From 05511992e9cc5b9fdd5c3ba59e30704d78fadda3 Mon Sep 17 00:00:00 2001 From: Rodrigue Koffi Date: Tue, 30 Aug 2022 19:59:34 +0200 Subject: [PATCH] Chore --- README.md | 18 +-- .../README.md | 11 +- .../main.tf | 9 +- .../variables.tf | 22 ++-- examples/new-cluster-with-base/main.tf | 110 ------------------ locals.tf | 2 - modules/add-ons/adot-operator/README.md | 2 +- modules/workloads/infra/README.md | 38 +----- .../workloads/infra/dashboards/apiserver.json | 2 +- .../infra/dashboards/cluster-networking.json | 2 +- .../workloads/infra/dashboards/cluster.json | 2 +- .../infra/dashboards/controller.json | 2 +- .../workloads/infra/dashboards/coredns.json | 2 +- modules/workloads/infra/dashboards/etcd.json | 2 +- .../workloads/infra/dashboards/kubelet.json | 2 +- .../dashboards/namespace-networking.json | 2 +- .../dashboards/namespace-nw-workloads.json | 2 +- .../infra/dashboards/namespace-pods.json | 2 +- .../infra/dashboards/namespace-workloads.json | 2 +- .../dashboards/networking-workloads.json | 2 +- .../infra/dashboards/nodeexporter-nodes.json | 2 +- .../dashboards/nodeexporter-use-node.json | 2 +- .../dashboards/nodeexpoter-use-cluster.json | 2 +- modules/workloads/infra/dashboards/nodes.json | 2 +- .../infra/dashboards/pesistentvolumes.json | 2 +- .../infra/dashboards/pods-networking.json | 2 +- modules/workloads/infra/dashboards/pods.json | 2 +- modules/workloads/infra/dashboards/proxy.json | 2 +- .../workloads/infra/dashboards/scheduler.json | 2 +- .../workloads/infra/dashboards/workloads.json | 2 +- .../templates/opentelemetrycollector.yaml | 30 ++--- modules/workloads/infra/rules.tf | 2 +- modules/workloads/java/README.md | 52 +++++++++ variables.tf | 33 +++--- 34 files changed, 144 insertions(+), 229 deletions(-) delete mode 100644 examples/new-cluster-with-base/main.tf create mode 100644 modules/workloads/java/README.md diff --git a/README.md b/README.md index b214640..14f0db0 100644 --- a/README.md +++ b/README.md @@ -68,18 +68,18 @@ Welcome to AWS Observability Accelerator for Terraform! |------|-------------|------|---------|:--------:| | [aws\_region](#input\_aws\_region) | AWS Region | `string` | n/a | yes | | [eks\_cluster\_id](#input\_eks\_cluster\_id) | EKS Cluster Id | `string` | n/a | yes | -| [enable\_alertmanager](#input\_enable\_alertmanager) | Create AMP AlertManager for all workloads | `bool` | `false` | no | -| [enable\_amazon\_eks\_adot](#input\_enable\_amazon\_eks\_adot) | n/a | `bool` | `true` | no | +| [enable\_alertmanager](#input\_enable\_alertmanager) | Creates AMP AlertManager for all workloads | `bool` | `false` | no | +| [enable\_amazon\_eks\_adot](#input\_enable\_amazon\_eks\_adot) | Enables the ADOT Operator on the EKS Cluster | `bool` | `true` | no | | [enable\_cert\_manager](#input\_enable\_cert\_manager) | Allow reusing an existing installation of cert-manager | `bool` | `true` | no | -| [enable\_managed\_grafana](#input\_enable\_managed\_grafana) | n/a | `bool` | `true` | no | -| [enable\_managed\_prometheus](#input\_enable\_managed\_prometheus) | n/a | `bool` | `true` | no | -| [grafana\_api\_key](#input\_grafana\_api\_key) | n/a | `string` | `null` | no | +| [enable\_managed\_grafana](#input\_enable\_managed\_grafana) | Creates a new Amazon Managed Grafana (AMG) Workspace | `bool` | `true` | no | +| [enable\_managed\_prometheus](#input\_enable\_managed\_prometheus) | Creates a new AMP workspace | `bool` | `true` | no | +| [grafana\_api\_key](#input\_grafana\_api\_key) | Grafana API key for the AMG workspace | `string` | `null` | no | | [irsa\_iam\_permissions\_boundary](#input\_irsa\_iam\_permissions\_boundary) | IAM permissions boundary for IRSA roles | `string` | `""` | no | | [irsa\_iam\_role\_path](#input\_irsa\_iam\_role\_path) | IAM role path for IRSA roles | `string` | `"/"` | no | -| [managed\_grafana\_region](#input\_managed\_grafana\_region) | AWS Managed Grafana Workspace Region | `string` | `null` | no | -| [managed\_grafana\_workspace\_id](#input\_managed\_grafana\_workspace\_id) | n/a | `string` | `""` | no | -| [managed\_prometheus\_workspace\_id](#input\_managed\_prometheus\_workspace\_id) | AWS Managed Prometheus Workspace ID | `string` | `""` | no | -| [managed\_prometheus\_workspace\_region](#input\_managed\_prometheus\_workspace\_region) | AWS Managed Prometheus Workspace Region | `string` | `null` | no | +| [managed\_grafana\_region](#input\_managed\_grafana\_region) | Region where AMG is deployed | `string` | `null` | no | +| [managed\_grafana\_workspace\_id](#input\_managed\_grafana\_workspace\_id) | AMG Workspace ID | `string` | `""` | no | +| [managed\_prometheus\_workspace\_id](#input\_managed\_prometheus\_workspace\_id) | AMP Workspace ID | `string` | `""` | no | +| [managed\_prometheus\_workspace\_region](#input\_managed\_prometheus\_workspace\_region) | Region where AMP is deployed | `string` | `null` | no | | [tags](#input\_tags) | Additional tags (e.g. `map('BusinessUnit`,`XYZ`) | `map(string)` | `{}` | no | ## Outputs diff --git a/examples/existing-cluster-with-base-and-infra/README.md b/examples/existing-cluster-with-base-and-infra/README.md index 1d1ec8f..59ddecc 100644 --- a/examples/existing-cluster-with-base-and-infra/README.md +++ b/examples/existing-cluster-with-base-and-infra/README.md @@ -59,7 +59,6 @@ If you don't specify anything a new workspace will be created for you. 5. Grafana API Key - - Give admin access to the SSO user you set up when creating the Amazon Managed Grafana Workspace: - In the AWS Console, navigate to Amazon Grafana. In the left navigation bar, click **All workspaces**, then click on the workspace name you are using for this example. @@ -131,11 +130,11 @@ add this `managed_prometheus_region=xxx` and `managed_prometheus_workspace_id=ws | [aws\_region](#input\_aws\_region) | AWS Region | `string` | n/a | yes | | [eks\_cluster\_id](#input\_eks\_cluster\_id) | EKS Cluster Id | `string` | n/a | yes | | [grafana\_api\_key](#input\_grafana\_api\_key) | API key for authorizing the Grafana provider to make changes to Amazon Managed Grafana | `string` | `""` | no | -| [grafana\_endpoint](#input\_grafana\_endpoint) | Grafana endpoint | `string` | `null` | no | -| [managed\_grafana\_workspace\_id](#input\_managed\_grafana\_workspace\_id) | n/a | `string` | `""` | no | -| [managed\_prometheus\_endpoint](#input\_managed\_prometheus\_endpoint) | n/a | `string` | `""` | no | -| [managed\_prometheus\_region](#input\_managed\_prometheus\_region) | n/a | `string` | `""` | no | -| [managed\_prometheus\_workspace\_id](#input\_managed\_prometheus\_workspace\_id) | n/a | `string` | `""` | no | +| [grafana\_endpoint](#input\_grafana\_endpoint) | AMG endpoint | `string` | `null` | no | +| [managed\_grafana\_workspace\_id](#input\_managed\_grafana\_workspace\_id) | Amazon Managed Grafana (AMG) workspace ID | `string` | `""` | no | +| [managed\_prometheus\_endpoint](#input\_managed\_prometheus\_endpoint) | AMP workspace ID | `string` | `""` | no | +| [managed\_prometheus\_region](#input\_managed\_prometheus\_region) | Region where AMP is deployed | `string` | `""` | no | +| [managed\_prometheus\_workspace\_id](#input\_managed\_prometheus\_workspace\_id) | Amazon Managed Service for Prometheus (AMP) workspace ID | `string` | `""` | no | ## Outputs diff --git a/examples/existing-cluster-with-base-and-infra/main.tf b/examples/existing-cluster-with-base-and-infra/main.tf index cd37640..b9a3e2f 100644 --- a/examples/existing-cluster-with-base-and-infra/main.tf +++ b/examples/existing-cluster-with-base-and-infra/main.tf @@ -81,11 +81,9 @@ module "eks_observability_accelerator" { # https://www.terraform.io/language/modules/develop/providers # A module intended to be called by one or more other modules must not contain # any provider blocks. -# This allows forcing depedency between base and workloads module +# This allows forcing dependency between base and workloads module provider "grafana" { - url = module.eks_observability_accelerator.managed_grafana_workspace_endpoint - - # TODO: manage with Secrets manager + url = module.eks_observability_accelerator.managed_grafana_workspace_endpoint auth = var.grafana_api_key } @@ -98,13 +96,10 @@ module "workloads_infra" { dashboards_folder_id = module.eks_observability_accelerator.grafana_dashboards_folder_id managed_prometheus_workspace_id = module.eks_observability_accelerator.managed_prometheus_workspace_id - # TODO remove when Kevin's PR is live managed_prometheus_workspace_endpoint = module.eks_observability_accelerator.managed_prometheus_workspace_endpoint managed_prometheus_workspace_region = module.eks_observability_accelerator.managed_prometheus_workspace_region enable_alerting_rules = false - # module custom configuration, check module documentation - # config = {} tags = local.tags diff --git a/examples/existing-cluster-with-base-and-infra/variables.tf b/examples/existing-cluster-with-base-and-infra/variables.tf index 43bf420..d89a6ef 100644 --- a/examples/existing-cluster-with-base-and-infra/variables.tf +++ b/examples/existing-cluster-with-base-and-infra/variables.tf @@ -7,23 +7,27 @@ variable "aws_region" { type = string } variable "managed_prometheus_workspace_id" { - type = string - default = "" + description = "Amazon Managed Service for Prometheus (AMP) workspace ID" + type = string + default = "" } variable "managed_prometheus_endpoint" { - type = string - default = "" + description = "AMP workspace ID" + type = string + default = "" } variable "managed_prometheus_region" { - type = string - default = "" + description = "Region where AMP is deployed" + type = string + default = "" } variable "managed_grafana_workspace_id" { - type = string - default = "" + description = "Amazon Managed Grafana (AMG) workspace ID" + type = string + default = "" } variable "grafana_endpoint" { - description = "Grafana endpoint" + description = "AMG endpoint" type = string default = null } diff --git a/examples/new-cluster-with-base/main.tf b/examples/new-cluster-with-base/main.tf deleted file mode 100644 index d566af4..0000000 --- a/examples/new-cluster-with-base/main.tf +++ /dev/null @@ -1,110 +0,0 @@ -provider "aws" { - region = local.region -} - -provider "kubernetes" { - host = module.eks_blueprints.eks_cluster_endpoint - cluster_ca_certificate = base64decode(module.eks_blueprints.eks_cluster_certificate_authority_data) - token = data.aws_eks_cluster_auth.this.token -} - -provider "helm" { - kubernetes { - host = module.eks_blueprints.eks_cluster_endpoint - cluster_ca_certificate = base64decode(module.eks_blueprints.eks_cluster_certificate_authority_data) - token = data.aws_eks_cluster_auth.this.token - } -} - -module "vpc" { - source = "terraform-aws-modules/vpc/aws" - version = "~> 3.0" - - name = local.name - cidr = local.vpc_cidr - - azs = local.azs - public_subnets = [for k, v in local.azs : cidrsubnet(local.vpc_cidr, 8, k)] - private_subnets = [for k, v in local.azs : cidrsubnet(local.vpc_cidr, 8, k + 10)] - - enable_nat_gateway = true - single_nat_gateway = true - enable_dns_hostnames = true - - # Manage so we can name - manage_default_network_acl = true - default_network_acl_tags = { Name = "${local.name}-default" } - manage_default_route_table = true - default_route_table_tags = { Name = "${local.name}-default" } - manage_default_security_group = true - default_security_group_tags = { Name = "${local.name}-default" } - - public_subnet_tags = { - "kubernetes.io/cluster/${local.name}" = "shared" - "kubernetes.io/role/elb" = 1 - } - - private_subnet_tags = { - "kubernetes.io/cluster/${local.name}" = "shared" - "kubernetes.io/role/internal-elb" = 1 - } - - tags = local.tags -} - -module "eks_blueprints" { - source = "github.com/aws-ia/terraform-aws-eks-blueprints" - - cluster_name = local.name - cluster_version = "1.22" - - vpc_id = module.vpc.vpc_id - private_subnet_ids = module.vpc.private_subnets - - managed_node_groups = { - t3_l = { - node_group_name = "managed-ondemand" - instance_types = ["t3.large"] - min_size = 2 - subnet_ids = module.vpc.private_subnets - } - } - - tags = local.tags -} - - -module "observability_accelerator" { - source = "../../" - - aws_region = local.region - eks_cluster_id = module.eks_blueprints.eks_cluster_id - - enable_alertmanager = true - enable_managed_grafana = false - - managed_grafana_workspace_id = var.managed_grafana_workspace_id - managed_grafana_region = var.managed_grafana_region - - grafana_api_key = var.grafana_api_key - - tags = { - Source = "aws-observability-accelerator" - } -} - -module "infra" { - source = "../../modules/workloads/infra" - - dashboards_folder_id = module.observability_accelerator.dashboards_folder_id - eks_cluster_id = module.eks_blueprints.eks_cluster_id - enable_alerting_rules = false - - managed_prometheus_workspace_id = module.observability_accelerator.managed_prometheus_workspace_id - managed_prometheus_workspace_region = module.observability_accelerator.managed_prometheus_workspace_region - - tags = { - Source = "aws-observability-accelerator" - } -} - diff --git a/locals.tf b/locals.tf index 10d67eb..a261ae0 100644 --- a/locals.tf +++ b/locals.tf @@ -31,8 +31,6 @@ locals { amg_ws_endpoint = var.managed_grafana_workspace_id == "" ? "https://${module.managed_grafana[0].workspace_endpoint}" : "https://${data.aws_grafana_workspace.this[0].endpoint}" amg_ws_id = var.managed_grafana_workspace_id == "" ? module.managed_grafana[0].workspace_ : data.aws_grafana_workspace.this[0].endpoint - # TODO when tf resource for AMG api keys are supported - # create a short-lived