Register the cluster’s Prometheus server with the central Grafana#

Once you have deployed the support chart, you must also register this cluster as a datasource for the central Grafana dashboard. This will allow you to visualize cluster statistics not only from the cluster-specific Grafana deployement but also from the central dashboard, that aggregates data from all the clusters.

Create a support.secret.values.yaml file#

Only 2i2c staff and our centralized grafana should be able to access the prometheus data on a cluster from outside the cluster. The basic auth feature of nginx-ingress is used to restrict this. A support.secret.values.yaml file is used to provide these secret credentials, which we create under the relevant config/clusters/<cluster-name>/ folder. It requires the following configuration:

prometheusIngressAuthSecret:
  username: <output of pwgen -s 64 1>
  password: <output of pwgen -s 64 1>

Note

We use the pwgen program, commonly installed by default in many operating systems, to generate the password.

Once you create the file, encrypt it with sops.

sops --output config/clusters/<cluster-name>/enc-support.secret.values.yaml --encrypt config/clusters/<cluster-name>/support.secret.values.yaml

Update your cluster.yaml file#

Update the support config in the cluster’s cluster.yaml file to include the encrypted secret file.

support:
  helm_chart_values_files:
    - support.values.yaml
    - enc-support.secret.values.yaml

Then redeploy the support chart.

deployer deploy-support <cluster-name>