* Managed Grafana Workspace with Identity Centre Users (#83) * update kuberenetes and instance type * initial setup of managed grafana workspace and identity centre identities * cleanup * run precommit * output grafana workspace ID * add identity store id variable * remove API key * update outputs naming convention as per terraform guidelines * update docs and add versions * update variables type * update naming conventions * add managed policy arn for querying promethues * update readme * update workshop references to this * add role arn type * cleanup and simplification * remove workshop --------- Co-authored-by: charlie keegan <chakeega@amazon.com> Co-authored-by: Rodrigue Koffi <bonclay7@users.noreply.github.com> * Rename example * Update grafana example and base module references * Update example's reference * Cleanup and docs ref * Add docs * Update docs * TODO: add link after merge * Update managed-grafana.md --------- Co-authored-by: Charlie Keegan <91210223+charliekeeegan@users.noreply.github.com> Co-authored-by: charlie keegan <chakeega@amazon.com> Co-authored-by: Mark Beacom <7315957+mbeacom@users.noreply.github.com>
6.7 KiB
Amazon EKS cluster metrics
This example demonstrates how to monitor your Amazon Elastic Kubernetes Service (Amazon EKS) cluster with the Observability Accelerator's EKS monitoring module.
Monitoring Amazon Elastic Kubernetes Service (Amazon EKS) for metrics has two categories: the control plane and the Amazon EKS nodes (with Kubernetes objects). The Amazon EKS control plane consists of control plane nodes that run the Kubernetes software, such as etcd and the Kubernetes API server. To read more on the components of an Amazon EKS cluster, please read the service documentation.
The Amazon EKS infrastructure Terraform modules focuses on metrics collection to Amazon Managed Service for Prometheus using the AWS Distro for OpenTelemetry Operator for Amazon EKS. It deploys the node exporter and kube-state-metrics in your cluster.
It provides default dashboards to get a comprehensible visibility on your nodes, namespaces, pods, and kubelet operations health. Finally, you get curated Prometheus recording rules and alerts to operate your cluster.
Additionally, you can optionally collect custom Prometheus metrics from your applications running on your EKS cluster.
Prerequisites
!!! note Make sure to complete the prerequisites section before proceeding.
Setup
1. Download sources and initialize Terraform
git clone https://github.com/aws-observability/terraform-aws-observability-accelerator.git
cd examples/existing-cluster-with-base-and-infra
terraform init
2. AWS Region
Specify the AWS Region where the resources will be deployed:
export TF_VAR_aws_region=xxx
3. Amazon EKS Cluster
To run this example, you need to provide your EKS cluster name. If you don't have a cluster ready, visit this example first to create a new one.
Specify your cluster name:
export TF_VAR_eks_cluster_id=xxx
4. Amazon Managed Service for Prometheus workspace (optional)
By default, we create an Amazon Managed Service for Prometheus workspace for you. However, if you have an existing workspace you want to reuse, edit and run:
export TF_VAR_managed_prometheus_workspace_id=ws-xxx
To create a workspace outside of Terraform's state, simply run:
aws amp create-workspace --alias observability-accelerator --query '.workspaceId' --output text
5. Amazon Managed Grafana workspace
To run this example you need an Amazon Managed Grafana workspace. If you have an existing workspace, create an environment variable as described below. To create a new workspace, visit our supporting example for Grafana.
!!! note
For the URL https://g-xyz.grafana-workspace.eu-central-1.amazonaws.com, the workspace ID would be g-xyz
export TF_VAR_managed_grafana_workspace_id=g-xxx
6. Grafana API Key
Amazon Managed Grafana provides a control plane API for generating Grafana API keys.
As a security best practice, we will provide to Terraform a short lived API key to
run the apply or destroy command.
Ensure you have necessary IAM permissions (CreateWorkspaceApiKey, DeleteWorkspaceApiKey)
export TF_VAR_grafana_api_key=`aws grafana create-workspace-api-key --key-name "observability-accelerator-$(date +%s)" --key-role ADMIN --seconds-to-live 1200 --workspace-id $TF_VAR_managed_grafana_workspace_id --query key --output text`
Deploy
Simply run this command to deploy the example
terraform apply
Visualization
1. Prometheus datasource on Grafana
Make sure to open the link in the output. After a successful deployment, this will open
the Prometheus datasource configuration on Grafana.
Click Save & test and you should see a notification confirming that the Amazon Managed Service for Prometheus workspace is ready to be used on Grafana.
terraform output grafana_prometheus_datasource_test
2. Grafana dashboards
Go to the Dashboards panel of your Grafana workspace. You should see a list of dashboards under the Observability Accelerator Dashboards
Open a specific dashboard and you should be able to view its visualization
3. Amazon Managed Service for Prometheus rules and alerts
Open the Amazon Managed Service for Prometheus console and view the details of your workspace. Under the Rules management tab, you should find new rules deployed.
!!! note To setup your alert receiver, with Amazon SNS, follow this documentation
Custom metrics collection
In addition to the cluster metrics, if you are interested in collecting Prometheus
metrics from your pods, you can use setup custom metrics collection.
This will instruct the ADOT collector to scrape your applications metrics based
on the configuration you provide. You can also exclude some of the metrics and save costs.
Using the example, you can edit examples/existing-cluster-with-base-and-infra/main.tf.
In the module module "workloads_infra" { add the following config (make sure the values matches your use case):
enable_custom_metrics = true
custom_metrics_config = {
# list of applications ports (example)
ports = [8000, 8080]
# list of series prefixes you want to discard from ingestion
dropped_series_prefix = ["go_gcc"]
}
After applying Terraform, on Grafana, you can query Prometheus for your application metrics, create alerts and build on your own dashboards. On the explorer section of Grafana, the following query will give you the containers exposing metrics that matched the custom metrics collection, grouped by cluster and node.
sum(up{job="custom-metrics"}) by (container_name, cluster, nodename)