example : Create a generic secret using `kubectl create secret generic --from-literal=license_token=${TOKEN} --from-literal=iam_role=${ROLE_ARN}` -aws: - license: - enabled: false - licenseConfigSecretName: - region: us-east-1 -## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container -containerSecurityContext: - enabled: true - runAsNonRoot: false - allowPrivilegeEscalation: true - seccompProfile: - type: RuntimeDefault - # capabilities: - # drop: - # - ALL -## The following router settings are to configure only when splitServicesToContainers set to true -## splitServicesToContainers (by default it is false) -router: - name: router - image: - registry: releases-docker.jfrog.io - repository: jfrog/router - tag: 7.81.0 - imagePullPolicy: IfNotPresent - serviceRegistry: - ## Service registry (Access) TLS verification skipped if enabled - insecure: false - internalPort: 8082 - externalPort: 8082 - tlsEnabled: false - ## Extra environment variables that can be used to tune router to your needs. - ## Uncomment and set value as needed - extraEnvironmentVariables: - # - name: MY_ENV_VAR - # value: "" - resources: {} - # requests: - # memory: "100Mi" - # cpu: "100m" - # limits: - # memory: "1Gi" - # cpu: "1" - - # Add lifecycle hooks for router container - lifecycle: - # From Artifactory versions 7.52.x, Wait for Artifactory to complete any open uploads or downloads before terminating - preStop: - exec: - command: ["sh", "-c", "while [[ $(curl --fail --silent --connect-timeout 2 http://localhost:8081/artifactory/api/v1/system/liveness) =~ OK ]]; do echo Artifactory is still alive; sleep 2; done"] - # postStart: - # exec: - # command: ["/bin/sh", "-c", "echo Hello from the postStart handler"] - ## Add custom volumesMounts - customVolumeMounts: "" - # - name: custom-script - # mountPath: /scripts/script.sh - # subPath: script.sh - - livenessProbe: - enabled: true - config: | - exec: - command: - - sh - - -c - - curl -s -k --fail --max-time {{ .Values.probes.timeoutSeconds }} {{ include "artifactory.scheme" . }}://localhost:{{ .Values.router.internalPort }}/router/api/v1/system/liveness - initialDelaySeconds: {{ if semverCompare " 1. This is only supported in Artifactory 7.25.x (appVersions) and above. - replicaCount: 1 - # minAvailable: 1 - - # Note that by default we use appVersion to get image tag/version - image: - registry: releases-docker.jfrog.io - repository: jfrog/artifactory-oss - # tag: - pullPolicy: IfNotPresent - labels: - bu: "infra" - team: "devops" - service: "jfrog-prd" - env: "prd" - priority: "p0" - type: "jfrog" - updateStrategy: - type: RollingUpdate - ## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/ - schedulerName: - # Create a priority class for the Artifactory pod or use an existing one - # NOTE - Maximum allowed value of a user defined priority is 1000000000 - priorityClass: - create: false - value: 1000000000 - ## Override default name - # name: - ## Use an existing priority class - # existingPriorityClass: - # Spread Artifactory pods evenly across your nodes or some other topology - topologySpreadConstraints: [] - # - maxSkew: 1 - # topologyKey: kubernetes.io/hostname - # whenUnsatisfiable: DoNotSchedule - # labelSelector: - # matchLabels: - # app: '{{ template "artifactory.name" . }}' - # role: '{{ template "artifactory.name" . }}' - # release: "{{ .Release.Name }}" - - # Delete the db.properties file in ARTIFACTORY_HOME/etc/db.properties - deleteDBPropertiesOnStartup: true - # certificates added to this secret will be copied to $JFROG_HOME/artifactory/var/etc/security/keys/trusted directory - customCertificates: - enabled: false - # certificateSecretName: - database: - maxOpenConnections: 80 - tomcat: - maintenanceConnector: - port: 8091 - connector: - maxThreads: 200 - sendReasonPhrase: false - extraConfig: 'acceptCount="400"' - # Support for open metrics is only available for Artifactory 7.7.x (appVersions) and above. - # To enable set `.Values.artifactory.openMetrics.enabled` to `true` - # Refer - https://www.jfrog.com/confluence/display/JFROG/Open+Metrics - openMetrics: - enabled: false - ## Settings for pushing metrics to Insight - enable filebeat to true - filebeat: - enabled: false - log: - enabled: false - ## Log level for filebeat. Possible values: debug, info, warning, or error. - level: "info" - ## Elasticsearch details for filebeat to connect - elasticsearch: - url: "Elasticsearch url where JFrog Insight is installed For example, http://:8082" - username: "" - password: "" - # Support for Cold Artifact Storage - # set 'coldStorage.enabled' to 'true' only for Artifactory instance that you are designating as the Cold instance - # Refer - https://jfrog.com/help/r/jfrog-platform-administration-documentation/setting-up-cold-artifact-storage - coldStorage: - enabled: false - # This directory is intended for use with NFS eventual configuration for HA - haDataDir: - enabled: false - path: - haBackupDir: - enabled: false - path: - # Files to copy to ARTIFACTORY_HOME/ on each Artifactory startup - # Note : From 107.46.x chart versions, copyOnEveryStartup is not needed for binarystore.xml, it is always copied via initContainers - copyOnEveryStartup: - # # Absolute path - # - source: /artifactory_bootstrap/artifactory.lic - # # Relative to ARTIFACTORY_HOME/ - # target: etc/artifactory/ - - # Sidecar containers for tailing Artifactory logs - loggers: [] - # - access-audit.log - # - access-request.log - # - access-security-audit.log - # - access-service.log - # - artifactory-access.log - # - artifactory-event.log - # - artifactory-import-export.log - # - artifactory-request.log - # - artifactory-service.log - # - frontend-request.log - # - frontend-service.log - # - metadata-request.log - # - metadata-service.log - # - router-request.log - # - router-service.log - # - router-traefik.log - # - derby.log - - # Loggers containers resources - loggersResources: {} - # requests: - # memory: "10Mi" - # cpu: "10m" - # limits: - # memory: "100Mi" - # cpu: "50m" - - # Sidecar containers for tailing Tomcat (catalina) logs - catalinaLoggers: [] - # - tomcat-catalina.log - # - tomcat-localhost.log - - # Tomcat (catalina) loggers resources - catalinaLoggersResources: {} - # requests: - # memory: "10Mi" - # cpu: "10m" - # limits: - # memory: "100Mi" - # cpu: "50m" - - # Migration support from 6.x to 7.x - migration: - enabled: false - timeoutSeconds: 3600 - ## Extra pre-start command in migration Init Container to install JDBC driver for MySql/MariaDb/Oracle - # preStartCommand: "mkdir -p /opt/jfrog/artifactory/var/bootstrap/artifactory/tomcat/lib; cd /opt/jfrog/artifactory/var/bootstrap/artifactory/tomcat/lib && curl -o /opt/jfrog/artifactory/var/bootstrap/artifactory/tomcat/lib/mysql-connector-java-5.1.41.jar https://jcenter.bintray.com/mysql/mysql-connector-java/5.1.41/mysql-connector-java-5.1.41.jar" - ## Add custom init containers execution before predefined init containers - customInitContainersBegin: "" - # - name: "custom-setup" - # image: "{{ .Values.initContainerImage }}" - # imagePullPolicy: "{{ .Values.artifactory.image.pullPolicy }}" - # securityContext: - # runAsNonRoot: true - # allowPrivilegeEscalation: false - # capabilities: - # drop: - # - NET_RAW - # command: - # - 'sh' - # - '-c' - # - 'touch {{ .Values.artifactory.persistence.mountPath }}/example-custom-setup' - # volumeMounts: - # - mountPath: "{{ .Values.artifactory.persistence.mountPath }}" - # name: artifactory-volume - - ## Add custom init containers execution after predefined init containers - customInitContainers: "" - # - name: "custom-systemyaml-setup" - # image: "{{ .Values.initContainerImage }}" - # imagePullPolicy: "{{ .Values.artifactory.image.pullPolicy }}" - # securityContext: - # runAsNonRoot: true - # allowPrivilegeEscalation: false - # capabilities: - # drop: - # - NET_RAW - # command: - # - 'sh' - # - '-c' - # - 'curl -o {{ .Values.artifactory.persistence.mountPath }}/etc/system.yaml https:///systemyaml' - # volumeMounts: - # - mountPath: "{{ .Values.artifactory.persistence.mountPath }}" - # name: artifactory-volume - - ## Add custom sidecar containers - # - The provided example uses a custom volume (customVolumes) - customSidecarContainers: "" - # - name: "sidecar-list-etc" - # image: "{{ .Values.initContainerImage }}" - # imagePullPolicy: "{{ .Values.artifactory.image.pullPolicy }}" - # securityContext: - # runAsNonRoot: true - # allowPrivilegeEscalation: false - # capabilities: - # drop: - # - NET_RAW - # command: - # - 'sh' - # - '-c' - # - 'sh /scripts/script.sh' - # volumeMounts: - # - mountPath: "{{ .Values.artifactory.persistence.mountPath }}" - # name: artifactory-volume - # - mountPath: "/scripts/script.sh" - # name: custom-script - # subPath: script.sh - # resources: - # requests: - # memory: "32Mi" - # cpu: "50m" - # limits: - # memory: "128Mi" - # cpu: "100m" - - ## Add custom volumes - # If .Values.artifactory.unifiedSecretInstallation is true then secret name should be '{{ template "artifactory.name" . }}-unified-secret' - customVolumes: "" - # - name: custom-script - # configMap: - # name: custom-script - - ## Add custom volumesMounts - customVolumeMounts: "" - # - name: custom-script - # mountPath: "/scripts/script.sh" - # subPath: script.sh - # - name: posthook-start - # mountPath: "/scripts/posthoook-start.sh" - # subPath: posthoook-start.sh - # - name: prehook-start - # mountPath: "/scripts/prehook-start.sh" - # subPath: prehook-start.sh - - # Add custom persistent volume mounts - Available to the entire namespace - customPersistentVolumeClaim: {} - # name: - # mountPath: - # accessModes: - # - "-" - # size: - # storageClassName: - - ## Artifactory license. - license: - ## licenseKey is the license key in plain text. Use either this or the license.secret setting - licenseKey: - ## If artifactory.license.secret is passed, it will be mounted as - ## ARTIFACTORY_HOME/etc/artifactory.lic and loaded at run time. - secret: - ## The dataKey should be the name of the secret data key created. - dataKey: - ## Create configMap with artifactory.config.import.xml and security.import.xml and pass name of configMap in following parameter - configMapName: - # Add any list of configmaps to Artifactory - configMaps: "" - # posthook-start.sh: |- - # echo "This is a post start script" - # posthook-end.sh: |- - # echo "This is a post end script" - - ## List of secrets for Artifactory user plugins. - ## One Secret per plugin's files. - userPluginSecrets: - # - archive-old-artifacts - # - build-cleanup - # - webhook - # - '{{ template "my-chart.fullname" . }}' - - ## Artifactory requires a unique master key. - ## You can generate one with the command: "openssl rand -hex 32" - ## An initial one is auto generated by Artifactory on first startup. - # masterKey: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF - ## Alternatively, you can use a pre-existing secret with a key called master-key by specifying masterKeySecretName - # masterKeySecretName: - - ## Join Key to connect other services to Artifactory - ## IMPORTANT: Setting this value overrides the existing joinKey - ## IMPORTANT: You should NOT use the example joinKey for a production deployment! - # joinKey: EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE - ## Alternatively, you can use a pre-existing secret with a key called join-key by specifying joinKeySecretName - # joinKeySecretName: - - ## Registration Token for JFConnect - # jfConnectToken: - ## Alternatively, you can use a pre-existing secret with a key called jfconnect-token by specifying jfConnectTokenSecretName - # jfConnectTokenSecretName: - - # Add custom secrets - secret per file - # If .Values.artifactory.unifiedSecretInstallation is true then secret name should be '{{ template "artifactory.name" . }}-unified-secret' common to all secrets - customSecrets: - # - name: custom-secret - # key: custom-secret.yaml - # data: > - # custom_secret_config: - # parameter1: value1 - # parameter2: value2 - # - name: custom-secret2 - # key: custom-secret2.config - # data: | - # here the custom secret 2 config - - ## If false, all service console logs will not redirect to a common console.log - consoleLog: false - ## admin allows to set the password for the default admin user. - ## See: https://www.jfrog.com/confluence/display/JFROG/Users+and+Groups#UsersandGroups-RecreatingtheDefaultAdminUserrecreate - admin: - ip: "127.0.0.1" - username: "admin" - password: - secret: - dataKey: - ## Extra pre-start command to install JDBC driver for MySql/MariaDb/Oracle - # preStartCommand: "mkdir -p /opt/jfrog/artifactory/var/bootstrap/artifactory/tomcat/lib; cd /opt/jfrog/artifactory/var/bootstrap/artifactory/tomcat/lib && curl -o /opt/jfrog/artifactory/var/bootstrap/artifactory/tomcat/lib/mysql-connector-java-5.1.41.jar https://jcenter.bintray.com/mysql/mysql-connector-java/5.1.41/mysql-connector-java-5.1.41.jar" - - # Add lifecycle hooks for artifactory container - lifecycle: {} - # postStart: - # exec: - # command: ["/bin/sh", "-c", "echo Hello from the postStart handler"] - # preStop: - # exec: - # command: ["/bin/sh","-c","echo Hello from the preStop handler"] - - ## Extra environment variables that can be used to tune Artifactory to your needs. - ## Uncomment and set value as needed - extraEnvironmentVariables: - # - name: SERVER_XML_ARTIFACTORY_PORT - # value: "8081" - # - name: SERVER_XML_ARTIFACTORY_MAX_THREADS - # value: "200" - # - name: SERVER_XML_ACCESS_MAX_THREADS - # value: "50" - # - name: SERVER_XML_ARTIFACTORY_EXTRA_CONFIG - # value: "" - # - name: SERVER_XML_ACCESS_EXTRA_CONFIG - # value: "" - # - name: SERVER_XML_EXTRA_CONNECTOR - # value: "" - # - name: DB_POOL_MAX_ACTIVE - # value: "100" - # - name: DB_POOL_MAX_IDLE - # value: "10" - # - name: MY_SECRET_ENV_VAR - # valueFrom: - # secretKeyRef: - # name: my-secret-name - # key: my-secret-key - - systemYaml: | - router: - serviceRegistry: - insecure: {{ .Values.router.serviceRegistry.insecure }} - shared: - {{- if .Values.artifactory.coldStorage.enabled }} - jfrogColdStorage: - coldInstanceEnabled: true - {{- end }} - {{- if .Values.artifactory.openMetrics.enabled }} - metrics: - enabled: true - {{- if .Values.artifactory.openMetrics.filebeat.enabled }} - filebeat: {{ toYaml .Values.artifactory.openMetrics.filebeat | nindent 6 }} - {{- end }} - {{- end }} - logging: - consoleLog: - enabled: {{ .Values.artifactory.consoleLog }} - extraJavaOpts: > - -Dartifactory.graceful.shutdown.max.request.duration.millis={{ mul .Values.artifactory.terminationGracePeriodSeconds 1000 }} - -Dartifactory.access.client.max.connections={{ .Values.access.tomcat.connector.maxThreads }} - {{- with .Values.artifactory.javaOpts }} - {{- if .corePoolSize }} - -Dartifactory.async.corePoolSize={{ .corePoolSize }} - {{- end }} - {{- if .xms }} - -Xms{{ .xms }} - {{- end }} - {{- if .xmx }} - -Xmx{{ .xmx }} - {{- end }} - {{- if .jmx.enabled }} - -Dcom.sun.management.jmxremote - -Dcom.sun.management.jmxremote.port={{ .jmx.port }} - -Dcom.sun.management.jmxremote.rmi.port={{ .jmx.port }} - -Dcom.sun.management.jmxremote.ssl={{ .jmx.ssl }} - {{- if .jmx.host }} - -Djava.rmi.server.hostname={{ tpl .jmx.host $ }} - {{- else }} - -Djava.rmi.server.hostname={{ template "artifactory.fullname" $ }} - {{- end }} - {{- if .jmx.authenticate }} - -Dcom.sun.management.jmxremote.authenticate=true - -Dcom.sun.management.jmxremote.access.file={{ .jmx.accessFile }} - -Dcom.sun.management.jmxremote.password.file={{ .jmx.passwordFile }} - {{- else }} - -Dcom.sun.management.jmxremote.authenticate=false - {{- end }} - {{- end }} - {{- if .other }} - {{ .other }} - {{- end }} - {{- end }} - {{- if or .Values.database.type .Values.postgresql.enabled }} - database: - {{- if .Values.postgresql.enabled }} - type: postgresql - url: "jdbc:postgresql://{{ .Release.Name }}-postgresql:{{ .Values.postgresql.service.port }}/{{ .Values.postgresql.postgresqlDatabase }}" - driver: org.postgresql.Driver - username: "{{ .Values.postgresql.postgresqlUsername }}" - {{- else }} - type: "{{ .Values.database.type }}" - driver: "{{ .Values.database.driver }}" - {{- end }} - {{- end }} - artifactory: - {{- if or .Values.artifactory.haDataDir.enabled .Values.artifactory.haBackupDir.enabled }} - node: - {{- if .Values.artifactory.haDataDir.path }} - haDataDir: {{ .Values.artifactory.haDataDir.path }} - {{- end }} - {{- if .Values.artifactory.haBackupDir.path }} - haBackupDir: {{ .Values.artifactory.haBackupDir.path }} - {{- end }} - {{- end }} - database: - maxOpenConnections: {{ .Values.artifactory.database.maxOpenConnections }} - tomcat: - maintenanceConnector: - port: {{ .Values.artifactory.tomcat.maintenanceConnector.port }} - connector: - maxThreads: {{ .Values.artifactory.tomcat.connector.maxThreads }} - sendReasonPhrase: {{ .Values.artifactory.tomcat.connector.sendReasonPhrase }} - extraConfig: {{ .Values.artifactory.tomcat.connector.extraConfig }} - frontend: - session: - timeMinutes: {{ .Values.frontend.session.timeoutMinutes | quote }} - access: - database: - maxOpenConnections: {{ .Values.access.database.maxOpenConnections }} - tomcat: - connector: - maxThreads: {{ .Values.access.tomcat.connector.maxThreads }} - sendReasonPhrase: {{ .Values.access.tomcat.connector.sendReasonPhrase }} - extraConfig: {{ .Values.access.tomcat.connector.extraConfig }} - {{- if .Values.mc.enabled }} - mc: - enabled: true - database: - maxOpenConnections: {{ .Values.mc.database.maxOpenConnections }} - idgenerator: - maxOpenConnections: {{ .Values.mc.idgenerator.maxOpenConnections }} - tomcat: - connector: - maxThreads: {{ .Values.mc.tomcat.connector.maxThreads }} - sendReasonPhrase: {{ .Values.mc.tomcat.connector.sendReasonPhrase }} - extraConfig: {{ .Values.mc.tomcat.connector.extraConfig }} - {{- end }} - metadata: - database: - maxOpenConnections: {{ .Values.metadata.database.maxOpenConnections }} - {{- if .Values.artifactory.replicator.enabled }} - replicator: - enabled: true - {{- end }} - {{- if and .Values.jfconnect.enabled (not (regexMatch "^.*(oss|cpp-ce|jcr).*$" .Values.artifactory.image.repository)) }} - jfconnect: - enabled: true - {{- else }} - jfconnect: - enabled: false - jfconnect_service: - enabled: false - {{- end }} - {{- if and .Values.federation.enabled (not (regexMatch "^.*(oss|cpp-ce|jcr).*$" .Values.artifactory.image.repository)) }} - federation: - enabled: true - extraJavaOpts: {{ .Values.federation.extraJavaOpts }} - port: {{ .Values.federation.internalPort }} - rtfs: - database: - driver: org.postgresql.Driver - type: postgresql - username: {{ .Values.federation.database.username }} - password: {{ .Values.federation.database.password }} - url: jdbc:postgresql://{{ .Values.federation.database.host }}:{{ .Values.federation.database.port }}/{{ .Values.federation.database.name }} - {{- else }} - federation: - enabled: false - {{- end }} - {{- if .Values.event.webhooks }} - event: - webhooks: {{ toYaml .Values.event.webhooks | nindent 6 }} - {{- end }} - annotations: {} - service: - name: artifactory - type: ClusterIP - ## For supporting whitelist on the Artifactory service (useful if setting service.type=LoadBalancer) - ## Set this to a list of IP CIDR ranges - ## Example: loadBalancerSourceRanges: ['10.10.10.5/32', '10.11.10.5/32'] - ## or pass from helm command line - ## Example: helm install ... --set nginx.service.loadBalancerSourceRanges='{10.10.10.5/32,10.11.10.5/32}' - loadBalancerSourceRanges: [] - annotations: {} - ## If the type is NodePort you can set a fixed port - # nodePort: 32082 - statefulset: - annotations: {} - ## The following setting are to configure a dedicated Ingress object for Replicator service - replicator: - name: replicator - enabled: false - ## Extra environment variables that can be used to tune replicator to your needs. - ## Uncomment and set value as needed - extraEnvironmentVariables: - # - name: MY_ENV_VAR - # value: "" - resources: {} - # requests: - # memory: "100Mi" - # cpu: "100m" - # limits: - # memory: "1Gi" - # cpu: "1" - - # Add lifecycle hooks for replicator container - lifecycle: {} - # postStart: - # exec: - # command: ["/bin/sh", "-c", "echo Hello from the postStart handler"] - # preStop: - # exec: - # command: ["/bin/sh","-c","echo Hello from the preStop handler"] - - ingress: - enabled: true - name: - hosts: [] - className: "" - annotations: {} - # kubernetes.io/ingress.class: nginx - # nginx.ingress.kubernetes.io/proxy-buffering: "off" - # nginx.ingress.kubernetes.io/configuration-snippet: | - # chunked_transfer_encoding on; - tls: [] - # Secrets must be manually created in the namespace. - # - hosts: - # - artifactory.domain.example - # secretName: chart-example-tls-secret - ## When replicator is enabled and want to use tracker feature, trackerIngress.enabled flag should be set to true - ## Please refer - https://www.jfrog.com/confluence/display/JFROG/JFrog+Peer-to-Peer+%28P2P%29+Downloads - trackerIngress: - enabled: false - name: - hosts: [] - className: "" - annotations: {} - # kubernetes.io/ingress.class: nginx - # nginx.ingress.kubernetes.io/proxy-buffering: "off" - # nginx.ingress.kubernetes.io/configuration-snippet: | - # chunked_transfer_encoding on; - tls: [] - # Secrets must be manually created in the namespace. - # - hosts: - # - artifactory.domain.example - # secretName: chart-example-tls-secret - ## IMPORTANT: If overriding artifactory.internalPort: - ## DO NOT use port lower than 1024 as Artifactory runs as non-root and cannot bind to ports lower than 1024! - externalPort: 8082 - internalPort: 8082 - externalArtifactoryPort: 8081 - internalArtifactoryPort: 8081 - uid: 0 - gid: 0 - # fsGroupChangePolicy: "Always" - # seLinuxOptions: {} - terminationGracePeriodSeconds: 30 - ## By default, the Artifactory StatefulSet is created with a securityContext that sets the `runAsUser` and the `fsGroup` to the `artifactory.uid` value. - ## If you want to disable the securityContext for the Artifactory StatefulSet, set this tag to false - setSecurityContext: true - livenessProbe: - enabled: true - config: | - exec: - command: - - sh - - -c - - curl -s -k --fail --max-time {{ .Values.probes.timeoutSeconds }} http://localhost:{{ .Values.artifactory.tomcat.maintenanceConnector.port }}/artifactory/api/v1/system/liveness - initialDelaySeconds: {{ if semverCompare "", - # "private_key_id": "?????", - # "private_key": "-----BEGIN PRIVATE KEY-----\n????????==\n-----END PRIVATE KEY-----\n", - # "client_email": "???@j.iam.gserviceaccount.com", - # "client_id": "???????", - # "auth_uri": "https://accounts.google.com/o/oauth2/auth", - # "token_uri": "https://oauth2.googleapis.com/token", - # "auth_provider_x509_cert_url": "https://www.googleapis.com/oauth2/v1/certs", - # "client_x509_cert_url": "https://www.googleapis.com/robot/v1....." - # } - endpoint: commondatastorage.googleapis.com - httpsOnly: false - # Set a unique bucket name - bucketName: "artifactory-gcp" - ## GCP Bucket Authentication with Identity and Credential is deprecated. - ## identity: - ## credential: - path: "artifactory/filestore" - bucketExists: false - useInstanceCredentials: false - enableSignedUrlRedirect: false - ## For artifactory.persistence.type aws-s3-v3, s3-storage-v3-direct, cluster-s3-storage-v3, s3-storage-v3-archive - awsS3V3: - testConnection: false - identity: - credential: - region: - bucketName: artifactory-aws - path: artifactory/filestore - endpoint: - port: - useHttp: - maxConnections: 50 - kmsServerSideEncryptionKeyId: - kmsKeyRegion: - kmsCryptoMode: - useInstanceCredentials: true - usePresigning: false - signatureExpirySeconds: 300 - signedUrlExpirySeconds: 30 - cloudFrontDomainName: - cloudFrontKeyPairId: - cloudFrontPrivateKey: - enableSignedUrlRedirect: false - enablePathStyleAccess: false - multiPartLimit: - multipartElementSize: - ## For artifactory.persistence.type azure-blob, azure-blob-storage-direct, cluster-azure-blob-storage - azureBlob: - accountName: - accountKey: - endpoint: - containerName: - multiPartLimit: 100000000 - multipartElementSize: 50000000 - testConnection: false - ## artifactory data Persistent Volume Storage Class - ## If defined, storageClassName: - ## If set to "-", storageClassName: "", which disables dynamic provisioning - ## If undefined (the default) or set to null, no storageClassName spec is - ## set, choosing the default provisioner. (gp2 on AWS, standard on - ## GKE, AWS & OpenStack) - ## - # storageClassName: "-" - ## Annotations for the Persistent Volume Claim - annotations: {} - ## Uncomment the following resources definitions or pass them from command line - ## to control the cpu and memory resources allocated by the Kubernetes cluster - resources: - requests: - memory: "16Gi" - cpu: "4" - limits: - memory: "32Gi" - cpu: "8" - ## The following Java options are passed to the java process running Artifactory. - ## You should set them according to the resources set above - javaOpts: - # xms: "1g" - # xmx: "2g" - jmx: - enabled: false - port: 9010 - host: - ssl: false - # When authenticate is true, accessFile and passwordFile are required - authenticate: false - accessFile: - passwordFile: - # corePoolSize: 24 - # other: "" - - nodeSelector: - dedicated: "jenkins" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "jenkins" - effect: "NoSchedule" - affinity: {} - ## Only used if "affinity" is empty - podAntiAffinity: - ## Valid values are "soft" or "hard"; any other value indicates no anti-affinity - type: "soft" - topologyKey: "kubernetes.io/hostname" - ssh: - enabled: false - internalPort: 1339 - externalPort: 1339 -frontend: - name: frontend - enabled: true - internalPort: 8070 - ## Extra environment variables that can be used to tune frontend to your needs. - ## Uncomment and set value as needed - extraEnvironmentVariables: - # - name: MY_ENV_VAR - # value: "" - resources: {} - # requests: - # memory: "100Mi" - # cpu: "100m" - # limits: - # memory: "1Gi" - # cpu: "1" - - # Add lifecycle hooks for frontend container - lifecycle: {} - # postStart: - # exec: - # command: ["/bin/sh", "-c", "echo Hello from the postStart handler"] - # preStop: - # exec: - # command: ["/bin/sh","-c","echo Hello from the preStop handler"] - - ## Session settings - session: - ## Time in minutes after which the frontend token will need to be refreshed - timeoutMinutes: '30' - ## The following settings are to configure the frequency of the liveness and startup probes when splitServicesToContainers set to true - livenessProbe: - enabled: true - config: | - exec: - command: - - sh - - -c - - curl --fail --max-time {{ .Values.probes.timeoutSeconds }} http://localhost:{{ .Values.frontend.internalPort }}/api/v1/system/liveness - initialDelaySeconds: {{ if semverCompare " --cert=ca.crt --key=ca.private.key` - # customCertificatesSecretName: - - ## When resetAccessCAKeys is true, Access will regenerate the CA certificate and matching private key - # resetAccessCAKeys: false - database: - maxOpenConnections: 80 - tomcat: - connector: - maxThreads: 50 - sendReasonPhrase: false - extraConfig: 'acceptCount="100"' -metadata: - name: metadata - enabled: false - internalPort: 8086 - database: - maxOpenConnections: 80 - ## Extra environment variables that can be used to tune metadata to your needs. - ## Uncomment and set value as needed - extraEnvironmentVariables: - # - name: MY_ENV_VAR - # value: "" - resources: {} - # requests: - # memory: "100Mi" - # cpu: "100m" - # limits: - # memory: "1Gi" - # cpu: "1" - - # Add lifecycle hooks for metadata container - lifecycle: {} - # postStart: - # exec: - # command: ["/bin/sh", "-c", "echo Hello from the postStart handler"] - # preStop: - # exec: - # command: ["/bin/sh","-c","echo Hello from the preStop handler"] - - ## The following settings are to configure the frequency of the liveness and startup probes when splitServicesToContainers set to true - livenessProbe: - enabled: true - config: | - exec: - command: - - sh - - -c - - curl --fail --max-time {{ .Values.probes.timeoutSeconds }} http://localhost:{{ .Values.metadata.internalPort }}/api/v1/system/liveness - initialDelaySeconds: {{ if semverCompare " /var/opt/jfrog/nginx/message"] - # preStop: - # exec: - # command: ["/bin/sh","-c","nginx -s quit; while killall -0 nginx; do sleep 1; done"] - - # Sidecar containers for tailing Nginx logs - loggers: [] - # - access.log - # - error.log - - # Loggers containers resources - loggersResources: {} - # requests: - # memory: "64Mi" - # cpu: "25m" - # limits: - # memory: "128Mi" - # cpu: "50m" - - # Logs options - logs: - stderr: false - level: warn - ## A list of custom ports to expose on the NGINX pod. Follows the conventional Kubernetes yaml syntax for container ports. - customPorts: [] - # customPorts: - # - containerPort: 8066 - # name: docker - - mainConf: | - # Main Nginx configuration file - worker_processes 4; - - {{ if .Values.nginx.logs.stderr }} - error_log stderr {{ .Values.nginx.logs.level }}; - {{- else -}} - error_log {{ .Values.nginx.persistence.mountPath }}/logs/error.log {{ .Values.nginx.logs.level }}; - {{- end }} - pid /tmp/nginx.pid; - - {{- if .Values.artifactory.ssh.enabled }} - ## SSH Server Configuration - stream { - server { - listen {{ .Values.nginx.ssh.internalPort }}; - proxy_pass {{ include "artifactory.fullname" . }}:{{ .Values.artifactory.ssh.externalPort }}; - } - } - {{- end }} - - events { - worker_connections 1024; - } - - - http { - include /etc/nginx/mime.types; - default_type application/octet-stream; - - variables_hash_max_size 1024; - variables_hash_bucket_size 64; - server_names_hash_max_size 4096; - server_names_hash_bucket_size 128; - types_hash_max_size 2048; - types_hash_bucket_size 64; - proxy_read_timeout 2400s; - client_header_timeout 2400s; - client_body_timeout 2400s; - proxy_connect_timeout 75s; - proxy_send_timeout 2400s; - proxy_buffer_size 128k; - proxy_buffers 40 128k; - proxy_busy_buffers_size 128k; - proxy_temp_file_write_size 250m; - proxy_http_version 1.1; - client_body_buffer_size 128k; - - log_format main '$remote_addr - $remote_user [$time_local] "$request" ' - '$status $body_bytes_sent "$http_referer" ' - '"$http_user_agent" "$http_x_forwarded_for"'; - - log_format timing 'ip = $remote_addr ' - 'user = \"$remote_user\" ' - 'local_time = \"$time_local\" ' - 'host = $host ' - 'request = \"$request\" ' - 'status = $status ' - 'bytes = $body_bytes_sent ' - 'upstream = \"$upstream_addr\" ' - 'upstream_time = $upstream_response_time ' - 'request_time = $request_time ' - 'referer = \"$http_referer\" ' - 'UA = \"$http_user_agent\"'; - - access_log {{ .Values.nginx.persistence.mountPath }}/logs/access.log timing; - - sendfile on; - #tcp_nopush on; - - keepalive_timeout 65; - - #gzip on; - - include /etc/nginx/conf.d/*.conf; - - } - artifactoryConf: | - {{- if .Values.nginx.https.enabled }} - ssl_protocols TLSv1 TLSv1.1 TLSv1.2 TLSv1.3; - ssl_certificate {{ .Values.nginx.persistence.mountPath }}/ssl/tls.crt; - ssl_certificate_key {{ .Values.nginx.persistence.mountPath }}/ssl/tls.key; - ssl_session_cache shared:SSL:1m; - ssl_prefer_server_ciphers on; - {{- end }} - ## server configuration - server { - {{- if .Values.nginx.internalPortHttps }} - listen {{ .Values.nginx.internalPortHttps }} ssl; - {{- else -}} - {{- if .Values.nginx.https.enabled }} - listen {{ .Values.nginx.https.internalPort }} ssl; - {{- end }} - {{- end }} - {{- if .Values.nginx.internalPortHttp }} - listen {{ .Values.nginx.internalPortHttp }}; - {{- else -}} - {{- if .Values.nginx.http.enabled }} - listen {{ .Values.nginx.http.internalPort }}; - {{- end }} - {{- end }} - server_name ~(?.+)\.{{ include "artifactory.fullname" . }} {{ include "artifactory.fullname" . }} - {{- range .Values.ingress.hosts -}} - {{- if contains "." . -}} - {{ "" | indent 0 }} ~(?.+)\.{{ . }} - {{- end -}} - {{- end -}}; - - if ($http_x_forwarded_proto = '') { - set $http_x_forwarded_proto $scheme; - } - ## Application specific logs - ## access_log /var/log/nginx/artifactory-access.log timing; - ## error_log /var/log/nginx/artifactory-error.log; - rewrite ^/artifactory/?$ / redirect; - if ( $repo != "" ) { - rewrite ^/(v1|v2)/(.*) /artifactory/api/docker/$repo/$1/$2 break; - } - chunked_transfer_encoding on; - client_max_body_size 0; - - location / { - proxy_read_timeout 900; - proxy_pass_header Server; - proxy_cookie_path ~*^/.* /; - proxy_pass {{ include "artifactory.scheme" . }}://{{ include "artifactory.fullname" . }}:{{ .Values.artifactory.externalPort }}/; - {{- if .Values.nginx.service.ssloffload}} - proxy_set_header X-JFrog-Override-Base-Url $http_x_forwarded_proto://$host; - {{- else }} - proxy_set_header X-JFrog-Override-Base-Url $http_x_forwarded_proto://$host:$server_port; - proxy_set_header X-Forwarded-Port $server_port; - {{- end }} - proxy_set_header X-Forwarded-Proto $http_x_forwarded_proto; - proxy_set_header Host $http_host; - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; - {{- if .Values.nginx.disableProxyBuffering}} - proxy_http_version 1.1; - proxy_request_buffering off; - proxy_buffering off; - {{- end }} - add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always; - - location /artifactory/ { - if ( $request_uri ~ ^/artifactory/(.*)$ ) { - proxy_pass http://{{ include "artifactory.fullname" . }}:{{ .Values.artifactory.externalArtifactoryPort }}/artifactory/$1; - } - proxy_pass http://{{ include "artifactory.fullname" . }}:{{ .Values.artifactory.externalArtifactoryPort }}/artifactory/; - } - location /pipelines/ { - proxy_http_version 1.1; - proxy_set_header Upgrade $http_upgrade; - proxy_set_header Connection "upgrade"; - proxy_set_header Host $http_host; - {{- if .Values.router.tlsEnabled }} - proxy_pass https://{{ include "artifactory.fullname" . }}:{{ .Values.router.internalPort }}; - {{- else }} - proxy_pass http://{{ include "artifactory.fullname" . }}:{{ .Values.router.internalPort }}; - {{- end }} - } - } - } - customInitContainers: "" - customSidecarContainers: "" - customVolumes: "" - customVolumeMounts: "" - customCommand: - ## allows overwriting the command for the nginx container. - ## defaults to [ 'nginx', '-g', 'daemon off;' ] - - service: - ## For minikube, set this to NodePort, elsewhere use LoadBalancer - type: LoadBalancer - ssloffload: false - ## For supporting whitelist on the Nginx LoadBalancer service - ## Set this to a list of IP CIDR ranges - ## Example: loadBalancerSourceRanges: ['10.10.10.5/32', '10.11.10.5/32'] - ## or pass from helm command line - ## Example: helm install ... --set nginx.service.loadBalancerSourceRanges='{10.10.10.5/32,10.11.10.5/32}' - loadBalancerSourceRanges: [] - annotations: {} - ## Provide static ip address - loadBalancerIP: - ## There are two available options: “Cluster” (default) and “Local”. - externalTrafficPolicy: Cluster - ## If the type is NodePort you can set a fixed port - # nodePort: 32082 - ## A list of custom ports to be exposed on nginx service. Follows the conventional Kubernetes yaml syntax for service ports. - customPorts: [] - # - port: 8066 - # targetPort: 8066 - # protocol: TCP - # name: docker - http: - enabled: true - externalPort: 80 - internalPort: 80 - https: - enabled: true - externalPort: 443 - internalPort: 443 - ssh: - internalPort: 1339 - externalPort: 1339 - # DEPRECATED: The following will be removed in a future release - # externalPortHttp: 80 - # internalPortHttp: 80 - # externalPortHttps: 443 - # internalPortHttps: 443 - - ## The following settings are to configure the frequency of the liveness and readiness probes. - livenessProbe: - enabled: true - config: | - exec: - command: - - sh - - -c - - curl -s -k --fail --max-time {{ .Values.probes.timeoutSeconds }} {{ include "nginx.scheme" . }}://localhost:{{ include "nginx.port" . }}/ - initialDelaySeconds: {{ if semverCompare " - ## If set to "-", storageClassName: "", which disables dynamic provisioning - ## If undefined (the default) or set to null, no storageClassName spec is - ## set, choosing the default provisioner. (gp2 on AWS, standard on - ## GKE, AWS & OpenStack) - ## - # storageClassName: "-" - resources: {} - # requests: - # memory: "250Mi" - # cpu: "100m" - # limits: - # memory: "250Mi" - # cpu: "500m" - nodeSelector: {} - tolerations: [] - affinity: {} -## Database configurations -## Use the wait-for-db init container. Set to false to skip -waitForDatabase: true - -## Configuration values for the PostgreSQL dependency sub-chart -## ref: https://github.com/bitnami/charts/blob/master/bitnami/postgresql/README.md -postgresql: - enabled: false - image: - registry: releases-docker.jfrog.io - repository: bitnami/postgresql - tag: 13.10.0-debian-11-r14 - postgresqlUsername: artifactory - postgresqlPassword: "admin" - postgresqlDatabase: artifactory - postgresqlExtendedConf: - listenAddresses: "*" - maxConnections: "1500" - persistence: - enabled: true - size: 10Gi - # existingClaim: - service: - port: 5432 - primary: - labels: - bu: "infra" - team: "devops" - service: "jfrog-prd" - env: "prd" - priority: "p0" - type: "jfrog-psql-master" - podLabels: - bu: "infra" - team: "devops" - service: "jfrog-prd" - env: "prd" - priority: "p0" - type: "jfrog-psql-master" - nodeSelector: - dedicated: "jenkins" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "jenkins" - effect: "NoSchedule" - affinity: {} - readReplicas: - labels: - bu: "infra" - team: "devops" - service: "jfrog-prd" - env: "prd" - priority: "p0" - type: "jfrog-psql-slave" - podLabels: - bu: "infra" - team: "devops" - service: "jfrog-prd" - env: "prd" - priority: "p0" - type: "jfrog-psql-slave" - affinity: {} - nodeSelector: - dedicated: "jenkins" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "jenkins" - effect: "NoSchedule" - resources: {} - securityContext: - enabled: true - containerSecurityContext: - enabled: true - runAsNonRoot: true - allowPrivilegeEscalation: false - seccompProfile: - type: RuntimeDefault - capabilities: - drop: - - ALL - # requests: - # memory: "512Mi" - # cpu: "100m" - # limits: - # memory: "1Gi" - # cpu: "500m" -## If NOT using the PostgreSQL in this chart (postgresql.enabled=false), -## specify custom database details here or leave empty and Artifactory will use embedded derby - -database: - type: postgresql - driver: org.postgresql.Driver - ## If you set the url, leave host and port empty - url: - ## If you would like this chart to create the secret containing the db - ## password, use these values - user: - password: - ## If you have existing Kubernetes secrets containing db credentials, use - ## these values - secrets: - user: - name: "jfrog-prd-secret" - key: "db-user" - password: - name: "jfrog-prd-secret" - key: "db-password" - url: - name: "jfrog-prd-secret" - key: "db-url" - -# Filebeat Sidecar container -## The provided filebeat configuration is for Artifactory logs. It assumes you have a logstash installed and configured properly. -filebeat: - enabled: false - name: artifactory-filebeat - image: - repository: "docker.elastic.co/beats/filebeat" - version: 7.16.2 - logstashUrl: "logstash:5044" - livenessProbe: - exec: - command: - - sh - - -c - - | - #!/usr/bin/env bash -e - curl --fail 127.0.0.1:5066 - failureThreshold: 3 - initialDelaySeconds: 10 - periodSeconds: 10 - timeoutSeconds: 5 - readinessProbe: - exec: - command: - - sh - - -c - - | - #!/usr/bin/env bash -e - filebeat test output - failureThreshold: 3 - initialDelaySeconds: 10 - periodSeconds: 10 - timeoutSeconds: 5 - resources: {} - # requests: - # memory: "100Mi" - # cpu: "100m" - # limits: - # memory: "100Mi" - # cpu: "100m" - - filebeatYml: | - logging.level: info - path.data: {{ .Values.artifactory.persistence.mountPath }}/log/filebeat - name: artifactory-filebeat - queue.spool: - file: - permissions: 0760 - filebeat.inputs: - - type: log - enabled: true - close_eof: ${CLOSE:false} - paths: - - {{ .Values.artifactory.persistence.mountPath }}/log/*.log - fields: - service: "jfrt" - log_type: "artifactory" - output: - logstash: - hosts: ["{{ .Values.filebeat.logstashUrl }}"] -## Allows to add additional kubernetes resources -## Use --- as a separator between multiple resources -## For an example, refer - https://github.com/jfrog/log-analytics-prometheus/blob/master/artifactory-values.yaml -additionalResources: "" -# Adding entries to a Pod's /etc/hosts file -# For an example, refer - https://kubernetes.io/docs/concepts/services-networking/add-entries-to-pod-etc-hosts-with-host-aliases -hostAliases: [] -# - ip: "127.0.0.1" -# hostnames: -# - "foo.local" -# - "bar.local" -# - ip: "10.1.2.3" -# hostnames: -# - "foo.remote" -# - "bar.remote" - -## Toggling this feature is seamless and requires helm upgrade -## will enable all microservices to run in different containers in a single pod (by default it is true) -splitServicesToContainers: true -## Specify common probes parameters -probes: - timeoutSeconds: 5 diff --git a/helm-overrides/k8s-admin-prd-ase1/keda/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/keda/custom-values.yaml deleted file mode 100644 index 135f17a..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/keda/custom-values.yaml +++ /dev/null @@ -1,26 +0,0 @@ -keda: - operator: - replicaCount: 2 - metricsServer: - replicaCount: 2 - nodeSelector: - dedicated: devops - tolerations: - - key: "dedicated" - operator: "Equal" - value: "devops" - effect: "NoSchedule" - podLabels: - bu: "infra" - team: "devops" - metricsAdapter: - bu: "infra" - team: "devops" - resources: - webhooks: - limits: - cpu: 50m - memory: 150Mi - requests: - cpu: 10m - memory: 25Mi diff --git a/helm-overrides/k8s-admin-prd-ase1/kube-dns/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/kube-dns/custom-values.yaml deleted file mode 100644 index c3c32d1..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/kube-dns/custom-values.yaml +++ /dev/null @@ -1,2 +0,0 @@ -stubDomains: >- - {"clusterset.local":["169.254.169.254"]} \ No newline at end of file diff --git a/helm-overrides/k8s-admin-prd-ase1/kube-events/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/kube-events/custom-values.yaml deleted file mode 100644 index 4b9b470..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/kube-events/custom-values.yaml +++ /dev/null @@ -1,149 +0,0 @@ - -fullnameOverride: kube-events-infra-prd - -operator: - enabled: true - image: - repository: kubesphere/kube-events-operator - tag: "" # If unset use v+ .Chart.appVersion - pullPolicy: IfNotPresent - configReloader: - image: jimmidyson/configmap-reload:v0.7.1 - affinity: {} - nodeSelector: - dedicated: "sre-shared-tmp" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "sre-shared-tmp" - effect: "NoSchedule" - resources: - limits: - cpu: 200m - memory: 200Mi - requests: - cpu: 20m - memory: 20Mi - # Additional volumes on the Deployment definition. - volumes: [] - # Additional volumeMounts on the Deployment definition. - volumeMounts: [] - serviceAccount: - create: true - name: "" - # If true, just clean up cr but not crd - cleanupAllCustomResources: false - kubectlImage: docker.io/bitnami/kubectl:1.14.1 - -exporter: - enabled: true - image: - repository: kubesphere/kube-events-exporter - tag: "" # If unset use v+ .Chart.appVersion - pullPolicy: IfNotPresent - affinity: {} - nodeSelector: - dedicated: "sre-shared-tmp" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "sre-shared-tmp" - effect: "NoSchedule" - resources: - limits: - cpu: 200m - memory: 500Mi - requests: - cpu: 20m - memory: 50Mi - # Additional volumes on the output Deployment definition. - volumes: [] - # Additional volumeMounts on the output Deployment definition. - volumeMounts: [] - sinks: - stdout: - enabled: true - additionalWebhooks: [] - # - url: - # service: - # namespace: - # name: - # port: - # path: - -# Configure fluentbit(operated by https://github.com/fluent/fluent-operator) to collect events logs of exporter. -# These will be applied only when exporter.stdout.enabled=true and fluentbit.enabled=true. -fluentbit: - enabled: false - # Set this to containerd or crio if you want fluentbit to collect CRI format logs. - # If not set, it will be auto detected. - containerRuntime: "" - input: - enabled: true - tail: - refreshIntervalSeconds: 10 - memBufLimit: 5MB - skipLongLines: true - dbSync: Normal - filter: - enabled: true - additionalFilters: [] - output: - enabled: true - opensearch: - host: opensearch-cluster-data.kubesphere-logging-system.svc - port: 9200 - logstashPrefix: ks-whizard-events - suppressTypeName: true - logstashFormat: true - generateID: true - -ruler: - enabled: false - replicas: 2 - image: - repository: kubesphere/kube-events-ruler - tag: "" # If unset use v+ .Chart.appVersion - pullPolicy: IfNotPresent - affinity: {} - nodeSelector: - dedicated: "sre-shared-tmp" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "sre-shared-tmp" - effect: "NoSchedule" - resources: - limits: - cpu: 500m - memory: 500Mi - requests: - cpu: 50m - memory: 50Mi - # Additional volumes on the output Deployment definition. - volumes: [] - # Additional volumeMounts on the output Deployment definition. - volumeMounts: [] - ruleNamespaceSelector: {} - ruleSelector: {} - sinks: - alertmanagers: - - namespace: kubesphere-monitoring-system - name: alertmanager-operated - # webhooks: - # - type: - # url: - # service: - # namespace: - # name: - # port: - # path: - ## 'stdout' sink type can be either 'notification' or 'alert' - # stdout: - # type: notification -rule: - createDefaults: true - overrideDefaults: false - -# Set timezone env variable to be set in containers -timezone: "Asia/Kolkata" diff --git a/helm-overrides/k8s-admin-prd-ase1/kube-state-metrics/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/kube-state-metrics/custom-values.yaml deleted file mode 100644 index a9caf18..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/kube-state-metrics/custom-values.yaml +++ /dev/null @@ -1,478 +0,0 @@ -# Default values for kube-state-metrics. -prometheusScrape: true -image: - registry: asia-southeast1-docker.pkg.dev - repository: meesho-devops-admin-0622/admin/sre/kube-state-metrics - # If unset use v + .Charts.appVersion - tag: v2.9.2 - sha: "" - pullPolicy: IfNotPresent - -fullnameOverride: kube-state-metrics-infra-prd - -dedicatedValue: false - -imagePullSecrets: [] -# - name: "image-pull-secret" - -ingress: - enabled: false - ingressClassName: internal - annotations: - nginx.ingress.kubernetes.io/force-ssl-redirect: "false" - nginx.ingress.kubernetes.io/rewrite-target: / - nginx.ingress.kubernetes.io/ssl-redirect: "false" - # kubernetes.io/ingress.class: nginx - # kubernetes.io/tls-acme: 'true' - - extraLabels: {} - hosts: - - name: clustermetrics-infra-prd.meesho.com - path: / - port: http - tls: [] - # - secretName: vmagent-ingress-tls - # hosts: - # - vmagent.local - # For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName - # See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress - # ingressClassName: nginx - # -- pathType is only for k8s >= 1.1= - pathType: Prefix - -global: - # To help compatibility with other charts which use global.imagePullSecrets. - # Allow either an array of {name: pullSecret} maps (k8s-style), or an array of strings (more common helm-style). - # global: - # imagePullSecrets: - # - name: pullSecret1 - # - name: pullSecret2 - # or - # global: - # imagePullSecrets: - # - pullSecret1 - # - pullSecret2 - imagePullSecrets: [] - # - # Allow parent charts to override registry hostname - imageRegistry: "" - -# If set to true, this will deploy kube-state-metrics as a StatefulSet and the data -# will be automatically sharded across <.Values.replicas> pods using the built-in -# autodiscovery feature: https://github.com/kubernetes/kube-state-metrics#automated-sharding -# This is an experimental feature and there are no stability guarantees. -autosharding: - enabled: false - -replicas: 2 - -# List of additional cli arguments to configure kube-state-metrics -# for example: --enable-gzip-encoding, --log-file, etc. -# all the possible args can be found here: https://github.com/kubernetes/kube-state-metrics/blob/master/docs/cli-arguments.md -extraArgs: [] - -service: - port: 8080 - # Default to clusterIP for backward compatibility - type: ClusterIP - nodePort: 0 - loadBalancerIP: "" - # Only allow access to the loadBalancerIP from these IPs - loadBalancerSourceRanges: [] - clusterIP: "" - annotations: {} - -## Additional labels to add to all resources -customLabels: - bu: "infra" - team: "sre" - service: "kube-state-metrics-infra-prd" - env: "prd" - priority: "p0" - type: "exporter" - - # app: kube-state-metrics - -## Override selector labels -selectorOverride: {} - -## set to true to add the release label so scraping of the servicemonitor with kube-prometheus-stack works out of the box -releaseLabel: false - -hostNetwork: false - -rbac: - # If true, create & use RBAC resources - create: true - - # Set to a rolename to use existing role - skipping role creating - but still doing serviceaccount and rolebinding to it, rolename set here. - # useExistingRole: your-existing-role - - # If set to false - Run without Cluteradmin privs needed - ONLY works if namespace is also set (if useExistingRole is set this name is used as ClusterRole or Role to bind to) - useClusterRole: true - - # Add permissions for CustomResources' apiGroups in Role/ClusterRole. Should be used in conjunction with Custom Resource State Metrics configuration - # Example: - # - apiGroups: ["monitoring.coreos.com"] - # resources: ["prometheuses"] - # verbs: ["list", "watch"] - extraRules: [] - -# Configure kube-rbac-proxy. When enabled, creates one kube-rbac-proxy container per exposed HTTP endpoint (metrics and telemetry if enabled). -# The requests are served through the same service but requests are then HTTPS. -kubeRBACProxy: - enabled: false - image: - registry: quay.io - repository: brancz/kube-rbac-proxy - tag: v0.14.0 - sha: "" - pullPolicy: IfNotPresent - - # List of additional cli arguments to configure kube-rbac-prxy - # for example: --tls-cipher-suites, --log-file, etc. - # all the possible args can be found here: https://github.com/brancz/kube-rbac-proxy#usage - extraArgs: [] - - ## Specify security settings for a Container - ## Allows overrides and additional options compared to (Pod) securityContext - ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container - containerSecurityContext: {} - - resources: {} - # We usually recommend not to specify default resources and to leave this as a conscious - # choice for the user. This also increases chances charts run on environments with little - # resources, such as Minikube. If you do want to specify resources, uncomment the following - # lines, adjust them as necessary, and remove the curly braces after 'resources:'. - # limits: - # cpu: 100m - # memory: 64Mi - # requests: - # cpu: 10m - # memory: 32Mi - - ## volumeMounts enables mounting custom volumes in rbac-proxy containers - ## Useful for TLS certificates and keys - volumeMounts: [] - # - mountPath: /etc/tls - # name: kube-rbac-proxy-tls - # readOnly: true - -serviceAccount: - # Specifies whether a ServiceAccount should be created, require rbac true - create: true - # The name of the ServiceAccount to use. - # If not set and create is true, a name is generated using the fullname template - name: - # Reference to one or more secrets to be used when pulling images - # ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ - imagePullSecrets: [] - # ServiceAccount annotations. - # Use case: AWS EKS IAM roles for service accounts - # ref: https://docs.aws.amazon.com/eks/latest/userguide/specify-service-account-role.html - annotations: {} - -prometheus: - monitor: - enabled: false - annotations: {} - additionalLabels: {} - namespace: "" - jobLabel: "" - targetLabels: [] - podTargetLabels: [] - interval: "" - ## SampleLimit defines per-scrape limit on number of scraped samples that will be accepted. - ## - sampleLimit: 0 - - ## TargetLimit defines a limit on the number of scraped targets that will be accepted. - ## - targetLimit: 0 - - ## Per-scrape limit on number of labels that will be accepted for a sample. Only valid in Prometheus versions 2.27.0 and newer. - ## - labelLimit: 0 - - ## Per-scrape limit on length of labels name that will be accepted for a sample. Only valid in Prometheus versions 2.27.0 and newer. - ## - labelNameLengthLimit: 0 - - ## Per-scrape limit on length of labels value that will be accepted for a sample. Only valid in Prometheus versions 2.27.0 and newer. - ## - labelValueLengthLimit: 0 - scrapeTimeout: "" - proxyUrl: "" - selectorOverride: {} - honorLabels: false - metricRelabelings: [] - relabelings: [] - scheme: "" - ## File to read bearer token for scraping targets - bearerTokenFile: "" - ## Secret to mount to read bearer token for scraping targets. The secret needs - ## to be in the same namespace as the service monitor and accessible by the - ## Prometheus Operator - bearerTokenSecret: {} - # name: secret-name - # key: key-name - tlsConfig: {} - -## Specify if a Pod Security Policy for kube-state-metrics must be created -## Ref: https://kubernetes.io/docs/concepts/policy/pod-security-policy/ -## -podSecurityPolicy: - enabled: false - annotations: {} - ## Specify pod annotations - ## Ref: https://kubernetes.io/docs/concepts/policy/pod-security-policy/#apparmor - ## Ref: https://kubernetes.io/docs/concepts/policy/pod-security-policy/#seccomp - ## Ref: https://kubernetes.io/docs/concepts/policy/pod-security-policy/#sysctl - ## - # seccomp.security.alpha.kubernetes.io/allowedProfileNames: '*' - # seccomp.security.alpha.kubernetes.io/defaultProfileName: 'docker/default' - # apparmor.security.beta.kubernetes.io/defaultProfileName: 'runtime/default' - - additionalVolumes: [] - -## Configure network policy for kube-state-metrics -networkPolicy: - enabled: false - # networkPolicy.flavor -- Flavor of the network policy to use. - # Can be: - # * kubernetes for networking.k8s.io/v1/NetworkPolicy - # * cilium for cilium.io/v2/CiliumNetworkPolicy - flavor: kubernetes - - ## Configure the cilium network policy kube-apiserver selector - # cilium: - # kubeApiServerSelector: - # - toEntities: - # - kube-apiserver - - # egress: - # - {} - # ingress: - # - {} - # podSelector: - # matchLabels: - # app.kubernetes.io/name: kube-state-metrics - -securityContext: - enabled: true - runAsGroup: 65534 - runAsUser: 65534 - fsGroup: 65534 - runAsNonRoot: true - seccompProfile: - type: RuntimeDefault - -## Specify security settings for a Container -## Allows overrides and additional options compared to (Pod) securityContext -## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container -containerSecurityContext: - allowPrivilegeEscalation: false - capabilities: - drop: - - ALL - -## Node labels for pod assignment -## Ref: https://kubernetes.io/docs/user-guide/node-selection/ -nodeSelector: - dedicated: "sre-shared-tmp" - -## Affinity settings for pod assignment -## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/ -affinity: {} - -## Tolerations for pod assignment -## Ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/ -tolerations: - - key: "dedicated" - operator: "Equal" - value: "sre-shared-tmp" - effect: "NoSchedule" - -## Topology spread constraints for pod assignment -## Ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/ -topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: DoNotSchedule - labelSelector: - matchLabels: - type: exporter - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: DoNotSchedule - labelSelector: - matchLabels: - type: exporter - -# Annotations to be added to the deployment/statefulset -annotations: - kubernetes.io/psp: eks.privileged - -# Annotations to be added to the pod -podAnnotations: {} - -## Assign a PriorityClassName to pods if set -# priorityClassName: "" - -# Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/ -podDisruptionBudget: {} - -# Comma-separated list of metrics to be exposed. -# This list comprises of exact metric names and/or regex patterns. -# The allowlist and denylist are mutually exclusive. -metricAllowlist: [] - -# Comma-separated list of metrics not to be enabled. -# This list comprises of exact metric names and/or regex patterns. -# The allowlist and denylist are mutually exclusive. -metricDenylist: [] - -# Comma-separated list of additional Kubernetes label keys that will be used in the resource's -# labels metric. By default the metric contains only name and namespace labels. -# To include additional labels, provide a list of resource names in their plural form and Kubernetes -# label keys you would like to allow for them (Example: '=namespaces=[k8s-label-1,k8s-label-n,...],pods=[app],...)'. -# A single '*' can be provided per resource instead to allow any labels, but that has -# severe performance implications (Example: '=pods=[*]'). -metricLabelsAllowlist: - - pods=[*] - - nodes=[*] - - deployments=[*] - - statefulsets=[*] - - persistentvolumeclaims=[*] - - persistentvolumes=[*] - - ingresses=[*] - - namespaces=[*] - - horizontalpodautoscalers=[*] - # - namespaces=[k8s-label-1,k8s-label-n] - -# Comma-separated list of Kubernetes annotations keys that will be used in the resource' -# labels metric. By default the metric contains only name and namespace labels. -# To include additional annotations provide a list of resource names in their plural form and Kubernetes -# annotation keys you would like to allow for them (Example: '=namespaces=[kubernetes.io/team,...],pods=[kubernetes.io/team],...)'