cw-infra-apps/grafana/values.yaml

1044 lines
41 KiB
YAML

# yamllint disable rule:line-length rule:comments-indentation
---
cluster:
# -- The name for this cluster.
# @section -- Cluster
name: "cluster.local"
#
# Global settings
#
global:
# -- The specific platform for this cluster. Will enable compatibility for some platforms. Supported options: (empty) or "openshift".
# @section -- Global Settings
platform: ""
# -- The Kubernetes service. Change this if your cluster DNS is configured differently than the default.
# @section -- Global Settings
kubernetesAPIService: ""
# -- How frequently to scrape metrics.
# @section -- Global Settings
scrapeInterval: 60s
# -- Sets the max_cache_size for every prometheus.relabel component. ([docs](https://grafana.com/docs/alloy/latest/reference/components/prometheus/prometheus.relabel/#arguments))
# This should be at least 2x-5x your largest scrape target or samples appended rate.
# @section -- Global Settings
maxCacheSize: 100000
alloyModules:
# -- The source of the Alloy modules. The valid options are "configMap" or "git"
# @section -- Global Settings
source: configMap
# -- If using git, the branch of the git repository to use.
# @section -- Global Settings
branch: main
#
# Destinations
#
# -- The list of destinations where telemetry data will be sent.
# See the [destinations documentation](https://github.com/grafana/k8s-monitoring-helm/blob/main/charts/k8s-monitoring/docs/destinations/README.md) for more information.
# @section -- Destinations
destinations:
- name: Metrics
type: prometheus
url: https://insert.metric.ngcloud.ru/insert/multitenant/prometheus/api/v1/write
extraLabels:
resourceRealm: "cowork.nubes.ru"
tls:
ca: |
-----BEGIN CERTIFICATE-----
MIIGzTCCBLWgAwIBAgIUQje87V6XtMmXTm2Zik9aZRTVN6swDQYJKoZIhvcNAQEL
BQAwazELMAkGA1UEBhMCUlUxDzANBgNVBAgMBlJ1c3NpYTEPMA0GA1UEBwwGTW9z
Y293MQ4wDAYDVQQKDAVudWJlczEOMAwGA1UECwwFbnViZXMxGjAYBgNVBAMMEW1l
dHJpYy5uZ2Nsb3VkLnJ1MB4XDTI1MDIxODIwMDQwNVoXDTM1MDIxNjIwMDQwNVow
azELMAkGA1UEBhMCUlUxDzANBgNVBAgMBlJ1c3NpYTEPMA0GA1UEBwwGTW9zY293
MQ4wDAYDVQQKDAVudWJlczEOMAwGA1UECwwFbnViZXMxGjAYBgNVBAMMEW1ldHJp
Yy5uZ2Nsb3VkLnJ1MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAzvqs
UfN5T6npdR2i0oOSngtmHfrBIy/6Cvc7ToQszvpA96PL8tyDYsnqpf44TPllHU5r
Y9jPM1RO4zBotTk7z8YLLn71uFUpbFDEJoXOmQzUL35KpD0CVMTzSc1WRwTICxi9
IKYM9K4d5W7F+ayfZagFI6vLTLTpX7pRJlromxpDD6dUZZTIf0Brm1U0fMXKNUxT
PZ/hj+5Uk8ehA43f95VwB+IXjOnYOELL/U/dLfdiTdtKx9jIVMi84cxdKjsXNsZq
p6298/Ibh6UazntYSFZi4/IP16RsK1kW5HBTuU+XnUk2BsXh36DpY1gdiUBSUK1P
rCMPQcnTb6jnlWx0FBS24WoA07tYWPVuLZoEyIIGC+pBAqh7O9tn/eqDmZIJpTxr
p1FNEXog3if6VOnzGgm+nTpSnIUlwaY+8AFg8+/m5irWRR1gqINYUN+AaqneNjds
sF4jHKuyaRVqhhi3ci9/3dNKbvouqqHMyMRZtf9TfOfI7Va/a/Fy7HHeXnm1XCfh
UyMjnhcZCmlTFGWQIoAvQmghOkGV4aZhJCUVgcwVWn7hbKCQprXjt0r7F2S95AQm
3IIZnWhqX69Zy4gT6iC3ekAkY4wbk3R8Px57bRy8Kl/fzs/TSzvDkLXNQp7fmCuf
uwIJlUw3777PptaxhhPBvn+qDXr75hztKRYYc5sCAwEAAaOCAWcwggFjMB0GA1Ud
DgQWBBT+NMAwR5MjzkqSINTOX8B+29W1cjCBqAYDVR0jBIGgMIGdgBT+NMAwR5Mj
zkqSINTOX8B+29W1cqFvpG0wazELMAkGA1UEBhMCUlUxDzANBgNVBAgMBlJ1c3Np
YTEPMA0GA1UEBwwGTW9zY293MQ4wDAYDVQQKDAVudWJlczEOMAwGA1UECwwFbnVi
ZXMxGjAYBgNVBAMMEW1ldHJpYy5uZ2Nsb3VkLnJ1ghRCN7ztXpe0yZdObZmKT1pl
FNU3qzAMBgNVHRMEBTADAQH/MAsGA1UdDwQEAwIC/DA9BgNVHREENjA0ghhzZWxl
Y3QubWV0cmljLm5nY2xvdWQucnWCGGluc2VydC5tZXRyaWMubmdjbG91ZC5ydTA9
BgNVHRIENjA0ghhzZWxlY3QubWV0cmljLm5nY2xvdWQucnWCGGluc2VydC5tZXRy
aWMubmdjbG91ZC5ydTANBgkqhkiG9w0BAQsFAAOCAgEAYIoWyjVwBhIAVeqEZwgL
S0HiouN1SNhd8+TjNpmq5pk51/TejoA3pZ1NAo9wdAziyxbKkyCH9H35G7n/DWFO
S5E11UbNmlKrRuREV9TzTot8K1kEQrABiPPXaio8i6vtZD8gakYefPxDeWAWZazs
NCfGR2xLybTeXdJ5qm+2S4GGA9DnW+6e0RItVZD8cY252o/a3JNBsJjwfNmZWakz
raK+7eiCrBfwoJ5aLILGe4yul0XKVCYwWEu4EdavmYWTl5mtbZnkZMIvRQ4ZyqMR
JOAGlgK2QcfMWAvDGQc/GmXr4n+DPji0kSO1GZFWGBCjVSjTjVvL54RJhfF28OX9
kFKAJJWaLR+wbaZMwTi6qD9zveqXvocQh9fmzJmkKlaQoDR6jeOCAOTQjkkKYQuX
DkTl9mytkWEdF8rqPSpzxbX3C7FMIC10oz7/vv8wNJL5jEUB/IuuiQmVbAjnn/hq
7Sll7Z+0kl3XMytmb3x3sF6Ri7c0oZkRf5Zd+Jh8dr3VT4Yq+cVbkzocD1QaXYNF
zL2b6/91gjgcHbqcbEksfwfMbre4fflBMo2Vs6h3E99enQ0ZB5VBJQRv8X9ZOVnv
OWCME8Oi+X0lOryCz2bGW38q5UUyFv2hJn3enDA97oZtioDJ9rxCFmliMjacOpoy
hPGGjhjtmeQX3ApWW+gmXWw=
-----END CERTIFICATE-----
- name: Logs
type: loki
url: https://insert.log.ngcloud.ru/loki/api/v1/push
extraLabels:
resourceRealm: "cowork.nubes.ru"
tls:
