Files
argocd-apps/apps/overlays/au-syd1/logging/values-vector-aggregator.yaml
T
unkinben 1202aae06f
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/vector-test Pipeline failed
ci/woodpecker/pr/kubeconform Pipeline was successful
Pull images via artifactapi; make transform tier stateless
Three changes from review:

1. Pull every container image through the artifactapi dockerhub remote instead
   of direct upstream: clickhouse-server, altinity operator + metrics-exporter,
   bitnami/kubectl (crdHook), nats + nats-server-config-reloader, nats-box
   (bootstrap Job), and vector (all tiers + the CI image). Requires
   terraform-artifactapi#16 (dockerhub allowlist patterns) merged first.

2. Keep upstream official images (no Docker Hardened Images). DHI exists for
   clickhouse-server and vector but is subscription-gated and served from a
   private org namespace not reachable via the anonymous artifactapi dockerhub
   proxy; its shell-less images would also break the bash bootstrap Jobs and the
   shell-based vector-test CI step. Use vector's distroless-libc for runtime
   pods (near-hardened) and the debian variant only for CI.

3. Make the transform tier a stateless Deployment (was a StatefulSet): no PVC,
   no disk buffer — JetStream is the sole durability layer. The ClickHouse sink
   uses an in-memory block buffer so a ClickHouse outage back-pressures the
   JetStream pull source (unpulled messages are retained/redelivered). Add a CPU
   HPA (2-8) — safe because JetStream pull consumers distribute work across N
   replicas on the one durable consumer. Caveat documented: vector's NATS source
   has no end-to-end acks (acks on receipt), so a pod killed mid-outage can lose
   its in-memory buffer window; accepted trade for a stateless autoscaling tier.

Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
2026-07-27 21:19:44 +10:00

81 lines
2.4 KiB
YAML

# Vector TRANSFORM tier (STATELESS Deployment) — the "brain": sole ClickHouse
# writer, owns all transforms, holds the only ClickHouse + NATS-consumer creds.
#
# Stateless by design: a JetStream pull consumer with NO PVC and NO disk buffer.
# JetStream is the sole durability layer. On a ClickHouse outage the clickhouse
# sink blocks (buffer when_full=block), back-pressure stops the source pulling,
# and unpulled messages stay in JetStream for redelivery. Because Vector's NATS
# source does NOT support end-to-end acknowledgements (it acks on receipt, not
# after the sink), the only at-risk window is the in-memory buffer's worth of
# already-pulled events if a pod is killed mid-outage — the accepted trade for a
# horizontally-autoscalable stateless tier. Multiple replicas share the one
# durable consumer `transform` (JetStream pull consumers distribute work), so
# HPA is safe.
role: Stateless-Aggregator
fullnameOverride: vector-aggregator
image:
repository: artifactapi.k8s.syd1.au.unkin.net/dockerhub/timberio/vector
tag: 0.57.0-distroless-libc
# Horizontal autoscaling on CPU — safe with N replicas on one durable consumer.
autoscaling:
enabled: true
minReplicas: 2
maxReplicas: 8
targetCPUUtilizationPercentage: 70
workloadResourceAnnotations:
reloader.stakater.com/auto: "true"
podLabels:
vector.dev/exclude: "true"
# Pipeline is the single source of truth in apps/base/logging/vector/
# aggregator.yaml (unit-tested by `vector test` in CI), mounted via
# existingConfigMaps. No persistence — stateless.
dataDir: /vector-data-dir
existingConfigMaps:
- vector-aggregator-config
# The ONLY place ClickHouse + NATS-consumer creds are consumed.
env:
- name: CLICKHOUSE_USER
valueFrom:
secretKeyRef:
name: clickhouse-credentials
key: username
- name: CLICKHOUSE_PASSWORD
valueFrom:
secretKeyRef:
name: clickhouse-credentials
key: password
- name: NATS_CONSUMER_PASSWORD
valueFrom:
secretKeyRef:
name: nats-auth
key: consumer_password
# Pure consumer: expose only the Vector API for debugging.
containerPorts:
- name: api
containerPort: 8686
protocol: TCP
service:
enabled: true
type: ClusterIP
ports:
- name: api
port: 8686
targetPort: 8686
protocol: TCP
resources:
requests:
cpu: 250m
memory: 512Mi
limits:
cpu: "2"
memory: 2Gi