api key on the fly if api_key is not provided amg_api_key = var.grafana_api_key context = { diff --git a/modules/add-ons/adot-operator/README.md b/modules/add-ons/adot-operator/README.md index 9e12cf4..70884c4 100644 --- a/modules/add-ons/adot-operator/README.md +++ b/modules/add-ons/adot-operator/README.md @@ -41,7 +41,7 @@ the ADOT Operator. | Name | Source | Version | |------|--------|---------| -| [cert\_manager](#module\_cert\_manager) | github.com/aws-observability/terraform-aws-eks-blueprints/modules/kubernetes-addons/cert-manager | n/a | +| [cert\_manager](#module\_cert\_manager) | github.com/aws-ia/terraform-aws-eks-blueprints/modules/kubernetes-addons/cert-manager | n/a | ## Resources diff --git a/modules/workloads/infra/README.md b/modules/workloads/infra/README.md index 1ffb82e..4eba836 100644 --- a/modules/workloads/infra/README.md +++ b/modules/workloads/infra/README.md @@ -1,7 +1,6 @@ -# Observability Pattern for Java/JMX +# Infrastructure monitoring -This module provides an automated experience around Observability for Nginx workloads. -It provides the following resources: +This module provides EKS cluster monitoring with the following resources: - AWS Distro For OpenTelemetry Operator and Collector - AWS Managed Grafana Dashboard and data source @@ -26,47 +25,21 @@ It provides the following resources: | Name | Source | Version | |------|--------|---------| -| [helm\_addon](#module\_helm\_addon) | github.com/aws-observability/terraform-aws-eks-blueprints/modules/kubernetes-addons/helm-addon | n/a | +| [helm\_addon](#module\_helm\_addon) | github.com/aws-ia/terraform-aws-eks-blueprints/modules/kubernetes-addons/helm-addon | n/a | ## Resources | Name | Type | |------|------| -| [aws_prometheus_rule_group_namespace.api-availability](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [aws_prometheus_rule_group_namespace.apibr](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [aws_prometheus_rule_group_namespace.apihg](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [aws_prometheus_rule_group_namespace.apislos](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [aws_prometheus_rule_group_namespace.etcd](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [aws_prometheus_rule_group_namespace.generic](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [aws_prometheus_rule_group_namespace.kubeapps](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [aws_prometheus_rule_group_namespace.kubelet](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [aws_prometheus_rule_group_namespace.kubeprom-recording](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [aws_prometheus_rule_group_namespace.kubepromnr](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [aws_prometheus_rule_group_namespace.kuberesources](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [aws_prometheus_rule_group_namespace.kubescheduler](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [aws_prometheus_rule_group_namespace.kubestm](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [aws_prometheus_rule_group_namespace.kubestorage](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [aws_prometheus_rule_group_namespace.kubesys](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [aws_prometheus_rule_group_namespace.kubesysapi](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [aws_prometheus_rule_group_namespace.kubesyschdlr](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [aws_prometheus_rule_group_namespace.kubesyscm](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [aws_prometheus_rule_group_namespace.kubesyskblt](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [aws_prometheus_rule_group_namespace.kubesyskbpxy](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [aws_prometheus_rule_group_namespace.kubprom](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [aws_prometheus_rule_group_namespace.ne](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [aws_prometheus_rule_group_namespace.nodeexporter](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [aws_prometheus_rule_group_namespace.nodenw](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [aws_prometheus_rule_group_namespace.noderules](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | -| [grafana_dashboard.alertmanager](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [aws_prometheus_rule_group_namespace.alerting_rules](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | +| [aws_prometheus_rule_group_namespace.recording_rules](