Dalet BaseOS Variables
Here's an exhaustive list of Dalet BaseOS public API variables.
All listed variables are meant to be overridable by platform specifics.
Network Settings
The following variables are meant to tune network settings.
dalet_baseos_network_airgapped
dalet_baseos_network_airgapped
Defines whether the environment is air-gapped, i.e. isolated from public Internet.
Prevents download/installation of external resources (only private OS mirror repositories will be used).
dalet_baseos_network_airgapped: false
dalet_baseos_network_http_proxy
dalet_baseos_network_http_proxy
Defines whether the environment requires an HTTP proxy to connect to Internet.
dalet_baseos_network_http_proxy:
enabled: false
blackbox: false
url: "http://my.local.proxy/"
username: ""
password: ""
bypass: [] # list of IP addresses for which direct connection is preferred, bypassing proxy
dalet_baseos_network_ipv6_enabled
dalet_baseos_network_ipv6_enabled
Defines whether network IPv6 support should be enabled/disabled from kernel settings.
dalet_baseos_network_ipv6_enabled: false
dalet_baseos_network_dns_systemd_resolution
dalet_baseos_network_dns_systemd_resolution
Defines whether local DNS resolution (and cache) should be handled by systemd (or legacy manual /etc/resolv.conf)
dalet_baseos_network_dns_systemd_resolution: true
dalet_baseos_network_firewall_enabled
dalet_baseos_network_firewall_enabled
Defines whether OS-based software firewall should be enabled.
Setting has no effect if system does not have a public network interface and configured IP address.
dalet_baseos_network_firewall_enabled: false
dalet_baseos_network_firewall_open_tcp_ports
dalet_baseos_network_firewall_open_tcp_ports
List of TCP ports to be opened if firewall is enabled.
Default policy is deny all but explicitly opened ports.
dalet_baseos_network_firewall_open_tcp_ports: []
dalet_baseos_network_firewall_open_udp_ports
dalet_baseos_network_firewall_open_udp_ports
List of UDP ports to be opened if firewall is enabled.
Default policy is deny all but explicitly opened ports.
dalet_baseos_network_firewall_open_udp_ports: []
dalet_baseos_network_ntp_servers
dalet_baseos_network_ntp_servers
List of NTP servers to be used to synchronize system's time.
Defaults to provider ones if unspecified.
dalet_baseos_network_ntp_servers: []
dalet_baseos_network_failover_enabled
dalet_baseos_network_failover_enabled
Defines whether network redundancy and virtual IP failover mechanisms must be enabled.
dalet_baseos_network_failover_enabled: false
dalet_baseos_network_failover_settings
dalet_baseos_network_failover_settings
Configuration settings for failover mechanisms (useless if not enabled)
dalet_baseos_network_failover_settings:
# Defines whether virtual MAC addresses (VMAC) must be used (formatted as 00:00:5e:00:00:xx).
# Useful if not supported by underlying network interface (e.g. VMware vSwitch with MAC address range restriction)
# Enabled if unspecified.
use_vmac: true
# Forces peer-to-peer unicast VRRP communication over multicast.
# Only supported with 2 peers failover.
# Disabled if unspecified.
use_unicast: false
# Defines whether to enable fast failure detection with point-to-point Bidirectional Forwarding Detection (BFD)
# Enabled if unspecified.
use_bfd: true
# List of hosts used as peers in a highly-available failover setup
# Recommended to use Ansible special variables like groups['ROLE']
peers: []
# List of VRRP trackers to be configured to managed virtual IP addresses.
trackers: []
Tracker format is:
- name: MYAPP
configs:
# Virtual IP address (VIP) to be assigned, must be unique in your network.
# Can be used either as a simple string or a list of strings to handle multiple IP addresses.
- vip: "192.168.0.1"
# Virtual Router Identification, integer in 1..255 range.
# Required to be unique on a given L2/L3 segment.
vrid: "50"
