Compare commits
3 Commits
83178d9a0d
...
monitoring
| Author | SHA1 | Date | |
|---|---|---|---|
| 44519e842b | |||
| 27e692c1ed | |||
| 338e0b0f19 |
6
playbooks/deploy-alertmanager.yml
Normal file
6
playbooks/deploy-alertmanager.yml
Normal file
@ -0,0 +1,6 @@
|
||||
---
|
||||
- name: Deploy Alertmanager
|
||||
hosts: 192.168.0.112 # app3
|
||||
become: true
|
||||
roles:
|
||||
- alertmanager
|
||||
6
playbooks/deploy-loki.yml
Normal file
6
playbooks/deploy-loki.yml
Normal file
@ -0,0 +1,6 @@
|
||||
---
|
||||
- name: Deploy Loki
|
||||
hosts: 192.168.0.112 # app3
|
||||
become: true
|
||||
roles:
|
||||
- loki
|
||||
6
playbooks/deploy-node-red.yml
Normal file
6
playbooks/deploy-node-red.yml
Normal file
@ -0,0 +1,6 @@
|
||||
---
|
||||
- name: Deploy Node-RED
|
||||
hosts: 192.168.0.112 # app3
|
||||
become: true
|
||||
roles:
|
||||
- node-red
|
||||
6
playbooks/deploy-promtail.yml
Normal file
6
playbooks/deploy-promtail.yml
Normal file
@ -0,0 +1,6 @@
|
||||
---
|
||||
- name: Deploy Promtail on all nodes
|
||||
hosts: all # Установим Promtail на все хосты для сбора логов
|
||||
become: true
|
||||
roles:
|
||||
- promtail
|
||||
12
roles/alertmanager/defaults/main.yml
Normal file
12
roles/alertmanager/defaults/main.yml
Normal file
@ -0,0 +1,12 @@
|
||||
---
|
||||
# Alertmanager settings
|
||||
alertmanager_port: 9093
|
||||
alertmanager_config_path: /etc/alertmanager
|
||||
|
||||
# Email notifications (заполнить позже)
|
||||
smtp_host: localhost
|
||||
smtp_from: alertmanager@example.com
|
||||
smtp_to: admin@example.com
|
||||
|
||||
# Webhook для тестирования
|
||||
webhook_url: "http://localhost:9099"
|
||||
33
roles/alertmanager/tasks/main.yml
Normal file
33
roles/alertmanager/tasks/main.yml
Normal file
@ -0,0 +1,33 @@
|
||||
---
|
||||
- name: Create Alertmanager directories
|
||||
file:
|
||||
path: "{{ item }}"
|
||||
state: directory
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0755'
|
||||
loop:
|
||||
- "{{ alertmanager_config_path }}"
|
||||
- /var/lib/alertmanager
|
||||
|
||||
- name: Deploy Alertmanager configuration
|
||||
template:
|
||||
src: alertmanager.yml.j2
|
||||
dest: "{{ alertmanager_config_path }}/alertmanager.yml"
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
|
||||
- name: Run Alertmanager container
|
||||
docker_container:
|
||||
name: alertmanager
|
||||
image: prom/alertmanager:latest
|
||||
state: started
|
||||
restart_policy: always
|
||||
ports:
|
||||
- "{{ alertmanager_port }}:9093"
|
||||
volumes:
|
||||
- "{{ alertmanager_config_path }}/alertmanager.yml:/etc/alertmanager/alertmanager.yml"
|
||||
- /var/lib/alertmanager:/alertmanager
|
||||
command: --config.file=/etc/alertmanager/alertmanager.yml --storage.path=/alertmanager
|
||||
tags: alertmanager
|
||||
52
roles/alertmanager/templates/alertmanager.yml.j2
Normal file
52
roles/alertmanager/templates/alertmanager.yml.j2
Normal file
@ -0,0 +1,52 @@
|
||||
global:
|
||||
# Настройки для уведомлений (можно настроить позже)
|
||||
# smtp_smarthost: 'smtp.gmail.com:587'
|
||||
# smtp_from: 'alertmanager@example.com'
|
||||
# smtp_auth_username: 'user@gmail.com'
|
||||
# smtp_auth_password: 'password'
|
||||
# smtp_require_tls: true
|
||||
|
||||
route:
|
||||
# Основной маршрут - все алерты идут в Node-RED
|
||||
receiver: 'node-red-webhook'
|
||||
group_by: ['alertname', 'severity']
|
||||
group_wait: 10s
|
||||
group_interval: 10s
