Available with limitations in: Ultimate/EE
The module lifecycle stage: Generally available version
The module has requirements for installation
Requirements
To the Deckhouse Platform version: 1.68 and above.
Conversions
The module is configured using the ModuleConfig resource, the schema of which contains a version number. When you apply an old version of the ModuleConfig schema in a cluster, automatic transformations are performed. To manually update the ModuleConfig schema version, the following steps must be completed sequentially for each version:
-
Updates from version 1 to 2:
Remove deprecated monitoring.collector.inlet and ui.postgres.backup.dir fields. Normalize storage.traces.logLevel to lowercase.
-
Updates from version 2 to 3:
Convert old internal PostgreSQL resources settings to the predefined instanceSize.
-
Updates from version 3 to 4:
Remove the resources settings for the metrics, logs, and traces etcd, for the Ceph OSD, and the ingester CPU limits: the module manages these resources itself, and manually specified values had no effect.
Parameters
Schema version: 4
-
-
objectsettings.generalGeneral configuration options.
Default:
{}-
stringsettings.general.baseDomain
Required value
Base domain for all components of the Observability Platform.
This domain is used to access the Observability Platform UI. There are also several subdomains which are used for certain components.
Pattern:
^[a-zA-Z0-9]([a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?(\.[a-zA-Z0-9]([a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?)*$ -
stringsettings.general.clusterBaseDomainThe domain name of the cluster which is used to distinguish between clusters in multi-cluster environments.
Pattern:
^([a-zA-Z0-9]([a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?(\.[a-zA-Z0-9]([a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?)*)?$ -
stringsettings.general.clusterName
Required value
The name of the cluster which is used to distinguish between clusters in multi-cluster environments. -
objectsettings.general.clusterNeighborsNeighbor clusters clusters in disaster recovery mode in
<clusterName>: <clusterDomain>format.Example:
dc2: msk.example.com dc3: spb.example.com -
objectsettings.general.tls
Configuration options for specifying certificates for HTTPS connections across all components of the Deckhouse Observability Platform module.
You can either provide your own certificates or use cert-manager to issue them.
Default:
{}-
stringsettings.general.tls.ca
The root certificate required if the certificate is issued by a non-public certification authority (CA).
It is used to verify inter-service requests and requests to external resources over HTTPS where the certificates are issued by the same CA.
-
stringsettings.general.tls.crt
The certificate provided for using a custom certificate on all domains of the Deckhouse Observability Platform.
The certificate must present
general.baseDomain(and, independently,general.clusterBaseDomain, if set) as DNS names in its Subject Alternative Name (SAN) extension: either the wildcard pair<domain>and*.<domain>, or the domain together with itsapi,update,logs,collector, ands3subdomains. Otherwise, the module fails to start with anError validating TLS-certificate: ...error. See SSL Certificate Requirements for the full list of names and an explanation. Specifying a Common Name is not required.This field is incompatible with the
issuerfield. You must specify eitherissueror bothcrtandkey. -
stringsettings.general.tls.issuer
The issuer of the certificate. For all domains of the Deckhouse Observability Platform, the certificate can be issued using cert-manager.
This field is not compatible with the
crtandkeyfields. You must specify eitherissueror bothcrtandkey.Default:
letsencryptAllowed values:
letsencrypt,digitalocean,cloudflare -
stringsettings.general.tls.key
The private key associated with the certificate, used for setting up custom certificates in the Deckhouse Observability Platform.
This field is incompatible with the
issuerfield. You must specify eitherissueror bothcrtandkey.
-
-
-
stringsettings.ingressClass
The class of the Ingress controller used for the Observability Platform components.
An optional parameter; by default, the
modules.ingressClassglobal value is used.Pattern:
^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$ -
objectsettings.monitoringOptions related to the configuration of components responsible for monitoring.
Default:
{}-
objectsettings.monitoring.agent
Default:
{}-
stringsettings.monitoring.agent.pgClientTableNameThe table name used by the PostgreSQL client.
Default:
okmeter -
stringsettings.monitoring.agent.productNameThe name of the monitoring agent product.
Default:
okagent
-
-
objectsettings.monitoring.agentUpdaterOptions related to the configuration of the component used for managing the update process of the Deckhouse Observability platform agent.