# Optional: network interface to use for VRRP messages communication.
# Defaults to private network one if unspecified.
control_interface: ens4
# Optional: network interface to use to attach virtual IP address.
# Defaults to private network one if unspecified.
interface: ens4
# Optional: password to authenticate VRRP messages between peers.
password: ""
# Optional: hostname from inventory of the expected master host.
# Overridden when `priority is set.
primary: 192.168.0.2
# Optional: allows lower priority machine to maintain the master role and prevent unnecessary VIP flapping.
# Disabled if unspecified.
nopreempt: false
# Optional: enforce priority (1..250). The lower value will be selected as master host.
priority: 100
# Optional: set custom route when virtual IP is acquired.
routes: []
# Optional: used to determine the condition under which a given instance goes from PRIMARY to BACKUP state.
# If unset, failover is performed when one server fails (crash, reboot, ...)
checkscript: "/usr/bin/killall -0 myapp"
# Optional: path to post-actions script, called at state change.
notifyscript: "/opt/keepalived-notify-myapp.sh"
Route format is:
- destination: <destination cidr>
gateway: <ip>
metric: <weight>
OS Packages Management
dalet_baseos_packages_mirror_archive_repository
dalet_baseos_packages_mirror_archive_repository
Defines custom OS packages repository to be used for regular packages management.
Defaults to Ubuntu official mirror, if unspecified.
NOTE: One may specify local country mirror location to pull system packages from, speeding up downloads (e.g. 'us.clouds.archive.ubuntu.com')
ISO3166-formatted 2-letters country code, e.g. 'us', 'fr', 'de', 'uk' ...
Allows using a private mirror proxy, if required.
dalet_baseos_packages_mirror_archive_repository: archive.ubuntu.com
dalet_baseos_packages_mirror_security_repository
dalet_baseos_packages_mirror_security_repository
Defines custom OS packages repository to be used for security packages management.
Defaults to Ubuntu official mirror, if unspecified.
Allows using a private mirror proxy.
dalet_baseos_packages_mirror_security_repository: security.ubuntu.com
dalet_baseos_packages_mirror_dalet_repository
dalet_baseos_packages_mirror_dalet_repository
Defines custom OS packages repository to be used for Dalet packages management.
Defaults to Dalet official mirror, if unspecified.
Allows using a private mirror proxy.
dalet_baseos_packages_mirror_dalet_repository: packages.cs.dalet.cloud
dalet_baseos_packages_list_custom
dalet_baseos_packages_list_custom
Defines a list of extra system packages to be installed on the platform.
dalet_baseos_packages_list_custom: []
dalet_baseos_packages_enforced_upgrade
dalet_baseos_packages_enforced_upgrade
Defines whether base OS packages must be upgraded at play or kept to present version.
Enforced upgrades improves security and bug-fixing but might cause unexpected regressions or service restarts.
dalet_baseos_packages_enforced_upgrade: false
OS Tuning
dalet_baseos_tuning_timezone
dalet_baseos_tuning_timezone
Defines the system's current timezone for proper time management.
Refer to system's /usr/share/zoneinfo/ content for list of eligible timezones.
It is highly recommended to keep it set to UTC (default, Universal Time Coordinated), making any collaboration between global teams way easier when it comes to troubleshooting.
dalet_baseos_tuning_timezone: UTC
dalet_baseos_hostctl_enabled
dalet_baseos_hostctl_enabled
Defines whether built-in HostControl utilities must be bundled.
Hostctl provides various scripts and aliases to quickly get system's status and helps with troubleshooting.
NOTE: Disabling it saves a bit of deployment time and comes in handy for sandbox deployments.
dalet_baseos_hostctl_enabled: true
dalet_baseos_tuning_thp_enabled
dalet_baseos_tuning_thp_enabled
Define state for Transparent HugePage (THP) support (default: enabled)
THP is an alternative mean of using huge pages for the backing of virtual memory with huge pages that supports the automatic promotion and demotion of page sizes and without the shortcomings of hugetlbfs.
dalet_baseos_tuning_thp_enabled: true
dalet_baseos_sysctl_settings
dalet_baseos_sysctl_settings
Defines custom sysctl tuning settings (only works on Linux).
