Grafana: real dashboards over VictoriaMetrics. Provisioned rather than
clicked through: a VictoriaMetrics datasource (type: prometheus — VM
speaks that query API, which is the whole point of it existing) is
baked into the chart's own datasource-provisioning config, so a fresh
install has it working with no manual setup. Admin credentials from
Vault via ExternalSecret (secretstores/grafana-admin-credentials.yaml
in devops-infra-argo-config), same pattern as every other admin
credential in this project — never plaintext in this repo. 1Gi
local-path PVC for dashboards/Grafana's own state (VictoriaMetrics
holds the actual metric data, not this). Dual LAN+Tailscale Ingress
hosts, same convention as everything externally reachable here.
Found and fixed while vendoring: helm-templates/grafana already held a
fully-vendored old Grafana chart (v6.58.7, appVersion 10.0.3) from the
original Meesho monorepo import (commit b8575bb) — generic production
config (fullnameOverride: grafana-infra-prd, GKE-shaped RBAC/PSP
defaults) unrelated to this homelab, same class of leftover as
victoria-metrics-single's collision two commits ago. Removed and
re-vendored fresh (10.5.15) as a thin wrapper, matching every other
official-chart component in this repo now.
vmui: VictoriaMetrics' own built-in UI (ad-hoc PromQL + graphs, no
saved dashboards — what Grafana is for) is served on the same
pod/port, so exposing it cost one ingress block on the
victoria-metrics-single values already committed. No new component,
no new RAM.
Verified with `helm template` against the real charts for both
components individually (Grafana: admin env vars correctly reference
the ExternalSecret's keys, datasource ConfigMap renders the intended
VictoriaMetrics URL, PVC/resources/ingress hosts all match; vmui:
ingress renders both hostnames pointing at the existing Service's named
http port) and again for the whole generic-argo-apps-chart appSpec
list — 12 Applications render, including grafana.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Wajog7nELA3i8JWTjxYGHF
45 lines
1.7 KiB
YAML
45 lines
1.7 KiB
YAML
victoria-metrics-single:
|
|
server:
|
|
# 7 days, not the chart's month-long default — a homelab whose entire
|
|
# purpose is proving a CI/CD pipeline has no use for that much
|
|
# history, and every extra day is disk this node does not have spare.
|
|
retentionPeriod: "7d"
|
|
|
|
persistentVolume:
|
|
# local-path-provisioner, this cluster's default StorageClass —
|
|
# installed right after Cilium precisely because kubeadm ships no
|
|
# default (unlike k3s). 3Gi, not the chart's 16Gi default: VM's own
|
|
# compression is the whole reason it replaced Prometheus here, and
|
|
# this cluster's metric volume at a 7-day retention comfortably
|
|
# fits well inside that. Not resizable in place with this
|
|
# provisioner, so sized deliberately rather than grown later.
|
|
storageClassName: local-path
|
|
size: 3Gi
|
|
|
|
resources:
|
|
requests:
|
|
cpu: 50m
|
|
memory: 128Mi
|
|
limits:
|
|
memory: 512Mi
|
|
|
|
# vmui — VictoriaMetrics' own built-in UI, served at /vmui/ on the
|
|
# same server. Ad-hoc PromQL queries and graphs only, no saved
|
|
# dashboards; Grafana (separate release) is what those need. Exposed
|
|
# anyway since it costs nothing extra to run — it's the same
|
|
# pod/port, not a new component — and is useful on its own for
|
|
# poking at a metric without opening Grafana.
|
|
#
|
|
# Dual LAN + Tailscale hostnames, same convention as every other
|
|
# externally-reachable service in this homelab.
|
|
ingress:
|
|
enabled: true
|
|
ingressClassName: contour
|
|
hosts:
|
|
- name: vm.192.168.1.7.nip.io
|
|
path: ["/"]
|
|
port: http
|
|
- name: vm.100.90.248.118.nip.io
|
|
path: ["/"]
|
|
port: http
|