ca: |
-----BEGIN CERTIFICATE-----
MIIEuDCCA6CgAwIBAgIUUADJQeKcpefXn/o6a8fba64bUscwDQYJKoZIhvcNAQEL
BQAwaDELMAkGA1UEBhMCUlUxDzANBgNVBAgMBlJ1c3NpYTEPMA0GA1UEBwwGTW9z
Y293MQ4wDAYDVQQKDAVudWJlczEOMAwGA1UECwwFbnViZXMxFzAVBgNVBAMMDmxv
Zy5uZ2Nsb3VkLnJ1MB4XDTI1MDIxOTA5MjkzOFoXDTM1MDIxNzA5MjkzOFowaDEL
MAkGA1UEBhMCUlUxDzANBgNVBAgMBlJ1c3NpYTEPMA0GA1UEBwwGTW9zY293MQ4w
DAYDVQQKDAVudWJlczEOMAwGA1UECwwFbnViZXMxFzAVBgNVBAMMDmxvZy5uZ2Ns
b3VkLnJ1MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvaVoQuQ8A1lO
7mrriMQWVfUO2MT/fcBhiulYJcxkZTOwfS7iHssBFz5PigOSn0PqqCHPUJZ/SfKI
FdEagfpc4FuEJ5Mv7Fex7UBkXwAyOomU29cyaJjtlqDEKnNHie5PZQfnFV0YxPM1
QtQsrOhhI2dMlQxR65I+440yPkrsv5hDXw5XBsHOvjxlnDnOfulmREgP8a+uwe8M
TokoE9XFCxIfYn0IbEhPEqWLlyHvBnXt2ddDOXDAp2XJndVrdj1rIy+rudAv5/Gx
Tna2JX+6h6f0JCwyOcbyYr3YznHmio5Gu0ZrAAFXueryYmuq9I9kUJJV9h5ilAFs
wRmt7EA9ywIDAQABo4IBWDCCAVQwHQYDVR0OBBYEFMjF50YBCR/hQMbeKCPYABSI
n789MIGlBgNVHSMEgZ0wgZqAFMjF50YBCR/hQMbeKCPYABSIn789oWykajBoMQsw
CQYDVQQGEwJSVTEPMA0GA1UECAwGUnVzc2lhMQ8wDQYDVQQHDAZNb3Njb3cxDjAM
BgNVBAoMBW51YmVzMQ4wDAYDVQQLDAVudWJlczEXMBUGA1UEAwwObG9nLm5nY2xv
dWQucnWCFFAAyUHinKXn15/6OmvH22uuG1LHMAwGA1UdEwQFMAMBAf8wCwYDVR0P
BAQDAgL8MDcGA1UdEQQwMC6CFXNlbGVjdC5sb2cubmdjbG91ZC5ydYIVaW5zZXJ0
LmxvZy5uZ2Nsb3VkLnJ1MDcGA1UdEgQwMC6CFXNlbGVjdC5sb2cubmdjbG91ZC5y
dYIVaW5zZXJ0LmxvZy5uZ2Nsb3VkLnJ1MA0GCSqGSIb3DQEBCwUAA4IBAQCrQJbU
WSnURocaIbaaXLqa/cpniVyFQQXf1i4kQMVXydJuroGgNWlq2qXv4YYau96wZOxF
POr/HJMXBZapMLqAbup3k/8Cb42+qUxC7m/M2dHIHwAEegBwvb7TV50m2/Nd2907
nhY/Jx22FaACpMdQPdiSdJLu2TTFHT3mpKJ0hse3El1Kw0WZBfwjaCESZvzH7K8h
9xNEiSG/lOl6mjnVc1WPv2YIzYStUCbVleMKAz0DEtQYgRYY89sVvJlkTDHkUc8A
l37qH3wZrQ/5BU6psxe+586CB86gpt3F/266BCeUtunS9SywNWJsajgmKUENTfYW
E3yjqYhIOgCdntfV
-----END CERTIFICATE-----
#
# Features
#
# -- Cluster Monitoring enables observability and monitoring for your Kubernetes Cluster itself.
# Requires a destination that supports metrics.
# To see the valid options, please see the [Cluster Monitoring feature documentation](https://github.com/grafana/k8s-monitoring-helm/tree/main/charts/k8s-monitoring/charts/feature-cluster-metrics).
# @default -- Disabled
# @section -- Features - Cluster Metrics
clusterMetrics:
# -- Enable gathering Kubernetes Cluster metrics.
# @section -- Features - Cluster Metrics
enabled: true
# -- The destinations where cluster metrics will be sent. If empty, all metrics-capable destinations will be used.
# @section -- Features - Cluster Metrics
destinations: []
# -- Which collector to assign this feature to. Do not change this unless you are sure of what you are doing.
# @section -- Features - Cluster Metrics
# @ignored
collector: alloy-metrics
# To see additional options, please see the [Cluster Monitoring feature documentation](https://github.com/grafana/k8s-monitoring-helm/tree/main/charts/k8s-monitoring/charts/feature-cluster-metrics).
# -- Cluster events.
# Requires a destination that supports logs.
# To see the valid options, please see the [Cluster Events feature documentation](https://github.com/grafana/k8s-monitoring-helm/tree/main/charts/k8s-monitoring/charts/feature-cluster-events).
# @default -- Disabled
# @section -- Features - Cluster Events
clusterEvents:
# -- Enable gathering Kubernetes Cluster events.
# @section -- Features - Cluster Events
enabled: true
# -- The destinations where cluster events will be sent. If empty, all logs-capable destinations will be used.
# @section -- Features - Cluster Events
destinations: []