Settings are defined as:
- name: "SYSCTL_SETTING_NAME" # e.g. 'net.ipv4.ip_forward'
value: string
enabled: bool # optional, defaults to 'true'. Condition for setting application.
set: bool # optional, defaults to 'true'. Whether to keep setting persistent.
state: string # optional, defaults to 'present'. Use 'absent' for setting removal.
reload: bool # optional, defaults to 'true'.
dalet_baseos_sysctl_settings: []
OS Users Management
dalet_baseos_users_root_password
dalet_baseos_users_root_password
Optionally allows setting a password for root/admin system user.
BaseOS SSH server policy strictly prohibits remote root login, making it safe against remote brute-force attacks.
Setting root password can however come in handy when system is stuck and you need physical terminal access to the system as last resort option.
dalet_baseos_users_root_password: "{{ vault_dalet_baseos_users_root_password | default('') }}"
dalet_baseos_users_admin_accounts_enabled
dalet_baseos_users_admin_accounts_enabled
Optionally defines a list of UNIX admin accounts to be created locally on system. List of strings.
Admin accounts:
- are nominative (one per user).
- have password-less escalation privileges. sudo command grants root rights.
- have no password set.
- require public key SSH authentication.
WARNING: These are system accounts, not application ones.
dalet_baseos_users_admin_accounts_enabled: []
dalet_baseos_users_admin_accounts_disabled
dalet_baseos_users_admin_accounts_disabled
Optionally defines a list of deprecated UNIX admin accounts to be removed locally from the system. List of strings.
dalet_baseos_users_admin_accounts_disabled: []
dalet_baseos_users_admin_accounts_pubkey_dirs
dalet_baseos_users_admin_accounts_pubkey_dirs
Defines a list of local directories (relative to playbook execution one) where to look for public SSH key files. List of strings.
Multiple directories can be passed for Ansible to look into.
Public SSH certificates must be PEM-formatted and labelled per account.
Example: If jdoe is part of dalet_baseos_users_admin_accounts_enabled list, Ansible will look for a pem-formatted jdoe file in one of the directories provided in dalet_baseos_users_admin_accounts_pubkey_dirs variable. If found, user's public key will be automatically pushed to the system.
dalet_baseos_users_admin_accounts_pubkey_dirs: []
dalet_baseos_users_extra_groups
dalet_baseos_users_extra_groups
Optionally defines list of extra UNIX groups to be created. List of strings.
All enabled user admin accounts will be part of the specified groups.
dalet_baseos_users_extra_groups: []
OS Drivers Management
dalet_baseos_drivers_installation_enabled
dalet_baseos_drivers_installation_enabled
Defines whether base OS drivers (like nVidia GPU,etc) must be installed.
dalet_baseos_drivers_installation_enabled: true
dalet_baseos_drivers_nvidia_extended_tuning
dalet_baseos_drivers_nvidia_extended_tuning
Defines globally whether base OS needs to apply extended tuning after drivers installation (like tuning of linux kernel, NIC, etc).
dalet_baseos_drivers_nvidia_extended_tuning: false
OS Security & Hardening Settings
dalet_baseos_security_access_trail_enabled
dalet_baseos_security_access_trail_enabled
Defines whether local user actions must be tracked for further audit and trailing.
If enabled, all user-input commands and system-calls will be logged.
dalet_baseos_security_access_trail_enabled: false
dalet_baseos_security_application_access_control
dalet_baseos_security_application_access_control
Defines whether kernel-based mandatory application access control (MAC) must be enabled.
dalet_baseos_security_application_access_control: true
dalet_baseos_security_auditing_enabled
dalet_baseos_security_auditing_enabled
Defines whether additional security auditing tools should be installed.
Allows for system's security status self-assessment for compliance (e.g. ISO, SOC-2 ...)
dalet_baseos_security_auditing_enabled: false
dalet_baseos_security_auditing_enforced
dalet_baseos_security_auditing_enforced
Defines whether security auditing tool must be run against each play to ensure minimal compliance.
