Metrics Exposer Chart Values Reference

This reference describes the Metrics Exposer values the Axual Governance chart exposes: the image and repository settings, TLS, the application configuration and the Axual-specific configuration.

Type

Reference

Goal

Look up a Metrics Exposer value and what it does, while writing the Axual Governance values.

Audience

Platform Operator writing or reviewing the Metrics Exposer section of an Axual Governance values.yaml.

When to use

While configuring Metrics Exposer, alongside the procedure that enables it.

Metrics Exposer needs little configuration, because most of the Kafka connection details are sent to it at runtime rather than set in values. Every key the chart accepts is in the generated Metrics Exposer 1.7.0 Helm Readme, and the Configuration section of the Metrics Exposer page covers the remaining options.

For the procedure that enables it, see How to Enable Insights and Metrics.

Metrics Exposer Repository Configuration

You can override the registry, tag, and pullPolicy for the Metrics Exposer pod. Without an override, these values come from the Axual Governance chart.

You can override imagePullSecrets as well. If you do not, the Metrics Exposer pod uses global.imagePullSecrets.

values.yaml
metrics-exposer:

  image:
    registry: "registry.axual.io"
    pullPolicy: "Always"
    tag: "1.1.0"

  imagePullSecrets:
    - name: axualdockercred

TLS Configuration

You can name the Secrets holding the Privacy Enhanced Mail (PEM) certificates the chart generates the keystores from:

  • Server keypair

  • Client keypair

  • Truststore

The example below sets all three.

values.yaml
metrics-exposer:

  tls:
    # -- Enables keystore generation
    enabled: true
    # -- Creates server keypair from PEM
    createServerKeypairSecret: true
    # -- PEM used to generate the server keypair if `createServerKeypairSecret` is true
    serverCertificatePem: <server-certificate>
    # -- PEM used to generate the server keypair if `createServerKeypairSecret` is true
    serverKeyPem: <server-key>

    # -- Creates client keypair from PEM
    createClientKeypairSecret: true
    # -- PEM used to generate the client keypair if `createClientKeypairSecret` is true
    clientCertificatePem: <client-certificate>
    # -- PEM used to generate the client keypair if `createClientKeypairSecret` is true
    clientKeyPem: <client-key>

    # -- Creates truststore from PEMs
    createTruststoreCaSecret: true
    # -- Set of PEMs used to generate the truststore if `createTruststoreCaSecret` is true
    caCerts:
      ca_one.crt:  <first-cert>
      ca_two.crt: <second-cert>

For the shape each of these Secrets takes, see Secret formats.

Application Configuration

Metrics Exposer is a Spring Boot application, so it reads its settings from an application.yml file. Whatever you put under config is injected into a ConfigMap and mounted as that file.

values.yaml
metrics-exposer:
  config: {}

Credentials Secret: secrets and existingSecretName

Metrics Exposer reads a second configuration file, secrets.yml, from a Kubernetes Secret. It takes the same structure as config, is loaded after it, and overrides any key the two share. existingSecretName names an existing Secret holding a secrets.yml key. When it is "", the chart creates the Secret from secrets. For the procedure, see How to Store Component Credentials in a Kubernetes Secret.

When the chart generates the keystores, as in TLS Configuration, it also sets their passwords, so they stay out of config. The credential keys that belong in secrets.yml, when you set them yourself, are:

  • axual.security.trust-store-password, axual.security.key-store-password and axual.security.key-password, for keystores you supply for the connection to Prometheus

  • server.ssl.key-store-password and server.ssl.key-password, for a server keystore you supply

  • management.opentelemetry.tracing.export.otlp.headers.<NAME>, for example an authorization header for the OpenTelemetry collector

Axual Configuration

Metrics Exposer needs the address of the Prometheus that stores the Kafka metrics.

Each {tenant} can have its own prometheus-url. The default key is the fallback for a tenant that has none.

values.yaml
metrics-exposer:

  config:
      # Axual Configuration
      metrics-exposer:
        # Used to expose the Redoc API documentation
        public-address: "http://platform.<domain>"
        prometheus-urls:
          default: http://kube-prometheus-stack-prometheus:9090
          axual: http://axual-prometheus-stack-prometheus:9090