# -- Which collector to assign this feature to. Do not change this unless you are sure of what you are doing.
# @section -- Features - Cluster Events
# @ignored
collector: alloy-singleton
# To see additional options, please see the [Cluster Events feature documentation](https://github.com/grafana/k8s-monitoring-helm/tree/main/charts/k8s-monitoring/charts/feature-cluster-events).
# -- Node logs.
# Requires a destination that supports logs.
# To see the valid options, please see the [Node Logs feature documentation](https://github.com/grafana/k8s-monitoring-helm/tree/main/charts/k8s-monitoring/charts/feature-node-logs).
# @default -- Disabled
# @section -- Features - Node Logs
nodeLogs:
# -- Enable gathering Kubernetes Cluster Node logs.
# @section -- Features - Node Logs
enabled: true
# -- The destinations where logs will be sent. If empty, all logs-capable destinations will be used.
# @section -- Features - Node Logs
destinations: []
# -- Which collector to assign this feature to. Do not change this unless you are sure of what you are doing.
# @section -- Features - Node Logs
# @ignored
collector: alloy-logs
# To see additional options, please see the [Node Logs feature documentation](https://github.com/grafana/k8s-monitoring-helm/tree/main/charts/k8s-monitoring/charts/feature-node-logs).
# -- Pod logs.
# Requires a destination that supports logs.
# To see the valid options, please see the [Pod Logs feature documentation](https://github.com/grafana/k8s-monitoring-helm/tree/main/charts/k8s-monitoring/charts/feature-pod-logs).
# @default -- Disabled
# @section -- Features - Pod Logs
podLogs:
# -- Enable gathering Kubernetes Pod logs.
# @section -- Features - Pod Logs
enabled: true
# -- The destinations where logs will be sent. If empty, all logs-capable destinations will be used.
# @section -- Features - Pod Logs
destinations: []
# -- Which collector to assign this feature to. Do not change this unless you are sure of what you are doing.
# @section -- Features - Pod Logs
# @ignored
collector: alloy-logs
# To see additional options, please see the [Pod Logs feature documentation](https://github.com/grafana/k8s-monitoring-helm/tree/main/charts/k8s-monitoring/charts/feature-pod-logs).
# -- Application Observability.
# Requires destinations that supports metrics, logs, and traces.
# To see the valid options, please see the [Application Observability feature documentation](https://github.com/grafana/k8s-monitoring-helm/tree/main/charts/k8s-monitoring/charts/feature-application-observability).
# @default -- Disabled
# @section -- Features - Application Observability
applicationObservability:
# -- Enable receiving Application Observability.
# @section -- Features - Application Observability
enabled: false
# -- The destinations where application data will be sent. If empty, all capable destinations will be used.
# @section -- Features - Application Observability
destinations: []
# -- The receivers used for receiving application data.
# @section -- Features - Application Observability
receivers: {}
# -- Which collector to assign this feature to. Do not change this unless you are sure of what you are doing.
# @section -- Features - Application Observability
# @ignored
collector: alloy-receiver
# To see additional options, please see the [Application Observability feature documentation](https://github.com/grafana/k8s-monitoring-helm/tree/main/charts/k8s-monitoring/charts/feature-application-observability).