Play will be stopped if enabled and resulting score does NOT meet requested expectation.
dalet_baseos_security_auditing_enforced: false
dalet_baseos_security_auditing_minimal_score
dalet_baseos_security_auditing_minimal_score
Defines the minimal expected security auditing score we need to reach for proper compliance.
dalet_baseos_security_auditing_minimal_score: 69
dalet_baseos_security_upgrade_enabled
dalet_baseos_security_upgrade_enabled
Defines whether OS packages scheduled auto-upgrades should be turned on.
dalet_baseos_security_upgrade_enabled: true
dalet_baseos_security_unattended_update_period
dalet_baseos_security_unattended_update_period
Defines frequency (in days) to update OS package list.
dalet_baseos_security_unattended_update_period: 7
dalet_baseos_security_unattended_upgrade_period
dalet_baseos_security_unattended_upgrade_period
Defines frequency (in days) to upgrade OS packages.
dalet_baseos_security_unattended_upgrade_period: 14
dalet_baseos_security_unattended_autoclean_interval
dalet_baseos_security_unattended_autoclean_interval
Defines frequency (in days) to clean leftover OS packages.
dalet_baseos_security_unattended_autoclean_interval: 28
dalet_baseos_security_unattended_upgrade_days_of_the_week
dalet_baseos_security_unattended_upgrade_days_of_the_week
Defines which day(s) of the week should security upgrades be applied.
Example: "Mon,Tue", defaults to everyday.
dalet_baseos_security_unattended_upgrade_days_of_the_week: ~
dalet_baseos_security_unattended_upgrade_hour
dalet_baseos_security_unattended_upgrade_hour
Defines which hour of the day should security upgrades be applied.
dalet_baseos_security_unattended_upgrade_hour: 3
dalet_baseos_security_ssh_auth_password_enabled
dalet_baseos_security_ssh_auth_password_enabled
Defines whether password-based SSH authentication is allowed (pubkey-based authentication only otherwise).
dalet_baseos_security_ssh_auth_password_enabled: false
dalet_baseos_security_ssh_root_login_enabled
dalet_baseos_security_ssh_root_login_enabled
Defines whether SSH root login is allowed.
dalet_baseos_security_ssh_root_login_enabled: false
Logs Management
dalet_baseos_logrotate_enabled
dalet_baseos_logrotate_enabled
Defines whether configuration for logrotate should be enabled.
Keep disabled if you do not intend to apply configuration of logrotate.
dalet_baseos_logrotate_enabled: true
dalet_baseos_logrotate_timer_frequency
dalet_baseos_logrotate_timer_frequency
Defines timer frequency for log rotation, as to prevent filesystem's completion.
Allowed values: hourly, daily, weekly, monthly, yearly.
dalet_baseos_logrotate_timer_frequency: daily
dalet_baseos_logrotate_count
dalet_baseos_logrotate_count
Defines how many times log files are rotated before being removed.
If count is 0, old versions are removed rather than rotated.
If count is -1, old logs are not removed at all, except they are affected by dalet_baseos_logrotate_max_age_days.
dalet_baseos_logrotate_count: 7
dalet_baseos_logrotate_max_age_days
dalet_baseos_logrotate_max_age_days
Instruct logrotate to remove rotated log files older than
The age is only checked if the logfile is to be rotated.
dalet_baseos_logrotate_max_age_days: 7
dalet_baseos_logrotate_syslog_extra_files
dalet_baseos_logrotate_syslog_extra_files
List of extra syslog-formatted files to be processed by log rotation mechanism.
dalet_baseos_logrotate_syslog_extra_files: []
dalet_baseos_logrotate_max_file_size_gb
dalet_baseos_logrotate_max_file_size_gb
Defines maximum log file size (in GB) before log rotation process if enforced.
Defaults to 10% of the root filesystem if unspecified.
dalet_baseos_logrotate_max_file_size_gb: 0
Containerization
dalet_baseos_docker_custom_subnet_size
dalet_baseos_docker_custom_subnet_size
Customize docker subnet size within docker_custom_ip_range cidr. Default is 24. Variable is only used when docker_custom_ip_range is set.
dalet_baseos_docker_custom_subnet_size: 24
dalet_baseos_containers_enabled
dalet_baseos_containers_enabled
Defines whether support for containerization stack should be enabled (Docker-managed).