. -# A single '*' can be provided per resource instead to allow any annotations, but that has -# severe performance implications (Example: '=pods=[*]'). -metricAnnotationsAllowList: [] - # - pods=[k8s-annotation-1,k8s-annotation-n] - -# Available collectors for kube-state-metrics. -# By default, all available resources are enabled, comment out to disable. -collectors: - - certificatesigningrequests - - configmaps - - cronjobs - - daemonsets - - deployments - - endpoints - - horizontalpodautoscalers - - ingresses - - jobs - - leases - - limitranges - - mutatingwebhookconfigurations - - namespaces - - networkpolicies - - nodes - - persistentvolumeclaims - - persistentvolumes - - poddisruptionbudgets - - pods - - replicasets - - replicationcontrollers - - resourcequotas - - secrets - - services - - statefulsets - - storageclasses - - validatingwebhookconfigurations - - volumeattachments - -# Enabling kubeconfig will pass the --kubeconfig argument to the container -kubeconfig: - enabled: false - # base64 encoded kube-config file - secret: - -# Enabling support for customResourceState, will create a configMap including your config that will be read from kube-state-metrics -customResourceState: - enabled: false - # Add (Cluster)Role permissions to list/watch the customResources defined in the config to rbac.extraRules - config: {} - -# Enable only the release namespace for collecting resources. By default all namespaces are collected. -# If releaseNamespace and namespaces are both set a merged list will be collected. -releaseNamespace: false - -# Comma-separated list(string) or yaml list of namespaces to be enabled for collecting resources. By default all namespaces are collected. -namespaces: "" - -# Comma-separated list of namespaces not to be enabled. If namespaces and namespaces-denylist are both set, -# only namespaces that are excluded in namespaces-denylist will be used. -namespacesDenylist: "" - -## Override the deployment namespace -## -namespaceOverride: "" - -resources: - # We usually recommend not to specify default resources and to leave this as a conscious - # choice for the user. This also increases chances charts run on environments with little - # resources, such as Minikube. If you do want to specify resources, uncomment the following - # lines, adjust them as necessary, and remove the curly braces after 'resources:'. - # limits: - # cpu: 100m - # memory: 64Mi - requests: - cpu: 40m - memory: 200Mi - -## Provide a k8s version to define apiGroups for podSecurityPolicy Cluster Role. -## For example: kubeTargetVersionOverride: 1.14.9 -## -kubeTargetVersionOverride: "" - -# Enable self metrics configuration for service and Service Monitor -# Default values for telemetry configuration can be overridden -# If you set telemetryNodePort, you must also set service.type to NodePort -selfMonitor: - enabled: true - # telemetryHost: 0.0.0.0 - telemetryPort: 8081 - # telemetryNodePort: 0 - -# Enable vertical pod autoscaler support for kube-state-metrics -verticalPodAutoscaler: - enabled: false - # List of resources that the vertical pod autoscaler can control. Defaults to cpu and memory - controlledResources: [] - - # Define the max allowed resources for the pod - maxAllowed: {} - # cpu: 200m - # memory: 100Mi - # Define the min allowed resources for the pod - minAllowed: {} - # cpu: 200m - # memory: 100Mi - - # updatePolicy: - # Specifies whether recommended updates are applied when a Pod is started and whether recommended updates - # are applied during the life of a Pod. Possible values are "Off", "Initial", "Recreate", and "Auto". - # updateMode: Auto - -# volumeMounts are used to add custom volume mounts to deployment. -# See example below -volumeMounts: [] -# - mountPath: /etc/config -# name: config-volume - -# volumes are used to add custom volumes to deployment -# See example below -volumes: [] -# - configMap: -# name: cm-for-volume -# name: config-volume diff --git a/helm-overrides/k8s-admin-prd-ase1/kubectl-mcp-server/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/kubectl-mcp-server/custom-values.yaml deleted file mode 100644 index 6153fd4..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/kubectl-mcp-server/custom-values.yaml +++ /dev/null @@ -1,128 +0,0 @@ -fullnameOverride: "kubectl-mcp-server" - -replicas: 1 - -image: - # In-house hardened build (helm-templates/kubectl-mcp-server/docker/) — - # NOT the upstream Docker Hub image. 266→18 HIGH/CRIT vulns, non-root, - # multi-stage slim base, kubectl v1.33.12 / helm v3.21.0. - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/prd/devop/kubectl-mcp-server - tag: "v2" - pullPolicy: IfNotPresent - -labels: - bu: infra - team: devops - service: kubectl-mcp-server - env: prd - -serviceAccount: - create: true - annotations: {} - -rbac: - create: true - -podAnnotations: {} - -podSecurityContext: {} - -securityContext: - runAsNonRoot: true - runAsUser: 1000 - allowPrivilegeEscalation: false - capabilities: - drop: - - ALL - -priorityClassName: "" - -# Admin cluster has no `admin-devops` pool — the general devops nodepool -# is labelled/tainted `dedicated=devops` (verified on k8s-admin-prd-ase1). -nodeSelector: - dedicated: "devops" - -tolerations: - - key: "dedicated" - operator: "Equal" - value: "devops" - effect: NoSchedule - -affinity: {} - -resources: - requests: - cpu: 250m - memory: 512Mi - limits: - cpu: 1000m - memory: 1Gi - -mcp: - mode: single - transport: http - host: "0.0.0.0" - port: 8000 - -auth: - allowAnonymous: false - -externalSecrets: - enabled: true - refreshInterval: "150s" - secretStoreRef: - name: vault-backend - kind: ClusterSecretStore - dataFrom: - secretKey: "meesho/prd/cntr/devop/kubectl-mcp-server-admin" - -# tcpSocket on purpose — streamable-http transport exposes only /mcp, -# there is no /health route (see chart values.yaml note). -livenessProbe: - tcpSocket: - port: 8000 - initialDelaySeconds: 30 - periodSeconds: 30 - timeoutSeconds: 5 - failureThreshold: 3 - -readinessProbe: - tcpSocket: - port: 8000 - initialDelaySeconds: 10 - periodSeconds: 10 - timeoutSeconds: 5 - failureThreshold: 3 - -service: - port: 8000 - type: ClusterIP - -# admin prd has no Contour — only nginx-external / nginx-internal ingress -# classes. Use the networking.k8s.io Ingress path (nginx-internal), not -# the HTTPProxy/Contour gateway. Verified on k8s-admin-prd-ase1. -createContourGateway: false - -ingress: - enabled: true - ingressClassName: nginx-internal - servicePortNumber: 8000 - hosts: - - host: kubectl-mcp-server-admin.prd.meesho.int - paths: - - path: / - pathType: Prefix - annotations: - kubernetes.io/ingress.class: nginx-internal - nginx.ingress.kubernetes.io/ssl-redirect: "false" - nginx.ingress.kubernetes.io/proxy-read-timeout: "300" - nginx.ingress.kubernetes.io/proxy-send-timeout: "300" - nginx.ingress.kubernetes.io/proxy-body-size: "10m" - nginx.ingress.kubernetes.io/proxy-buffer-size: "16k" - nginx.ingress.kubernetes.io/limit-rps: "10" - nginx.ingress.kubernetes.io/limit-connections: "20" - slowStart: - enabled: false - window: "120s" - aggression: 1 - minPercent: 10 diff --git a/helm-overrides/k8s-admin-prd-ase1/loki-distributed/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/loki-distributed/custom-values.yaml deleted file mode 100644 index 3d3ff74..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/loki-distributed/custom-values.yaml +++ /dev/null @@ -1,272 +0,0 @@ -fullnameOverride: "loki" - -serviceAccount: - annotations: { - iam.gke.io/gcp-service-account: sa-infr-sre-obs-prd@meesho-admin-prd-0622.iam.gserviceaccount.com - } - -loki: - auth_enabled: false - - server: - grpc_server_max_recv_msg_size: 104857600 - grpc_server_max_send_msg_size: 104857600 - http_server_read_timeout: 60s - http_server_write_timeout: 60s - - ingester_client: - remote_timeout: 60s - - limits_config: - allow_structured_metadata: true - retention_period: 744h - max_line_size: 0 - ingestion_rate_mb: 512 - ingestion_burst_size_mb: 1024 - per_stream_rate_limit: 512M - per_stream_rate_limit_burst: 1024M - - schemaConfig: - configs: - - from: 2024-04-01 - store: tsdb - object_store: gcs - schema: v13 - index: - prefix: index_ - period: 24h - - storage_config: - tsdb_shipper: - active_index_directory: /var/loki/index - cache_location: /var/loki/index_cache - cache_ttl: 48h - gcs: - bucket_name: "loki_data" - object_prefix: "chunks" - storage: - type: gcs - bucketNames: - chunks: loki_data - - compactor: - working_directory: /var/loki/compactor - - tracing: - enabled: false - -deploymentMode: Distributed - -distributor: - replicas: 1 - maxUnavailable: 1 - resources: - limits: - cpu: 32 - memory: 30Gi - requests: - cpu: 30 - memory: 27Gi - nodeSelector: - dedicated: "loki-highcpu" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "loki-highcpu" - effect: "NoSchedule" - affinity: {} - -ingester: - replicas: 2 - persistence: - enabled: true - claims: - - name: data - size: 500Gi - storageClass: "premium-rwo" - resources: - limits: - cpu: 47 - memory: 180Gi - requests: - cpu: 45 - memory: 175Gi - nodeSelector: - dedicated: "loki-standard" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "loki-standard" - effect: "NoSchedule" - zoneAwareReplication: - enabled: false - -queryFrontend: - replicas: 2 - maxUnavailable: 1 - resources: - limits: - cpu: 1 - memory: 1Gi - requests: - cpu: 1 - memory: 1Gi - nodeSelector: - dedicated: "loki-highcpu-s" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "loki-highcpu-s" - effect: "NoSchedule" - affinity: {} - -queryScheduler: - replicas: 1 - resources: - limits: - cpu: 1 - memory: 1Gi - requests: - cpu: 1 - memory: 1Gi - nodeSelector: - dedicated: "loki-highcpu-s" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "loki-highcpu-s" - effect: "NoSchedule" - affinity: {} - -querier: - replicas: 1 - maxUnavailable: 1 - resources: - limits: - cpu: 31 - memory: 30Gi - requests: - cpu: 30 - memory: 27Gi - nodeSelector: - dedicated: "loki-highcpu" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "loki-highcpu" - effect: "NoSchedule" - affinity: {} - -indexGateway: - replicas: 2 - maxUnavailable: 1 - persistence: - enabled: true - size: 10Gi - storageClass: "premium-rwo" - resources: - limits: - cpu: 1 - memory: 1Gi - requests: - cpu: 1 - memory: 1Gi - nodeSelector: - dedicated: "loki-highcpu-s" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "loki-highcpu-s" - effect: "NoSchedule" - affinity: {} - -compactor: - replicas: 1 - persistence: - enabled: true - claims: - - name: data - size: 10Gi - storageClass: "sc-pd-standard" - resources: - limits: - cpu: 3 - memory: 10Gi - requests: - cpu: 2 - memory: 8Gi - nodeSelector: - dedicated: "loki-highmem" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "loki-highmem" - effect: "NoSchedule" - -resultsCache: - replicas: 2 - allocatedMemory: 2048 - nodeSelector: - dedicated: "loki-highmem" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "loki-highmem" - effect: "NoSchedule" - -chunksCache: - replicas: 2 - allocatedMemory: 32768 - nodeSelector: - dedicated: "loki-highmem" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "loki-highmem" - effect: "NoSchedule" - -lokiCanary: - enabled: true - nodeSelector: - dedicated: "loki-highcpu-s" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "loki-highcpu-s" - effect: "NoSchedule" - -gateway: - enabled: true - replicas: 2 - nodeSelector: - dedicated: "loki-highcpu-s" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "loki-highcpu-s" - effect: "NoSchedule" - affinity: {} - -# unused components -ruler: - enabled: false -test: - enabled: false - -# Experimental - could be helpful in the future for faster queries -bloomPlanner: - replicas: 0 -bloomBuilder: - replicas: 0 -bloomGateway: - replicas: 0 - -# Zero out replica counts of other deployment modes -backend: - replicas: 0 -read: - replicas: 0 -write: - replicas: 0 -singleBinary: - replicas: 0 \ No newline at end of file diff --git a/helm-overrides/k8s-admin-prd-ase1/mimir-distributed/alertmanager_config.yaml b/helm-overrides/k8s-admin-prd-ase1/mimir-distributed/alertmanager_config.yaml deleted file mode 100644 index bc6fdce..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/mimir-distributed/alertmanager_config.yaml +++ /dev/null @@ -1,21 +0,0 @@ -route: - receiver: mimir-alerts - repeat_interval: 60m - group_by: ['alertname'] - -receivers: - - name: mimir-alerts - slack_configs: - - api_url: "https://hooks.slack.com/services/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" - channel: "#mimir-alerts" - send_resolved: true - title: '[{{ .Status | toUpper }} {{ .Alerts.Firing | len }}] {{ .GroupLabels.alertname }}' - text: | - {{ range .Alerts }} - *Alert:* {{ .Annotations.summary }} - `{{ .Labels.severity }}` - *Status:* `{{ .Status | toUpper }}` - *Details:* - {{ range .Labels.SortedPairs }} - • *{{ .Name }}:* `{{ .Value }}` - {{ end }} - {{ end }} \ No newline at end of file diff --git a/helm-overrides/k8s-admin-prd-ase1/mimir-distributed/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/mimir-distributed/custom-values.yaml deleted file mode 100644 index 00bc25b..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/mimir-distributed/custom-values.yaml +++ /dev/null @@ -1,406 +0,0 @@ -fullnameOverride: "mimir" - -image: - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/mimir - tag: 2.13.0 - -serviceAccount: - annotations: { - iam.gke.io/gcp-service-account: sa-infr-sre-obs-prd@meesho-admin-prd-0622.iam.gserviceaccount.com - } - -runtimeConfig: - overrides: - anonymous: - out_of_order_time_window: 10m - # ingester_limits: - # max_inflight_push_requests: 0 - -mimir: - multitenancy_enabled: false - - structuredConfig: - limits: - max_global_exemplars_per_user: 1000000000 # 0 - out_of_order_time_window: 2m # 0s - compactor_blocks_retention_period: 90d # 0s - max_global_series_per_user: 0 # 150000 - max_label_names_per_series: 100 # 30 - ingestion_rate: 100000000 # 10000 - ingestion_burst_size: 100000000 # 200000 - ruler_max_rules_per_rule_group: 0 # 20 - ruler_max_rule_groups_per_tenant: 0 # 70 - max_fetched_chunks_per_query: 0 # 2000000 - compactor_split_and_merge_shards: 36 # 0 - compactor_split_groups: 36 # 1 - - ingester: - # read_path_cpu_utilization_limit: 31.5 - # read_path_memory_utilization_limit: 131941395200 - ring: - replication_factor: 3 # 3 - instance_limits: - max_inflight_push_requests: 0 # 2000 - - compactor: - meta_sync_concurrency: 200 # 4 - block_sync_concurrency: 50 # 1 - max_compaction_time: 12h - - common: - storage: - backend: gcs - - server: - log_level: "info" - - blocks_storage: - backend: gcs - gcs: - bucket_name: "mimir_data" - storage_prefix: "blocks" - - alertmanager_storage: - backend: gcs - gcs: - bucket_name: "mimir_data" - storage_prefix: "alertmanager" - - ruler_storage: - backend: gcs - gcs: - bucket_name: "mimir_data" - storage_prefix: "ruler" - -distributor: - replicas: 1 - resources: - limits: - cpu: 62 - memory: 60Gi - requests: - cpu: 60 - memory: 54Gi - nodeSelector: - dedicated: "mimir-highcpu" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "mimir-highcpu" - effect: "NoSchedule" - -ingester: - replicas: 6 - persistentVolume: - enabled: true - size: 250Gi - storageClass: "premium-rwo" - resources: - limits: - cpu: 47 - memory: 180Gi - requests: - cpu: 45 - memory: 175Gi - nodeSelector: - dedicated: "mimir-standard" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "mimir-standard" - effect: "NoSchedule" - affinity: - podAntiAffinity: - requiredDuringSchedulingIgnoredDuringExecution: - - labelSelector: - matchExpressions: - - key: app.kubernetes.io/component - operator: In - values: - - ingester - topologyKey: 'kubernetes.io/hostname' - zoneAwareReplication: - enabled: false - - -query_frontend: - replicas: 2 - resources: - limits: - cpu: 1 - memory: 1Gi - requests: - cpu: 1 - memory: 1Gi - nodeSelector: - dedicated: "mimir-highcpu-s" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "mimir-highcpu-s" - effect: "NoSchedule" - -query_scheduler: - enabled: true - replicas: 2 - resources: - limits: - cpu: 1 - memory: 1Gi - requests: - cpu: 1 - memory: 1Gi - nodeSelector: - dedicated: "mimir-highcpu-s" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "mimir-highcpu-s" - effect: "NoSchedule" - -querier: - replicas: 2 - resources: - limits: - cpu: 31 - memory: 30Gi - requests: - cpu: 30 - memory: 27Gi - nodeSelector: - dedicated: "mimir-highcpu" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "mimir-highcpu" - effect: "NoSchedule" - -store_gateway: - replicas: 6 - persistentVolume: - enabled: true - size: 500Gi - storageClass: "premium-rwo" - resources: - limits: - cpu: 20 - memory: 20Gi - requests: - cpu: 20 - memory: 18Gi - nodeSelector: - dedicated: "mimir-highcpu" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "mimir-highcpu" - effect: "NoSchedule" - affinity: {} - # podAntiAffinity: - # requiredDuringSchedulingIgnoredDuringExecution: - # - labelSelector: - # matchExpressions: - # - key: app.kubernetes.io/component - # operator: In - # values: - # - store-gateway - # topologyKey: 'kubernetes.io/hostname' - zoneAwareReplication: - enabled: false - -compactor: - replicas: 16 - persistentVolume: - enabled: true - size: 100Gi - storageClass: "premium-rwo" - resources: - limits: - cpu: 3 - memory: 10Gi - requests: - cpu: 2 - memory: 8Gi - nodeSelector: - dedicated: "mimir-highmem" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "mimir-highmem" - effect: "NoSchedule" - -chunks-cache: - enabled: true - replicas: 2 - allocatedMemory: 32768 - nodeSelector: - dedicated: "mimir-highmem" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "mimir-highmem" - effect: "NoSchedule" - -index-cache: - enabled: true - replicas: 2 - allocatedMemory: 8192 - nodeSelector: - dedicated: "mimir-highmem" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "mimir-highmem" - effect: "NoSchedule" - -metadata-cache: - enabled: true - replicas: 2 - allocatedMemory: 2048 - nodeSelector: - dedicated: "mimir-highmem" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "mimir-highmem" - effect: "NoSchedule" - -results-cache: - enabled: true - replicas: 2 - allocatedMemory: 2048 - nodeSelector: - dedicated: "mimir-highmem" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "mimir-highmem" - effect: "NoSchedule" - -ruler: - enabled: true - replicas: 1 - resources: - limits: - cpu: 11 - memory: 12Gi - requests: - cpu: 10 - memory: 10Gi - nodeSelector: - dedicated: "mimir-highcpu-s" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "mimir-highcpu-s" - effect: "NoSchedule" - remoteEvaluationDedicatedQueryPath: true - -ruler_query_frontend: - replicas: 2 - resources: - limits: - cpu: 1 - memory: 1Gi - requests: - cpu: 1 - memory: 1Gi - nodeSelector: - dedicated: "mimir-highcpu-s" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "mimir-highcpu-s" - effect: "NoSchedule" - -ruler_query_scheduler: - replicas: 2 - resources: - limits: - cpu: 1 - memory: 1Gi - requests: - cpu: 1 - memory: 1Gi - nodeSelector: - dedicated: "mimir-highcpu-s" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "mimir-highcpu-s" - effect: "NoSchedule" - -ruler_querier: - replicas: 1 - resources: - limits: - cpu: 31 - memory: 30Gi - requests: - cpu: 30 - memory: 27Gi - nodeSelector: - dedicated: "mimir-highcpu" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "mimir-highcpu" - effect: "NoSchedule" - -alertmanager: - replicas: 2 - persistentVolume: - enabled: false - resources: - limits: - cpu: 1 - memory: 1Gi - requests: - cpu: 1 - memory: 1Gi - nodeSelector: - dedicated: "mimir-highcpu-s" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "mimir-highcpu-s" - effect: "NoSchedule" - -overrides_exporter: - replicas: 1 - resources: - limits: - cpu: 200m - memory: 128Mi - requests: - cpu: 100m - memory: 128Mi - nodeSelector: - dedicated: "mimir-highcpu-s" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "mimir-highcpu-s" - effect: "NoSchedule" - -ingress: - enabled: true - ingressClassName: nginx-internal - hosts: - - mimir.meeshogcp.in - -nginx: - enabled: true - replicas: 2 - nodeSelector: - dedicated: "mimir-highcpu-s" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "mimir-highcpu-s" - effect: "NoSchedule" - -rollout_operator: - enabled: false -minio: - enabled: false \ No newline at end of file diff --git a/helm-overrides/k8s-admin-prd-ase1/node-exporter/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/node-exporter/custom-values.yaml deleted file mode 100644 index 317966a..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/node-exporter/custom-values.yaml +++ /dev/null @@ -1,16 +0,0 @@ -prometheus-node-exporter: - # Same resource trim this ran with as a subchart of the (now removed) - # prometheus server chart. One DaemonSet pod, hostNetwork, light enough - # that this is the whole footprint regardless of which TSDB scrapes it. - resources: - requests: - cpu: 20m - memory: 32Mi - limits: - memory: 64Mi - - # rbac.pspEnabled defaults false already (no PodSecurityPolicy on this - # cluster) — nothing to override here. The chart's own Service carries - # `prometheus.io/scrape: true` by default, which is what vmagent's - # already-enabled kubernetes-service-endpoints job picks up — no - # separate scrape config needed on either side. diff --git a/helm-overrides/k8s-admin-prd-ase1/opentelemetry-collector/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/opentelemetry-collector/custom-values.yaml deleted file mode 100644 index f13b2a5..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/opentelemetry-collector/custom-values.yaml +++ /dev/null @@ -1,659 +0,0 @@ -# Default values for opentelemetry-collector. -# This is a YAML-formatted file. -# Declare variables to be passed into your templates. - -nameOverride: "" -fullnameOverride: "opentelemetry-admin-prd" - -dedicatedValue: false -schedulerName: default-scheduler - -labels: - bu: "infra" - team: "sre" - service: "opentelemetry-admin-prd" - env: "prd" - priority: "p0" - type: "opentelemetry" - arch: "any" - runpod: "ondemand" - -externalSecret: - enabled: true - key: prd/admin/coralogix-keys - secretStoreRef: - name: vault-backend - -# Valid values are "daemonset", "deployment", and "statefulset". -mode: "deployment" - -# Specify which namespace should be used to deploy the resources into -namespaceOverride: "" - -# Handles basic configuration of components that -# also require k8s modifications to work correctly. -# .Values.config can be used to modify/add to a preset -# component configuration, but CANNOT be used to remove -# preset configuration. If you require removal of any -# sections of a preset configuration, you cannot use -# the preset. Instead, configure the component manually in -# .Values.config and use the other fields supplied in the -# values.yaml to configure k8s as necessary. -presets: - # Configures the collector to collect logs. - # Adds the filelog receiver to the logs pipeline - # and adds the necessary volumes and volume mounts. - # Best used with mode = daemonset. - # See https://opentelemetry.io/docs/kubernetes/collector/components/#filelog-receiver for details on the receiver. - logsCollection: - enabled: false - includeCollectorLogs: false - # Enabling this writes checkpoints in /var/lib/otelcol/ host directory. - # Note this changes collector's user to root, so that it can write to host directory. - storeCheckpoints: false - # The maximum bytes size of the recombined field. - # Once the size exceeds the limit, all received entries of the source will be combined and flushed. - maxRecombineLogSize: 102400 - # Configures the collector to collect host metrics. - # Adds the hostmetrics receiver to the metrics pipeline - # and adds the necessary volumes and volume mounts. - # Best used with mode = daemonset. - # See https://opentelemetry.io/docs/kubernetes/collector/components/#host-metrics-receiver for details on the receiver. - hostMetrics: - enabled: false - # Configures the Kubernetes Processor to add Kubernetes metadata. - # Adds the k8sattributes processor to all the pipelines - # and adds the necessary rules to ClusteRole. - # Best used with mode = daemonset. - # See https://opentelemetry.io/docs/kubernetes/collector/components/#kubernetes-attributes-processor for details on the receiver. - kubernetesAttributes: - enabled: false - # When enabled the processor will extra all labels for an associated pod and add them as resource attributes. - # The label's exact name will be the key. - extractAllPodLabels: false - # When enabled the processor will extra all annotations for an associated pod and add them as resource attributes. - # The annotation's exact name will be the key. - extractAllPodAnnotations: false - # Configures the collector to collect node, pod, and container metrics from the API server on a kubelet.. - # Adds the kubeletstats receiver to the metrics pipeline - # and adds the necessary rules to ClusteRole. - # Best used with mode = daemonset. - # See https://opentelemetry.io/docs/kubernetes/collector/components/#kubeletstats-receiver for details on the receiver. - kubeletMetrics: - enabled: false - # Configures the collector to collect kubernetes events. - # Adds the k8sobject receiver to the logs pipeline - # and collects kubernetes events by default. - # Best used with mode = deployment or statefulset. - # See https://opentelemetry.io/docs/kubernetes/collector/components/#kubernetes-objects-receiver for details on the receiver. - kubernetesEvents: - enabled: false - # Configures the Kubernetes Cluster Receiver to collect cluster-level metrics. - # Adds the k8s_cluster receiver to the metrics pipeline - # and adds the necessary rules to ClusteRole. - # Best used with mode = deployment or statefulset. - # See https://opentelemetry.io/docs/kubernetes/collector/components/#kubernetes-cluster-receiver for details on the receiver. - clusterMetrics: - enabled: false - -configMap: - # Specifies whether a configMap should be created (true by default) - create: true - -# Base collector configuration. -# Supports templating. To escape existing instances of {{ }}, use {{` `}}. -# For example, {{ REDACTED_EMAIL }} becomes {{` {{ REDACTED_EMAIL }} `}}. -config: - receivers: - otlp: - protocols: - grpc: - endpoint: ${env:MY_POD_IP}:4317 - max_recv_msg_size_mib: 7 - http: - endpoint: ${env:MY_POD_IP}:4318 - processors: - batch: - send_batch_size: 1024 - timeout: 5s - # If set to null, will be overridden with values based on k8s resource limits - memory_limiter: null - attributes/shipper: - actions: - - key: shipper - action: insert - value: '${MY_POD_IP}' - - key: cloud - action: insert - value: 'gcp' - tail_sampling: - decision_wait: 30s - num_traces: 300000 - expected_new_traces_per_sec: 100000 - policies: - [ - { - name: errors-policy, - type: status_code, - status_code: {status_codes: [ERROR]} - }, - { - name: probablistic-policy, - type: probabilistic, - probabilistic: {sampling_percentage: 1} - } - ] - # filter/include: - # spans: - # include: - # match_type: regexp - # services: - # - order-service - exporters: - logging: {} - coralogix: - domain: "coralogixsg.com" - private_key: "${CORALOGIX_PRIVATE_KEY}" - application_name: "default" - subsystem_name: "nodes" - application_name_attributes: - - "applicationName" - - "service.namespace" - - "k8s.namespace.name" - subsystem_name_attributes: - - "service.name" - - "k8s.deployment.name" - - "k8s.statefulset.name" - - "k8s.daemonset.name" - - "k8s.cronjob.name" - - "k8s.job.name" - - "k8s.container.name" - timeout: 30s - otlp/elastic: - endpoint: "946ece6f7b344005aa1e5c273b1a886f.apm.psc.asia-southeast1.gcp.elastic-cloud.com:443" - headers: - Authorization: "Bearer ehllv9fQQ7GGMOjE79" - timeout: 10s - extensions: - # The health_check extension is mandatory for this chart. - # Without the health_check extension the collector will fail the readiness and liveliness probes. - # The health_check extension can be modified, but should never be removed. - health_check: {} -# memory_ballast: {} - - connectors: - spanmetrics: - histogram: - explicit: - buckets: [100us, 1ms, 2ms, 6ms, 10ms, 100ms, 250ms] - dimensions_cache_size: 1000 - aggregation_temporality: "AGGREGATION_TEMPORALITY_CUMULATIVE" - metrics_flush_interval: 15s - - service: - telemetry: - metrics: - address: ${env:MY_POD_IP}:8888 - extensions: - - health_check -# - memory_ballast - pipelines: - # traces: - # receivers: - # - otlp - # processors: - # - tail_sampling - # - attributes/shipper - # - batch - # exporters: - # - coralogix -# - spanmetrics - traces: - receivers: - - otlp - processors: - - tail_sampling - - attributes/shipper -# - filter/include - - batch - exporters: - - otlp/elastic - # - spanmetrics - metrics: null - logs: null - -image: - # If you want to use the core image `otel/opentelemetry-collector`, you also need to change `command.name` value to `otelcol`. - #repository: 847438129436.dkr.ecr.ap-southeast-1.amazonaws.com/otel/opentelemetry-collector-contrib - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/opentelemetry-collector-contrib - # repository: otel/opentelemetry-collector-contrib - pullPolicy: IfNotPresent - # Overrides the image tag whose default is the chart appVersion. - tag: "0.87.0" - # When digest is set to a non-empty value, images will be pulled by digest (regardless of tag value). - digest: "" -imagePullSecrets: [] - -# OpenTelemetry Collector executable -command: - name: otelcol-contrib - extraArgs: [] - -serviceAccount: - # Specifies whether a service account should be created - create: true - # Annotations to add to the service account - annotations: {} - # The name of the service account to use. - # If not set and create is true, a name is generated using the fullname template - name: "" - -clusterRole: - # Specifies whether a clusterRole should be created - # Some presets also trigger the creation of a cluster role and cluster role binding. - # If using one of those presets, this field is no-op. - create: false - # Annotations to add to the clusterRole - # Can be used in combination with presets that create a cluster role. - annotations: {} - # The name of the clusterRole to use. - # If not set a name is generated using the fullname template - # Can be used in combination with presets that create a cluster role. - name: "" - # A set of rules as documented here : https://kubernetes.io/docs/reference/access-authn-authz/rbac/ - # Can be used in combination with presets that create a cluster role to add additional rules. - rules: [] - # - apiGroups: - # - '' - # resources: - # - 'pods' - # - 'nodes' - # verbs: - # - 'get' - # - 'list' - # - 'watch' - - clusterRoleBinding: - # Annotations to add to the clusterRoleBinding - # Can be used in combination with presets that create a cluster role binding. - annotations: {} - # The name of the clusterRoleBinding to use. - # If not set a name is generated using the fullname template - # Can be used in combination with presets that create a cluster role binding. - name: "" - -podSecurityContext: {} -securityContext: {} - -# nodeSelector: [] -# tolerations: {} - -nodeSelector: - dedicated: "opentelemetry" - -tolerations: - - key: "dedicated" - operator: "Equal" - value: "opentelemetry" - effect: "NoSchedule" - -affinity: {} -topologySpreadConstraints: [] - -# Allows for pod scheduler prioritisation -priorityClassName: "" - -#extraEnvs: [] - -extraEnvs: -- name: OTEL_RESOURCE_ATTRIBUTES - value: "k8s.node.name=$(K8S_NODE_NAME)" -- name: KUBE_NODE_NAME - valueFrom: - fieldRef: - apiVersion: v1 - fieldPath: spec.nodeName - -extraEnvsFrom: [] -extraVolumes: [] -extraVolumeMounts: [] - -# Configuration for ports -# nodePort is also allowed -ports: - otlp: - enabled: true - containerPort: 4317 - servicePort: 4317 - # hostPort: 4317 - protocol: TCP - # nodePort: 30317 - appProtocol: grpc - otlp-http: - enabled: true - containerPort: 4318 - servicePort: 4318 - # hostPort: 4318 - protocol: TCP - jaeger-compact: - enabled: false - containerPort: 6831 - servicePort: 6831 - # hostPort: 6831 - protocol: UDP - jaeger-thrift: - enabled: false - containerPort: 14268 - servicePort: 14268 - # hostPort: 14268 - protocol: TCP - jaeger-grpc: - enabled: false - containerPort: 14250 - servicePort: 14250 - # hostPort: 14250 - protocol: TCP - zipkin: - enabled: false - containerPort: 9411 - servicePort: 9411 - # hostPort: 9411 - protocol: TCP - metrics: - # The metrics port is disabled by default. However you need to enable the port - # in order to use the ServiceMonitor (serviceMonitor.enabled) or PodMonitor (podMonitor.enabled). - enabled: false - containerPort: 8888 - servicePort: 8888 - protocol: TCP - -# Resource limits & requests. Update according to your own use case as these values might be too low for a typical deployment. -#resources: {} -resources: - requests: - cpu: 25 - memory: 25Gi - limits: - cpu: 30 - memory: 30Gi - -# Annotations to be added to pod -podAnnotations: - otel.io/path: /metrics - otel.io/port: '8888' - otel.io/scrape: 'true' - -podLabels: {} - -# Host networking requested for this pod. Use the host's network namespace. -hostNetwork: false - -# Pod DNS policy ClusterFirst, ClusterFirstWithHostNet, None, Default, None -dnsPolicy: "ClusterFirstWithHostNet" - -# Custom DNS config. Required when DNS policy is None. -dnsConfig: {} - -# only used with deployment mode -replicaCount: 1 - -# only used with deployment mode -revisionHistoryLimit: 100 - -annotations: {} - # prometheus.io/path: "/metrics" - # prometheus.io/scrape: "true" - # prometheus.io/port: "8888" - -# List of extra sidecars to add -extraContainers: [] -# extraContainers: -# - name: test -# command: -# - cp -# args: -# - /bin/sleep -# - /test/sleep -# image: busybox:latest -# volumeMounts: -# - name: test -# mountPath: /test - -# List of init container specs, e.g. for copying a binary to be executed as a lifecycle hook. -# Another usage of init containers is e.g. initializing filesystem permissions to the OTLP Collector user `10001` in case you are using persistence and the volume is producing a permission denied error for the OTLP Collector container. -initContainers: [] -# initContainers: -# - name: test -# image: busybox:latest -# command: -# - cp -# args: -# - /bin/sleep -# - /test/sleep -# volumeMounts: -# - name: test -# mountPath: /test -# - name: init-fs -# image: busybox:latest -# command: -# - sh -# - '-c' -# - 'chown -R 10001: /var/lib/storage/otc' # use the path given as per `extensions.file_storage.directory` & `extraVolumeMounts[x].mountPath` -# volumeMounts: -# - name: opentelemetry-collector-data # use the name of the volume used for persistence -# mountPath: /var/lib/storage/otc # use the path given as per `extensions.file_storage.directory` & `extraVolumeMounts[x].mountPath` - -# Pod lifecycle policies. -lifecycleHooks: {} -# lifecycleHooks: -# preStop: -# exec: -# command: -# - /test/sleep -# - "5" - -# liveness probe configuration -# Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/ -## -livenessProbe: - # Number of seconds after the container has started before startup, liveness or readiness probes are initiated. - # initialDelaySeconds: 1 - # How often in seconds to perform the probe. - # periodSeconds: 10 - # Number of seconds after which the probe times out. - # timeoutSeconds: 1 - # Minimum consecutive failures for the probe to be considered failed after having succeeded. - # failureThreshold: 1 - # Duration in seconds the pod needs to terminate gracefully upon probe failure. - # terminationGracePeriodSeconds: 10 - httpGet: - port: 13133 - path: / - -# readiness probe configuration -# Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/ -## -readinessProbe: - # Number of seconds after the container has started before startup, liveness or readiness probes are initiated. - # initialDelaySeconds: 1 - # How often (in seconds) to perform the probe. - # periodSeconds: 10 - # Number of seconds after which the probe times out. - # timeoutSeconds: 1 - # Minimum consecutive successes for the probe to be considered successful after having failed. - # successThreshold: 1 - # Minimum consecutive failures for the probe to be considered failed after having succeeded. - # failureThreshold: 1 - httpGet: - port: 13133 - path: / - -service: - # Enable the creation of a Service. - # By default, it's enabled on mode != daemonset. - # However, to enable it on mode = daemonset, its creation must be explicitly enabled - # enabled: true - - type: ClusterIP - # type: LoadBalancer - # loadBalancerIP: 1.2.3.4 - # loadBalancerSourceRanges: [] - - # By default, Service of type 'LoadBalancer' will be created setting 'externalTrafficPolicy: Cluster' - # unless other value is explicitly set. - # Possible values are Cluster or Local (https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip) - # externalTrafficPolicy: Cluster - - annotations: - io.cilium/global-service: "true" - - # By default, Service will be created setting 'internalTrafficPolicy: Local' on mode = daemonset - # unless other value is explicitly set. - # Setting 'internalTrafficPolicy: Cluster' on a daemonset is not recommended - # internalTrafficPolicy: Cluster - -ingress: - enabled: false - # annotations: {} - # ingressClassName: nginx - # hosts: - # - host: collector.example.com - # paths: - # - path: / - # pathType: Prefix - # port: 4318 - # tls: - # - secretName: collector-tls - # hosts: - # - collector.example.com - - # Additional ingresses - only created if ingress.enabled is true - # Useful for when differently annotated ingress services are required - # Each additional ingress needs key "name" set to something unique - additionalIngresses: [] - # - name: cloudwatch - # ingressClassName: nginx - # annotations: {} - # hosts: - # - host: collector.example.com - # paths: - # - path: / - # pathType: Prefix - # port: 4318 - # tls: - # - secretName: collector-tls - # hosts: - # - collector.example.com - -podMonitor: - # The pod monitor by default scrapes the metrics port. - # The metrics port needs to be enabled as well. - enabled: false - metricsEndpoints: - - port: metrics - # interval: 15s - - # additional labels for the PodMonitor - extraLabels: {} - # release: kube-prometheus-stack - -serviceMonitor: - # The service monitor by default scrapes the metrics port. - # The metrics port needs to be enabled as well. - enabled: false - metricsEndpoints: - - port: metrics - # interval: 15s - - # additional labels for the ServiceMonitor - extraLabels: {} - # release: kube-prometheus-stack - -# PodDisruptionBudget is used only if deployment enabled -podDisruptionBudget: - enabled: false -# minAvailable: 2 - maxUnavailable: 1 - -# autoscaling is used only if deployment enabled -autoscaling: - enabled: true - minReplicas: 5 - maxReplicas: 300 - behavior: {} - targetCPUUtilizationPercentage: 80 - targetMemoryUtilizationPercentage: 80 - -rollout: - # When 'mode: daemonset', maxSurge cannot be used when hostPort is set for any of the ports - rollingUpdate: - # maxSurge: 10% - maxUnavailable: 5 - strategy: RollingUpdate - -prometheusRule: - enabled: false - groups: [] - # Create default rules for monitoring the collector - defaultRules: - enabled: false - - # additional labels for the PrometheusRule - extraLabels: {} - -statefulset: - # volumeClaimTemplates for a statefulset - volumeClaimTemplates: [] - podManagementPolicy: "Parallel" - -networkPolicy: - enabled: false - - # Annotations to add to the NetworkPolicy - annotations: {} - - # Configure the 'from' clause of the NetworkPolicy. - # By default this will restrict traffic to ports enabled for the Collector. If - # you wish to further restrict traffic to other hosts or specific namespaces, - # see the standard NetworkPolicy 'spec.ingress.from' definition for more info: - # https://kubernetes.io/docs/reference/kubernetes-api/policy-resources/network-policy-v1/ - allowIngressFrom: [] - # # Allow traffic from any pod in any namespace, but not external hosts - # - namespaceSelector: {} - # # Allow external access from a specific cidr block - # - ipBlock: - # cidr: 192.168.1.64/32 - # # Allow access from pods in specific namespaces - # - namespaceSelector: - # matchExpressions: - # - key: kubernetes.io/metadata.name - # operator: In - # values: - # - "cats" - # - "dogs" - - # Add additional ingress rules to specific ports - # Useful to allow external hosts/services to access specific ports - # An example is allowing an external prometheus server to scrape metrics - # - # See the standard NetworkPolicy 'spec.ingress' definition for more info: - # https://kubernetes.io/docs/reference/kubernetes-api/policy-resources/network-policy-v1/ - extraIngressRules: [] - # - ports: - # - port: metrics - # protocol: TCP - # from: - # - ipBlock: - # cidr: 192.168.1.64/32 - - # Restrict egress traffic from the OpenTelemetry collector pod - # See the standard NetworkPolicy 'spec.egress' definition for more info: - # https://kubernetes.io/docs/reference/kubernetes-api/policy-resources/network-policy-v1/ - egressRules: [] - # - to: - # - namespaceSelector: {} - # - ipBlock: - # cidr: 192.168.10.10/24 - # ports: - # - port: 1234 - # protocol: TCP \ No newline at end of file diff --git a/helm-overrides/k8s-admin-prd-ase1/opentelemetry-deployment/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/opentelemetry-deployment/custom-values.yaml deleted file mode 100644 index 7fee208..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/opentelemetry-deployment/custom-values.yaml +++ /dev/null @@ -1,111 +0,0 @@ -config: - - receivers: - otlp: - protocols: - grpc: - endpoint: ${env:MY_POD_IP}:4317 - max_recv_msg_size_mib: 50 - - processors: - batch: - send_batch_size: 256 - timeout: 200ms - send_batch_max_size: 512 - filter/drop-noisy-services: - error_mode: ignore - traces: - span: - - IsMatch(resource.attributes["service.name"], ".*consumer.*|.*scheduler.*|.*cron.*|.*worker.*|.*inhouse-ingestion.*|.*.messaging-api-internal*|.*cis.*") - tail_sampling: - decision_wait: 10s # avg latency across services - num_traces: 25000000 # expected_new_traces_per_sec * decision_wait + some buffer - expected_new_traces_per_sec: 1500000 # combined span rate across all business units - decision_cache: - sampled_cache_size: 6000000 # sampling rate * num_traces + some buffer - policies: - [ - { - name: errors-policy, - type: status_code, - status_code: {status_codes: [ERROR]} - }, - # { - # name: latency-policy, - # type: latency, - # latency: {threshold_ms: 1000} - # }, - { - name: probablistic-policy, - type: probabilistic, - probabilistic: {sampling_percentage: 1} - } - ] - - exporters: - otlp/elastic: - endpoint: "946ece6f7b344005aa1e5c273b1a886f.apm.psc.asia-southeast1.gcp.elastic-cloud.com:443" - timeout: 15s - sending_queue: - num_consumers: 50 - queue_size: 10000 - headers: - Authorization: "Bearer ehllv9fQQ7GGMOjE79" - - service: - telemetry: - metrics: - level: detailed - readers: - - pull: - exporter: - prometheus: - host: '0.0.0.0' - port: 8888 - extensions: - - health_check - pipelines: - traces: - receivers: [otlp] - processors: [filter/drop-noisy-services, tail_sampling, batch] - exporters: [otlp/elastic] - metrics: null - logs: null - -fullnameOverride: "opentelemetry-admin-prd" - -mode: "deployment" - -podAnnotations: - otel.io/path: '/metrics' - otel.io/port: '8888' - otel.io/scrape: 'true' - -image: - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/opentelemetry-collector-contrib - pullPolicy: IfNotPresent - tag: "0.114.0" - -nodeSelector: - dedicated: "opentelemetry-std" - -tolerations: - - key: "dedicated" - operator: "Equal" - value: "opentelemetry-std" - effect: "NoSchedule" - -resources: - requests: - cpu: '45' - memory: 175Gi - limits: - cpu: '45' - memory: 175Gi - -autoscaling: - enabled: true - minReplicas: 15 - maxReplicas: 50 - targetCPUUtilizationPercentage: 75 - targetMemoryUtilizationPercentage: 75 \ No newline at end of file diff --git a/helm-overrides/k8s-admin-prd-ase1/paused-container/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/paused-container/custom-values.yaml deleted file mode 100644 index eb75dfc..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/paused-container/custom-values.yaml +++ /dev/null @@ -1,73 +0,0 @@ -# Default values for hello-world. -# This is a YAML-formatted file. -# Declare variables to be passed into your templates. - -deployments: - - nodepool: vminsert - bu: infra - cpuRequest: 1 - memoryRequest: 1Gi - replicaCount: 3 - -priorityClass: - name: "ultralow-priority" - -image: - repository: nginx - tag: "1.14.2" - pullPolicy: IfNotPresent - # Overrides the image tag whose default is the chart appVersion. - -nameOverride: "" -fullnameOverride: "paused-container-infra-prd" - -extraLabels: - team: "devops" - bu: "infra" - env: "prd" - service: "paused-container-infra-prd" - priority: "p3" - type: "tools" - -topologySpreadConstraints: [] - # - labelSelector: - # matchLabels: - # dedicated: vminsert - # maxSkew: 1 - # topologyKey: topology.kubernetes.io/hostname - # whenUnsatisfiable: DoNotSchedule - -affinity: - podAffinity: - requiredDuringSchedulingIgnoredDuringExecution: - - labelSelector: - matchExpressions: - - key: run - operator: In - values: - - paused-container-infra-prd - topologyKey: topology.kubernetes.io/zone - podAntiAffinity: - requiredDuringSchedulingIgnoredDuringExecution: - - labelSelector: - matchExpressions: - - key: run - operator: In - values: - - paused-container-infra-prd - topologyKey: kubernetes.io/hostname - namespaceSelector: {} - - -serviceAccount: - # Specifies whether a service account should be created - create: true - # Annotations to add to the service account - annotations: {} - # The name of the service account to use. - # If not set and create is true, a name is generated using the fullname template - name: "" - -service: - type: ClusterIP - port: 80 diff --git a/helm-overrides/k8s-admin-prd-ase1/pmm-mongo/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/pmm-mongo/custom-values.yaml deleted file mode 100644 index df46cca..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/pmm-mongo/custom-values.yaml +++ /dev/null @@ -1,279 +0,0 @@ -## @section Percona Monitoring and Management (PMM) parameters -## Default values for PMM. -## This is a YAML-formatted file. -## Declare variables to be passed into your templates. - -## PMM image version -## ref: https://hub.docker.com/r/percona/pmm-server/tags -## @param image.repository PMM image repository -## @param image.pullPolicy PMM image pull policy -## @param image.tag PMM image tag (immutable tags are recommended) -## @param image.imagePullSecrets Global Docker registry secret names as an array -## -image: - repository: percona/pmm-server - pullPolicy: IfNotPresent - # Overrides the image tag whose default is the chart appVersion. - tag: "2.41.0" - imagePullSecrets: [] - -## PMM environment variables -## ref: https://docs.percona.com/percona-monitoring-and-management/setting-up/server/docker.html#environment-variables -## -pmmEnv: - ## @param pmmEnv.DISABLE_UPDATES Disables a periodic check for new PMM versions as well as ability to apply upgrades using the UI (need to be disabled in k8s environment as updates rolled with helm/container update) - ## - DISABLE_UPDATES: "1" -# optional variables to integrate Grafana with internal iDP, see also secret part -# GF_AUTH_GENERIC_OAUTH_ENABLED: 'true' -# GF_AUTH_GENERIC_OAUTH_SCOPES: '' -# GF_AUTH_GENERIC_OAUTH_AUTH_URL: '' -# GF_AUTH_GENERIC_OAUTH_TOKEN_URL: '' -# GF_AUTH_GENERIC_OAUTH_API_URL: '' -# GF_AUTH_GENERIC_OAUTH_ALLOWED_DOMAINS: '' - -## @param pmmResources optional [Resources](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) requested for [PMM container](https://docs.percona.com/percona-monitoring-and-management/setting-up/server/index.html#set-up-pmm-server) - # pmmResources: - # requests: - # memory: "32Gi" - # cpu: "8" - # limits: - # memory: "64Gi" - # cpu: "32" -pmmResources: - requests: - memory: "14Gi" - cpu: "4" - limits: - memory: "16Gi" - cpu: "6" - -## Readiness probe Config -## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#configure-probes -## @param readyProbeConf.initialDelaySeconds Number of seconds after the container has started before readiness probes is initiated -## @param readyProbeConf.periodSeconds How often (in seconds) to perform the probe -## @param readyProbeConf.failureThreshold When a probe fails, Kubernetes will try failureThreshold times before giving up -## -readyProbeConf: - initialDelaySeconds: 1 - periodSeconds: 5 - failureThreshold: 6 - -## @section PMM secrets -## -secret: - ## @param secret.name Defines the name of the k8s secret that holds passwords and other secrets - ## - name: pmm-secret - ## @param secret.create If true then secret will be generated by Helm chart. Otherwise it is expected to be created by user. - ## - create: false - ## @param secret.pmm_password Initial PMM password - it changes only on the first deployment, ignored if PMM was already provisioned and just restarted. If PMM admin password is not set, it will be generated. - ## E.g. - ## pmm_password: admin - ## - ## To get password execute `kubectl get secret pmm-secret -o jsonpath='{.data.PMM_ADMIN_PASSWORD}' | base64 --decode` - ## - pmm_password: "" - ## - # GF_AUTH_GENERIC_OAUTH_CLIENT_ID optional client ID to integrate Grafana with internal iDP, requires other env defined as well under pmmEnv - # GF_AUTH_GENERIC_OAUTH_CLIENT_ID: - # GF_AUTH_GENERIC_OAUTH_CLIENT_SECRET optional secret to integrate Grafana with internal iDP, requires other env defined as well under pmmEnv - # GF_AUTH_GENERIC_OAUTH_CLIENT_SECRET: - -## @param certs Optional certificates, if not provided PMM would use generated self-signed certificates, -## please provide your own signed ssl certificates like this in base 64 format: -## certs: - ## name: pmm-certs - ## files: - ## certificate.crt: - ## certificate.key: - ## ca-certs.pem: - ## dhparam.pem: - ## certificate.conf: -certs: {} - -## @section PMM network configuration -## Service configuration -## -service: - ## @param service.name Service name that is dns name monitoring services would send data to. `monitoring-service` used by default by pmm-client in Percona operators. - ## - name: monitoring-service - ## @param service.type Kubernetes Service type - ## - type: ClusterIP - - ## Ports 443 and/or 80 - ## - ports: - ## @param service.ports[0].port https port number - - port: 443 - ## @param service.ports[0].targetPort target port to map for statefulset and ingress - targetPort: https - ## @param service.ports[0].protocol protocol for https - protocol: TCP - ## @param service.ports[0].name port name - name: https - ## @param service.ports[1].port http port number - - port: 80 - ## @param service.ports[1].targetPort target port to map for statefulset and ingress - targetPort: http - ## @param service.ports[1].protocol protocol for http - protocol: TCP - ## @param service.ports[1].name port name - name: http - -## Ingress controller configuration -## -ingress: - ## @param ingress.enabled -- Enable ingress controller resource - enabled: true - ## @param ingress.nginxInc -- Using ingress controller from NGINX Inc - nginxInc: false - ## @param ingress.annotations -- Ingress annotations configuration - annotations: {} - ## kubernetes.io/ingress.class: nginx - ## kubernetes.io/tls-acme: "true" - ### nginx proxy to https - ## nginx.ingress.kubernetes.io/backend-protocol: "HTTPS" - ## @param ingress.community.annotations -- Ingress annotations configuration for community managed ingress (nginxInc = false) - community: - annotations: {} - ## kubernetes.io/ingress.class: nginx - ## kubernetes.io/tls-acme: "true" - ## @param ingress.ingressClassName -- Sets the ingress controller class name to use. - ingressClassName: "nginx-internal" - - ## Ingress resource hostnames and path mappings - hosts: - ## @param ingress.hosts[0].host hostname - - host: pmmmongo-admin-prd.meeshogcp.in - ## @param ingress.hosts[0].paths path mapping - paths: [/] - - ## @param ingress.pathType -- How ingress paths should be treated. - pathType: Prefix - - ## @param ingress.tls -- Ingress TLS configuration - tls: [] - ## - secretName: chart-example-tls - ## hosts: - ## - chart-example.local - -## @section PMM storage configuration -## Claiming storage for PMM using Persistent Volume Claims (PVC) -## ref: https://kubernetes.io/docs/user-guide/persistent-volumes/ -## -storage: - ## @param storage.name name of PVC - name: pmmmongo-storage - ## @param storage.storageClassName optional PMM data Persistent Volume Storage Class - ## If defined, storageClassName: - ## If set to "-", storageClassName: "", which disables dynamic provisioning - ## If undefined (the default) or set to null, no storageClassName spec is - ## set, choosing the default provisioner. (gp2 on AWS, standard on - ## GKE, AWS & OpenStack) - ## - storageClassName: "pd-balanced" - ## - ## @param storage.size size of storage [depends](https://docs.percona.com/percona-monitoring-and-management/setting-up/server/index.html#set-up-pmm-server) on number of monitored services and data retention - ## - size: 300Gi - ## - ## @param storage.dataSource VolumeSnapshot to start from - ## - dataSource: {} - ## name: before-vX.Y.Z-upgrade - ## kind: VolumeSnapshot - ## apiGroup: snapshot.storage.k8s.io - ## - ## @param storage.selector select existing PersistentVolume - ## - selector: {} - ## matchLabels: - ## release: "stable" - ## matchExpressions: - ## - key: environment - ## operator: In - ## values: - ## - dev - -## @section PMM kubernetes configurations -## @param nameOverride String to partially override common.names.fullname template with a string (will prepend the release name) -## -nameOverride: "" - -## @param extraLabels Labels to add to all deployed objects -## -extraLabels: - priority: p0 - env: prod - team: dbe - bu: infra - -## Pods Service Account -## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/ -## @param serviceAccount.create Specifies whether a ServiceAccount should be created -## @param serviceAccount.annotations Annotations for service account. Evaluated as a template. Only used if `create` is `true`. -## @param serviceAccount.name Name of the service account to use. If not set and create is true, a name is generated using the fullname template. -## -serviceAccount: - create: true - annotations: {} - name: "pmmmongo-service-account" - -## @param podAnnotations Pod annotations -## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/ -## -podAnnotations: {} - -## @param podSecurityContext Configure Pods Security Context -## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod -## E.g -## podSecurityContext: - ## fsGroup: 2000 -## -podSecurityContext: {} - -## @param securityContext Configure Container Security Context -## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod -## securityContext.capabilities The capabilities to add/drop when running containers -## securityContext.runAsUser Set pmm containers' Security Context runAsUser -## securityContext.runAsNonRoot Set pmm container's Security Context runAsNonRoot -## E.g. -## securityContext: - ## capabilities: - ## drop: - ## - ALL - ## readOnlyRootFilesystem: true - ## runAsNonRoot: true - ## runAsUser: 1000 -securityContext: {} - - -## @param nodeSelector Node labels for pod assignment -## Ref: https://kubernetes.io/docs/user-guide/node-selection/ -## -nodeSelector: {} - -## @param tolerations Tolerations for pod assignment -## Ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/ -## -tolerations: - - effect: NoSchedule - key: dedicated - operator: Equal - value: devops - -## @param affinity Affinity for pod assignment -## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity -## -affinity: {} - -## @param extraVolumeMounts Optionally specify extra list of additional volumeMounts -## -extraVolumeMounts: [] -## @param extraVolumes Optionally specify extra list of additional volumes -## -extraVolumes: [] diff --git a/helm-overrides/k8s-admin-prd-ase1/postgresql/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/postgresql/custom-values.yaml deleted file mode 100644 index 3a60ac0..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/postgresql/custom-values.yaml +++ /dev/null @@ -1,48 +0,0 @@ -# PostgreSQL for toolshed's control plane. -# -# Deployed as shared infrastructure in its own namespace rather than inside -# the toolshed namespace, so it is addressed over cluster DNS like any other -# platform component and its lifecycle is independent of the application -# that happens to be its first consumer: -# -# postgresql.postgres.svc.cluster.local:5432 -# -# Credentials come from Vault through External Secrets — see -# devops-infra-argo-config/secretstores/toolshed-postgres-credentials.yaml. -# The Secret must exist before this pod can start; a missing Secret leaves it -# in CreateContainerConfigError rather than failing in a way that explains -# itself. - -fullnameOverride: postgresql - -image: - repository: postgres - tag: "16-alpine" - pullPolicy: IfNotPresent - -existingSecret: postgresql-credentials -database: toolshed - -persistence: - enabled: true - # local-path-provisioner, this cluster's default StorageClass — installed - # right after Cilium precisely because kubeadm ships no default (unlike - # k3s). 5Gi is generous for control-plane metadata; the volume is not - # resizable in place with this provisioner, so it is sized up front. - storageClass: local-path - size: 5Gi - -config: - # Deliberately far below PostgreSQL's 128MB default. The node has 8GB and - # was already at its ceiling before this; the demo apps were scaled to zero - # to make room. Revisit only if query performance actually suffers, which - # for a handful of control-plane tables it will not. - sharedBuffers: 32MB - maxConnections: "50" - -resources: - requests: - cpu: 50m - memory: 64Mi - limits: - memory: 256Mi diff --git a/helm-overrides/k8s-admin-prd-ase1/prometheus-node-exporter/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/prometheus-node-exporter/custom-values.yaml deleted file mode 100644 index bef002f..