* Move modules around * Update amp billing source * Merge Java monitoring to EKS * Update docs * Merge nginx pattern * Pre-commit * Add save and test URL output * Move EKS dependencies to EKS monitoring module * update docs * Update examples and docs * Add java doc * Add NGINX doc * Update nginx doc * Fix amp monitoring example path * Fix pre-commit * Todo: move to main after merge * Update docs, fix tags
Existing Managed Prometheus Workspace Observability Pattern
This example demonstrates how to use the AWS Observability Accelerator Terraform modules with Amazon Managed Prometheus (AMP) workspace monitoring enabled.
The current example deploys a dashboard into an existing Amazon Managed Grafana (AMG) workspace to provide observability over an existing AMP workspace. It also deploys CloudWatch alarms for AMP usage service limits.
Prerequisites
Ensure that you have the following tools installed locally:
It is also required to have existing AMP and Grafana workspaces. These could be created through the other example modules in this repository.
Setup
This example uses a local terraform state. If you need states to be saved remotely, on Amazon S3 for example, visit the terraform remote states documentation
- Clone the repo using the command below
git clone https://github.com/aws-observability/terraform-aws-observability-accelerator.git
- Initialize terraform
cd examples/amp-monitoring
terraform init
- AWS Region
Specify the AWS Region where the resources will be deployed. Edit the terraform.tfvars file and modify aws_region="...". You can also use environement variables export TF_VAR_aws_region=xxx.
- Amazon Managed Service for Prometheus workspace
If you have an existing workspace, add managed_prometheus_workspace_id=ws-xxx
or use an environment variable export TF_VAR_managed_prometheus_workspace_id=ws-xxx.
If you would like to create CloudWatch alarms for multiple workspaces in a region you can pass them in a comma seperated string.
managed_prometheus_workspace_id = "ws-xxx,ws-xxx"
You can use the following export command to create alarms for all of the workspaces in a region.
export TF_VAR_managed_prometheus_workspace_id=$(aws amp list-workspaces --query 'workspaces[].workspaceId' --output text | sed -E 's/\t/,/g')
- Amazon Managed Grafana workspace
Use an existing workspace, add managed_grafana_workspace_id=g-xxx
or use an environment variable export TF_VAR_managed_grafana_workspace_id=g-xxx.
Amazon Managed Service for Grafana provides a control plane API for generating Grafana API keys. We will provide to Terraform
a short lived API key to run the apply or destroy command.
Ensure you have necessary IAM permissions (CreateWorkspaceApiKey, DeleteWorkspaceApiKey)
export TF_VAR_grafana_api_key=`aws grafana create-workspace-api-key --key-name "observability-accelerator-$(date +%s)" --key-role ADMIN --seconds-to-live 1200 --workspace-id $TF_VAR_managed_grafana_workspace_id --query key --output text`
Deploy
terraform apply -var-file=terraform.tfvars
or if you had only setup environment variables, run
terraform apply
Visualization
- Cloudwatch datasource on Grafana
Open your Grafana workspace and under Configuration -> Data sources, you should see aws-observability-accelerator-cloudwatch. Open and click Save & test. You should see a notification confirming that the CloudWatch datasource is ready to be used on Grafana.
- Grafana dashboards
Go to the Dashboards panel of your Grafana workspace. You should see a list of dashboards under the AMP Monitoring Dashboards folder.
Open the AMP Accelerator Dashboard to see a visualization of the AMP workspace.
- Amazon Managed Service for Prometheus CloudWatch Alarms.
Open the CloudWatch console and click Alarms > All Alarms to review the service limit alarms.
In us-east-1 region an alarm is created for billing. This alarm utilizes anomaly detection to detect anomalies in the Estimated Charges billing metric.
Requirements
| Name | Version |
|---|---|
| terraform | >= 1.1.0 |
| aws | >= 4.0.0 |
| grafana | >= 1.25.0 |
Providers
| Name | Version |
|---|---|
| aws | 4.46.0 |
| grafana | 1.31.1 |
Modules
| Name | Source | Version |
|---|---|---|
| managed_prometheus_monitoring | ../../modules/workloads/managed-prometheus-monitoring | n/a |
Resources
| Name | Type |
|---|---|
| grafana_folder.this | resource |
| aws_grafana_workspace.this | data source |
Inputs
| Name | Description | Type | Default | Required |
|---|---|---|---|---|
| aws_region | AWS Region | string |
n/a | yes |
| grafana_api_key | API key for authorizing the Grafana provider to make changes to Amazon Managed Grafana | string |
n/a | yes |
| managed_grafana_workspace_id | Amazon Managed Grafana workspace ID | string |
n/a | yes |
| managed_prometheus_workspace_ids | Amazon Managed Service for Prometheus Workspace IDs to create Alarms for | string |
n/a | yes |
Outputs
| Name | Description |
|---|---|
| grafana_dashboard_urls | URLs for dashboards created |