Default:
{}-
objectsettings.monitoring.agentUpdater.configConfiguration for the agent updater.
Default:
{}
-
-
objectsettings.monitoring.collectorOptions related to the configuration of the metrics collector.
Default:
{}-
integersettings.monitoring.collector.maxConnectionAllowMaximum number of simultaneous agent connections a single metrics-collector pod accepts. Increase it when the collector HorizontalPodAutoscaler is already bounded by the number of nodes and connection utilization stays high.
Default:
2000Allowed values:
100 <= X <= 100000 -
stringsettings.monitoring.collector.storageClassThe StorageClass used to create volumes for the metrics collector. The volume lifetime is the same as the pod lifetime, so you can use the StorageClass from LocalPathProvisioner.
-
-
objectsettings.monitoring.customDomainCustom domain settings for the monitoring module.
Default:
{}-
stringsettings.monitoring.customDomain.baseDomainCustom domain settings for the monitoring module.
Default:
‘’Pattern:
^([a-zA-Z0-9]([a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?(\.[a-zA-Z0-9]([a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?)*)?$ -
stringsettings.monitoring.customDomain.collectorDomainSpecify the domain for the metrics collector.
Default:
‘’Pattern:
^([a-zA-Z0-9]([a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?(\.[a-zA-Z0-9]([a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?)*)?$ -
objectsettings.monitoring.customDomain.tlsTLS certificate settings for the monitoring collector and related endpoints.
Default:
{}-
stringsettings.monitoring.customDomain.tls.ca
-
stringsettings.monitoring.customDomain.tls.crt
-
stringsettings.monitoring.customDomain.tls.issuer
-
stringsettings.monitoring.customDomain.tls.key
-
-
-
objectsettings.monitoring.dockerRegistryOptions related to the configuration of the container registry used for publishing new images with new versions of the Deckhouse observability platform agent.
Default:
{}-
booleansettings.monitoring.dockerRegistry.enabledIndicates whether the Docker Registry components should be installed.
Default:
false
-
-
booleansettings.monitoring.enabledAllows enabling or disabling components necessary for collecting and displaying metrics using opAgent.
Default:
false
-
-
objectsettings.storageOptions related to the configuration of components responsible for data ingestion and storage.
Default:
{}-
objectsettings.storage.cephOptions related to the configuration of Ceph.
Default:
{}-
stringsettings.storage.ceph.configOverride
-
objectsettings.storage.ceph.mgrOptions related to the configuration of Ceph MGR.
Default:
{}-
objectsettings.storage.ceph.mgr.resourcesResource management options for the Ceph MGR pods.
Default:
{}Example:
limits: memory: 1Gi requests: cpu: 500M memory: 1Gi-
objectsettings.storage.ceph.mgr.resources.limitsResource limits options for Ceph MGR pods.
-
settings.storage.ceph.mgr.resources.limits.cpuMaximum amount of CPU per pod for Ceph MGR pods.
-
settings.storage.ceph.mgr.resources.limits.memoryMaximum amount of memory per pod for Ceph MGR pods.
-
-
objectsettings.storage.ceph.mgr.resources.requestsResource requests options for Ceph MGR pods.
-
settings.storage.ceph.mgr.resources.requests.cpuMinimum amount of CPU per pod for Ceph MGR pods.
-
settings.storage.ceph.mgr.resources.requests.memoryMinimum amount of memory per pod for the ceph-mgr.
-
-
-
-
objectsettings.storage.ceph.monOptions related to the configuration of Ceph monitors.
Default:
{}-
objectsettings.storage.ceph.mon.resourcesResource management options for the Ceph monitors pods.
Default:
{}Example:
limits: cpu: 250m memory: 512Mi requests: cpu: 55m memory: 256Mi-
objectsettings.storage.ceph.mon.resources.limitsConfiguring CPU and memory limits Ceph monitors pods.
-
settings.storage.ceph.mon.resources.limits.cpuConfiguring CPU limits.
-
settings.storage.ceph.mon.resources.limits.memoryConfiguring memory limits.
-
-
objectsettings.storage.ceph.mon.resources.requestsResource requests options for Ceph monitors pods.
-
settings.storage.ceph.mon.resources.requests.cpuConfiguring CPU requests.
-
settings.storage.ceph.mon.resources.requests.memoryConfiguring memory requests.
