Dalet BaseOS Variables

Here's an exhaustive list of Dalet BaseOS public API variables.

All listed variables are meant to be overridable by platform specifics.

Network Settings

The following variables are meant to tune network settings.

dalet_baseos_network_airgapped

Defines whether the environment is air-gapped, i.e. isolated from public Internet.

Prevents download/installation of external resources (only private OS mirror repositories will be used).

dalet_baseos_network_airgapped: false

dalet_baseos_network_http_proxy

Defines whether the environment requires an HTTP proxy to connect to Internet.

dalet_baseos_network_http_proxy:
  enabled: false
  blackbox: false
  url: "http://my.local.proxy/"
  username: ""
  password: ""
  bypass: [] # list of IP addresses for which direct connection is preferred, bypassing proxy

dalet_baseos_network_ipv6_enabled

Defines whether network IPv6 support should be enabled/disabled from kernel settings.

dalet_baseos_network_ipv6_enabled: false

dalet_baseos_network_dns_systemd_resolution

Defines whether local DNS resolution (and cache) should be handled by systemd (or legacy manual /etc/resolv.conf)

dalet_baseos_network_dns_systemd_resolution: true

dalet_baseos_network_firewall_enabled

Defines whether OS-based software firewall should be enabled.

Setting has no effect if system does not have a public network interface and configured IP address.

dalet_baseos_network_firewall_enabled: false

dalet_baseos_network_firewall_open_tcp_ports

List of TCP ports to be opened if firewall is enabled.

Default policy is deny all but explicitly opened ports.

dalet_baseos_network_firewall_open_tcp_ports: []

dalet_baseos_network_firewall_open_udp_ports

List of UDP ports to be opened if firewall is enabled.

Default policy is deny all but explicitly opened ports.

dalet_baseos_network_firewall_open_udp_ports: []

dalet_baseos_network_ntp_servers

List of NTP servers to be used to synchronize system's time.

Defaults to provider ones if unspecified.

dalet_baseos_network_ntp_servers: []

dalet_baseos_network_failover_enabled

Defines whether network redundancy and virtual IP failover mechanisms must be enabled.

dalet_baseos_network_failover_enabled: false

dalet_baseos_network_failover_settings

Configuration settings for failover mechanisms (useless if not enabled)

dalet_baseos_network_failover_settings:
  # Defines whether virtual MAC addresses (VMAC) must be used (formatted as 00:00:5e:00:00:xx).
  # Useful if not supported by underlying network interface (e.g. VMware vSwitch with MAC address range restriction)
  # Enabled if unspecified.
  use_vmac: true
  # Forces peer-to-peer unicast VRRP communication over multicast.
  # Only supported with 2 peers failover.
  # Disabled if unspecified.
  use_unicast: false
  # Defines whether to enable fast failure detection with point-to-point Bidirectional Forwarding Detection (BFD)
  # Enabled if unspecified.
  use_bfd: true
  # List of hosts used as peers in a highly-available failover setup
  # Recommended to use Ansible special variables like groups['ROLE']
  peers: []
  # List of VRRP trackers to be configured to managed virtual IP addresses.
  trackers: []

Tracker format is:

    - name: MYAPP
      configs:
          # Virtual IP address (VIP) to be assigned, must be unique in your network.
          # Can be used either as a simple string or a list of strings to handle multiple IP addresses.
        - vip: "192.168.0.1"
          # Virtual Router Identification, integer in 1..255 range.
          # Required to be unique on a given L2/L3 segment.
          vrid: "50"
          # Optional: network interface to use for VRRP messages communication.
          # Defaults to private network one if unspecified.
          control_interface: ens4
          # Optional: network interface to use to attach virtual IP address.
          # Defaults to private network one if unspecified.
          interface: ens4
          # Optional: password to authenticate VRRP messages between peers.
          password: ""
          # Optional: hostname from inventory of the expected master host.
          # Overridden when `priority is set.
          primary: 192.168.0.2
          # Optional: allows lower priority machine to maintain the master role and prevent unnecessary VIP flapping.
          # Disabled if unspecified.
          nopreempt: false
          # Optional: enforce priority (1..250). The lower value will be selected as master host.
          priority:  100
          # Optional: set custom route when virtual IP is acquired.
          routes: []
      # Optional: used to determine the condition under which a given instance goes from PRIMARY to BACKUP state.
      # If unset, failover is performed when one server fails (crash, reboot, ...)
      checkscript: "/usr/bin/killall -0 myapp"
      # Optional: path to post-actions script, called at state change.
      notifyscript: "/opt/keepalived-notify-myapp.sh"

Route format is:

             - destination: <destination cidr>
               gateway: <ip>
               metric: <weight>

OS Packages Management

dalet_baseos_packages_mirror_archive_repository

Defines custom OS packages repository to be used for regular packages management.

