kibana.j2 6.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170
  1. apiVersion: "v1"
  2. kind: "DeploymentConfig"
  3. metadata:
  4. name: "{{ deploy_name }}"
  5. labels:
  6. provider: openshift
  7. component: "{{ component }}"
  8. logging-infra: "{{ logging_component }}"
  9. spec:
  10. replicas: {{ kibana_replicas | default(1) }}
  11. selector:
  12. provider: openshift
  13. component: "{{ component }}"
  14. logging-infra: "{{ logging_component }}"
  15. strategy:
  16. rollingParams:
  17. intervalSeconds: 1
  18. timeoutSeconds: 600
  19. updatePeriodSeconds: 1
  20. type: Rolling
  21. template:
  22. metadata:
  23. name: "{{ deploy_name }}"
  24. labels:
  25. logging-infra: "{{ logging_component }}"
  26. provider: openshift
  27. component: "{{ component }}"
  28. spec:
  29. serviceAccountName: aggregated-logging-kibana
  30. {% if kibana_node_selector is iterable and kibana_node_selector | length > 0 %}
  31. nodeSelector:
  32. {% for key, value in kibana_node_selector.items() %}
  33. {{ key }}: "{{ value }}"
  34. {% endfor %}
  35. {% endif %}
  36. containers:
  37. -
  38. name: "kibana"
  39. image: {{ image }}
  40. imagePullPolicy: IfNotPresent
  41. {% if (kibana_memory_limit is defined and kibana_memory_limit is not none and kibana_memory_limit != "") or (kibana_cpu_limit is defined and kibana_cpu_limit is not none and kibana_cpu_limit != "") or (kibana_cpu_request is defined and kibana_cpu_request is not none and kibana_cpu_request != "") %}
  42. resources:
  43. {% if (kibana_memory_limit is defined and kibana_memory_limit is not none and kibana_memory_limit != "") or (kibana_cpu_limit is defined and kibana_cpu_limit is not none and kibana_cpu_limit != "") %}
  44. limits:
  45. {% if kibana_cpu_limit is not none and kibana_cpu_limit != "" %}
  46. cpu: "{{ kibana_cpu_limit }}"
  47. {% endif %}
  48. {% if kibana_memory_limit is not none and kibana_memory_limit != "" %}
  49. memory: "{{ kibana_memory_limit }}"
  50. {% endif %}
  51. {% endif %}
  52. {% if (kibana_memory_limit is defined and kibana_memory_limit is not none and kibana_memory_limit != "") or (kibana_cpu_request is defined and kibana_cpu_request is not none and kibana_cpu_request != "") %}
  53. requests:
  54. {% if kibana_cpu_request is not none and kibana_cpu_request != "" %}
  55. cpu: "{{ kibana_cpu_request }}"
  56. {% endif %}
  57. {% if kibana_memory_limit is not none and kibana_memory_limit != "" %}
  58. memory: "{{ kibana_memory_limit }}"
  59. {% endif %}
  60. {% endif %}
  61. {% endif %}
  62. env:
  63. - name: "ES_URL"
  64. value: "https://{{ es_host }}:{{ es_port }}"
  65. -
  66. name: "KIBANA_MEMORY_LIMIT"
  67. valueFrom:
  68. resourceFieldRef:
  69. containerName: kibana
  70. resource: limits.memory
  71. volumeMounts:
  72. - name: kibana
  73. mountPath: /etc/kibana/keys
  74. readOnly: true
  75. readinessProbe:
  76. exec:
  77. command:
  78. - "/usr/share/kibana/probe/readiness.sh"
  79. initialDelaySeconds: 5
  80. timeoutSeconds: 4
  81. periodSeconds: 5
  82. -
  83. name: "kibana-proxy"
  84. image: {{ proxy_image }}
  85. imagePullPolicy: IfNotPresent