-
-
-
stringsettings.storage.ceph.mon.storageClassSpecifies the StorageClass to be used for the persistent volume (PV). If not specified, the first available StorageClass from the list of StorageClasses applicable to the node group where the Ceph components will be deployed will be used.
-
stringsettings.storage.ceph.mon.storageSize
Defines the size of the persistent volume (PV) to be created for Ceph monitor.
The size should be specified using standard storage units (e.g., Gi for Gibibytes, Ti for Tebibytes, Mi for Mebibytes).
Pattern:
^[0-9]+(\.[0-9]+)?(E|P|T|G|M|k|Ei|Pi|Ti|Gi|Mi|Ki)?$
-
-
objectsettings.storage.ceph.objectStoreOptions related to Ceph object store pools.
Default:
{}-
stringsettings.storage.ceph.objectStore.poolType
Specifies the data pool type for the Ceph object store.
Supported values:
Replicated— store object data in a replicated pool.ErasureCoded— store object data in a 3+2 erasure-coded pool. This mode requires at least 5 Ceph nodes.
Default:
ReplicatedAllowed values:
Replicated,ErasureCoded
-
-
objectsettings.storage.ceph.osdOptions related to the configuration of Ceph object storage daemons.
Default:
{}-
integersettings.storage.ceph.osd.countSpecifies the number of OSDs (Object Storage Daemons) to be created.
-
stringsettings.storage.ceph.osd.storageClass
Required value
Specifies the StorageClass to be used for the persistent volume (PV).
If not specified, the first available StorageClass from the list of StorageClasses applicable to the node group where the Ceph components will be deployed will be used.
-
stringsettings.storage.ceph.osd.storageSize
Defines the size of the persistent volume (PV) to be created for Ceph object storage daemons.
The size should be specified using standard storage units (e.g., Gi for Gibibytes, Ti for Tebibytes, Mi for Mebibytes).
Pattern:
^[0-9]+(\.[0-9]+)?(E|P|T|G|M|k|Ei|Pi|Ti|Gi|Mi|Ki)?$
-
-
objectsettings.storage.ceph.rgwOptions related to the configuration of Ceph object gateway.
Default:
{}-
objectsettings.storage.ceph.rgw.resourcesResource management options for the Ceph RGW pods.
Default:
{}Example:
resources: limits: cpu: 250m memory: 512Mi requests: cpu: 55m memory: 256Mi-
objectsettings.storage.ceph.rgw.resources.limitsResource limits options for Ceph RGW pods.
-
settings.storage.ceph.rgw.resources.limits.cpuConfiguring CPU limits.
-
settings.storage.ceph.rgw.resources.limits.memoryConfiguring memory limits.
-
-
objectsettings.storage.ceph.rgw.resources.requestsResource requests options for Ceph RGW pods.
-
settings.storage.ceph.rgw.resources.requests.cpuConfiguring CPU requests.
-
settings.storage.ceph.rgw.resources.requests.memoryConfiguring memory requests.
-
-
-
-
-
objectsettings.storage.logsOptions related to the configuration of components responsible for log collection and storage.
Default:
{}-
stringsettings.storage.logs.cacheSize
Size of your memcached servers.
Small- 1 Pod with 1Gi of Memory.Medium- 3 Pods with 2Gi of Memory.Large- 3 Pods with 4Gi of Memory.
Default:
SmallAllowed values:
Small,Medium,Large -
objectsettings.storage.logs.compactorOptions related to the configuration of the Compactor.
Default:
{}-
stringsettings.storage.logs.compactor.storageClassThe StorageClass used for PersistentVolumes (PV) by the Compactor.
-
stringsettings.storage.logs.compactor.storageSizeThe size of the PersistentVolume (PV) allocated for the Compactor.
Default:
50GiPattern:
^[0-9]+(\.[0-9]+)?(Ei|Pi|Ti|Gi|Mi)?$
-
-
stringsettings.storage.logs.defaultStorageClassStorageClass that is used for all components involved in logs storage, unless a specific StorageClass is defined for a component.
-
booleansettings.storage.logs.enabledEnable or disable the log components.
Default:
false -
objectsettings.storage.logs.etcdOptions related to the configuration of etcd.
Default:
{}-
stringsettings.storage.logs.etcd.storageClassThe StorageClass used for PersistentVolumes (PV) by the etcd.
