Files
homelab-infra/platform/observability/grafana/values.yaml
T
panxiao81 47042d4df4
yaml / yaml (push) Successful in 20s
ansible / collection-test (push) Successful in 1m10s
ansible / lint (push) Successful in 13m9s
完善内存监控并迁移 Grafana 内网入口
Co-authored-by: panxiao81 <[email protected]>
2026-09-16 12:47:52 +00:00

99 lines
3.5 KiB
YAML

# Grafana — single pane over metrics (VictoriaMetrics), logs (VictoriaLogs) and
# traces (VictoriaTraces via Jaeger API). LAN: grafana.ad.ddupan.top,
# authenticated via Authelia OIDC. Local admin is
# break-glass only.
#
# Chart: grafana/grafana (repo: https://grafana.github.io/helm-charts)
# --- VictoriaLogs needs its Grafana datasource plugin ---
plugins:
- victoriametrics-logs-datasource
# --- Dashboard sidecar: auto-loads any ConfigMap labeled grafana_dashboard=1 in the
# namespace. Migrated boards live in ./dashboards and are applied by ./dashboards/apply.sh ---
sidecar:
dashboards:
enabled: true
label: grafana_dashboard
labelValue: "1"
folderAnnotation: grafana_folder
provider:
foldersFromFilesStructure: true
# --- Provisioned datasources ---
datasources:
datasources.yaml:
apiVersion: 1
datasources:
- name: VictoriaMetrics
type: prometheus
access: proxy
url: http://vmsingle-main.monitoring.svc:8428
isDefault: true
jsonData:
prometheusType: Prometheus
- name: VictoriaLogs
type: victoriametrics-logs-datasource
access: proxy
url: http://vlsingle-main.monitoring.svc:9428
- name: VictoriaTraces
type: jaeger
access: proxy
# VictoriaTraces (VTSingle CR) exposes a Jaeger-compatible query API under /select/jaeger.
url: http://vtsingle-main.monitoring.svc:10428/select/jaeger
# --- Persistence on OpenEBS ZFS ---
persistence:
enabled: true
storageClassName: localpv-zfs-ceph
size: 5Gi
# localpv-zfs-ceph cannot mount the same RWO volume into the old and new Grafana
# Pods concurrently. RollingUpdate leaves the old Pod serving while the new Pod
# blocks forever in verifyMount, so upgrades must stop the old Pod first.
deploymentStrategy:
type: Recreate
# 内网入口由 httproute.yaml 接入 Envoy,使用现有通配 TLS 证书。
# 客户端通过既有内网 DNS 转发解析,无需独立 Tailscale Ingress。
ingress:
enabled: false
# --- OIDC via Authelia (AD groups -> Grafana roles) ---
# client_secret is injected from the grafana-oidc Secret (see oidc-secret.yaml),
# which overrides any value in grafana.ini.
envValueFrom:
GF_AUTH_GENERIC_OAUTH_CLIENT_SECRET:
secretKeyRef:
name: grafana-oidc
key: client_secret
grafana.ini:
server:
root_url: "https://grafana.ad.ddupan.top" # 与 Authelia redirect_uri 一致
auth:
# Keep the local admin login available as break-glass; don't force OIDC-only.
disable_login_form: false
oauth_auto_login: false
auth.generic_oauth:
enabled: true
name: Authelia
client_id: grafana
scopes: "openid profile email groups"
auth_url: "https://auth.ddupan.top/api/oidc/authorization"
token_url: "https://auth.ddupan.top/api/oidc/token"
api_url: "https://auth.ddupan.top/api/oidc/userinfo"
login_attribute_path: preferred_username
name_attribute_path: name
email_attribute_path: email
groups_attribute_path: groups
# AD "Enterprise Admins" -> full Grafana server admin; "Domain Admins" -> org Admin;
# everyone else who can authenticate -> Viewer. Tune group names to taste.
role_attribute_path: "contains(groups[*], 'Enterprise Admins') && 'GrafanaAdmin' || contains(groups[*], 'Domain Admins') && 'Admin' || 'Viewer'"
allow_assign_grafana_admin: true
role_attribute_strict: false
use_pkce: true
# Dashboards are loaded by the sidecar (above) from ConfigMaps created by
# ./dashboards/apply.sh. Drop more JSON into ./dashboards and re-run that script.