  86. {% if (kibana_proxy_memory_limit is defined and kibana_proxy_memory_limit is not none and kibana_proxy_memory_limit != "") or (kibana_proxy_cpu_limit is defined and kibana_proxy_cpu_limit is not none and kibana_proxy_cpu_limit != "") or (kibana_proxy_cpu_request is defined and kibana_proxy_cpu_request is not none and kibana_proxy_cpu_request != "") %}
  87. resources:
  88. {% if (kibana_proxy_memory_limit is defined and kibana_proxy_memory_limit is not none and kibana_proxy_memory_limit != "") or (kibana_proxy_cpu_limit is defined and kibana_proxy_cpu_limit is not none and kibana_proxy_cpu_limit != "") %}
  89. limits:
  90. {% if kibana_proxy_cpu_limit is not none and kibana_proxy_cpu_limit != "" %}
  91. cpu: "{{ kibana_proxy_cpu_limit }}"
  92. {% endif %}
  93. {% if kibana_proxy_memory_limit is not none and kibana_proxy_memory_limit != "" %}
  94. memory: "{{ kibana_proxy_memory_limit }}"
  95. {% endif %}
  96. {% endif %}
  97. {% if (kibana_proxy_memory_limit is defined and kibana_proxy_memory_limit is not none and kibana_proxy_memory_limit != "") or (kibana_proxy_cpu_request is defined and kibana_proxy_cpu_request is not none and kibana_proxy_cpu_request != "") %}
  98. requests:
  99. {% if kibana_proxy_cpu_request is not none and kibana_proxy_cpu_request != "" %}
  100. cpu: "{{ kibana_proxy_cpu_request }}"
  101. {% endif %}
  102. {% if kibana_proxy_memory_limit is not none and kibana_proxy_memory_limit != "" %}
  103. memory: "{{ kibana_proxy_memory_limit }}"
  104. {% endif %}
  105. {% endif %}
  106. {% endif %}
  107. ports:
  108. -
  109. name: "oaproxy"
  110. containerPort: 3000
  111. env:
  112. -
  113. name: "OAP_BACKEND_URL"
  114. value: "http://localhost:5601"
  115. -
  116. name: "OAP_AUTH_MODE"
  117. value: "oauth2"
  118. -
  119. name: "OAP_TRANSFORM"
  120. value: "user_header,token_header"
  121. -
  122. name: "OAP_OAUTH_ID"
  123. value: kibana-proxy
  124. -
  125. name: "OAP_MASTER_URL"
  126. value: {{ openshift_logging_kibana_master_url }}
  127. -
  128. name: "OAP_PUBLIC_MASTER_URL"
  129. value: {{ openshift_logging_kibana_master_public_url }}
  130. -
  131. name: "OAP_LOGOUT_REDIRECT"
  132. value: {{ openshift_logging_kibana_master_public_url }}/console/logout
  133. -
  134. name: "OAP_MASTER_CA_FILE"
  135. value: "/var/run/secrets/kubernetes.io/serviceaccount/ca.crt"
  136. -
  137. name: "OAP_DEBUG"
  138. value: "{{ openshift_logging_kibana_proxy_debug }}"
  139. -
  140. name: "OAP_OAUTH_SECRET_FILE"
  141. value: "/secret/oauth-secret"
  142. -
  143. name: "OAP_SERVER_CERT_FILE"
  144. value: "/secret/server-cert"
  145. -
  146. name: "OAP_SERVER_KEY_FILE"
  147. value: "/secret/server-key"
  148. -
  149. name: "OAP_SERVER_TLS_FILE"
  150. value: "/secret/server-tls.json"
  151. -
  152. name: "OAP_SESSION_SECRET_FILE"
  153. value: "/secret/session-secret"
  154. -
  155. name: "OCP_AUTH_PROXY_MEMORY_LIMIT"
  156. valueFrom:
  157. resourceFieldRef:
  158. containerName: kibana-proxy
  159. resource: limits.memory
  160. volumeMounts:
  161. - name: kibana-proxy
  162. mountPath: /secret
  163. readOnly: true
  164. volumes:
  165. - name: kibana
  166. secret:
  167. secretName: logging-kibana
  168. - name: kibana-proxy
  169. secret:
  170. secretName: logging-kibana-proxy