Defaults to Ubuntu official mirror, if unspecified.

NOTE: One may specify local country mirror location to pull system packages from, speeding up downloads (e.g. 'us.clouds.archive.ubuntu.com')

ISO3166-formatted 2-letters country code, e.g. 'us', 'fr', 'de', 'uk' ...

Allows using a private mirror proxy, if required.

dalet_baseos_packages_mirror_archive_repository: archive.ubuntu.com

dalet_baseos_packages_mirror_security_repository

Defines custom OS packages repository to be used for security packages management.

Defaults to Ubuntu official mirror, if unspecified.

Allows using a private mirror proxy.

dalet_baseos_packages_mirror_security_repository: security.ubuntu.com

dalet_baseos_packages_mirror_dalet_repository

Defines custom OS packages repository to be used for Dalet packages management.

Defaults to Dalet official mirror, if unspecified.

Allows using a private mirror proxy.

dalet_baseos_packages_mirror_dalet_repository: packages.cs.dalet.cloud

dalet_baseos_packages_list_custom

Defines a list of extra system packages to be installed on the platform.

dalet_baseos_packages_list_custom: []

dalet_baseos_packages_enforced_upgrade

Defines whether base OS packages must be upgraded at play or kept to present version.

Enforced upgrades improves security and bug-fixing but might cause unexpected regressions or service restarts.

dalet_baseos_packages_enforced_upgrade: false

OS Tuning

dalet_baseos_tuning_timezone

Defines the system's current timezone for proper time management.

Refer to system's /usr/share/zoneinfo/ content for list of eligible timezones.

It is highly recommended to keep it set to UTC (default, Universal Time Coordinated), making any collaboration between global teams way easier when it comes to troubleshooting.

dalet_baseos_tuning_timezone: UTC

dalet_baseos_hostctl_enabled

Defines whether built-in HostControl utilities must be bundled.

Hostctl provides various scripts and aliases to quickly get system's status and helps with troubleshooting.

NOTE: Disabling it saves a bit of deployment time and comes in handy for sandbox deployments.

dalet_baseos_hostctl_enabled: true

dalet_baseos_tuning_thp_enabled

Define state for Transparent HugePage (THP) support (default: enabled)

THP is an alternative mean of using huge pages for the backing of virtual memory with huge pages that supports the automatic promotion and demotion of page sizes and without the shortcomings of hugetlbfs.

dalet_baseos_tuning_thp_enabled: true

dalet_baseos_sysctl_settings

Defines custom sysctl tuning settings (only works on Linux).

Settings are defined as:

  - name: "SYSCTL_SETTING_NAME"       # e.g. 'net.ipv4.ip_forward'
    value: string
    enabled: bool                     # optional, defaults to 'true'. Condition for setting application.
    set: bool                         # optional, defaults to 'true'. Whether to keep setting persistent.
    state: string                     # optional, defaults to 'present'. Use 'absent' for setting removal.
    reload: bool                      # optional, defaults to 'true'.
dalet_baseos_sysctl_settings: []

OS Users Management

dalet_baseos_users_root_password

Optionally allows setting a password for root/admin system user.

BaseOS SSH server policy strictly prohibits remote root login, making it safe against remote brute-force attacks.

Setting root password can however come in handy when system is stuck and you need physical terminal access to the system as last resort option.

dalet_baseos_users_root_password: "{{ vault_dalet_baseos_users_root_password | default('') }}"

dalet_baseos_users_admin_accounts_enabled

Optionally defines a list of UNIX admin accounts to be created locally on system. List of strings.