-
stringsettings.storage.logs.etcd.storageSizeThe size of the PersistentVolume (PV) allocated for the etcd.
Default:
2GiPattern:
^[0-9]+(\.[0-9]+)?(Ei|Pi|Ti|Gi|Mi)?$
-
-
objectsettings.storage.logs.indexCuratorIndex Curator settings.
Default:
{}-
stringsettings.storage.logs.indexCurator.logLevelThe log level for index curator, which determines the verbosity of log messages.
Default:
infoAllowed values:
debug,info,warn,error
-
-
objectsettings.storage.logs.indexGatewayOptions related to the configuration of loki’s index gateway.
Default:
{}-
stringsettings.storage.logs.indexGateway.storageClassThe StorageClass used for PersistentVolumes (PV) by the index gateway.
-
stringsettings.storage.logs.indexGateway.storageSizeThe size of the PersistentVolume (PV) allocated for the index gateway.
Default:
50GiPattern:
^[0-9]+(\.[0-9]+)?(Ei|Pi|Ti|Gi|Mi)?$
-
-
objectsettings.storage.logs.ingesterOptions related to the configuration of the Ingester.
Default:
{}-
objectsettings.storage.logs.ingester.resourcesResource management options for the Ingester pods.
Default:
{}-
objectsettings.storage.logs.ingester.resources.limitsResource limits settings for the Ingester pods.
Default:
{}-
settings.storage.logs.ingester.resources.limits.memoryConfiguring memory limits.
Default:
4Gi
-
-
objectsettings.storage.logs.ingester.resources.requestsResource requests settings for the Ingester pods.
Default:
{}-
settings.storage.logs.ingester.resources.requests.cpuConfiguring CPU requests.
Default:
50m -
settings.storage.logs.ingester.resources.requests.memoryConfiguring memory requests.
Default:
512Mi
-
-
-
stringsettings.storage.logs.ingester.storageClassThe StorageClass used for PersistentVolumes (PV) by the Ingester.
-
stringsettings.storage.logs.ingester.storageSizeThe size of the PersistentVolume (PV) allocated for the Ingester.
Default:
50GiPattern:
^[0-9]+(\.[0-9]+)?(Ei|Pi|Ti|Gi|Mi)?$
-
-
stringsettings.storage.logs.logLevelThe log level for loki, which determines the verbosity of log messages.
Default:
infoAllowed values:
debug,info,warn,error -
objectsettings.storage.logs.rulerOptions related to the configuration of the ruler.
Default:
{}-
stringsettings.storage.logs.ruler.storageClassThe StorageClass used for PersistentVolumes (PV) by the ruler.
-
stringsettings.storage.logs.ruler.storageSizeThe size of the PersistentVolume (PV) allocated for the ruler.
Default:
50GiPattern:
^[0-9]+(\.[0-9]+)?(Ei|Pi|Ti|Gi|Mi)?$
-
-
-
objectsettings.storage.metricsOptions related to the configuration of components responsible for metrics collection and storage.
Default:
{}-
objectsettings.storage.metrics.alertmanagerOptions related to the configuration of the Alertmanager.
Default:
{}-
stringsettings.storage.metrics.alertmanager.storageClassThe StorageClass used for PersistentVolumes (PV) by the Alertmanager.
-
stringsettings.storage.metrics.alertmanager.storageSizeThe size of the PersistentVolume (PV) allocated for the Alertmanager.
Default:
2GiPattern:
^[0-9]+(\.[0-9]+)?(Ei|Pi|Ti|Gi|Mi)?$
-
-
stringsettings.storage.metrics.cacheSize
Size of your memcached servers.
Small- 1 Pod with 1Gi of Memory.Medium- 3 Pods with 2Gi of Memory.Large- 3 Pods with 4Gi of Memory.
Default:
SmallAllowed values:
Small,Medium,Large -
objectsettings.storage.metrics.compactorOptions related to the configuration of the Compactor.
Default:
{}-
integersettings.storage.metrics.compactor.concurrencyNumber of concurrent compaction jobs.
Default:
1 -
stringsettings.storage.metrics.compactor.storageClassThe StorageClass used for PersistentVolumes (PV) by the Compactor.
-
stringsettings.storage.metrics.compactor.storageSizeThe size of the PersistentVolume (PV) allocated for the Compactor.