Keep disabled if you do not intend to run any container-based application on the system.
dalet_baseos_containers_enabled: true
dalet_baseos_containers_enforced_upgrade
dalet_baseos_containers_enforced_upgrade
Defines whether containers management daemon should be upgraded at play.
Enforced upgrades allow for more features, security and bug-fixes but implies application restart and downtime.
dalet_baseos_containers_enforced_upgrade: false
dalet_baseos_containers_bridge_network
dalet_baseos_containers_bridge_network
Defines private IP range used by containers management subsystem for bridged network.
dalet_baseos_containers_bridge_network: "172.17.0.0/16"
dalet_baseos_containers_registries
dalet_baseos_containers_registries
Defines a list of container registries authorized to log into.
Enabled user admin accounts will feature pre-defined registries credentials for seamless authentication.
Registry list entries to be formatted as:
- endpoint: string # Example registry.acme.com, no http(s):// prefix.
user: string # User name to authenticate with.
password: string # Password to authenticate with.
and declared into:
dalet_baseos_containers_registries: []
Remote Network File Systems
dalet_baseos_mounts_nfs_endpoints
dalet_baseos_mounts_nfs_endpoints
A list of NFS shares to be mounted, e.g:
- host: "NFS_SERVER_ADDRESS"
share: "NFS_SHARE_NAME"
target: "/PATH"
fstype: "FSTYPE" # optional, defaults to 'nfs4' if unspecified
version: "NFS_VERSION" # optional, defaults to '4.1' if unspecified
opts: "KERNEL MOUNT OPTIONS" # optional
(compatible with box.com and GCP network shares)
dalet_baseos_mounts_nfs_endpoints: []
dalet_baseos_mounts_efs_endpoints
dalet_baseos_mounts_efs_endpoints
A list of AWS EFS shares to be mounted, e.g:
- id: "AWS EFS ID"
region: "AWS EFS REGION"
target: "/PATH"
iam: bool # optional, defaults to 'false'
version: "EFS_VERSION" # optional, defaults to '4.1' if unspecified
dalet_baseos_mounts_efs_endpoints: []
dalet_baseos_mounts_cifs_endpoints
dalet_baseos_mounts_cifs_endpoints
A list of Samba/CIFS shares to be mounted, e.g:
- host: "CIFS_SERVER_ADDRESS"
share: "CIFS_SHARE_NAME"
target: "/PATH"
username: "USERNAME"
password: "PASSWORD"
version: "CIFS_VERSION" # optional, defaults to '3.0' if unspecified
dalet_baseos_mounts_cifs_endpoints: []
dalet_baseos_mounts_azure_endpoints
dalet_baseos_mounts_azure_endpoints
A list of Azure Files shares to be mounted, e.g:
- account: "AZURE_ACCOUNT_ID"
share: "AZURE_SHARE_NAME"
target: "/PATH"
username: "USERNAME"
password: "PASSWORD"
version: "CIFS_VERSION" # optional, defaults to '3.0' if unspecified
dalet_baseos_mounts_azure_endpoints: []
dalet_baseos_mounts_s3_endpoints
dalet_baseos_mounts_s3_endpoints
A list of S3 buckets to be mounted, e.g:
- bucket: "BUCKET_NAME"
provider: "PROVIDER" # currently supported are 'AWS' and 'OVH'
region: "REGION"
access_key: "S3_ACCESS_KEY"
secret: "S3_SECRET_KEY"
target: "/PATH" # optional, mount point on local filesystem, defaults to /var/lib/rclone/BUCKET_NAME if unspecified
dalet_baseos_mounts_s3_endpoints: []
Monitoring and Observability
dalet_baseos_monitoring_enabled
dalet_baseos_monitoring_enabled
Defines whether to install platform monitoring agents to collect key logs and metrics.
dalet_baseos_monitoring_enabled: true
dalet_baseos_monitoring_high_availability
dalet_baseos_monitoring_high_availability
Defines whether to enable resilient support for metrics collection agents.
