1202aae06f
Three changes from review: 1. Pull every container image through the artifactapi dockerhub remote instead of direct upstream: clickhouse-server, altinity operator + metrics-exporter, bitnami/kubectl (crdHook), nats + nats-server-config-reloader, nats-box (bootstrap Job), and vector (all tiers + the CI image). Requires terraform-artifactapi#16 (dockerhub allowlist patterns) merged first. 2. Keep upstream official images (no Docker Hardened Images). DHI exists for clickhouse-server and vector but is subscription-gated and served from a private org namespace not reachable via the anonymous artifactapi dockerhub proxy; its shell-less images would also break the bash bootstrap Jobs and the shell-based vector-test CI step. Use vector's distroless-libc for runtime pods (near-hardened) and the debian variant only for CI. 3. Make the transform tier a stateless Deployment (was a StatefulSet): no PVC, no disk buffer — JetStream is the sole durability layer. The ClickHouse sink uses an in-memory block buffer so a ClickHouse outage back-pressures the JetStream pull source (unpulled messages are retained/redelivered). Add a CPU HPA (2-8) — safe because JetStream pull consumers distribute work across N replicas on the one durable consumer. Caveat documented: vector's NATS source has no end-to-end acks (acks on receipt), so a pod killed mid-outage can lose its in-memory buffer window; accepted trade for a stateless autoscaling tier. Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
81 lines
2.4 KiB
YAML
81 lines
2.4 KiB
YAML
# Vector TRANSFORM tier (STATELESS Deployment) — the "brain": sole ClickHouse
|
|
# writer, owns all transforms, holds the only ClickHouse + NATS-consumer creds.
|
|
#
|
|
# Stateless by design: a JetStream pull consumer with NO PVC and NO disk buffer.
|
|
# JetStream is the sole durability layer. On a ClickHouse outage the clickhouse
|
|
# sink blocks (buffer when_full=block), back-pressure stops the source pulling,
|
|
# and unpulled messages stay in JetStream for redelivery. Because Vector's NATS
|
|
# source does NOT support end-to-end acknowledgements (it acks on receipt, not
|
|
# after the sink), the only at-risk window is the in-memory buffer's worth of
|
|
# already-pulled events if a pod is killed mid-outage — the accepted trade for a
|
|
# horizontally-autoscalable stateless tier. Multiple replicas share the one
|
|
# durable consumer `transform` (JetStream pull consumers distribute work), so
|
|
# HPA is safe.
|
|
role: Stateless-Aggregator
|
|
fullnameOverride: vector-aggregator
|
|
|
|
image:
|
|
repository: artifactapi.k8s.syd1.au.unkin.net/dockerhub/timberio/vector
|
|
tag: 0.57.0-distroless-libc
|
|
|
|
# Horizontal autoscaling on CPU — safe with N replicas on one durable consumer.
|
|
autoscaling:
|
|
enabled: true
|
|
minReplicas: 2
|
|
maxReplicas: 8
|
|
targetCPUUtilizationPercentage: 70
|
|
|
|
workloadResourceAnnotations:
|
|
reloader.stakater.com/auto: "true"
|
|
|
|
podLabels:
|
|
vector.dev/exclude: "true"
|
|
|
|
# Pipeline is the single source of truth in apps/base/logging/vector/
|
|
# aggregator.yaml (unit-tested by `vector test` in CI), mounted via
|
|
# existingConfigMaps. No persistence — stateless.
|
|
dataDir: /vector-data-dir
|
|
existingConfigMaps:
|
|
- vector-aggregator-config
|
|
|
|
# The ONLY place ClickHouse + NATS-consumer creds are consumed.
|
|
env:
|
|
- name: CLICKHOUSE_USER
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: clickhouse-credentials
|
|
key: username
|
|
- name: CLICKHOUSE_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: clickhouse-credentials
|
|
key: password
|
|
- name: NATS_CONSUMER_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: nats-auth
|
|
key: consumer_password
|
|
|
|
# Pure consumer: expose only the Vector API for debugging.
|
|
containerPorts:
|
|
- name: api
|
|
containerPort: 8686
|
|
protocol: TCP
|
|
|
|
service:
|
|
enabled: true
|
|
type: ClusterIP
|
|
ports:
|
|
- name: api
|
|
port: 8686
|
|
targetPort: 8686
|
|
protocol: TCP
|
|
|
|
resources:
|
|
requests:
|
|
cpu: 250m
|
|
memory: 512Mi
|
|
limits:
|
|
cpu: "2"
|
|
memory: 2Gi
|