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/prometheus-node-exporter/custom-values.yaml +++ /dev/null @@ -1,496 +0,0 @@ -# Default values for prometheus-node-exporter. -# This is a YAML-formatted file. -# Declare variables to be passed into your templates. -image: - registry: quay.io - repository: prometheus/node-exporter - # Overrides the image tag whose default is {{ printf "v%s" .Chart.AppVersion }} - tag: "" - pullPolicy: IfNotPresent - digest: "" - -imagePullSecrets: [] -# - name: "image-pull-secret" -nameOverride: "" -fullnameOverride: "" - -# Number of old history to retain to allow rollback -# Default Kubernetes value is set to 10 -revisionHistoryLimit: 10 - -global: - # To help compatibility with other charts which use global.imagePullSecrets. - # Allow either an array of {name: pullSecret} maps (k8s-style), or an array of strings (more common helm-style). - # global: - # imagePullSecrets: - # - name: pullSecret1 - # - name: pullSecret2 - # or - # global: - # imagePullSecrets: - # - pullSecret1 - # - pullSecret2 - imagePullSecrets: [] - # - # Allow parent charts to override registry hostname - imageRegistry: "" - -# Configure kube-rbac-proxy. When enabled, creates a kube-rbac-proxy to protect the node-exporter http endpoint. -# The requests are served through the same service but requests are HTTPS. -kubeRBACProxy: - enabled: false - image: - registry: quay.io - repository: brancz/kube-rbac-proxy - tag: v0.14.0 - sha: "" - pullPolicy: IfNotPresent - - # List of additional cli arguments to configure kube-rbac-prxy - # for example: --tls-cipher-suites, --log-file, etc. - # all the possible args can be found here: https://github.com/brancz/kube-rbac-proxy#usage - extraArgs: [] - - ## Specify security settings for a Container - ## Allows overrides and additional options compared to (Pod) securityContext - ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container - containerSecurityContext: {} - - resources: {} - # We usually recommend not to specify default resources and to leave this as a conscious - # choice for the user. This also increases chances charts run on environments with little - # resources, such as Minikube. If you do want to specify resources, uncomment the following - # lines, adjust them as necessary, and remove the curly braces after 'resources:'. - # limits: - # cpu: 100m - # memory: 64Mi - # requests: - # cpu: 10m - # memory: 32Mi - -service: - enabled: true - type: ClusterIP - port: 9200 - targetPort: 9200 - nodePort: - portName: metrics - listenOnAllInterfaces: true - annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "9200" - prometheus.io/path: "/metrics" - ipDualStack: - enabled: false - ipFamilies: ["IPv6", "IPv4"] - ipFamilyPolicy: "PreferDualStack" - -# Set a NetworkPolicy with: -# ingress only on service.port -# no egress permitted -networkPolicy: - enabled: false - -# Additional environment variables that will be passed to the daemonset -env: {} -## env: -## VARIABLE: value - -prometheus: - monitor: - enabled: false - additionalLabels: {} - namespace: "" - - jobLabel: "" - - # List of pod labels to add to node exporter metrics - # https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api.md#servicemonitor - podTargetLabels: [] - - scheme: http - basicAuth: {} - bearerTokenFile: - tlsConfig: {} - - ## proxyUrl: URL of a proxy that should be used for scraping. - ## - proxyUrl: "" - - ## Override serviceMonitor selector - ## - selectorOverride: {} - - ## Attach node metadata to discovered targets. Requires Prometheus v2.35.0 and above. - ## - attachMetadata: - node: false - - relabelings: [] - metricRelabelings: [] - interval: "" - scrapeTimeout: 10s - ## prometheus.monitor.apiVersion ApiVersion for the serviceMonitor Resource(defaults to "monitoring.coreos.com/v1") - apiVersion: "" - - ## SampleLimit defines per-scrape limit on number of scraped samples that will be accepted. - ## - sampleLimit: 0 - - ## TargetLimit defines a limit on the number of scraped targets that will be accepted. - ## - targetLimit: 0 - - ## Per-scrape limit on number of labels that will be accepted for a sample. Only valid in Prometheus versions 2.27.0 and newer. - ## - labelLimit: 0 - - ## Per-scrape limit on length of labels name that will be accepted for a sample. Only valid in Prometheus versions 2.27.0 and newer. - ## - labelNameLengthLimit: 0 - - ## Per-scrape limit on length of labels value that will be accepted for a sample. Only valid in Prometheus versions 2.27.0 and newer. - ## - labelValueLengthLimit: 0 - - # PodMonitor defines monitoring for a set of pods. - # ref. https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api.md#monitoring.coreos.com/v1.PodMonitor - # Using a PodMonitor may be preferred in some environments where there is very large number - # of Node Exporter endpoints (1000+) behind a single service. - # The PodMonitor is disabled by default. When switching from ServiceMonitor to PodMonitor, - # the time series resulting from the configuration through PodMonitor may have different labels. - # For instance, there will not be the service label any longer which might - # affect PromQL queries selecting that label. - podMonitor: - enabled: false - # Namespace in which to deploy the pod monitor. Defaults to the release namespace. - namespace: "" - # Additional labels, e.g. setting a label for pod monitor selector as set in prometheus - additionalLabels: {} - # release: kube-prometheus-stack - # PodTargetLabels transfers labels of the Kubernetes Pod onto the target. - podTargetLabels: [] - # apiVersion defaults to monitoring.coreos.com/v1. - apiVersion: "" - # Override pod selector to select pod objects. - selectorOverride: {} - # Attach node metadata to discovered targets. Requires Prometheus v2.35.0 and above. - attachMetadata: - node: false - # The label to use to retrieve the job name from. Defaults to label app.kubernetes.io/name. - jobLabel: "" - - # Scheme/protocol to use for scraping. - scheme: "http" - # Path to scrape metrics at. - path: "/metrics" - - # BasicAuth allow an endpoint to authenticate over basic authentication. - # More info: https://prometheus.io/docs/operating/configuration/#endpoint - basicAuth: {} - # Secret to mount to read bearer token for scraping targets. - # The secret needs to be in the same namespace as the pod monitor and accessible by the Prometheus Operator. - # https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.24/#secretkeyselector-v1-core - bearerTokenSecret: {} - # TLS configuration to use when scraping the endpoint. - tlsConfig: {} - # Authorization section for this endpoint. - # https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api.md#monitoring.coreos.com/v1.SafeAuthorization - authorization: {} - # OAuth2 for the URL. Only valid in Prometheus versions 2.27.0 and newer. - # https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api.md#monitoring.coreos.com/v1.OAuth2 - oauth2: {} - - # ProxyURL eg http://proxyserver:2195. Directs scrapes through proxy to this endpoint. - proxyUrl: "" - # Interval at which endpoints should be scraped. If not specified Prometheus’ global scrape interval is used. - interval: "" - # Timeout after which the scrape is ended. If not specified, the Prometheus global scrape interval is used. - scrapeTimeout: "" - # HonorTimestamps controls whether Prometheus respects the timestamps present in scraped data. - honorTimestamps: true - # HonorLabels chooses the metric’s labels on collisions with target labels. - honorLabels: true - # Whether to enable HTTP2. Default false. - enableHttp2: "" - # Drop pods that are not running. (Failed, Succeeded). - # Enabled by default. More info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle/#pod-phase - filterRunning: "" - # FollowRedirects configures whether scrape requests follow HTTP 3xx redirects. Default false. - followRedirects: "" - # Optional HTTP URL parameters - params: {} - - # RelabelConfigs to apply to samples before scraping. Prometheus Operator automatically adds - # relabelings for a few standard Kubernetes fields. The original scrape job’s name - # is available via the __tmp_prometheus_job_name label. - # More info: https://prometheus.io/docs/prometheus/latest/configuration/configuration/#relabel_config - relabelings: [] - # MetricRelabelConfigs to apply to samples before ingestion. - metricRelabelings: [] - - # SampleLimit defines per-scrape limit on number of scraped samples that will be accepted. - sampleLimit: 0 - # TargetLimit defines a limit on the number of scraped targets that will be accepted. - targetLimit: 0 - # Per-scrape limit on number of labels that will be accepted for a sample. - # Only valid in Prometheus versions 2.27.0 and newer. - labelLimit: 0 - # Per-scrape limit on length of labels name that will be accepted for a sample. - # Only valid in Prometheus versions 2.27.0 and newer. - labelNameLengthLimit: 0 - # Per-scrape limit on length of labels value that will be accepted for a sample. - # Only valid in Prometheus versions 2.27.0 and newer. - labelValueLengthLimit: 0 - -## Customize the updateStrategy if set -updateStrategy: - type: RollingUpdate - rollingUpdate: - maxUnavailable: 1 - -resources: - # We usually recommend not to specify default resources and to leave this as a conscious - # choice for the user. This also increases chances charts run on environments with little - # resources, such as Minikube. If you do want to specify resources, uncomment the following - # lines, adjust them as necessary, and remove the curly braces after 'resources:'. - limits: - cpu: 200m - memory: 50Mi - requests: - cpu: 100m - memory: 30Mi - -serviceAccount: - # Specifies whether a ServiceAccount should be created - create: true - # The name of the ServiceAccount to use. - # If not set and create is true, a name is generated using the fullname template - name: - annotations: {} - # annotations: { - # iam.gke.io/gcp-service-account: node-exporter-admin-prd@meesho-admin-prd-0622.iam.gserviceaccount.com - # } - imagePullSecrets: [] - automountServiceAccountToken: false - -securityContext: - fsGroup: 65534 - runAsGroup: 65534 - runAsNonRoot: true - runAsUser: 65534 - -containerSecurityContext: - readOnlyRootFilesystem: true - # capabilities: - # add: - # - SYS_TIME - -rbac: - ## If true, create & use RBAC resources - ## - create: true - ## If true, create & use Pod Security Policy resources - ## https://kubernetes.io/docs/concepts/policy/pod-security-policy/ - pspEnabled: true - pspAnnotations: {} - -# for deployments that have node_exporter deployed outside of the cluster, list -# their addresses here -endpoints: [] - -# Expose the service to the host network -hostNetwork: true - -# Share the host process ID namespace -hostPID: true - -# Mount the node's root file system (/) at /host/root in the container -hostRootFsMount: - enabled: true - # Defines how new mounts in existing mounts on the node or in the container - # are propagated to the container or node, respectively. Possible values are - # None, HostToContainer, and Bidirectional. If this field is omitted, then - # None is used. More information on: - # https://kubernetes.io/docs/concepts/storage/volumes/#mount-propagation - mountPropagation: HostToContainer - -## Assign a group of affinity scheduling rules -## -affinity: {} -# nodeAffinity: -# requiredDuringSchedulingIgnoredDuringExecution: -# nodeSelectorTerms: -# - matchFields: -# - key: metadata.name -# operator: In -# values: -# - target-host-name - -# Annotations to be added to node exporter pods -podAnnotations: - # Fix for very slow GKE cluster upgrades - cluster-autoscaler.kubernetes.io/safe-to-evict: "true" - prometheus.io/scrape: "true" - prometheus.io/port: "9200" - prometheus.io/path: "/metrics" - -# Extra labels to be added to node exporter pods -podLabels: - bu: "infra" - team: "infra-sre" - service: "node-exporter-infra-prd" - env: "prd" - priority: "p0" - type: "exporter" - -# Annotations to be added to node exporter daemonset -daemonsetAnnotations: - prometheus.io/scrape: "true" - prometheus.io/port: "9200" - prometheus.io/path: "/metrics" - -## set to true to add the release label so scraping of the servicemonitor with kube-prometheus-stack works out of the box -releaseLabel: false - -# Custom DNS configuration to be added to prometheus-node-exporter pods -dnsConfig: {} -# nameservers: -# - 1.2.3.4 -# searches: -# - ns1.svc.cluster-domain.example -# - my.dns.search.suffix -# options: -# - name: ndots -# value: "2" -# - name: edns0 - -## Assign a nodeSelector if operating a hybrid cluster -## -nodeSelector: {} - # kubernetes.io/os: linux - # kubernetes.io/arch: amd64 - -tolerations: - - operator: Exists - -## Assign a PriorityClassName to pods if set -priorityClassName: "system-node-critical" - -## Additional container arguments -## -extraArgs: [] -# - --collector.diskstats.ignored-devices=^(ram|loop|fd|(h|s|v)d[a-z]|nvme\\d+n\\d+p)\\d+$ -# - --collector.textfile.directory=/run/prometheus - -## Additional mounts from the host to node-exporter container -## -extraHostVolumeMounts: [] -# - name: -# hostPath: -# mountPath: -# readOnly: true|false -# mountPropagation: None|HostToContainer|Bidirectional - -## Additional configmaps to be mounted. -## -configmaps: [] -# - name: -# mountPath: -secrets: [] -# - name: -# mountPath: -## Override the deployment namespace -## -namespaceOverride: "monitoring" - -## Additional containers for export metrics to text file -## -sidecars: [] -## - name: nvidia-dcgm-exporter -## image: nvidia/dcgm-exporter:1.4.3 - -## Volume for sidecar containers -## -sidecarVolumeMount: [] -## - name: collector-textfiles -## mountPath: /run/prometheus -## readOnly: false - -## Additional mounts from the host to sidecar containers -## -sidecarHostVolumeMounts: [] -# - name: -# hostPath: -# mountPath: -# readOnly: true|false -# mountPropagation: None|HostToContainer|Bidirectional - -## Additional InitContainers to initialize the pod -## -extraInitContainers: [] - -## Liveness probe -## -livenessProbe: - failureThreshold: 3 - httpGet: - httpHeaders: [] - scheme: http - initialDelaySeconds: 0 - periodSeconds: 10 - successThreshold: 1 - timeoutSeconds: 1 - -## Readiness probe -## -readinessProbe: - failureThreshold: 3 - httpGet: - httpHeaders: [] - scheme: http - initialDelaySeconds: 0 - periodSeconds: 10 - successThreshold: 1 - timeoutSeconds: 1 - -# Enable vertical pod autoscaler support for prometheus-node-exporter -verticalPodAutoscaler: - enabled: false - - # Recommender responsible for generating recommendation for the object. - # List should be empty (then the default recommender will generate the recommendation) - # or contain exactly one recommender. - # recommenders: - # - name: custom-recommender-performance - - # List of resources that the vertical pod autoscaler can control. Defaults to cpu and memory - controlledResources: [] - # Specifies which resource values should be controlled: RequestsOnly or RequestsAndLimits. - # controlledValues: RequestsAndLimits - - # Define the max allowed resources for the pod - maxAllowed: {} - # cpu: 200m - # memory: 100Mi - # Define the min allowed resources for the pod - minAllowed: {} - # cpu: 200m - # memory: 100Mi - - # updatePolicy: - # Specifies minimal number of replicas which need to be alive for VPA Updater to attempt pod eviction - # minReplicas: 1 - # Specifies whether recommended updates are applied when a Pod is started and whether recommended updates - # are applied during the life of a Pod. Possible values are "Off", "Initial", "Recreate", and "Auto". - # updateMode: Auto - -# Extra manifests to deploy as an array -extraManifests: [] - # - | - # apiVersion: v1 - # kind: ConfigMap - # metadata: - # name: prometheus-extra - # data: - # extra-data: "value" diff --git a/helm-overrides/k8s-admin-prd-ase1/prometheus-stackdriver-exporter/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/prometheus-stackdriver-exporter/custom-values.yaml deleted file mode 100644 index e72ca57..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/prometheus-stackdriver-exporter/custom-values.yaml +++ /dev/null @@ -1,170 +0,0 @@ -# Provide a name in place of prometheus-stackdriver-exporter for `app:` labels -nameOverride: "stackdriver-exporter-infra-prd" - -# Provide a name to substitute for the full names of resources -fullnameOverride: "stackdriver-exporter-infra-prd" - -# Number of exporters to run -replicaCount: 1 - -# Restart policy for container -restartPolicy: Always - -image: - repository: prometheuscommunity/stackdriver-exporter - # if not set appVersion field from Chart.yaml is used - tag: "v0.16.0" - pullPolicy: IfNotPresent - - ## Optionally specify an array of imagePullSecrets. - ## Secrets must be manually created in the namespace. - ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ - ## - # pullSecrets: - # - myDockerConfigJsonSecretName - -resources: - requests: - cpu: 500m - memory: 512Mi - # limits: - # cpu: 100m - # memory: 128Mi - -securityContext: {} - -containerSecurityContext: {} - -service: - type: ClusterIP - httpPort: 9255 - annotations: {} - -## Additional labels to add to all resources -customLabels: - bu: "infra" - team: "infra-sre" - service: "stackdriver-exporter-infra-prd" - env: "prd" - priority: "p0" - type: "exporter" - # app: prometheus-stackdriver-exporter - -secret: - labels: {} - -stackdriver: - # The Google Project ID to gather metrics for - projectId: "meesho-admin-prd-0622" - # An existing secret which contains credentials.json - serviceAccountSecret: "" - # Provide custom key for the existing secret to load credentials.json from - serviceAccountSecretKey: "" - # A service account key JSON file. Must be provided when no existing secret is used, in this case a new secret will be created holding this service account - serviceAccountKey: "" - # Max number of retries that should be attempted on 503 errors from Stackdriver - maxRetries: 0 - # How long should Stackdriver_exporter wait for a result from the Stackdriver API - httpTimeout: 10s - # Max time between each request in an exp backoff scenario - maxBackoff: 5s - # The amount of jitter to introduce in an exp backoff scenario - backoffJitter: 1s - # The HTTP statuses that should trigger a retry - retryStatuses: 503 - # Drop metrics from attached projects and fetch `project_id` only - dropDelegatedProjects: true - metrics: - # The prefixes to gather metrics for, we default to just CPU metrics. - typePrefixes: 'compute.googleapis.com/instance,cloudsql.googleapis.com/database,logging.googleapis.com/user/node_drain_metric,compute.googleapis.com/guest/system/uptime' - # The filters to refine the metrics query by using Filter objects that Google provides. - # Filter objects: project, group.id, resource.type, resource.labels.[KEY], metric.type, metric.labels.[KEY] - # https://cloud.google.com/monitoring/api/v3/filters - filters: [] - # - 'pubsub.googleapis.com/subscription:resource.labels.subscription_id=monitoring.regex.full_match("us-west4.*my-team.*")' - # The frequency to request - interval: '5m' - # How far into the past to offset - offset: '0s' - # Offset for the Google Stackdriver Monitoring Metrics interval into the past by the ingest delay from the metric's metadata. - ingestDelay: false - # If enabled will treat all DELTA metrics as an in-memory counter instead of a gauge. - aggregateDeltas: false - # How long should a delta metric continue to be exported after GCP stops producing a metric - aggregateDeltasTTL: '30m' - -web: - # Port to listen on - listenAddress: ':9255' - # Path under which to expose metrics. - path: /metrics - -## Pod affinity -## -affinity: {} - -annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "9255" - prometheus.io/path: "/metrics" - -## Pod extra arguments -## -extraArgs: {} - -## Node labels for stackdriver-exporter pod assignment -## Ref: https://kubernetes.io/docs/user-guide/node-selection/ -## -nodeSelector: - dedicated: "sre-shared-tmp" - -## Node tolerations for stackdriver-exporter scheduling to nodes with taints -## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/ -## -tolerations: - - key: "dedicated" - operator: "Equal" - value: "sre-shared-tmp" - effect: "NoSchedule" - - -## Service Account -## -serviceAccount: - # Specifies whether a ServiceAccount should be created - create: true - # The name of the ServiceAccount to use. - # If not set and create is false, 'default' is used - # If not set and create is true, a name is generated using the fullname template - name: - annotations: { - iam.gke.io/gcp-service-account: sa-stackdriver-exp-infra-prd@meesho-admin-prd-0622.iam.gserviceaccount.com - } - - -# Enable this if you're using https://github.com/coreos/prometheus-operator -serviceMonitor: - enabled: false - namespace: monitoring - # additionalLabels is the set of additional labels to add to the ServiceMonitor - additionalLabels: {} - # How long until a scrape request times out. - scrapeTimeout: '10s' - # fallback to the prometheus default unless specified - interval: 10s - # Defaults to what's used if you follow CoreOS [Prometheus Install Instructions](https://github.com/helm/charts/tree/master/stable/prometheus-operator#tldr) - honorLabels: true - # Whether Prometheus should use the timestamps of the metrics exposed by stackdriver-exporter - honorTimestamps: true - # MetricRelabelConfigs to apply to samples before ingestion https://github.com/prometheus-operator/prometheus-operator/blob/master/Documentation/api.md#relabelconfig - metricRelabelings: [] - # RelabelConfigs to apply to samples before scraping. https://github.com/prometheus-operator/prometheus-operator/blob/master/Documentation/api.md#relabelconfig - relabelings: [] - -## Custom PrometheusRules to be defined -## ref: https://github.com/coreos/prometheus-operator#customresourcedefinitions -prometheusRule: - enabled: false - additionalLabels: {} - namespace: "" - rules: [] diff --git a/helm-overrides/k8s-admin-prd-ase1/pyroscope/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/pyroscope/custom-values.yaml deleted file mode 100644 index 68d0cba..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/pyroscope/custom-values.yaml +++ /dev/null @@ -1,62 +0,0 @@ -alloy: - enabled: false - -agent: - enabled: false - -minio: - enabled: false - -pyroscope: - fullnameOverride: prd-pyroscope - - image: - repository: grafana/pyroscope - pullPolicy: IfNotPresent - tag: "" - - extraLabels: - bu: "infra" - team: "devops" - service: "prd-pyroscope" - env: "prd" - priority: "p1" - type: "pyroscope" - - resources: - requests: - cpu: 500m - memory: 1Gi - limits: - cpu: "2" - memory: 4Gi - - persistence: - enabled: true - accessModes: - - ReadWriteOnce - size: 50Gi - storageClassName: pd-balanced - - nodeSelector: - dedicated: devops - - tolerations: - - key: "dedicated" - operator: "Equal" - value: "devops" - effect: "NoSchedule" - - podDisruptionBudget: - enabled: false - - serviceAccount: - create: true - -ingress: - enabled: true - className: nginx-internal - annotations: {} - hosts: - - pyroscope.meeshogcp.in - tls: [] diff --git a/helm-overrides/k8s-admin-prd-ase1/redis/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/redis/custom-values.yaml deleted file mode 100644 index a62f6ff..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/redis/custom-values.yaml +++ /dev/null @@ -1,50 +0,0 @@ -# Redis backing toolshed's managed cache add-on. -# -# Deployed as shared infrastructure in its own namespace rather than inside -# the toolshed namespace, so it is addressed over cluster DNS like any other -# platform component and its lifecycle is independent of the application -# that happens to be its first consumer: -# -# redis.redis.svc.cluster.local:6379 -# -# The admin password comes from Vault through External Secrets — see -# devops-infra-argo-config/secretstores/toolshed-redis-credentials.yaml. The -# Secret must exist before this pod can start; a missing Secret leaves the -# init container in CreateContainerConfigError rather than failing in a way -# that explains itself. -# -# Read values.yaml's `config` block before changing anything about -# authentication here. The absence of `requirepass` is deliberate and -# security-relevant, not an oversight. - -fullnameOverride: redis - -image: - repository: redis - tag: "7-alpine" - pullPolicy: IfNotPresent - -existingSecret: redis-credentials - -persistence: - enabled: true - storageClass: local-path - # Holds the ACL file and nothing else worth keeping — snapshotting is off - # (see config.save). 1Gi is already far more than needed; local-path - # cannot resize in place, so it is sized up front rather than tightly. - size: 1Gi - -config: - # The node has 8GB and was at its ceiling before Postgres was added; the - # demo apps were scaled to zero to make room for that. 48mb is a real - # cache for a handful of small internal tools and costs little. - maxmemory: 48mb - maxmemoryPolicy: allkeys-lru - save: "" - -resources: - requests: - cpu: 25m - memory: 32Mi - limits: - memory: 96Mi diff --git a/helm-overrides/k8s-admin-prd-ase1/sonarqube-public/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/sonarqube-public/custom-values.yaml deleted file mode 100644 index e898aa8..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/sonarqube-public/custom-values.yaml +++ /dev/null @@ -1,652 +0,0 @@ -# Default values for sonarqube. -# This is a YAML-formatted file. -# Declare variables to be passed into your templates. - -# If the deployment Type is set to Deployment sonarqube is deployed as a replica set. -deploymentType: "StatefulSet" -labels: - bu: "infra" - team: "devops" - service: "sonarqube-public-prd" - env: "prd" - priority: "p0" - type: "sonarqube" - -# There should not be more than 1 sonarqube instance connected to the same database. Please set this value to 1 or 0 (in case you need to scale down programmatically). -replicaCount: 1 - -# How many revisions to retain (Deployment ReplicaSets or StatefulSets) -revisionHistoryLimit: 10 - -# This will use the default deployment strategy unless it is overriden -deploymentStrategy: {} -# Uncomment this to scheduler pods on priority -# priorityClassName: "high-priority" - -## Use an alternate scheduler, e.g. "stork". -## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/ -## -# schedulerName: - -## Is this deployment for OpenShift? If so, we help with SCCs -OpenShift: - enabled: false - createSCC: true - -edition: "community" - -image: - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/devops/sonarqube - tag: 10.4.0-{{ .Values.edition }} - pullPolicy: Always - # If using a private repository, the imagePullSecrets to use - # pullSecrets: - # - name: my-repo-secret - -# Set security context for sonarqube pod -securityContext: - fsGroup: 0 - -# Set security context for sonarqube container -containerSecurityContext: - # Sonarqube dockerfile creates sonarqube user as UID and GID 1000 - # Those default are used to match pod security standard restricted as least privileged approach - allowPrivilegeEscalation: false - runAsNonRoot: true - runAsUser: 1000 - runAsGroup: 1000 - seccompProfile: - type: RuntimeDefault - # capabilities: - # drop: ["ALL"] - -# Settings to configure elasticsearch host requirements -elasticsearch: - # DEPRECATED: Use initSysctl.enabled instead - configureNode: false - bootstrapChecks: false - -service: - type: ClusterIP - externalPort: 9000 - internalPort: 9000 - labels: - annotations: {} - # May be used in example for internal load balancing in GCP: - # cloud.google.com/load-balancer-type: Internal - # loadBalancerSourceRanges: - # - 0.0.0.0/0 - # loadBalancerIP: 1.2.3.4 - -# Optionally create Network Policies -networkPolicy: - enabled: false - - # If you plan on using the jmx exporter, you need to define where the traffic is coming from - prometheusNamespace: "monitoring" - - # If you are using a external database and enable network Policies to be created - # you will need to explicitly allow egress traffic to your database - # expects https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.21/#networkpolicyspec-v1-networking-k8s-io - # additionalNetworkPolicys: - -# will be used as default for ingress path and probes path, will be injected in .Values.env as SONAR_WEB_CONTEXT -# if .Values.env.SONAR_WEB_CONTEXT is set, this value will be ignored -sonarWebContext: "" - -# also install the nginx ingress helm chart -nginx: - enabled: false - -ingress: - enabled: true - # Used to create an Ingress record. - hosts: - - name: sonarqube-public-prd.infr-h1.meeshogcp.in -#sonarProperties: -# sonar.auth.saml.enabled: true -# sonar.auth.saml.applicationId: sonarqube -# sonar.auth.saml.providerName: -# sonar.auth.saml.providerId: http://okta.url/ -# sonar.auth.saml.loginUrl: https://okta.url/sso/saml -# sonar.auth.saml.user.login: login -# sonar.auth.saml.user.name: name -# sonar.auth.saml.user.email: email -# sonar.auth.saml.group.name: groups -# sonar.auth.saml.certificate.secured: -# sonar.core.serverBaseURL: https://sonar.url - # Different clouds or configurations might need /* as the default path - # path: / - # For additional control over serviceName and servicePort - # serviceName: someService - # servicePort: somePort - # the pathType can be one of the following values: Exact|Prefix|ImplementationSpecific(default) - # pathType: ImplementationSpecific - annotations: - kubernetes.io/ingress.class: nginx-external - nginx.ingress.kubernetes.io/proxy-body-size: "20M" - # kubernetes.io/tls-acme: "true" - - # Set the ingressClassName on the ingress record - ingressClassName: nginx-external - -# Additional labels for Ingress manifest file - # labels: - # traffic-type: external - # traffic-type: internal - tls: [] - # Secrets must be manually created in the namespace. To generate a self-signed certificate (and private key) and then create the secret in the cluster please refer to official documentation available at https://kubernetes.github.io/ingress-nginx/user-guide/tls/#tls-secrets - # - secretName: chart-example-tls - # hosts: - # - chart-example.local - -route: - enabled: false - host: "" - # Add tls section to secure traffic. TODO: extend this section with other secure route settings - # Comment this out if you want plain http route created. - tls: - termination: edge - - annotations: {} - # See Openshift/OKD route annotation - # https://docs.openshift.com/container-platform/4.10/networking/routes/route-configuration.html#nw-route-specific-annotations_route-configuration - # haproxy.router.openshift.io/timeout: 1m - - # Additional labels for Route manifest file - # labels: - # external: 'true' - -# Affinity for pod assignment -# Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity -affinity: {} - -# Tolerations for pod assignment -# Ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/ -# taint a node with the following command to mark it as not schedulable for new pods -# kubectl taint nodes sonarqube=true:NoSchedule -# The following statement will tolerate this taint and as such reverse a node for sonarqube -tolerations: - - key: "dedicated" - operator: "Equal" - value: "jenkins" - effect: "NoSchedule" - -# Node labels for pod assignment -# Ref: https://kubernetes.io/docs/user-guide/node-selection/ -# add a label to a node with the following command -# kubectl label node sonarqube=true -nodeSelector: - dedicated: "jenkins" - -# hostAliases allows the modification of the hosts file inside a container -hostAliases: [] -# - ip: "192.168.1.10" -# hostnames: -# - "example.com" -# - "www.example.com" - -readinessProbe: - initialDelaySeconds: 90 - periodSeconds: 30 - failureThreshold: 6 - # Note that timeoutSeconds was not respected before Kubernetes 1.20 for exec probes - timeoutSeconds: 1 - # If an ingress *path* other than the root (/) is defined, it should be reflected here - # A trailing "/" must be included - # deprecated please use sonarWebContext at the value top level - # sonarWebContext: / - -livenessProbe: - initialDelaySeconds: 90 - periodSeconds: 30 - failureThreshold: 6 - # Note that timeoutSeconds was not respected before Kubernetes 1.20 for exec probes - timeoutSeconds: 1 - # If an ingress *path* other than the root (/) is defined, it should be reflected here - # A trailing "/" must be included - # deprecated please use sonarWebContext at the value top level - # sonarWebContext: / - -startupProbe: - initialDelaySeconds: 180 - periodSeconds: 10 - failureThreshold: 24 - # Note that timeoutSeconds was not respected before Kubernetes 1.20 for exec probes - timeoutSeconds: 1 - # If an ingress *path* other than the root (/) is defined, it should be reflected here - # A trailing "/" must be included - # deprecated please use sonarWebContext at the value top level - # sonarWebContext: / - -initContainers: - # image: busybox:1.36 - # We allow the init containers to have a separate security context declaration because - # the initContainer may not require the same as SonarQube. - # Those default are used to match pod security standard restricted as least privileged approach - securityContext: - allowPrivilegeEscalation: false - runAsNonRoot: true - runAsUser: 1000 - runAsGroup: 1000 - seccompProfile: - type: RuntimeDefault - capabilities: - drop: ["ALL"] - # We allow the init containers to have a separate resources declaration because - # the initContainer does not take as much resources. - resources: {} - -# Extra init containers to e.g. download required artifacts -extraInitContainers: {} - -## Array of extra containers to run alongside the sonarqube container -## -## Example: -## - name: myapp-container -## image: busybox -## command: ['sh', '-c', 'echo Hello && sleep 3600'] -## -extraContainers: [] - -## Provide a secret containing one or more certificate files in the keys that will be added to cacerts -## The cacerts file will be set via SONARQUBE_WEB_JVM_OPTS and SONAR_CE_JAVAOPTS -## -caCerts: - enabled: false - image: adoptopenjdk/openjdk11:alpine - secret: your-secret - -initSysctl: - enabled: false - vmMaxMapCount: 524288 - fsFileMax: 131072 - nofile: 131072 - nproc: 8192 - # image: busybox:1.36 - securityContext: - # Compatible with podSecurity standard privileged - privileged: true - # resources: {} - -# This should not be required anymore, used to chown/chmod folder created by faulty CSI driver that are not applying properly POSIX fsgroup. -initFs: - enabled: false - # Image: busybox:1.36 - # Compatible with podSecurity standard baseline. - securityContext: - privileged: false - runAsNonRoot: false - runAsUser: 0 - runAsGroup: 0 - seccompProfile: - type: RuntimeDefault - capabilities: - drop: ["ALL"] - add: ["CHOWN"] - -prometheusExporter: - enabled: false - # jmx_prometheus_javaagent version to download from Maven Central - version: "0.17.2" - # Alternative full download URL for the jmx_prometheus_javaagent.jar (overrides prometheusExporter.version) - # downloadURL: "" - # if you need to ignore TLS certificates for whatever reason enable the following flag - noCheckCertificate: false - - # Ports for the jmx prometheus agent to export metrics at - webBeanPort: 8000 - ceBeanPort: 8001 - - config: - rules: - - pattern: ".*" - # Overrides config for the CE process Prometheus exporter (by default, the same rules are used for both the Web and CE processes). - # ceConfig: - # rules: - # - pattern: ".*" - # image: curlimages/curl:8.2.1 - # For use behind a corporate proxy when downloading prometheus - # httpProxy: "" - # httpsProxy: "" - # noProxy: "" - # Reuse default initcontainers.securityContext that match restricted pod security standard - # securityContext: {} - -prometheusMonitoring: - # Generate a Prometheus Pod Monitor (https://github.com/coreos/prometheus-operator) - # - podMonitor: - # Create PodMonitor Resource for Prometheus scraping - enabled: false - # Specify a custom namespace where the PodMonitor will be created - namespace: "sonarqube" - # Specify the interval how often metrics should be scraped - interval: 30s - # Specify the timeout after a scrape is ended - # scrapeTimeout: "" - # Name of the label on target services that prometheus uses as job name - # jobLabel: "" - -# List of plugins to install. -# For example: -# plugins: -# install: -# - "https://github.com/AmadeusITGroup/sonar-stash/releases/download/1.3.0/sonar-stash-plugin-1.3.0.jar" -# - "https://github.com/SonarSource/sonar-ldap/releases/download/2.2-RC3/sonar-ldap-plugin-2.2.0.601.jar" -# -plugins: - image: curlimages/curl:8.2.1 - install: - - https://github.com/iSergio/sonarqube-community-branch-plugin/releases/download/1.16.1/sonarqube-community-branch-plugin-1.16.1-SNAPSHOT.jar - - https://github.com/insideapp-oss/sonar-apple/releases/download/0.4.0/sonar-apple-plugin-0.4.0.jar - noCheckCertificate: false - -env: - - name: TZ - value: Asia/Kolkata - - name: SONAR_WEB_JAVAOPTS - value: "-javaagent:/opt/sonarqube/extensions/plugins/sonarqube-community-branch-plugin-1.16.1-SNAPSHOT.jar=web" - - name: SONAR_CE_JAVAOPTS - value: "-javaagent:/opt/sonarqube/extensions/plugins/sonarqube-community-branch-plugin-1.16.1-SNAPSHOT.jar=ce" - - # For use behind a corporate proxy when downloading plugins - # httpProxy: "" - # httpsProxy: "" - # noProxy: "" - - # resources: {} - - # .netrc secret file with a key "netrc" to use basic auth while downloading plugins - # netrcCreds: "" - - # Set to true to not validate the server's certificate to download plugin - - # Reuse default initcontainers.securityContext that match restricted pod security standard - # securityContext: {} - -## (DEPRECATED) The following value sets SONAR_WEB_JAVAOPTS (e.g., jvmOpts: "-Djava.net.preferIPv4Stack=true"). However, this is deprecated, please set SONAR_WEB_JAVAOPTS or sonar.web.javaOpts directly instead. -jvmOpts: "" - -## (DEPRECATED) The following value sets SONAR_CE_JAVAOPTS. However, this is deprecated, please set SONAR_CE_JAVAOPTS or sonar.ce.javaOpts directly instead. -jvmCeOpts: "" - -## a monitoring passcode needs to be defined in order to get reasonable probe results -# not setting the monitoring passcode will result in a deployment that will never be ready -monitoringPasscode: "define_it" -# Alternatively, you can define the passcode loading it from an existing secret specifying the right key -# monitoringPasscodeSecretName: "pass-secret-name" -# monitoringPasscodeSecretKey: "pass-key" - -## Environment variables to attach to the pods -## -# env: -# # If you use a different ingress path from /, you have to add it here as the value of SONAR_WEB_CONTEXT -# - name: SONAR_WEB_CONTEXT -# value: /sonarqube -# - name: VARIABLE -# value: my-value - -# Set annotations for pods -annotations: {} - -## We usually don't make specific ressource recommandations, as they are heavily dependend on -## The usage of SonarQube and the surrounding infrastructure. -## Adjust these values to your needs, but make sure that the memory limit is never under 4 GB -resources: - limits: - cpu: 800m - memory: 4Gi - requests: - cpu: 400m - memory: 2Gi - -persistence: - enabled: true - ## Set annotations on pvc - annotations: {} - - ## Specify an existing volume claim instead of creating a new one. - ## When using this option all following options like storageClass, accessMode and size are ignored. - # existingClaim: - - ## If defined, storageClassName: - ## If set to "-", storageClassName: "", which disables dynamic provisioning - ## If undefined (the default) or set to null, no storageClassName spec is - ## set, choosing the default provisioner. (gp2 on AWS, standard on - ## GKE, AWS & OpenStack) - ## - storageClass: - accessMode: ReadWriteOnce - size: 5Gi - uid: 1000 - guid: 0 - - ## Specify extra volumes. Refer to ".spec.volumes" specification : https://kubernetes.io/fr/docs/concepts/storage/volumes/ - volumes: [] - ## Specify extra mounts. Refer to ".spec.containers.volumeMounts" specification : https://kubernetes.io/fr/docs/concepts/storage/volumes/ - mounts: [] - -# In case you want to specify different resources for emptyDir than {} -emptyDir: {} - # Example of resouces that might be used: - # medium: Memory - # sizeLimit: 16Mi - -# A custom sonar.properties file can be provided via dictionary. -# For example: -# sonarProperties: -# sonar.forceAuthentication: true -# sonar.security.realm: LDAP -# ldap.url: ldaps://organization.com - -# Additional sonar properties to load from a secret with a key "secret.properties" (must be a string) -# sonarSecretProperties: - -# Kubernetes secret that contains the encryption key for the sonarqube instance. -# The secret must contain the key 'sonar-secret.txt'. -# The 'sonar.secretKeyPath' property will be set automatically. -# sonarSecretKey: "settings-encryption-secret" - -## Override JDBC values -## for external Databases -jdbcOverwrite: - # If enable the JDBC Overwrite, make sure to set `postgresql.enabled=false` - enable: false - # The JDBC url of the external DB - jdbcUrl: "jdbc:postgresql://myPostgress/myDatabase?socketTimeout=1500" - # The DB user that should be used for the JDBC connection - jdbcUsername: "sonarUser" - # Use this if you don't mind the DB password getting stored in plain text within the values file - jdbcPassword: "sonarPass" - ## Alternatively, use a pre-existing k8s secret containing the DB password - # jdbcSecretName: "sonarqube-jdbc" - ## and the secretValueKey of the password found within that secret - # jdbcSecretPasswordKey: "jdbc-password" - -## (DEPRECATED) Configuration values for postgresql dependency -## ref: https://github.com/bitnami/charts/blob/master/bitnami/postgresql/README.md -postgresql: - # Enable to deploy the bitnami PostgreSQL chart - enabled: true - primary: - tolerations: - - key: "dedicated" - operator: "Equal" - value: "jenkins" - effect: "NoSchedule" - - nodeSelector: - dedicated: "jenkins" - labels: - bu: "infra" - team: "devops" - service: "sonarqube-prd" - env: "prd" - priority: "p0" - type: "sonarqube-psql-master" - podLabels: - bu: "infra" - team: "devops" - service: "sonarqube-prd" - env: "prd" - priority: "p0" - type: "sonarqube-psql-master" - readReplicas: - tolerations: - - key: "dedicated" - operator: "Equal" - value: "jenkins" - effect: "NoSchedule" - - nodeSelector: - dedicated: "jenkins" - labels: - bu: "infra" - team: "devops" - service: "sonarqube-prd" - env: "prd" - priority: "p0" - type: "sonarqube-psql-slave" - podLabels: - bu: "infra" - team: "devops" - service: "sonarqube-prd" - env: "prd" - priority: "p0" - type: "sonarqube-psql-slave" - ## postgresql Chart global settings - # global: - # imageRegistry: '' - # imagePullSecrets: '' - ## bitnami/postgres image tag - # image: - # tag: 11.7.0-debian-10-r9 - # existingSecret Name of existing secret to use for PostgreSQL passwords - # The secret has to contain the keys postgresql-password which is the password for postgresqlUsername when it is - # different of postgres, postgresql-postgres-password which will override postgresqlPassword, - # postgresql-replication-password which will override replication.password and postgresql-ldap-password which will be - # used to authenticate on LDAP. The value is evaluated as a template. - # existingSecret: "" - # - # The bitnami chart enforces the key to be "postgresql-password". This value is only here for historic purposes - # existingSecretPasswordKey: "postgresql-password" - postgresqlUsername: "sonarUser" - postgresqlPassword: "sonarPass" - postgresqlDatabase: "sonarDB" - # Specify the TCP port that PostgreSQL should use - service: - port: 5432 - resources: - limits: - cpu: 2 - memory: 2Gi - requests: - cpu: 100m - memory: 200Mi - persistence: - enabled: true - accessMode: ReadWriteOnce - size: 2Gi - storageClass: - securityContext: - # For standard Kubernetes deployment, set enabled=true - # If using OpenShift, enabled=false for restricted SCC and enabled=true for anyuid/nonroot SCC - enabled: true - # fsGroup specification below are not applied if enabled=false. enabled=false is the required setting for OpenShift "restricted SCC" to work successfully. - # postgresql dockerfile sets user as 1001 - fsGroup: 1001 - containerSecurityContext: - # For standard Kubernetes deployment, set enabled=true - # If using OpenShift, enabled=false for restricted SCC and enabled=true for anyuid/nonroot SCC - enabled: true - # runAsUser specification below are not applied if enabled=false. enabled=false is the required setting for OpenShift "restricted SCC" to work successfully. - # postgresql dockerfile sets user as 1001, the rest aim at making it compatible with restricted pod security standard. - runAsUser: 1001 - allowPrivilegeEscalation: false - runAsNonRoot: true - seccompProfile: - type: RuntimeDefault - capabilities: - drop: ["ALL"] - volumePermissions: - # For standard Kubernetes deployment, set enabled=false - # For OpenShift, set enabled=true and ensure to set volumepermissions.securitycontext.runAsUser below. - enabled: false - # if using restricted SCC set runAsUser: "auto" and if running under anyuid/nonroot SCC - runAsUser needs to match runAsUser above - securityContext: - runAsUser: 0 - shmVolume: - chmod: - enabled: false - serviceAccount: - ## If enabled = true, and name is not set, postgreSQL will create a serviceAccount - enabled: false - # name: - -# Additional labels to add to the pods: -# podLabels: -# key: value -podLabels: {} -# For compatibility with 8.0 replace by "/opt/sq" -# For compatibility with 8.2, leave the default. They changed it back to /opt/sonarqube -sonarqubeFolder: /opt/sonarqube - -tests: - image: "" - enabled: true - resources: {} - -# For OpenShift set create=true to ensure service account is created. -serviceAccount: - create: false - # name: - # automountToken: false # default - ## Annotations for the Service Account - annotations: {} - -# extraConfig is used to load Environment Variables from Secrets and ConfigMaps -# which may have been written by other tools, such as external orchestrators. -# -# These Secrets/ConfigMaps are expected to contain Key/Value pairs, such as: -# -# apiVersion: v1 -# kind: ConfigMap -# metadata: -# name: external-sonarqube-opts -# data: -# SONARQUBE_JDBC_USERNAME: foo -# SONARQUBE_JDBC_URL: jdbc:postgresql://db.example.com:5432/sonar -# -# These vars can then be injected into the environment by uncommenting the following: -# -# extraConfig: -# configmaps: -# - external-sonarqube-opts - -extraConfig: - secrets: [] - configmaps: [] - -# account: -# The values can be set to define the current and the (new) custom admin passwords at the startup (the username will remain "admin") -# adminPassword: admin -# currentAdminPassword: admin -# The above values can be also provided by a secret that contains "password" and "currentPassword" as keys. You can generate such a secret in your cluster -# using "kubectl create secret generic admin-password-secret-name --from-literal=password=admin --from-literal=currentPassword=admin" -# adminPasswordSecretName: "" -# # Reuse default initcontainers.securityContext that match restricted pod security standard -# # securityContext: {} -# resources: -# limits: -# cpu: 100m -# memory: 128Mi -# requests: -# cpu: 100m -# memory: 128Mi -# curlContainerImage: curlimages/curl:8.2.1 -# adminJobAnnotations: {} -# deprecated please use sonarWebContext at the value top level -# sonarWebContext: / - -terminationGracePeriodSeconds: 60 diff --git a/helm-overrides/k8s-admin-prd-ase1/sonarqube/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/sonarqube/custom-values.yaml deleted file mode 100644 index 5144a28..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/sonarqube/custom-values.yaml +++ /dev/null @@ -1,650 +0,0 @@ -# Default values for sonarqube. -# This is a YAML-formatted file. -# Declare variables to be passed into your templates. - -# If the deployment Type is set to Deployment sonarqube is deployed as a replica set. -deploymentType: "StatefulSet" -labels: - bu: "infra" - team: "devops" - service: "sonarqube-prd" - env: "prd" - priority: "p0" - type: "sonarqube" - -# There should not be more than 1 sonarqube instance connected to the same database. Please set this value to 1 or 0 (in case you need to scale down programmatically). -replicaCount: 1 - -# How many revisions to retain (Deployment ReplicaSets or StatefulSets) -revisionHistoryLimit: 10 - -# This will use the default deployment strategy unless it is overriden -deploymentStrategy: {} -# Uncomment this to scheduler pods on priority -# priorityClassName: "high-priority" - -## Use an alternate scheduler, e.g. "stork". -## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/ -## -# schedulerName: - -## Is this deployment for OpenShift? If so, we help with SCCs -OpenShift: - enabled: false - createSCC: true - -edition: "community" - -image: - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/devops/sonarqube - tag: 10.4.1-{{ .Values.edition }} - pullPolicy: Always - # If using a private repository, the imagePullSecrets to use - # pullSecrets: - # - name: my-repo-secret - -# Set security context for sonarqube pod -securityContext: - fsGroup: 0 - -# Set security context for sonarqube container -containerSecurityContext: - # Sonarqube dockerfile creates sonarqube user as UID and GID 1000 - # Those default are used to match pod security standard restricted as least privileged approach - allowPrivilegeEscalation: false - runAsNonRoot: true - runAsUser: 1000 - runAsGroup: 1000 - seccompProfile: - type: RuntimeDefault - # capabilities: - # drop: ["ALL"] - -# Settings to configure elasticsearch host requirements -elasticsearch: - # DEPRECATED: Use initSysctl.enabled instead - configureNode: false - bootstrapChecks: false - -service: - type: ClusterIP - externalPort: 9000 - internalPort: 9000 - labels: - annotations: {} - # May be used in example for internal load balancing in GCP: - # cloud.google.com/load-balancer-type: Internal - # loadBalancerSourceRanges: - # - 0.0.0.0/0 - # loadBalancerIP: 1.2.3.4 - -# Optionally create Network Policies -networkPolicy: - enabled: false - - # If you plan on using the jmx exporter, you need to define where the traffic is coming from - prometheusNamespace: "monitoring" - - # If you are using a external database and enable network Policies to be created - # you will need to explicitly allow egress traffic to your database - # expects https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.21/#networkpolicyspec-v1-networking-k8s-io - # additionalNetworkPolicys: - -# will be used as default for ingress path and probes path, will be injected in .Values.env as SONAR_WEB_CONTEXT -# if .Values.env.SONAR_WEB_CONTEXT is set, this value will be ignored -sonarWebContext: "" - -# also install the nginx ingress helm chart -nginx: - enabled: false - -ingress: - enabled: true - # Used to create an Ingress record. - hosts: - - name: sonarqube-prd.meeshogcp.in -#sonarProperties: -# sonar.auth.saml.enabled: true -# sonar.auth.saml.applicationId: sonarqube -# sonar.auth.saml.providerName: -# sonar.auth.saml.providerId: http://okta.url/ -# sonar.auth.saml.loginUrl: https://okta.url/sso/saml -# sonar.auth.saml.user.login: login -# sonar.auth.saml.user.name: name -# sonar.auth.saml.user.email: email -# sonar.auth.saml.group.name: groups -# sonar.auth.saml.certificate.secured: -# sonar.core.serverBaseURL: https://sonar.url - # Different clouds or configurations might need /* as the default path - # path: / - # For additional control over serviceName and servicePort - # serviceName: someService - # servicePort: somePort - # the pathType can be one of the following values: Exact|Prefix|ImplementationSpecific(default) - # pathType: ImplementationSpecific - annotations: - nginx.ingress.kubernetes.io/proxy-body-size: "20M" - # kubernetes.io/tls-acme: "true" - - # Set the ingressClassName on the ingress record - ingressClassName: nginx-internal - -# Additional labels for Ingress manifest file - # labels: - # traffic-type: external - # traffic-type: internal - tls: [] - # Secrets must be manually created in the namespace. To generate a self-signed certificate (and private key) and then create the secret in the cluster please refer to official documentation available at https://kubernetes.github.io/ingress-nginx/user-guide/tls/#tls-secrets - # - secretName: chart-example-tls - # hosts: - # - chart-example.local - -route: - enabled: false - host: "" - # Add tls section to secure traffic. TODO: extend this section with other secure route settings - # Comment this out if you want plain http route created. - tls: - termination: edge - - annotations: {} - # See Openshift/OKD route annotation - # https://docs.openshift.com/container-platform/4.10/networking/routes/route-configuration.html#nw-route-specific-annotations_route-configuration - # haproxy.router.openshift.io/timeout: 1m - - # Additional labels for Route manifest file - # labels: - # external: 'true' - -# Affinity for pod assignment -# Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity -affinity: {} - -# Tolerations for pod assignment -# Ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/ -# taint a node with the following command to mark it as not schedulable for new pods -# kubectl taint nodes sonarqube=true:NoSchedule -# The following statement will tolerate this taint and as such reverse a node for sonarqube -tolerations: - - key: "dedicated" - operator: "Equal" - value: "jenkins" - effect: "NoSchedule" - -# Node labels for pod assignment -# Ref: https://kubernetes.io/docs/user-guide/node-selection/ -# add a label to a node with the following command -# kubectl label node sonarqube=true -nodeSelector: - dedicated: "jenkins" - -# hostAliases allows the modification of the hosts file inside a container -hostAliases: [] -# - ip: "192.168.1.10" -# hostnames: -# - "example.com" -# - "www.example.com" - -readinessProbe: - initialDelaySeconds: 90 - periodSeconds: 30 - failureThreshold: 6 - # Note that timeoutSeconds was not respected before Kubernetes 1.20 for exec probes - timeoutSeconds: 1 - # If an ingress *path* other than the root (/) is defined, it should be reflected here - # A trailing "/" must be included - # deprecated please use sonarWebContext at the value top level - # sonarWebContext: / - -livenessProbe: - initialDelaySeconds: 90 - periodSeconds: 30 - failureThreshold: 6 - # Note that timeoutSeconds was not respected before Kubernetes 1.20 for exec probes - timeoutSeconds: 1 - # If an ingress *path* other than the root (/) is defined, it should be reflected here - # A trailing "/" must be included - # deprecated please use sonarWebContext at the value top level - # sonarWebContext: / - -startupProbe: - initialDelaySeconds: 180 - periodSeconds: 10 - failureThreshold: 24 - # Note that timeoutSeconds was not respected before Kubernetes 1.20 for exec probes - timeoutSeconds: 1 - # If an ingress *path* other than the root (/) is defined, it should be reflected here - # A trailing "/" must be included - # deprecated please use sonarWebContext at the value top level - # sonarWebContext: / - -initContainers: - # image: busybox:1.36 - # We allow the init containers to have a separate security context declaration because - # the initContainer may not require the same as SonarQube. - # Those default are used to match pod security standard restricted as least privileged approach - securityContext: - allowPrivilegeEscalation: false - runAsNonRoot: true - runAsUser: 1000 - runAsGroup: 1000 - seccompProfile: - type: RuntimeDefault - capabilities: - drop: ["ALL"] - # We allow the init containers to have a separate resources declaration because - # the initContainer does not take as much resources. - resources: {} - -# Extra init containers to e.g. download required artifacts -extraInitContainers: {} - -## Array of extra containers to run alongside the sonarqube container -## -## Example: -## - name: myapp-container -## image: busybox -## command: ['sh', '-c', 'echo Hello && sleep 3600'] -## -extraContainers: [] - -## Provide a secret containing one or more certificate files in the keys that will be added to cacerts -## The cacerts file will be set via SONARQUBE_WEB_JVM_OPTS and SONAR_CE_JAVAOPTS -## -caCerts: - enabled: false - image: adoptopenjdk/openjdk11:alpine - secret: your-secret - -initSysctl: - enabled: false - vmMaxMapCount: 524288 - fsFileMax: 131072 - nofile: 131072 - nproc: 8192 - # image: busybox:1.36 - securityContext: - # Compatible with podSecurity standard privileged - privileged: true - # resources: {} - -# This should not be required anymore, used to chown/chmod folder created by faulty CSI driver that are not applying properly POSIX fsgroup. -initFs: - enabled: false - # Image: busybox:1.36 - # Compatible with podSecurity standard baseline. - securityContext: - privileged: false - runAsNonRoot: false - runAsUser: 0 - runAsGroup: 0 - seccompProfile: - type: RuntimeDefault - capabilities: - drop: ["ALL"] - add: ["CHOWN"] - -prometheusExporter: - enabled: false - # jmx_prometheus_javaagent version to download from Maven Central - version: "0.17.2" - # Alternative full download URL for the jmx_prometheus_javaagent.jar (overrides prometheusExporter.version) - # downloadURL: "" - # if you need to ignore TLS certificates for whatever reason enable the following flag - noCheckCertificate: false - - # Ports for the jmx prometheus agent to export metrics at - webBeanPort: 8000 - ceBeanPort: 8001 - - config: - rules: - - pattern: ".*" - # Overrides config for the CE process Prometheus exporter (by default, the same rules are used for both the Web and CE processes). - # ceConfig: - # rules: - # - pattern: ".