|
||||
repeat_interval: 1h
|
||||
|
||||
# Вложенные маршруты
|
||||
routes:
|
||||
- match:
|
||||
severity: critical
|
||||
receiver: 'node-red-critical'
|
||||
group_wait: 5s
|
||||
repeat_interval: 10m
|
||||
|
||||
- match:
|
||||
severity: warning
|
||||
receiver: 'node-red-warning'
|
||||
group_wait: 30s
|
||||
repeat_interval: 2h
|
||||
|
||||
receivers:
|
||||
- name: 'node-red-webhook'
|
||||
webhook_configs:
|
||||
- url: 'http://node-red:1880/webhook/alertmanager'
|
||||
send_resolved: true
|
||||
|
||||
- name: 'node-red-critical'
|
||||
webhook_configs:
|
||||
- url: 'http://node-red:1880/webhook/critical'
|
||||
send_resolved: true
|
||||
|
||||
- name: 'node-red-warning'
|
||||
webhook_configs:
|
||||
- url: 'http://node-red:1880/webhook/warning'
|
||||
send_resolved: true
|
||||
|
||||
inhibit_rules:
|
||||
- source_match:
|
||||
severity: 'critical'
|
||||
target_match:
|
||||
severity: 'warning'
|
||||
equal: ['alertname', 'instance']
|
||||
9
roles/loki/defaults/main.yml
Normal file
9
roles/loki/defaults/main.yml
Normal file
@ -0,0 +1,9 @@
|
||||
---
|
||||
# Default port for Loki
|
||||
loki_port: 3100
|
||||
|
||||
# Storage configuration
|
||||
loki_storage_path: /var/lib/loki
|
||||
|
||||
# Retention period
|
||||
loki_retention_period: 720h # 30 дней
|
||||
33
roles/loki/tasks/main.yml
Normal file
33
roles/loki/tasks/main.yml
Normal file
@ -0,0 +1,33 @@
|
||||
---
|
||||
- name: Create Loki directories
|
||||
file:
|
||||
path: "{{ item }}"
|
||||
state: directory
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0755'
|
||||
loop:
|
||||
- /etc/loki
|
||||
- /var/lib/loki
|
||||
|
||||
- name: Deploy Loki configuration
|
||||
template:
|
||||
src: loki-config.yml.j2
|
||||
dest: /etc/loki/loki-config.yml
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
|
||||
- name: Run Loki container
|
||||
docker_container:
|
||||
name: loki
|
||||
image: grafana/loki:latest
|
||||
state: started
|
||||
restart_policy: always
|
||||
ports:
|
||||
- "3100:3100"
|
||||
volumes:
|
||||
- /etc/loki/loki-config.yml:/etc/loki/loki-config.yml
|
||||
- /var/lib/loki:/loki
|
||||
command: -config.file=/etc/loki/loki-config.yml
|
||||
tags: loki
|
||||
33
roles/loki/templates/loki-config.yml.j2
Normal file
33
roles/loki/templates/loki-config.yml.j2
Normal file
@ -0,0 +1,33 @@
|
||||
auth_enabled: false
|
||||
|
||||
server:
|
||||
http_listen_port: 3100
|
||||
grpc_listen_port: 9096
|
||||
|
||||
common:
|
||||
path_prefix: /tmp/loki # Изменяем путь на /tmp для теста
|
||||
storage:
|
||||
filesystem:
|
||||
chunks_directory: /tmp/loki/chunks
|
||||
rules_directory: /tmp/loki/rules
|
||||
replication_factor: 1
|
||||
ring:
|
||||
instance_addr: 127.0.0.1
|
||||
kvstore:
|
||||
store: inmemory
|
||||
|
||||
limits_config:
|
||||
allow_structured_metadata: false
|
||||
|
||||
schema_config:
|
||||
configs:
|
||||
- from: 2020-10-24
|
||||
store: boltdb-shipper
|
||||
object_store: filesystem
|
||||
schema: v11
|
||||
index:
|
||||
prefix: index_
|
||||
period: 24h
|
||||
|
||||
ruler:
|
||||
alertmanager_url: http://alertmanager:9093
|
||||
9
roles/node-red/defaults/main.yml
Normal file
9
roles/node-red/defaults/main.yml
Normal file
@ -0,0 +1,9 @@
|
||||
---
|
||||
# Node-RED settings
|
||||
node_red_port: 1880
|
||||
node_red_data_dir: /var/lib/node-red
|
||||
node_red_image: nodered/node-red:latest
|
||||
|
||||