# -- Auto-Instrumentation.
# Requires destinations that supports metrics, logs, and traces.
# To see the valid options, please see the [Auto-Instrumentation feature documentation](https://github.com/grafana/k8s-monitoring-helm/tree/main/charts/k8s-monitoring/charts/feature-auto-instrumentation).
# @default -- Disabled
# @section -- Features - Auto-Instrumentation
autoInstrumentation:
# -- Enable automatic instrumentation for applications.
# @section -- Features - Auto-Instrumentation
enabled: false
# -- The destinations where application data will be sent. If empty, all capable destinations will be used.
# @section -- Features - Auto-Instrumentation
destinations: []
# -- Which collector to assign this feature to. Do not change this unless you are sure of what you are doing.
# @section -- Features - Auto-Instrumentation
# @ignored
collector: alloy-metrics
# To see additional options, please see the [Auto-Instrumentation feature documentation](https://github.com/grafana/k8s-monitoring-helm/tree/main/charts/k8s-monitoring/charts/feature-auto-instrumentation).
# -- Annotation Autodiscovery enables gathering metrics from Kubernetes Pods and Services discovered by special annotations.
# Requires a destination that supports metrics.
# To see the valid options, please see the [Annotation Autodiscovery feature documentation](https://github.com/grafana/k8s-monitoring-helm/tree/main/charts/k8s-monitoring/charts/feature-annotation-autodiscovery).
# @default -- Disabled
# @section -- Features - Annotation Autodiscovery
annotationAutodiscovery:
# -- Enable gathering metrics from Kubernetes Pods and Services discovered by special annotations.
# @section -- Features - Annotation Autodiscovery
enabled: false
# -- The destinations where cluster metrics will be sent. If empty, all metrics-capable destinations will be used.
# @section -- Features - Annotation Autodiscovery
destinations: []
# -- Which collector to assign this feature to. Do not change this unless you are sure of what you are doing.
# @section -- Features - Annotation Autodiscovery
# @ignored
collector: alloy-metrics
# To see additional options, please see the [Annotation Autodiscovery feature documentation](https://github.com/grafana/k8s-monitoring-helm/tree/main/charts/k8s-monitoring/charts/feature-annotation-autodiscovery).
# -- Prometheus Operator Objects enables the gathering of metrics from objects like Probes, PodMonitors, and
# ServiceMonitors. Requires a destination that supports metrics.
# To see the valid options, please see the [Prometheus Operator Objects feature documentation](https://github.com/grafana/k8s-monitoring-helm/tree/main/charts/k8s-monitoring/charts/feature-prometheus-operator-objects).
# @default -- Disabled
# @section -- Features - Prometheus Operator Objects
prometheusOperatorObjects:
# -- Enable gathering metrics from Prometheus Operator Objects.
# @section -- Features - Prometheus Operator Objects
enabled: false
# -- The destinations where metrics will be sent. If empty, all metrics-capable destinations will be used.
# @section -- Features - Prometheus Operator Objects
destinations: []
# -- Which collector to assign this feature to. Do not change this unless you are sure of what you are doing.
# @section -- Features - Prometheus Operator Objects
# @ignored
collector: alloy-metrics
# To see additional options, please see the [Prometheus Operator Objects feature documentation](https://github.com/grafana/k8s-monitoring-helm/tree/main/charts/k8s-monitoring/charts/feature-prometheus-operator-objects).
# -- Profiling enables gathering profiles from applications.
# Requires a destination that supports profiles.
# To see the valid options, please see the [Profiling feature documentation](https://github.com/grafana/k8s-monitoring-helm/tree/main/charts/k8s-monitoring/charts/feature-profiling).
# @default -- Disabled
# @section -- Features - Profiling
profiling:
# -- Enable gathering profiles from applications.
# @section -- Features - Profiling
enabled: false
# -- The destinations where profiles will be sent. If empty, all profiles-capable destinations will be used.
# @section -- Features - Profiling
destinations: []
# -- Which collector to assign this feature to. Do not change this unless you are sure of what you are doing.
# @section -- Features - Profiling
# @ignored
collector: alloy-profiles
# To see additional options, please see the [Profiling feature documentation](https://github.com/grafana/k8s-monitoring-helm/tree/main/charts/k8s-monitoring/charts/feature-profiling).
# -- Service Integrations enables gathering telemetry data for common services and applications deployed to Kubernetes.
# To see the valid options, please see the [Service Integrations documentation](https://github.com/grafana/k8s-monitoring-helm/tree/main/charts/k8s-monitoring/charts/feature-integrations).
# @default -- No integrations enabled
# @section -- Features - Service Integrations
integrations:
# -- The destinations where integration metrics will be sent. If empty, all metrics-capable destinations will be used.
# @section -- Features - Service Integrations
destinations: []
# -- Which collectors to assign this feature to. Do not change this unless you are sure of what you are doing.
# @section -- Features - Service Integrations
# @ignored
collector: alloy-metrics
# To see additional options, please see the [Service Integrations documentation](https://github.com/grafana/k8s-monitoring-helm/tree/main/charts/k8s-monitoring/charts/feature-integrations).