Admin accounts:

  • are nominative (one per user).
  • have password-less escalation privileges. sudo command grants root rights.
  • have no password set.
  • require public key SSH authentication.

WARNING: These are system accounts, not application ones.

dalet_baseos_users_admin_accounts_enabled: []

dalet_baseos_users_admin_accounts_disabled

Optionally defines a list of deprecated UNIX admin accounts to be removed locally from the system. List of strings.

dalet_baseos_users_admin_accounts_disabled: []

dalet_baseos_users_admin_accounts_pubkey_dirs

Defines a list of local directories (relative to playbook execution one) where to look for public SSH key files. List of strings.

Multiple directories can be passed for Ansible to look into.

Public SSH certificates must be PEM-formatted and labelled per account.

Example: If jdoe is part of dalet_baseos_users_admin_accounts_enabled list, Ansible will look for a pem-formatted jdoe file in one of the directories provided in dalet_baseos_users_admin_accounts_pubkey_dirs variable. If found, user's public key will be automatically pushed to the system.

dalet_baseos_users_admin_accounts_pubkey_dirs: []

dalet_baseos_users_extra_groups

Optionally defines list of extra UNIX groups to be created. List of strings.

All enabled user admin accounts will be part of the specified groups.

dalet_baseos_users_extra_groups: []

OS Drivers Management

dalet_baseos_drivers_installation_enabled

Defines whether base OS drivers (like nVidia GPU,etc) must be installed.

dalet_baseos_drivers_installation_enabled: true

dalet_baseos_drivers_nvidia_extended_tuning

Defines globally whether base OS needs to apply extended tuning after drivers installation (like tuning of linux kernel, NIC, etc).

dalet_baseos_drivers_nvidia_extended_tuning: false

OS Security & Hardening Settings

dalet_baseos_security_access_trail_enabled

Defines whether local user actions must be tracked for further audit and trailing.

If enabled, all user-input commands and system-calls will be logged.

dalet_baseos_security_access_trail_enabled: false

dalet_baseos_security_application_access_control

Defines whether kernel-based mandatory application access control (MAC) must be enabled.

dalet_baseos_security_application_access_control: true

dalet_baseos_security_auditing_enabled

Defines whether additional security auditing tools should be installed.

Allows for system's security status self-assessment for compliance (e.g. ISO, SOC-2 ...)

dalet_baseos_security_auditing_enabled: false

dalet_baseos_security_auditing_enforced

Defines whether security auditing tool must be run against each play to ensure minimal compliance.

Play will be stopped if enabled and resulting score does NOT meet requested expectation.

dalet_baseos_security_auditing_enforced: false

dalet_baseos_security_auditing_minimal_score

Defines the minimal expected security auditing score we need to reach for proper compliance.

dalet_baseos_security_auditing_minimal_score: 69

dalet_baseos_security_upgrade_enabled

Defines whether OS packages scheduled auto-upgrades should be turned on.

dalet_baseos_security_upgrade_enabled: true

dalet_baseos_security_unattended_update_period

Defines frequency (in days) to update OS package list.

dalet_baseos_security_unattended_update_period: 7

dalet_baseos_security_unattended_upgrade_period

Defines frequency (in days) to upgrade OS packages.

dalet_baseos_security_unattended_upgrade_period: 14

dalet_baseos_security_unattended_autoclean_interval

Defines frequency (in days) to clean leftover OS packages.

dalet_baseos_security_unattended_autoclean_interval: 28

dalet_baseos_security_unattended_upgrade_days_of_the_week

Defines which day(s) of the week should security upgrades be applied.

Example: "Mon,Tue", defaults to everyday.

dalet_baseos_security_unattended_upgrade_days_of_the_week: ~

dalet_baseos_security_unattended_upgrade_hour

Defines which hour of the day should security upgrades be applied.

dalet_baseos_security_unattended_upgrade_hour: 3

dalet_baseos_security_ssh_auth_password_enabled

Defines whether password-based SSH authentication is allowed (pubkey-based authentication only otherwise).

dalet_baseos_security_ssh_auth_password_enabled: false

dalet_baseos_security_ssh_root_login_enabled

Defines whether SSH root login is allowed.

dalet_baseos_security_ssh_root_login_enabled: false

Logs Management

dalet_baseos_logrotate_enabled

Defines whether configuration for logrotate should be enabled.