*" - # image: curlimages/curl:8.2.1 - # For use behind a corporate proxy when downloading prometheus - # httpProxy: "" - # httpsProxy: "" - # noProxy: "" - # Reuse default initcontainers.securityContext that match restricted pod security standard - # securityContext: {} - -prometheusMonitoring: - # Generate a Prometheus Pod Monitor (https://github.com/coreos/prometheus-operator) - # - podMonitor: - # Create PodMonitor Resource for Prometheus scraping - enabled: false - # Specify a custom namespace where the PodMonitor will be created - namespace: "sonarqube" - # Specify the interval how often metrics should be scraped - interval: 30s - # Specify the timeout after a scrape is ended - # scrapeTimeout: "" - # Name of the label on target services that prometheus uses as job name - # jobLabel: "" - -# List of plugins to install. -# For example: -# plugins: -# install: -# - "https://github.com/AmadeusITGroup/sonar-stash/releases/download/1.3.0/sonar-stash-plugin-1.3.0.jar" -# - "https://github.com/SonarSource/sonar-ldap/releases/download/2.2-RC3/sonar-ldap-plugin-2.2.0.601.jar" -# -plugins: - image: curlimages/curl:8.2.1 - install: - - https://github.com/mc1arke/sonarqube-community-branch-plugin/releases/download/1.17.1/sonarqube-community-branch-plugin-1.17.1.jar - noCheckCertificate: false - -env: - - name: TZ - value: Asia/Kolkata - - name: SONAR_WEB_JAVAOPTS - value: "-javaagent:/opt/sonarqube/extensions/plugins/sonarqube-community-branch-plugin-1.17.1.jar=web" - - name: SONAR_CE_JAVAOPTS - value: "-javaagent:/opt/sonarqube/extensions/plugins/sonarqube-community-branch-plugin-1.17.1.jar=ce" - - # For use behind a corporate proxy when downloading plugins - # httpProxy: "" - # httpsProxy: "" - # noProxy: "" - - # resources: {} - - # .netrc secret file with a key "netrc" to use basic auth while downloading plugins - # netrcCreds: "" - - # Set to true to not validate the server's certificate to download plugin - - # Reuse default initcontainers.securityContext that match restricted pod security standard - # securityContext: {} - -## (DEPRECATED) The following value sets SONAR_WEB_JAVAOPTS (e.g., jvmOpts: "-Djava.net.preferIPv4Stack=true"). However, this is deprecated, please set SONAR_WEB_JAVAOPTS or sonar.web.javaOpts directly instead. -jvmOpts: "" - -## (DEPRECATED) The following value sets SONAR_CE_JAVAOPTS. However, this is deprecated, please set SONAR_CE_JAVAOPTS or sonar.ce.javaOpts directly instead. -jvmCeOpts: "" - -## a monitoring passcode needs to be defined in order to get reasonable probe results -# not setting the monitoring passcode will result in a deployment that will never be ready -monitoringPasscode: "define_it" -# Alternatively, you can define the passcode loading it from an existing secret specifying the right key -# monitoringPasscodeSecretName: "pass-secret-name" -# monitoringPasscodeSecretKey: "pass-key" - -## Environment variables to attach to the pods -## -# env: -# # If you use a different ingress path from /, you have to add it here as the value of SONAR_WEB_CONTEXT -# - name: SONAR_WEB_CONTEXT -# value: /sonarqube -# - name: VARIABLE -# value: my-value - -# Set annotations for pods -annotations: {} - -## We usually don't make specific ressource recommandations, as they are heavily dependend on -## The usage of SonarQube and the surrounding infrastructure. -## Adjust these values to your needs, but make sure that the memory limit is never under 4 GB -resources: - limits: - cpu: 4 - memory: 10Gi - requests: - cpu: 3 - memory: 8Gi - -persistence: - enabled: true - ## Set annotations on pvc - annotations: {} - - ## Specify an existing volume claim instead of creating a new one. - ## When using this option all following options like storageClass, accessMode and size are ignored. - # existingClaim: - - ## If defined, storageClassName: - ## If set to "-", storageClassName: "", which disables dynamic provisioning - ## If undefined (the default) or set to null, no storageClassName spec is - ## set, choosing the default provisioner. (gp2 on AWS, standard on - ## GKE, AWS & OpenStack) - ## - storageClass: - accessMode: ReadWriteOnce - size: 5Gi - uid: 1000 - guid: 0 - - ## Specify extra volumes. Refer to ".spec.volumes" specification : https://kubernetes.io/fr/docs/concepts/storage/volumes/ - volumes: [] - ## Specify extra mounts. Refer to ".spec.containers.volumeMounts" specification : https://kubernetes.io/fr/docs/concepts/storage/volumes/ - mounts: [] - -# In case you want to specify different resources for emptyDir than {} -emptyDir: {} - # Example of resouces that might be used: - # medium: Memory - # sizeLimit: 16Mi - -# A custom sonar.properties file can be provided via dictionary. -# For example: -# sonarProperties: -# sonar.forceAuthentication: true -# sonar.security.realm: LDAP -# ldap.url: ldaps://organization.com - -# Additional sonar properties to load from a secret with a key "secret.properties" (must be a string) -# sonarSecretProperties: - -# Kubernetes secret that contains the encryption key for the sonarqube instance. -# The secret must contain the key 'sonar-secret.txt'. -# The 'sonar.secretKeyPath' property will be set automatically. -# sonarSecretKey: "settings-encryption-secret" - -## Override JDBC values -## for external Databases -jdbcOverwrite: - # If enable the JDBC Overwrite, make sure to set `postgresql.enabled=false` - enable: false - # The JDBC url of the external DB - jdbcUrl: "jdbc:postgresql://myPostgress/myDatabase?socketTimeout=1500" - # The DB user that should be used for the JDBC connection - jdbcUsername: "sonarUser" - # Use this if you don't mind the DB password getting stored in plain text within the values file - jdbcPassword: "sonarPass" - ## Alternatively, use a pre-existing k8s secret containing the DB password - # jdbcSecretName: "sonarqube-jdbc" - ## and the secretValueKey of the password found within that secret - # jdbcSecretPasswordKey: "jdbc-password" - -## (DEPRECATED) Configuration values for postgresql dependency -## ref: https://github.com/bitnami/charts/blob/master/bitnami/postgresql/README.md -postgresql: - # Enable to deploy the bitnami PostgreSQL chart - enabled: true - primary: - # tolerations: - # - key: "dedicated" - # operator: "Equal" - # value: "jenkins" - # effect: "NoSchedule" - - # nodeSelector: - # dedicated: "jenkins" - labels: - bu: "infra" - team: "devops" - service: "sonarqube-prd" - env: "prd" - priority: "p0" - type: "sonarqube-psql-master" - podLabels: - bu: "infra" - team: "devops" - service: "sonarqube-prd" - env: "prd" - priority: "p0" - type: "sonarqube-psql-master" - readReplicas: - # tolerations: - # - key: "dedicated" - # operator: "Equal" - # value: "jenkins" - # effect: "NoSchedule" - - # nodeSelector: - # dedicated: "jenkins" - labels: - bu: "infra" - team: "devops" - service: "sonarqube-prd" - env: "prd" - priority: "p0" - type: "sonarqube-psql-slave" - podLabels: - bu: "infra" - team: "devops" - service: "sonarqube-prd" - env: "prd" - priority: "p0" - type: "sonarqube-psql-slave" - ## postgresql Chart global settings - # global: - # imageRegistry: '' - # imagePullSecrets: '' - ## bitnami/postgres image tag - # image: - # tag: 11.7.0-debian-10-r9 - # existingSecret Name of existing secret to use for PostgreSQL passwords - # The secret has to contain the keys postgresql-password which is the password for postgresqlUsername when it is - # different of postgres, postgresql-postgres-password which will override postgresqlPassword, - # postgresql-replication-password which will override replication.password and postgresql-ldap-password which will be - # used to authenticate on LDAP. The value is evaluated as a template. - # existingSecret: "" - # - # The bitnami chart enforces the key to be "postgresql-password". This value is only here for historic purposes - # existingSecretPasswordKey: "postgresql-password" - postgresqlUsername: "sonarUser" - postgresqlPassword: "sonarPass" - postgresqlDatabase: "sonarDB" - # Specify the TCP port that PostgreSQL should use - service: - port: 5432 - resources: - limits: - cpu: "2" - memory: 6Gi - requests: - cpu: "2" - memory: 4Gi - persistence: - enabled: true - accessMode: ReadWriteOnce - size: 2Gi - storageClass: - securityContext: - # For standard Kubernetes deployment, set enabled=true - # If using OpenShift, enabled=false for restricted SCC and enabled=true for anyuid/nonroot SCC - enabled: true - # fsGroup specification below are not applied if enabled=false. enabled=false is the required setting for OpenShift "restricted SCC" to work successfully. - # postgresql dockerfile sets user as 1001 - fsGroup: 1001 - containerSecurityContext: - # For standard Kubernetes deployment, set enabled=true - # If using OpenShift, enabled=false for restricted SCC and enabled=true for anyuid/nonroot SCC - enabled: true - # runAsUser specification below are not applied if enabled=false. enabled=false is the required setting for OpenShift "restricted SCC" to work successfully. - # postgresql dockerfile sets user as 1001, the rest aim at making it compatible with restricted pod security standard. - runAsUser: 1001 - allowPrivilegeEscalation: false - runAsNonRoot: true - seccompProfile: - type: RuntimeDefault - capabilities: - drop: ["ALL"] - volumePermissions: - # For standard Kubernetes deployment, set enabled=false - # For OpenShift, set enabled=true and ensure to set volumepermissions.securitycontext.runAsUser below. - enabled: false - # if using restricted SCC set runAsUser: "auto" and if running under anyuid/nonroot SCC - runAsUser needs to match runAsUser above - securityContext: - runAsUser: 0 - shmVolume: - chmod: - enabled: false - serviceAccount: - ## If enabled = true, and name is not set, postgreSQL will create a serviceAccount - enabled: false - # name: - -# Additional labels to add to the pods: -# podLabels: -# key: value -podLabels: {} -# For compatibility with 8.0 replace by "/opt/sq" -# For compatibility with 8.2, leave the default. They changed it back to /opt/sonarqube -sonarqubeFolder: /opt/sonarqube - -tests: - image: "" - enabled: true - resources: {} - -# For OpenShift set create=true to ensure service account is created. -serviceAccount: - create: false - # name: - # automountToken: false # default - ## Annotations for the Service Account - annotations: {} - -# extraConfig is used to load Environment Variables from Secrets and ConfigMaps -# which may have been written by other tools, such as external orchestrators. -# -# These Secrets/ConfigMaps are expected to contain Key/Value pairs, such as: -# -# apiVersion: v1 -# kind: ConfigMap -# metadata: -# name: external-sonarqube-opts -# data: -# SONARQUBE_JDBC_USERNAME: foo -# SONARQUBE_JDBC_URL: jdbc:postgresql://db.example.com:5432/sonar -# -# These vars can then be injected into the environment by uncommenting the following: -# -# extraConfig: -# configmaps: -# - external-sonarqube-opts - -extraConfig: - secrets: [] - configmaps: [] - -# account: -# The values can be set to define the current and the (new) custom admin passwords at the startup (the username will remain "admin") - # adminPassword: admin - # currentAdminPassword: admin -# The above values can be also provided by a secret that contains "password" and "currentPassword" as keys. You can generate such a secret in your cluster -# using "kubectl create secret generic admin-password-secret-name --from-literal=password=admin --from-literal=currentPassword=admin" -# adminPasswordSecretName: "" -# # Reuse default initcontainers.securityContext that match restricted pod security standard -# # securityContext: {} -# resources: -# limits: -# cpu: 100m -# memory: 128Mi -# requests: -# cpu: 100m -# memory: 128Mi -# curlContainerImage: curlimages/curl:8.2.1 -# adminJobAnnotations: {} -# deprecated please use sonarWebContext at the value top level -# sonarWebContext: / - -terminationGracePeriodSeconds: 60 diff --git a/helm-overrides/k8s-admin-prd-ase1/superset/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/superset/custom-values.yaml deleted file mode 100644 index b8aa4f2..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/superset/custom-values.yaml +++ /dev/null @@ -1,245 +0,0 @@ -bootstrapScript: | - #!/bin/bash - apt-get update && apt-get install -y python3-dev default-libmysqlclient-dev - rm -rf /var/lib/apt/lists/* - pip install --upgrade pip - pip install \ - sqlalchemy-bigquery \ - cachelib \ - redis \ - authlib \ - packaging==23.2 \ - clickhouse-connect \ - sqlalchemy==1.4.36 && \ - if [ ! -f ~/bootstrap ]; then echo "Running Superset with uid {{ .Values.runAsUser }}" > ~/bootstrap; fi - -extraEnv: - GUNICORN_TIMEOUT: 900 - SERVER_WORKER_AMOUNT: 4 - WORKER_MAX_REQUESTS: 0 - WORKER_MAX_REQUESTS_JITTER: 0 - SERVER_THREADS_AMOUNT: 20 - GUNICORN_KEEPALIVE: 2 - SERVER_LIMIT_REQUEST_LINE: 0 - SERVER_LIMIT_REQUEST_FIELD_SIZE: 0 - -configOverrides: - sql_query_settings: | - SQL_MAX_ROW = 1000000 - SQLLAB_CTAS_NO_LIMIT = True - FEATURE_FLAGS = {"ALLOW_FULL_CSV_EXPORT": True, "DRUID_JOINS": True, "ALERT_REPORTS": True, "ALLOW_ADHOC_SUBQUERY": True, "DASHBOARD_VIRTUALIZATION": True, "DYNAMIC_PLUGINS": True, "DRILL_TO_DETAIL": True, "DRILL_BY": True, "ENABLE_TEMPLATE_PROCESSING": True, "DASHBOARD_NATIVE_FILTERS": True, "DASHBOARD_CROSS_FILTERS": True, "EMBEDDED_SUPERSET": True, "DASHBOARD_RBAC": False} - metatda_db_settings: - SQLALCHEMY_DATABASE_URI = f"mysql+mysqldb://{env('DB_USER')}:{env('DB_PASS')}@{env('DB_HOST')}:{env('DB_PORT')}/{env('DB_NAME')}" - superset_config.py: | - import logging - import os - from datetime import timedelta - from typing import Optional - from cachelib.file import FileSystemCache - from celery.schedules import crontab - - REDIS_HOST = os.environ.get("REDIS_HOST"), - REDIS_PORT = "6379" - REDIS_CELERY_DB = "0" - REDIS_RESULTS_DB = "1" - - CACHE_CONFIG = { - "CACHE_TYPE": "RedisCache", - "CACHE_DEFAULT_TIMEOUT": 86400, - "CACHE_KEY_PREFIX": "superset_", - "CACHE_REDIS_HOST": REDIS_HOST, - "CACHE_REDIS_PORT": REDIS_PORT, - "CACHE_REDIS_DB": REDIS_RESULTS_DB, - } - DATA_CACHE_CONFIG = CACHE_CONFIG - - class CeleryConfig: - broker_url = "redis://superset-infra-admin-prd-redis-master.prd-superset-infra.svc.cluster.local:6379/0" - imports = ('superset.sql_lab', "superset.tasks", "superset.tasks.thumbnails",) - result_backend = "redis://superset-infra-admin-prd-redis-master.prd-superset-infra.svc.cluster.local:6379/1" - CELERYD_LOG_LEVEL = "DEBUG" - worker_prefetch_multiplier = 10 - task_acks_late = True - task_annotations = { - 'sql_lab.get_sql_results': { - 'rate_limit': '100/s', - }, - 'email_reports.send': { - 'rate_limit': '1/s', - 'time_limit': 600, - 'soft_time_limit': 600, - 'ignore_result': True, - }, - } - - CELERY_CONFIG = CeleryConfig - - extend_timeout: | - # Extend timeout to allow long running queries. - SQLLAB_TIMEOUT = 300 - SQLLAB_ASYNC_TIME_LIMIT_SEC = 900 - SUPERSET_WEBSERVER_TIMEOUT = 300 - enable_oauth: | - import os - from flask_appbuilder.security.manager import AUTH_OID, AUTH_REMOTE_USER, AUTH_DB, AUTH_LDAP, AUTH_OAUTH - basedir = os.path.abspath(os.path.dirname(__file__)) - ENABLE_PROXY_FIX = True - AUTH_TYPE = AUTH_OAUTH - PREFERRED_URL_SCHEME = "https" - OAUTH_HOME_DOMAIN = "meesho.com" - CSRF_ENABLED = True - OAUTH_PROVIDERS = [ - { - "name": "google", - "whitelist": [ "@meesho.com" ], - "icon": "fa-google", - "token_key": "access_token", - "remote_app": { - "client_id": os.environ.get("GOOGLE_KEY"), - "client_secret": os.environ.get("GOOGLE_SECRET"), - "api_base_url": "https://www.googleapis.com/oauth2/v2/", - "client_kwargs": {"scope": "email profile"}, - "request_token_url": None, - "access_token_url": "https://accounts.google.com/o/oauth2/token", - "authorize_url": "https://accounts.google.com/o/oauth2/auth", - "authorize_params": {"hd": "meesho.com"} - } - } - ] - # Map Authlib roles to superset roles - AUTH_ROLE_ADMIN = 'Admin' - AUTH_ROLE_PUBLIC = 'Public' - # Will allow user self registration, allowing to create Flask users from Authorized User - AUTH_USER_REGISTRATION = True - # The default user self registration role - AUTH_USER_REGISTRATION_ROLE = "read_user_basic" - cors: | - ENABLE_CORS = True - CORS_OPTIONS = { - 'supports_credentials': True, - 'allow_headers': [ - '*', - ], - 'resources': [ - '*' - ], - 'origins': ['*'], - } - WTF_CSRF_ENABLED = False - TALISMAN_ENABLED = False - ENABLE_PROXY_FIX = True - extend_timeout: | - SUPERSET_WEBSERVER_TIMEOUT = 300 - secret: | - SECRET_KEY = os.getenv("SECRET_KEY") - -ingress: - enabled: true - ingressClassName: nginx-external - annotations: - nginx.ingress.kubernetes.io/force-ssl-redirect: "false" - nginx.ingress.kubernetes.io/ssl-redirect: "true" - nginx.ingress.kubernetes.io/rewrite-target: / - nginx.ingress.kubernetes.io/proxy-connect-timeout: "300" - nginx.ingress.kubernetes.io/proxy-read-timeout: "300" - nginx.ingress.kubernetes.io/proxy-send-timeout: "300" - path: / - pathType: Prefix - hosts: - - superset-infra-prd.meeshogcp.in - -labels: - priority: p1 - env: prd - team: devops - bu: infra - service: superset-infra - -resources: - limits: - cpu: 1000m - memory: 1000Mi - requests: - cpu: 1000m - memory: 1000Mi - -supersetNode: - replicas: - replicaCount: 2 - connections: - redis_host: 'superset-infra-admin-prd-redis-master.prd-superset-infra.svc.cluster.local' - redis_port: "6379" - - affinity: {} - resources: - limits: - cpu: 3 - memory: 8000Mi - requests: - cpu: 2000m - memory: 4000Mi - -supersetWorker: - replicas: - replicaCount: 2 - resources: - limits: - cpu: 2000m - memory: 6000Mi - requests: - cpu: 1000m - memory: 3000Mi - -init: - enabled: true - loadExamples: false - createAdmin: true - adminUser: - username: admin - firstname: Superset - lastname: Admin - email: devops@meesho.com - password: superset - -celery: - enabled: true - broker_url: 'redis://superset-infra-admin-prd-redis-master.prd-superset-infra.svc.cluster.local:6379/0' - result_backend: 'redis://superset-infra-admin-prd-redis-master.prd-superset-infra.svc.cluster.local:6379/1' - worker: - replicas: 1 # Number of Celery workers - resources: - limits: - cpu: 500m - memory: 2000Mi - requests: - cpu: 100m - memory: 1000Mi - - -postgresql: - enabled: false - -redis: - enabled: true - image: - registry: asia-southeast1-docker.pkg.dev - repository: meesho-devops-admin-0622/admin/devops/bitnami/redis - tag: "7.0.10-debian-11-r4" - pullPolicy: IfNotPresent - architecture: standalone - auth: - enabled: false - master: - resources: - limits: - cpu: 2 - memory: 8000Mi - requests: - cpu: 1 - memory: 4000Mi - -tolerations: - - key: dedicated - operator: "Equal" - value: devops - effect: "NoSchedule" diff --git a/helm-overrides/k8s-admin-prd-ase1/tempo-distributed/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/tempo-distributed/custom-values.yaml deleted file mode 100644 index cc34814..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/tempo-distributed/custom-values.yaml +++ /dev/null @@ -1,209 +0,0 @@ -fullnameOverride: "tempo" - -serviceAccount: - annotations: { - iam.gke.io/gcp-service-account: sa-infr-sre-obs-prd@meesho-admin-prd-0622.iam.gserviceaccount.com - } - -traces: - otlp: - http: - enabled: true - grpc: - enabled: true - receiverConfig: - max_recv_msg_size_mib: 50 - -storage: - trace: - backend: gcs - gcs: - bucket_name: "tempo_data" - prefix: "trace" - pool: - max_workers: 300 - queue_depth: 100000 - -global_overrides: - defaults: - global: - max_bytes_per_trace: 0 - # metrics_generator: - # processors: [span-metrics,service-graphs] - ingestion: - max_traces_per_user: 0 - burst_size_bytes: 1000000000 - rate_limit_bytes: 1000000000 - -server: - grpc_server_max_recv_msg_size: 500000000 - grpc_server_max_send_msg_size: 500000000 - http_server_read_timeout: 2m - http_server_write_timeout: 2m - -distributor: - replicas: 1 - resources: - limits: - cpu: 31 - memory: 30Gi - requests: - cpu: 30 - memory: 27Gi - nodeSelector: - dedicated: "tempo-highcpu" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "tempo-highcpu" - effect: "NoSchedule" - -ingester: - replicas: 2 - persistence: - enabled: true - size: 500Gi - storageClass: "premium-rwo" - resources: - limits: - cpu: 31 - memory: 235Gi - requests: - cpu: 28 - memory: 230Gi - nodeSelector: - dedicated: "tempo-highmem-h" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "tempo-highmem-h" - effect: "NoSchedule" - -queryFrontend: - config: - max_outstanding_per_tenant: 8000 - max_batch_size: 5 - search: - concurrent_jobs: 8000 - replicas: 1 - resources: - limits: - cpu: 1 - memory: 1Gi - requests: - cpu: 1 - memory: 1Gi - nodeSelector: - dedicated: "tempo-standard-s" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "tempo-standard-s" - effect: "NoSchedule" - -querier: - config: - trace_by_id: - query_timeout: 120s - search: - query_timeout: 300s - max_concurrent_queries: 100 - frontend_worker: - grpc_client_config: - max_send_msg_size: 100000000 - replicas: 1 - resources: - limits: - cpu: 31 - memory: 30Gi - requests: - cpu: 30 - memory: 27Gi - nodeSelector: - dedicated: "tempo-highcpu" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "tempo-highcpu" - effect: "NoSchedule" - -compactor: - config: - compaction: - block_retention: 72h - replicas: 6 - resources: - limits: - cpu: 3 - memory: 10Gi - requests: - cpu: 2 - memory: 8Gi - nodeSelector: - dedicated: "tempo-standard-s" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "tempo-standard-s" - effect: "NoSchedule" - -memcached: - replicas: 1 - allocatedMemory: 51200 - resources: - limits: - memory: 56320Mi - requests: - cpu: 500m - memory: 56320Mi - nodeSelector: - dedicated: "tempo-highmem" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "tempo-highmem" - effect: "NoSchedule" - -metricsGenerator: - config: - storage: - remote_write: - - url: "http://mimir-nginx.mimir-distributed.svc.clusterset.local/api/v1/push" - send_exemplars: true - headers: - X-Scope-OrgID: anonymous - enabled: false - replicas: 1 - resources: - limits: - cpu: 11 - memory: 22Gi - requests: - cpu: 10 - memory: 20Gi - nodeSelector: - dedicated: "tempo-standard-s" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "tempo-standard-s" - effect: "NoSchedule" - -gateway: - enabled: true - ingress: - enabled: true - ingressClassName: nginx-internal - hosts: - - host: tempo.meeshogcp.in - paths: - - path: / - pathType: Prefix - tls: [] - nodeSelector: - dedicated: "tempo-standard-s" - tolerations: - - key: "dedicated" - operator: "Equal" - value: "tempo-standard-s" - effect: "NoSchedule" \ No newline at end of file diff --git a/helm-overrides/k8s-admin-prd-ase1/uptime-kuma/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/uptime-kuma/custom-values.yaml deleted file mode 100644 index 1a529ff..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/uptime-kuma/custom-values.yaml +++ /dev/null @@ -1,168 +0,0 @@ -# Default values for uptime-kuma. -# This is a YAML-formatted file. -# Declare variables to be passed into your templates. - -image: - repository: louislam/uptime-kuma - pullPolicy: IfNotPresent - # Overrides the image tag whose default is the chart appVersion. - tag: "1.21.3-debian" - -dedicatedValue: true - -imagePullSecrets: [] -nameOverride: "" -fullnameOverride: prd-infra-uptime-kuma - -labels: - bu: "infra" - team: "sre" - service: "prd-infra-uptime-kuma" - env: "prd" - priority: "p0" - type: "uptime-kuma" - arch: "amd64" - runpod: "ondemand" - -# If this option is set to false a StateFulset instead of a Deployment is used -useDeploy: true - -serviceAccount: - # Specifies whether a service account should be created - create: false - # Annotations to add to the service account - annotations: {} - # The name of the service account to use. - # If not set and create is true, a name is generated using the fullname template - name: "" - -podAnnotations: {} -podLabels: {} - # app: uptime-kuma -podEnv: - # a default port must be set. required by container - - name: "UPTIME_KUMA_PORT" - value: "3001" - -podSecurityContext: {} - # fsGroup: 2000 - -securityContext: {} - # capabilities: - # drop: - # - ALL - # readOnlyRootFilesystem: true - # runAsNonRoot: true - # runAsUser: 1000 - -service: - type: ClusterIP - port: 3001 - nodePort: - annotations: {} - -ingress: - enabled: true - className: nginx-internal - extraLabels: {} - # vhost: uptime-kuma.company.corp - annotations: - nginx.ingress.kubernetes.io/proxy-read-timeout: "3600" - nginx.ingress.kubernetes.io/proxy-send-timeout: "3600" - nginx.ingress.kubernetes.io/server-snippets: | - location / { - proxy_set_header Upgrade $http_upgrade; - proxy_http_version 1.1; - proxy_set_header X-Forwarded-Host $http_host; - proxy_set_header X-Forwarded-Proto $scheme; - proxy_set_header X-Forwarded-For $remote_addr; - proxy_set_header Host $host; - proxy_set_header Connection "upgrade"; - proxy_set_header X-Real-IP $remote_addr; - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; - proxy_set_header Upgrade $http_upgrade; - proxy_cache_bypass $http_upgrade; - } - hosts: - - host: prd-infra-uptime-kuma.meeshogcp.in - paths: - - path: / - pathType: ImplementationSpecific - - tls: - [] - # - secretName: chart-example-tls - # hosts: - # - chart-example.local - -resources: - # We usually recommend not to specify default resources and to leave this as a conscious - # choice for the user. This also increases chances charts run on environments with little - # resources, such as Minikube. If you do want to specify resources, uncomment the following - # lines, adjust them as necessary, and remove the curly braces after 'resources:'. - # limits: - # cpu: 100m - # memory: 128Mi - requests: - cpu: 100m - memory: 128Mi - -nodeSelector: - dedicated: "vmselect-temp" - -tolerations: - - key: "dedicated" - operator: "Equal" - value: "vmselect-temp" - effect: "NoSchedule" - -affinity: {} - -livenessProbe: - enabled: true - timeoutSeconds: 2 - initialDelaySeconds: 15 - -readinessProbe: - enabled: true - initialDelaySeconds: 5 - -volume: - enabled: true - accessMode: ReadWriteOnce - size: 13Gi - # If you want to use a storage class other than the default, uncomment this - # line and define the storage class name - # storageClassName: meesho-gp3 - # Reuse your own pre-existing PVC. - existingClaim: "" - -strategy: - type: Recreate - -# Prometheus ServiceMonitor configuration -serviceMonitor: - enabled: false - # -- Scrape interval. If not set, the Prometheus default scrape interval is used. - interval: 60s - # -- Timeout if metrics can't be retrieved in given time interval - scrapeTimeout: 10s - # -- Scheme to use when scraping, e.g. http (default) or https. - scheme: ~ - # -- TLS configuration to use when scraping, only applicable for scheme https. - tlsConfig: {} - # -- Prometheus [RelabelConfigs] to apply to samples before scraping - relabelings: [] - # -- Prometheus [MetricRelabelConfigs] to apply to samples before ingestion - metricRelabelings: [] - # -- Prometheus ServiceMonitor selector, only select Prometheus's with these - # labels (if not set, select any Prometheus) - selector: {} - - # -- Namespace where the ServiceMonitor resource should be created, default is - # the same as the release namespace - namespace: ~ - # -- Additional labels to add to the ServiceMonitor - additionalLabels: {} - # -- Additional annotations to add to the ServiceMonitor - annotations: {} diff --git a/helm-overrides/k8s-admin-prd-ase1/vault/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/vault/custom-values.yaml deleted file mode 100644 index 69e6730..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/vault/custom-values.yaml +++ /dev/null @@ -1,67 +0,0 @@ -vault: - # This started as your live `helm get values vault -n vault` output, - # verbatim. One deliberate deviation from that since: injector.enabled - # is now false, not true. Secret delivery into pods is going through - # External Secrets Operator instead of Vault Agent Injector sidecars — - # nothing currently depends on the injector (claude.md's "Pending / not - # yet built" list has "Vault Agent Injector annotations for pulling - # secrets at pod start" — never actually wired up to any workload), so - # this removes an unused webhook rather than breaking anything live. - # - # Production mode (file storage, not dev), standalone (no HA/raft). - # Init/unseal are still NEVER in Git or scripted: run by hand and keep - # the unseal keys / root token in a password manager, same as claude.md - # says. This adoption only manages Vault's own Deployment config, not - # its data or seal state. - # - # `ui = true` in the HCL block AND top-level ui.enabled: true are BOTH - # required — this is claude.md issue #10 (Vault UI 404'd until both were - # set; the chart has two separate toggles for the same thing). - injector: - enabled: false - - server: - dataStorage: - enabled: true - # Must stay 5Gi to match the already-bound PVC — local-path-provisioner - # doesn't support volume expansion, same constraint as Gitea's PVC. - size: 5Gi - ha: - enabled: false - resources: - limits: - memory: 256Mi - requests: - cpu: 100m - memory: 128Mi - standalone: - enabled: true - config: | - ui = true - listener "tcp" { - address = "[::]:8200" - cluster_address = "[::]:8201" - tls_disable = "true" # lab only - enable TLS for anything beyond local testing - } - storage "file" { - path = "/vault/data" - } - - # No ingress config existed here before — access was via two raw, - # unmanaged Ingress objects (vault-ingress, vault-ingress-tailscale) - # that don't match anything Helm would generate, so this creates new - # GitOps-managed ones alongside them rather than adopting. Once these - # are confirmed working, the two raw ones should be deleted by hand - # (kubectl -n vault delete ingress vault-ingress vault-ingress-tailscale) - # — do that only after confirming, not before, so there's no access gap. - ingress: - enabled: true - ingressClassName: contour - hosts: - - host: "vault.192.168.1.7.nip.io" - paths: [] - - host: "vault.100.90.248.118.nip.io" - paths: [] - - ui: - enabled: true diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-agent-dr/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-agent-dr/custom-values.yaml deleted file mode 100644 index d365260..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-agent-dr/custom-values.yaml +++ /dev/null @@ -1,296 +0,0 @@ -# Default values for victoria-metrics-agent. -# This is a YAML-formatted file. -# Declare variables to be passed into your templates. - -replicaCount: 2 - -fullnameOverride: vmagent-infra-prd-dr -# vmagent scraping configuration: -# https://github.com/VictoriaMetrics/VictoriaMetrics/blob/master/docs/vmagent.md#how-to-collect-metrics-in-prometheus-format - -# use existing configmap if specified -# otherwise .config values will be used -configMap: "vmagent-infra-prd-dr-config" # Use same name as in fullnameOverride-config - -dedicatedValue: false - - -topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmagent-dr - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: DoNotSchedule - labelSelector: - matchLabels: - type: vmagent-dr - -# ref: https://kubernetes.io/docs/concepts/workloads/controllers/deployment/ -deployment: - enabled: true - - # vmagent pods will take almost 20-25 mins to work properly - minReadySeconds: 180 - progressDeadlineSeconds: 300 - - # ref: https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#strategy - strategy: {} - # rollingUpdate: - # maxSurge: 25% - # maxUnavailable: 25% - # type: RollingUpdate - -# ref: https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/ -statefulset: - enabled: false - # -- create cluster of vmagents. See https://docs.victoriametrics.com/vmagent.html#scraping-big-number-of-targets - # available since 1.77.2 version https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.77.2 - clusterMode: false - # -- replication factor for vmagent in cluster mode - replicationFactor: 1 - # ref: https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#update-strategies - updateStrategy: {} - # type: RollingUpdate - - -image: - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/vmagent - tag: v1.93.7-cluster # rewrites Chart.AppVersion - pullPolicy: IfNotPresent - -imagePullSecrets: [] -nameOverride: "" - -containerWorkingDir: "/" - -rbac: - create: true - # Note: The PSP will only be deployed, if Kubernetes (<1.25) supports the resource. - pspEnabled: true - annotations: {} - extraLabels: {} - # -- if true and `rbac.enabled`, will deploy a Role/Rolebinding instead of a ClusterRole/ClusterRoleBinding - namespaced: false - -serviceAccount: - # Specifies whether a service account should be created - create: true - # Annotations to add to the service account - annotations: { - iam.gke.io/gcp-service-account: sa-infr-sre-vmagent-prd@meesho-admin-prd-0622.iam.gserviceaccount.com - } - # The name of the service account to use. - # If not set and create is true, a name is generated using the fullname template - name: - -## See `kubectl explain poddisruptionbudget.spec` for more -## ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/ -podDisruptionBudget: - enabled: false - # minAvailable: 1 - # maxUnavailable: 1 - labels: {} - -# WARN: need to specify at least one remote write url or one multi tenant url -# remoteWriteUrls: [] -remoteWriteUrls: - # - https://vminsert-prd-infra.meeshogcp.in/insert/100/prometheus/api/v1/write - - http://vminsert-infra-prd-dr.victoriametrics.svc.cluster.local:8480/insert/100/prometheus/api/v1/write -# - http://prometheus:8480/insert/0/prometheus - -multiTenantUrls: [] -# multiTenantUrls: -# - http://vm-insert-az1:8480 -# - http://vm-insert-az2:8480 - -extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - promscrape.config.strictParse: false - promscrape.maxScrapeSize: 1000000000 - promscrape.minResponseSizeForStreamParse: 1000000 - loggerTimezone: "Asia/Kolkata" - - # Uncomment and specify the port if you want to support any of the protocols: - # https://victoriametrics.github.io/vmagent.html#features - # graphiteListenAddr: ":2003" - # influxListenAddr: ":8189" - # opentsdbHTTPListenAddr: ":4242" - # opentsdbListenAddr: ":4242" - -# -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables -env: - [] - # - name: VM_remoteWrite_basicAuth_password - # valueFrom: - # secretKeyRef: - # name: auth_secret - # key: password - -# extra Labels for Pods, Deployment and Statefulset -extraLabels: - bu: "infra" - team: "sre" - service: "vmagent-infra-prd" - env: "prd" - priority: "p0" - type: "vmagent-dr" - - - -# extra Labels for Pods only -podLabels: {} - -# Additional hostPath mounts -extraHostPathMounts: - [] - # - name: certs-dir - # mountPath: /etc/kubernetes/certs - # subPath: "" - # hostPath: /etc/kubernetes/certs - # readOnly: true - -# Extra Volumes for the pod -extraVolumes: - [] - # - name: example - # configMap: - # name: example - -# Extra Volume Mounts for the container -extraVolumeMounts: - [] - # - name: example - # mountPath: /example - -extraContainers: [] -# - name: config-reloader -# image: reloader-image - -podSecurityContext: - {} - # fsGroup: 2000 - -securityContext: - {} - # capabilities: - # drop: - # - ALL - # readOnlyRootFilesystem: true - # runAsNonRoot: true - # runAsUser: 1000 - -service: - enabled: true - annotations: {} - # cloud.google.com/neg: '{"exposed_ports": {"8429":{"name": "vmagent-infra-prd"}}}' - extraLabels: {} - clusterIP: "" - ## Ref: https://kubernetes.io/docs/user-guide/services/#external-ips - ## - externalIPs: [] - loadBalancerIP: "" - loadBalancerSourceRanges: [] - servicePort: 8429 - # nodePort: 30000 - type: ClusterIP - # Ref: https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip - # externalTrafficPolicy: "local" - # healthCheckNodePort: 0 -ingress: - enabled: true - ingressClassName: nginx-internal - annotations: - nginx.ingress.kubernetes.io/force-ssl-redirect: "false" - nginx.ingress.kubernetes.io/rewrite-target: / - nginx.ingress.kubernetes.io/ssl-redirect: "false" - # kubernetes.io/ingress.class: nginx - # kubernetes.io/tls-acme: 'true' - - extraLabels: {} - hosts: - - name: vmagent-infra-prd-dr.meeshogcp.in - path: / - port: http - tls: [] - # - secretName: vmagent-ingress-tls - # hosts: - # - vmagent.local - # For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName - # See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress - # ingressClassName: nginx - # -- pathType is only for k8s >= 1.1= - pathType: Prefix - -resources: - # We usually recommend not to specify default resources and to leave this as a conscious - # choice for the user. This also increases chances charts run on environments with little - # resources, such as Minikube. If you do want to specify resources, uncomment the following - # lines, adjust them as necessary, and remove the curly braces after 'resources:'. - # limits: - # cpu: 100m - # memory: 128Mi - requests: - cpu: 5 - memory: 5Gi - -# Annotations to be added to the deployment -annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8429" - -# Annotations to be added to pod -podAnnotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8429" - -nodeSelector: - dedicated: "vmagent-dr" - -tolerations: - - key: "dedicated" - operator: "Equal" - value: "vmagent-dr" - effect: "NoSchedule" - - -affinity: {} - -# -- priority class to be assigned to the pod(s) -priorityClassName: "" - -serviceMonitor: - enabled: false - extraLabels: {} - annotations: {} - relabelings: [] -# interval: 15s -# scrapeTimeout: 5s - # -- Commented. HTTP scheme to use for scraping. -# scheme: https - # -- Commented. TLS configuration to use when scraping the endpoint -# tlsConfig: -# insecureSkipVerify: true - -persistence: - enabled: false - # storageClassName: default - accessModes: - - ReadWriteOnce - size: 10Gi - annotations: {} - extraLabels: {} - existingClaim: "" - # -- Bind Persistent Volume by labels. Must match all labels of targeted PV. - matchLabels: {} - -# -- Extra scrape configs that will be appended to `config` -extraScrapeConfigs: [] - -# Add extra specs dynamically to this chart -extraObjects: [] diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-agent-fb/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-agent-fb/custom-values.yaml deleted file mode 100644 index 30e9ab5..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-agent-fb/custom-values.yaml +++ /dev/null @@ -1,272 +0,0 @@ -# Default values for victoria-metrics-agent. -# This is a YAML-formatted file. -# Declare variables to be passed into your templates. - -replicaCount: 1 - -fullnameOverride: vmagent-infra-prd-fb -# vmagent scraping configuration: -# https://github.com/VictoriaMetrics/VictoriaMetrics/blob/master/docs/vmagent.md#how-to-collect-metrics-in-prometheus-format - -# use existing configmap if specified -# otherwise .config values will be used -configMap: "vmagent-infra-prd-fb-config" # Use same name as in fullnameOverride-config - -dedicatedValue: false - -# Remove topology spread constraints -topologySpreadConstraints: [] - -# Modify deployment strategy -deployment: - enabled: true - -# Remove HPA -horizontalPodAutoscaler: - enabled: false - -# ref: https://kubernetes.io/docs/concepts/workloads/controllers/deployment/ -statefulset: - enabled: false - # -- create cluster of vmagents. See https://docs.victoriametrics.com/vmagent.html#scraping-big-number-of-targets - # available since 1.77.2 version https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.77.2 - clusterMode: false - # -- replication factor for vmagent in cluster mode - replicationFactor: 1 - # ref: https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#update-strategies - updateStrategy: {} - # type: RollingUpdate - - -image: - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/vmagent - tag: v1.93.7-cluster # rewrites Chart.AppVersion - pullPolicy: IfNotPresent - -imagePullSecrets: [] -nameOverride: "" - -containerWorkingDir: "/" - -rbac: - create: true - # Note: The PSP will only be deployed, if Kubernetes (<1.25) supports the resource. - pspEnabled: true - annotations: {} - extraLabels: {} - # -- if true and `rbac.enabled`, will deploy a Role/Rolebinding instead of a ClusterRole/ClusterRoleBinding - namespaced: false - -serviceAccount: - # Specifies whether a service account should be created - create: true - # Annotations to add to the service account - annotations: { - iam.gke.io/gcp-service-account: sa-infr-sre-vmagent-prd-fb@meesho-admin-prd-0622.iam.gserviceaccount.com - } - # The name of the service account to use. - # If not set and create is true, a name is generated using the fullname template - name: - -# Remove pod disruption budget -podDisruptionBudget: - enabled: false - -# WARN: need to specify at least one remote write url or one multi tenant url -# remoteWriteUrls: [] -remoteWriteUrls: - # - https://vminsert-prd-infra.meeshogcp.in/insert/100/prometheus/api/v1/write - # - http://vmsinglenode-infra-prd.victoriametrics.svc.cluster.local:8428/api/v1/write - - https://vmsinglenode-infra-prd.meeshogcp.in/api/v1/write -# - http://prometheus:8480/insert/0/prometheus - -multiTenantUrls: [] -# multiTenantUrls: -# - http://vm-insert-az1:8480 -# - http://vm-insert-az2:8480 - -extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - promscrape.config.strictParse: false - promscrape.maxScrapeSize: 1000000000 - promscrape.minResponseSizeForStreamParse: 1000000 - loggerTimezone: "Asia/Kolkata" - - # Uncomment and specify the port if you want to support any of the protocols: - # https://victoriametrics.github.io/vmagent.html#features - # graphiteListenAddr: ":2003" - # influxListenAddr: ":8189" - # opentsdbHTTPListenAddr: ":4242" - # opentsdbListenAddr: ":4242" - -# -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables -env: - [] - # - name: VM_remoteWrite_basicAuth_password - # valueFrom: - # secretKeyRef: - # name: auth_secret - # key: password - -# extra Labels for Pods, Deployment and Statefulset -extraLabels: - bu: "infra-fb" - team: "sre" - service: "vmagent-infra-prd-fb" - env: "prd" - priority: "p0" - type: "vmagent-fb" - - - -# extra Labels for Pods only -podLabels: {} - -# Additional hostPath mounts -extraHostPathMounts: - [] - # - name: certs-dir - # mountPath: /etc/kubernetes/certs - # subPath: "" - # hostPath: /etc/kubernetes/certs - # readOnly: true - -# Extra Volumes for the pod -extraVolumes: - [] - # - name: example - # configMap: - # name: example - -# Extra Volume Mounts for the container -extraVolumeMounts: - [] - # - name: example - # mountPath: /example - -extraContainers: [] -# - name: config-reloader -# image: reloader-image - -podSecurityContext: - {} - # fsGroup: 2000 - -securityContext: - {} - # capabilities: - # drop: - # - ALL - # readOnlyRootFilesystem: true - # runAsNonRoot: true - # runAsUser: 1000 - -service: - enabled: true - annotations: {} - # cloud.google.com/neg: '{"exposed_ports": {"8429":{"name": "vmagent-infra-prd"}}}' - extraLabels: {} - clusterIP: "" - ## Ref: https://kubernetes.io/docs/user-guide/services/#external-ips - ## - externalIPs: [] - loadBalancerIP: "" - loadBalancerSourceRanges: [] - servicePort: 8429 - # nodePort: 30000 - type: ClusterIP - # Ref: https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip - # externalTrafficPolicy: "local" - # healthCheckNodePort: 0 -ingress: - enabled: true - ingressClassName: nginx-internal - annotations: - nginx.ingress.kubernetes.io/force-ssl-redirect: "false" - nginx.ingress.kubernetes.io/rewrite-target: / - nginx.ingress.kubernetes.io/ssl-redirect: "false" - # kubernetes.io/ingress.class: nginx - # kubernetes.io/tls-acme: 'true' - - extraLabels: {} - hosts: - - name: vmagent-infra-prd-fb.meeshogcp.in - path: / - port: http - tls: [] - # - secretName: vmagent-ingress-tls - # hosts: - # - vmagent.local - # For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName - # See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress - # ingressClassName: nginx - # -- pathType is only for k8s >= 1.1= - pathType: Prefix - -# Modify resources -resources: - # We usually recommend not to specify default resources and to leave this as a conscious - # choice for the user. This also increases chances charts run on environments with little - # resources, such as Minikube. If you do want to specify resources, uncomment the following - # lines, adjust them as necessary, and remove the curly braces after 'resources:'. - requests: - cpu: 3 - memory: 1Gi - -# Annotations to be added to the deployment -annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8429" - -# Annotations to be added to pod -podAnnotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8429" - -nodeSelector: - dedicated: "vmstack-fb" - -tolerations: - - key: "dedicated" - operator: "Equal" - value: "vmstack-fb" - effect: "NoSchedule" - - -affinity: {} - -# -- priority class to be assigned to the pod(s) -priorityClassName: "" - -serviceMonitor: - enabled: false - extraLabels: {} - annotations: {} - relabelings: [] -# interval: 15s -# scrapeTimeout: 5s - # -- Commented. HTTP scheme to use for scraping. -# scheme: https - # -- Commented. TLS configuration to use when scraping the endpoint -# tlsConfig: -# insecureSkipVerify: true - -persistence: - enabled: false - # storageClassName: default - accessModes: - - ReadWriteOnce - size: 10Gi - annotations: {} - extraLabels: {} - existingClaim: "" - # -- Bind Persistent Volume by labels. Must match all labels of targeted PV. - matchLabels: {} - -# -- Extra scrape configs that will be appended to `config` -extraScrapeConfigs: [] - -# Add extra specs dynamically to this chart -extraObjects: [] diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-agent/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-agent/custom-values.yaml deleted file mode 100644 index a11ef9c..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-agent/custom-values.yaml +++ /dev/null @@ -1,296 +0,0 @@ -# Default values for victoria-metrics-agent. -# This is a YAML-formatted file. -# Declare variables to be passed into your templates. - -replicaCount: 2 - -fullnameOverride: vmagent-infra-prd -# vmagent scraping configuration: -# https://github.com/VictoriaMetrics/VictoriaMetrics/blob/master/docs/vmagent.md#how-to-collect-metrics-in-prometheus-format - -# use existing configmap if specified -# otherwise .config values will be used -configMap: "vmagent-infra-prd-config" # Use same name as in fullnameOverride-config - -dedicatedValue: false - - -topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmagent - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: DoNotSchedule - labelSelector: - matchLabels: - type: vmagent - -# ref: https://kubernetes.io/docs/concepts/workloads/controllers/deployment/ -deployment: - enabled: true - - # vmagent pods will take almost 20-25 mins to work properly - minReadySeconds: 180 - progressDeadlineSeconds: 300 - - # ref: https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#strategy - strategy: {} - # rollingUpdate: - # maxSurge: 25% - # maxUnavailable: 25% - # type: RollingUpdate - -# ref: https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/ -statefulset: - enabled: false - # -- create cluster of vmagents. See https://docs.victoriametrics.com/vmagent.html#scraping-big-number-of-targets - # available since 1.77.2 version https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.77.2 - clusterMode: false - # -- replication factor for vmagent in cluster mode - replicationFactor: 1 - # ref: https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#update-strategies - updateStrategy: {} - # type: RollingUpdate - - -image: - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/vmagent - tag: v1.93.7-cluster # rewrites Chart.AppVersion - pullPolicy: IfNotPresent - -imagePullSecrets: [] -nameOverride: "" - -containerWorkingDir: "/" - -rbac: - create: true - # Note: The PSP will only be deployed, if Kubernetes (<1.25) supports the resource. - pspEnabled: true - annotations: {} - extraLabels: {} - # -- if true and `rbac.enabled`, will deploy a Role/Rolebinding instead of a ClusterRole/ClusterRoleBinding - namespaced: false - -serviceAccount: - # Specifies whether a service account should be created - create: true - # Annotations to add to the service account - annotations: { - iam.gke.io/gcp-service-account: sa-infr-sre-vmagnt-prd-mds@meesho-admin-prd-0622.iam.gserviceaccount.com - } - # The name of the service account to use. - # If not set and create is true, a name is generated using the fullname template - name: - -## See `kubectl explain poddisruptionbudget.spec` for more -## ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/ -podDisruptionBudget: - enabled: false - # minAvailable: 1 - # maxUnavailable: 1 - labels: {} - -# WARN: need to specify at least one remote write url or one multi tenant url -# remoteWriteUrls: [] -remoteWriteUrls: - # - https://vminsert-prd-infra.meeshogcp.in/insert/100/prometheus/api/v1/write - - http://vminsert-infra-prd.victoriametrics.svc.cluster.local:8480/insert/multitenant/prometheus/api/v1/write -# - http://prometheus:8480/insert/0/prometheus - -multiTenantUrls: [] -# multiTenantUrls: -# - http://vm-insert-az1:8480 -# - http://vm-insert-az2:8480 - -extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - promscrape.config.strictParse: false - promscrape.maxScrapeSize: 1000000000 - promscrape.minResponseSizeForStreamParse: 1000000 - loggerTimezone: "Asia/Kolkata" - - # Uncomment and specify the port if you want to support any of the protocols: - # https://victoriametrics.github.io/vmagent.html#features - # graphiteListenAddr: ":2003" - # influxListenAddr: ":8189" - # opentsdbHTTPListenAddr: ":4242" - # opentsdbListenAddr: ":4242" - -# -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables -env: - [] - # - name: VM_remoteWrite_basicAuth_password - # valueFrom: - # secretKeyRef: - # name: auth_secret - # key: password - -# extra Labels for Pods, Deployment and Statefulset -extraLabels: - bu: "infra" - team: "sre" - service: "vmagent-infra-prd" - env: "prd" - priority: "p0" - type: "vmagent" - - - -# extra Labels for Pods only -podLabels: {} - -# Additional hostPath mounts -extraHostPathMounts: - [] - # - name: certs-dir - # mountPath: /etc/kubernetes/certs - # subPath: "" - # hostPath: /etc/kubernetes/certs - # readOnly: true - -# Extra Volumes for the pod -extraVolumes: - [] - # - name: example - # configMap: - # name: example - -# Extra Volume Mounts for the container -extraVolumeMounts: - [] - # - name: example - # mountPath: /example - -extraContainers: [] -# - name: config-reloader -# image: reloader-image - -podSecurityContext: - {} - # fsGroup: 2000 - -securityContext: - {} - # capabilities: - # drop: - # - ALL - # readOnlyRootFilesystem: true - # runAsNonRoot: true - # runAsUser: 1000 - -service: - enabled: true - annotations: {} - # cloud.google.com/neg: '{"exposed_ports": {"8429":{"name": "vmagent-infra-prd"}}}' - extraLabels: {} - clusterIP: "" - ## Ref: https://kubernetes.io/docs/user-guide/services/#external-ips - ## - externalIPs: [] - loadBalancerIP: "" - loadBalancerSourceRanges: [] - servicePort: 8429 - # nodePort: 30000 - type: ClusterIP - # Ref: https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip - # externalTrafficPolicy: "local" - # healthCheckNodePort: 0 -ingress: - enabled: true - ingressClassName: nginx-internal - annotations: - nginx.ingress.kubernetes.io/force-ssl-redirect: "false" - nginx.ingress.kubernetes.io/rewrite-target: / - nginx.ingress.kubernetes.io/ssl-redirect: "false" - # kubernetes.io/ingress.class: nginx - # kubernetes.io/tls-acme: 'true' - - extraLabels: {} - hosts: - - name: vmagent-infra-prd.meeshogcp.in - path: / - port: http - tls: [] - # - secretName: vmagent-ingress-tls - # hosts: - # - vmagent.local - # For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName - # See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress - # ingressClassName: nginx - # -- pathType is only for k8s >= 1.1= - pathType: Prefix - -resources: - # We usually recommend not to specify default resources and to leave this as a conscious - # choice for the user. This also increases chances charts run on environments with little - # resources, such as Minikube. If you do want to specify resources, uncomment the following - # lines, adjust them as necessary, and remove the curly braces after 'resources:'. - # limits: - # cpu: 100m - # memory: 128Mi - requests: - cpu: 12 - memory: 20Gi - -# Annotations to be added to the deployment -annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8429" - -# Annotations to be added to pod -podAnnotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8429" - -nodeSelector: - dedicated: "vmagent-mds" - -tolerations: - - key: "dedicated" - operator: "Equal" - value: "vmagent-mds" - effect: "NoSchedule" - - -affinity: {} - -# -- priority class to be assigned to the pod(s) -priorityClassName: "" - -serviceMonitor: - enabled: false - extraLabels: {} - annotations: {} - relabelings: [] -# interval: 15s -# scrapeTimeout: 5s - # -- Commented. HTTP scheme to use for scraping. -# scheme: https - # -- Commented. TLS configuration to use when scraping the endpoint -# tlsConfig: -# insecureSkipVerify: true - -persistence: - enabled: false - # storageClassName: default - accessModes: - - ReadWriteOnce - size: 10Gi - annotations: {} - extraLabels: {} - existingClaim: "" - # -- Bind Persistent Volume by labels. Must match all labels of targeted PV. - matchLabels: {} - -# -- Extra scrape configs that will be appended to `config` -extraScrapeConfigs: [] - -# Add extra specs dynamically to this chart -extraObjects: [] diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-alert-dr/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-alert-dr/custom-values.yaml deleted file mode 100644 index 70148b2..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-alert-dr/custom-values.yaml +++ /dev/null @@ -1,304 +0,0 @@ -serviceAccount: - # Specifies whether a service account should be created - create: true - # Annotations to add to the service account - annotations: {} - # The name of the service account to use. - # If not set and create is true, a name is generated using the fullname template - name: - # mount API token to pod directly - automountToken: true - -imagePullSecrets: [] - -dedicatedValue: false -schedulerName: default-scheduler - -rbac: - create: true - # Note: The PSP will only be deployed, if Kubernetes (<1.25) supports the resource. - pspEnabled: true - namespaced: false - extraLabels: {} - annotations: {} - -topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmselect-dr - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: DoNotSchedule - labelSelector: - matchLabels: - type: vmselect-dr - -alertmanager: - enabled: false - -server: - enabled: true - name: vmalert - image: - repository: victoriametrics/vmalert - tag: "" # rewrites Chart.AppVersion - pullPolicy: IfNotPresent - nameOverride: "" - fullnameOverride: vmalert-infra-prd-dr - configMap: "" - - ## See `kubectl explain poddisruptionbudget.spec` for more - ## ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/ - podDisruptionBudget: - enabled: false - # minAvailable: 1 - # maxUnavailable: 1 - labels: {} - - # -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables - env: - [] - # - name: VM_remoteWrite_basicAuth_password - # valueFrom: - # secretKeyRef: - # name: auth_secret - # key: password - - replicaCount: 2 - - # deployment strategy, set to standard k8s default - strategy: - type: RollingUpdate - rollingUpdate: - maxSurge: 25% - maxUnavailable: 25% - - # specifies the minimum number of seconds for which a newly created Pod should be ready without any of its containers crashing/terminating - # 0 is the standard k8s default - minReadySeconds: 0 - - # vmalert reads metrics from source, next section represents its configuration. It can be any service which supports - # MetricsQL or PromQL. - datasource: - url: "http://vmselect-infra-prd-dr.victoriametrics.svc.cluster.local:8481/select/100/prometheus" - # -- Basic auth for datasource - basicAuth: - username: "" - password: "" - # -- Auth based on Bearer token for datasource - bearer: - # -- Token with Bearer token. You can use one of token or tokenFile. You don't need to add "Bearer" prefix string - token: "" - # -- Token Auth file with Bearer token. You can use one of token or tokenFile - tokenFile: "" - - remote: - write: - url: "http://vminsert-infra-prd-dr.victoriametrics.svc.cluster.local:8480/insert/100/prometheus" - # -- Basic auth for remote write - basicAuth: - username: "" - password: "" - # -- Auth based on Bearer token for remote write - bearer: - # -- Token with Bearer token. You can use one of token or tokenFile. You don't need to add "Bearer" prefix string - token: "" - # -- Token Auth file with Bearer token. You can use one of token or tokenFile - tokenFile: "" - read: - url: "http://vmselect-infra-prd-dr.victoriametrics.svc.cluster.local:8481/select/100/prometheus" - # -- Basic auth for remote read - basicAuth: - username: "" - password: "" - # -- Auth based on Bearer token for remote read - bearer: - # -- Token with Bearer token. You can use one of token or tokenFile. You don't need to add "Bearer" prefix string - token: "" - # -- Token Auth file with Bearer token. You can use one of token or tokenFile - tokenFile: "" - - # -- Notifier to use for alerts. - # Multiple notifiers can be enabled by using `notifiers` section - notifier: - alertmanager: - url: "http://alertmanager-infra-prd.alertmanager.svc.cluster.local:9093" - # -- Basic auth for alertmanager - basicAuth: - username: "" - password: "" - # -- Auth based on Bearer token for alertmanager - bearer: - # -- Token with Bearer token. You can use one of token or tokenFile. You don't need to add "Bearer" prefix string - token: "" - # -- Token Auth file with Bearer token. You can use one of token or tokenFile - tokenFile: "" - - # -- Additional notifiers to use for alerts - notifiers: [] - # - alertmanager: - # url: "http://devops-p-alertmanager-01b.meeshoint.in:9093" - # basicAuth: - # username: "" - # password: "" - # bearer: - # token: "" - # tokenFile: "" - # - alertmanager: - # url: "https://prd-infra-alertmanager.meesho.com" - # basicAuth: - # username: "" - # password: "" - # bearer: - # token: "" - # tokenFile: "" - - extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - rule: "/config/vm-alerts-config/cross-cluster/**/*.yaml" - loggerTimezone: "Asia/Kolkata" - - # Additional hostPath mounts - extraHostPathMounts: - [] - # - name: certs-dir - # mountPath: /etc/kubernetes/certs - # subPath: "" - # hostPath: /etc/kubernetes/certs - # readOnly: true - - # Extra Volumes for the pod - extraVolumes: - [] - # Extra Volume Mounts for the container - extraVolumeMounts: - [] - extraContainers: - [] - #- name: config-reloader - # image: reloader-image - - service: - annotations: {} - labels: {} - clusterIP: "" - ## Ref: https://kubernetes.io/docs/user-guide/services/#external-ips - ## - externalIPs: [] - loadBalancerIP: "" - loadBalancerSourceRanges: [] - servicePort: 8880 - # nodePort: 30000 - type: ClusterIP - # Ref: https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip - # externalTrafficPolicy: "local" - # healthCheckNodePort: 0 - - ingress: - enabled: true - annotations: {} - ingressClassName: nginx-internal - # kubernetes.io/ingress.class: nginx - # kubernetes.io/tls-acme: 'true' - - extraLabels: {} - hosts: - - name: vmalert-infra-prd-dr.meeshogcp.in - path: / - port: http - - tls: [] - # - secretName: vmselect-ingress-tls - # hosts: - # - vmselect.local - - # For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName - # See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress - # ingressClassName: nginx - # -- pathType is only for k8s >= 1.1= - pathType: Prefix - - podSecurityContext: {} - # fsGroup: 2000 - - securityContext: - {} - # capabilities: - # drop: - # - ALL - # readOnlyRootFilesystem: true - # runAsNonRoot: true - # runAsUser: 1000 - - resources: - # We usually recommend not to specify default resources and to leave this as a conscious - # choice for the user. This also increases chances charts run on environments with little - # resources, such as Minikube. If you do want to specify resources, uncomment the following - # lines, adjust them as necessary, and remove the curly braces after 'resources:'. - # limits: - # cpu: 100m - # memory: 128Mi - requests: - cpu: 1 - memory: 2Gi - - # Annotations to be added to the deployment - annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8880" - - # labels to be added to the deployment, pods and other resources - labels: - bu: "infra" - team: "sre" - service: "vmalert-infra-prd-dr" - env: "prd" - priority: "p0" - type: "vmalert-dr" - - # Annotations to be added to pod - podAnnotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8880" - - podLabels: {} - - nodeSelector: - dedicated: "vmselect-dr" - - - priorityClassName: "" - - tolerations: - - key: "dedicated" - operator: "Equal" - value: "vmselect-dr" - effect: "NoSchedule" - - affinity: {} - - # vmalert alert rules configuration configuration: - # use existing configmap if specified - # otherwise .config values will be used - config: - alerts: - groups: [] - - -serviceMonitor: - enabled: false - extraLabels: {} - annotations: {} - relabelings: [] -# interval: 15s -# scrapeTimeout: 5s -# -- Commented. HTTP scheme to use for scraping. -# scheme: https -# -- Commented. TLS configuration to use when scraping the endpoint -# tlsConfig: -# insecureSkipVerify: true diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-alert-fb/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-alert-fb/custom-values.yaml deleted file mode 100644 index d489cc3..