When enabled, multiple agents might be in charge of collecting the same metrics, but only at a time will be scraping. Once enabled, requires per-scraper explicit enablement.
dalet_baseos_monitoring_high_availability: false
dalet_baseos_monitoring_high_availability_identifier
dalet_baseos_monitoring_high_availability_identifier
Defines the monitoring cluster unique identifier for peers to be part of.
dalet_baseos_monitoring_high_availability_identifier: ""
dalet_baseos_monitoring_high_availability_group
dalet_baseos_monitoring_high_availability_group
Defines the ansible group name of peers to be part of.
dalet_baseos_monitoring_high_availability_group: ""
dalet_baseos_monitoring_control_tower_enabled
dalet_baseos_monitoring_control_tower_enabled
Controls whether platform collected logs and metrics are shipped to Dalet's Control Tower.
dalet_baseos_monitoring_control_tower_enabled: false
dalet_baseos_monitoring_control_tower_tenant_id
dalet_baseos_monitoring_control_tower_tenant_id
Dalet Control Tower's tenant ID, used for platform's identification (must be unique)
It usually consists of $PRODUCT-$PLATFORM-$ENV form, where:
- PRODUCT is one of amberfin, controltower, cortex, flex, galaxy, instream, kowabunga, pyramid
- PLATFORM is free name
- ENV is free name (usually prod or stg)
dalet_baseos_monitoring_control_tower_tenant_id: ""
dalet_baseos_monitoring_control_tower_env
dalet_baseos_monitoring_control_tower_env
Control Dalet Control Tower's endpoint.
Accepted values are prod and stg.
dalet_baseos_monitoring_control_tower_env: "prod"
dalet_baseos_monitoring_control_tower_mimir_password
dalet_baseos_monitoring_control_tower_mimir_password
Credentials used to ship collected metrics to Dalet's Control Tower.
Differs from staging and production endpoints.
Defaults to a vault-encrypted vault_cct_mimir_password secret variable, if unspecified.
dalet_baseos_monitoring_control_tower_mimir_password: ""
dalet_baseos_monitoring_control_tower_loki_password
dalet_baseos_monitoring_control_tower_loki_password
Credentials used to ship collected logs to Dalet's Control Tower.
Differs from staging and production endpoints.
Defaults to a vault-encrypted vault_cct_loki_password secret variable, if unspecified.
dalet_baseos_monitoring_control_tower_loki_password: ""
dalet_baseos_monitoring_extra_targets
dalet_baseos_monitoring_extra_targets
Optionally defines a list of additional targets to ship collected logs and metrics to (aside from Dalet Control Tower).
Used to specify customer-specific LGTM stacks for example.
Target format is:
- name: TARGET_NAME
enabled: bool
tenant_id: FREE_NAME # optional
prometheus: # optional
endpoint: "https://metrics.acme.com"
path: "/api/v1/push" # optional
username: "METRICS_USERNAME" # optional
password: "METRICS_PASSWORD" # optional
loki: # optional
endpoint: "https://logs.acme.com"
path: "/loki/api/v1/push" # optional
username: "LOGS_USERNAME" # optional
password: "LOGS_PASSWORD" # optional
dalet_baseos_monitoring_extra_targets: []
dalet_baseos_monitoring_targets_relabelling_rules
dalet_baseos_monitoring_targets_relabelling_rules
Optionally defines a list of default target relabelling rules after scraping
Rule format is:
- sources: ["label"] # optional
target: "label" # optional
action: "replace" # optional
replacement: "value" # optional
regex: "REGEX" # optional
separator: ";" # optional
enabled: bool # optional, defaults to true.
dalet_baseos_monitoring_targets_relabelling_rules: []
dalet_baseos_monitoring_metrics_relabelling_rules
dalet_baseos_monitoring_metrics_relabelling_rules
Optionally defines a list of default metric relabelling rules after scraping
Rule format is:
- sources: ["label"] # optional
target: "label" # optional
action: "replace" # optional
replacement: "value" # optional
regex: "REGEX" # optional
separator: ";" # optional
enabled: bool # optional, defaults to true.
dalet_baseos_monitoring_metrics_relabelling_rules: []
dalet_baseos_monitoring_metrics_builtin_exporters
dalet_baseos_monitoring_metrics_builtin_exporters
List of optional enabled built-in Prometheus exporters to pull metrics from.
