v-m: Deploy (clustered) Victoria Metrics

Since *mtrcs0.pyrocufflink.blue* (the Metrics Pi) seems to be dying,
I decided to move monitoring and alerting into Kubernetes.

I was originally planning to have a single, dedicated virtual machine
for Victoria Metrics and Grafana, similar to how the Metrics Pi was set
up, but running Fedora CoreOS instead of a custom Buildroot-based OS.
While I was working on the Ignition configuration for the VM, it
occurred to me that monitoring would be interrupted frequently, since
FCOS updates weekly and all updates require a reboot.  I would rather
not have that many gaps in the data.  Ultimately I decided that
deploying a cluster with Kubernetes would probably be more robust and
reliable, as updates can be performed without any downtime at all.

I chose not to use the Victoria Metrics Operator, but rather handle
the resource definitions myself.  Victoria Metrics components are not
particularly difficult to deploy, so the overhead of running the
operator and using its custom resources would not be worth the minor
convenience it provides.
This commit is contained in:
2024-01-01 15:23:14 -06:00
parent 8c605d0f9f
commit 8f088fb6ae
17 changed files with 1474 additions and 0 deletions

View File

@@ -0,0 +1,88 @@
apiVersion: v1
kind: Service
metadata:
name: vmalert
labels:
app.kubernetes.io/name: vmalert
app.kubernetes.io/component: vmalert
spec:
ports:
- port: 8880
name: vmalert
selector:
app.kubernetes.io/name: vmalert
app.kubernetes.io/component: vmalert
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: vmalert
labels:
app.kubernetes.io/name: vmalert
app.kubernetes.io/component: vmalert
spec:
selector:
matchLabels:
app.kubernetes.io/name: vmalert
app.kubernetes.io/component: vmalert
template:
metadata:
labels:
app.kubernetes.io/name: vmalert
app.kubernetes.io/component: vmalert
spec:
containers:
- name: vmalert
image: docker.io/victoriametrics/vmalert:v1.96.0
args:
- -envflag.enable=true
- -envflag.prefix=vmalert_
- -httpListenAddr=0.0.0.0:8880
- -configCheckInterval=30s
env:
- name: vmalert_rule
value: /rules/*.yml
- name: vmalert_datasource_url
value: http://vmselect:8481/select/1/prometheus
- name: vmalert_remoteread_url
value: http://vmselect:8481/select/1/prometheus
- name: vmalert_remorewrite_url
value: http://vminsert:8480/select/1/prometheus
- name: vmalert_notifier_url
value: http://alertmanager:9093
ports:
- containerPort: 8880
name: http
readinessProbe: &probe
httpGet:
port: http
path: /health
periodSeconds: 60
startupProbe:
<<: *probe
periodSeconds: 1
successThreshold: 1
failureThreshold: 30
timeoutSeconds: 1
securityContext:
runAsNonRoot: true
readOnlyRootFilesystem: true
volumeMounts:
- mountPath: /rules
name: rules
readOnly: true
- mountPath: /tmp
name: tmp
subPath: tmp
securityContext:
runAsGroup: 2093
runAsNonRoot: true
runAsUser: 2093
volumes:
- name: rules
configMap:
name: vmalert-rules
optional: true
- name: tmp
emptyDir: {}