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-alert-fb/custom-values.yaml +++ /dev/null @@ -1,286 +0,0 @@ -serviceAccount: - # Specifies whether a service account should be created - create: true - # Annotations to add to the service account - annotations: {} - # The name of the service account to use. - # If not set and create is true, a name is generated using the fullname template - name: - # mount API token to pod directly - automountToken: true - -imagePullSecrets: [] - -dedicatedValue: false -schedulerName: default-scheduler - -rbac: - create: true - # Note: The PSP will only be deployed, if Kubernetes (<1.25) supports the resource. - pspEnabled: true - namespaced: false - extraLabels: {} - annotations: {} - -topologySpreadConstraints: [] - -alertmanager: - enabled: false - -server: - enabled: true - name: vmalert - image: - repository: victoriametrics/vmalert - tag: "" # rewrites Chart.AppVersion - pullPolicy: IfNotPresent - nameOverride: "" - fullnameOverride: vmalert-infra-prd-fb - configMap: "" - - ## See `kubectl explain poddisruptionbudget.spec` for more - ## ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/ - podDisruptionBudget: - enabled: false - # minAvailable: 1 - # maxUnavailable: 1 - labels: {} - - # -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables - env: - [] - # - name: VM_remoteWrite_basicAuth_password - # valueFrom: - # secretKeyRef: - # name: auth_secret - # key: password - - replicaCount: 1 - - # Modify deployment strategy - strategy: - type: RollingUpdate - rollingUpdate: - maxSurge: 25% - maxUnavailable: 25% - - # specifies the minimum number of seconds for which a newly created Pod should be ready without any of its containers crashing/terminating - # 0 is the standard k8s default - minReadySeconds: 0 - - # vmalert reads metrics from source, next section represents its configuration. It can be any service which supports - # MetricsQL or PromQL. - datasource: - url: "http://vmsinglenode-infra-prd.victoriametrics.svc.cluster.local:8428" - # -- Basic auth for datasource - basicAuth: - username: "" - password: "" - # -- Auth based on Bearer token for datasource - bearer: - # -- Token with Bearer token. You can use one of token or tokenFile. You don't need to add "Bearer" prefix string - token: "" - # -- Token Auth file with Bearer token. You can use one of token or tokenFile - tokenFile: "" - - remote: - write: - url: "http://vmsinglenode-infra-prd.victoriametrics.svc.cluster.local:8428/api/v1/write" - # -- Basic auth for remote write - basicAuth: - username: "" - password: "" - # -- Auth based on Bearer token for remote write - bearer: - # -- Token with Bearer token. You can use one of token or tokenFile. You don't need to add "Bearer" prefix string - token: "" - # -- Token Auth file with Bearer token. You can use one of token or tokenFile - tokenFile: "" - read: - url: "http://vmsinglenode-infra-prd.victoriametrics.svc.cluster.local:8428/api/v1/read" - # -- Basic auth for remote read - basicAuth: - username: "" - password: "" - # -- Auth based on Bearer token for remote read - bearer: - # -- Token with Bearer token. You can use one of token or tokenFile. You don't need to add "Bearer" prefix string - token: "" - # -- Token Auth file with Bearer token. You can use one of token or tokenFile - tokenFile: "" - - # -- Notifier to use for alerts. - # Multiple notifiers can be enabled by using `notifiers` section - notifier: - alertmanager: - url: "http://alertmanager-infra-prd.alertmanager.svc.cluster.local:9093" - # -- Basic auth for alertmanager - basicAuth: - username: "" - password: "" - # -- Auth based on Bearer token for alertmanager - bearer: - # -- Token with Bearer token. You can use one of token or tokenFile. You don't need to add "Bearer" prefix string - token: "" - # -- Token Auth file with Bearer token. You can use one of token or tokenFile - tokenFile: "" - - # -- Additional notifiers to use for alerts - notifiers: [] - # - alertmanager: - # url: "http://devops-p-alertmanager-01b.meeshoint.in:9093" - # basicAuth: - # username: "" - # password: "" - # bearer: - # token: "" - # tokenFile: "" - # - alertmanager: - # url: "https://prd-infra-alertmanager.meesho.com" - # basicAuth: - # username: "" - # password: "" - # bearer: - # token: "" - # tokenFile: "" - - extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - rule: "/config/vm-alerts-config/vmstack-fb/**/*.yaml" - loggerTimezone: "Asia/Kolkata" - - # Additional hostPath mounts - extraHostPathMounts: - [] - # - name: certs-dir - # mountPath: /etc/kubernetes/certs - # subPath: "" - # hostPath: /etc/kubernetes/certs - # readOnly: true - - # Extra Volumes for the pod - extraVolumes: - [] - # Extra Volume Mounts for the container - extraVolumeMounts: - [] - extraContainers: - [] - #- name: config-reloader - # image: reloader-image - - service: - annotations: {} - labels: {} - clusterIP: "" - ## Ref: https://kubernetes.io/docs/user-guide/services/#external-ips - ## - externalIPs: [] - loadBalancerIP: "" - loadBalancerSourceRanges: [] - servicePort: 8880 - # nodePort: 30000 - type: ClusterIP - # Ref: https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip - # externalTrafficPolicy: "local" - # healthCheckNodePort: 0 - - ingress: - enabled: true - annotations: {} - ingressClassName: nginx-internal - # kubernetes.io/ingress.class: nginx - # kubernetes.io/tls-acme: 'true' - - extraLabels: {} - hosts: - - name: vmalert-infra-prd-fb.meeshogcp.in - path: / - port: http - - tls: [] - # - secretName: vmselect-ingress-tls - # hosts: - # - vmselect.local - - # For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName - # See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress - # ingressClassName: nginx - # -- pathType is only for k8s >= 1.1= - pathType: Prefix - - podSecurityContext: {} - # fsGroup: 2000 - - securityContext: - {} - # capabilities: - # drop: - # - ALL - # readOnlyRootFilesystem: true - # runAsNonRoot: true - # runAsUser: 1000 - - # Modify resources - resources: - requests: - cpu: 1 - memory: 1Gi - - # Annotations to be added to the deployment - annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8880" - - # labels to be added to the deployment, pods and other resources - labels: - bu: "infra" - team: "sre" - service: "vmalert-infra-prd-fb" - env: "prd" - priority: "p0" - type: "vmalert-fb" - - # Annotations to be added to pod - podAnnotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8880" - - podLabels: {} - - nodeSelector: - dedicated: "vmstack-fb" - - - priorityClassName: "" - - tolerations: - - key: "dedicated" - operator: "Equal" - value: "vmstack-fb" - effect: "NoSchedule" - - affinity: {} - - # vmalert alert rules configuration configuration: - # use existing configmap if specified - # otherwise .config values will be used - config: - alerts: - groups: [] - - -serviceMonitor: - enabled: false - extraLabels: {} - annotations: {} - relabelings: [] -# interval: 15s -# scrapeTimeout: 5s -# -- Commented. HTTP scheme to use for scraping. -# scheme: https -# -- Commented. TLS configuration to use when scraping the endpoint -# tlsConfig: -# insecureSkipVerify: true diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-alert-secured-stateful/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-alert-secured-stateful/custom-values.yaml deleted file mode 100644 index e17933d..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-alert-secured-stateful/custom-values.yaml +++ /dev/null @@ -1,340 +0,0 @@ -serviceAccount: - # Specifies whether a service account should be created - create: true - # Annotations to add to the service account - annotations: {} - # The name of the service account to use. - # If not set and create is true, a name is generated using the fullname template - name: - # mount API token to pod directly - automountToken: true - -imagePullSecrets: [] - -dedicatedValue: false -schedulerName: default-scheduler - -rbac: - create: true - # Note: The PSP will only be deployed, if Kubernetes (<1.25) supports the resource. - pspEnabled: true - namespaced: false - extraLabels: {} - annotations: {} - -topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmalert - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: DoNotSchedule - labelSelector: - matchLabels: - type: vmalert - -alertmanager: - enabled: false - -server: - enabled: true - name: vmalert - image: - repository: victoriametrics/vmalert - tag: "" # rewrites Chart.AppVersion - pullPolicy: IfNotPresent - nameOverride: "" - fullnameOverride: vmalert-stateful-secured-infra-prd - configMap: "" - - ## See `kubectl explain poddisruptionbudget.spec` for more - ## ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/ - podDisruptionBudget: - enabled: false - # minAvailable: 1 - # maxUnavailable: 1 - labels: {} - - # -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables - env: - [] - # - name: VM_remoteWrite_basicAuth_password - # valueFrom: - # secretKeyRef: - # name: auth_secret - # key: password - - replicaCount: 1 - - # deployment strategy, set to standard k8s default - strategy: - type: RollingUpdate - rollingUpdate: - maxSurge: 25% - maxUnavailable: 25% - - # specifies the minimum number of seconds for which a newly created Pod should be ready without any of its containers crashing/terminating - # 0 is the standard k8s default - minReadySeconds: 0 - - # vmalert reads metrics from source, next section represents its configuration. It can be any service which supports - # MetricsQL or PromQL. - datasource: - url: "http://vmselect-infra-prd-test-proxy.victoriametrics.svc.cluster.local:8481/select/200/prometheus" - # -- Basic auth for datasource - basicAuth: - username: "" - password: "" - # -- Auth based on Bearer token for datasource - bearer: - # -- Token with Bearer token. You can use one of token or tokenFile. You don't need to add "Bearer" prefix string - token: "" - # -- Token Auth file with Bearer token. You can use one of token or tokenFile - tokenFile: "" - - remote: - write: - url: "http://vm-insert-infra-prd.victoriametrics.svc.cluster.local:8480/insert/200/prometheus" - # -- Basic auth for remote write - basicAuth: - username: "" - password: "" - # -- Auth based on Bearer token for remote write - bearer: - # -- Token with Bearer token. You can use one of token or tokenFile. You don't need to add "Bearer" prefix string - token: "" - # -- Token Auth file with Bearer token. You can use one of token or tokenFile - tokenFile: "" - read: - url: "http://vmselect-infra-prd-test-proxy.victoriametrics.svc.cluster.local:8481/select/200/prometheus" - # -- Basic auth for remote read - basicAuth: - username: "" - password: "" - # -- Auth based on Bearer token for remote read - bearer: - # -- Token with Bearer token. You can use one of token or tokenFile. You don't need to add "Bearer" prefix string - token: "" - # -- Token Auth file with Bearer token. You can use one of token or tokenFile - tokenFile: "" - - # -- Notifier to use for alerts. - # Multiple notifiers can be enabled by using `notifiers` section - notifier: - alertmanager: - url: "http://alertmanager-infra-prd.alertmanager.svc.cluster.local:9093" - # -- Basic auth for alertmanager - basicAuth: - username: "" - password: "" - # -- Auth based on Bearer token for alertmanager - bearer: - # -- Token with Bearer token. You can use one of token or tokenFile. You don't need to add "Bearer" prefix string - token: "" - # -- Token Auth file with Bearer token. You can use one of token or tokenFile - tokenFile: "" - - # -- Additional notifiers to use for alerts - notifiers: [] - # - alertmanager: - # url: "http://devops-p-alertmanager-01b.meeshoint.in:9093" - # basicAuth: - # username: "" - # password: "" - # bearer: - # token: "" - # tokenFile: "" - # - alertmanager: - # url: "https://prd-infra-alertmanager.meesho.com" - # basicAuth: - # username: "" - # password: "" - # bearer: - # token: "" - # tokenFile: "" - - extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - rule: "/alert-rules/vm-alerts-config/configmap/sensitive/cross-cluster/**/*.yaml" - evaluationInterval: 60s - configCheckInterval: 10s - loggerTimezone: "Asia/Kolkata" - - # Additional hostPath mounts - extraHostPathMounts: - [] - # - name: certs-dir - # mountPath: /etc/kubernetes/certs - # subPath: "" - # hostPath: /etc/kubernetes/certs - # readOnly: true - - # Extra Volumes for the pod - extraVolumes: - [] - # Extra Volume Mounts for the container - extraVolumeMounts: - [] - extraContainers: - [] - #- name: config-reloader - # image: reloader-image - - service: - annotations: {} - labels: {} - clusterIP: "" - ## Ref: https://kubernetes.io/docs/user-guide/services/#external-ips - ## - externalIPs: [] - loadBalancerIP: "" - loadBalancerSourceRanges: [] - servicePort: 8880 - # nodePort: 30000 - type: ClusterIP - # Ref: https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip - # externalTrafficPolicy: "local" - # healthCheckNodePort: 0 - - ingress: - enabled: false - annotations: {} - ingressClassName: nginx-internal - # kubernetes.io/ingress.class: nginx - # kubernetes.io/tls-acme: 'true' - - extraLabels: {} - hosts: - - name: vmalert-infra-prd-stateful.meeshogcp.in - path: / - port: http - - tls: [] - # - secretName: vmselect-ingress-tls - # hosts: - # - vmselect.local - - # For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName - # See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress - # ingressClassName: nginx - # -- pathType is only for k8s >= 1.1= - pathType: Prefix - - podSecurityContext: {} - # fsGroup: 2000 - - securityContext: - {} - # capabilities: - # drop: - # - ALL - # readOnlyRootFilesystem: true - # runAsNonRoot: true - # runAsUser: 1000 - - resources: - # We usually recommend not to specify default resources and to leave this as a conscious - # choice for the user. This also increases chances charts run on environments with little - # resources, such as Minikube. If you do want to specify resources, uncomment the following - # lines, adjust them as necessary, and remove the curly braces after 'resources:'. - # limits: - # cpu: 100m - # memory: 128Mi - requests: - cpu: 1 - memory: 2Gi - - # Annotations to be added to the deployment - annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8880" - - # labels to be added to the deployment, pods and other resources - labels: - bu: "infra" - team: "sre" - service: "vmalert-stateful-secured-infra-prd" - env: "prd" - priority: "p0" - type: "vmalert" - - # Annotations to be added to pod - podAnnotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8880" - cluster-autoscaler.kubernetes.io/safe-to-evict: 'false' - - podLabels: {} - - nodeSelector: - dedicated: "sre-shared-tmp" - - - priorityClassName: "" - - tolerations: - - key: "dedicated" - operator: "Equal" - value: "sre-shared-tmp" - effect: "NoSchedule" - - affinity: {} - - # vmalert alert rules configuration configuration: - # use existing configmap if specified - # otherwise .config values will be used - config: - alerts: - groups: [] - - # -- Persistent Volume configuration for alert rules - persistentVolume: - # -- Create/use Persistent Volume Claim for alert rules. Empty dir if false - enabled: true - - # -- Override Persistent Volume Claim name - name: "" - - # -- Array of access modes. Must match those of existing PV or dynamic provisioner. Details are [here](https://kubernetes.io/docs/concepts/storage/persistent-volumes/) - accessModes: - - ReadWriteMany - - # -- Persistent volume annotations - annotations: {} - - # -- PVC extra labels - extraLabels: {} - - # -- StorageClass to use for persistent volume. Requires server.persistentVolume.enabled: true. If defined, PVC created automatically - storageClassName: "pulse-nfs-sc-secured-prd" - - # -- Existing Claim name. If defined, PVC must be created manually before volume will be bound - existingClaim: "" - - # -- Mount path. Alert rules Persistent Volume mount root path. - mountPath: /alert-rules - - # -- Mount subpath - subPath: "" - - # -- Size of the volume. Better to set the same as resource limit memory property. - size: 10Gi - - -serviceMonitor: - enabled: false - extraLabels: {} - annotations: {} - relabelings: [] -# interval: 15s -# scrapeTimeout: 5s -# -- Commented. HTTP scheme to use for scraping. -# scheme: https -# -- Commented. TLS configuration to use when scraping the endpoint -# tlsConfig: -# insecureSkipVerify: true diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-alert-secured/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-alert-secured/custom-values.yaml deleted file mode 100644 index b925984..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-alert-secured/custom-values.yaml +++ /dev/null @@ -1,305 +0,0 @@ -serviceAccount: - # Specifies whether a service account should be created - create: true - # Annotations to add to the service account - annotations: {} - # The name of the service account to use. - # If not set and create is true, a name is generated using the fullname template - name: - # mount API token to pod directly - automountToken: true - -imagePullSecrets: [] - -dedicatedValue: false -schedulerName: default-scheduler - -rbac: - create: true - # Note: The PSP will only be deployed, if Kubernetes (<1.25) supports the resource. - pspEnabled: true - namespaced: false - extraLabels: {} - annotations: {} - -topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmalert - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: DoNotSchedule - labelSelector: - matchLabels: - type: vmalert - -alertmanager: - enabled: false - -server: - enabled: true - name: vmalert - image: - repository: victoriametrics/vmalert - tag: "" # rewrites Chart.AppVersion - pullPolicy: IfNotPresent - nameOverride: "" - fullnameOverride: vmalert-secured-infra-prd - configMap: "" - - ## See `kubectl explain poddisruptionbudget.spec` for more - ## ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/ - podDisruptionBudget: - enabled: false - # minAvailable: 1 - # maxUnavailable: 1 - labels: {} - - # -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables - env: - [] - # - name: VM_remoteWrite_basicAuth_password - # valueFrom: - # secretKeyRef: - # name: auth_secret - # key: password - - replicaCount: 2 - - # deployment strategy, set to standard k8s default - strategy: - type: RollingUpdate - rollingUpdate: - maxSurge: 25% - maxUnavailable: 25% - - # specifies the minimum number of seconds for which a newly created Pod should be ready without any of its containers crashing/terminating - # 0 is the standard k8s default - minReadySeconds: 0 - - # vmalert reads metrics from source, next section represents its configuration. It can be any service which supports - # MetricsQL or PromQL. - datasource: - url: "http://vmselect-infra-prd-test-proxy.victoriametrics.svc.cluster.local:8481/select/200/prometheus" - # -- Basic auth for datasource - basicAuth: - username: "" - password: "" - # -- Auth based on Bearer token for datasource - bearer: - # -- Token with Bearer token. You can use one of token or tokenFile. You don't need to add "Bearer" prefix string - token: "" - # -- Token Auth file with Bearer token. You can use one of token or tokenFile - tokenFile: "" - - remote: - write: - url: "http://vminsert-infra-prd.victoriametrics.svc.cluster.local:8480/insert/200/prometheus" - # -- Basic auth for remote write - basicAuth: - username: "" - password: "" - # -- Auth based on Bearer token for remote write - bearer: - # -- Token with Bearer token. You can use one of token or tokenFile. You don't need to add "Bearer" prefix string - token: "" - # -- Token Auth file with Bearer token. You can use one of token or tokenFile - tokenFile: "" - read: - url: "http://vmselect-infra-prd-test-proxy.victoriametrics.svc.cluster.local:8481/select/200/prometheus" - # -- Basic auth for remote read - basicAuth: - username: "" - password: "" - # -- Auth based on Bearer token for remote read - bearer: - # -- Token with Bearer token. You can use one of token or tokenFile. You don't need to add "Bearer" prefix string - token: "" - # -- Token Auth file with Bearer token. You can use one of token or tokenFile - tokenFile: "" - - # -- Notifier to use for alerts. - # Multiple notifiers can be enabled by using `notifiers` section - notifier: - alertmanager: - url: "http://alertmanager-infra-prd.alertmanager.svc.cluster.local:9093" - # -- Basic auth for alertmanager - basicAuth: - username: "" - password: "" - # -- Auth based on Bearer token for alertmanager - bearer: - # -- Token with Bearer token. You can use one of token or tokenFile. You don't need to add "Bearer" prefix string - token: "" - # -- Token Auth file with Bearer token. You can use one of token or tokenFile - tokenFile: "" - - # -- Additional notifiers to use for alerts - notifiers: [] - # - alertmanager: - # url: "http://devops-p-alertmanager-01b.meeshoint.in:9093" - # basicAuth: - # username: "" - # password: "" - # bearer: - # token: "" - # tokenFile: "" - # - alertmanager: - # url: "https://prd-infra-alertmanager.meesho.com" - # basicAuth: - # username: "" - # password: "" - # bearer: - # token: "" - # tokenFile: "" - - extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - rule: "/config/vm-alerts-config1/sensitive/cross-cluster/**/*.yaml" - loggerTimezone: "Asia/Kolkata" - - # Additional hostPath mounts - extraHostPathMounts: - [] - # - name: certs-dir - # mountPath: /etc/kubernetes/certs - # subPath: "" - # hostPath: /etc/kubernetes/certs - # readOnly: true - - # Extra Volumes for the pod - extraVolumes: - [] - # Extra Volume Mounts for the container - extraVolumeMounts: - [] - extraContainers: - [] - #- name: config-reloader - # image: reloader-image - - service: - annotations: {} - labels: {} - clusterIP: "" - ## Ref: https://kubernetes.io/docs/user-guide/services/#external-ips - ## - externalIPs: [] - loadBalancerIP: "" - loadBalancerSourceRanges: [] - servicePort: 8880 - # nodePort: 30000 - type: ClusterIP - # Ref: https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip - # externalTrafficPolicy: "local" - # healthCheckNodePort: 0 - - ingress: - enabled: true - annotations: {} - ingressClassName: nginx-internal - # kubernetes.io/ingress.class: nginx - # kubernetes.io/tls-acme: 'true' - - extraLabels: {} - hosts: - - name: vmalert-secured-infra-prd.meeshogcp.in - path: / - port: http - - tls: [] - # - secretName: vmselect-ingress-tls - # hosts: - # - vmselect.local - - # For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName - # See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress - # ingressClassName: nginx - # -- pathType is only for k8s >= 1.1= - pathType: Prefix - - podSecurityContext: {} - # fsGroup: 2000 - - securityContext: - {} - # capabilities: - # drop: - # - ALL - # readOnlyRootFilesystem: true - # runAsNonRoot: true - # runAsUser: 1000 - - resources: - # We usually recommend not to specify default resources and to leave this as a conscious - # choice for the user. This also increases chances charts run on environments with little - # resources, such as Minikube. If you do want to specify resources, uncomment the following - # lines, adjust them as necessary, and remove the curly braces after 'resources:'. - # limits: - # cpu: 100m - # memory: 128Mi - requests: - cpu: 1 - memory: 2Gi - - # Annotations to be added to the deployment - annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8880" - - # labels to be added to the deployment, pods and other resources - labels: - bu: "infra" - team: "sre" - service: "vmalert-secured-infra-prd" - env: "prd" - priority: "p0" - type: "vmalert" - - # Annotations to be added to pod - podAnnotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8880" - cluster-autoscaler.kubernetes.io/safe-to-evict: 'false' - - podLabels: {} - - nodeSelector: - dedicated: "sre-shared-tmp" - - - priorityClassName: "" - - tolerations: - - key: "dedicated" - operator: "Equal" - value: "sre-shared-tmp" - effect: "NoSchedule" - - affinity: {} - - # vmalert alert rules configuration configuration: - # use existing configmap if specified - # otherwise .config values will be used - config: - alerts: - groups: [] - - -serviceMonitor: - enabled: false - extraLabels: {} - annotations: {} - relabelings: [] -# interval: 15s -# scrapeTimeout: 5s -# -- Commented. HTTP scheme to use for scraping. -# scheme: https -# -- Commented. TLS configuration to use when scraping the endpoint -# tlsConfig: -# insecureSkipVerify: true diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-alert-stateful/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-alert-stateful/custom-values.yaml deleted file mode 100644 index 6cf4a49..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-alert-stateful/custom-values.yaml +++ /dev/null @@ -1,340 +0,0 @@ -serviceAccount: - # Specifies whether a service account should be created - create: true - # Annotations to add to the service account - annotations: {} - # The name of the service account to use. - # If not set and create is true, a name is generated using the fullname template - name: - # mount API token to pod directly - automountToken: true - -imagePullSecrets: [] - -dedicatedValue: false -schedulerName: default-scheduler - -rbac: - create: true - # Note: The PSP will only be deployed, if Kubernetes (<1.25) supports the resource. - pspEnabled: true - namespaced: false - extraLabels: {} - annotations: {} - -topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmalert - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: DoNotSchedule - labelSelector: - matchLabels: - type: vmalert - -alertmanager: - enabled: false - -server: - enabled: true - name: vmalert - image: - repository: victoriametrics/vmalert - tag: "" # rewrites Chart.AppVersion - pullPolicy: IfNotPresent - nameOverride: "" - fullnameOverride: vmalert-infra-prd-stateful - configMap: "" - - ## See `kubectl explain poddisruptionbudget.spec` for more - ## ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/ - podDisruptionBudget: - enabled: false - # minAvailable: 1 - # maxUnavailable: 1 - labels: {} - - # -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables - env: - [] - # - name: VM_remoteWrite_basicAuth_password - # valueFrom: - # secretKeyRef: - # name: auth_secret - # key: password - - replicaCount: 1 - - # deployment strategy, set to standard k8s default - strategy: - type: RollingUpdate - rollingUpdate: - maxSurge: 25% - maxUnavailable: 25% - - # specifies the minimum number of seconds for which a newly created Pod should be ready without any of its containers crashing/terminating - # 0 is the standard k8s default - minReadySeconds: 0 - - # vmalert reads metrics from source, next section represents its configuration. It can be any service which supports - # MetricsQL or PromQL. - datasource: - url: "http://vmselect-infra-prd-test-proxy.victoriametrics.svc.cluster.local:8481/select/100/prometheus" - # -- Basic auth for datasource - basicAuth: - username: "" - password: "" - # -- Auth based on Bearer token for datasource - bearer: - # -- Token with Bearer token. You can use one of token or tokenFile. You don't need to add "Bearer" prefix string - token: "" - # -- Token Auth file with Bearer token. You can use one of token or tokenFile - tokenFile: "" - - remote: - write: - url: "http://vm-insert-infra-prd.victoriametrics.svc.cluster.local:8480/insert/100/prometheus" - # -- Basic auth for remote write - basicAuth: - username: "" - password: "" - # -- Auth based on Bearer token for remote write - bearer: - # -- Token with Bearer token. You can use one of token or tokenFile. You don't need to add "Bearer" prefix string - token: "" - # -- Token Auth file with Bearer token. You can use one of token or tokenFile - tokenFile: "" - read: - url: "http://vmselect-infra-prd-test-proxy.victoriametrics.svc.cluster.local:8481/select/100/prometheus" - # -- Basic auth for remote read - basicAuth: - username: "" - password: "" - # -- Auth based on Bearer token for remote read - bearer: - # -- Token with Bearer token. You can use one of token or tokenFile. You don't need to add "Bearer" prefix string - token: "" - # -- Token Auth file with Bearer token. You can use one of token or tokenFile - tokenFile: "" - - # -- Notifier to use for alerts. - # Multiple notifiers can be enabled by using `notifiers` section - notifier: - alertmanager: - url: "http://alertmanager-infra-prd.alertmanager.svc.cluster.local:9093" - # -- Basic auth for alertmanager - basicAuth: - username: "" - password: "" - # -- Auth based on Bearer token for alertmanager - bearer: - # -- Token with Bearer token. You can use one of token or tokenFile. You don't need to add "Bearer" prefix string - token: "" - # -- Token Auth file with Bearer token. You can use one of token or tokenFile - tokenFile: "" - - # -- Additional notifiers to use for alerts - notifiers: [] - # - alertmanager: - # url: "http://devops-p-alertmanager-01b.meeshoint.in:9093" - # basicAuth: - # username: "" - # password: "" - # bearer: - # token: "" - # tokenFile: "" - # - alertmanager: - # url: "https://prd-infra-alertmanager.meesho.com" - # basicAuth: - # username: "" - # password: "" - # bearer: - # token: "" - # tokenFile: "" - - extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - rule: "/alert-rules/vm-alerts-config/configmap/cross-cluster/**/*.yaml" - evaluationInterval: 60s - configCheckInterval: 10s - loggerTimezone: "Asia/Kolkata" - - # Additional hostPath mounts - extraHostPathMounts: - [] - # - name: certs-dir - # mountPath: /etc/kubernetes/certs - # subPath: "" - # hostPath: /etc/kubernetes/certs - # readOnly: true - - # Extra Volumes for the pod - extraVolumes: - [] - # Extra Volume Mounts for the container - extraVolumeMounts: - [] - extraContainers: - [] - #- name: config-reloader - # image: reloader-image - - service: - annotations: {} - labels: {} - clusterIP: "" - ## Ref: https://kubernetes.io/docs/user-guide/services/#external-ips - ## - externalIPs: [] - loadBalancerIP: "" - loadBalancerSourceRanges: [] - servicePort: 8880 - # nodePort: 30000 - type: ClusterIP - # Ref: https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip - # externalTrafficPolicy: "local" - # healthCheckNodePort: 0 - - ingress: - enabled: true - annotations: {} - ingressClassName: nginx-internal - # kubernetes.io/ingress.class: nginx - # kubernetes.io/tls-acme: 'true' - - extraLabels: {} - hosts: - - name: vmalert-infra-prd-stateful.meeshogcp.in - path: / - port: http - - tls: [] - # - secretName: vmselect-ingress-tls - # hosts: - # - vmselect.local - - # For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName - # See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress - # ingressClassName: nginx - # -- pathType is only for k8s >= 1.1= - pathType: Prefix - - podSecurityContext: {} - # fsGroup: 2000 - - securityContext: - {} - # capabilities: - # drop: - # - ALL - # readOnlyRootFilesystem: true - # runAsNonRoot: true - # runAsUser: 1000 - - resources: - # We usually recommend not to specify default resources and to leave this as a conscious - # choice for the user. This also increases chances charts run on environments with little - # resources, such as Minikube. If you do want to specify resources, uncomment the following - # lines, adjust them as necessary, and remove the curly braces after 'resources:'. - # limits: - # cpu: 100m - # memory: 128Mi - requests: - cpu: 3 - memory: 6Gi - - # Annotations to be added to the deployment - annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8880" - - # labels to be added to the deployment, pods and other resources - labels: - bu: "infra" - team: "sre" - service: "vmalert-infra-prd-stateful" - env: "prd" - priority: "p0" - type: "vmalert" - - # Annotations to be added to pod - podAnnotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8880" - cluster-autoscaler.kubernetes.io/safe-to-evict: 'false' - - podLabels: {} - - nodeSelector: - dedicated: "sre-shared-tmp" - - - priorityClassName: "" - - tolerations: - - key: "dedicated" - operator: "Equal" - value: "sre-shared-tmp" - effect: "NoSchedule" - - affinity: {} - - # vmalert alert rules configuration configuration: - # use existing configmap if specified - # otherwise .config values will be used - config: - alerts: - groups: [] - - # -- Persistent Volume configuration for alert rules - persistentVolume: - # -- Create/use Persistent Volume Claim for alert rules. Empty dir if false - enabled: true - - # -- Override Persistent Volume Claim name - name: "" - - # -- Array of access modes. Must match those of existing PV or dynamic provisioner. Details are [here](https://kubernetes.io/docs/concepts/storage/persistent-volumes/) - accessModes: - - ReadWriteMany - - # -- Persistent volume annotations - annotations: {} - - # -- PVC extra labels - extraLabels: {} - - # -- StorageClass to use for persistent volume. Requires server.persistentVolume.enabled: true. If defined, PVC created automatically - storageClassName: "pulse-nfs-sc-prd" - - # -- Existing Claim name. If defined, PVC must be created manually before volume will be bound - existingClaim: "" - - # -- Mount path. Alert rules Persistent Volume mount root path. - mountPath: /alert-rules - - # -- Mount subpath - subPath: "" - - # -- Size of the volume. Better to set the same as resource limit memory property. - size: 10Gi - - -serviceMonitor: - enabled: false - extraLabels: {} - annotations: {} - relabelings: [] -# interval: 15s -# scrapeTimeout: 5s -# -- Commented. HTTP scheme to use for scraping. -# scheme: https -# -- Commented. TLS configuration to use when scraping the endpoint -# tlsConfig: -# insecureSkipVerify: true diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-alert/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-alert/custom-values.yaml deleted file mode 100644 index 63729f3..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-alert/custom-values.yaml +++ /dev/null @@ -1,305 +0,0 @@ -serviceAccount: - # Specifies whether a service account should be created - create: true - # Annotations to add to the service account - annotations: {} - # The name of the service account to use. - # If not set and create is true, a name is generated using the fullname template - name: - # mount API token to pod directly - automountToken: true - -imagePullSecrets: [] - -dedicatedValue: false -schedulerName: default-scheduler - -rbac: - create: true - # Note: The PSP will only be deployed, if Kubernetes (<1.25) supports the resource. - pspEnabled: true - namespaced: false - extraLabels: {} - annotations: {} - -topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmalert - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: DoNotSchedule - labelSelector: - matchLabels: - type: vmalert - -alertmanager: - enabled: false - -server: - enabled: true - name: vmalert - image: - repository: victoriametrics/vmalert - tag: "" # rewrites Chart.AppVersion - pullPolicy: IfNotPresent - nameOverride: "" - fullnameOverride: vmalert-infra-prd - configMap: "" - - ## See `kubectl explain poddisruptionbudget.spec` for more - ## ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/ - podDisruptionBudget: - enabled: false - # minAvailable: 1 - # maxUnavailable: 1 - labels: {} - - # -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables - env: - [] - # - name: VM_remoteWrite_basicAuth_password - # valueFrom: - # secretKeyRef: - # name: auth_secret - # key: password - - replicaCount: 1 - - # deployment strategy, set to standard k8s default - strategy: - type: RollingUpdate - rollingUpdate: - maxSurge: 25% - maxUnavailable: 25% - - # specifies the minimum number of seconds for which a newly created Pod should be ready without any of its containers crashing/terminating - # 0 is the standard k8s default - minReadySeconds: 0 - - # vmalert reads metrics from source, next section represents its configuration. It can be any service which supports - # MetricsQL or PromQL. - datasource: - url: "http://vmselect-infra-prd-test-proxy.victoriametrics.svc.cluster.local:8481/select/100/prometheus" - # -- Basic auth for datasource - basicAuth: - username: "" - password: "" - # -- Auth based on Bearer token for datasource - bearer: - # -- Token with Bearer token. You can use one of token or tokenFile. You don't need to add "Bearer" prefix string - token: "" - # -- Token Auth file with Bearer token. You can use one of token or tokenFile - tokenFile: "" - - remote: - write: - url: "http://vminsert-infra-prd.victoriametrics.svc.cluster.local:8480/insert/100/prometheus" - # -- Basic auth for remote write - basicAuth: - username: "" - password: "" - # -- Auth based on Bearer token for remote write - bearer: - # -- Token with Bearer token. You can use one of token or tokenFile. You don't need to add "Bearer" prefix string - token: "" - # -- Token Auth file with Bearer token. You can use one of token or tokenFile - tokenFile: "" - read: - url: "http://vmselect-infra-prd-test-proxy.victoriametrics.svc.cluster.local:8481/select/100/prometheus" - # -- Basic auth for remote read - basicAuth: - username: "" - password: "" - # -- Auth based on Bearer token for remote read - bearer: - # -- Token with Bearer token. You can use one of token or tokenFile. You don't need to add "Bearer" prefix string - token: "" - # -- Token Auth file with Bearer token. You can use one of token or tokenFile - tokenFile: "" - - # -- Notifier to use for alerts. - # Multiple notifiers can be enabled by using `notifiers` section - notifier: - alertmanager: - url: "http://alertmanager-infra-prd.alertmanager.svc.cluster.local:9093" - # -- Basic auth for alertmanager - basicAuth: - username: "" - password: "" - # -- Auth based on Bearer token for alertmanager - bearer: - # -- Token with Bearer token. You can use one of token or tokenFile. You don't need to add "Bearer" prefix string - token: "" - # -- Token Auth file with Bearer token. You can use one of token or tokenFile - tokenFile: "" - - # -- Additional notifiers to use for alerts - notifiers: [] - # - alertmanager: - # url: "http://devops-p-alertmanager-01b.meeshoint.in:9093" - # basicAuth: - # username: "" - # password: "" - # bearer: - # token: "" - # tokenFile: "" - # - alertmanager: - # url: "https://prd-infra-alertmanager.meesho.com" - # basicAuth: - # username: "" - # password: "" - # bearer: - # token: "" - # tokenFile: "" - - extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - rule: "/config/vm-alerts-config1/cross-cluster/**/*.yaml" - loggerTimezone: "Asia/Kolkata" - - # Additional hostPath mounts - extraHostPathMounts: - [] - # - name: certs-dir - # mountPath: /etc/kubernetes/certs - # subPath: "" - # hostPath: /etc/kubernetes/certs - # readOnly: true - - # Extra Volumes for the pod - extraVolumes: - [] - # Extra Volume Mounts for the container - extraVolumeMounts: - [] - extraContainers: - [] - #- name: config-reloader - # image: reloader-image - - service: - annotations: {} - labels: {} - clusterIP: "" - ## Ref: https://kubernetes.io/docs/user-guide/services/#external-ips - ## - externalIPs: [] - loadBalancerIP: "" - loadBalancerSourceRanges: [] - servicePort: 8880 - # nodePort: 30000 - type: ClusterIP - # Ref: https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip - # externalTrafficPolicy: "local" - # healthCheckNodePort: 0 - - ingress: - enabled: true - annotations: {} - ingressClassName: nginx-internal - # kubernetes.io/ingress.class: nginx - # kubernetes.io/tls-acme: 'true' - - extraLabels: {} - hosts: - - name: vmalert-infra-prd.meeshogcp.in - path: / - port: http - - tls: [] - # - secretName: vmselect-ingress-tls - # hosts: - # - vmselect.local - - # For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName - # See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress - # ingressClassName: nginx - # -- pathType is only for k8s >= 1.1= - pathType: Prefix - - podSecurityContext: {} - # fsGroup: 2000 - - securityContext: - {} - # capabilities: - # drop: - # - ALL - # readOnlyRootFilesystem: true - # runAsNonRoot: true - # runAsUser: 1000 - - resources: - # We usually recommend not to specify default resources and to leave this as a conscious - # choice for the user. This also increases chances charts run on environments with little - # resources, such as Minikube. If you do want to specify resources, uncomment the following - # lines, adjust them as necessary, and remove the curly braces after 'resources:'. - # limits: - # cpu: 100m - # memory: 128Mi - requests: - cpu: 1 - memory: 2Gi - - # Annotations to be added to the deployment - annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8880" - - # labels to be added to the deployment, pods and other resources - labels: - bu: "infra" - team: "sre" - service: "vmalert-infra-prd" - env: "prd" - priority: "p0" - type: "vmalert" - - # Annotations to be added to pod - podAnnotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8880" - cluster-autoscaler.kubernetes.io/safe-to-evict: 'false' - - podLabels: {} - - nodeSelector: - dedicated: "sre-shared-tmp" - - - priorityClassName: "" - - tolerations: - - key: "dedicated" - operator: "Equal" - value: "sre-shared-tmp" - effect: "NoSchedule" - - affinity: {} - - # vmalert alert rules configuration configuration: - # use existing configmap if specified - # otherwise .config values will be used - config: - alerts: - groups: [] - - -serviceMonitor: - enabled: false - extraLabels: {} - annotations: {} - relabelings: [] -# interval: 15s -# scrapeTimeout: 5s -# -- Commented. HTTP scheme to use for scraping. -# scheme: https -# -- Commented. TLS configuration to use when scraping the endpoint -# tlsConfig: -# insecureSkipVerify: true diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-auth/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-auth/custom-values.yaml deleted file mode 100644 index a45f449..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-auth/custom-values.yaml +++ /dev/null @@ -1,345 +0,0 @@ -# Default values for victoria-metrics-auth. -# This is a YAML-formatted file. -# Declare variables to be passed into your templates. - -# -- Number of replicas of vmauth -replicaCount: 1 - -# -- Name of Priority Class -priorityClassName: "" - -image: - # -- Victoria Metrics Auth Docker repository and image name - repository: victoriametrics/vmauth - # -- Tag of Docker image - tag: "" # rewrites Chart.AppVersion - # -- Variant of the image to use. - # e.g. enterprise, scratch - variant: "" - # -- Pull policy of Docker image - pullPolicy: IfNotPresent - - - -# -- Override resources fullname -fullnameOverride: vmauth-infra-prd - -containerWorkingDir: "" - -# -- Specify pod lifecycle -lifecycle: {} - - # -- Init containers for vmauth -initContainers: - [] - # - name: example - # image: example-image - -serviceAccount: - # -- Specifies whether a service account should be created - create: true - # -- Annotations to add to the service account - annotations: { - iam.gke.io/gcp-service-account: sa-infr-sre-vmagnt-prd-mds@meesho-admin-prd-0622.iam.gserviceaccount.com - } - # -- The name of the service account to use. If not set and create is true, a name is generated using the fullname template - name: - -# -- See `kubectl explain poddisruptionbudget.spec` for more. Official guide is [here](https://kubernetes.io/docs/tasks/run-application/configure-pdb/) -podDisruptionBudget: - enabled: false - # minAvailable: 1 - # maxUnavailable: 1 - labels: {} - -# -- Extra command line arguments for container of component -extraArgs: - envflag.enable: true - envflag.prefix: VM_ - loggerFormat: json - httpListenAddr: :8427 - loggerTimezone: "Asia/Kolkata" - responseTimeout: 180s - maxConcurrentRequests: 100 - -# -- Additional environment variables (ex.: secret tokens, flags). Check [here](https://docs.victoriametrics.com/victoriametrics/#environment-variables) for details -env: [] - -# -- Pod topologySpreadConstraints -topologySpreadConstraints: [] - # - maxSkew: 1 - # topologyKey: topology.kubernetes.io/zone - # whenUnsatisfiable: DoNotSchedule - -# -- Specify alternative source for env variables -envFrom: [] - #- configMapRef: - # name: special-config - -# -- Additional hostPath mounts -extraHostPathMounts: [] - # - name: certs-dir - # mountPath: /etc/kubernetes/certs - # subPath: "" - # hostPath: /etc/kubernetes/certs - # readOnly: true - -# -- Extra Volumes for the pod -extraVolumes: [] - # - name: example - # configMap: - # name: example - -# -- Extra Volume Mounts for the container -extraVolumeMounts: [] - # - name: example - # mountPath: /example - -# -- Extra containers to run in a pod with vmauth -extraContainers: - [] - # - name: config-reloader - # image: reloader-image - -# -- Pod's security context. Details are [here](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/) -podSecurityContext: {} - -# -- Container security context. Check [here](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/) for details. -securityContext: {} - -service: - # -- Enable vmauth service - enabled: true - # -- Service annotations - annotations: - io.cilium/global-service: "true" - # -- Service labels - extraLabels: {} - # -- Service ClusterIP - clusterIP: "" - # -- Service external IPs. Check [here](https://kubernetes.io/docs/concepts/services-networking/service/#external-ips) for details - externalIPs: [] - # -- Service load balancer IP - loadBalancerIP: "" - # -- Load balancer source range - loadBalancerSourceRanges: [] - # -- Service port - servicePort: 8427 - # nodePort: 30000 - # -- Service type - type: ClusterIP - # -- Service external traffic policy. Check [here](https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip) for details - externalTrafficPolicy: "" - # -- Health check node port for a service. Check [here](https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip) for details - healthCheckNodePort: "" - # -- Service IP family policy. Check [here](https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services) for details. - ipFamilyPolicy: "" - # -- List of service IP families. Check [here](https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services) for details. - ipFamilies: [] - -ingress: - # -- Enable deployment of ingress for vmauth component - enabled: true - - # -- Ingress annotations - annotations: - nginx.ingress.kubernetes.io/force-ssl-redirect: "false" - nginx.ingress.kubernetes.io/ssl-redirect: "false" - # kubernetes.io/ingress.class: nginx - # kubernetes.io/tls-acme: 'true' - - # -- Ingress extra labels - extraLabels: {} - - # -- Array of host objects - hosts: - - name: vmauth-infra-prd.meeshogcp.in - path: - - / - port: http - - # -- Array of TLS objects - tls: [] - # - secretName: vmauth-ingress-tls - # hosts: - # - vmauth.local - - # -- Ingress controller class name - ingressClassName: nginx-internal - - # -- Ingress path type - pathType: Prefix - - - -# -- We usually recommend not to specify default resources and to leave this as a conscious choice for the user. This also increases chances charts run on environments with little resources, such as Minikube. If you do want to specify resources, uncomment the following lines, adjust them as necessary, and remove the curly braces after `resources:`. -resources: - # limits: - # cpu: 100m - # memory: 128Mi - requests: - cpu: 4 - memory: 6Gi - -# -- Annotations to be added to the deployment -annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8427" - -# -- Annotations to be added to pod -podAnnotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8427" - cluster-autoscaler.kubernetes.io/safe-to-evict: 'false' - -# -- Labels to be added to pod -podLabels: - bu: "infra" - team: "sre" - service: "vmauth-infra-prd" - env: "prd" - priority: "p0" - type: "vmauth" - -# -- Labels to be added to the deployment -extraLabels: - bu: "infra" - team: "sre" - service: "vmauth-infra-prd" - env: "prd" - priority: "p0" - type: "vmauth" - -# -- NodeSelector configurations. Check [here](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector) for details -nodeSelector: - dedicated: "vmselect-c3" - -# -- Tolerations configurations. Check [here](https://kubernetes.io/docs/concepts/configuration/assign-pod-node/) for details -tolerations: - - key: "dedicated" - operator: "Equal" - value: "vmselect-c3" - effect: "NoSchedule" - -# -- Affinity configurations -affinity: {} - - - -# -- [K8s Deployment](https://kubernetes.io/docs/concepts/workloads/controllers/deployment/) specific variables -deployment: - enabled: true - spec: - strategy: - rollingUpdate: - maxSurge: 25% - maxUnavailable: 25% - type: RollingUpdate - - -serviceMonitor: - # -- Enable deployment of Service Monitor for server component. This is Prometheus operator object - enabled: false - # -- Service Monitor labels - extraLabels: {} - # -- Service Monitor annotations - annotations: {} - # -- Service Monitor relabelings - relabelings: [] - # -- Basic auth params for Service Monitor - basicAuth: {} - # -- Service Monitor metricRelabelings - metricRelabelings: [] -# interval: 15s -# scrapeTimeout: 5s - # -- Commented. HTTP scheme to use for scraping. -# scheme: https - # -- Commented. TLS configuration to use when scraping the endpoint -# tlsConfig: -# insecureSkipVerify: true - -# -- Use existing secret if specified otherwise .config values will be used. Check [here](https://docs.victoriametrics.com/victoriametrics/vmauth/) for details. -# Configuration in the given secret must be stored under `auth.yml` key. -secretName: "vmauth-infra-prd-secret" - -# -- Config file content. -config: {} - # users: - # - username: "$(USERNAME)" - # password: "$(PASSWORD)" - # url_map: - # - src_paths: - # - "/admin-secured/.*" - # drop_src_path_prefix_parts: 1 - # url_prefix: "http://vmselect-infra-prd-test:8481/select/200" - # - src_paths: - # - "/supply-secured/.*" - # drop_src_path_prefix_parts: 1 - # url_prefix: "http://vmselect-supply-prd-clusternative.victoriametrics.svc.clusterset.local:8481/select/200" - # unauthorized_user: - # url_map: - # - src_paths: - # - "/admin/.*" - # drop_src_path_prefix_parts: 1 - # url_prefix: "http://vmselect-infra-prd-test:8481/select/100" - # - src_paths: - # - "/supply/.*" - # drop_src_path_prefix_parts: 1 - # url_prefix: "http://vmselect-supply-prd-clusternative.victoriametrics.svc.clusterset.local:8481/select/100" - # Usernames must be unique. - # users: - # The user for querying local single-node VictoriaMetrics. - # All the requests to http://vmauth:8427 with the given Basic Auth (username:password) - # will be routed to http://localhost:8428 . - # For example, http://vmauth:8427/api/v1/query is routed to http://localhost:8428/api/v1/query - # - username: "local-single-node" - # password: "***" - # url_prefix: "http://localhost:8428" - - # The user for querying account 123 in VictoriaMetrics cluster - # See https://github.com/VictoriaMetrics/VictoriaMetrics/blob/cluster/README.md#url-format - # All the requests to http://vmauth:8427 with the given Basic Auth (username:password) - # will be routed to http://vmselect:8481/select/123/prometheus . - # For example, http://vmauth:8427/api/v1/query is routed to http://vmselect:8481/select/123/prometheus/api/v1/select - # - username: "cluster-select-account-123" - # password: "***" - # url_prefix: "http://vmselect:8481/select/123/prometheus" - - # The user for inserting Prometheus data into VictoriaMetrics cluster under account 42 - # See https://github.com/VictoriaMetrics/VictoriaMetrics/blob/cluster/README.md#url-format - # All the requests to http://vmauth:8427 with the given Basic Auth (username:password) - # will be routed to http://vminsert:8480/insert/42/prometheus . - # For example, http://vmauth:8427/api/v1/write is routed to http://vminsert:8480/insert/42/prometheus/api/v1/write - # - username: "cluster-insert-account-42" - # password: "***" - # url_prefix: "http://vminsert:8480/insert/42/prometheus" - -# -- Annotations for config secret -configAnnotations: {} - -# -- Add extra specs dynamically to this chart -extraObjects: [] - - -externalSecrets: - refreshInterval: "150s" - secretStoreRef: - name: vault-backend - kind: ClusterSecretStore - dataFrom: - secretKey: "admin/common-infra/vmauth" - -probe: - # -- Readiness probe - readiness: - tcpSocket: {} - initialDelaySeconds: 5 - periodSeconds: 15 - # -- Liveness probe - liveness: - tcpSocket: {} - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - # -- Startup probe - startup: {} diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-insert-dbackup/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-insert-dbackup/custom-values.yaml deleted file mode 100644 index bf99edd..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-insert-dbackup/custom-values.yaml +++ /dev/null @@ -1,235 +0,0 @@ -vmselect: - enabled: false - -vmstorage: - enabled: false - fullnameOverride: vmstorage-infra-prd-dbackup - replicaCount: 2 - -dedicatedValue: false -# schedulerName: default-scheduler - -vminsert: - # -- Enable deployment of vminsert component. Deployment is used - enabled: true - # -- vminsert container name - name: vminsert - strategy: {} - # rollingUpdate: - # maxSurge: 25% - # maxUnavailable: 25% - # type: RollingUpdate - image: - # -- Image repository - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/vminsert - # -- Image tag - tag: v1.93.7-cluster - # -- Image pull policy - pullPolicy: IfNotPresent - # -- Name of Priority Class - priorityClassName: "" - # -- Overrides the full name of vminsert component - fullnameOverride: vminsert-infra-prd-dbackup - # Extra command line arguments for vminsert component - extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - maxLabelsPerTimeseries: 40 - maxInsertRequestSize: 1TB - replicationFactor: 1 - loggerTimezone: "Asia/Kolkata" - - annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8480" - extraLabels: - bu: "infra" - team: "sre" - service: "vminsert-infra-prd-dbackup" - env: "prd" - priority: "p0" - type: "vminsert-dbackup" - # arch: "arm64" - # runpod: "ondemand" - - # -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables - env: [] - # -- Suppress rendering `--storageNode` FQDNs based on `vmstorage.replicaCount` value. If true suppress rendering `--storageNodes`, they can be re-defined in extraArgs - suppresStorageFQDNsRender: false - automountServiceAccountToken: true - - # Readiness & Liveness probes - probe: - readiness: - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - liveness: - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - -# Horizontal Pod Autoscaling - horizontalPodAutoscaler: - # -- Use HPA for vminsert component - enabled: true - # -- Maximum replicas for HPA to use to to scale the vminsert component - maxReplicas: 10 - # -- Minimum replicas for HPA to use to scale the vminsert component - minReplicas: 2 - # -- Metric for HPA to use to scale the vminsert component - metrics: - - type: Resource - resource: - name: cpu - target: - type: Utilization - averageUtilization: 40 - - # Extra Volumes for the pod - extraVolumes: - [] - # - name: example - # configMap: - # name: example - - # Extra Volume Mounts for the container - extraVolumeMounts: - [] - # - name: example - # mountPath: /example - - extraContainers: - [] - # - name: config-reloader - # image: reloader-image - - initContainers: - [] - # - name: example - # image: example-image - - podDisruptionBudget: - # -- See `kubectl explain poddisruptionbudget.spec` for more. Ref: [https://kubernetes.io/docs/tasks/run-application/configure-pdb/](https://kubernetes.io/docs/tasks/run-application/configure-pdb/) - enabled: false - # minAvailable: 1 - # maxUnavailable: 1 - labels: {} - - # -- Array of tolerations object. Ref: [https://kubernetes.io/docs/concepts/configuration/assign-pod-node/](https://kubernetes.io/docs/concepts/configuration/assign-pod-node/) - tolerations: - - key: "dedicated" - operator: "Equal" - value: "vmstack-dbackup" - effect: "NoSchedule" - - # -- Pod's node selector. Ref: [https://kubernetes.io/docs/user-guide/node-selection/](https://kubernetes.io/docs/user-guide/node-selection/) - nodeSelector: - dedicated: "vmstack-dbackup" - - # -- Pod affinity - affinity: {} - topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmstack-dbackup - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: DoNotSchedule - labelSelector: - matchLabels: - type: vmstack-dbackup - # -- Pod's annotations - podAnnotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8480" - # -- Count of vminsert pods - replicaCount: 2 - # -- Container workdir - containerWorkingDir: "" - # -- Resource object - resources: - # limits: - # cpu: 50m - # memory: 64Mi - requests: - cpu: 4 - memory: 4Gi - # -- Pod's security context. Ref: [https://kubernetes.io/docs/tasks/configure-pod-container/security-context/](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/) - securityContext: {} - podSecurityContext: {} - service: - # -- Service annotations - annotations: {} - # -- Service labels - labels: {} - # -- Service ClusterIP - clusterIP: "" - # -- Service External IPs. Ref: [https://kubernetes.io/docs/user-guide/services/#external-ips]( https://kubernetes.io/docs/user-guide/services/#external-ips) - externalIPs: [] - # -- Extra service ports - extraServicePorts: [] - # -- Service load balancer IP - loadBalancerIP: "" - # -- Load balancer source range - loadBalancerSourceRanges: [] - # -- Service port - servicePort: 8480 - # -- Target port - targetPort: http - # -- Service type - type: ClusterIP - # -- Enable UDP port. used if you have "spec.opentsdbListenAddr" specified - # -- Make sure that service is not type "LoadBalancer", as it requires "MixedProtocolLBService" feature gate. ref: https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/ - udp: false - ingress: - # -- Enable deployment of ingress for vminsert component - enabled: true - # -- Ingress annotations - annotations: - nginx.ingress.kubernetes.io/force-ssl-redirect: "false" - nginx.ingress.kubernetes.io/ssl-redirect: "false" - # kubernetes.io/ingress.class: nginx - # kubernetes.io/tls-acme: 'true' - extraLabels: {} - # -- Array of host objects - hosts: - - name: vminsert-infra-prd-dbackup.meeshogcp.in - path: / - port: http - # -- Array of TLS objects - tls: [] - # - secretName: vminsert-ingress-tls - # hosts: - # - vminsert.local - # For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName - # See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress - ingressClassName: nginx-internal - # -- pathType is only for k8s >= 1.1= - pathType: Prefix - serviceMonitor: - # -- Enable deployment of Service Monitor for vminsert component. This is Prometheus operator object - enabled: false - # -- Target namespace of ServiceMonitor manifest - namespace: "" - # -- Service Monitor labels - extraLabels: {} - # -- Service Monitor annotations - annotations: {} - # Commented. Prometheus scare interval for vminsert component -# interval: 15s - # Commented. Prometheus pre-scrape timeout for vminsert component -# scrapeTimeout: 5s - # -- Commented. HTTP scheme to use for scraping. -# scheme: https - # -- Commented. TLS configuration to use when scraping the endpoint -# tlsConfig: -# insecureSkipVerify: true - # -- Service Monitor relabelings - relabelings: [] diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-insert-dr/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-insert-dr/custom-values.yaml deleted file mode 100644 index 5b045a3..