Keep disabled if you do not intend to apply configuration of logrotate.

dalet_baseos_logrotate_enabled: true

dalet_baseos_logrotate_timer_frequency

Defines timer frequency for log rotation, as to prevent filesystem's completion.

Allowed values: hourly, daily, weekly, monthly, yearly.

dalet_baseos_logrotate_timer_frequency: daily

dalet_baseos_logrotate_count

Defines how many times log files are rotated before being removed.

If count is 0, old versions are removed rather than rotated.

If count is -1, old logs are not removed at all, except they are affected by dalet_baseos_logrotate_max_age_days.

dalet_baseos_logrotate_count: 7

dalet_baseos_logrotate_max_age_days

Instruct logrotate to remove rotated log files older than days.

The age is only checked if the logfile is to be rotated.

dalet_baseos_logrotate_max_age_days: 7

dalet_baseos_logrotate_syslog_extra_files

List of extra syslog-formatted files to be processed by log rotation mechanism.

dalet_baseos_logrotate_syslog_extra_files: []

dalet_baseos_logrotate_max_file_size_gb

Defines maximum log file size (in GB) before log rotation process if enforced.

Defaults to 10% of the root filesystem if unspecified.

dalet_baseos_logrotate_max_file_size_gb: 0

Containerization

dalet_baseos_docker_custom_subnet_size

Customize docker subnet size within docker_custom_ip_range cidr. Default is 24. Variable is only used when docker_custom_ip_range is set.

dalet_baseos_docker_custom_subnet_size: 24

dalet_baseos_containers_enabled

Defines whether support for containerization stack should be enabled (Docker-managed).

Keep disabled if you do not intend to run any container-based application on the system.

dalet_baseos_containers_enabled: true

dalet_baseos_containers_enforced_upgrade

Defines whether containers management daemon should be upgraded at play.

Enforced upgrades allow for more features, security and bug-fixes but implies application restart and downtime.

dalet_baseos_containers_enforced_upgrade: false

dalet_baseos_containers_bridge_network

Defines private IP range used by containers management subsystem for bridged network.

dalet_baseos_containers_bridge_network: "172.17.0.0/16"

dalet_baseos_containers_registries

Defines a list of container registries authorized to log into.

Enabled user admin accounts will feature pre-defined registries credentials for seamless authentication.

Registry list entries to be formatted as:

  - endpoint: string                   # Example registry.acme.com, no http(s):// prefix.
    user: string                       # User name to authenticate with.
    password: string                   # Password to authenticate with.

and declared into:

dalet_baseos_containers_registries: []

Remote Network File Systems

dalet_baseos_mounts_nfs_endpoints

A list of NFS shares to be mounted, e.g:

  - host: "NFS_SERVER_ADDRESS"
    share: "NFS_SHARE_NAME"
    target: "/PATH"
    fstype: "FSTYPE"                  # optional, defaults to 'nfs4' if unspecified
    version: "NFS_VERSION"            # optional, defaults to '4.1' if unspecified
    opts: "KERNEL MOUNT OPTIONS"      # optional

(compatible with box.com and GCP network shares)

dalet_baseos_mounts_nfs_endpoints: []

dalet_baseos_mounts_efs_endpoints

A list of AWS EFS shares to be mounted, e.g:

  - id: "AWS EFS ID"
    region: "AWS EFS REGION"
    target: "/PATH"
    iam: bool                         # optional, defaults to 'false'
    version: "EFS_VERSION"            # optional, defaults to '4.1' if unspecified
dalet_baseos_mounts_efs_endpoints: []

dalet_baseos_mounts_cifs_endpoints

A list of Samba/CIFS shares to be mounted, e.g:

  - host: "CIFS_SERVER_ADDRESS"
    share: "CIFS_SHARE_NAME"
    target: "/PATH"
    username: "USERNAME"
    password: "PASSWORD"
    version: "CIFS_VERSION"            # optional, defaults to '3.0' if unspecified
dalet_baseos_mounts_cifs_endpoints: []

dalet_baseos_mounts_azure_endpoints

A list of Azure Files shares to be mounted, e.g:

  - account: "AZURE_ACCOUNT_ID"
    share: "AZURE_SHARE_NAME"
    target: "/PATH"
    username: "USERNAME"
    password: "PASSWORD"
    version: "CIFS_VERSION"            # optional, defaults to '3.0' if unspecified
dalet_baseos_mounts_azure_endpoints: []

dalet_baseos_mounts_s3_endpoints

A list of S3 buckets to be mounted, e.g:

  - bucket: "BUCKET_NAME"
    provider: "PROVIDER" # currently supported are 'AWS' and 'OVH'
    region: "REGION"
    access_key: "S3_ACCESS_KEY"
    secret: "S3_SECRET_KEY"
    target: "/PATH"                   # optional, mount point on local filesystem, defaults to /var/lib/rclone/BUCKET_NAME if unspecified
dalet_baseos_mounts_s3_endpoints: []

Monitoring and Observability

dalet_baseos_monitoring_enabled

Defines whether to install platform monitoring agents to collect key logs and metrics.

dalet_baseos_monitoring_enabled: true

dalet_baseos_monitoring_high_availability

Defines whether to enable resilient support for metrics collection agents.

When enabled, multiple agents might be in charge of collecting the same metrics, but only at a time will be scraping. Once enabled, requires per-scraper explicit enablement.

dalet_baseos_monitoring_high_availability: false

dalet_baseos_monitoring_high_availability_identifier

Defines the monitoring cluster unique identifier for peers to be part of.

dalet_baseos_monitoring_high_availability_identifier: ""

dalet_baseos_monitoring_high_availability_group

Defines the ansible group name of peers to be part of.

dalet_baseos_monitoring_high_availability_group: ""

dalet_baseos_monitoring_control_tower_enabled

Controls whether platform collected logs and metrics are shipped to Dalet's Control Tower.

dalet_baseos_monitoring_control_tower_enabled: false

dalet_baseos_monitoring_control_tower_tenant_id

Dalet Control Tower's tenant ID, used for platform's identification (must be unique)

It usually consists of $PRODUCT-$PLATFORM-$ENV form, where:

  • PRODUCT is one of amberfin, controltower, cortex, flex, galaxy, instream, kowabunga, pyramid
  • PLATFORM is free name
  • ENV is free name (usually prod or stg)
dalet_baseos_monitoring_control_tower_tenant_id: ""

dalet_baseos_monitoring_control_tower_env

Control Dalet Control Tower's endpoint.

Accepted values are prod and stg.

dalet_baseos_monitoring_control_tower_env: "prod"

dalet_baseos_monitoring_control_tower_mimir_password

Credentials used to ship collected metrics to Dalet's Control Tower.

Differs from staging and production endpoints.

Defaults to a vault-encrypted vault_cct_mimir_password secret variable, if unspecified.

dalet_baseos_monitoring_control_tower_mimir_password: ""

dalet_baseos_monitoring_control_tower_loki_password

Credentials used to ship collected logs to Dalet's Control Tower.

Differs from staging and production endpoints.

Defaults to a vault-encrypted vault_cct_loki_password secret variable, if unspecified.

dalet_baseos_monitoring_control_tower_loki_password: ""

dalet_baseos_monitoring_extra_targets

Optionally defines a list of additional targets to ship collected logs and metrics to (aside from Dalet Control Tower).

Used to specify customer-specific LGTM stacks for example.

Target format is:

  - name: TARGET_NAME
    enabled: bool
    tenant_id: FREE_NAME                        # optional
    prometheus:                                 # optional
      endpoint: "https://metrics.acme.com"
      path:     "/api/v1/push"                  # optional
      username: "METRICS_USERNAME"              # optional
      password: "METRICS_PASSWORD"              # optional
    loki:                                       # optional
      endpoint: "https://logs.acme.com"
      path:     "/loki/api/v1/push"             # optional
      username: "LOGS_USERNAME"                 # optional
      password: "LOGS_PASSWORD"                 # optional
dalet_baseos_monitoring_extra_targets: []

dalet_baseos_monitoring_targets_relabelling_rules

Optionally defines a list of default target relabelling rules after scraping

Rule format is:

  - sources: ["label"]               # optional
    target: "label"                  # optional
    action: "replace"                # optional
    replacement: "value"             # optional
    regex: "REGEX"                   # optional
    separator: ";"                   # optional
    enabled: bool                    # optional, defaults to true.
dalet_baseos_monitoring_targets_relabelling_rules: []

dalet_baseos_monitoring_metrics_relabelling_rules

Optionally defines a list of default metric relabelling rules after scraping

Rule format is:

  - sources: ["label"]               # optional
    target: "label"                  # optional
    action: "replace"                # optional
    replacement: "value"             # optional
    regex: "REGEX"                   # optional
    separator: ";"                   # optional
    enabled: bool                    # optional, defaults to true.
dalet_baseos_monitoring_metrics_relabelling_rules: []

dalet_baseos_monitoring_metrics_builtin_exporters

List of optional enabled built-in Prometheus exporters to pull metrics from.

Currently supported: blackbox, consul, elasticsearch, mongodb, mssql, mysql, redis.

dalet_baseos_monitoring_metrics_builtin_exporters: []

dalet_baseos_monitoring_metrics_mongodb_targets

List of optional MongoDB instances to be monitored.

Requires mongodb to be listed in dalet_baseos_monitoring_metrics_builtin_exporters variable.

Target format is:

  - name: string       # optional, instance identifier, 'mongodb' if unspecified.
    enabled: bool      # optional, defaults to true.
    host: string       # optional, IP address or FQDN, local IP if unspecified.
    port: int          # optional, 27017 if unspecified.
    user: string       # MongoDB admin username to be used.
    password: string   # MongoDB admin password to be used.
    rs: string         # optional, replicaset name, if any.
dalet_baseos_monitoring_metrics_mongodb_targets: []

dalet_baseos_monitoring_metrics_mysql_targets

List of optional MySQL/MariaDB instances to be monitored.

Requires mysql to be listed in dalet_baseos_monitoring_metrics_builtin_exporters variable.

Target format is:

  - name: string       # optional, instance identifier, 'mysql' if unspecified.
    enabled: bool      # optional, defaults to true.
    host: string       # optional, IP address or FQDN, local IP if unspecified.
    port: int          # optional, 3306 if unspecified.
    user: string       # MySQL username to be used.
    password: string   # MySQL password to be used.
dalet_baseos_monitoring_metrics_mysql_targets: []

dalet_baseos_monitoring_metrics_blackbox_targets

List of optional external targets to be scraped for liveness.

Requires blackbox to be listed in dalet_baseos_monitoring_metrics_builtin_exporters variable.

Target format is:

  - name: TARGET_NAME
    enabled: bool   # optional, defaults to true.
    address: string # endpoint to query, e.g. 1.2.3.4 for 'icmp' probe or 'https://acme.com' for 'https' probe
    probe: string   # supported options: 'http' (default), 'https', 'icmp'
dalet_baseos_monitoring_metrics_blackbox_targets: []

dalet_baseos_monitoring_metrics_elasticsearch_targets

List of optional ElasticSearch instances to be monitored.

Requires elasticsearch to be listed in dalet_baseos_monitoring_metrics_builtin_exporters variable.

Target format is:

  - name: string       # optional, instance identifier, 'elasticsearch' if unspecified.
    enabled: bool      # optional, defaults to true.
    host: string       # optional, IP address or FQDN, local IP if unspecified.
    port: int          # optional, 9200 if unspecified.
    user: string       # ElasticSearch admin username to be used.
    password: string   # ElasticSearch admin password to be used.
dalet_baseos_monitoring_metrics_elasticsearch_targets: []

dalet_baseos_monitoring_metrics_redis_targets

List of optional Redis instances to be monitored.

Requires redis to be listed in dalet_baseos_monitoring_metrics_builtin_exporters variable.

Target format is:

  - name: string       # optional, instance identifier, 'redis' if unspecified.
    enabled: bool      # optional, defaults to true.
    host: string       # optional, IP address or FQDN, local IP if unspecified.
    port: int          # optional, 6379 if unspecified.
    user: string       # Redis username to be used.
    password: string   # Redis password to be used.
dalet_baseos_monitoring_metrics_redis_targets: []

dalet_baseos_monitoring_metrics_consul_targets

List of optional Consul instances to be monitored.