# Self-reporting creates a single metric and log that reports anonymized information about how this Helm chart was
# configured. It reports features enabled, destinations types used, and alloy instances enabled. It does not report any
# actual telemetry data, credentials or configuration, or send any data to any destination other than the ones
# configured above.
# @section -- Features - Self-reporting
selfReporting:
# -- Enable Self-reporting.
# @section -- Features - Self-reporting
enabled: true
# -- The destinations where self-report metrics will be sent. If empty, all metrics-capable destinations will be used.
# @section -- Features - Self-reporting
destinations: []
# -- How frequently to generate self-report metrics. This does utilize the global scrapeInterval setting.
# @default -- 60s
# @section -- Features - Self-reporting
scrapeInterval: ""
#
# Collectors (Alloy instances)
#
# An Alloy instance for collecting metrics.
# To see additional valid options, please see the [Alloy Helm chart documentation](https://github.com/grafana/alloy/tree/main/operations/helm/charts/alloy).
alloy-metrics:
# -- Deploy the Alloy instance for collecting metrics.
# @section -- Collectors - Alloy Metrics
enabled: true
# -- Extra Alloy configuration to be added to the configuration file.
# @section -- Collectors - Alloy Metrics
extraConfig: ""
# Remote configuration from a remote config server.
remoteConfig:
# -- Enable fetching configuration from a remote config server.
# @section -- Collectors - Alloy Metrics
enabled: false
# -- The URL of the remote config server.
# @section -- Collectors - Alloy Metrics
url: ""
# -- The proxy URL to use of the remote config server.
# @section -- Collectors - Alloy Metrics
proxyURL: ""
auth:
# -- The type of authentication to use for the remote config server.
# @section -- Collectors - Alloy Metrics
type: "none"
# -- The username to use for the remote config server.
# @section -- Collectors - Alloy Metrics
username: ""
# -- The key for storing the username in the secret.
# @section -- Collectors - Alloy Metrics
usernameKey: "username"
# -- Raw config for accessing the password.
# @section -- Collectors - Alloy Metrics
usernameFrom: ""
# -- The password to use for the remote config server.
# @section -- Collectors - Alloy Metrics
password: ""
# -- The key for storing the password in the secret.
# @section -- Collectors - Alloy Metrics
passwordKey: "password"
# -- Raw config for accessing the password.
# @section -- Collectors - Alloy Metrics
passwordFrom: ""
secret:
# -- Whether to create a secret for the remote config server.
# @section -- Collectors - Alloy Metrics
create: true
# -- If true, skip secret creation and embed the credentials directly into the configuration.
# @section -- Collectors - Alloy Metrics
embed: false
# -- The name of the secret to create.
# @section -- Collectors - Alloy Metrics
name: ""
# -- The namespace for the secret.
# @section -- Collectors - Alloy Metrics
namespace: ""
# -- The frequency at which to poll the remote config server for updates.
# @section -- Collectors - Alloy Metrics
pollFrequency: 5m
# -- Attributes to be added to this collector when requesting configuration.
# @section -- Collectors - Alloy Metrics
extraAttributes: {}
logging:
# -- Level at which Alloy log lines should be written.
# @section -- Collectors - Alloy Metrics
level: info
# -- Format to use for writing Alloy log lines.
# @section -- Collectors - Alloy Metrics
format: logfmt
liveDebugging:
# -- Enable live debugging for the Alloy instance.
# @section -- Collectors - Alloy Metrics
enabled: false
# @ignored
alloy:
configMap: {create: false}
# Enable clustering to ensure that scraping is distributed across all instances.
# @ignored
clustering:
name: alloy-metrics
enabled: true
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]
add: ["CHOWN", "DAC_OVERRIDE", "FOWNER", "FSETID", "KILL", "SETGID", "SETUID", "SETPCAP", "NET_BIND_SERVICE", "NET_RAW", "SYS_CHROOT", "MKNOD", "AUDIT_WRITE", "SETFCAP"]
seccompProfile:
type: "RuntimeDefault"
# Set resource requests and limits. [Guidelines](https://grafana.com/docs/alloy/latest/introduction/estimate-resource-usage/).
# resources:
# requests: {}
# limits: {}
controller:
# -- The type of controller to use for the Alloy Metrics instance.
# @section -- Collectors - Alloy Metrics
type: statefulset
# -- The number of replicas for the Alloy Metrics instance.
# @section -- Collectors - Alloy Metrics
replicas: 1
# @ignored
nodeSelector:
kubernetes.io/os: linux
# @ignored
podAnnotations:
k8s.grafana.com/logs.job: integrations/alloy
# Skip installation of the Grafana Alloy CRDs, since we don't use them in this chart
# @ignored
crds: {create: false}
# An Alloy instance for data sources required to be deployed on a single replica.
# To see additional valid options, please see the [Alloy Helm chart documentation](https://github.com/grafana/alloy/tree/main/operations/helm/charts/alloy).