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-insert-dr/custom-values.yaml +++ /dev/null @@ -1,234 +0,0 @@ -vmselect: - enabled: false - -vmstorage: - enabled: false - fullnameOverride: vmstorage-infra-prd-dr - replicaCount: 5 - -dedicatedValue: false -# schedulerName: default-scheduler - -vminsert: - # -- Enable deployment of vminsert component. Deployment is used - enabled: true - # -- vminsert container name - name: vminsert - strategy: {} - # rollingUpdate: - # maxSurge: 25% - # maxUnavailable: 25% - # type: RollingUpdate - image: - # -- Image repository - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/vminsert - # -- Image tag - tag: v1.93.7-cluster - # -- Image pull policy - pullPolicy: IfNotPresent - # -- Name of Priority Class - priorityClassName: "" - # -- Overrides the full name of vminsert component - fullnameOverride: vminsert-infra-prd-dr - # Extra command line arguments for vminsert component - extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - maxLabelsPerTimeseries: 40 - replicationFactor: 1 - loggerTimezone: "Asia/Kolkata" - - annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8480" - extraLabels: - bu: "infra" - team: "sre" - service: "vminsert-infra-prd-dr" - env: "prd" - priority: "p0" - type: "vminsert-dr" - # arch: "arm64" - # runpod: "ondemand" - - # -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables - env: [] - # -- Suppress rendering `--storageNode` FQDNs based on `vmstorage.replicaCount` value. If true suppress rendering `--storageNodes`, they can be re-defined in extraArgs - suppresStorageFQDNsRender: false - automountServiceAccountToken: true - - # Readiness & Liveness probes - probe: - readiness: - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - liveness: - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - -# Horizontal Pod Autoscaling - horizontalPodAutoscaler: - # -- Use HPA for vminsert component - enabled: true - # -- Maximum replicas for HPA to use to to scale the vminsert component - maxReplicas: 10 - # -- Minimum replicas for HPA to use to scale the vminsert component - minReplicas: 2 - # -- Metric for HPA to use to scale the vminsert component - metrics: - - type: Resource - resource: - name: cpu - target: - type: Utilization - averageUtilization: 40 - - # Extra Volumes for the pod - extraVolumes: - [] - # - name: example - # configMap: - # name: example - - # Extra Volume Mounts for the container - extraVolumeMounts: - [] - # - name: example - # mountPath: /example - - extraContainers: - [] - # - name: config-reloader - # image: reloader-image - - initContainers: - [] - # - name: example - # image: example-image - - podDisruptionBudget: - # -- See `kubectl explain poddisruptionbudget.spec` for more. Ref: [https://kubernetes.io/docs/tasks/run-application/configure-pdb/](https://kubernetes.io/docs/tasks/run-application/configure-pdb/) - enabled: false - # minAvailable: 1 - # maxUnavailable: 1 - labels: {} - - # -- Array of tolerations object. Ref: [https://kubernetes.io/docs/concepts/configuration/assign-pod-node/](https://kubernetes.io/docs/concepts/configuration/assign-pod-node/) - tolerations: - - key: "dedicated" - operator: "Equal" - value: "vminsert-dr" - effect: "NoSchedule" - - # -- Pod's node selector. Ref: [https://kubernetes.io/docs/user-guide/node-selection/](https://kubernetes.io/docs/user-guide/node-selection/) - nodeSelector: - dedicated: "vminsert-dr" - - # -- Pod affinity - affinity: {} - topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vminsert-dr - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: DoNotSchedule - labelSelector: - matchLabels: - type: vminsert-dr - # -- Pod's annotations - podAnnotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8480" - # -- Count of vminsert pods - replicaCount: 2 - # -- Container workdir - containerWorkingDir: "" - # -- Resource object - resources: - # limits: - # cpu: 50m - # memory: 64Mi - requests: - cpu: 4 - memory: 2Gi - # -- Pod's security context. Ref: [https://kubernetes.io/docs/tasks/configure-pod-container/security-context/](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/) - securityContext: {} - podSecurityContext: {} - service: - # -- Service annotations - annotations: {} - # -- Service labels - labels: {} - # -- Service ClusterIP - clusterIP: "" - # -- Service External IPs. Ref: [https://kubernetes.io/docs/user-guide/services/#external-ips]( https://kubernetes.io/docs/user-guide/services/#external-ips) - externalIPs: [] - # -- Extra service ports - extraServicePorts: [] - # -- Service load balancer IP - loadBalancerIP: "" - # -- Load balancer source range - loadBalancerSourceRanges: [] - # -- Service port - servicePort: 8480 - # -- Target port - targetPort: http - # -- Service type - type: ClusterIP - # -- Enable UDP port. used if you have "spec.opentsdbListenAddr" specified - # -- Make sure that service is not type "LoadBalancer", as it requires "MixedProtocolLBService" feature gate. ref: https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/ - udp: false - ingress: - # -- Enable deployment of ingress for vminsert component - enabled: true - # -- Ingress annotations - annotations: - nginx.ingress.kubernetes.io/force-ssl-redirect: "false" - nginx.ingress.kubernetes.io/ssl-redirect: "false" - # kubernetes.io/ingress.class: nginx - # kubernetes.io/tls-acme: 'true' - extraLabels: {} - # -- Array of host objects - hosts: - - name: vminsert-infra-prd-dr.meeshogcp.in - path: / - port: http - # -- Array of TLS objects - tls: [] - # - secretName: vminsert-ingress-tls - # hosts: - # - vminsert.local - # For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName - # See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress - ingressClassName: nginx-internal - # -- pathType is only for k8s >= 1.1= - pathType: Prefix - serviceMonitor: - # -- Enable deployment of Service Monitor for vminsert component. This is Prometheus operator object - enabled: false - # -- Target namespace of ServiceMonitor manifest - namespace: "" - # -- Service Monitor labels - extraLabels: {} - # -- Service Monitor annotations - annotations: {} - # Commented. Prometheus scare interval for vminsert component -# interval: 15s - # Commented. Prometheus pre-scrape timeout for vminsert component -# scrapeTimeout: 5s - # -- Commented. HTTP scheme to use for scraping. -# scheme: https - # -- Commented. TLS configuration to use when scraping the endpoint -# tlsConfig: -# insecureSkipVerify: true - # -- Service Monitor relabelings - relabelings: [] diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-insert/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-insert/custom-values.yaml deleted file mode 100644 index 92a0b55..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-insert/custom-values.yaml +++ /dev/null @@ -1,234 +0,0 @@ -vmselect: - enabled: false - -vmstorage: - enabled: false - fullnameOverride: vmstorage-infra-prd - replicaCount: 5 - -dedicatedValue: false -# schedulerName: default-scheduler - -vminsert: - # -- Enable deployment of vminsert component. Deployment is used - enabled: true - # -- vminsert container name - name: vminsert - strategy: {} - # rollingUpdate: - # maxSurge: 25% - # maxUnavailable: 25% - # type: RollingUpdate - image: - # -- Image repository - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/vminsert - # -- Image tag - tag: v1.93.7-cluster - # -- Image pull policy - pullPolicy: IfNotPresent - # -- Name of Priority Class - priorityClassName: "" - # -- Overrides the full name of vminsert component - fullnameOverride: vminsert-infra-prd - # Extra command line arguments for vminsert component - extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - maxLabelsPerTimeseries: 40 - replicationFactor: 1 - loggerTimezone: "Asia/Kolkata" - - annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8480" - extraLabels: - bu: "infra" - team: "sre" - service: "vminsert-infra-prd" - env: "prd" - priority: "p0" - type: "vminsert" - # arch: "arm64" - # runpod: "ondemand" - - # -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables - env: [] - # -- Suppress rendering `--storageNode` FQDNs based on `vmstorage.replicaCount` value. If true suppress rendering `--storageNodes`, they can be re-defined in extraArgs - suppresStorageFQDNsRender: false - automountServiceAccountToken: true - - # Readiness & Liveness probes - probe: - readiness: - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - liveness: - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - -# Horizontal Pod Autoscaling - horizontalPodAutoscaler: - # -- Use HPA for vminsert component - enabled: true - # -- Maximum replicas for HPA to use to to scale the vminsert component - maxReplicas: 10 - # -- Minimum replicas for HPA to use to scale the vminsert component - minReplicas: 3 - # -- Metric for HPA to use to scale the vminsert component - metrics: - - type: Resource - resource: - name: cpu - target: - type: Utilization - averageUtilization: 40 - - # Extra Volumes for the pod - extraVolumes: - [] - # - name: example - # configMap: - # name: example - - # Extra Volume Mounts for the container - extraVolumeMounts: - [] - # - name: example - # mountPath: /example - - extraContainers: - [] - # - name: config-reloader - # image: reloader-image - - initContainers: - [] - # - name: example - # image: example-image - - podDisruptionBudget: - # -- See `kubectl explain poddisruptionbudget.spec` for more. Ref: [https://kubernetes.io/docs/tasks/run-application/configure-pdb/](https://kubernetes.io/docs/tasks/run-application/configure-pdb/) - enabled: false - # minAvailable: 1 - # maxUnavailable: 1 - labels: {} - - # -- Array of tolerations object. Ref: [https://kubernetes.io/docs/concepts/configuration/assign-pod-node/](https://kubernetes.io/docs/concepts/configuration/assign-pod-node/) - tolerations: - - key: "dedicated" - operator: "Equal" - value: "vminsert-mds" - effect: "NoSchedule" - - # -- Pod's node selector. Ref: [https://kubernetes.io/docs/user-guide/node-selection/](https://kubernetes.io/docs/user-guide/node-selection/) - nodeSelector: - dedicated: "vminsert-mds" - - # -- Pod affinity - affinity: {} - topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vminsert - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: DoNotSchedule - labelSelector: - matchLabels: - type: vminsert - # -- Pod's annotations - podAnnotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8480" - # -- Count of vminsert pods - replicaCount: 2 - # -- Container workdir - containerWorkingDir: "" - # -- Resource object - resources: - # limits: - # cpu: 50m - # memory: 64Mi - requests: - cpu: 5 - memory: 10Gi - # -- Pod's security context. Ref: [https://kubernetes.io/docs/tasks/configure-pod-container/security-context/](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/) - securityContext: {} - podSecurityContext: {} - service: - # -- Service annotations - annotations: {} - # -- Service labels - labels: {} - # -- Service ClusterIP - clusterIP: "" - # -- Service External IPs. Ref: [https://kubernetes.io/docs/user-guide/services/#external-ips]( https://kubernetes.io/docs/user-guide/services/#external-ips) - externalIPs: [] - # -- Extra service ports - extraServicePorts: [] - # -- Service load balancer IP - loadBalancerIP: "" - # -- Load balancer source range - loadBalancerSourceRanges: [] - # -- Service port - servicePort: 8480 - # -- Target port - targetPort: http - # -- Service type - type: ClusterIP - # -- Enable UDP port. used if you have "spec.opentsdbListenAddr" specified - # -- Make sure that service is not type "LoadBalancer", as it requires "MixedProtocolLBService" feature gate. ref: https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/ - udp: false - ingress: - # -- Enable deployment of ingress for vminsert component - enabled: true - # -- Ingress annotations - annotations: - nginx.ingress.kubernetes.io/force-ssl-redirect: "false" - nginx.ingress.kubernetes.io/ssl-redirect: "false" - # kubernetes.io/ingress.class: nginx - # kubernetes.io/tls-acme: 'true' - extraLabels: {} - # -- Array of host objects - hosts: - - name: vminsert-infra-prd.meeshogcp.in - path: / - port: http - # -- Array of TLS objects - tls: [] - # - secretName: vminsert-ingress-tls - # hosts: - # - vminsert.local - # For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName - # See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress - ingressClassName: nginx-internal - # -- pathType is only for k8s >= 1.1= - pathType: Prefix - serviceMonitor: - # -- Enable deployment of Service Monitor for vminsert component. This is Prometheus operator object - enabled: false - # -- Target namespace of ServiceMonitor manifest - namespace: "" - # -- Service Monitor labels - extraLabels: {} - # -- Service Monitor annotations - annotations: {} - # Commented. Prometheus scare interval for vminsert component -# interval: 15s - # Commented. Prometheus pre-scrape timeout for vminsert component -# scrapeTimeout: 5s - # -- Commented. HTTP scheme to use for scraping. -# scheme: https - # -- Commented. TLS configuration to use when scraping the endpoint -# tlsConfig: -# insecureSkipVerify: true - # -- Service Monitor relabelings - relabelings: [] diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-mcp/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-mcp/custom-values.yaml deleted file mode 100644 index 7dbe61d..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-mcp/custom-values.yaml +++ /dev/null @@ -1,226 +0,0 @@ -externalSecrets: - refreshInterval: "150s" - secretStoreRef: - name: vault-backend - kind: ClusterSecretStore - dataFrom: - secretKey: "admin/common-infra/victoriametrics-mcp" - -replicaCount: 1 - -image: - registry: ghcr.io - repository: victoriametrics/mcp-victoriametrics - pullPolicy: IfNotPresent - # Overrides the image tag whose default is the chart appVersion. - tag: "" - -# This is for the secrets for pulling an image from a private repository more information can be found here: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ -imagePullSecrets: [] -# This is to override the chart name. -nameOverride: "victoriametrics-mcp" -fullnameOverride: "victoriametrics-mcp" - -# This section builds out the service account more information can be found here: https://kubernetes.io/docs/concepts/security/service-accounts/ -serviceAccount: - # Specifies whether a service account should be created - create: true - # Automatically mount a ServiceAccount's API credentials? - automount: true - # Annotations to add to the service account - annotations: {} - # The name of the service account to use. - # If not set and create is true, a name is generated using the fullname template - name: "" - -# This is for setting Kubernetes Annotations to a Pod. -# For more information checkout: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/ -podAnnotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8080" - -# This is for setting Kubernetes Labels to a Pod. -# For more information checkout: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/ -podLabels: - bu: "central" - team: "central-sre" - service: "victoriametrics-mcp-prd" - env: "prd" - priority: "p1" - type: "victoriametrics-mcp" - -podSecurityContext: {} - # fsGroup: 2000 - -mcp: - # Server operation mode: http / sse - mode: http - disable: - # list of tool names to disable - tools: [] - # disable all resources (documentation tool will continue to work) - resources: false - # Defines the heartbeat interval for the streamable-http protocol. It means the MCP server will send a heartbeat to the client through the GET connection, to keep the connection alive from being closed by the network infrastructure (e.g. gateways) - heartbeatInterval: 30s - # HTTP header names to forward from incoming MCP requests to VictoriaMetrics - passthroughHeaders: [] - -vm: - # Type of VictoriaMetrics instance: single / cluster - type: cluster - # URL to VictoriaMetrics instance (it should be root `/` URL of vmsingle or vmselect) - entrypoint: "http://vmselect-central-prd-proxy.victoriametrics.svc.cluster.local:8481/select/100/prometheus" - # Authentication token for VictoriaMetrics API - bearerToken: - secretKeyRef: - name: victoriametrics-mcp-secret - key: bearer-token - # API key from VictoriaMetrics Cloud Console if you work with VictoriaMetrics Cloud - cloudAPIKey: "" - # Custom HTTP headers to send with requests to instances of VictoriaMetrics - headers: [] - -# Extra environment variables to set in the container. -env: [] - -securityContext: {} - # capabilities: - # drop: - # - ALL - # readOnlyRootFilesystem: true - # runAsNonRoot: true - # runAsUser: 1000 - -# This is for setting up a service more information can be found here: https://kubernetes.io/docs/concepts/services-networking/service/ -service: - # This sets the service type more information can be found here: https://kubernetes.io/docs/concepts/services-networking/service/#publishing-services-service-types - type: ClusterIP - # This sets the ports more information can be found here: https://kubernetes.io/docs/concepts/services-networking/service/#field-spec-ports - port: 8080 - -# Exposed via Contour (contour-internal-0, newly deployed on k8s-admin-prd-ase1) -# instead of nginx-internal. `ingress.enabled: false` keeps the chart's -# networking.k8s.io Ingress from rendering; the Contour HTTPProxy template -# (gated on httpProxy.enabled + createContourGateway + a contour-* class) -# builds the parent/child HTTPProxy from ingress.hosts / servicePortNumber. -ingress: - enabled: false - ingressClassName: contour-internal-0 - servicePortNumber: 8080 - hosts: - - host: vm-mcp.prd.meesho.int - paths: - - path: / - pathType: Prefix - tls: [] - -# Render the Contour HTTPProxy (parent/child) for this MCP service. -httpProxy: - enabled: true - -# Required by the chart's HTTPProxy template gate. -createContourGateway: true - -# -- Expose the service via gateway-api HTTPRoute -# Requires Gateway API resources and suitable controller installed within the cluster -# (see: https://gateway-api.sigs.k8s.io/guides/) -route: - # HTTPRoute enabled. - enabled: false - # HTTPRoute annotations. - annotations: {} - # Which Gateways this Route is attached to. - parentRefs: - - name: gateway - sectionName: http - # namespace: default - # Hostnames matching HTTP header. - hostnames: [] - # List of rules and filters applied. - rules: - - matches: - - path: - type: PathPrefix - value: / - # filters: - # - type: RequestHeaderModifier - # requestHeaderModifier: - # set: - # - name: My-Overwrite-Header - # value: this-is-the-only-value - # remove: - # - User-Agent - # - matches: - # - path: - # type: PathPrefix - # value: /echo - # headers: - # - name: version - # value: v2 - -resources: - requests: - cpu: 250m - memory: 256Mi - # limits: - # cpu: 100m - # memory: 128Mi - -# This is to setup the liveness and readiness probes more information can be found here: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/ -livenessProbe: - httpGet: - path: /health/liveness - port: http - scheme: HTTP - initialDelaySeconds: 10 - timeoutSeconds: 1 - periodSeconds: 10 -readinessProbe: - httpGet: - path: /health/readiness - port: http - scheme: HTTP - initialDelaySeconds: 10 - timeoutSeconds: 1 - periodSeconds: 10 - -# Additional volumes on the output Deployment definition. -volumes: [] -# - name: foo -# secret: -# secretName: mysecret -# optional: false - -# Additional volumeMounts on the output Deployment definition. -volumeMounts: [] -# - name: foo -# mountPath: "/etc/foo" -# readOnly: true - -nodeSelector: - dedicated: "vmagent-mds" - -tolerations: - - key: "dedicated" - operator: "Equal" - value: "vmagent-mds" - effect: "NoSchedule" - -topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: victoriametrics-mcp - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: victoriametrics-mcp - -affinity: {} - -scrape: - enabled: false diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-select-dbackup/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-select-dbackup/custom-values.yaml deleted file mode 100644 index 8554390..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-select-dbackup/custom-values.yaml +++ /dev/null @@ -1,311 +0,0 @@ -vminsert: - enabled: false - -vmstorage: - enabled: false - fullnameOverride: vmstorage-infra-prd-dbackup - replicaCount: 5 - -dedicatedValue: false - - -vmselect: - # -- Enable deployment of vmselect component. Can be deployed as Deployment(default) or StatefulSet - enabled: true - splitService: True - # -- Vmselect container name - name: vmselect - strategy: - rollingUpdate: - maxSurge: 25% - maxUnavailable: 25% - type: RollingUpdate - #extraVMSelects: [] - extraVMSelects: - # - --storageNode=vmselect-supply-prd.victoriametrics.svc.cluster.local:8401 - # - --storageNode=vmselect-demand-prd.victoriametrics.svc.cluster.local:8401 - # - --storageNode=vmselect-central-prd.victoriametrics.svc.cluster.local:8401 - # - --storageNode=vmselect-demand-prd-clusternative.victoriametrics.svc.cluster.local:8401 - # - --storageNode=vmselect-datascience-prd-clusternative.victoriametrics.svc.cluster.local:8401 - # - --storageNode=vmselect-dataengg-prd-clusternative.victoriametrics.svc.cluster.local:8401 - # - --storageNode=vmselect-supply-prd-clusternative.victoriametrics.svc.cluster.local:8401 - # - --storageNode=vmselect-farmiso-prd-clusternative.victoriametrics.svc.cluster.local:8401 - # # - --storageNode=vmselect-datascience-prd.victoriametrics.svc.cluster.local:8401 - # - --storageNode=vmselect-dataengg-prd.victoriametrics.svc.cluster.local:8401 - # - --storageNode=vmselect-farmiso-prd.victoriametrics.svc.cluster.local:8401 - # - --storageNode=prd-supply-vmselect:8401 - # - --storageNode=prd-dataplatform-vmselect:8401 - # - --storageNode=prd-datascience-vmselect:8401 - # - --storageNode=prd-dp-starburst-vmselect:8401 - # - --storageNode=prd-central-vmselect:8401 - # - --storageNode=prd-mcache-vmselect:8401 - - image: - # -- Image repository - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/vmselect - # -- Image tag - tag: v1.93.7-cluster - # -- Image pull policy - pullPolicy: IfNotPresent - # -- Name of Priority Class - priorityClassName: "" - # -- Overrides the full name of vmselect component - fullnameOverride: vmselect-infra-prd-dbackup - # -- Suppress rendering `--storageNode` FQDNs based on `vmstorage.replicaCount` value. If true suppress rendering `--storageNodes`, they can be re-defined in extraArgs - suppresStorageFQDNsRender: false - automountServiceAccountToken: true - # Extra command line arguments for vmselect component - extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - clusternativeListenAddr: ":8401" - dedup.minScrapeInterval: 60s - search.maxSamplesPerQuery: "1000000000000" - search.maxQueryDuration: 180s - search.maxQueueDuration: 60s - search.maxSeries: "10000000000" - search.maxExportSeries: "1000000000" - search.maxConcurrentRequests: 89 - search.maxUniqueTimeseries: "1000000000000" - search.maxQueryLen: "1000000" - loggerTimezone: "Asia/Kolkata" - - - annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8481" - extraLabels: - bu: "infra" - team: "sre" - service: "vmselect-infra-prd-dbackup" - env: "prd" - priority: "p0" - type: "vmselect-dbackup" - # arch: "arm64" - # runpod: "ondemand" - - # -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables - env: [] - - # Readiness & Liveness probes - probe: - readiness: - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - liveness: - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - - horizontalPodAutoscaler: - # -- Use HPA for vmselect component - enabled: true - # -- Maximum replicas for HPA to use to to scale the vmselect component - maxReplicas: 80 - # -- Minimum replicas for HPA to use to scale the vmselect component - minReplicas: 2 - # -- Metric for HPA to use to scale the vmselect component - metrics: - - type: Resource - resource: - name: cpu - target: - type: Utilization - averageUtilization: 60 - - # Additional hostPath mounts - extraHostPathMounts: - [] - # - name: certs-dir - # mountPath: /etc/kubernetes/certs - # subPath: "" - # hostPath: /etc/kubernetes/certs - # readOnly: true - - # Extra Volumes for the pod - extraVolumes: - [] - # - name: example - # configMap: - # name: example - - # Extra Volume Mounts for the container - extraVolumeMounts: - [] - # - name: example - # mountPath: /example - - extraContainers: - [] - # - name: config-reloader - # image: reloader-image - - initContainers: - [] - # - name: example - # image: example-image - - podDisruptionBudget: - # -- See `kubectl explain poddisruptionbudget.spec` for more. Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/ - enabled: true - minAvailable: 1 - # maxUnavailable: 1 - labels: {} - - - nodeSelector: - dedicated: "vmstack-dbackup" - - tolerations: - - key: "dedicated" - operator: "Equal" - value: "vmstack-dbackup" - effect: "NoSchedule" - - - # -- Pod affinity - affinity: {} - # -- Pod topologySpreadConstraints - topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmstack-dbackup - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmstack-dbackup - # -- Pod's annotations - podAnnotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8481" - # -- Count of vmselect pods - replicaCount: 2 - # -- Container workdir - containerWorkingDir: "" - # -- Resource object - resources: - # limits: - # cpu: 50m - # memory: 64Mi - requests: - cpu: 4 - memory: 4Gi - - # -- Pod's security context. Ref: [https://kubernetes.io/docs/tasks/configure-pod-container/security-context/](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ - securityContext: {} - podSecurityContext: {} - # -- Cache root folder - cacheMountPath: /cache - service: - # -- Service annotations - annotations: - io.cilium/global-service: "true" - # -- Service labels - labels: {} - # -- Service ClusterIP - clusterIP: "" - # -- Service External IPs. Ref: [https://kubernetes.io/docs/user-guide/services/#external-ips](https://kubernetes.io/docs/user-guide/services/#external-ips) - externalIPs: [] - # -- Extra service ports - extraServicePorts: [] - # -- Service load balacner IP - loadBalancerIP: "" - # -- Load balancer source range - loadBalancerSourceRanges: [] - # -- Service port - servicePort: 8481 - # -- Target port - targetPort: http - # -- Service type - type: ClusterIP - ingress: - # -- Enable deployment of ingress for vmselect component - enabled: true - # -- Ingress annotations - annotations: - nginx.ingress.kubernetes.io/force-ssl-redirect: "false" - nginx.ingress.kubernetes.io/ssl-redirect: "false" - # kubernetes.io/ingress.class: nginx - # kubernetes.io/tls-acme: 'true' - ingressClassName: nginx-internal - - extraLabels: {} - # -- Array of host objects - hosts: - - name: vmselect-infra-prd-dbackup.meeshogcp.in - path: / - port: http - # -- Array of TLS objects - tls: [] - # - secretName: vmselect-ingress-tls - # hosts: - # - vmselect.local - # For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName - # See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress - # ingressClassName: nginx - # -- pathType is only for k8s >= 1.1= - pathType: Prefix - statefulSet: - # -- Deploy StatefulSet instead of Deployment for vmselect. Useful if you want to keep cache data. - enabled: false - # -- Deploy order policy for StatefulSet pods - podManagementPolicy: OrderedReady - ## Headless service for statefulset - service: - # -- Headless service annotations - annotations: {} - # -- Headless service labels - labels: {} - # -- Headless service port - servicePort: 8481 - persistentVolume: - # -- Create/use Persistent Volume Claim for vmselect component. Empty dir if false. If true, vmselect will create/use a Persistent Volume Claim - enabled: false - - # -- Array of access mode. Must match those of existing PV or dynamic provisioner. Ref: [http://kubernetes.io/docs/user-guide/persistent-volumes/](http://kubernetes.io/docs/user-guide/persistent-volumes/) - accessModes: - - ReadWriteOnce - # -- Persistent volume annotations - annotations: {} - - # -- Persistent volume labels - labels: {} - - # -- Existing Claim name. Requires vmselect.persistentVolume.enabled: true. If defined, PVC must be created manually before volume will be bound - existingClaim: "" - - ## Vmselect data Persistent Volume mount root path - ## - # -- Size of the volume. Better to set the same as resource limit memory property - size: 2Gi - # -- Mount subpath - subPath: "" - serviceMonitor: - # -- Enable deployment of Service Monitor for vmselect component. This is Prometheus operator object - enabled: false - # -- Target namespace of ServiceMonitor manifest - namespace: "" - # -- Service Monitor labels - extraLabels: {} - # -- Service Monitor annotations - annotations: {} - # Commented. Prometheus scare interval for vmselect component -# interval: 15s - # Commented. Prometheus pre-scrape timeout for vmselect component -# scrapeTimeout: 5s - # -- Commented. HTTP scheme to use for scraping. -# scheme: https - # -- Commented. TLS configuration to use when scraping the endpoint -# tlsConfig: -# insecureSkipVerify: true - # -- Service Monitor relabelings - relabelings: [] diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-select-dr/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-select-dr/custom-values.yaml deleted file mode 100644 index 7a51116..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-select-dr/custom-values.yaml +++ /dev/null @@ -1,311 +0,0 @@ -vminsert: - enabled: false - -vmstorage: - enabled: false - fullnameOverride: vmstorage-infra-prd-dr - replicaCount: 5 - -dedicatedValue: false - - -vmselect: - # -- Enable deployment of vmselect component. Can be deployed as Deployment(default) or StatefulSet - enabled: true - splitService: True - # -- Vmselect container name - name: vmselect - strategy: - rollingUpdate: - maxSurge: 25% - maxUnavailable: 25% - type: RollingUpdate - #extraVMSelects: [] - extraVMSelects: - # - --storageNode=vmselect-supply-prd.victoriametrics.svc.cluster.local:8401 - # - --storageNode=vmselect-demand-prd.victoriametrics.svc.cluster.local:8401 - # - --storageNode=vmselect-central-prd.victoriametrics.svc.cluster.local:8401 - # - --storageNode=vmselect-demand-prd-clusternative.victoriametrics.svc.cluster.local:8401 - # - --storageNode=vmselect-datascience-prd-clusternative.victoriametrics.svc.cluster.local:8401 - # - --storageNode=vmselect-dataengg-prd-clusternative.victoriametrics.svc.cluster.local:8401 - # - --storageNode=vmselect-supply-prd-clusternative.victoriametrics.svc.cluster.local:8401 - # - --storageNode=vmselect-farmiso-prd-clusternative.victoriametrics.svc.cluster.local:8401 - # # - --storageNode=vmselect-datascience-prd.victoriametrics.svc.cluster.local:8401 - # - --storageNode=vmselect-dataengg-prd.victoriametrics.svc.cluster.local:8401 - # - --storageNode=vmselect-farmiso-prd.victoriametrics.svc.cluster.local:8401 - # - --storageNode=prd-supply-vmselect:8401 - # - --storageNode=prd-dataplatform-vmselect:8401 - # - --storageNode=prd-datascience-vmselect:8401 - # - --storageNode=prd-dp-starburst-vmselect:8401 - # - --storageNode=prd-central-vmselect:8401 - # - --storageNode=prd-mcache-vmselect:8401 - - image: - # -- Image repository - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/vmselect - # -- Image tag - tag: v1.93.7-cluster - # -- Image pull policy - pullPolicy: IfNotPresent - # -- Name of Priority Class - priorityClassName: "" - # -- Overrides the full name of vmselect component - fullnameOverride: vmselect-infra-prd-dr - # -- Suppress rendering `--storageNode` FQDNs based on `vmstorage.replicaCount` value. If true suppress rendering `--storageNodes`, they can be re-defined in extraArgs - suppresStorageFQDNsRender: false - automountServiceAccountToken: true - # Extra command line arguments for vmselect component - extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - clusternativeListenAddr: ":8401" - dedup.minScrapeInterval: 60s - search.maxSamplesPerQuery: "1000000000000" - search.maxQueryDuration: 180s - search.maxQueueDuration: 60s - search.maxSeries: "10000000000" - search.maxExportSeries: "1000000000" - search.maxConcurrentRequests: 89 - search.maxUniqueTimeseries: "1000000000000" - search.maxQueryLen: "1000000" - loggerTimezone: "Asia/Kolkata" - - - annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8481" - extraLabels: - bu: "infra" - team: "sre" - service: "vmselect-infra-prd-dr" - env: "prd" - priority: "p0" - type: "vmselect-dr" - # arch: "arm64" - # runpod: "ondemand" - - # -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables - env: [] - - # Readiness & Liveness probes - probe: - readiness: - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - liveness: - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - - horizontalPodAutoscaler: - # -- Use HPA for vmselect component - enabled: true - # -- Maximum replicas for HPA to use to to scale the vmselect component - maxReplicas: 80 - # -- Minimum replicas for HPA to use to scale the vmselect component - minReplicas: 2 - # -- Metric for HPA to use to scale the vmselect component - metrics: - - type: Resource - resource: - name: cpu - target: - type: Utilization - averageUtilization: 60 - - # Additional hostPath mounts - extraHostPathMounts: - [] - # - name: certs-dir - # mountPath: /etc/kubernetes/certs - # subPath: "" - # hostPath: /etc/kubernetes/certs - # readOnly: true - - # Extra Volumes for the pod - extraVolumes: - [] - # - name: example - # configMap: - # name: example - - # Extra Volume Mounts for the container - extraVolumeMounts: - [] - # - name: example - # mountPath: /example - - extraContainers: - [] - # - name: config-reloader - # image: reloader-image - - initContainers: - [] - # - name: example - # image: example-image - - podDisruptionBudget: - # -- See `kubectl explain poddisruptionbudget.spec` for more. Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/ - enabled: true - minAvailable: 1 - # maxUnavailable: 1 - labels: {} - - - nodeSelector: - dedicated: "vmselect-dr" - - tolerations: - - key: "dedicated" - operator: "Equal" - value: "vmselect-dr" - effect: "NoSchedule" - - - # -- Pod affinity - affinity: {} - # -- Pod topologySpreadConstraints - topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmselect-dr - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmselect-dr - # -- Pod's annotations - podAnnotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8481" - # -- Count of vmselect pods - replicaCount: 2 - # -- Container workdir - containerWorkingDir: "" - # -- Resource object - resources: - # limits: - # cpu: 50m - # memory: 64Mi - requests: - cpu: 29 - memory: 100Gi - - # -- Pod's security context. Ref: [https://kubernetes.io/docs/tasks/configure-pod-container/security-context/](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ - securityContext: {} - podSecurityContext: {} - # -- Cache root folder - cacheMountPath: /cache - service: - # -- Service annotations - annotations: - io.cilium/global-service: "true" - # -- Service labels - labels: {} - # -- Service ClusterIP - clusterIP: "" - # -- Service External IPs. Ref: [https://kubernetes.io/docs/user-guide/services/#external-ips](https://kubernetes.io/docs/user-guide/services/#external-ips) - externalIPs: [] - # -- Extra service ports - extraServicePorts: [] - # -- Service load balacner IP - loadBalancerIP: "" - # -- Load balancer source range - loadBalancerSourceRanges: [] - # -- Service port - servicePort: 8481 - # -- Target port - targetPort: http - # -- Service type - type: ClusterIP - ingress: - # -- Enable deployment of ingress for vmselect component - enabled: true - # -- Ingress annotations - annotations: - nginx.ingress.kubernetes.io/force-ssl-redirect: "false" - nginx.ingress.kubernetes.io/ssl-redirect: "false" - # kubernetes.io/ingress.class: nginx - # kubernetes.io/tls-acme: 'true' - ingressClassName: nginx-internal - - extraLabels: {} - # -- Array of host objects - hosts: - - name: vmselect-infra-prd-dr.meeshogcp.in - path: / - port: http - # -- Array of TLS objects - tls: [] - # - secretName: vmselect-ingress-tls - # hosts: - # - vmselect.local - # For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName - # See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress - # ingressClassName: nginx - # -- pathType is only for k8s >= 1.1= - pathType: Prefix - statefulSet: - # -- Deploy StatefulSet instead of Deployment for vmselect. Useful if you want to keep cache data. - enabled: false - # -- Deploy order policy for StatefulSet pods - podManagementPolicy: OrderedReady - ## Headless service for statefulset - service: - # -- Headless service annotations - annotations: {} - # -- Headless service labels - labels: {} - # -- Headless service port - servicePort: 8481 - persistentVolume: - # -- Create/use Persistent Volume Claim for vmselect component. Empty dir if false. If true, vmselect will create/use a Persistent Volume Claim - enabled: false - - # -- Array of access mode. Must match those of existing PV or dynamic provisioner. Ref: [http://kubernetes.io/docs/user-guide/persistent-volumes/](http://kubernetes.io/docs/user-guide/persistent-volumes/) - accessModes: - - ReadWriteOnce - # -- Persistent volume annotations - annotations: {} - - # -- Persistent volume labels - labels: {} - - # -- Existing Claim name. Requires vmselect.persistentVolume.enabled: true. If defined, PVC must be created manually before volume will be bound - existingClaim: "" - - ## Vmselect data Persistent Volume mount root path - ## - # -- Size of the volume. Better to set the same as resource limit memory property - size: 2Gi - # -- Mount subpath - subPath: "" - serviceMonitor: - # -- Enable deployment of Service Monitor for vmselect component. This is Prometheus operator object - enabled: false - # -- Target namespace of ServiceMonitor manifest - namespace: "" - # -- Service Monitor labels - extraLabels: {} - # -- Service Monitor annotations - annotations: {} - # Commented. Prometheus scare interval for vmselect component -# interval: 15s - # Commented. Prometheus pre-scrape timeout for vmselect component -# scrapeTimeout: 5s - # -- Commented. HTTP scheme to use for scraping. -# scheme: https - # -- Commented. TLS configuration to use when scraping the endpoint -# tlsConfig: -# insecureSkipVerify: true - # -- Service Monitor relabelings - relabelings: [] diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-select-rs-test1/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-select-rs-test1/custom-values.yaml deleted file mode 100644 index 07afdee..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-select-rs-test1/custom-values.yaml +++ /dev/null @@ -1,315 +0,0 @@ -vminsert: - enabled: false - -vmstorage: - enabled: false - fullnameOverride: vmstorage-test-admin-c-prd - replicaCount: 1 - -dedicatedValue: false - - -vmselect: - # -- Enable deployment of vmselect component. Can be deployed as Deployment(default) or StatefulSet - enabled: true - splitService: True - # -- Vmselect container name - name: vmselect - strategy: - rollingUpdate: - maxSurge: 25% - maxUnavailable: 25% - type: RollingUpdate - #extraVMSelects: [] - extraVMSelects: - # - --storageNode=vmselect-supply-prd.victoriametrics.svc.clusterset.local:8401 - # - --storageNode=vmselect-demand-prd.victoriametrics.svc.clusterset.local:8401 - # # - --storageNode=vmselect-central-prd.victoriametrics.svc.clusterset.local:8401 - # - --storageNode=vmselect-central-prd-clusternative.victoriametrics.svc.clusterset.local:8401 - # - --storageNode=vmselect-demand-prd-clusternative.victoriametrics.svc.clusterset.local:8401 - # - --storageNode=vmselect-datascience-prd-clusternative.victoriametrics.svc.clusterset.local:8401 - # - --storageNode=vmselect-dataengg-prd-clusternative.victoriametrics.svc.clusterset.local:8401 - - --storageNode=vmselect-test-supply-prd-clusternative.victoriametrics.svc.clusterset.local:8401 - # - --storageNode=vmselect-farmiso-prd-clusternative.victoriametrics.svc.clusterset.local:8401 - # - --storageNode=vmselect-dataengg-startree-prd-clusternative.victoriametrics.svc.clusterset.local:8401 - # - --storageNode=vmselect-dengspark-prd-clusternative.victoriametrics.svc.clusterset.local:8401 - # - --storageNode=vmselect-ml-platform-prd-clusternative.victoriametrics.svc.clusterset.local:8401 - # - --storageNode=vmselect-datascience-prd.victoriametrics.svc.clusterset.local:8401 - # - --storageNode=vmselect-dataengg-prd.victoriametrics.svc.clusterset.local:8401 - # - --storageNode=vmselect-farmiso-prd.victoriametrics.svc.clusterset.local:8401 - # - --storageNode=prd-supply-vmselect:8401 - # - --storageNode=prd-dataplatform-vmselect:8401 - # - --storageNode=prd-datascience-vmselect:8401 - # - --storageNode=prd-dp-starburst-vmselect:8401 - # - --storageNode=prd-central-vmselect:8401 - # - --storageNode=prd-mcache-vmselect:8401 - - image: - # -- Image repository - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/vmselect - # -- Image tag - tag: v1.93.7-cluster - # -- Image pull policy - pullPolicy: IfNotPresent - # -- Name of Priority Class - priorityClassName: "" - # -- Overrides the full name of vmselect component - fullnameOverride: vmselect-test-admin-c-prd - # -- Suppress rendering `--storageNode` FQDNs based on `vmstorage.replicaCount` value. If true suppress rendering `--storageNodes`, they can be re-defined in extraArgs - suppresStorageFQDNsRender: false - automountServiceAccountToken: true - # Extra command line arguments for vmselect component - extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - clusternativeListenAddr: ":8401" - dedup.minScrapeInterval: 60s - search.maxSamplesPerQuery: "1000000000000" - search.maxQueryDuration: 180s - search.maxQueueDuration: 60s - search.maxSeries: "10000000000" - search.maxExportSeries: "1000000000" - search.maxConcurrentRequests: 89 - search.maxUniqueTimeseries: "1000000000000" - search.maxQueryLen: "1000000" - loggerTimezone: "Asia/Kolkata" - - - annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8481" - extraLabels: - bu: "infra" - team: "sre" - service: "vmselect-test-admin-c-prd" - env: "prd" - priority: "p0" - type: "vmselect" - # arch: "arm64" - # runpod: "ondemand" - - # -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables - env: [] - - # Readiness & Liveness probes - probe: - readiness: - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - liveness: - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - - horizontalPodAutoscaler: - # -- Use HPA for vmselect component - enabled: true - # -- Maximum replicas for HPA to use to to scale the vmselect component - maxReplicas: 1 - # -- Minimum replicas for HPA to use to scale the vmselect component - minReplicas: 1 - # -- Metric for HPA to use to scale the vmselect component - metrics: - - type: Resource - resource: - name: cpu - target: - type: Utilization - averageUtilization: 60 - - # Additional hostPath mounts - extraHostPathMounts: - [] - # - name: certs-dir - # mountPath: /etc/kubernetes/certs - # subPath: "" - # hostPath: /etc/kubernetes/certs - # readOnly: true - - # Extra Volumes for the pod - extraVolumes: - [] - # - name: example - # configMap: - # name: example - - # Extra Volume Mounts for the container - extraVolumeMounts: - [] - # - name: example - # mountPath: /example - - extraContainers: - [] - # - name: config-reloader - # image: reloader-image - - initContainers: - [] - # - name: example - # image: example-image - - podDisruptionBudget: - # -- See `kubectl explain poddisruptionbudget.spec` for more. Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/ - enabled: true - minAvailable: 1 - # maxUnavailable: 1 - labels: {} - - - nodeSelector: - dedicated: "vmselect" - - tolerations: - - key: "dedicated" - operator: "Equal" - value: "vmselect" - effect: "NoSchedule" - - - # -- Pod affinity - affinity: {} - # -- Pod topologySpreadConstraints - topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmselect - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmselect - # -- Pod's annotations - podAnnotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8481" - # -- Count of vmselect pods - replicaCount: 1 - # -- Container workdir - containerWorkingDir: "" - # -- Resource object - resources: - # limits: - # cpu: 50m - # memory: 64Mi - requests: - cpu: 29 - memory: 100Gi - - # -- Pod's security context. Ref: [https://kubernetes.io/docs/tasks/configure-pod-container/security-context/](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ - securityContext: {} - podSecurityContext: {} - # -- Cache root folder - cacheMountPath: /cache - service: - # -- Service annotations - annotations: - io.cilium/global-service: "true" - # -- Service labels - labels: {} - # -- Service ClusterIP - clusterIP: "" - # -- Service External IPs. Ref: [https://kubernetes.io/docs/user-guide/services/#external-ips](https://kubernetes.io/docs/user-guide/services/#external-ips) - externalIPs: [] - # -- Extra service ports - extraServicePorts: [] - # -- Service load balacner IP - loadBalancerIP: "" - # -- Load balancer source range - loadBalancerSourceRanges: [] - # -- Service port - servicePort: 8481 - # -- Target port - targetPort: http - # -- Service type - type: ClusterIP - ingress: - # -- Enable deployment of ingress for vmselect component - enabled: true - # -- Ingress annotations - annotations: - nginx.ingress.kubernetes.io/force-ssl-redirect: "false" - nginx.ingress.kubernetes.io/ssl-redirect: "false" - # kubernetes.io/ingress.class: nginx - # kubernetes.io/tls-acme: 'true' - ingressClassName: nginx-internal - - extraLabels: {} - # -- Array of host objects - hosts: - - name: vmselect-test-admin-c-prd-test.meeshogcp.in - path: / - port: http - # -- Array of TLS objects - tls: [] - # - secretName: vmselect-ingress-tls - # hosts: - # - vmselect.local - # For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName - # See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress - # ingressClassName: nginx - # -- pathType is only for k8s >= 1.1= - pathType: Prefix - statefulSet: - # -- Deploy StatefulSet instead of Deployment for vmselect. Useful if you want to keep cache data. - enabled: false - # -- Deploy order policy for StatefulSet pods - podManagementPolicy: OrderedReady - ## Headless service for statefulset - service: - # -- Headless service annotations - annotations: {} - # -- Headless service labels - labels: {} - # -- Headless service port - servicePort: 8481 - persistentVolume: - # -- Create/use Persistent Volume Claim for vmselect component. Empty dir if false. If true, vmselect will create/use a Persistent Volume Claim - enabled: false - - # -- Array of access mode. Must match those of existing PV or dynamic provisioner. Ref: [http://kubernetes.io/docs/user-guide/persistent-volumes/](http://kubernetes.io/docs/user-guide/persistent-volumes/) - accessModes: - - ReadWriteOnce - # -- Persistent volume annotations - annotations: {} - - # -- Persistent volume labels - labels: {} - - # -- Existing Claim name. Requires vmselect.persistentVolume.enabled: true. If defined, PVC must be created manually before volume will be bound - existingClaim: "" - - ## Vmselect data Persistent Volume mount root path - ## - # -- Size of the volume. Better to set the same as resource limit memory property - size: 2Gi - # -- Mount subpath - subPath: "" - serviceMonitor: - # -- Enable deployment of Service Monitor for vmselect component. This is Prometheus operator object - enabled: false - # -- Target namespace of ServiceMonitor manifest - namespace: "" - # -- Service Monitor labels - extraLabels: {} - # -- Service Monitor annotations - annotations: {} - # Commented. Prometheus scare interval for vmselect component -# interval: 15s - # Commented. Prometheus pre-scrape timeout for vmselect component -# scrapeTimeout: 5s - # -- Commented. HTTP scheme to use for scraping. -# scheme: https - # -- Commented. TLS configuration to use when scraping the endpoint -# tlsConfig: -# insecureSkipVerify: true - # -- Service Monitor relabelings - relabelings: [] diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-select-test/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-select-test/custom-values.yaml deleted file mode 100644 index 48074ec..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-select-test/custom-values.yaml +++ /dev/null @@ -1,309 +0,0 @@ -vminsert: - enabled: false - -vmstorage: - enabled: false - fullnameOverride: vmstorage-infra-prd - replicaCount: 5 - -dedicatedValue: false - - -vmselect: - # -- Enable deployment of vmselect component. Can be deployed as Deployment(default) or StatefulSet - enabled: true - splitService: True - # -- Vmselect container name - name: vmselect-test - strategy: - rollingUpdate: - maxSurge: 25% - maxUnavailable: 25% - type: RollingUpdate - #extraVMSelects: [] - extraVMSelects: - - --storageNode=vmselect-mqkafka-prd-clusternative.victoriametrics.svc.clusterset.local:8401 - - --storageNode=vm-select-central-prd-cluster-tcp.victoriametrics.svc.clusterset.local:8401 - - --storageNode=vm-select-demand-prd-cluster-tcp.victoriametrics.svc.clusterset.local:8401 - - --storageNode=vm-select-datascience-prd-cluster-tcp.victoriametrics.svc.clusterset.local:8401 - - --storageNode=vmselect-dataengg-prd-clusternative.victoriametrics.svc.clusterset.local:8401 - - --storageNode=vm-select-supply-prd-cluster-tcp.victoriametrics.svc.clusterset.local:8401 - - --storageNode=vm-select-farmiso-prd-cluster-tcp.victoriametrics.svc.clusterset.local:8401 - - image: - # -- Image repository - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/vmselect - # -- Image tag - tag: v1.93.7-cluster - # -- Image pull policy - pullPolicy: IfNotPresent - # -- Name of Priority Class - priorityClassName: "" - # -- Overrides the full name of vmselect component - fullnameOverride: vmselect-infra-prd-test - # -- Suppress rendering `--storageNode` FQDNs based on `vmstorage.replicaCount` value. If true suppress rendering `--storageNodes`, they can be re-defined in extraArgs - suppresStorageFQDNsRender: false - automountServiceAccountToken: true - # Extra command line arguments for vmselect component - extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - clusternativeListenAddr: ":8401" - dedup.minScrapeInterval: 60s - search.maxSamplesPerQuery: "1000000000000" - search.maxQueryDuration: 300s - search.maxQueueDuration: 60s - search.maxSeries: "10000000000" - search.maxExportSeries: "1000000000" - search.maxUniqueTimeseries: "1000000000000" - search.maxQueryLen: "1000000" - search.maxConcurrentRequests: 1600 - clusternative.maxConcurrentRequests: 1000 - search.maxWorkersPerQuery: 89 - memory.allowedPercent: 80 - loggerTimezone: "Asia/Kolkata" - - annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8481" - extraLabels: - bu: "infra" - team: "sre" - service: "vmselect-infra-prd-test" - env: "prd" - priority: "p0" - type: "vmselect-test" - # arch: "arm64" - # runpod: "ondemand" - - # -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables - env: [] - - # Readiness & Liveness probes - probe: - readiness: - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - liveness: - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - - horizontalPodAutoscaler: - # -- Use HPA for vmselect component - enabled: true - # -- Maximum replicas for HPA to use to to scale the vmselect component - maxReplicas: 80 - # -- Minimum replicas for HPA to use to scale the vmselect component - minReplicas: 13 - # -- Metric for HPA to use to scale the vmselect component - metrics: - - type: Resource - resource: - name: cpu - target: - type: Utilization - averageUtilization: 60 - - type: Resource - resource: - name: memory - target: - type: Utilization - averageUtilization: 60 - - # Additional hostPath mounts - extraHostPathMounts: - [] - # - name: certs-dir - # mountPath: /etc/kubernetes/certs - # subPath: "" - # hostPath: /etc/kubernetes/certs - # readOnly: true - - # Extra Volumes for the pod - extraVolumes: - [] - # - name: example - # configMap: - # name: example - - # Extra Volume Mounts for the container - extraVolumeMounts: - [] - # - name: example - # mountPath: /example - - extraContainers: - [] - # - name: config-reloader - # image: reloader-image - - initContainers: - [] - # - name: example - # image: example-image - - podDisruptionBudget: - # -- See `kubectl explain poddisruptionbudget.spec` for more. Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/ - enabled: true - minAvailable: 1 - # maxUnavailable: 1 - labels: {} - - - nodeSelector: - dedicated: "vmselect-mds" - - tolerations: - - key: "dedicated" - operator: "Equal" - value: "vmselect-mds" - effect: "NoSchedule" - - - # -- Pod affinity - affinity: {} - # -- Pod topologySpreadConstraints - topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmselect - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmselect - # -- Pod's annotations - podAnnotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8481" - # -- Count of vmselect pods - replicaCount: 2 - # -- Container workdir - containerWorkingDir: "" - # -- Resource object - resources: - # limits: - # cpu: 50m - # memory: 64Mi - requests: - cpu: 80 - memory: 140Gi - - # -- Pod's security context. Ref: [https://kubernetes.io/docs/tasks/configure-pod-container/security-context/](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ - securityContext: {} - podSecurityContext: {} - # -- Cache root folder - cacheMountPath: /cache - service: - # -- Service annotations - annotations: - io.cilium/global-service: "true" - # -- Service labels - labels: {} - # -- Service ClusterIP - clusterIP: "" - # -- Service External IPs. Ref: [https://kubernetes.io/docs/user-guide/services/#external-ips](https://kubernetes.io/docs/user-guide/services/#external-ips) - externalIPs: [] - # -- Extra service ports - extraServicePorts: [] - # -- Service load balacner IP - loadBalancerIP: "" - # -- Load balancer source range - loadBalancerSourceRanges: [] - # -- Service port - servicePort: 8481 - # -- Target port - targetPort: http - # -- Service type - type: ClusterIP - ingress: - # -- Enable deployment of ingress for vmselect component - enabled: true - # -- Ingress annotations - annotations: - nginx.ingress.kubernetes.io/force-ssl-redirect: "false" - nginx.ingress.kubernetes.io/ssl-redirect: "false" - # kubernetes.io/ingress.class: nginx - # kubernetes.io/tls-acme: 'true' - ingressClassName: nginx-internal - - extraLabels: {} - # -- Array of host objects - hosts: - - name: vmselect-infra-prd.meeshogcp.in - path: / - port: http - # -- Array of TLS objects - tls: [] - # - secretName: vmselect-ingress-tls - # hosts: - # - vmselect.local - # For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName - # See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress - # ingressClassName: nginx - # -- pathType is only for k8s >= 1.1= - pathType: Prefix - statefulSet: - # -- Deploy StatefulSet instead of Deployment for vmselect. Useful if you want to keep cache data. - enabled: false - # -- Deploy order policy for StatefulSet pods - podManagementPolicy: OrderedReady - ## Headless service for statefulset - service: - # -- Headless service annotations - annotations: {} - # -- Headless service labels - labels: {} - # -- Headless service port - servicePort: 8481 - persistentVolume: - # -- Create/use Persistent Volume Claim for vmselect component. Empty dir if false. If true, vmselect will create/use a Persistent Volume Claim - enabled: false - - # -- Array of access mode. Must match those of existing PV or dynamic provisioner. Ref: [http://kubernetes.io/docs/user-guide/persistent-volumes/](http://kubernetes.io/docs/user-guide/persistent-volumes/) - accessModes: - - ReadWriteOnce - # -- Persistent volume annotations - annotations: {} - - # -- Persistent volume labels - labels: {} - - # -- Existing Claim name. Requires vmselect.persistentVolume.enabled: true. If defined, PVC must be created manually before volume will be bound - existingClaim: "" - - ## Vmselect data Persistent Volume mount root path - ## - # -- Size of the volume. Better to set the same as resource limit memory property - size: 2Gi - # -- Mount subpath - subPath: "" - serviceMonitor: - # -- Enable deployment of Service Monitor for vmselect component. This is Prometheus operator object - enabled: false - # -- Target namespace of ServiceMonitor manifest - namespace: "" - # -- Service Monitor labels - extraLabels: {} - # -- Service Monitor annotations - annotations: {} - # Commented. Prometheus scare interval for vmselect component -# interval: 15s - # Commented. Prometheus pre-scrape timeout for vmselect component -# scrapeTimeout: 5s - # -- Commented. HTTP scheme to use for scraping. -# scheme: https - # -- Commented. TLS configuration to use when scraping the endpoint -# tlsConfig: -# insecureSkipVerify: true - # -- Service Monitor relabelings - relabelings: [] diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-select/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-select/custom-values.yaml deleted file mode 100644 index 3f7409a..