From 1898daa4a5a1695a51bc30451adbd0ed96cf7bc7 Mon Sep 17 00:00:00 2001 From: miwr Date: Wed, 26 Mar 2025 14:36:03 +0100 Subject: [PATCH 1/7] bao audit enable file file_path=stdout added --- template/stacks/ref-implementation/openbao/values.yaml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/template/stacks/ref-implementation/openbao/values.yaml b/template/stacks/ref-implementation/openbao/values.yaml index 0ff72cf..4a9e926 100644 --- a/template/stacks/ref-implementation/openbao/values.yaml +++ b/template/stacks/ref-implementation/openbao/values.yaml @@ -4,6 +4,7 @@ server: - -c - | sleep 10 + rm -rf /openbao/data/* # UN-initialises the openbao server (necessary for the new instance to spin up if the pod or container crashes) bao operator init >> /tmp/init.txt cat /tmp/init.txt | grep "Key " | awk '{print $NF}' | xargs -I{} bao operator unseal {} echo $(grep "Initial Root Token:" /tmp/init.txt | awk '{print $NF}')| cat > /openbao/data/initial_token.txt @@ -13,5 +14,7 @@ server: echo $(grep "Unseal Key 4:" /tmp/init.txt | awk '{print $NF}')| cat > /openbao/data/unseal_key4.txt echo $(grep "Unseal Key 5:" /tmp/init.txt | awk '{print $NF}')| cat > /openbao/data/unseal_key5.txt rm /tmp/init.txt + bao login $(grep "Initial Root Token:" /tmp/init.txt | awk '{print $NF}') + bao audit enable file file_path=stdout ui: enabled: true -- 2.45.2 From a772e4f9ae53ee269a90552e7c23e6c8278a73dd Mon Sep 17 00:00:00 2001 From: miwr Date: Wed, 26 Mar 2025 15:00:49 +0100 Subject: [PATCH 2/7] # UN-initialises the openbao server (necessary for the new instance to spin up if the pod or container crashes) removed --- template/stacks/ref-implementation/openbao/values.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/template/stacks/ref-implementation/openbao/values.yaml b/template/stacks/ref-implementation/openbao/values.yaml index 4a9e926..1317001 100644 --- a/template/stacks/ref-implementation/openbao/values.yaml +++ b/template/stacks/ref-implementation/openbao/values.yaml @@ -4,7 +4,7 @@ server: - -c - | sleep 10 - rm -rf /openbao/data/* # UN-initialises the openbao server (necessary for the new instance to spin up if the pod or container crashes) + rm -rf /openbao/data/* bao operator init >> /tmp/init.txt cat /tmp/init.txt | grep "Key " | awk '{print $NF}' | xargs -I{} bao operator unseal {} echo $(grep "Initial Root Token:" /tmp/init.txt | awk '{print $NF}')| cat > /openbao/data/initial_token.txt -- 2.45.2 From 8126550d70bb6dbbad378f746e171476eff6c09c Mon Sep 17 00:00:00 2001 From: miwr Date: Wed, 26 Mar 2025 15:09:21 +0100 Subject: [PATCH 3/7] rm removed --- template/stacks/ref-implementation/openbao/values.yaml | 1 - 1 file changed, 1 deletion(-) diff --git a/template/stacks/ref-implementation/openbao/values.yaml b/template/stacks/ref-implementation/openbao/values.yaml index 1317001..01d7ddd 100644 --- a/template/stacks/ref-implementation/openbao/values.yaml +++ b/template/stacks/ref-implementation/openbao/values.yaml @@ -4,7 +4,6 @@ server: - -c - | sleep 10 - rm -rf /openbao/data/* bao operator init >> /tmp/init.txt cat /tmp/init.txt | grep "Key " | awk '{print $NF}' | xargs -I{} bao operator unseal {} echo $(grep "Initial Root Token:" /tmp/init.txt | awk '{print $NF}')| cat > /openbao/data/initial_token.txt -- 2.45.2 From 66a56f2c43b1ac092d525c79373fae77dfcbb285 Mon Sep 17 00:00:00 2001 From: miwr Date: Wed, 26 Mar 2025 15:14:06 +0100 Subject: [PATCH 4/7] bao login $(grep "Initial Root Token:" /tmp/init.txt | awk '{print $NF}') moved two lines up --- template/stacks/ref-implementation/openbao/values.