add POST /logs installer log relay to VictoriaLogs
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful

A host being PXE-discovered or installed is not in Kubernetes, so vlagent
cannot collect its logs and a failed install leaves no record; the installer
environment has no internal-CA trust or credentials for the HTTPS log ingest,
and bootapi is already the plain-HTTP broker it can reach.

- add POST /logs, token-guarded like POST /provisioned, relaying ndjson to
  vlinsert's jsonline endpoint keyed on serial+phase
- stamp observed source IP and resolved NetBox device name into extra_fields
- return 202 on a sink failure so logs never block an install
- add BOOTAPI_VLINSERT_URL/_TIMEOUT and bootapi_log_relay metrics
This commit is contained in:
2026-10-03 19:44:27 +10:00
parent 0f0fb7fa8e
commit 3c77895788
9 changed files with 416 additions and 5 deletions
+6 -1
View File
@@ -47,7 +47,10 @@ func main() {
slog.Warn("no NetBox token set (BOOTAPI_NETBOX_TOKEN/_FILE); NetBox reads will likely be denied")
}
if cfg.ProvisionToken == "" {
slog.Warn("no BOOTAPI_PROVISION_TOKEN set; the /provisioned callback is disabled (pxe_enabled will not auto-clear)")
slog.Warn("no BOOTAPI_PROVISION_TOKEN set; the /provisioned callback and /logs relay are disabled")
}
if cfg.VLInsertURL == "" {
slog.Warn("BOOTAPI_VLINSERT_URL is empty; the /logs installer log relay is disabled")
}
rcfg := render.RenderConfig{
@@ -92,6 +95,8 @@ func main() {
Cache: cache,
UnknownMACFallback: cfg.UnknownMACFallback,
ProvisionToken: cfg.ProvisionToken,
VLInsertURL: cfg.VLInsertURL,
VLInsertTimeout: cfg.VLInsertTimeout,
TLSAddr: cfg.TLSListenAddr,
TLSCertFile: cfg.TLSCertFile,
TLSKeyFile: cfg.TLSKeyFile,