-
-
Notifications
You must be signed in to change notification settings - Fork 56
Expand file tree
/
Copy pathvalues.yaml
More file actions
220 lines (193 loc) · 6.6 KB
/
Copy pathvalues.yaml
File metadata and controls
220 lines (193 loc) · 6.6 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
# -- Provide a name in place of `ntp-exporter`
nameOverride: ""
# -- String to fully override `"ntp-exporter.fullname"`
fullnameOverride: ""
image:
# -- image registry
registry: ghcr.io
# -- image repository
repository: sapcc/ntp_exporter
# -- image pull policy
pullPolicy: Always
# -- Overrides the image tag
tag: "v2.9.0"
# -- If defined, uses a Secret to pull an image from a private Docker registry or repository.
imagePullSecrets: []
serviceAccount:
# -- Specifies whether a service account should be created
create: true
# -- Annotations to add to the service account
annotations: {}
# -- The name of the service account to use.
# If not set and create is true, a name is generated using the fullname template
name: ""
# -- Annotations to be added to pods
podAnnotations: {}
# -- pod-level security context
# @default -- see [values.yaml](./values.yaml)
podSecurityContext:
fsGroup: 4200
# -- container-level security context
# @default -- see [values.yaml](./values.yaml)
securityContext:
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsGroup: 4200
runAsUser: 4200
service:
# -- Kubernetes service type
type: ClusterIP
# -- Kubernetes port where service is exposed
port: 80
ingress:
enabled: false
className: ""
annotations: {}
# kubernetes.io/ingress.class: nginx
# kubernetes.io/tls-acme: "true"
hosts:
- host: chart-example.local
paths:
- path: /
pathType: ImplementationSpecific
tls: []
# - secretName: chart-example-tls
# hosts:
# - chart-example.local
# BETA: Configure the gateway routes for the chart here.
# More routes can be added by adding a dictionary key like the 'main' route.
# Being BETA this can/will change in the future without notice, do not use unless you want to take that risk
# [[ref]](https://gateway-api.sigs.k8s.io/references/spec/#gateway.networking.k8s.io%2fv1alpha2)
route:
main:
# -- Enables or disables the route
enabled: false
# -- Set the route apiVersion, e.g. gateway.networking.k8s.io/v1 or gateway.networking.k8s.io/v1alpha2
apiVersion: gateway.networking.k8s.io/v1
# -- Set the route kind
# Valid options are GRPCRoute, HTTPRoute, TCPRoute, TLSRoute, UDPRoute
kind: HTTPRoute
# -- Add annotations to the route
annotations: {}
# -- Add labels to the route
labels: {}
# -- Hostnames to be matched
hostnames: []
# - my-filter.example.com
# -- Parent references (Gateway)
parentRefs: []
# - name: acme-gw
# -- define conditions used for matching the rule against incoming HTTP requests.
# @default -- see [values.yaml](./values.yaml)
matches:
- path:
type: PathPrefix
value: /
# -- Filters define the filters that are applied to requests that match this rule.
filters: []
# -- Additional custom rules that can be added to the route
additionalRules: []
# -- adds a filter for redirecting to https (HTTP 301 Moved Permanently). To redirect HTTP traffic to HTTPS, you need to have a Gateway with both HTTP and HTTPS listeners. Matches and filters do not take effect if enabled. Ref. https://gateway-api.sigs.k8s.io/guides/http-redirect-rewrite/
httpsRedirect: false
# -- defines the timeouts that can be configured for an HTTP request
timeouts: {}
# -- Resource limits and requests for the headwind pods.
# @default -- see [values.yaml](./values.yaml)
resources:
requests:
cpu: 10m
memory: 32Mi
limits:
cpu: 100m
memory: 128Mi
# -- Node labels for pod assignment
nodeSelector: {}
# -- Toleration labels for pod assignment
# @default -- see [values.yaml](./values.yaml)
tolerations:
- key: "node-role.kubernetes.io/control-plane"
operator: "Exists"
effect: "NoSchedule"
# -- Affinity settings for pod assignment
affinity: {}
ntp:
config:
# -- High drift threshold
highDriftThreshold: "10ms"
# -- Duration of measurements in case of high (>10ms) drift
measurementDuration: 30s
# -- NTP protocol version to use
protocolVersion: "4"
exporter:
# -- Path under which to expose metrics
path: /metrics
# -- The port the exporter will listen on
port: 9559
# -- NTP server to query for time
server: ""
# -- source of information about ntp server. Valid options are cli and http
source: "cli"
podMonitor:
# -- Enable a prometheus PodMonitor
enabled: false
# -- Prometheus PodMonitor labels
additionalLabels: {}
# release: prometheus
# -- Prometheus PodMonitor selector
selector: {}
# prometheus: kube-prometheus
# -- Prometheus PodMonitor interval
interval: 30s
# -- Prometheus PodMonitor namespace
namespace: ""
# -- Prometheus [MetricRelabelConfigs] to apply to samples before ingestion
metricRelabelings: []
# -- Prometheus [RelabelConfigs] to apply to samples before scraping
# @default -- see [values.yaml](./values.yaml)
# -- Prometheus PodMonitor scrapeTimeout, cannot be longer than the scrape interval
scrapeTimeout: ""
relabelings:
- action: replace
sourceLabels: [__meta_kubernetes_pod_node_name]
targetLabel: node
## Custom PrometheusRule to be defined
## ref: https://github.com/coreos/prometheus-operator#customresourcedefinitions
prometheusRule:
# -- Enable a PrometheusRule
enabled: false
defaultRules:
# -- Enable the default rules that alert on clock drift and metrics absence
enabled: true
absence:
# -- Enable the rule that alerts if no metrics are scraped from ntp-exporter
enabled: true
# -- The rule definition for clock drift alerting
# @default -- see [values.yaml](./values.yaml) for definition
rule:
alert: KubernetesNodeNTPMetricsDown
expr: absent(ntp_drift_seconds)
for: 1h
labels:
severity: warning
annotations:
summary: NTP drift metrics absent
description: The NTP drift metrics are missing for node {{`{{ $labels.node }}`}}. Check NTP exporter pod logs and connectifity to NTP servers.
clockDrift:
# -- Enable the rule that alerts on high clock drift
enabled: true
# -- The rule definition for clock drift alerting
# @default -- see [values.yaml](./values.yaml) for definition
rule:
alert: KubernetesNodeNTPClockDrift
expr: abs(ntp_drift_seconds) > 0.1
for: 1h
annotations:
summary: High NTP drift
description: The local clock on node {{`{{ $labels.node }}`}} is more than 100ms apart from its NTP server. This can cause service degradation.
labels:
severity: warning
# -- List of additional rules
rules: []