Currently supported: blackbox, consul, elasticsearch, mongodb, mssql, mysql, redis.
dalet_baseos_monitoring_metrics_builtin_exporters: []
dalet_baseos_monitoring_metrics_mongodb_targets
dalet_baseos_monitoring_metrics_mongodb_targets
List of optional MongoDB instances to be monitored.
Requires mongodb to be listed in dalet_baseos_monitoring_metrics_builtin_exporters variable.
Target format is:
- name: string # optional, instance identifier, 'mongodb' if unspecified.
enabled: bool # optional, defaults to true.
host: string # optional, IP address or FQDN, local IP if unspecified.
port: int # optional, 27017 if unspecified.
user: string # MongoDB admin username to be used.
password: string # MongoDB admin password to be used.
rs: string # optional, replicaset name, if any.
dalet_baseos_monitoring_metrics_mongodb_targets: []
dalet_baseos_monitoring_metrics_mysql_targets
dalet_baseos_monitoring_metrics_mysql_targets
List of optional MySQL/MariaDB instances to be monitored.
Requires mysql to be listed in dalet_baseos_monitoring_metrics_builtin_exporters variable.
Target format is:
- name: string # optional, instance identifier, 'mysql' if unspecified.
enabled: bool # optional, defaults to true.
host: string # optional, IP address or FQDN, local IP if unspecified.
port: int # optional, 3306 if unspecified.
user: string # MySQL username to be used.
password: string # MySQL password to be used.
dalet_baseos_monitoring_metrics_mysql_targets: []
dalet_baseos_monitoring_metrics_blackbox_targets
dalet_baseos_monitoring_metrics_blackbox_targets
List of optional external targets to be scraped for liveness.
Requires blackbox to be listed in dalet_baseos_monitoring_metrics_builtin_exporters variable.
Target format is:
- name: TARGET_NAME
enabled: bool # optional, defaults to true.
address: string # endpoint to query, e.g. 1.2.3.4 for 'icmp' probe or 'https://acme.com' for 'https' probe
probe: string # supported options: 'http' (default), 'https', 'icmp'
dalet_baseos_monitoring_metrics_blackbox_targets: []
dalet_baseos_monitoring_metrics_elasticsearch_targets
dalet_baseos_monitoring_metrics_elasticsearch_targets
List of optional ElasticSearch instances to be monitored.
Requires elasticsearch to be listed in dalet_baseos_monitoring_metrics_builtin_exporters variable.
Target format is:
- name: string # optional, instance identifier, 'elasticsearch' if unspecified.
enabled: bool # optional, defaults to true.
host: string # optional, IP address or FQDN, local IP if unspecified.
port: int # optional, 9200 if unspecified.
user: string # ElasticSearch admin username to be used.
password: string # ElasticSearch admin password to be used.
dalet_baseos_monitoring_metrics_elasticsearch_targets: []
dalet_baseos_monitoring_metrics_redis_targets
dalet_baseos_monitoring_metrics_redis_targets
List of optional Redis instances to be monitored.
Requires redis to be listed in dalet_baseos_monitoring_metrics_builtin_exporters variable.
Target format is:
- name: string # optional, instance identifier, 'redis' if unspecified.
enabled: bool # optional, defaults to true.
host: string # optional, IP address or FQDN, local IP if unspecified.
port: int # optional, 6379 if unspecified.
user: string # Redis username to be used.
password: string # Redis password to be used.
dalet_baseos_monitoring_metrics_redis_targets: []
dalet_baseos_monitoring_metrics_consul_targets
dalet_baseos_monitoring_metrics_consul_targets
List of optional Consul instances to be monitored.
Requires consul to be listed in dalet_baseos_monitoring_metrics_builtin_exporters variable.