Default:
100GiPattern:
^[0-9]+(\.[0-9]+)?(Ei|Pi|Ti|Gi|Mi)?$
-
-
stringsettings.storage.metrics.defaultStorageClassStorageClass that is used for all components involved in metrics storage, unless a specific StorageClass is defined for a component.
-
objectsettings.storage.metrics.etcdOptions related to the configuration of etcd used by metrics storage components.
Default:
{}-
stringsettings.storage.metrics.etcd.storageClassThe StorageClass used for PersistentVolumes (PV) by the etcd.
-
stringsettings.storage.metrics.etcd.storageSizeThe size of the PersistentVolume (PV) allocated for the etcd.
Default:
2GiPattern:
^[0-9]+(\.[0-9]+)?(Ei|Pi|Ti|Gi|Mi)?$
-
-
objectsettings.storage.metrics.ingesterOptions related to the configuration of the Ingester.
Default:
{}-
objectsettings.storage.metrics.ingester.resourcesResource management options for the Ingester pods.
Default:
{}-
objectsettings.storage.metrics.ingester.resources.limitsResource limits settings for Ingester pods.
Default:
{}-
settings.storage.metrics.ingester.resources.limits.memoryMaximum amount of memory per pod for the Ingester.
Default:
4Gi
-
-
objectsettings.storage.metrics.ingester.resources.requestsResource requests settings for Ingester pods.
Default:
{}-
settings.storage.metrics.ingester.resources.requests.cpuMinimum amount of cpu per pod for the Ingester.
Default:
100m -
settings.storage.metrics.ingester.resources.requests.memoryMinimum amount of memory per pod for the Ingester.
Default:
1Gi
-
-
-
stringsettings.storage.metrics.ingester.storageClassThe StorageClass used for PersistentVolumes (PV) by the Ingester.
-
stringsettings.storage.metrics.ingester.storageSizeThe size of the PersistentVolume (PV) allocated for the Ingester.
Default:
50GiPattern:
^[0-9]+(\.[0-9]+)?(Ei|Pi|Ti|Gi|Mi)?$
-
-
stringsettings.storage.metrics.logLevelThe log level for metrics, which determines the verbosity of log messages.
Default:
infoAllowed values:
debug,info,warn,error -
objectsettings.storage.metrics.storeGatewayOptions related to the configuration of the Store-gateway.
Default:
{}-
stringsettings.storage.metrics.storeGateway.storageClassThe StorageClass used for PersistentVolumes (PV) by the Store-gateway.
-
stringsettings.storage.metrics.storeGateway.storageSizeThe size of the PersistentVolume (PV) allocated for the Store-gateway.
Default:
50GiPattern:
^[0-9]+(\.[0-9]+)?(Ei|Pi|Ti|Gi|Mi)?$
-
-
-
objectsettings.storage.reconcilerOptions related to the configuration of the reconciler.
Default:
{}-
stringsettings.storage.reconciler.logLevelThe log level for the reconciler, which determines the verbosity of log messages.
Default:
infoAllowed values:
debug,info,warn,error
-
-
objectsettings.storage.tracesOptions related to the configuration of components responsible for traces collection and storage.
Default:
{}-
stringsettings.storage.traces.cacheSize
Size of your memcached servers.
Small- 1 Pod with 1Gi of Memory.Medium- 3 Pods with 2Gi of Memory.Large- 3 Pods with 4Gi of Memory.
Default:
SmallAllowed values:
Small,Medium,Large -
objectsettings.storage.traces.compactorOptions related to the configuration of the Compactor.
Default:
{}-
stringsettings.storage.traces.compactor.storageClassThe StorageClass used for PersistentVolumes (PV) by the Compactor.
-
stringsettings.storage.traces.compactor.storageSizeThe size of the PersistentVolume (PV) allocated for the Compactor.
Default:
50GiPattern:
^[0-9]+(\.[0-9]+)?(Ei|Pi|Ti|Gi|Mi)?$
-
-
stringsettings.storage.traces.defaultStorageClassStorageClass that is used for all components involved in traces storage, unless a specific StorageClass is defined for a component.
-
booleansettings.storage.traces.enabledEnable or disable the traces components.
Default:
false -
objectsettings.storage.traces.etcdOptions related to the configuration of etcd.