alloy-singleton:
# -- Deploy the Alloy instance for data sources required to be deployed on a single replica.
# @section -- Collectors - Alloy Singleton
enabled: true
# -- Extra Alloy configuration to be added to the configuration file.
# @section -- Collectors - Alloy Singleton
extraConfig: ""
# Remote configuration from a remote config server.
remoteConfig:
# -- Enable fetching configuration from a remote config server.
# @section -- Collectors - Alloy Singleton
enabled: false
# -- The URL of the remote config server.
# @section -- Collectors - Alloy Singleton
url: ""
# -- The proxy URL to use of the remote config server.
# @section -- Collectors - Alloy Singleton
proxyURL: ""
auth:
# -- The type of authentication to use for the remote config server.
# @section -- Collectors - Alloy Singleton
type: "none"
# -- The username to use for the remote config server.
# @section -- Collectors - Alloy Singleton
username: ""
# -- The key for storing the username in the secret.
# @section -- Collectors - Alloy Singleton
usernameKey: "username"
# -- Raw config for accessing the username.
# @section -- Collectors - Alloy Singleton
usernameFrom: ""
# -- The password to use for the remote config server.
# @section -- Collectors - Alloy Singleton
password: ""
# -- The key for storing the password in the secret.
# @section -- Collectors - Alloy Singleton
passwordKey: "password"
# -- Raw config for accessing the password.
# @section -- Collectors - Alloy Singleton
passwordFrom: ""
secret:
# -- Whether to create a secret for the remote config server.
# @section -- Collectors - Alloy Singleton
create: true
# -- If true, skip secret creation and embed the credentials directly into the configuration.
# @section -- Collectors - Alloy Singleton
embed: false
# -- The name of the secret to create.
# @section -- Collectors - Alloy Singleton
name: ""
# -- The namespace for the secret.
# @section -- Collectors - Alloy Singleton
namespace: ""
# -- The frequency at which to poll the remote config server for updates.
# @section -- Collectors - Alloy Singleton
pollFrequency: 5m
# -- Attributes to be added to this collector when requesting configuration.
# @section -- Collectors - Alloy Singleton
extraAttributes: {}
logging:
# -- Level at which Alloy log lines should be written.
# @section -- Collectors - Alloy Singleton
level: info
# -- Format to use for writing Alloy log lines.
# @section -- Collectors - Alloy Singleton
format: logfmt
liveDebugging:
# -- Enable live debugging for the Alloy instance.
# @section -- Collectors - Alloy Singleton
enabled: false
# @ignored
alloy:
# This chart is creating the configuration, so the alloy chart does not need to.
configMap: {create: false}
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]
add: ["CHOWN", "DAC_OVERRIDE", "FOWNER", "FSETID", "KILL", "SETGID", "SETUID", "SETPCAP", "NET_BIND_SERVICE", "NET_RAW", "SYS_CHROOT", "MKNOD", "AUDIT_WRITE", "SETFCAP"]
seccompProfile:
type: "RuntimeDefault"
# Set resource requests and limits. [Guidelines](https://grafana.com/docs/alloy/latest/introduction/estimate-resource-usage/).
# resources:
# requests: {}
# limits: {}
controller:
# -- The type of controller to use for the Alloy Singleton instance.
# @section -- Collectors - Alloy Singleton
type: deployment
# -- The number of replicas for the Alloy Singleton instance.
# This should remain a single instance to avoid duplicate data.
# @section -- Collectors - Alloy Singleton
replicas: 1
# @ignored
nodeSelector:
kubernetes.io/os: linux
# @ignored
podAnnotations:
k8s.grafana.com/logs.job: integrations/alloy
# Skip installation of the Grafana Alloy CRDs, since we don't use them in this chart
# @ignored
crds: {create: false}
# An Alloy instance for collecting log data.
# To see additional valid options, please see the [Alloy Helm chart documentation](https://github.com/grafana/alloy/tree/main/operations/helm/charts/alloy).
alloy-logs:
# -- Deploy the Alloy instance for collecting log data.
# @section -- Collectors - Alloy Logs
enabled: true
# -- Extra Alloy configuration to be added to the configuration file.
# @section -- Collectors - Alloy Logs
extraConfig: ""
# Remote configuration from a remote config server.
remoteConfig:
# -- Enable fetching configuration from a remote config server.
# @section -- Collectors - Alloy Logs
enabled: false
# -- The URL of the remote config server.
# @section -- Collectors - Alloy Logs
url: ""
# -- The proxy URL to use of the remote config server.
# @section -- Collectors - Alloy Logs
proxyURL: ""
auth:
# -- The type of authentication to use for the remote config server.
# @section -- Collectors - Alloy Logs
type: "none"
# -- The username to use for the remote config server.
# @section -- Collectors - Alloy Logs
username: ""
# -- The key for storing the username in the secret.
# @section -- Collectors - Alloy Logs
usernameKey: "username"
# -- Raw config for accessing the username.
# @section -- Collectors - Alloy Logs
usernameFrom: ""
# -- The password to use for the remote config server.
# @section -- Collectors - Alloy Logs
password: ""
# -- The key for storing the username in the secret.
# @section -- Collectors - Alloy Logs
passwordKey: "password"
# -- Raw config for accessing the password.
# @section -- Collectors - Alloy Logs
passwordFrom: ""
secret:
# -- Whether to create a secret for the remote config server.
# @section -- Collectors - Alloy Logs
create: true
# -- If true, skip secret creation and embed the credentials directly into the configuration.
# @section -- Collectors - Alloy Logs
embed: false
# -- The name of the secret to create.
# @section -- Collectors - Alloy Logs
name: ""
# -- The namespace for the secret.
# @section -- Collectors - Alloy Logs
namespace: ""