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | | [grafana_dashboard.apis](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | | [grafana_dashboard.cluster](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | | [grafana_dashboard.clusternw](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | | [grafana_dashboard.controller](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | | [grafana_dashboard.coredns](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | | [grafana_dashboard.etcd](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | -| [grafana_dashboard.grafana](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | | [grafana_dashboard.kubelet](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | -| [grafana_dashboard.macos](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | | [grafana_dashboard.necluster](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | | [grafana_dashboard.nenode](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | | [grafana_dashboard.nenodeuse](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | @@ -78,7 +51,6 @@ It provides the following resources: | [grafana_dashboard.nwworload](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | | [grafana_dashboard.podnetwork](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | | [grafana_dashboard.pods](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | -| [grafana_dashboard.prometheus](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | | [grafana_dashboard.proxy](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | | [grafana_dashboard.pv](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | | [grafana_dashboard.scheduler](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | diff --git a/modules/workloads/infra/dashboards/apiserver.json b/modules/workloads/infra/dashboards/apiserver.json index e4754d1..850f68b 100644 --- a/modules/workloads/infra/dashboards/apiserver.json +++ b/modules/workloads/infra/dashboards/apiserver.json @@ -1582,4 +1582,4 @@ "uid": "09ec8aa1e996d6ffcd6817bbaff4db1b", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/modules/workloads/infra/dashboards/cluster-networking.json b/modules/workloads/infra/dashboards/cluster-networking.json index e2f8653..fe90e73 100644 --- a/modules/workloads/infra/dashboards/cluster-networking.json +++ b/modules/workloads/infra/dashboards/cluster-networking.json @@ -1742,4 +1742,4 @@ "uid": "ff635a025bcfea7bc3dd4f508990a3e9", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/modules/workloads/infra/dashboards/cluster.json b/modules/workloads/infra/dashboards/cluster.json index a800a68..3be7583 100644 --- a/modules/workloads/infra/dashboards/cluster.json +++ b/modules/workloads/infra/dashboards/cluster.json @@ -2944,4 +2944,4 @@ "uid": "efa86fd1d0c121a26444b636a3f509a8", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/modules/workloads/infra/dashboards/controller.json b/modules/workloads/infra/dashboards/controller.json index 658e66b..1e11736 100644 --- a/modules/workloads/infra/dashboards/controller.json +++ b/modules/workloads/infra/dashboards/controller.json @@ -1023,4 +1023,4 @@ "uid": "72e0e05bef5099e5f049b05fdc429ed4", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/modules/workloads/infra/dashboards/coredns.json b/modules/workloads/infra/dashboards/coredns.json index 58daafb..d26810a 100644 --- a/modules/workloads/infra/dashboards/coredns.json +++ b/modules/workloads/infra/dashboards/coredns.json @@ -1511,4 +1511,4 @@ "uid": "vkQ0UHxik", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/modules/workloads/infra/dashboards/etcd.json b/modules/workloads/infra/dashboards/etcd.json index cd6c564..415813b 100644 --- a/modules/workloads/infra/dashboards/etcd.json +++ b/modules/workloads/infra/dashboards/etcd.json @@ -1266,4 +1266,4 @@ "uid": "c2f4e12cdf69feb95caa41a5a1b423d9", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/modules/workloads/infra/dashboards/kubelet.json b/modules/workloads/infra/dashboards/kubelet.json index 9677249..5b164ac 100644 --- a/modules/workloads/infra/dashboards/kubelet.json +++ b/modules/workloads/infra/dashboards/kubelet.json @@ -1983,4 +1983,4 @@ "uid": "3138fa155d5915769fbded898ac09fd9", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/modules/workloads/infra/dashboards/namespace-networking.json b/modules/workloads/infra/dashboards/namespace-networking.json index b3ed1cc..b045bb1 100644 --- a/modules/workloads/infra/dashboards/namespace-networking.json +++ b/modules/workloads/infra/dashboards/namespace-networking.json @@ -1398,4 +1398,4 @@ "uid": "8b7a8b326d7a6f1f04244066368c67af", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/modules/workloads/infra/dashboards/namespace-nw-workloads.json b/modules/workloads/infra/dashboards/namespace-nw-workloads.json index b756d2a..244aac8 100644 --- a/modules/workloads/infra/dashboards/namespace-nw-workloads.json +++ b/modules/workloads/infra/dashboards/namespace-nw-workloads.json @@ -1631,4 +1631,4 @@ "uid": "bbb2a765a623ae38130206c7d94a160f", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/modules/workloads/infra/dashboards/namespace-pods.json b/modules/workloads/infra/dashboards/namespace-pods.json index 42f62b8..df59627 100644 --- a/modules/workloads/infra/dashboards/namespace-pods.json +++ b/modules/workloads/infra/dashboards/namespace-pods.json @@ -2718,4 +2718,4 @@ "uid": "85a562078cdf77779eaa1add43ccec1e", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/modules/workloads/infra/dashboards/namespace-workloads.json b/modules/workloads/infra/dashboards/namespace-workloads.json index 80b7a25..76a445d 100644 --- a/modules/workloads/infra/dashboards/namespace-workloads.json +++ b/modules/workloads/infra/dashboards/namespace-workloads.json @@ -2274,4 +2274,4 @@ "uid": "a87fb0d919ec0ea5f6543124e16c42a5", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/modules/workloads/infra/dashboards/networking-workloads.json b/modules/workloads/infra/dashboards/networking-workloads.json index 86898a7..05e4efc 100644 --- a/modules/workloads/infra/dashboards/networking-workloads.json +++ b/modules/workloads/infra/dashboards/networking-workloads.json @@ -1351,4 +1351,4 @@ "uid": "728bf77cc1166d2f3133bf25846876cc", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/modules/workloads/infra/dashboards/nodeexporter-nodes.json b/modules/workloads/infra/dashboards/nodeexporter-nodes.json index 286fe8c..3902fbf 100644 --- a/modules/workloads/infra/dashboards/nodeexporter-nodes.json +++ b/modules/workloads/infra/dashboards/nodeexporter-nodes.json @@ -1004,4 +1004,4 @@ "uid": "v8yDYJqnz", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/modules/workloads/infra/dashboards/nodeexporter-use-node.json b/modules/workloads/infra/dashboards/nodeexporter-use-node.json index b173d4a..9aa6fec 100644 --- a/modules/workloads/infra/dashboards/nodeexporter-use-node.json +++ b/modules/workloads/infra/dashboards/nodeexporter-use-node.json @@ -1077,4 +1077,4 @@ "uid": "XysDYJ37k", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/modules/workloads/infra/dashboards/nodeexpoter-use-cluster.json b/modules/workloads/infra/dashboards/nodeexpoter-use-cluster.json index acfbaef..5addb6a 100644 --- a/modules/workloads/infra/dashboards/nodeexpoter-use-cluster.json +++ b/modules/workloads/infra/dashboards/nodeexpoter-use-cluster.json @@ -1075,4 +1075,4 @@ "uid": "h-sDLJ37z", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/modules/workloads/infra/dashboards/nodes.json b/modules/workloads/infra/dashboards/nodes.json index c145796..76e78ea 100644 --- a/modules/workloads/infra/dashboards/nodes.json +++ b/modules/workloads/infra/dashboards/nodes.json @@ -1049,4 +1049,4 @@ "uid": "200ac8fdbfbb74b39aff88118e4d1c2c", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/modules/workloads/infra/dashboards/pesistentvolumes.json b/modules/workloads/infra/dashboards/pesistentvolumes.json index 0168891..53f2480 100644 --- a/modules/workloads/infra/dashboards/pesistentvolumes.json +++ b/modules/workloads/infra/dashboards/pesistentvolumes.json @@ -547,4 +547,4 @@ "uid": "919b92a8e8041bd567af9edab12c840c", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/modules/workloads/infra/dashboards/pods-networking.json b/modules/workloads/infra/dashboards/pods-networking.json index ff12b3f..7f13606 100644 --- a/modules/workloads/infra/dashboards/pods-networking.json +++ b/modules/workloads/infra/dashboards/pods-networking.json @@ -1178,4 +1178,4 @@ "uid": "7a18067ce943a40ae25454675c19ff5c", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/modules/workloads/infra/dashboards/pods.json b/modules/workloads/infra/dashboards/pods.json index 0ed5bd4..01784d6 100644 --- a/modules/workloads/infra/dashboards/pods.json +++ b/modules/workloads/infra/dashboards/pods.json @@ -2483,4 +2483,4 @@ "uid": "6581e46e4e5c7ba40a07646395ef7b23", "version": 1, "weekStart": "" -} \ No newline at end of file +} diff --git a/modules/workloads/infra/dashboards/proxy.json b/modules/workloads/infra/dashboards/proxy.json index 0a9348d..f107a45 