Default:
{}-
stringsettings.storage.traces.etcd.storageClassThe StorageClass used for PersistentVolumes (PV) by the etcd.
-
stringsettings.storage.traces.etcd.storageSizeThe size of the PersistentVolume (PV) allocated for the etcd.
Default:
2GiPattern:
^[0-9]+(\.[0-9]+)?(Ei|Pi|Ti|Gi|Mi)?$
-
-
objectsettings.storage.traces.ingesterOptions related to the configuration of the Ingester.
Default:
{}-
objectsettings.storage.traces.ingester.resourcesResource management options for the Ingester pods.
Default:
{}-
objectsettings.storage.traces.ingester.resources.limits
Default:
{}-
settings.storage.traces.ingester.resources.limits.memoryConfiguring memory limits.
Default:
4Gi
-
-
objectsettings.storage.traces.ingester.resources.requests
Default:
{}-
settings.storage.traces.ingester.resources.requests.cpuConfiguring CPU requests.
Default:
50m -
settings.storage.traces.ingester.resources.requests.memoryConfiguring memory requests.
Default:
512Mi
-
-
-
stringsettings.storage.traces.ingester.storageClassThe StorageClass used for PersistentVolumes (PV) by the Ingester.
-
stringsettings.storage.traces.ingester.storageSizeThe size of the PersistentVolume (PV) allocated for the Ingester.
Default:
50GiPattern:
^[0-9]+(\.[0-9]+)?(Ei|Pi|Ti|Gi|Mi)?$
-
-
stringsettings.storage.traces.logLevelThe log level for traces, which determines the verbosity of log messages.
Default:
infoAllowed values:
debug,info,warn,error
-
-
objectsettings.storage.usageCollectorOptions related to the configuration of the usage collector.
Default:
{}-
stringsettings.storage.usageCollector.logLevelThe log level for the usage collector, which determines the verbosity of log messages.
Default:
infoAllowed values:
debug,info,warn,error
-
-
-
objectsettings.uiOptions related to the configuration of user interface components.
Default:
{}-
objectsettings.ui.authOptions related to the configuration of authentication components.
Default:
{}-
stringsettings.ui.auth.afterLogoutUrlThe URL to redirect to after the user logs out.
-
stringsettings.ui.auth.clientId
The client ID registered with the OIDC provider.
This ID is used to identify the client application during the authentication process.
-
stringsettings.ui.auth.clientSecretThe client secret associated with the client ID, used for authenticating the client application with the OIDC provider.
-
stringsettings.ui.auth.groupsParamNameThe name of the parameter in the provider response containing the list of user groups, defaults to
groups. -
stringsettings.ui.auth.issuer
The issuer URL for the OIDC provider.
This is typically the base URL of the provider where the OIDC metadata can be found.
-
stringsettings.ui.auth.mode
Authentication mode used for logging into the ui:
default- email address and password are used for authentication;externalAuth- use an oidc provider for authentication.
Default:
defaultAllowed values:
default,externalAuth -
stringsettings.ui.auth.providerThe oidc provider for the external auth mode. If option
loginis used, then Keycloak is used.Default:
dexAllowed values:
dex,okta,adfs,login
-
-
stringsettings.ui.clusterBootstrapToken
Required value
Token used for joining multiple deckhouse observability platform installations into a cluster. -
objectsettings.ui.configValidatorOptions related to the configuration validator component that checks module configuration.
Default:
{}-
stringsettings.ui.configValidator.logLevelThe log level for the configuration validator, which determines the verbosity of log messages.
Default:
infoAllowed values:
info,warn,error,debug
-
-
objectsettings.ui.grafanaOptions related to the configuration of grafana.
Default:
{}-
stringsettings.ui.grafana.logLevelThe log level for Grafana, which determines the verbosity of log messages.
Default:
infoAllowed values:
info,warn,error,debug
-
-
stringsettings.ui.localeLanguage to use for the interface.
Allowed values:
ru,en -
objectsettings.ui.postgresSettings for configuring the PostgreSQL database used by the UI component.
Default:
{}-
objectsettings.ui.postgres.backupSettings related to database backups.
Default:
{}-
booleansettings.ui.postgres.backup.enabledEnable or disable database backups.
Default:
true -
booleansettings.ui.postgres.backup.includeAuditLogsInclude audit logs in the backups.