# -- The frequency at which to poll the remote config server for updates.
# @section -- Collectors - Alloy Logs
pollFrequency: 5m
# -- Attributes to be added to this collector when requesting configuration.
# @section -- Collectors - Alloy Logs
extraAttributes: {}
logging:
# -- Level at which Alloy log lines should be written.
# @section -- Collectors - Alloy Logs
level: info
# -- Format to use for writing Alloy log lines.
# @section -- Collectors - Alloy Logs
format: logfmt
liveDebugging:
# -- Enable live debugging for the Alloy instance.
# @section -- Collectors - Alloy Logs
enabled: false
# @ignored
alloy:
# This chart is creating the configuration, so the alloy chart does not need to.
configMap: {create: false}
# Disabling clustering by default, because the default log gathering format does not require clusters.
clustering: {enabled: false}
# @ignored
mounts:
# Mount /var/log from the host into the container for log collection.
varlog: true
# Mount /var/lib/docker/containers from the host into the container for log
# collection. Set to true if your cluster puts log files inside this directory.
dockercontainers: true
# @ignored
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]
add: ["CHOWN", "DAC_OVERRIDE", "FOWNER", "FSETID", "KILL", "SETGID", "SETUID", "SETPCAP", "NET_BIND_SERVICE", "NET_RAW", "SYS_CHROOT", "MKNOD", "AUDIT_WRITE", "SETFCAP"]
seccompProfile:
type: "RuntimeDefault"
# Set resource requests and limits. [Guidelines](https://grafana.com/docs/alloy/latest/introduction/estimate-resource-usage/).
# resources:
# requests: {}
# limits: {}
controller:
# -- The type of controller to use for the Alloy Logs instance.
# @section -- Collectors - Alloy Logs
type: daemonset
# @ignored
nodeSelector:
kubernetes.io/os: linux
# If this is not scheduled on every Node, then logs from Pods on that Node might not be collected.
# @ignored
tolerations:
- effect: NoSchedule
operator: Exists
# @ignored
podAnnotations:
k8s.grafana.com/logs.job: integrations/alloy
# Skip installation of the Grafana Alloy CRDs, since we don't use them in this chart
# @ignored
crds: {create: false}
# An Alloy instance for opening receivers to collect application data.
# To see additional valid options, please see the [Alloy Helm chart documentation](https://github.com/grafana/alloy/tree/main/operations/helm/charts/alloy).
alloy-receiver:
# -- Deploy the Alloy instance for opening receivers to collect application data.
# @section -- Collectors - Alloy Receiver
enabled: false
# -- Extra Alloy configuration to be added to the configuration file.
# @section -- Collectors - Alloy Receiver
extraConfig: ""
# Remote configuration from a remote config server.
remoteConfig:
# -- Enable fetching configuration from a remote config server.
# @section -- Collectors - Alloy Receiver
enabled: false
# -- The URL of the remote config server.
# @section -- Collectors - Alloy Receiver
url: ""
# -- The proxy URL to use of the remote config server.
# @section -- Collectors - Alloy Receiver
proxyURL: ""
auth:
# -- The type of authentication to use for the remote config server.
# @section -- Collectors - Alloy Receiver
type: "none"
# -- The username to use for the remote config server.
# @section -- Collectors - Alloy Receiver
username: ""
# -- The key for storing the username in the secret.
# @section -- Collectors - Alloy Receiver
usernameKey: "username"
# -- Raw config for accessing the username.
# @section -- Collectors - Alloy Receiver
usernameFrom: ""
# -- The password to use for the remote config server.
# @section -- Collectors - Alloy Receiver
password: ""
# -- The key for storing the password in the secret.
# @section -- Collectors - Alloy Receiver
passwordKey: "password"
# -- Raw config for accessing the password.
# @section -- Collectors - Alloy Receiver
passwordFrom: ""
secret:
# -- Whether to create a secret for the remote config server.
# @section -- Collectors - Alloy Receiver
create: true
# -- If true, skip secret creation and embed the credentials directly into the configuration.
# @section -- Collectors - Alloy Receiver
embed: false
# -- The name of the secret to create.
# @section -- Collectors - Alloy Receiver
name: ""
# -- The namespace for the secret.
# @section -- Collectors - Alloy Receiver
namespace: ""
# -- The frequency at which to poll the remote config server for updates.
# @section -- Collectors - Alloy Receiver
pollFrequency: 5m
# -- Attributes to be added to this collector when requesting configuration.
# @section -- Collectors - Alloy Receiver
extraAttributes: {}
logging:
# -- Level at which Alloy log lines should be written.
# @section -- Collectors - Alloy Receiver
level: info
# -- Format to use for writing Alloy log lines.
# @section -- Collectors - Alloy Receiver
format: logfmt
liveDebugging:
# -- Enable live debugging for the Alloy instance.
# @section -- Collectors - Alloy Receiver
enabled: false
alloy:
# -- The ports to expose for the Alloy receiver.
# @section -- Collectors - Alloy Receiver
extraPorts: []
# This chart is creating the configuration, so the alloy chart does not need to.
# @ignored
configMap: {create: false}
# @ignored
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]
add: ["CHOWN", "DAC_OVERRIDE", "FOWNER", "FSETID", "KILL", "SETGID", "SETUID", "SETPCAP", "NET_BIND_SERVICE", "NET_RAW", "SYS_CHROOT", "MKNOD", "AUDIT_WRITE", "SETFCAP"]
seccompProfile:
type: "RuntimeDefault"
# Set resource requests and limits. [Guidelines](https://grafana.com/docs/alloy/latest/introduction/estimate-resource-usage/).