Requires consul to be listed in dalet_baseos_monitoring_metrics_builtin_exporters variable.

Target format is:

  - name: string       # optional, instance identifier, 'consul' if unspecified.
    enabled: bool      # optional, defaults to true.
    host: string       # optional, IP address or FQDN, local IP if unspecified.
    port: int          # optional, 8500 if unspecified.
    token: string      # optional, ACL token to pass to HTTP queries to retrieve metrics from Consul instance.
dalet_baseos_monitoring_metrics_consul_targets: []

dalet_baseos_monitoring_metrics_consul_service_discovery_enabled

Defines whether Consul services discovery scraping should be enabled.

dalet_baseos_monitoring_metrics_consul_service_discovery_enabled: false

dalet_baseos_monitoring_metrics_consul_service_discovery_endpoint

Defines Consul server endpoint to be used for services discovery.

dalet_baseos_monitoring_metrics_consul_service_discovery_endpoint: "consul.domain:8500"

dalet_baseos_monitoring_metrics_consul_service_discovery_token

Defines and optional secret token used to access Consul API.

dalet_baseos_monitoring_metrics_consul_service_discovery_token: ""

dalet_baseos_monitoring_metrics_consul_service_discovery_datacenter

Defines the Consul datacenter name to query.

dalet_baseos_monitoring_metrics_consul_service_discovery_datacenter: "dc1"

dalet_baseos_monitoring_metrics_consul_service_discovery_scrapers

Optionally defines a list of custom scrapers using Consul services discovery protocol

Scraper format is:

  - name: "MY_SCRAPER"
    enabled: bool                        # optional, defaults to true.
    bearer_token_file: "/path/to/file"   # optional, used to authenticate to service, when required
    services: []                         # optional, consul service names, list of strings
    metrics_path: "/metrics"
    clustered: bool                      # optional, defaults to false;
                                         # defines whether metric collection can be done by multiple peers.
    relabel_rules:                       # optional, list of target relabel configurations
      - sources: ["label"]               # optional
        target: "label"                  # optional
        action: "replace"                # optional
        replacement: "value"             # optional
        regex: "REGEX"                   # optional
        separator: ";"                   # optional
        enabled: bool                    # optional, defaults to true.
    metric_relabel_rules:                # optional, list of metric relabel configurations
      - sources: ["label"]               # optional
        target: "label"                  # optional
        action: "replace"                # optional
        replacement: "value"             # optional
        regex: "REGEX"                   # optional
        separator: ";"                   # optional
        enabled: bool                    # optional, defaults to true.
dalet_baseos_monitoring_metrics_consul_service_discovery_scrapers: []

dalet_baseos_monitoring_metrics_external_exporters

List of optional external exporters to pull metrics from.

Target format is:

    - name: "MY_APP"
      enabled: bool       # optional, defaults to true.
      address: 127.0.0.1  # optional
      port: 8080
      path: "/metrics"    # optional
      interval: "15s"     # optional
      clustered: bool     # optional, defaults to false;
                          # defines whether metric collection can be done by multiple peers.
      extra_labels:       # optional
        - key: LABEL_NAME
          value: LABEL_VALUE
dalet_baseos_monitoring_metrics_external_exporters: []

dalet_baseos_monitoring_metrics_extra_labels

Dictionary of extra labels to be appended to each metrics before being shipped to time-series database(s).

Format is:

label_name: label_value
dalet_baseos_monitoring_metrics_extra_labels: {}

dalet_baseos_monitoring_metrics_blacklisted_regex

List of collected metrics regex to be dropped (i.e. not remotely shipped)

Allows saving bandwidth and processing power, minimizing amount of collected timeseries.

dalet_baseos_monitoring_metrics_blacklisted_regex: []

dalet_baseos_monitoring_extra_log_files

List of local log files to be monitored and shipped remotely.

dalet_baseos_monitoring_extra_log_files: []

dalet_baseos_monitoring_containers_relabelling_rules

List of extra relabel rules for loki docker source (container, logstream and job are already there)

Rule format is:

   - sources: ["__meta_docker_container_label"]
     target: 'new_label'
     regex: '/(.*)' # optional
dalet_baseos_monitoring_containers_relabelling_rules: []