Default:
false -
numbersettings.ui.postgres.backup.keepDaysNumber of days to retain the backups.
Default:
3 -
objectsettings.ui.postgres.backup.s3Configuration of the external s3 storage of the backup.
Default:
{}-
stringsettings.ui.postgres.backup.s3.accessKeyThe access key used for authorization to the bucket.
-
stringsettings.ui.postgres.backup.s3.bucketThe bucket name.
-
booleansettings.ui.postgres.backup.s3.enabledEnable or disable backups to an S3-compatible storage.
Default:
false -
stringsettings.ui.postgres.backup.s3.hostUrl pointing to the bucket.
-
stringsettings.ui.postgres.backup.s3.secretKeyThe secret key used for authorization to the bucket.
-
-
stringsettings.ui.postgres.backup.scheduleDefine a schedule for the backups using a cron expression.
Default:
0 * * * *
-
-
objectsettings.ui.postgres.externalCredentials and connection details for using an external PostgreSQL database.
-
stringsettings.ui.postgres.external.dbName of the database on the external PostgreSQL server.
-
booleansettings.ui.postgres.external.fromSecretIf set to
true, credentials will be read from a Kubernetes Secret located in thed8-observability-platformnamespace and namedcustom-postgres-credentials.Default:
true -
stringsettings.ui.postgres.external.hostHost address of the external PostgreSQL server.
-
stringsettings.ui.postgres.external.passwordPassword for authenticating with the external PostgreSQL server.
-
stringsettings.ui.postgres.external.portPort on which the external PostgreSQL server is listening.
-
stringsettings.ui.postgres.external.sslmodeSSL mode used for connecting to the external PostgreSQL server.
Default:
requireAllowed values:
disable,allow,prefer,require,verify-ca,verify-full -
stringsettings.ui.postgres.external.userUsername for authenticating with the external PostgreSQL server.
-
-
objectsettings.ui.postgres.internalConfiguration settings for the internal PostgreSQL cluster.
Default:
{}-
stringsettings.ui.postgres.internal.instanceSize
Size of PostgreSQL pods in cluster:
Light- 2 pods with 1 CPU and 2 GiB memory requests and limits.Small- 2 pods with 2 CPU and 4 GiB memory requests and limits.Medium- 2 pods with 4 CPU and 8 GiB memory requests and limits.Large- 2 pods with 8 CPU and 16 GiB memory requests and limits.
Default:
SmallAllowed values:
Light,Small,Medium,Large -
objectsettings.ui.postgres.internal.storageStorage configuration for the PostgreSQL cluster.
Default:
{}-
stringsettings.ui.postgres.internal.storage.classStorageClass used by the PostgreSQL cluster.
-
stringsettings.ui.postgres.internal.storage.sizeStorage size allocated for the PostgreSQL cluster.
Default:
50Gi
-
-
-
stringsettings.ui.postgres.mode
Configure whether to use the internal or an external postgres server.
When using an external postgres database the following extensions have to be enabled:
pgcrypto;citext- for the Deckhouse observability platform database;btree_gin- for the Deckhouse observability platform alertgate database.
Default:
InternalAllowed values:
Internal,External
-
-
stringsettings.ui.secretKeyBase
Required value
Random string used for data encryption and verification. -
objectsettings.ui.secretsStore
Integration with a HashiCorp Vault-compatible secrets store (Deckhouse Stronghold or HashiCorp Vault) for web monitoring.
Site configurations reference secrets as
${secret:<path>#<key>}instead of plain-text passwords and tokens. The backend reads the values from a KV v2 secrets engine only when it renders the configuration for gogomonia agents; values are never stored in the platform database, returned by the API or written to the audit log.A reference is resolved into a request the agents send, so being able to edit the sites of a project (roles
userandadmin, an API token with web monitoring access) is equivalent to being able to read every secret that project may reference.Default:
{}-
stringsettings.ui.secretsStore.addressURL of the secrets store API, for example
https://stronghold.d8-stronghold.svc:8200. Required whenenabledistrue. -
objectsettings.ui.secretsStore.authHow the backend authenticates in the secrets store.
Default:
{}-
objectsettings.ui.secretsStore.auth.kubernetesSettings of the Kubernetes auth method.