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/template/stacks/ref-implementation/openbao/values.yaml b/template/stacks/ref-implementation/openbao/values.yaml index 01d7ddd..25c519c 100644 --- a/template/stacks/ref-implementation/openbao/values.yaml +++ b/template/stacks/ref-implementation/openbao/values.yaml @@ -12,8 +12,8 @@ server: echo $(grep "Unseal Key 3:" /tmp/init.txt | awk '{print $NF}')| cat > /openbao/data/unseal_key3.txt echo $(grep "Unseal Key 4:" /tmp/init.txt | awk '{print $NF}')| cat > /openbao/data/unseal_key4.txt echo $(grep "Unseal Key 5:" /tmp/init.txt | awk '{print $NF}')| cat > /openbao/data/unseal_key5.txt - rm /tmp/init.txt - bao login $(grep "Initial Root Token:" /tmp/init.txt | awk '{print $NF}') + bao login $(grep "Initial Root Token:" /tmp/init.txt | awk '{print $NF}') + rm /tmp/init.txt bao audit enable file file_path=stdout ui: enabled: true -- 2.45.2 From abe39e9b514746527301c65f9af62efcb4cbf7b3 Mon Sep 17 00:00:00 2001 From: miwr Date: Wed, 30 Apr 2025 11:23:53 +0200 Subject: [PATCH 5/7] added app label --- template/stacks/monitoring/alloy/values.yaml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/template/stacks/monitoring/alloy/values.yaml b/template/stacks/monitoring/alloy/values.yaml index a2ac67d..75e5781 100644 --- a/template/stacks/monitoring/alloy/values.yaml +++ b/template/stacks/monitoring/alloy/values.yaml @@ -70,6 +70,11 @@ alloy: target_label = "container" } + rule { + source_labels = ["__meta_kubernetes_pod_label_app"] + action = "replace" + target_label = "app" + } } loki.source.kubernetes "all_pod_logs" { -- 2.45.2 From 0d9eb6488c9fa110a046e9d3a44a1348c434d597 Mon Sep 17 00:00:00 2001 From: miwr Date: Wed, 30 Apr 2025 11:36:14 +0200 Subject: [PATCH 6/7] k8s_io_app added to alloy configuration --- template/stacks/monitoring/alloy/values.yaml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/template/stacks/monitoring/alloy/values.yaml b/template/stacks/monitoring/alloy/values.yaml index 75e5781..9ce3854 100644 --- a/template/stacks/monitoring/alloy/values.yaml +++ b/template/stacks/monitoring/alloy/values.yaml @@ -75,6 +75,12 @@ alloy: action = "replace" target_label = "app" } + + rule { + source_labels = ["__meta_kubernetes_pod_label_app_kubernetes_io_name"] + action = "replace" + target_label = "k8s_io_app" + } } loki.source.kubernetes "all_pod_logs" { -- 2.45.2 From 0ddaa6b48b3c57618645d0c546e962443cb0a3fd Mon Sep 17 00:00:00 2001 From: miwr Date: Wed, 30 Apr 2025 11:47:07 +0200 Subject: [PATCH 7/7] app-name --- template/stacks/monitoring/alloy/values.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/template/stacks/monitoring/alloy/values.yaml b/template/stacks/monitoring/alloy/values.yaml index 9ce3854..6be721b 100644 --- a/template/stacks/monitoring/alloy/values.yaml +++ b/template/stacks/monitoring/alloy/values.yaml @@ -79,7 +79,7 @@ alloy: rule { source_labels = ["__meta_kubernetes_pod_label_app_kubernetes_io_name"] action = "replace" - target_label = "k8s_io_app" + target_label = "app-name" } } -- 2.45.2