Grafana: real dashboards over VictoriaMetrics. Provisioned rather than
clicked through: a VictoriaMetrics datasource (type: prometheus — VM
speaks that query API, which is the whole point of it existing) is
baked into the chart's own datasource-provisioning config, so a fresh
install has it working with no manual setup. Admin credentials from
Vault via ExternalSecret (secretstores/grafana-admin-credentials.yaml
in devops-infra-argo-config), same pattern as every other admin
credential in this project — never plaintext in this repo. 1Gi
local-path PVC for dashboards/Grafana's own state (VictoriaMetrics
holds the actual metric data, not this). Dual LAN+Tailscale Ingress
hosts, same convention as everything externally reachable here.
Found and fixed while vendoring: helm-templates/grafana already held a
fully-vendored old Grafana chart (v6.58.7, appVersion 10.0.3) from the
original Meesho monorepo import (commit b8575bb) — generic production
config (fullnameOverride: grafana-infra-prd, GKE-shaped RBAC/PSP
defaults) unrelated to this homelab, same class of leftover as
victoria-metrics-single's collision two commits ago. Removed and
re-vendored fresh (10.5.15) as a thin wrapper, matching every other
official-chart component in this repo now.
vmui: VictoriaMetrics' own built-in UI (ad-hoc PromQL + graphs, no
saved dashboards — what Grafana is for) is served on the same
pod/port, so exposing it cost one ingress block on the
victoria-metrics-single values already committed. No new component,
no new RAM.
Verified with `helm template` against the real charts for both
components individually (Grafana: admin env vars correctly reference
the ExternalSecret's keys, datasource ConfigMap renders the intended
VictoriaMetrics URL, PVC/resources/ingress hosts all match; vmui:
ingress renders both hostnames pointing at the existing Service's named
http port) and again for the whole generic-argo-apps-chart appSpec
list — 12 Applications render, including grafana.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Wajog7nELA3i8JWTjxYGHF
52 lines
1.8 KiB
YAML
52 lines
1.8 KiB
YAML
grafana:
|
|
# From Vault via ExternalSecret (devops-infra-argo-config/secretstores/
|
|
# grafana-admin-credentials.yaml), same pattern as gitea/harbor/jenkins
|
|
# admin credentials elsewhere in this project — never a plaintext
|
|
# adminPassword in this file.
|
|
admin:
|
|
existingSecret: grafana-admin-credentials
|
|
userKey: username
|
|
passwordKey: password
|
|
|
|
persistence:
|
|
# local-path-provisioner, this cluster's default StorageClass —
|
|
# installed right after Cilium precisely because kubeadm ships no
|
|
# default (unlike k3s). 1Gi, not the chart's 10Gi default: this is
|
|
# dashboards, folders and Grafana's own sqlite state, not metric
|
|
# data — VictoriaMetrics holds that. Not resizable in place with
|
|
# this provisioner, so sized deliberately rather than grown later.
|
|
enabled: true
|
|
storageClassName: local-path
|
|
size: 1Gi
|
|
|
|
resources:
|
|
requests:
|
|
cpu: 50m
|
|
memory: 128Mi
|
|
limits:
|
|
memory: 384Mi
|
|
|
|
# Provisioned at boot, not clicked through in the UI — the same reason
|
|
# every other credential/config in this project is committed rather
|
|
# than set by hand: it survives a pod restart and a fresh install gets
|
|
# it automatically. VictoriaMetrics speaks Prometheus's own query API,
|
|
# so `type: prometheus` here is correct even though the URL is VM's —
|
|
# see devops-infra-helm-charts' victoria-metrics-single chart for why.
|
|
datasources:
|
|
datasources.yaml:
|
|
apiVersion: 1
|
|
datasources:
|
|
- name: VictoriaMetrics
|
|
type: prometheus
|
|
access: proxy
|
|
url: http://victoria-metrics-single-server.monitoring.svc.cluster.local:8428
|
|
isDefault: true
|
|
|
|
ingress:
|
|
enabled: true
|
|
ingressClassName: contour
|
|
path: /
|
|
hosts:
|
|
- grafana.192.168.1.7.nip.io
|
|
- grafana.100.90.248.118.nip.io
|