100644 --- a/modules/workloads/infra/dashboards/proxy.json +++ b/modules/workloads/infra/dashboards/proxy.json @@ -1126,4 +1126,4 @@ "uid": "632e265de029684c40b21cb76bca4f94", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/modules/workloads/infra/dashboards/scheduler.json b/modules/workloads/infra/dashboards/scheduler.json index feff65a..852872a 100644 --- a/modules/workloads/infra/dashboards/scheduler.json +++ b/modules/workloads/infra/dashboards/scheduler.json @@ -1035,4 +1035,4 @@ "uid": "2e6b6a3b4bddf1427b3a55aa1311c656", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/modules/workloads/infra/dashboards/workloads.json b/modules/workloads/infra/dashboards/workloads.json index 5297ca0..634c12f 100644 --- a/modules/workloads/infra/dashboards/workloads.json +++ b/modules/workloads/infra/dashboards/workloads.json @@ -2031,4 +2031,4 @@ "uid": "a164a7f0339f99e89cea5cb47e9be617", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/modules/workloads/infra/otel-config/templates/opentelemetrycollector.yaml b/modules/workloads/infra/otel-config/templates/opentelemetrycollector.yaml index 766ddea..083ec6a 100644 --- a/modules/workloads/infra/otel-config/templates/opentelemetrycollector.yaml +++ b/modules/workloads/infra/otel-config/templates/opentelemetrycollector.yaml @@ -12,7 +12,7 @@ spec: config: global: scrape_interval: {{ .Values.scrapeInterval }} - scrape_timeout: {{ .Values.scrapeTimeout }} + scrape_timeout: {{ .Values.scrapeTimeout }} external_labels: cluster: {{ .Values.ekscluster }} scrape_configs: @@ -49,7 +49,7 @@ spec: - source_labels: [__meta_kubernetes_node_name] regex: (.+) target_label: __metrics_path__ - replacement: /api/v1/nodes/$${1}/proxy/metrics/cadvisor + replacement: /api/v1/nodes/$${1}/proxy/metrics/cadvisor - job_name: serviceMonitor/default/kube-prometheus-stack-prometheus-node-exporter/0 honor_timestamps: true scrape_interval: 30s @@ -153,7 +153,7 @@ spec: namespaces: own_namespace: false names: - - default + - default - job_name: serviceMonitor/default/kube-prometheus-stack-prometheus/0 honor_timestamps: true scrape_interval: 30s @@ -256,7 +256,7 @@ spec: namespaces: own_namespace: false names: - - default + - default - job_name: serviceMonitor/default/kube-prometheus-stack-operator/0 honor_labels: true honor_timestamps: true @@ -359,7 +359,7 @@ spec: namespaces: own_namespace: false names: - - default + - default - job_name: serviceMonitor/default/kube-prometheus-stack-kubelet/2 honor_labels: true honor_timestamps: true @@ -476,7 +476,7 @@ spec: namespaces: own_namespace: false names: - - kube-system + - kube-system - job_name: serviceMonitor/default/kube-prometheus-stack-kubelet/1 honor_labels: true honor_timestamps: true @@ -711,7 +711,7 @@ spec: namespaces: own_namespace: false names: - - kube-system + - kube-system - job_name: serviceMonitor/default/kube-prometheus-stack-kube-state-metrics/0 honor_labels: true honor_timestamps: true @@ -816,7 +816,7 @@ spec: namespaces: own_namespace: false names: - - default + - default - job_name: serviceMonitor/default/kube-prometheus-stack-kube-scheduler/0 honor_timestamps: true scrape_interval: 30s @@ -923,7 +923,7 @@ spec: namespaces: own_namespace: false names: - - kube-system + - kube-system - job_name: serviceMonitor/default/kube-prometheus-stack-kube-proxy/0 honor_timestamps: true scrape_interval: 30s @@ -1030,7 +1030,7 @@ spec: namespaces: own_namespace: false names: - - kube-system + - kube-system - job_name: serviceMonitor/default/kube-prometheus-stack-kube-etcd/0 honor_timestamps: true scrape_interval: 30s @@ -1349,7 +1349,7 @@ spec: namespaces: own_namespace: false names: - - kube-system + - kube-system - job_name: serviceMonitor/default/kube-prometheus-stack-apiserver/0 honor_timestamps: true @@ -1362,7 +1362,7 @@ spec: credentials_file: /var/run/secrets/kubernetes.io/serviceaccount/token tls_config: ca_file: /var/run/secrets/kubernetes.io/serviceaccount/ca.crt - server_name: kubernetes + server_name: kubernetes follow_redirects: true enable_http2: true relabel_configs: @@ -1434,7 +1434,7 @@ spec: regex: (.*) target_label: endpoint replacement: https - action: replace + action: replace - source_labels: [__address__] separator: ; regex: (.