# Persistence settings
|
||||
node_red_persist_flows: true
|
||||
node_red_enable_projects: false
|
||||
32
roles/node-red/tasks/main.yml
Normal file
32
roles/node-red/tasks/main.yml
Normal file
@ -0,0 +1,32 @@
|
||||
---
|
||||
- name: Create Node-RED data directory with correct permissions
|
||||
file:
|
||||
path: "{{ node_red_data_dir }}"
|
||||
state: directory
|
||||
owner: 1000 # Node-RED контейнер запускается от пользователя 1000
|
||||
group: 1000
|
||||
mode: '0755'
|
||||
|
||||
- name: Run Node-RED container
|
||||
docker_container:
|
||||
name: node-red
|
||||
image: "{{ node_red_image }}"
|
||||
state: started
|
||||
restart_policy: always
|
||||
ports:
|
||||
- "{{ node_red_port }}:1880"
|
||||
volumes:
|
||||
- "{{ node_red_data_dir }}:/data"
|
||||
user: "1000:1000" # Запускаем от правильного пользователя
|
||||
env:
|
||||
NODE_RED_ENABLE_PROJECTS: "{{ 'true' if node_red_enable_projects else 'false' }}"
|
||||
TZ: "UTC"
|
||||
tags: node-red
|
||||
|
||||
- name: Display Node-RED access info
|
||||
debug:
|
||||
msg: |
|
||||
Node-RED is available at:
|
||||
- Web UI: http://{{ inventory_hostname }}:{{ node_red_port }}
|
||||
- API: http://{{ inventory_hostname }}:{{ node_red_port }}/red/api
|
||||
tags: node-red
|
||||
7
roles/promtail/defaults/main.yml
Normal file
7
roles/promtail/defaults/main.yml
Normal file
@ -0,0 +1,7 @@
|
||||
---
|
||||
# Loki connection
|
||||
loki_host: 192.168.0.112
|
||||
loki_port: 3100
|
||||
|
||||
# Promtail settings
|
||||
promtail_port: 9080
|
||||
31
roles/promtail/tasks/main.yml
Normal file
31
roles/promtail/tasks/main.yml
Normal file
@ -0,0 +1,31 @@
|
||||
---
|
||||
- name: Create Promtail directories
|
||||
file:
|
||||
path: /etc/promtail
|
||||
state: directory
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0755'
|
||||
|
||||
- name: Deploy Promtail configuration
|
||||
template:
|
||||
src: promtail-config.yml.j2
|
||||
dest: /etc/promtail/promtail-config.yml
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
|
||||
- name: Run Promtail container (using host network)
|
||||
docker_container:
|
||||
name: promtail
|
||||
image: grafana/promtail:latest
|
||||
state: started
|
||||
restart_policy: always
|
||||
network_mode: host # <-- КЛЮЧЕВОЕ ИЗМЕНЕНИЕ
|
||||
volumes:
|
||||
- /var/log:/var/log:ro
|
||||
- /var/lib/docker/containers:/var/lib/docker/containers:ro
|
||||
- /etc/promtail/promtail-config.yml:/etc/promtail/config.yml
|
||||
command: -config.file=/etc/promtail/config.yml
|
||||
pid_mode: host
|
||||
tags: promtail
|
||||
28
roles/promtail/templates/promtail-config.yml.j2
Normal file
28
roles/promtail/templates/promtail-config.yml.j2
Normal file
@ -0,0 +1,28 @@
|
||||
server:
|
||||
http_listen_port: 9080
|
||||
grpc_listen_port: 0
|
||||
|
||||
positions:
|
||||
filename: /tmp/positions.yaml
|
||||
|
||||
clients:
|
||||
- url: http://localhost:3100/loki/api/v1/push # Теперь localhost работает
|
||||
|
||||
scrape_configs:
|
||||
- job_name: system
|
||||
static_configs:
|
||||
- targets:
|
||||
- localhost
|
||||
labels:
|
||||
job: varlogs
|
||||
__path__: /var/log/*log
|
||||
host: "{{ inventory_hostname }}"
|
||||
|
||||
- job_name: docker
|
||||
static_configs:
|
||||
- targets:
|
||||
- localhost
|
||||
labels:
|
||||
job: docker
|
||||
__path__: /var/lib/docker/containers/*/*log
|
||||
host: "{{ inventory_hostname }}"
|
||||
Reference in New Issue
Block a user