Default:
{}-
stringsettings.ui.secretsStore.auth.kubernetes.audienceAudience of the projected ServiceAccount token. Set it only if the auth role in the secrets store has an explicit
audience; the values must match. Leave empty to use the default Kubernetes API server audience. -
booleansettings.ui.secretsStore.auth.kubernetes.grantTokenReviewBind the ServiceAccount
backend-secretsto thesystem:auth-delegatorClusterRole. Required when the secrets store validates client tokens with the token of the client itself (auth/<path>/configwithouttoken_reviewer_jwt), which is the usual case for an external HashiCorp Vault. Not needed for Deckhouse Stronghold running in the same cluster.Default:
false -
stringsettings.ui.secretsStore.auth.kubernetes.pathMount path of the Kubernetes auth method in the secrets store. Deckhouse Stronghold pre-configures
kubernetes_localfor the cluster it runs in; HashiCorp Vault useskubernetesby default.Default:
kubernetes_local -
stringsettings.ui.secretsStore.auth.kubernetes.roleName of the Kubernetes auth role bound to the ServiceAccount
backend-secretsof thed8-observability-platformnamespace. Required whenmethodisKubernetes.
-
-
stringsettings.ui.secretsStore.auth.method
Authentication method:
Kubernetes— Kubernetes auth method: the backend pod logs in with the projected token of its ServiceAccountbackend-secrets;Token— a static token stored in a Kubernetes Secret.
Default:
KubernetesAllowed values:
Kubernetes,Token -
objectsettings.ui.secretsStore.auth.tokenSettings of the static token authentication.
Default:
{}-
stringsettings.ui.secretsStore.auth.token.secretNameName of the Kubernetes Secret in the
d8-observability-platformnamespace holding the token in thetokenkey.Default:
secrets-store-token
-
-
-
stringsettings.ui.secretsStore.caCertPEM-encoded CA certificate used to verify the TLS certificate of the secrets store. Leave empty to use the system CA bundle.
-
booleansettings.ui.secretsStore.enabledEnable secret references in web monitoring configurations.
Default:
false -
objectsettings.ui.secretsStore.kvLocation of web monitoring secrets in the store. Only one KV v2 secrets engine is used.
Default:
{}-
stringsettings.ui.secretsStore.kv.mountMount path of the KV v2 secrets engine. All secret paths, relative and absolute, are resolved inside this engine.
Default:
secret -
stringsettings.ui.secretsStore.kv.pathPrefixPrefix of per-project secret paths inside the engine. A relative reference
${secret:app/prod#key}of a project resolves to<mount>/<pathPrefix>/<space name>/<project name>/app/prod. Absolute references (${secret:/team/db#key}) ignore the prefix and are allowed only for the path prefixes listed in the project settings by a platform administrator.Default:
dop/web-monitoring
-
-
stringsettings.ui.secretsStore.namespaceVault namespace sent in the
X-Vault-Namespaceheader (Stronghold namespaces, Vault Enterprise). Leave empty for a single-namespace store or HashiCorp Vault OSS.
-
-
objectsettings.ui.sentryOptions related to the configuration of sentry.
Default:
{}-
stringsettings.ui.sentry.dsnThe dsn for sentry.
-
stringsettings.ui.sentry.envThe environment used by sentry.
-
-
objectsettings.ui.smtpConfiguration for the SMTP server used to send authentication-related emails such as account verification and password resets.
Default:
{}-
stringsettings.ui.smtp.addressThe address of the SMTP server. This could be an IP address or a domain name.
-
stringsettings.ui.smtp.domainThe domain name that will be used as the sender’s email domain. This is the part that appears after the
@symbol in the email address. -
booleansettings.ui.smtp.enabledWhether SMTP is enabled or disabled for the UI component. Set to
trueto enable SMTP functionality. -
stringsettings.ui.smtp.passwordThe password required to authenticate with the SMTP server.
-
stringsettings.ui.smtp.portThe port on which the SMTP server is listening. Standard ports include 25, 465 (for SSL), and 587 (for TLS).
-
stringsettings.ui.smtp.userThe username required to authenticate with the SMTP server.
-
-
stringsettings.ui.tenantHashSalt
Required value
Random string used for generating the tenant ID -
objectsettings.ui.webAppConfigurationAdditional configuration options passed to the user interface components.
-
-