*) @@ -1455,7 +1455,7 @@ spec: namespaces: own_namespace: false names: - - default + - default - job_name: serviceMonitor/default/kube-prometheus-stack-alertmanager/0 honor_timestamps: true scrape_interval: 30s @@ -1558,7 +1558,7 @@ spec: namespaces: own_namespace: false names: - - default + - default - job_name: 'kube-state-metrics' static_configs: - targets: ['kube-state-metrics.kube-system.svc.cluster.local:8080'] diff --git a/modules/workloads/infra/rules.tf b/modules/workloads/infra/rules.tf index 03fc270..c382a7b 100644 --- a/modules/workloads/infra/rules.tf +++ b/modules/workloads/infra/rules.tf @@ -5,7 +5,7 @@ ################################################################################################################################################ resource "aws_prometheus_rule_group_namespace" "recording_rules" { - count = var.enable_recording_rules ? 1 : 0 + count = var.enable_recording_rules ? 1 : 0 name = "infra-recording-rules" workspace_id = var.managed_prometheus_workspace_id data = < +## Requirements + +| Name | Version | +|------|---------| +| [grafana](#requirement\_grafana) | ~> 1.25.0 | + +## Providers + +| Name | Version | +|------|---------| +| [aws](#provider\_aws) | n/a | +| [grafana](#provider\_grafana) | ~> 1.25.0 | + +## Modules + +| Name | Source | Version | +|------|--------|---------| +| [helm\_addon](#module\_helm\_addon) | github.com/aws-ia/terraform-aws-eks-blueprints/modules/kubernetes-addons/helm-addon | n/a | + +## Resources + +| Name | Type | +|------|------| +| [aws_prometheus_rule_group_namespace.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | +| [grafana_dashboard.this](https://registry.terraform.io/providers/grafana/grafana/latest/docs/resources/dashboard) | resource | +| [aws_partition.current](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/partition) | data source | + +## Inputs + +| Name | Description | Type | Default | Required | +|------|-------------|------|---------|:--------:| +| [addon\_context](#input\_addon\_context) | Input configuration for the addon |
object({
aws_caller_identity_account_id = string
aws_caller_identity_arn = string
aws_eks_cluster_endpoint = string
aws_partition_id = string
aws_region_name = string
eks_cluster_id = string
eks_oidc_issuer_url = string
eks_oidc_provider_arn = string
irsa_iam_permissions_boundary = string
irsa_iam_role_path = string
tags = map(string)
})
| n/a | yes | +| [amp\_endpoint](#input\_amp\_endpoint) | Amazon Managed Prometheus endpoint | `string` | n/a | yes | +| [amp\_id](#input\_amp\_id) | Managed Prometheus workspace id | `string` | n/a | yes | +| [amp\_region](#input\_amp\_region) | Amazon Managed Prometheus Workspace's Region | `string` | `null` | no | +| [dashboards\_folder\_id](#input\_dashboards\_folder\_id) | n/a | `string` | n/a | yes | +| [enable\_recording\_rules](#input\_enable\_recording\_rules) | Enable AMP recording rules | `bool` | `true` | no | +| [helm\_config](#input\_helm\_config) | Helm Config for Prometheus | `any` | `{}` | no | + +## Outputs + +No outputs. + diff --git a/variables.tf b/variables.tf index f8d071f..7716f49 100644 --- a/variables.tf +++ b/variables.tf @@ -21,8 +21,9 @@ variable "irsa_iam_permissions_boundary" { } variable "enable_amazon_eks_adot" { - type = bool - default = true + description = "Enables the ADOT Operator on the EKS Cluster" + type = bool + default = true } variable "enable_cert_manager" { @@ -32,45 +33,49 @@ variable "enable_cert_manager" { } variable "enable_managed_prometheus" { - type = bool - default = true + description = "Creates a new AMP workspace" + type = bool + default = true } variable "managed_prometheus_workspace_id" { - description = "AWS Managed Prometheus Workspace ID" + description = "AMP Workspace ID" type = string default = "" } variable "managed_prometheus_workspace_region" { - description = "AWS Managed Prometheus Workspace Region" + description = "Region where AMP is deployed" type = string default = null } variable "enable_alertmanager" { - description = "Create AMP AlertManager for all workloads" + description = "Creates AMP AlertManager for all workloads" type = bool default = false } variable "enable_managed_grafana" { - type = bool - default = true + description = "Creates a new Amazon Managed Grafana (AMG) Workspace" + type = bool + default = true } variable "managed_grafana_region" { - description = "AWS Managed Grafana Workspace Region" + description = "Region where AMG is deployed" type = string default = null } variable "managed_grafana_workspace_id" { - type = string - default = "" + description = "AMG Workspace ID" + type = string + default = "" } variable "grafana_api_key" { - type = string - default = null + description = "Grafana API key for the AMG workspace" + type = string + default = null } variable "tags" {