Metrics Exposer Chart Values Reference
This reference describes the Metrics Exposer values the Axual Governance chart exposes: the image and repository settings, TLS, the application configuration and the Axual-specific configuration.
Type |
Reference |
Goal |
Look up a Metrics Exposer value and what it does, while writing the Axual Governance values. |
Audience |
Platform Operator writing or reviewing the Metrics Exposer section of an Axual Governance |
When to use |
While configuring Metrics Exposer, alongside the procedure that enables it. |
Metrics Exposer needs little configuration, because most of the Kafka connection details are sent to it at runtime rather than set in values. Every key the chart accepts is in the generated Metrics Exposer 1.7.0 Helm Readme, and the Configuration section of the Metrics Exposer page covers the remaining options.
For the procedure that enables it, see How to Enable Insights and Metrics.
Metrics Exposer Repository Configuration
You can override the registry, tag, and pullPolicy for the Metrics Exposer pod. Without an override, these values come from the Axual Governance chart.
You can override imagePullSecrets as well. If you do not, the Metrics Exposer pod uses global.imagePullSecrets.
metrics-exposer:
image:
registry: "registry.axual.io"
pullPolicy: "Always"
tag: "1.1.0"
imagePullSecrets:
- name: axualdockercred
TLS Configuration
You can name the Secrets holding the Privacy Enhanced Mail (PEM) certificates the chart generates the keystores from:
-
Server keypair
-
Client keypair
-
Truststore
The example below sets all three.
metrics-exposer:
tls:
# -- Enables keystore generation
enabled: true
# -- Creates server keypair from PEM
createServerKeypairSecret: true
# -- PEM used to generate the server keypair if `createServerKeypairSecret` is true
serverCertificatePem: <server-certificate>
# -- PEM used to generate the server keypair if `createServerKeypairSecret` is true
serverKeyPem: <server-key>
# -- Creates client keypair from PEM
createClientKeypairSecret: true
# -- PEM used to generate the client keypair if `createClientKeypairSecret` is true
clientCertificatePem: <client-certificate>
# -- PEM used to generate the client keypair if `createClientKeypairSecret` is true
clientKeyPem: <client-key>
# -- Creates truststore from PEMs
createTruststoreCaSecret: true
# -- Set of PEMs used to generate the truststore if `createTruststoreCaSecret` is true
caCerts:
ca_one.crt: <first-cert>
ca_two.crt: <second-cert>
For the shape each of these Secrets takes, see Secret formats.
Application Configuration
Metrics Exposer is a Spring Boot application, so it reads its settings from an application.yml file. Whatever you put under config is injected into a ConfigMap and mounted as that file.
metrics-exposer:
config: {}
Credentials Secret: secrets and existingSecretName
Metrics Exposer reads a second configuration file, secrets.yml, from a Kubernetes Secret. It takes the same structure as config, is loaded after it, and overrides any key the two share. existingSecretName names an existing Secret holding a secrets.yml key. When it is "", the chart creates the Secret from secrets. For the procedure, see How to Store Component Credentials in a Kubernetes Secret.
When the chart generates the keystores, as in TLS Configuration, it also sets their passwords, so they stay out of config. The credential keys that belong in secrets.yml, when you set them yourself, are:
-
axual.security.trust-store-password,axual.security.key-store-passwordandaxual.security.key-password, for keystores you supply for the connection to Prometheus -
server.ssl.key-store-passwordandserver.ssl.key-password, for a server keystore you supply -
management.opentelemetry.tracing.export.otlp.headers.<NAME>, for example anauthorizationheader for the OpenTelemetry collector
Axual Configuration
Metrics Exposer needs the address of the Prometheus that stores the Kafka metrics.
Each {tenant} can have its own prometheus-url. The default key is the fallback for a tenant that has none.
metrics-exposer:
config:
# Axual Configuration
metrics-exposer:
# Used to expose the Redoc API documentation
public-address: "http://platform.<domain>"
prometheus-urls:
default: http://kube-prometheus-stack-prometheus:9090
axual: http://axual-prometheus-stack-prometheus:9090