Target format is:
- name: string # optional, instance identifier, 'consul' if unspecified.
enabled: bool # optional, defaults to true.
host: string # optional, IP address or FQDN, local IP if unspecified.
port: int # optional, 8500 if unspecified.
token: string # optional, ACL token to pass to HTTP queries to retrieve metrics from Consul instance.
dalet_baseos_monitoring_metrics_consul_targets: []
dalet_baseos_monitoring_metrics_consul_service_discovery_enabled
dalet_baseos_monitoring_metrics_consul_service_discovery_enabled
Defines whether Consul services discovery scraping should be enabled.
dalet_baseos_monitoring_metrics_consul_service_discovery_enabled: false
dalet_baseos_monitoring_metrics_consul_service_discovery_endpoint
dalet_baseos_monitoring_metrics_consul_service_discovery_endpoint
Defines Consul server endpoint to be used for services discovery.
dalet_baseos_monitoring_metrics_consul_service_discovery_endpoint: "consul.domain:8500"
dalet_baseos_monitoring_metrics_consul_service_discovery_token
dalet_baseos_monitoring_metrics_consul_service_discovery_token
Defines and optional secret token used to access Consul API.
dalet_baseos_monitoring_metrics_consul_service_discovery_token: ""
dalet_baseos_monitoring_metrics_consul_service_discovery_datacenter
dalet_baseos_monitoring_metrics_consul_service_discovery_datacenter
Defines the Consul datacenter name to query.
dalet_baseos_monitoring_metrics_consul_service_discovery_datacenter: "dc1"
dalet_baseos_monitoring_metrics_consul_service_discovery_scrapers
dalet_baseos_monitoring_metrics_consul_service_discovery_scrapers
Optionally defines a list of custom scrapers using Consul services discovery protocol
Scraper format is:
- name: "MY_SCRAPER"
enabled: bool # optional, defaults to true.
bearer_token_file: "/path/to/file" # optional, used to authenticate to service, when required
services: [] # optional, consul service names, list of strings
metrics_path: "/metrics"
clustered: bool # optional, defaults to false;
# defines whether metric collection can be done by multiple peers.
relabel_rules: # optional, list of target relabel configurations
- sources: ["label"] # optional
target: "label" # optional
action: "replace" # optional
replacement: "value" # optional
regex: "REGEX" # optional
separator: ";" # optional
enabled: bool # optional, defaults to true.
metric_relabel_rules: # optional, list of metric relabel configurations
- sources: ["label"] # optional
target: "label" # optional
action: "replace" # optional
replacement: "value" # optional
regex: "REGEX" # optional
separator: ";" # optional
enabled: bool # optional, defaults to true.
dalet_baseos_monitoring_metrics_consul_service_discovery_scrapers: []
dalet_baseos_monitoring_metrics_external_exporters
dalet_baseos_monitoring_metrics_external_exporters
List of optional external exporters to pull metrics from.
Target format is:
- name: "MY_APP"
enabled: bool # optional, defaults to true.
address: 127.0.0.1 # optional
port: 8080
path: "/metrics" # optional
interval: "15s" # optional
clustered: bool # optional, defaults to false;
# defines whether metric collection can be done by multiple peers.
extra_labels: # optional
- key: LABEL_NAME
value: LABEL_VALUE
dalet_baseos_monitoring_metrics_external_exporters: []
dalet_baseos_monitoring_metrics_extra_labels
dalet_baseos_monitoring_metrics_extra_labels
Dictionary of extra labels to be appended to each metrics before being shipped to time-series database(s).
Format is:
label_name: label_value
dalet_baseos_monitoring_metrics_extra_labels: {}
dalet_baseos_monitoring_metrics_blacklisted_regex
dalet_baseos_monitoring_metrics_blacklisted_regex
List of collected metrics regex to be dropped (i.e. not remotely shipped)
Allows saving bandwidth and processing power, minimizing amount of collected timeseries.
dalet_baseos_monitoring_metrics_blacklisted_regex: []
dalet_baseos_monitoring_extra_log_files
dalet_baseos_monitoring_extra_log_files
List of local log files to be monitored and shipped remotely.
dalet_baseos_monitoring_extra_log_files: []
dalet_baseos_monitoring_containers_relabelling_rules
dalet_baseos_monitoring_containers_relabelling_rules
List of extra relabel rules for loki docker source (container, logstream and job are already there)
Rule format is:
- sources: ["__meta_docker_container_label"]
target: 'new_label'
regex: '/(.*)' # optional
dalet_baseos_monitoring_containers_relabelling_rules: []