# resources:
# requests: {}
# limits: {}
controller:
# -- The type of controller to use for the Alloy Receiver instance.
# @section -- Collectors - Alloy Receiver
type: daemonset
# @ignored
nodeSelector:
kubernetes.io/os: linux
# @ignored
podAnnotations:
k8s.grafana.com/logs.job: integrations/alloy
# Skip installation of the Grafana Alloy CRDs, since we don't use them in this chart
# @ignored
crds: {create: false}
extraService:
# -- Create an extra service for the Alloy receiver. This service will mirror the alloy-receiver service, but its
# name can be customized to match existing application settings.
# @section -- Collectors - Alloy Receiver
enabled: false
# -- The name of the extra service to create. This will result in the format `<release-name>-<name>`.
# @section -- Collectors - Alloy Receiver
name: alloy
# -- If set, the full name of the extra service to create. This will result in the format `<fullname>`.
# @section -- Collectors - Alloy Receiver
fullname: ""
# An Alloy instance for gathering profiles.
# To see additional valid options, please see the [Alloy Helm chart documentation](https://github.com/grafana/alloy/tree/main/operations/helm/charts/alloy).
alloy-profiles:
# -- Deploy the Alloy instance for gathering profiles.
# @section -- Collectors - Alloy Profiles
enabled: false
# -- Extra Alloy configuration to be added to the configuration file.
# @section -- Collectors - Alloy Profiles
extraConfig: ""
# Remote configuration from a remote config server.
remoteConfig:
# -- Enable fetching configuration from a remote config server.
# @section -- Collectors - Alloy Profiles
enabled: false
# -- The URL of the remote config server.
# @section -- Collectors - Alloy Profiles
url: ""
# -- The proxy URL to use of the remote config server.
# @section -- Collectors - Alloy Profiles
proxyURL: ""
auth:
# -- The type of authentication to use for the remote config server.
# @section -- Collectors - Alloy Profiles
type: "none"
# -- The username to use for the remote config server.
# @section -- Collectors - Alloy Profiles
username: ""
# -- The key for storing the username in the secret.
# @section -- Collectors - Alloy Profiles
usernameKey: "username"
# -- Raw config for accessing the username.
# @section -- Collectors - Alloy Profiles
usernameFrom: ""
# -- The password to use for the remote config server.
# @section -- Collectors - Alloy Profiles
password: ""
# -- The key for storing the password in the secret.
# @section -- Collectors - Alloy Profiles
passwordKey: "password"
# -- Raw config for accessing the password.
# @section -- Collectors - Alloy Profiles
passwordFrom: ""
secret:
# -- Whether to create a secret for the remote config server.
# @section -- Collectors - Alloy Profiles
create: true
# -- If true, skip secret creation and embed the credentials directly into the configuration.
# @section -- Collectors - Alloy Profiles
embed: false
# -- The name of the secret to create.
# @section -- Collectors - Alloy Profiles
name: ""
# -- The namespace for the secret.
# @section -- Collectors - Alloy Profiles
namespace: ""
# -- The frequency at which to poll the remote config server for updates.
# @section -- Collectors - Alloy Profiles
pollFrequency: 5m
# -- Attributes to be added to this collector when requesting configuration.
# @section -- Collectors - Alloy Profiles
extraAttributes: {}
logging:
# -- Level at which Alloy log lines should be written.
# @section -- Collectors - Alloy Profiles
level: info
# -- Format to use for writing Alloy log lines.
# @section -- Collectors - Alloy Profiles
format: logfmt
liveDebugging:
# -- Enable live debugging for the Alloy instance.
# @section -- Collectors - Alloy Profiles
enabled: false
# @ignored
alloy:
# Pyroscope components are currently in public preview
stabilityLevel: public-preview
# This chart is creating the configuration, so the alloy chart does not need to.
configMap: {create: false}
# Disabling clustering because each instance will gather profiles for the workloads on the same node.
clustering:
name: alloy-profiles
enabled: false
securityContext:
privileged: true
runAsGroup: 0
runAsUser: 0
# Set resource requests and limits. [Guidelines](https://grafana.com/docs/alloy/latest/introduction/estimate-resource-usage/).
# resources:
# requests: {}
# limits: {}
controller:
# -- The type of controller to use for the Alloy Profiles instance.
# @section -- Collectors - Alloy Profiles
type: daemonset
# @ignored
hostPID: true
# @ignored
nodeSelector:
kubernetes.io/os: linux
# @ignored
podAnnotations:
k8s.grafana.com/logs.job: integrations/alloy
# @ignored
tolerations:
- effect: NoSchedule
operator: Exists
# Skip installation of the Grafana Alloy CRDs, since we don't use them in this chart
# @ignored
crds: {create: false}
# -- Deploy additional manifest objects
extraObjects: []
# - apiVersion: external-secrets.io/v1beta1
# kind: ExternalSecret
# metadata:
# name: prometheus-secret
# spec:
# refreshInterval: 1h
# secretStoreRef:
# kind: SecretStore
# name: example
# target:
# template:
# data:
# prometheus_host: "{{ .Values.externalServices.prometheus.host }}"
# username: "{{`{{ .username }}`}}"
# password: "{{`{{ .password }}`}}"
# dataFrom:
# - extract:
# key: mysecret