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-select/custom-values.yaml +++ /dev/null @@ -1,302 +0,0 @@ -vminsert: - enabled: false - -vmstorage: - enabled: false - fullnameOverride: vmstorage-infra-prd - replicaCount: 5 - -dedicatedValue: false - - -vmselect: - # -- Enable deployment of vmselect component. Can be deployed as Deployment(default) or StatefulSet - enabled: true - splitService: True - # -- Vmselect container name - name: vmselect - strategy: - rollingUpdate: - maxSurge: 25% - maxUnavailable: 25% - type: RollingUpdate - extraVMSelects: - - --storageNode=vm-select-central-prd-cluster-tcp.victoriametrics.svc.clusterset.local:8401 - - --storageNode=vmselect-dataengg-prd-clusternative.victoriametrics.svc.clusterset.local:8401 - - --storageNode=vmselect-dataengg-startree-prd-clusternative.victoriametrics.svc.clusterset.local:8401 - - --storageNode=vmselect-datascience-prd-clusternative.victoriametrics.svc.clusterset.local:8401 - - --storageNode=vmselect-demand-prd-clusternative.victoriametrics.svc.clusterset.local:8401 - - --storageNode=vmselect-dengspark-prd-clusternative.victoriametrics.svc.clusterset.local:8401 - - --storageNode=vm-select-farmiso-prd-cluster-tcp.victoriametrics.svc.clusterset.local:8401 - - --storageNode=vmselect-ml-platform-prd-clusternative.victoriametrics.svc.clusterset.local:8401 - - --storageNode=vmselect-supply-prd-clusternative.victoriametrics.svc.clusterset.local:8401 - - image: - # -- Image repository - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/vmselect - # -- Image tag - tag: v1.93.7-cluster - # -- Image pull policy - pullPolicy: IfNotPresent - # -- Name of Priority Class - priorityClassName: "" - # -- Overrides the full name of vmselect component - fullnameOverride: vmselect-infra-prd - # -- Suppress rendering `--storageNode` FQDNs based on `vmstorage.replicaCount` value. If true suppress rendering `--storageNodes`, they can be re-defined in extraArgs - suppresStorageFQDNsRender: false - automountServiceAccountToken: true - # Extra command line arguments for vmselect component - extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - clusternativeListenAddr: ":8401" - dedup.minScrapeInterval: 60s - search.maxSamplesPerQuery: "1000000000000" - search.maxQueryDuration: 180s - search.maxQueueDuration: 60s - search.maxSeries: "10000000000" - search.maxExportSeries: "1000000000" - search.maxConcurrentRequests: 89 - search.maxUniqueTimeseries: "1000000000000" - search.maxQueryLen: "1000000" - loggerTimezone: "Asia/Kolkata" - - - annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8481" - extraLabels: - bu: "infra" - team: "sre" - service: "vmselect-infra-prd" - env: "prd" - priority: "p0" - type: "vmselect" - # arch: "arm64" - # runpod: "ondemand" - - # -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables - env: [] - - # Readiness & Liveness probes - probe: - readiness: - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - liveness: - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - - horizontalPodAutoscaler: - # -- Use HPA for vmselect component - enabled: true - # -- Maximum replicas for HPA to use to to scale the vmselect component - maxReplicas: 1 - # -- Minimum replicas for HPA to use to scale the vmselect component - minReplicas: 0 - # -- Metric for HPA to use to scale the vmselect component - metrics: - - type: Resource - resource: - name: cpu - target: - type: Utilization - averageUtilization: 60 - - # Additional hostPath mounts - extraHostPathMounts: - [] - # - name: certs-dir - # mountPath: /etc/kubernetes/certs - # subPath: "" - # hostPath: /etc/kubernetes/certs - # readOnly: true - - # Extra Volumes for the pod - extraVolumes: - [] - # - name: example - # configMap: - # name: example - - # Extra Volume Mounts for the container - extraVolumeMounts: - [] - # - name: example - # mountPath: /example - - extraContainers: - [] - # - name: config-reloader - # image: reloader-image - - initContainers: - [] - # - name: example - # image: example-image - - podDisruptionBudget: - # -- See `kubectl explain poddisruptionbudget.spec` for more. Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/ - enabled: true - minAvailable: 1 - # maxUnavailable: 1 - labels: {} - - - nodeSelector: - dedicated: "vmselect" - - tolerations: - - key: "dedicated" - operator: "Equal" - value: "vmselect" - effect: "NoSchedule" - - - # -- Pod affinity - affinity: {} - # -- Pod topologySpreadConstraints - topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmselect - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmselect - # -- Pod's annotations - podAnnotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8481" - # -- Count of vmselect pods - replicaCount: 2 - # -- Container workdir - containerWorkingDir: "" - # -- Resource object - resources: - # limits: - # cpu: 50m - # memory: 64Mi - requests: - cpu: 29 - memory: 100Gi - - # -- Pod's security context. Ref: [https://kubernetes.io/docs/tasks/configure-pod-container/security-context/](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ - securityContext: {} - podSecurityContext: {} - # -- Cache root folder - cacheMountPath: /cache - service: - # -- Service annotations - annotations: - io.cilium/global-service: "true" - # -- Service labels - labels: {} - # -- Service ClusterIP - clusterIP: "" - # -- Service External IPs. Ref: [https://kubernetes.io/docs/user-guide/services/#external-ips](https://kubernetes.io/docs/user-guide/services/#external-ips) - externalIPs: [] - # -- Extra service ports - extraServicePorts: [] - # -- Service load balacner IP - loadBalancerIP: "" - # -- Load balancer source range - loadBalancerSourceRanges: [] - # -- Service port - servicePort: 8481 - # -- Target port - targetPort: http - # -- Service type - type: ClusterIP - ingress: - # -- Enable deployment of ingress for vmselect component - enabled: true - # -- Ingress annotations - annotations: - nginx.ingress.kubernetes.io/force-ssl-redirect: "false" - nginx.ingress.kubernetes.io/ssl-redirect: "false" - # kubernetes.io/ingress.class: nginx - # kubernetes.io/tls-acme: 'true' - ingressClassName: nginx-internal - - extraLabels: {} - # -- Array of host objects - hosts: - - name: vmselect-infra-prd-test.meeshogcp.in - path: / - port: http - # -- Array of TLS objects - tls: [] - # - secretName: vmselect-ingress-tls - # hosts: - # - vmselect.local - # For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName - # See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress - # ingressClassName: nginx - # -- pathType is only for k8s >= 1.1= - pathType: Prefix - statefulSet: - # -- Deploy StatefulSet instead of Deployment for vmselect. Useful if you want to keep cache data. - enabled: false - # -- Deploy order policy for StatefulSet pods - podManagementPolicy: OrderedReady - ## Headless service for statefulset - service: - # -- Headless service annotations - annotations: {} - # -- Headless service labels - labels: {} - # -- Headless service port - servicePort: 8481 - persistentVolume: - # -- Create/use Persistent Volume Claim for vmselect component. Empty dir if false. If true, vmselect will create/use a Persistent Volume Claim - enabled: false - - # -- Array of access mode. Must match those of existing PV or dynamic provisioner. Ref: [http://kubernetes.io/docs/user-guide/persistent-volumes/](http://kubernetes.io/docs/user-guide/persistent-volumes/) - accessModes: - - ReadWriteOnce - # -- Persistent volume annotations - annotations: {} - - # -- Persistent volume labels - labels: {} - - # -- Existing Claim name. Requires vmselect.persistentVolume.enabled: true. If defined, PVC must be created manually before volume will be bound - existingClaim: "" - - ## Vmselect data Persistent Volume mount root path - ## - # -- Size of the volume. Better to set the same as resource limit memory property - size: 2Gi - # -- Mount subpath - subPath: "" - serviceMonitor: - # -- Enable deployment of Service Monitor for vmselect component. This is Prometheus operator object - enabled: false - # -- Target namespace of ServiceMonitor manifest - namespace: "" - # -- Service Monitor labels - extraLabels: {} - # -- Service Monitor annotations - annotations: {} - # Commented. Prometheus scare interval for vmselect component -# interval: 15s - # Commented. Prometheus pre-scrape timeout for vmselect component -# scrapeTimeout: 5s - # -- Commented. HTTP scheme to use for scraping. -# scheme: https - # -- Commented. TLS configuration to use when scraping the endpoint -# tlsConfig: -# insecureSkipVerify: true - # -- Service Monitor relabelings - relabelings: [] diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-single-fb/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-single-fb/custom-values.yaml deleted file mode 100644 index 53ac3a9..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-single-fb/custom-values.yaml +++ /dev/null @@ -1,297 +0,0 @@ -# Default values for victoria-metrics. -# This is a YAML-formatted file. -# Declare variables to be passed into your templates. -global: - imagePullSecrets: [] - image: - registry: "" - compatibility: - openshift: - adaptSecurityContext: "auto" - cluster: - dnsDomain: cluster.local. - -rbac: - create: true - pspEnabled: true - namespaced: false - extraLabels: {} - annotations: {} - -serviceAccount: - create: true - annotations: { - iam.gke.io/gcp-service-account: sa-infr-sre-vmsinglenode-prd@meesho-admin-prd-0622.iam.gserviceaccount.com - } - name: sa-infr-sre-vmsinglenode-prd - -topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmsinglenode - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: DoNotSchedule - labelSelector: - matchLabels: - type: vmsinglenode - -server: - # -- Enable deployment of server component. Deployed as StatefulSet - enabled: true - # -- Override default `app` label name - name: vmsinglenode - image: - registry: "" - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/victoria-metrics-single-node-amd - # repository: victoriametrics/victoria-metrics - # tag: "" - tag: v1.101.0 - pullPolicy: IfNotPresent - imagePullSecrets: [] - lifecycle: {} - replicaCount: 2 - priorityClassName: "" - fullnameOverride: vmsinglenode-infra-prd - retentionPeriod: 7d - extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - httpListenAddr: :8428 - maxLabelsPerTimeseries: 40 - loggerTimezone: "Asia/Kolkata" - annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8428" - # Additional hostPath mounts - extraHostPathMounts: - [] - #- name: certs-dir - # mountPath: /etc/kubernetes/certs - # subPath: "" - # hostPath: /etc/kubernetes/certs - # readOnly: true - - # Extra Volumes for the pod - extraVolumes: - [] - #- name: example - # configMap: - # name: example - - # -- Extra Volume Mounts for the container - extraVolumeMounts: - [] - # - name: example - # mountPath: /example - - # -- Extra containers to run in a pod with VM single - extraContainers: - [] - #- name: config-reloader - # image: reloader-image - - # -- Init containers for VM single pod - initContainers: - [] - # - name: vmrestore - # image: victoriametrics/vmrestore:latest - # volumeMounts: - # - mountPath: /storage - # name: vmstorage-volume - # - mountPath: /etc/vm/creds - # name: secret-remote-storage-keys - # readOnly: true - # args: - # - -storageDataPath=/storage - # - -src=s3://your_bucket/folder/latest - # - -credsFilePath=/etc/vm/creds/credentials - - # -- Node tolerations for server scheduling to nodes with taints. Details are [here](https://kubernetes.io/docs/concepts/configuration/assign-pod-node/) - tolerations: - - key: "dedicated" - operator: "Equal" - value: "vmstack-fb" - effect: "NoSchedule" - - # -- Pod's node selector. Details are [here](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector) - nodeSelector: { - dedicated: "vmstack-fb" - } - - affinity: {} - containerWorkingDir: "" - persistentVolume: - enabled: true - name: "" - accessModes: - - ReadWriteOnce - annotations: {} - storageClassName: "" - existingClaim: "" - matchLabels: {} - mountPath: /storage - subPath: "" - size: 70Gi - - # -- Sts/Deploy additional labels - extraLabels: - bu: "infra" - team: "sre" - service: "vmsinglenode-infra-prd" - env: "prd" - priority: "p0" - type: "vmsinglenode" - # -- Pod's additional labels. As in single node extra labels by default dont get attached to pod so pod labels again written here - podLabels: - bu: "infra" - team: "sre" - service: "vmsinglenode-infra-prd" - env: "prd" - priority: "p0" - type: "vmsinglenode" - # -- Pod's annotations - podAnnotations: - prometheus.io/port: "8428" - prometheus.io/scrape: "true" - - # -- Resource object. Details are [here](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) - resources: - limits: - cpu: 3 - memory: 5Gi - requests: - cpu: 2 - memory: 3Gi - - probe: - readiness: - httpGet: - path: /health - port: http - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - liveness: - tcpSocket: - port: http - initialDelaySeconds: 30 - periodSeconds: 30 - timeoutSeconds: 5 - failureThreshold: 10 - - # -- Indicates whether the Container is done with potentially costly initialization. If set it is executed first. If it fails Container is restarted. If it succeeds liveness and readiness probes takes over. - startup: {} - #failureThreshold: 30 - #periodSeconds: 15 - #successThreshold: 1 - #timeoutSeconds: 5 - - # -- Security context to be added to server pods - securityContext: - enabled: true - # -- Pod's security context. Details are [here](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/) - podSecurityContext: - enabled: true - ingress: - # -- Enable deployment of ingress for server component - enabled: true - annotations: - nginx.ingress.kubernetes.io/force-ssl-redirect: "false" - nginx.ingress.kubernetes.io/ssl-redirect: "false" - extraLabels: {} - hosts: - - name: vmsinglenode-infra-prd.meeshogcp.in - path: / - port: http - ingressClassName: nginx-internal - tls: [] - # - secretName: vmselect-ingress-tls - # hosts: - # - vmselect.local - # For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName - # See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress - # ingressClassName: nginx - pathType: Prefix - - service: - # -- Service annotations - annotations: {} - # -- Service labels - labels: {} - # -- Service ClusterIP - # clusterIP: "" - # -- Service external IPs. Details are [here](https://kubernetes.io/docs/concepts/services-networking/service/#external-ips) - externalIPs: [] - # -- Service load balancer IP - loadBalancerIP: "" - # -- Load balancer source range - loadBalancerSourceRanges: [] - # -- Service port - servicePort: 8428 - # -- Target port - targetPort: http - # -- Node port - # nodePort: 30000 - # -- Service type - type: ClusterIP - # -- Service external traffic policy. Check [here](https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip) for details - externalTrafficPolicy: "" - # -- Health check node port for a service. Check [here](https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip) for details - healthCheckNodePort: "" - # -- Service IP family policy. Check [here](https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services) for details. - ipFamilyPolicy: "" - # -- List of service IP families. Check [here](https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services) for details. - ipFamilies: [] - - # -- VictoriaMetrics mode: deployment, statefulSet - # mode: statefulSet - - # removed these two as they are not a part of 0.9.24v - # # -- [K8s Deployment](https://kubernetes.io/docs/concepts/workloads/controllers/deployment/) specific variables - # deployment: - # spec: - # strategy: - # # Must be "Recreate" when we have a persistent volume - # type: Recreate - - # -- [K8s StatefulSet](https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/) specific variables - # statefulSet: - # spec: - # # -- Deploy order policy for StatefulSet pods - # podManagementPolicy: OrderedReady - # # -- StatefulSet update strategy. Check [here](https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#update-strategies) for details. - # updateStrategy: {} - # # type: RollingUpdate - - # -- Pod's termination grace period in seconds - terminationGracePeriodSeconds: 60 - serviceMonitor: - # -- Enable deployment of Service Monitor for server component. This is Prometheus operator object - enabled: false - # -- Service Monitor labels - extraLabels: {} - # -- Service Monitor annotations - annotations: {} - # -- Basic auth params for Service Monitor - basicAuth: {} - # -- Commented. Prometheus scrape interval for server component -# interval: 15s - # -- Commented. Prometheus pre-scrape timeout for server component -# scrapeTimeout: 5s - # -- Commented. HTTP scheme to use for scraping. -# scheme: https - # -- Commented. TLS configuration to use when scraping the endpoint -# tlsConfig: -# insecureSkipVerify: true - # -- Service Monitor relabelings - relabelings: [] - # -- Service Monitor metricRelabelings - metricRelabelings: [] - # -- Service Monitor target port - targetPort: http diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-single/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-single/custom-values.yaml deleted file mode 100644 index 0d31f1c..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-single/custom-values.yaml +++ /dev/null @@ -1,44 +0,0 @@ -victoria-metrics-single: - server: - # 7 days, not the chart's month-long default — a homelab whose entire - # purpose is proving a CI/CD pipeline has no use for that much - # history, and every extra day is disk this node does not have spare. - retentionPeriod: "7d" - - persistentVolume: - # local-path-provisioner, this cluster's default StorageClass — - # installed right after Cilium precisely because kubeadm ships no - # default (unlike k3s). 3Gi, not the chart's 16Gi default: VM's own - # compression is the whole reason it replaced Prometheus here, and - # this cluster's metric volume at a 7-day retention comfortably - # fits well inside that. Not resizable in place with this - # provisioner, so sized deliberately rather than grown later. - storageClassName: local-path - size: 3Gi - - resources: - requests: - cpu: 50m - memory: 128Mi - limits: - memory: 512Mi - - # vmui — VictoriaMetrics' own built-in UI, served at /vmui/ on the - # same server. Ad-hoc PromQL queries and graphs only, no saved - # dashboards; Grafana (separate release) is what those need. Exposed - # anyway since it costs nothing extra to run — it's the same - # pod/port, not a new component — and is useful on its own for - # poking at a metric without opening Grafana. - # - # Dual LAN + Tailscale hostnames, same convention as every other - # externally-reachable service in this homelab. - ingress: - enabled: true - ingressClassName: contour - hosts: - - name: vm.192.168.1.7.nip.io - path: ["/"] - port: http - - name: vm.100.90.248.118.nip.io - path: ["/"] - port: http diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-storage-dbackup/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-storage-dbackup/custom-values.yaml deleted file mode 100644 index c7781bc..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-storage-dbackup/custom-values.yaml +++ /dev/null @@ -1,316 +0,0 @@ -vminsert: - enabled: false - -vmselect: - enabled: false - -serviceAccount: - create: true - # name: - extraLabels: {} - annotations: - eks.amazonaws.com/role-arn: arn:aws:iam::847438129436:role/eks-s3-vmbackup-role - # mount API token to pod directly - automountToken: true - -dedicatedValue: false -# schedulerName: default-scheduler - -vmstorage: - # -- Enable deployment of vmstorage component. StatefulSet is used - enabled: true - # -- vmstorage container name - name: vmstorage - image: - # -- Image repository - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/vmstorage - # -- Image tag - tag: v1.93.7-cluster - # -- Image pull policy - pullPolicy: IfNotPresent - # -- Name of Priority Class - priorityClassName: "" - # -- Overrides the full name of vmstorage component - fullnameOverride: vmstorage-infra-prd-dbackup - automountServiceAccountToken: true - # -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables - env: [] - # -- Data retention period. Supported values 1w, 1d, number without measurement means month, e.g. 2 = 2month - retentionPeriod: 1095d - # Additional vmstorage container arguments. Extra command line arguments for vmstorage component - extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - search.maxUniqueTimeseries: "30000000" - dedup.minScrapeInterval: 60s - loggerTimezone: "Asia/Kolkata" - - # Additional hostPath mounts - extraHostPathMounts: - [] - # - name: certs-dir - # mountPath: /etc/kubernetes/certs - # subPath: "" - # hostPath: /etc/kubernetes/certs - # readOnly: true - - # Extra Volumes for the pod - extraVolumes: - [] - # - name: example - # configMap: - # name: example - - # Extra Volume Mounts for the container - extraVolumeMounts: - [] - # - name: example - # mountPath: /example - - extraContainers: - [] - # - name: config-reloader - # image: reloader-image - - extraSecretMounts: - [] - # - name: secret - # mountPath: /etc/credentials - # subPath: "" - # readOnly: true - - initContainers: - [] - # - name: vmrestore - # image: victoriametrics/vmrestore:latest - # volumeMounts: - # - mountPath: /storage - # name: vmstorage-volume - # - mountPath: /etc/vm/creds - # name: secret-remote-storage-keys - # readOnly: true - # args: - # - -storageDataPath=/storage - # - -src=s3://your_bucket/folder/latest - # - -credsFilePath=/etc/vm/creds/credentials - - # -- See `kubectl explain poddisruptionbudget.spec` for more. Ref: [https://kubernetes.io/docs/tasks/run-application/configure-pdb/](https://kubernetes.io/docs/tasks/run-application/configure-pdb/) - podDisruptionBudget: - enabled: false - # minAvailable: 1 - # maxUnavailable: 1 - labels: {} - - # -- Array of tolerations object. Node tolerations for server scheduling to nodes with taints. Ref: [https://kubernetes.io/docs/concepts/configuration/assign-pod-node/](https://kubernetes.io/docs/concepts/configuration/assign-pod-node/) - ## - tolerations: - - key: "dedicated" - operator: "Equal" - value: "vmstack-dbackup" - effect: "NoSchedule" - - # -- Pod's node selector. Ref: [https://kubernetes.io/docs/user-guide/node-selection/](https://kubernetes.io/docs/user-guide/node-selection/) - nodeSelector: - dedicated: "vmstack-dbackup" - - # -- Pod affinity - affinity: {} - - topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmstack-dbackup - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: DoNotSchedule - labelSelector: - matchLabels: - type: vmstack-dbackup - - ## Use an alternate scheduler, e.g. "stork". - ## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/ - ## - # schedulerName: - - persistentVolume: - # -- Create/use Persistent Volume Claim for vmstorage component. Empty dir if false. If true, vmstorage will create/use a Persistent Volume Claim - enabled: true - - # -- Array of access modes. Must match those of existing PV or dynamic provisioner. Ref: [http://kubernetes.io/docs/user-guide/persistent-volumes/](http://kubernetes.io/docs/user-guide/persistent-volumes/) - accessModes: - - ReadWriteOnce - # -- Persistent volume annotations - annotations: {} - # -- Persistent volume labels - labels: {} - # -- Storage class name. Will be empty if not setted - storageClass: pd-standard-retain-dr - # -- Existing Claim name. Requires vmstorage.persistentVolume.enabled: true. If defined, PVC must be created manually before volume will be bound - existingClaim: "" - - # -- Data root path. Vmstorage data Persistent Volume mount root path - mountPath: /storage - # -- Size of the volume. Better to set the same as resource limit memory property - size: 500Gi - # -- Mount subpath - subPath: "" - - # -- Pod's annotations - podAnnotations: - prometheus.io/port: "8482" - prometheus.io/scrape: "true" - annotations: - prometheus.io/port: "8482" - prometheus.io/scrape: "true" - extraLabels: - bu: "infra" - team: "sre" - service: "vmstorage-infra-prd-dbackup" - env: "prd" - priority: "p0" - type: "vmstorage-dbackup" - # arch: "arm64" - # runpod: "ondemand" - - # -- Count of vmstorage pods - replicaCount: 2 - # -- Container workdir - containerWorkingDir: "" - # -- Deploy order policy for StatefulSet pods - podManagementPolicy: OrderedReady - - # -- Resource object. Ref: [https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) - resources: - # limits: - # cpu: 500m - # memory: 512Mi - requests: - cpu: 4 - memory: 4Gi - - # -- Pod's security context. Ref: [https://kubernetes.io/docs/tasks/configure-pod-container/security-context/](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/) - securityContext: {} - podSecurityContext: {} - service: - # -- Service annotations - annotations: {} - # -- Service labels - labels: {} - # -- Service port - servicePort: 8482 - # -- Port for accepting connections from vminsert - vminsertPort: 8400 - # -- Port for accepting connections from vmstorage - vmstoragePort: 8401 - # -- Extra service ports - extraServicePorts: [] - # -- Pod's termination grace period in seconds - terminationGracePeriodSeconds: 60 - probe: - readiness: - httpGet: - path: /health - port: http - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - liveness: - tcpSocket: - port: http - initialDelaySeconds: 30 - periodSeconds: 30 - timeoutSeconds: 5 - failureThreshold: 10 - - vmbackupmanager: - # -- enable automatic creation of backup via vmbackupmanager. vmbackupmanager is part of Enterprise packages - enable: false - # -- should be true and means that you have the legal right to run a backup manager - # that can either be a signed contract or an email with confirmation to run the service in a trial period - # # https://victoriametrics.com/legal/eula/ - eula: true - image: - # -- vmbackupmanager image repository - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/vmbackupmanager - # -- vmbackupmanager image tag - tag: v1.93.7-cluster - # -- disable hourly backups - disableHourly: true - # -- disable daily backups - disableDaily: false - # -- disable weekly backups - disableWeekly: true - # -- disable monthly backups - disableMonthly: true - # -- backup destination at S3, GCS or local filesystem. Pod name will be included to path! - destination: "s3://prd-infra-vmbackup" - # -- backups' retention settings - retention: - # -- keep last N hourly backups. 0 means delete all existing hourly backups. Specify -1 to turn off - keepLastHourly: 0 - # -- keep last N daily backups. 0 means delete all existing daily backups. Specify -1 to turn off - keepLastDaily: 30 - # -- keep last N weekly backups. 0 means delete all existing weekly backups. Specify -1 to turn off - keepLastWeekly: 0 - # -- keep last N monthly backups. 0 means delete all existing monthly backups. Specify -1 to turn off - keepLastMonthly: 0 - extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - concurrency: 15 - loggerTimezone: "Asia/Kolkata" - # -- Allows to enable restore options for pod. - # Read more: https://docs.victoriametrics.com/vmbackupmanager.html#restore-commands - restore: - onStart: - enabled: false - resources: {} - # -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables - env: [] - readinessProbe: - httpGet: - path: /health - port: manager-http - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - livenessProbe: - tcpSocket: - port: manager-http - initialDelaySeconds: 30 - periodSeconds: 30 - timeoutSeconds: 5 - failureThreshold: 10 - extraSecretMounts: - [] - # - name: secret - # mountPath: /etc/credentials - # subPath: "" - # readOnly: true - serviceMonitor: - # -- Enable deployment of Service Monitor for vmstorage component. This is Prometheus operator object - enabled: false - # -- Target namespace of ServiceMonitor manifest - namespace: "" - # -- Service Monitor labels - extraLabels: {} - # -- Service Monitor annotations - annotations: {} - # Commented. Prometheus scare interval for vmstorage component -# interval: 15s - # Commented. Prometheus pre-scrape timeout for vmstorage component -# scrapeTimeout: 5s - # -- Commented. HTTP scheme to use for scraping. -# scheme: https - # -- Commented. TLS configuration to use when scraping the endpoint -# tlsConfig: -# insecureSkipVerify: true - # -- Service Monitor relabelings - relabelings: [] diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-storage-dr/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-storage-dr/custom-values.yaml deleted file mode 100644 index a7dc346..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-storage-dr/custom-values.yaml +++ /dev/null @@ -1,316 +0,0 @@ -vminsert: - enabled: false - -vmselect: - enabled: false - -serviceAccount: - create: true - # name: - extraLabels: {} - annotations: - eks.amazonaws.com/role-arn: arn:aws:iam::847438129436:role/eks-s3-vmbackup-role - # mount API token to pod directly - automountToken: true - -dedicatedValue: false -# schedulerName: default-scheduler - -vmstorage: - # -- Enable deployment of vmstorage component. StatefulSet is used - enabled: true - # -- vmstorage container name - name: vmstorage - image: - # -- Image repository - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/vmstorage - # -- Image tag - tag: v1.93.7-cluster - # -- Image pull policy - pullPolicy: IfNotPresent - # -- Name of Priority Class - priorityClassName: "" - # -- Overrides the full name of vmstorage component - fullnameOverride: vmstorage-infra-prd-dr - automountServiceAccountToken: true - # -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables - env: [] - # -- Data retention period. Supported values 1w, 1d, number without measurement means month, e.g. 2 = 2month - retentionPeriod: 90d - # Additional vmstorage container arguments. Extra command line arguments for vmstorage component - extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - search.maxUniqueTimeseries: "30000000" - dedup.minScrapeInterval: 60s - loggerTimezone: "Asia/Kolkata" - - # Additional hostPath mounts - extraHostPathMounts: - [] - # - name: certs-dir - # mountPath: /etc/kubernetes/certs - # subPath: "" - # hostPath: /etc/kubernetes/certs - # readOnly: true - - # Extra Volumes for the pod - extraVolumes: - [] - # - name: example - # configMap: - # name: example - - # Extra Volume Mounts for the container - extraVolumeMounts: - [] - # - name: example - # mountPath: /example - - extraContainers: - [] - # - name: config-reloader - # image: reloader-image - - extraSecretMounts: - [] - # - name: secret - # mountPath: /etc/credentials - # subPath: "" - # readOnly: true - - initContainers: - [] - # - name: vmrestore - # image: victoriametrics/vmrestore:latest - # volumeMounts: - # - mountPath: /storage - # name: vmstorage-volume - # - mountPath: /etc/vm/creds - # name: secret-remote-storage-keys - # readOnly: true - # args: - # - -storageDataPath=/storage - # - -src=s3://your_bucket/folder/latest - # - -credsFilePath=/etc/vm/creds/credentials - - # -- See `kubectl explain poddisruptionbudget.spec` for more. Ref: [https://kubernetes.io/docs/tasks/run-application/configure-pdb/](https://kubernetes.io/docs/tasks/run-application/configure-pdb/) - podDisruptionBudget: - enabled: false - # minAvailable: 1 - # maxUnavailable: 1 - labels: {} - - # -- Array of tolerations object. Node tolerations for server scheduling to nodes with taints. Ref: [https://kubernetes.io/docs/concepts/configuration/assign-pod-node/](https://kubernetes.io/docs/concepts/configuration/assign-pod-node/) - ## - tolerations: - - key: "dedicated" - operator: "Equal" - value: "vmstorage-dr" - effect: "NoSchedule" - - # -- Pod's node selector. Ref: [https://kubernetes.io/docs/user-guide/node-selection/](https://kubernetes.io/docs/user-guide/node-selection/) - nodeSelector: - dedicated: "vmstorage-dr" - - # -- Pod affinity - affinity: {} - - topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmstorage-dr - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: DoNotSchedule - labelSelector: - matchLabels: - type: vmstorage-dr - - ## Use an alternate scheduler, e.g. "stork". - ## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/ - ## - # schedulerName: - - persistentVolume: - # -- Create/use Persistent Volume Claim for vmstorage component. Empty dir if false. If true, vmstorage will create/use a Persistent Volume Claim - enabled: true - - # -- Array of access modes. Must match those of existing PV or dynamic provisioner. Ref: [http://kubernetes.io/docs/user-guide/persistent-volumes/](http://kubernetes.io/docs/user-guide/persistent-volumes/) - accessModes: - - ReadWriteOnce - # -- Persistent volume annotations - annotations: {} - # -- Persistent volume labels - labels: {} - # -- Storage class name. Will be empty if not setted - storageClass: pd-standard-retain-dr - # -- Existing Claim name. Requires vmstorage.persistentVolume.enabled: true. If defined, PVC must be created manually before volume will be bound - existingClaim: "" - - # -- Data root path. Vmstorage data Persistent Volume mount root path - mountPath: /storage - # -- Size of the volume. Better to set the same as resource limit memory property - size: 500Gi - # -- Mount subpath - subPath: "" - - # -- Pod's annotations - podAnnotations: - prometheus.io/port: "8482" - prometheus.io/scrape: "true" - annotations: - prometheus.io/port: "8482" - prometheus.io/scrape: "true" - extraLabels: - bu: "infra" - team: "sre" - service: "vmstorage-infra-prd-dr" - env: "prd" - priority: "p0" - type: "vmstorage-dr" - # arch: "arm64" - # runpod: "ondemand" - - # -- Count of vmstorage pods - replicaCount: 5 - # -- Container workdir - containerWorkingDir: "" - # -- Deploy order policy for StatefulSet pods - podManagementPolicy: OrderedReady - - # -- Resource object. Ref: [https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) - resources: - # limits: - # cpu: 500m - # memory: 512Mi - requests: - cpu: 5 - memory: 40Gi - - # -- Pod's security context. Ref: [https://kubernetes.io/docs/tasks/configure-pod-container/security-context/](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/) - securityContext: {} - podSecurityContext: {} - service: - # -- Service annotations - annotations: {} - # -- Service labels - labels: {} - # -- Service port - servicePort: 8482 - # -- Port for accepting connections from vminsert - vminsertPort: 8400 - # -- Port for accepting connections from vmstorage - vmstoragePort: 8401 - # -- Extra service ports - extraServicePorts: [] - # -- Pod's termination grace period in seconds - terminationGracePeriodSeconds: 60 - probe: - readiness: - httpGet: - path: /health - port: http - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - liveness: - tcpSocket: - port: http - initialDelaySeconds: 30 - periodSeconds: 30 - timeoutSeconds: 5 - failureThreshold: 10 - - vmbackupmanager: - # -- enable automatic creation of backup via vmbackupmanager. vmbackupmanager is part of Enterprise packages - enable: false - # -- should be true and means that you have the legal right to run a backup manager - # that can either be a signed contract or an email with confirmation to run the service in a trial period - # # https://victoriametrics.com/legal/eula/ - eula: true - image: - # -- vmbackupmanager image repository - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/vmbackupmanager - # -- vmbackupmanager image tag - tag: v1.93.7-cluster - # -- disable hourly backups - disableHourly: true - # -- disable daily backups - disableDaily: false - # -- disable weekly backups - disableWeekly: true - # -- disable monthly backups - disableMonthly: true - # -- backup destination at S3, GCS or local filesystem. Pod name will be included to path! - destination: "s3://prd-infra-vmbackup" - # -- backups' retention settings - retention: - # -- keep last N hourly backups. 0 means delete all existing hourly backups. Specify -1 to turn off - keepLastHourly: 0 - # -- keep last N daily backups. 0 means delete all existing daily backups. Specify -1 to turn off - keepLastDaily: 30 - # -- keep last N weekly backups. 0 means delete all existing weekly backups. Specify -1 to turn off - keepLastWeekly: 0 - # -- keep last N monthly backups. 0 means delete all existing monthly backups. Specify -1 to turn off - keepLastMonthly: 0 - extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - concurrency: 15 - loggerTimezone: "Asia/Kolkata" - # -- Allows to enable restore options for pod. - # Read more: https://docs.victoriametrics.com/vmbackupmanager.html#restore-commands - restore: - onStart: - enabled: false - resources: {} - # -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables - env: [] - readinessProbe: - httpGet: - path: /health - port: manager-http - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - livenessProbe: - tcpSocket: - port: manager-http - initialDelaySeconds: 30 - periodSeconds: 30 - timeoutSeconds: 5 - failureThreshold: 10 - extraSecretMounts: - [] - # - name: secret - # mountPath: /etc/credentials - # subPath: "" - # readOnly: true - serviceMonitor: - # -- Enable deployment of Service Monitor for vmstorage component. This is Prometheus operator object - enabled: false - # -- Target namespace of ServiceMonitor manifest - namespace: "" - # -- Service Monitor labels - extraLabels: {} - # -- Service Monitor annotations - annotations: {} - # Commented. Prometheus scare interval for vmstorage component -# interval: 15s - # Commented. Prometheus pre-scrape timeout for vmstorage component -# scrapeTimeout: 5s - # -- Commented. HTTP scheme to use for scraping. -# scheme: https - # -- Commented. TLS configuration to use when scraping the endpoint -# tlsConfig: -# insecureSkipVerify: true - # -- Service Monitor relabelings - relabelings: [] diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-storage-mds-backup/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-storage-mds-backup/custom-values.yaml deleted file mode 100644 index abe9ce3..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-storage-mds-backup/custom-values.yaml +++ /dev/null @@ -1,316 +0,0 @@ -vminsert: - enabled: false - -vmselect: - enabled: false - -serviceAccount: - create: true - # name: - extraLabels: {} - annotations: - eks.amazonaws.com/role-arn: arn:aws:iam::847438129436:role/eks-s3-vmbackup-role - # mount API token to pod directly - automountToken: true - -dedicatedValue: false -# schedulerName: default-scheduler - -vmstorage: - # -- Enable deployment of vmstorage component. StatefulSet is used - enabled: true - # -- vmstorage container name - name: vmstorage - image: - # -- Image repository - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/vmstorage - # -- Image tag - tag: v1.93.7-cluster - # -- Image pull policy - pullPolicy: IfNotPresent - # -- Name of Priority Class - priorityClassName: "" - # -- Overrides the full name of vmstorage component - fullnameOverride: vmstorage-infra-prd-mds-backup - automountServiceAccountToken: true - # -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables - env: [] - # -- Data retention period. Supported values 1w, 1d, number without measurement means month, e.g. 2 = 2month - retentionPeriod: 90d - # Additional vmstorage container arguments. Extra command line arguments for vmstorage component - extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - search.maxUniqueTimeseries: "30000000" - dedup.minScrapeInterval: 60s - loggerTimezone: "Asia/Kolkata" - - # Additional hostPath mounts - extraHostPathMounts: - [] - # - name: certs-dir - # mountPath: /etc/kubernetes/certs - # subPath: "" - # hostPath: /etc/kubernetes/certs - # readOnly: true - - # Extra Volumes for the pod - extraVolumes: - [] - # - name: example - # configMap: - # name: example - - # Extra Volume Mounts for the container - extraVolumeMounts: - [] - # - name: example - # mountPath: /example - - extraContainers: - [] - # - name: config-reloader - # image: reloader-image - - extraSecretMounts: - [] - # - name: secret - # mountPath: /etc/credentials - # subPath: "" - # readOnly: true - - initContainers: - [] - # - name: vmrestore - # image: victoriametrics/vmrestore:latest - # volumeMounts: - # - mountPath: /storage - # name: vmstorage-volume - # - mountPath: /etc/vm/creds - # name: secret-remote-storage-keys - # readOnly: true - # args: - # - -storageDataPath=/storage - # - -src=s3://your_bucket/folder/latest - # - -credsFilePath=/etc/vm/creds/credentials - - # -- See `kubectl explain poddisruptionbudget.spec` for more. Ref: [https://kubernetes.io/docs/tasks/run-application/configure-pdb/](https://kubernetes.io/docs/tasks/run-application/configure-pdb/) - podDisruptionBudget: - enabled: false - # minAvailable: 1 - # maxUnavailable: 1 - labels: {} - - # -- Array of tolerations object. Node tolerations for server scheduling to nodes with taints. Ref: [https://kubernetes.io/docs/concepts/configuration/assign-pod-node/](https://kubernetes.io/docs/concepts/configuration/assign-pod-node/) - ## - tolerations: - - key: "dedicated" - operator: "Equal" - value: "vmstorage-mds-backup" - effect: "NoSchedule" - - # -- Pod's node selector. Ref: [https://kubernetes.io/docs/user-guide/node-selection/](https://kubernetes.io/docs/user-guide/node-selection/) - nodeSelector: - dedicated: "vmstorage-mds-backup" - - # -- Pod affinity - affinity: {} - - topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmstorage - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: DoNotSchedule - labelSelector: - matchLabels: - type: vmstorage - - ## Use an alternate scheduler, e.g. "stork". - ## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/ - ## - # schedulerName: - - persistentVolume: - # -- Create/use Persistent Volume Claim for vmstorage component. Empty dir if false. If true, vmstorage will create/use a Persistent Volume Claim - enabled: true - - # -- Array of access modes. Must match those of existing PV or dynamic provisioner. Ref: [http://kubernetes.io/docs/user-guide/persistent-volumes/](http://kubernetes.io/docs/user-guide/persistent-volumes/) - accessModes: - - ReadWriteOnce - # -- Persistent volume annotations - annotations: {} - # -- Persistent volume labels - labels: {} - # -- Storage class name. Will be empty if not setted - storageClass: pd-standard-retain-dr - # -- Existing Claim name. Requires vmstorage.persistentVolume.enabled: true. If defined, PVC must be created manually before volume will be bound - existingClaim: "" - - # -- Data root path. Vmstorage data Persistent Volume mount root path - mountPath: /storage - # -- Size of the volume. Better to set the same as resource limit memory property - size: 800Gi - # -- Mount subpath - subPath: "" - - # -- Pod's annotations - podAnnotations: - prometheus.io/port: "8482" - prometheus.io/scrape: "true" - annotations: - prometheus.io/port: "8482" - prometheus.io/scrape: "true" - extraLabels: - bu: "infra" - team: "sre" - service: "vmstorage-infra-prd-mds-backup" - env: "prd" - priority: "p0" - type: "vmstorage" - # arch: "arm64" - # runpod: "ondemand" - - # -- Count of vmstorage pods - replicaCount: 5 - # -- Container workdir - containerWorkingDir: "" - # -- Deploy order policy for StatefulSet pods - podManagementPolicy: OrderedReady - - # -- Resource object. Ref: [https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) - resources: - # limits: - # cpu: 500m - # memory: 512Mi - requests: - cpu: 100 - memory: 700Gi - - # -- Pod's security context. Ref: [https://kubernetes.io/docs/tasks/configure-pod-container/security-context/](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/) - securityContext: {} - podSecurityContext: {} - service: - # -- Service annotations - annotations: {} - # -- Service labels - labels: {} - # -- Service port - servicePort: 8482 - # -- Port for accepting connections from vminsert - vminsertPort: 8400 - # -- Port for accepting connections from vmstorage - vmstoragePort: 8401 - # -- Extra service ports - extraServicePorts: [] - # -- Pod's termination grace period in seconds - terminationGracePeriodSeconds: 60 - probe: - readiness: - httpGet: - path: /health - port: http - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - liveness: - tcpSocket: - port: http - initialDelaySeconds: 30 - periodSeconds: 30 - timeoutSeconds: 5 - failureThreshold: 10 - - vmbackupmanager: - # -- enable automatic creation of backup via vmbackupmanager. vmbackupmanager is part of Enterprise packages - enable: false - # -- should be true and means that you have the legal right to run a backup manager - # that can either be a signed contract or an email with confirmation to run the service in a trial period - # # https://victoriametrics.com/legal/eula/ - eula: true - image: - # -- vmbackupmanager image repository - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/vmbackupmanager - # -- vmbackupmanager image tag - tag: v1.93.7-cluster - # -- disable hourly backups - disableHourly: true - # -- disable daily backups - disableDaily: false - # -- disable weekly backups - disableWeekly: true - # -- disable monthly backups - disableMonthly: true - # -- backup destination at S3, GCS or local filesystem. Pod name will be included to path! - destination: "s3://prd-infra-vmbackup" - # -- backups' retention settings - retention: - # -- keep last N hourly backups. 0 means delete all existing hourly backups. Specify -1 to turn off - keepLastHourly: 0 - # -- keep last N daily backups. 0 means delete all existing daily backups. Specify -1 to turn off - keepLastDaily: 30 - # -- keep last N weekly backups. 0 means delete all existing weekly backups. Specify -1 to turn off - keepLastWeekly: 0 - # -- keep last N monthly backups. 0 means delete all existing monthly backups. Specify -1 to turn off - keepLastMonthly: 0 - extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - concurrency: 15 - loggerTimezone: "Asia/Kolkata" - # -- Allows to enable restore options for pod. - # Read more: https://docs.victoriametrics.com/vmbackupmanager.html#restore-commands - restore: - onStart: - enabled: false - resources: {} - # -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables - env: [] - readinessProbe: - httpGet: - path: /health - port: manager-http - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - livenessProbe: - tcpSocket: - port: manager-http - initialDelaySeconds: 30 - periodSeconds: 30 - timeoutSeconds: 5 - failureThreshold: 10 - extraSecretMounts: - [] - # - name: secret - # mountPath: /etc/credentials - # subPath: "" - # readOnly: true - serviceMonitor: - # -- Enable deployment of Service Monitor for vmstorage component. This is Prometheus operator object - enabled: false - # -- Target namespace of ServiceMonitor manifest - namespace: "" - # -- Service Monitor labels - extraLabels: {} - # -- Service Monitor annotations - annotations: {} - # Commented. Prometheus scare interval for vmstorage component -# interval: 15s - # Commented. Prometheus pre-scrape timeout for vmstorage component -# scrapeTimeout: 5s - # -- Commented. HTTP scheme to use for scraping. -# scheme: https - # -- Commented. TLS configuration to use when scraping the endpoint -# tlsConfig: -# insecureSkipVerify: true - # -- Service Monitor relabelings - relabelings: [] diff --git a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-storage/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-storage/custom-values.yaml deleted file mode 100644 index b25c639..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoria-metrics-storage/custom-values.yaml +++ /dev/null @@ -1,316 +0,0 @@ -vminsert: - enabled: false - -vmselect: - enabled: false - -serviceAccount: - create: true - # name: - extraLabels: {} - annotations: - eks.amazonaws.com/role-arn: arn:aws:iam::847438129436:role/eks-s3-vmbackup-role - # mount API token to pod directly - automountToken: true - -dedicatedValue: false -# schedulerName: default-scheduler - -vmstorage: - # -- Enable deployment of vmstorage component. StatefulSet is used - enabled: true - # -- vmstorage container name - name: vmstorage - image: - # -- Image repository - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/vmstorage - # -- Image tag - tag: v1.93.7-cluster - # -- Image pull policy - pullPolicy: IfNotPresent - # -- Name of Priority Class - priorityClassName: "" - # -- Overrides the full name of vmstorage component - fullnameOverride: vmstorage-infra-prd - automountServiceAccountToken: true - # -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables - env: [] - # -- Data retention period. Supported values 1w, 1d, number without measurement means month, e.g. 2 = 2month - retentionPeriod: 90d - # Additional vmstorage container arguments. Extra command line arguments for vmstorage component - extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - search.maxUniqueTimeseries: "30000000" - dedup.minScrapeInterval: 60s - loggerTimezone: "Asia/Kolkata" - - # Additional hostPath mounts - extraHostPathMounts: - [] - # - name: certs-dir - # mountPath: /etc/kubernetes/certs - # subPath: "" - # hostPath: /etc/kubernetes/certs - # readOnly: true - - # Extra Volumes for the pod - extraVolumes: - [] - # - name: example - # configMap: - # name: example - - # Extra Volume Mounts for the container - extraVolumeMounts: - [] - # - name: example - # mountPath: /example - - extraContainers: - [] - # - name: config-reloader - # image: reloader-image - - extraSecretMounts: - [] - # - name: secret - # mountPath: /etc/credentials - # subPath: "" - # readOnly: true - - initContainers: - [] - # - name: vmrestore - # image: victoriametrics/vmrestore:latest - # volumeMounts: - # - mountPath: /storage - # name: vmstorage-volume - # - mountPath: /etc/vm/creds - # name: secret-remote-storage-keys - # readOnly: true - # args: - # - -storageDataPath=/storage - # - -src=s3://your_bucket/folder/latest - # - -credsFilePath=/etc/vm/creds/credentials - - # -- See `kubectl explain poddisruptionbudget.spec` for more. Ref: [https://kubernetes.io/docs/tasks/run-application/configure-pdb/](https://kubernetes.io/docs/tasks/run-application/configure-pdb/) - podDisruptionBudget: - enabled: false - # minAvailable: 1 - # maxUnavailable: 1 - labels: {} - - # -- Array of tolerations object. Node tolerations for server scheduling to nodes with taints. Ref: [https://kubernetes.io/docs/concepts/configuration/assign-pod-node/](https://kubernetes.io/docs/concepts/configuration/assign-pod-node/) - ## - tolerations: - - key: "dedicated" - operator: "Equal" - value: "vmstorage-mds" - effect: "NoSchedule" - - # -- Pod's node selector. Ref: [https://kubernetes.io/docs/user-guide/node-selection/](https://kubernetes.io/docs/user-guide/node-selection/) - nodeSelector: - dedicated: "vmstorage-mds" - - # -- Pod affinity - affinity: {} - - topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmstorage - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: DoNotSchedule - labelSelector: - matchLabels: - type: vmstorage - - ## Use an alternate scheduler, e.g. "stork". - ## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/ - ## - # schedulerName: - - persistentVolume: - # -- Create/use Persistent Volume Claim for vmstorage component. Empty dir if false. If true, vmstorage will create/use a Persistent Volume Claim - enabled: true - - # -- Array of access modes. Must match those of existing PV or dynamic provisioner. Ref: [http://kubernetes.io/docs/user-guide/persistent-volumes/](http://kubernetes.io/docs/user-guide/persistent-volumes/) - accessModes: - - ReadWriteOnce - # -- Persistent volume annotations - annotations: {} - # -- Persistent volume labels - labels: {} - # -- Storage class name. Will be empty if not setted - storageClass: pd-standard-retain - # -- Existing Claim name. Requires vmstorage.persistentVolume.enabled: true. If defined, PVC must be created manually before volume will be bound - existingClaim: "" - - # -- Data root path. Vmstorage data Persistent Volume mount root path - mountPath: /storage - # -- Size of the volume. Better to set the same as resource limit memory property - size: 500Gi - # -- Mount subpath - subPath: "" - - # -- Pod's annotations - podAnnotations: - prometheus.io/port: "8482" - prometheus.io/scrape: "true" - annotations: - prometheus.io/port: "8482" - prometheus.io/scrape: "true" - extraLabels: - bu: "infra" - team: "sre" - service: "vmstorage-infra-prd" - env: "prd" - priority: "p0" - type: "vmstorage" - # arch: "arm64" - # runpod: "ondemand" - - # -- Count of vmstorage pods - replicaCount: 5 - # -- Container workdir - containerWorkingDir: "" - # -- Deploy order policy for StatefulSet pods - podManagementPolicy: OrderedReady - - # -- Resource object. Ref: [https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) - resources: - # limits: - # cpu: 500m - # memory: 512Mi - requests: - cpu: 10 - memory: 100Gi - - # -- Pod's security context. Ref: [https://kubernetes.io/docs/tasks/configure-pod-container/security-context/](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/) - securityContext: {} - podSecurityContext: {} - service: - # -- Service annotations - annotations: {} - # -- Service labels - labels: {} - # -- Service port - servicePort: 8482 - # -- Port for accepting connections from vminsert - vminsertPort: 8400 - # -- Port for accepting connections from vmstorage - vmstoragePort: 8401 - # -- Extra service ports - extraServicePorts: [] - # -- Pod's termination grace period in seconds - terminationGracePeriodSeconds: 60 - probe: - readiness: - httpGet: - path: /health - port: http - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - liveness: - tcpSocket: - port: http - initialDelaySeconds: 30 - periodSeconds: 30 - timeoutSeconds: 5 - failureThreshold: 10 - - vmbackupmanager: - # -- enable automatic creation of backup via vmbackupmanager. vmbackupmanager is part of Enterprise packages - enable: false - # -- should be true and means that you have the legal right to run a backup manager - # that can either be a signed contract or an email with confirmation to run the service in a trial period - # # https://victoriametrics.com/legal/eula/ - eula: true - image: - # -- vmbackupmanager image repository - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/vmbackupmanager - # -- vmbackupmanager image tag - tag: v1.93.7-cluster - # -- disable hourly backups - disableHourly: true - # -- disable daily backups - disableDaily: false - # -- disable weekly backups - disableWeekly: true - # -- disable monthly backups - disableMonthly: true - # -- backup destination at S3, GCS or local filesystem. Pod name will be included to path! - destination: "s3://prd-infra-vmbackup" - # -- backups' retention settings - retention: - # -- keep last N hourly backups. 0 means delete all existing hourly backups. Specify -1 to turn off - keepLastHourly: 0 - # -- keep last N daily backups. 0 means delete all existing daily backups. Specify -1 to turn off - keepLastDaily: 30 - # -- keep last N weekly backups. 0 means delete all existing weekly backups. Specify -1 to turn off - keepLastWeekly: 0 - # -- keep last N monthly backups. 0 means delete all existing monthly backups. Specify -1 to turn off - keepLastMonthly: 0 - extraArgs: - envflag.enable: "true" - envflag.prefix: VM_ - loggerFormat: json - concurrency: 15 - loggerTimezone: "Asia/Kolkata" - # -- Allows to enable restore options for pod. - # Read more: https://docs.victoriametrics.com/vmbackupmanager.html#restore-commands - restore: - onStart: - enabled: false - resources: {} - # -- Additional environment variables (ex.: secret tokens, flags) https://github.com/VictoriaMetrics/VictoriaMetrics#environment-variables - env: [] - readinessProbe: - httpGet: - path: /health - port: manager-http - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - livenessProbe: - tcpSocket: - port: manager-http - initialDelaySeconds: 30 - periodSeconds: 30 - timeoutSeconds: 5 - failureThreshold: 10 - extraSecretMounts: - [] - # - name: secret - # mountPath: /etc/credentials - # subPath: "" - # readOnly: true - serviceMonitor: - # -- Enable deployment of Service Monitor for vmstorage component. This is Prometheus operator object - enabled: false - # -- Target namespace of ServiceMonitor manifest - namespace: "" - # -- Service Monitor labels - extraLabels: {} - # -- Service Monitor annotations - annotations: {} - # Commented. Prometheus scare interval for vmstorage component -# interval: 15s - # Commented. Prometheus pre-scrape timeout for vmstorage component -# scrapeTimeout: 5s - # -- Commented. HTTP scheme to use for scraping. -# scheme: https - # -- Commented. TLS configuration to use when scraping the endpoint -# tlsConfig: -# insecureSkipVerify: true - # -- Service Monitor relabelings - relabelings: [] diff --git a/helm-overrides/k8s-admin-prd-ase1/victoriametrics-agent/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoriametrics-agent/custom-values.yaml deleted file mode 100644 index cf514ed..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoriametrics-agent/custom-values.yaml +++ /dev/null @@ -1,480 +0,0 @@ -# -- Meesho orginazation specific fields for victoria-metrics-agent chart. -custom: - configFileFolderPath: "configmap" - scrapeConfigFileName: "infra-scrape.yaml" - -# Default values for victoria-metrics-agent. -# This is a YAML-formatted file. -# Declare variables to be passed into your templates. -global: - # -- Image pull secrets, that can be shared across multiple helm charts - imagePullSecrets: [] - image: - # -- Image registry, that can be shared across multiple helm charts - registry: "" - # -- Openshift security context compatibility configuration - compatibility: - openshift: - adaptSecurityContext: "auto" - cluster: - # -- K8s cluster domain suffix, uses for building storage pods' FQDN. Details are [here](https://kubernetes.io/docs/tasks/administer-cluster/dns-custom-nameservers/) - dnsDomain: cluster.local. - -# -- Replica count -replicaCount: 2 - -# -- Specify pod lifecycle -lifecycle: {} - -# -- Use an alternate scheduler, e.g. "stork". Check details [here](https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/) -schedulerName: "" - -# -- VMAgent mode: daemonSet, deployment, statefulSet -mode: deployment - -# -- [K8s DaemonSet](https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/) specific variables -daemonSet: - spec: {} - -# -- [K8s Deployment](https://kubernetes.io/docs/concepts/workloads/controllers/deployment/) specific variables -deployment: - spec: - minReadySeconds: 1200 - progressDeadlineSeconds: 1800 - # -- Deployment strategy. Check [here](https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#strategy) for details - strategy: {} - # rollingUpdate: - # maxSurge: 25% - # maxUnavailable: 25% - # type: RollingUpdate - -# -- [K8s StatefulSet](https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/) specific variables -statefulSet: - # -- create cluster of vmagents. Check [here](https://docs.victoriametrics.com/victoriametrics/vmagent/#scraping-big-number-of-targets) - # available since [v1.77.2](https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.77.2) - clusterMode: true - # -- replication factor for vmagent in cluster mode - replicationFactor: 1 - spec: - # -- StatefulSet update strategy. Check [here](https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#update-strategies) for details. - updateStrategy: {} - # type: RollingUpdate - -image: - # -- Image registry - registry: "" - # -- Image repository - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/vmagent - # -- Image tag, set to `Chart.AppVersion` by default - tag: v1.133.0 # rewrites Chart.AppVersion - # -- Variant of the image to use. - # e.g. enterprise, scratch - variant: "" - # -- Image pull policy - pullPolicy: IfNotPresent - -# -- Image pull secrets -imagePullSecrets: [] - -# -- Add additional DNS entries to pods hosts file. Check [official documentation](https://kubernetes.io/docs/tasks/network/customize-hosts-file-for-pods/) -hostAliases: [] -# - ip: 192.168.1.1 -# hostNames: -# - test.example.com -# - another.example.net - -# -- Override chart name -nameOverride: "" - -# -- Override resources fullname -fullnameOverride: "vm-agent-infra-prd" - -# -- Container working directory -containerWorkingDir: "/" - -rbac: - # -- Enables Role/RoleBinding creation - create: true - - # -- Role/RoleBinding annotations - annotations: {} - - # -- Role/RoleBinding labels - extraLabels: {} - - # -- If true and `rbac.enabled`, will deploy a Role/RoleBinding instead of a ClusterRole/ClusterRoleBinding - namespaced: false - - # -- additional rules for a role - extraRules: [] - -serviceAccount: - # -- Specifies whether a service account should be created - create: true - # -- Annotations to add to the service account - annotations: { - iam.gke.io/gcp-service-account: sa-infr-sre-vmagnt-prd-mds@meesho-admin-prd-0622.iam.gserviceaccount.com - } - # -- The name of the service account to use. - # If not set and create is true, a name is generated using the fullname template - name: - # -- mount API token to pod directly - automountToken: true - -# -- See `kubectl explain poddisruptionbudget.spec` for more or check [official documentation](https://kubernetes.io/docs/tasks/run-application/configure-pdb/) -podDisruptionBudget: - enabled: false - # minAvailable: 1 - # maxUnavailable: 1 - labels: {} - -# -- Generates `remoteWrite.*` flags and config maps with value content for values, that are of type list of map. -# Each item should contain `url` param to pass validation. -remoteWrite: - - url: http://vm-insert-infra-prd.victoriametrics.svc.cluster.local:8480/insert/multitenant/prometheus/api/v1/write -# urlRelabelConfig: -# - action: keep -# source_labels: [env] -# regex: "dev" - -# -- VMAgent extra command line arguments -extraArgs: - envflag.enable: true - envflag.prefix: VM_ - loggerFormat: json - httpListenAddr: :8429 - promscrape.config.strictParse: false # default is true - promscrape.maxScrapeSize: 1000000000 # default is 167772160 - promscrape.minResponseSizeForStreamParse: 1000000 - loggerTimezone: "Asia/Kolkata" - # promscrape.suppressScrapeErrors: true # default is false - - # Uncomment and specify the port if you want to support any of the protocols: - # https://docs.victoriametrics.com/victoriametrics/vmagent/#features - # graphiteListenAddr: ":2003" - # influxListenAddr: ":8189" - # opentsdbHTTPListenAddr: ":4242" - # opentsdbListenAddr: ":4242" - -# -- Additional environment variables (ex.: secret tokens, flags). Check [here](https://docs.victoriametrics.com/victoriametrics/#environment-variables) for more details. -env: - - name: GOGC - value: "200" - # - name: VM_remoteWrite_basicAuth_password - # valueFrom: - # secretKeyRef: - # name: auth-secret - # key: password - -# -- Specify alternative source for env variables -envFrom: - [] - #- configMapRef: - # name: special-config - -# -- Extra labels for Deployment and Statefulset -extraLabels: - bu: "infra" - team: "infra-sre" - service: "vm-agent-infra-prd" - env: "prd" - priority: "p0" - type: "vmagent" - -# -- Extra labels for Pods only -podLabels: - bu: "infra" - team: "infra-sre" - service: "vm-agent-infra-prd" - env: "prd" - priority: "p0" - type: "vmagent" - -# -- Extra selector labels common for pod and service -selectorLabels: {} - -# -- Additional hostPath mounts -extraHostPathMounts: - [] - # - name: certs-dir - # mountPath: /etc/kubernetes/certs - # subPath: "" - # hostPath: /etc/kubernetes/certs - # readOnly: true - -# -- Extra Volumes for the pod -extraVolumes: - [] - # - name: example - # configMap: - # name: example - -# -- Extra Volume Mounts for the container -extraVolumeMounts: - [] - # - name: example - # mountPath: /example - -# -- Extra containers to run in a pod with vmagent -extraContainers: [] -# - name: config-reloader -# image: reloader-image - -# -- Init containers for vmagent -initContainers: - [] - # - name: example - # image: example-image - -# -- Security context to be added to pod -podSecurityContext: - enabled: true - # fsGroup: 2000 - -# -- Security context to be added to pod's containers -securityContext: - enabled: true - # capabilities: - # drop: - # - ALL - # readOnlyRootFilesystem: true - # runAsNonRoot: true - # runAsUser: 1000 - -service: - # -- Enable agent service - enabled: true - # -- Service annotations - annotations: {} - # -- Service labels - extraLabels: {} - # -- Service ClusterIP - clusterIP: "" - # -- Service external IPs. Check [here](https://kubernetes.io/docs/concepts/services-networking/service/#external-ips) for details - externalIPs: [] - # -- Service load balancer IP - loadBalancerIP: "" - # -- Load balancer source range - loadBalancerSourceRanges: [] - # -- Service port - servicePort: 8429 - # -- Target port - targetPort: http - # nodePort: 30000 - # -- Service type - type: ClusterIP - # -- Service IP family policy. Check [here](https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services) for details. - ipFamilyPolicy: "" - # -- List of service IP families. Check [here](https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services) for details. - ipFamilies: [] - # -- Service external traffic policy. Check [here](https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip) for details - externalTrafficPolicy: "" - # -- Service internal traffic policy. Check [here](https://kubernetes.io/docs/concepts/services-networking/service/#internal-traffic-policy) for details - internalTrafficPolicy: "" - # -- Health check node port for a service. Check [here](https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip) for details - healthCheckNodePort: "" - # -- Traffic Distribution. Check [Traffic distribution](https://kubernetes.io/docs/concepts/services-networking/service/#traffic-distribution) - trafficDistribution: "" - # -- Extra selector labels common for service only - selectorLabels: {} - -ingress: - # -- Enable deployment of ingress for agent - enabled: false - - # -- Ingress annotations - annotations: - nginx.ingress.kubernetes.io/force-ssl-redirect: "false" - nginx.ingress.kubernetes.io/rewrite-target: / - nginx.ingress.kubernetes.io/ssl-redirect: "false" - # kubernetes.io/ingress.class: nginx - # kubernetes.io/tls-acme: 'true' - - # -- Ingress extra labels - extraLabels: {} - - # -- Array of host objects - hosts: - - name: vm-agent-infra-prd.meeshogcp.in - path: - - / - port: http - - # -- Array of TLS objects - tls: [] - # - secretName: vmagent-ingress-tls - # hosts: - # - vmagent.local - - # -- Ingress controller class name - ingressClassName: "nginx-internal" - - # -- Ingress path type - pathType: Prefix - -# -- Resource object. Details are [here](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) -resources: - requests: - cpu: 13 - memory: 22Gi - -# -- Annotations to be added to the deployment -annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8429" - -# -- Annotations to be added to pod -podAnnotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8429" - -# -- Pod's node selector. Details are [here](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector) -nodeSelector: - dedicated: "vmagent-mds" - -# -- Node tolerations for server scheduling to nodes with taints. Details are [here](https://kubernetes.io/docs/concepts/configuration/assign-pod-node/) -tolerations: - - key: "dedicated" - operator: "Equal" - value: "vmagent-mds" - effect: "NoSchedule" - -# -- Pod topologySpreadConstraints -topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmagent - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: DoNotSchedule - labelSelector: - matchLabels: - type: vmagent - -# -- Pod affinity -affinity: {} - -# -- VMAgent [scraping configuration](https://docs.victoriametrics.com/victoriametrics/vmagent/#how-to-collect-metrics-in-prometheus-format) -# use existing configmap if specified -# otherwise .config values will be used -configMap: "vm-agent-infra-prd" - -# -- Priority class to be assigned to the pod(s) -priorityClassName: "" - -# -- Enable the host network -hostNetwork: false - -serviceMonitor: - # -- Enable deployment of Service Monitor for server component. This is Prometheus operator object - enabled: false - # -- Service Monitor labels - extraLabels: {} - # -- Service Monitor annotations - annotations: {} - # -- Service Monitor relabelings - relabelings: [] - # -- Basic auth params for Service Monitor - basicAuth: {} - # -- Service Monitor metricRelabelings - metricRelabelings: [] - # -- Service Monitor targetPort - targetPort: http - # interval: 15s - # scrapeTimeout: 5s - # -- Commented. HTTP scheme to use for scraping. - # scheme: https - # -- Commented. TLS configuration to use when scraping the endpoint - # tlsConfig: - # insecureSkipVerify: true - -# -- Empty dir configuration for a case, when persistence is disabled -emptyDir: {} - -persistentVolume: - # -- Create/use Persistent Volume Claim for server component. Empty dir if false - enabled: false - - # -- Override Persistent Volume Claim name - name: "" - - # -- StorageClass to use for persistent volume. Requires server.persistentVolume.enabled: true. If defined, PVC created automatically - storageClassName: "" - - # -- Array of access modes. Must match those of existing PV or dynamic provisioner. Details are [here](https://kubernetes.io/docs/concepts/storage/persistent-volumes/) - accessModes: - - ReadWriteOnce - - # -- Size of the volume. Should be calculated based on the logs you send and retention policy you set. - size: 10Gi - - # -- Persistent volume annotations - annotations: {} - - # -- Persistent volume additional labels - extraLabels: {} - - # -- Existing Claim name. If defined, PVC must be created manually before volume will be bound - existingClaim: "" - - # -- Bind Persistent Volume by labels. Must match all labels of targeted PV. - matchLabels: {} - -# -- Horizontal Pod Autoscaling. -# Note that it is not intended to be used for vmagents which perform scraping. -# In order to scale scraping vmagents check [here](https://docs.victoriametrics.com/victoriametrics/vmagent/#scraping-big-number-of-targets) -horizontalPodAutoscaling: - # -- Use HPA for vmagent - enabled: false - # -- Maximum replicas for HPA to use to to scale vmagent - maxReplicas: 10 - # -- Minimum replicas for HPA to use to scale vmagent - minReplicas: 1 - # -- Metric for HPA to use to scale vmagent - metrics: [] - -# -- VMAgent scrape configuration -config: {} - -# -- Extra scrape configs that will be appended to `config` -extraScrapeConfigs: [] - -probe: - # -- Readiness probe - readiness: - httpGet: {} - initialDelaySeconds: 5 - periodSeconds: 15 - # -- Liveness probe - liveness: - tcpSocket: {} - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - # -- Startup probe - startup: {} - -# -- Add extra specs dynamically to this chart -extraObjects: [] - -allowedMetricsEndpoints: - - /metrics - -# -- Enterprise license key configuration for VictoriaMetrics enterprise. -# Required only for VictoriaMetrics enterprise. Check docs [here](https://docs.victoriametrics.com/victoriametrics/enterprise/), -# for more information, visit [site](https://victoriametrics.com/products/enterprise/). -# Request a trial license [here](https://victoriametrics.com/products/enterprise/trial/) -# Supported starting from VictoriaMetrics v1.94.0 -license: - # -- License key - key: "" - - # -- Use existing secret with license key - secret: - # -- Existing secret name - name: "" - # -- Key in secret with license key - key: "" diff --git a/helm-overrides/k8s-admin-prd-ase1/victoriametrics-insert/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoriametrics-insert/custom-values.yaml deleted file mode 100644 index 8b9b06d..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoriametrics-insert/custom-values.yaml +++ /dev/null @@ -1,411 +0,0 @@ -# Default values for victoria-metrics. -# This is a YAML-formatted file. -# Declare variables to be passed into your templates. -global: - # -- Image pull secrets, that can be shared across multiple helm charts - imagePullSecrets: [] - image: - # -- Image registry, that can be shared across multiple helm charts - registry: "" - vm: - # -- Image tag for all vm charts - tag: "" - # -- Openshift security context compatibility configuration - compatibility: - openshift: - adaptSecurityContext: "auto" - # -- k8s cluster domain suffix, uses for building storage pods' FQDN. Details are [here](https://kubernetes.io/docs/tasks/administer-cluster/dns-custom-nameservers/) - cluster: - dnsDomain: cluster.local. - -# -- Print information after deployment -printNotes: true - -# -- use SRV discovery for storageNode and selectNode flags for enterprise version -autoDiscovery: false - -common: - # -- common for all components image configuration - image: - tag: "" - -serviceAccount: - # -- Specifies whether a service account should be created - create: true - - # -- The name of the service account to use. - # If not set and create is true, a name is generated using the fullname template - name: - - # -- Service account labels - extraLabels: {} - - # -- Service account annotations - annotations: {} - - # -- mount API token to pod directly - automountToken: true - -# -- Override chart name -nameOverride: "" - -extraSecrets: - [] - # - name: secret-remote-storage-keys - # annotations: [] - # labels: [] - # data: | - # credentials: b64_encoded_str - -# -- Add extra specs dynamically to this chart -extraObjects: [] - -vmselect: - # -- Enable deployment of vmselect component. Can be deployed as Deployment(default) or StatefulSet - enabled: false - -vminsert: - # -- Enable deployment of vminsert component. Deployment is used - enabled: true - # -- IDs of vmstorage nodes to exclude from writing - excludeStorageIDs: [] - # -- Override default `app` label name - name: vminsert - # -- VMInsert strategy - strategy: {} - # rollingUpdate: - # maxSurge: 25% - # maxUnavailable: 25% - # type: RollingUpdate - image: - # -- Image registry - registry: "" - # -- Image repository - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/vminsert - # -- Image tag - # override Chart.AppVersion - tag: v1.107.0-cluster - # -- Variant of the image to use. - # e.g. cluster, enterprise-cluster - variant: cluster - # -- Image pull policy - pullPolicy: IfNotPresent - # -- Specify pod lifecycle - lifecycle: {} - ports: - # -- VMInsert http port name - name: "http" - # -- Name of Priority Class - priorityClassName: "" - # -- Overrides the full name of vminsert component - fullnameOverride: vm-insert-infra-prd - # -- Extra command line arguments for vminsert component - extraArgs: - envflag.enable: true - envflag.prefix: VM_ - loggerFormat: json - httpListenAddr: :8480 - maxLabelsPerTimeseries: 40 - replicationFactor: 1 - loggerTimezone: "Asia/Kolkata" - storageNode: - - "vm-storage-infra-prd-0.vm-storage-infra-prd.victoriametrics.svc:8400" - - "vm-storage-infra-prd-1.vm-storage-infra-prd.victoriametrics.svc:8400" - - "vm-storage-infra-prd-2.vm-storage-infra-prd.victoriametrics.svc:8400" - - "vm-storage-infra-prd-3.vm-storage-infra-prd.victoriametrics.svc:8400" - - "vm-storage-infra-prd-4.vm-storage-infra-prd.victoriametrics.svc:8400" - # -- StatefulSet/Deployment annotations - annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8480" - # -- StatefulSet/Deployment additional labels - extraLabels: - bu: "infra" - team: "infra-sre" - service: "vm-insert-infra-prd" - env: "prd" - priority: "p0" - type: "vminsert" - # -- Pod's additional labels - podLabels: - bu: "infra" - team: "infra-sre" - service: "vm-insert-infra-prd" - env: "prd" - priority: "p0" - type: "vminsert" - terminationGracePeriodSeconds: 30 - - # -- Additional environment variables (ex.: secret tokens, flags). Check [here](https://docs.victoriametrics.com/victoriametrics/#environment-variables) for details. - env: [] - - # -- Specify alternative source for env variables - envFrom: [] - #- configMapRef: - # name: special-config - - # -- Suppress rendering `--storageNode` FQDNs based on `vmstorage.replicaCount` value. If true suppress rendering `--storageNodes`, they can be re-defined in extraArgs - suppressStorageFQDNsRender: false - - # -- Readiness & Liveness probes - probe: - # -- VMInsert readiness probe - readiness: - httpGet: {} - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - # -- VMInsert liveness probe - liveness: - tcpSocket: {} - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - # -- VMInsert startup probe - startup: {} - - # -- Relabel configuration - relabel: - enabled: false - config: [] - # -- Use existing configmap if specified - # otherwise .config values will be used. Relabel config **should** reside under `relabel.yml` key - configMap: "" - - # Horizontal Pod Autoscaling - horizontalPodAutoscaler: - # -- Use HPA for vminsert component - enabled: true - # -- Maximum replicas for HPA to use to to scale the vminsert component - maxReplicas: 20 - # -- Minimum replicas for HPA to use to scale the vminsert component - minReplicas: 3 - # -- Metric for HPA to use to scale the vminsert component - metrics: - - type: Resource - resource: - name: cpu - target: - type: Utilization - averageUtilization: 40 - # -- Behavior settings for scaling by the HPA - behavior: {} - - # -- Extra Volumes for the pod - extraVolumes: - [] - # - name: example - # configMap: - # name: example - - # -- Extra Volume Mounts for the container - extraVolumeMounts: - [] - # - name: example - # mountPath: /example - - # -- Extra containers to run in a pod with vminsert - extraContainers: - [] - # - name: config-reloader - # image: reloader-image - - # -- Init containers for vminsert - initContainers: - [] - # - name: example - # image: example-image - - # -- See `kubectl explain poddisruptionbudget.spec` for more. Details are [here](https://kubernetes.io/docs/tasks/run-application/configure-pdb/) - podDisruptionBudget: - enabled: false - # minAvailable: 1 - # maxUnavailable: 1 - labels: {} - - # -- Array of tolerations object. Details are [here](https://kubernetes.io/docs/concepts/configuration/assign-pod-node/) - tolerations: - - key: "dedicated" - operator: "Equal" - value: "vminsert-mds" - effect: "NoSchedule" - - # -- Pod's node selector. Details are [here](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector) - nodeSelector: - dedicated: "vminsert-mds" - # -- Pod affinity - affinity: {} - # -- Pod topologySpreadConstraints - topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vminsert - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: DoNotSchedule - labelSelector: - matchLabels: - type: vminsert - # -- Pod's annotations - podAnnotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8480" - # -- Count of vminsert pods - replicaCount: 2 - # -- Container workdir - containerWorkingDir: "" - # -- Resource object. Details are [here](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) - resources: - # limits: - # cpu: 50m - # memory: 64Mi - requests: - cpu: 5 - memory: 10Gi - # -- Pod's security context. Details are [here](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/) - securityContext: - enabled: false - # -- Pod's security context. Details are [here](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/) - podSecurityContext: - enabled: false - service: - # -- Create VMInsert service - enabled: true - # -- Service annotations - annotations: {} - # -- Service labels - labels: {} - # -- Service ClusterIP - clusterIP: "" - # -- Service external IPs. Details are [here]( https://kubernetes.io/docs/concepts/services-networking/service/#external-ips) - externalIPs: [] - # -- Extra service ports - extraPorts: [] - # -- Service load balancer IP - loadBalancerIP: "" - # -- Load balancer source range - loadBalancerSourceRanges: [] - # -- Service port - servicePort: 8480 - # -- Target port - targetPort: http - # -- Service type - type: ClusterIP - # -- Enable UDP port. used if you have `spec.opentsdbListenAddr` specified - # Make sure that service is not type `LoadBalancer`, as it requires `MixedProtocolLBService` feature gate. Check [here](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) for details - udp: false - # -- Health check node port for a service. Check [here](https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip) for details - healthCheckNodePort: "" - # -- Service external traffic policy. Check [here](https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip) for details - externalTrafficPolicy: "" - # -- Service IP family policy. Check [here](https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services) for details. - ipFamilyPolicy: "" - # -- List of service IP families. Check [here](https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services) for details. - ipFamilies: [] - # -- Traffic Distribution. Check [Traffic distribution](https://kubernetes.io/docs/concepts/services-networking/service/#traffic-distribution) - trafficDistribution: "" - - ingress: - # -- Enable deployment of ingress for vminsert component - enabled: false - - # -- Ingress annotations - annotations: - nginx.ingress.kubernetes.io/force-ssl-redirect: "false" - nginx.ingress.kubernetes.io/ssl-redirect: "false" - - # -- Ingress extra labels - extraLabels: {} - - # -- Array of host objects - hosts: - - name: vm-insert-infra-prd.meeshogcp.in - path: / - port: http - - # -- Array of TLS objects - tls: [] - # - secretName: vminsert-ingress-tls - # hosts: - # - vminsert.local - - # -- Ingress controller class name - ingressClassName: nginx-internal - - # -- Ingress path type - pathType: Prefix - - route: - # -- Enable deployment of HTTPRoute for insert component - enabled: false - # -- HTTPRoute annotations - annotations: {} - # -- HTTPRoute extra labels - labels: {} - # -- HTTPGateway objects refs - parentRefs: [] - # -- Array of hostnames - hostnames: [] - # -- Extra rules to prepend to route. This is useful when working with annotation based services. - extraRules: [] - # -- Filters for a default rule in HTTPRoute - filters: [] - # -- Matches for a default rule in HTTPRoute - matches: - - path: - type: PathPrefix - value: '{{ dig "extraArgs" "http.pathPrefix" "/insert" .Values.vminsert }}' - - serviceMonitor: - # -- Enable deployment of Service Monitor for vminsert component. This is Prometheus operator object - enabled: false - # -- Target namespace of ServiceMonitor manifest - namespace: "" - # -- Service Monitor labels - extraLabels: {} - # -- Service Monitor annotations - annotations: {} - # -- Basic auth params for Service Monitor - basicAuth: {} - # Commented. Prometheus scare interval for vminsert component - # interval: 15s - # Commented. Prometheus pre-scrape timeout for vminsert component - # scrapeTimeout: 5s - # -- Commented. HTTP scheme to use for scraping. - # scheme: https - # -- Commented. TLS configuration to use when scraping the endpoint - # tlsConfig: - # insecureSkipVerify: true - # -- Service Monitor relabelings - relabelings: [] - # -- Service Monitor metricRelabelings - metricRelabelings: [] - -vmauth: - # -- Enable deployment of vmauth component. - enabled: false - -vmstorage: - # -- Enable deployment of vmstorage component. StatefulSet is used - enabled: false - -# -- Enterprise license key configuration for VictoriaMetrics enterprise. -# Required only for VictoriaMetrics enterprise. Check docs [here](https://docs.victoriametrics.com/victoriametrics/enterprise/), -# for more information, visit [site](https://victoriametrics.com/products/enterprise/). -# Request a trial license [here](https://victoriametrics.com/products/enterprise/trial/) -# Supported starting from VictoriaMetrics v1.94.0 -license: - # -- License key - key: "" - - # -- Use existing secret with license key - secret: - # -- Existing secret name - name: "" - # -- Key in secret with license key - key: "" diff --git a/helm-overrides/k8s-admin-prd-ase1/victoriametrics-select/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoriametrics-select/custom-values.yaml deleted file mode 100644 index a12ea81..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoriametrics-select/custom-values.yaml +++ /dev/null @@ -1,468 +0,0 @@ -# Default values for victoria-metrics. -# This is a YAML-formatted file. -# Declare variables to be passed into your templates. -global: - # -- Image pull secrets, that can be shared across multiple helm charts - imagePullSecrets: [] - image: - # -- Image registry, that can be shared across multiple helm charts - registry: "" - vm: - # -- Image tag for all vm charts - tag: "" - # -- Openshift security context compatibility configuration - compatibility: - openshift: - adaptSecurityContext: "auto" - # -- k8s cluster domain suffix, uses for building storage pods' FQDN. Details are [here](https://kubernetes.io/docs/tasks/administer-cluster/dns-custom-nameservers/) - cluster: - dnsDomain: cluster.local. - -# -- Print information after deployment -printNotes: true - -# -- use SRV discovery for storageNode and selectNode flags for enterprise version -autoDiscovery: false - -common: - # -- common for all components image configuration - image: - tag: "" - -serviceAccount: - # -- Specifies whether a service account should be created - create: true - - # -- The name of the service account to use. - # If not set and create is true, a name is generated using the fullname template - name: - - # -- Service account labels - extraLabels: {} - - # -- Service account annotations - annotations: {} - - # -- mount API token to pod directly - automountToken: true - -# -- Override chart name -nameOverride: "" - -extraSecrets: - [] - # - name: secret-remote-storage-keys - # annotations: [] - # labels: [] - # data: | - # credentials: b64_encoded_str - -# -- Add extra specs dynamically to this chart -extraObjects: [] - -vmselect: - # -- Enable deployment of vmselect component. Can be deployed as Deployment(default) or StatefulSet - enabled: true - splitService: true - externalService: - enabled: true - name: vmselect-infra-prd-test-proxy - clusternativeService: - enabled: false - # -- Override default `app` label name - name: "" - image: - # -- Image registry - registry: "" - # -- Image repository - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/vmselect - # override Chart.AppVersion - tag: v1.133.0-cluster - # -- Image pull policy - pullPolicy: IfNotPresent - # -- Variant of the image to use. - # e.g. cluster, enterprise-cluster - variant: cluster - # -- Specify pod lifecycle - lifecycle: {} - ports: - # -- VMSelect http port name - name: "http" - # -- Name of Priority Class - priorityClassName: "" - # -- Overrides the full name of vmselect component - fullnameOverride: vm-select-infra-prd - # -- Suppress rendering `--storageNode` FQDNs based on `vmstorage.replicaCount` value. If true suppress rendering `--storageNodes`, they can be re-defined in extraArgs - suppressStorageFQDNsRender: false - # -- Pod's termination grace period in seconds - terminationGracePeriodSeconds: 60 - # -- Extra command line arguments for vmselect component - extraArgs: - envflag.enable: true - envflag.prefix: VM_ - loggerFormat: json - httpListenAddr: :8481 - clusternativeListenAddr: ":8401" - dedup.minScrapeInterval: 60s - search.maxSamplesPerQuery: "1000000000000" - search.maxQueryDuration: 300s - search.maxQueueDuration: 60s - search.maxSeries: "10000000000" - search.maxExportSeries: "1000000000" - search.maxUniqueTimeseries: "1000000000000" - search.maxQueryLen: "1000000" - loggerTimezone: "Asia/Kolkata" - storageNode: - - "vm-storage-infra-prd-0.vm-storage-infra-prd.victoriametrics.svc:8401" - - "vm-storage-infra-prd-1.vm-storage-infra-prd.victoriametrics.svc:8401" - - "vm-storage-infra-prd-2.vm-storage-infra-prd.victoriametrics.svc:8401" - - "vm-storage-infra-prd-3.vm-storage-infra-prd.victoriametrics.svc:8401" - - "vm-storage-infra-prd-4.vm-storage-infra-prd.victoriametrics.svc:8401" - - "vmselect-mqkafka-prd-clusternative.victoriametrics.svc.clusterset.local:8401" - # - "vm-select-central-prd-cluster-tcp.victoriametrics.svc.clusterset.local:8401" - - "vm-select-central-a-prd-cluster-tcp.victoriametrics.svc.clusterset.local:8401" - # - "vm-select-demand-prd-cluster-tcp.victoriametrics.svc.clusterset.local:8401" - - "vm-select-demand-a-prd-cluster-tcp.victoriametrics.svc.clusterset.local:8401" - - "vm-select-datascience-prd-cluster-tcp.victoriametrics.svc.clusterset.local:8401" - # - "vm-select-dataengg-prd-cluster-tcp.victoriametrics.svc.clusterset.local:8401" - - "vm-select-dataengg-a-prd-cluster-tcp.victoriametrics.svc.clusterset.local:8401" - # - "vm-select-farmiso-prd-cluster-tcp.victoriametrics.svc.clusterset.local:8401" - - "vm-select-farmiso-a-prd-cluster-tcp.victoriametrics.svc.clusterset.local:8401" - # - "vm-select-supply-prd-cluster-tcp.victoriametrics.svc.clusterset.local:8401" - - "vm-select-supply-a-prd-cluster-tcp.victoriametrics.svc.clusterset.local:8401" - # - "vm-select-dsgpu-prd-cluster-tcp.victoriametrics.svc.clusterset.local:8401" - - "vm-select-dsgpu-a-prd-cluster-tcp.victoriametrics.svc.clusterset.local:8401" - - # -- StatefulSet/Deployment annotations - annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8481" - # -- StatefulSet/Deployment additional labels - extraLabels: - bu: "infra" - team: "infra-sre" - service: "vm-select-infra-prd" - env: "prd" - priority: "p0" - type: "vmselect" - # -- Pod's additional labels - podLabels: - bu: "infra" - team: "infra-sre" - service: "vm-select-infra-prd" - env: "prd" - priority: "p0" - type: "vmselect" - - # -- Additional environment variables (ex.: secret tokens, flags). Check [here](https://docs.victoriametrics.com/victoriametrics/#environment-variables) for details. - env: [] - - # -- Specify alternative source for env variables - envFrom: [] - #- configMapRef: - # name: special-config - - # -- Readiness & Liveness probes - probe: - # -- VMSelect readiness probe - readiness: - httpGet: {} - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - # -- VMSelect liveness probe - liveness: - tcpSocket: {} - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - # -- VMSelect startup probe - startup: {} - - horizontalPodAutoscaler: - # -- Use HPA for vmselect component - enabled: true - # -- Maximum replicas for HPA to use to to scale the vmselect component - maxReplicas: 80 - # -- Minimum replicas for HPA to use to scale the vmselect component - minReplicas: 10 - # -- Metric for HPA to use to scale the vmselect component - metrics: - - type: Resource - resource: - name: cpu - target: - type: Utilization - averageUtilization: 60 - - type: Resource - resource: - name: memory - target: - type: Utilization - averageUtilization: 60 - # -- Behavior settings for scaling by the HPA - behavior: {} - - # -- Additional hostPath mounts - extraHostPathMounts: - [] - # - name: certs-dir - # mountPath: /etc/kubernetes/certs - # subPath: "" - # hostPath: /etc/kubernetes/certs - # readOnly: true - - # -- Extra Volumes for the pod - extraVolumes: - [] - # - name: example - # configMap: - # name: example - - # -- Extra Volume Mounts for the container - extraVolumeMounts: - [] - # - name: example - # mountPath: /example - - # -- Extra containers to run in a pod with vmselect - extraContainers: - [] - # - name: config-reloader - # image: reloader-image - - # -- Init containers for vmselect - initContainers: - [] - # - name: example - # image: example-image - - # -- See `kubectl explain poddisruptionbudget.spec` for more. Details are [here](https://kubernetes.io/docs/tasks/run-application/configure-pdb/) - podDisruptionBudget: - # -- See `kubectl explain poddisruptionbudget.spec` for more. Details are [here](https://kubernetes.io/docs/tasks/run-application/configure-pdb/) - enabled: true - minAvailable: 1 - # maxUnavailable: 1 - labels: {} - - # -- Array of tolerations object. Details are [here](https://kubernetes.io/docs/concepts/configuration/assign-pod-node/) - tolerations: - - key: "dedicated" - operator: "Equal" - value: "vmselect-c3" - effect: "NoSchedule" - - # -- Pod's node selector. Details are [here](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector) - nodeSelector: - dedicated: "vmselect-c3" - # -- Pod affinity - affinity: {} - # -- Pod topologySpreadConstraints - topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmselect - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmselect - # -- Pod's annotations - podAnnotations: - prometheus.io/scrape: "true" - prometheus.io/port: "8481" - # -- Count of vmselect pods - replicaCount: 2 - # -- Container workdir - containerWorkingDir: "" - # -- Resource object. Details are [here](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) - resources: - # limits: - # cpu: 50m - # memory: 64Mi - requests: - cpu: 80 - memory: 315Gi - - # -- Pod's security context. Details are [here](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/) - securityContext: - enabled: false - # -- Pod's security context. Details are [here](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/) - podSecurityContext: - enabled: false - # -- Cache root folder - cacheMountPath: /cache - service: - # -- Create VMSelect service - enabled: true - # -- Service annotations - annotations: {} - # -- Service labels - labels: {} - # -- Service ClusterIP - clusterIP: "" - # -- Service external IPs. Details are [here](https://kubernetes.io/docs/concepts/services-networking/service/#external-ips) - externalIPs: [] - # -- Extra service ports - extraPorts: [] - # -- Service load balancer IP - loadBalancerIP: "" - # -- Load balancer source range - loadBalancerSourceRanges: [] - # -- Service port - servicePort: 8481 - # -- Target port - targetPort: http - # -- Service type - type: ClusterIP - # -- Health check node port for a service. Check [here](https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip) for details - healthCheckNodePort: "" - # -- Service external traffic policy. Check [here](https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip) for details - externalTrafficPolicy: "" - # -- Service IP family policy. Check [here](https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services) for details. - ipFamilyPolicy: "" - # -- List of service IP families. Check [here](https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services) for details. - ipFamilies: [] - # -- Traffic Distribution. Check [Traffic distribution](https://kubernetes.io/docs/concepts/services-networking/service/#traffic-distribution) - trafficDistribution: "" - ingress: - # -- Enable deployment of ingress for vmselect component - enabled: false - - # -- Ingress annotations - annotations: - nginx.ingress.kubernetes.io/force-ssl-redirect: "false" - nginx.ingress.kubernetes.io/ssl-redirect: "false" - - # -- Ingress extra labels - extraLabels: {} - - # -- Array of host objects - hosts: - - name: vm-select-infra.prd.meesho.int - path: / - port: http - - # -- Array of TLS objects - tls: [] - # - secretName: vmselect-ingress-tls - # hosts: - # - vmselect.local - - # -- Ingress controller class name - ingressClassName: contour-internal-0 - - # -- Ingress path type - pathType: Prefix - - route: - # -- Enable deployment of HTTPRoute for select component - enabled: false - # -- HTTPRoute annotations - annotations: {} - # -- HTTPRoute extra labels - labels: {} - # -- HTTPGateway objects refs - parentRefs: [] - # -- Array of hostnames - hostnames: [] - # -- Extra rules to prepend to route. This is useful when working with annotation based services. - extraRules: [] - # -- Filters for a default rule in HTTPRoute - filters: [] - # -- Matches for a default rule in HTTPRoute - matches: - - path: - type: PathPrefix - value: '{{ dig "extraArgs" "http.pathPrefix" "/select" .Values.vmselect }}' - - # -- vmselect mode: deployment, daemonSet - mode: deployment - - # -- [K8s Deployment](https://kubernetes.io/docs/concepts/workloads/controllers/deployment/) specific variables - deployment: - spec: - # -- VMSelect strategy - strategy: {} - # rollingUpdate: - # maxSurge: 25% - # maxUnavailable: 25% - # type: RollingUpdate - - # -- [K8s StatefulSet](https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/) specific variables - statefulSet: - enabled: false - spec: - # -- Deploy order policy for StatefulSet pods - podManagementPolicy: OrderedReady - - # -- Empty dir configuration if persistence is disabled - emptyDir: {} - persistentVolume: - # -- Create/use Persistent Volume Claim for vmselect component. Empty dir if false. If true, vmselect will create/use a Persistent Volume Claim - enabled: false - - # -- Override Persistent Volume Claim name - name: "" - - # -- Array of access mode. Must match those of existing PV or dynamic provisioner. Details are [here](https://kubernetes.io/docs/concepts/storage/persistent-volumes/) - accessModes: - - ReadWriteOnce - - # -- Persistent volume annotations - annotations: {} - - # -- Persistent volume extra labels - extraLabels: {} - - # -- Existing Claim name. Requires vmselect.persistentVolume.enabled: true. If defined, PVC must be created manually before volume will be bound - existingClaim: "" - - # -- Size of the volume. Better to set the same as resource limit memory property - size: 2Gi - - # -- Mount subpath - subPath: "" - serviceMonitor: - # -- Enable deployment of Service Monitor for vmselect component. This is Prometheus operator object - enabled: false - # -- Target namespace of ServiceMonitor manifest - namespace: "" - # -- Service Monitor labels - extraLabels: {} - # -- Service Monitor annotations - annotations: {} - # -- Basic auth params for Service Monitor - basicAuth: {} - # Commented. Prometheus scare interval for vmselect component - # interval: 15s - # Commented. Prometheus pre-scrape timeout for vmselect component - # scrapeTimeout: 5s - # -- Commented. HTTP scheme to use for scraping. - # scheme: https - # -- Commented. TLS configuration to use when scraping the endpoint - # tlsConfig: - # insecureSkipVerify: true - # -- Service Monitor relabelings - relabelings: [] - # -- Service Monitor metricRelabelings - metricRelabelings: [] - -vminsert: - # -- Enable deployment of vminsert component. Deployment is used - enabled: false - -vmauth: - # -- Enable deployment of vmauth component. - enabled: false - -vmstorage: - # -- Enable deployment of vmstorage component. StatefulSet is used - enabled: false - diff --git a/helm-overrides/k8s-admin-prd-ase1/victoriametrics-storage/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/victoriametrics-storage/custom-values.yaml deleted file mode 100644 index 939084a..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/victoriametrics-storage/custom-values.yaml +++ /dev/null @@ -1,363 +0,0 @@ -# Default values for victoria-metrics. -# This is a YAML-formatted file. -# Declare variables to be passed into your templates. -global: - # -- Image pull secrets, that can be shared across multiple helm charts - imagePullSecrets: [] - image: - # -- Image registry, that can be shared across multiple helm charts - registry: "" - vm: - # -- Image tag for all vm charts - tag: "" - # -- Openshift security context compatibility configuration - compatibility: - openshift: - adaptSecurityContext: "auto" - # -- k8s cluster domain suffix, uses for building storage pods' FQDN. Details are [here](https://kubernetes.io/docs/tasks/administer-cluster/dns-custom-nameservers/) - cluster: - dnsDomain: cluster.local. - -# -- Print information after deployment -printNotes: true - -# -- use SRV discovery for storageNode and selectNode flags for enterprise version -autoDiscovery: false - -common: - # -- common for all components image configuration - image: - tag: "" - -serviceAccount: - # -- Specifies whether a service account should be created - create: true - - # -- The name of the service account to use. - # If not set and create is true, a name is generated using the fullname template - name: - - # -- Service account labels - extraLabels: {} - - # -- Service account annotations - annotations: {} - - # -- mount API token to pod directly - automountToken: true - -# -- Override chart name -nameOverride: "" - -extraSecrets: - [] - # - name: secret-remote-storage-keys - # annotations: [] - # labels: [] - # data: | - # credentials: b64_encoded_str - -# -- Add extra specs dynamically to this chart -extraObjects: [] - -vmselect: - enabled: false - -vminsert: - enabled: false - -vmauth: - enabled: false - -vmstorage: - # -- Enable deployment of vmstorage component. StatefulSet is used - enabled: true - # -- Override default `app` label name - name: vmstorage - image: - # -- Image registry - registry: "" - # -- Image repository - repository: asia-southeast1-docker.pkg.dev/meesho-devops-admin-0622/admin/sre/vmstorage - # -- Image tag - tag: v1.133.0-cluster - # -- Variant of the image to use. e.g. cluster, enterprise-cluster - variant: cluster - # -- Image pull policy - pullPolicy: IfNotPresent - # -- Specify pod lifecycle - lifecycle: {} - ports: - # -- VMStorage http port name - name: "http" - # -- Name of Priority Class - priorityClassName: "" - # -- Overrides the full name of vmstorage component - fullnameOverride: vm-storage-infra-prd - - # -- Additional environment variables (ex.: secret tokens, flags). Check https://docs.victoriametrics.com/victoriametrics/#environment-variables for details - env: [] - # -- Specify alternative source for env variables - envFrom: [] - # -- Data retention period. Possible units character: h(ours), d(ays), w(eeks), y(ears), if no unit character specified - month. The minimum retention period is 24h. - retentionPeriod: 90d - # Additional vmstorage container arguments. Extra command line arguments for vmstorage component - extraArgs: - envflag.enable: true - envflag.prefix: VM_ - loggerFormat: json - search.maxUniqueTimeseries: "30000000" - httpListenAddr: :8482 - loggerTimezone: "Asia/Kolkata" - dedup.minScrapeInterval: 60s - - # Additional hostPath mounts - extraHostPathMounts: - [] - # - name: certs-dir - # mountPath: /etc/kubernetes/certs - # subPath: "" - # hostPath: /etc/kubernetes/certs - # readOnly: true - - # Extra Volumes for the pod - extraVolumes: - [] - # - name: example - # configMap: - # name: example - - # Extra Volume Mounts for the container - extraVolumeMounts: - [] - # - name: example - # mountPath: /example - - extraContainers: - [] - # - name: config-reloader - # image: reloader-image - - extraSecretMounts: - [] - # - name: secret - # mountPath: /etc/credentials - # subPath: "" - # readOnly: true - - initContainers: - [] - # - name: vmrestore - # image: victoriametrics/vmrestore:latest - # volumeMounts: - # - mountPath: /storage - # name: vmstorage-volume - # - mountPath: /etc/vm/creds - # name: secret-remote-storage-keys - # readOnly: true - # args: - # - -storageDataPath=/storage - # - -src=s3://your_bucket/folder/latest - # - -credsFilePath=/etc/vm/creds/credentials - - # -- See `kubectl explain poddisruptionbudget.spec` for more. Ref: [https://kubernetes.io/docs/tasks/run-application/configure-pdb/](https://kubernetes.io/docs/tasks/run-application/configure-pdb/) - podDisruptionBudget: - enabled: false - # minAvailable: 1 - # maxUnavailable: 1 - labels: {} - - # -- Array of tolerations object. Node tolerations for server scheduling to nodes with taints. Ref: [https://kubernetes.io/docs/concepts/configuration/assign-pod-node/](https://kubernetes.io/docs/concepts/configuration/assign-pod-node/) - ## - tolerations: - - key: "dedicated" - operator: "Equal" - value: "vmstorage-n4d" - effect: "NoSchedule" - - # -- Pod's node selector. Ref: [https://kubernetes.io/docs/user-guide/node-selection/](https://kubernetes.io/docs/user-guide/node-selection/) - nodeSelector: - dedicated: "vmstorage-n4d" - - # -- Pod affinity - affinity: {} - - topologySpreadConstraints: - - maxSkew: 1 - topologyKey: topology.kubernetes.io/zone - whenUnsatisfiable: ScheduleAnyway - labelSelector: - matchLabels: - type: vmstorage - - maxSkew: 1 - topologyKey: kubernetes.io/hostname - whenUnsatisfiable: DoNotSchedule - labelSelector: - matchLabels: - type: vmstorage - - # -- Use an alternate scheduler, e.g. "stork". Check https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/ for details - # schedulerName: - - # -- Empty dir configuration if persistence is disabled - emptyDir: {} - persistentVolume: - # -- Create/use Persistent Volume Claim for vmstorage component. Empty dir if false. If true, vmstorage will create/use a Persistent Volume Claim - enabled: true - - # -- Override Persistent Volume Claim name - name: vmstack-storage-volume - - # -- Array of access modes. Must match those of existing PV or dynamic provisioner. Details are https://kubernetes.io/docs/concepts/storage/persistent-volumes/ - accessModes: - - ReadWriteOnce - # -- Persistent volume annotations - annotations: {} - # -- Persistent volume extra labels - extraLabels: {} - # -- Storage class name. Will be empty if not set - storageClassName: hyperdisk-balanced - # -- Existing Claim name. Requires vmstorage.persistentVolume.enabled: true. If defined, PVC must be created manually before volume will be bound - existingClaim: "" - - # -- Data root path. Vmstorage data Persistent Volume mount root path - mountPath: /storage - # -- Size of the volume - size: 500Gi - # -- Mount subpath - subPath: "" - - # -- Pod's annotations - podAnnotations: - prometheus.io/port: "8482" - prometheus.io/scrape: "true" - # -- StatefulSet/Deployment annotations - annotations: - prometheus.io/port: "8482" - prometheus.io/scrape: "true" - # -- StatefulSet/Deployment additional labels - extraLabels: - bu: "infra" - team: "infra-sre" - service: "vm-storage-infra-prd" - env: "prd" - priority: "p0" - type: "vmstorage" - # arch: "arm64" - # runpod: "ondemand" - # -- Pod's additional labels - podLabels: - bu: "infra" - team: "infra-sre" - service: "vm-storage-infra-prd" - env: "prd" - priority: "p0" - type: "vmstorage" - - # -- Count of vmstorage pods - replicaCount: 5 - # -- Container workdir - containerWorkingDir: "" - # -- Deploy order policy for StatefulSet pods - podManagementPolicy: OrderedReady - - # -- Resource object. Details are https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ - resources: - # limits: - # cpu: 500m - # memory: 512Mi - requests: - cpu: 12 - memory: 100Gi - - # -- Pod's security context. Details are https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ - securityContext: - enabled: false - # -- Pod's security context. Details are https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ - podSecurityContext: - enabled: false - service: - enabled: true - # -- Service annotations - annotations: {} - # -- Service ClusterIP - clusterIP: None - # -- Service type - type: ClusterIP - # -- Service labels - labels: {} - # -- Service port - servicePort: 8482 - # -- Port for accepting connections from vminsert - vminsertPort: 8400 - # -- Port for accepting connections from vmselect - vmselectPort: 8401 - # -- Extra service ports - extraPorts: [] - # -- Health check node port for a service. Check https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip for details - healthCheckNodePort: "" - # -- Service external traffic policy. Check https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip for details - externalTrafficPolicy: "" - # -- Service IP family policy. Check https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services for details - ipFamilyPolicy: "" - # -- List of service IP families. Check https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services for details - ipFamilies: [] - # -- Traffic Distribution. Check https://kubernetes.io/docs/concepts/services-networking/service/#traffic-distribution - trafficDistribution: "" - # -- Pod's termination grace period in seconds - terminationGracePeriodSeconds: 60 - minReadySeconds: 5 - # -- Readiness probes - probe: - # -- VMStorage readiness probe - readiness: - httpGet: - path: /health - port: http - initialDelaySeconds: 5 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - liveness: - tcpSocket: - port: http - initialDelaySeconds: 30 - periodSeconds: 30 - timeoutSeconds: 5 - failureThreshold: 10 - # -- VMStorage startup probe - startup: {} - - horizontalPodAutoscaler: - # -- Use HPA for vmstorage component - enabled: false - # -- Maximum replicas for HPA to use to to scale the vmstorage component - maxReplicas: 10 - # -- Minimum replicas for HPA to use to scale the vmstorage component - minReplicas: 2 - # -- Metric for HPA to use to scale the vmstorage component - metrics: [] - # -- Behavior settings for scaling by the HPA - behavior: - scaleDown: - selectPolicy: Disabled - - vmbackupmanager: - # -- Enable automatic creation of backup via vmbackupmanager. vmbackupmanager is part of Enterprise packages - enabled: false - -# -- Enterprise license key configuration for VictoriaMetrics enterprise. -# Required only for VictoriaMetrics enterprise. Check docs [here](https://docs.victoriametrics.com/victoriametrics/enterprise/), -# for more information, visit [site](https://victoriametrics.com/products/enterprise/). -# Request a trial license [here](https://victoriametrics.com/products/enterprise/trial/) -# Supported starting from VictoriaMetrics v1.94.0 -license: - # -- License key - key: "" - - # -- Use existing secret with license key - secret: - # -- Existing secret name - name: "" - # -- Key in secret with license key - key: "" \ No newline at end of file diff --git a/helm-overrides/k8s-admin-prd-ase1/vm-alert-config/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/vm-alert-config/custom-values.yaml deleted file mode 100644 index 8b13789..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/vm-alert-config/custom-values.yaml +++ /dev/null @@ -1 +0,0 @@ - diff --git a/helm-overrides/k8s-admin-prd-ase1/vmagent/custom-values.yaml b/helm-overrides/k8s-admin-prd-ase1/vmagent/custom-values.yaml deleted file mode 100644 index f9488be..0000000 --- a/helm-overrides/k8s-admin-prd-ase1/vmagent/custom-values.yaml +++ /dev/null @@ -1,102 +0,0 @@ -victoria-metrics-agent: - # Ships to victoria-metrics-single. The write path is /api/v1/write, - # the same endpoint any Prometheus remote_write client uses — this is - # the one config line that actually wires the two components together; - # the chart names don't imply it on their own. - # - # Cluster-internal Service DNS: this call happens from a pod, so - # CoreDNS resolves it. Same reasoning as everywhere else in this - # project that a Service name (not an Ingress hostname) is correct - # here — see claude.md's registry-hostname convention for the one case - # where cluster DNS specifically does NOT work (a node-level pull), - # which does not apply to this pod-to-pod write. - remoteWrite: - - url: http://victoria-metrics-single-server.monitoring.svc.cluster.local:8428/api/v1/write - - # config.scrape_configs is left at the chart's own default — it already - # includes kubernetes-nodes-cadvisor (kubelet's cAdvisor endpoint, - # comment literally says "COPY from Prometheus helm chart") and - # kubernetes-service-endpoints (the prometheus.io/scrape annotation - # convention node-exporter's Service carries). Nothing here needs a - # scrape target the chart doesn't already define out of the box — - # except Contour's own Envoy, added below via extraScrapeConfigs (the - # chart concatenates this onto config.scrape_configs rather than - # replacing it, so the defaults above are unaffected). - # - # Confirmed live, not assumed: Cilium's own embedded Envoy (a separate - # thing — its L7 policy proxy, kube-system namespace) was already being - # scraped via the annotation-based kubernetes-pods job, which is what - # first showed envoy_* metrics existed at all in this cluster. Contour's - # ingress Envoy (projectcontour namespace — the actual data plane for - # everything routed through this homelab's Ingress, hostPort 80/443) - # carries no such annotation, confirmed by its total absence from - # `envoy_http_downstream_rq_total{namespace="projectcontour"}` before - # this job existed — so it needs its own explicit target. - # - # Filtered by container port number (8002, the official Contour - # chart's fixed metrics port for Envoy — projectcontour/values or - # equivalent) rather than by pod label: this cluster's Contour install - # auto-detected object names after install rather than assuming the - # chart's defaults (see claude.md's Contour install history), so a - # label guess is less trustworthy here than the one thing that has to - # be true for Envoy's own metrics port to exist at all. - # - # /stats/prometheus is Envoy's own built-in admin endpoint format, not - # a Contour-specific path — this is how any Envoy exposes Prometheus - # metrics once a metrics listener is configured, independent of chart. - # - # node-exporter needed the same treatment, for a different reason: - # confirmed live that kubernetes-service-endpoints (role: endpointslice, - # keyed on the *Service's* prometheus.io/scrape annotation — where the - # node-exporter chart actually puts it, not on the pod) finds nothing - # at all in this cluster — not "down", entirely absent from `up`, no - # `kubernetes-service-endpoints`/`kubernetes-services` job present - # whatsoever. Rather than chase why that discovery path is empty here, - # targeting node-exporter's pod directly by its declared container port - # (9100, the chart's fixed default) sidesteps it the same way the - # Envoy job above does, and is no less correct for not depending on - # whichever annotation-propagation mechanism isn't working. - extraScrapeConfigs: - - job_name: contour-envoy - kubernetes_sd_configs: - - role: pod - namespaces: - names: ["projectcontour"] - relabel_configs: - - action: keep - source_labels: [__meta_kubernetes_pod_container_port_number] - regex: "8002" - - target_label: __metrics_path__ - replacement: /stats/prometheus - - action: labelmap - regex: __meta_kubernetes_pod_label_(.+) - - source_labels: [__meta_kubernetes_pod_name] - target_label: pod - - source_labels: [__meta_kubernetes_namespace] - target_label: namespace - - source_labels: [__meta_kubernetes_pod_node_name] - target_label: node - - job_name: node-exporter - kubernetes_sd_configs: - - role: pod - namespaces: - names: ["monitoring"] - relabel_configs: - - action: keep - source_labels: [__meta_kubernetes_pod_container_port_number] - regex: "9100" - - action: labelmap - regex: __meta_kubernetes_pod_label_(.+) - - source_labels: [__meta_kubernetes_pod_name] - target_label: pod - - source_labels: [__meta_kubernetes_namespace] - target_label: namespace - - source_labels: [__meta_kubernetes_pod_node_name] - target_label: node - - resources: - requests: - cpu: 25m - memory: 64Mi - limits: - memory: 192Mi