Compare commits

..

4 Commits

Author SHA1 Message Date
d2219a9348 feat: manage openbao audit devices
- manage openbao audit devices in the configuration file
- enable audit and audit_raw logs
2025-11-22 11:57:34 +11:00
a5b9850e82 feat: add audit log for openbao
- openbao requires audit-log configured in config file
2025-11-22 11:57:15 +11:00
9854403b02 feat: add syslog listener for vlinsert (#427)
- enable syslog capture via vlinsert
- add syslog.service.consul service

Reviewed-on: #427
2025-11-20 23:47:10 +11:00
6400c89853 feat: add vmcluster static targets (#426)
- add ability to list static targets for vmagent to scrape
- add vyos router to be scraped

Reviewed-on: #426
2025-11-20 20:19:53 +11:00
5 changed files with 57 additions and 0 deletions

View File

@ -14,6 +14,8 @@ victorialogs::node::options:
envflag.enable: 'true' envflag.enable: 'true'
select.disable: 'undef' select.disable: 'undef'
storageNode.tls: 'undef' storageNode.tls: 'undef'
syslog.listenAddr.tcp: ':21514'
syslog.timezone: 'Australia/Sydney'
storageNode: storageNode:
- ausyd1nxvm2108.main.unkin.net:9428 - ausyd1nxvm2108.main.unkin.net:9428
- ausyd1nxvm2109.main.unkin.net:9428 - ausyd1nxvm2109.main.unkin.net:9428
@ -45,7 +47,20 @@ consul::services:
tls_skip_verify: true tls_skip_verify: true
interval: '10s' interval: '10s'
timeout: '1s' timeout: '1s'
syslog:
service_name: 'syslog'
address: "%{facts.networking.ip}"
port: 21514
checks:
- id: 'vlinsert_syslog_tcp_check'
name: 'VictoriaLogs Syslog TCP Check'
tcp: "%{facts.networking.fqdn}:21514"
interval: '30s'
timeout: '5s'
profiles::consul::client::node_rules: profiles::consul::client::node_rules:
- resource: service - resource: service
segment: vlinsert segment: vlinsert
disposition: write disposition: write
- resource: service
segment: syslog
disposition: write

View File

@ -3,6 +3,16 @@ hiera_include:
- vmcluster::vmagent - vmcluster::vmagent
vmcluster::vmagent::enable: true vmcluster::vmagent::enable: true
vmcluster::vmagent::static_targets:
vyos_node:
targets:
- '198.18.21.160:9100'
scrape_interval: '15s'
metrics_path: '/metrics'
scheme: 'http'
labels:
instance: 'syrtvm0001.main.unkin.net'
job: 'vyos_node'
vmcluster::vmagent::options: vmcluster::vmagent::options:
tls: 'true' tls: 'true'
tlsCertFile: '/etc/pki/tls/vault/certificate.crt' tlsCertFile: '/etc/pki/tls/vault/certificate.crt'

View File

@ -5,10 +5,16 @@ profiles::vault::server::data_dir: /data/vault
profiles::vault::server::manage_storage_dir: true profiles::vault::server::manage_storage_dir: true
profiles::vault::server::tls_disable: false profiles::vault::server::tls_disable: false
profiles::vault::server::audit_devices: profiles::vault::server::audit_devices:
- file:
audit-file:
options:
file_path: /data/vault/audit_raw.log
log_raw: true
- file: - file:
audit-file: audit-file:
options: options:
file_path: /data/vault/audit.log file_path: /data/vault/audit.log
log_raw: false
vault::package_name: openbao vault::package_name: openbao
vault::package_ensure: latest vault::package_ensure: latest

View File

@ -10,6 +10,7 @@ class vmcluster::vmagent (
Stdlib::Absolutepath $vars_file = '/etc/default/vmagent', Stdlib::Absolutepath $vars_file = '/etc/default/vmagent',
String $consul_node_token = $facts['consul_node_token'], String $consul_node_token = $facts['consul_node_token'],
Hash[String, Variant[String, Array[String]]] $options = {}, Hash[String, Variant[String, Array[String]]] $options = {},
Hash[String, Hash] $static_targets = {},
) { ) {
# if enabled, manage this service # if enabled, manage this service

View File

@ -35,3 +35,28 @@ scrape_configs:
- source_labels: [__meta_consul_tag_metrics_job] - source_labels: [__meta_consul_tag_metrics_job]
target_label: job target_label: job
action: replace action: replace
<% if @static_targets -%>
<% @static_targets.each do |job_name, config| -%>
- job_name: '<%= job_name %>'
static_configs:
<% config['targets'].each do |target| -%>
- targets: ['<%= target %>']
<% if config['labels'] -%>
labels:
<% config['labels'].each do |label_name, label_value| -%>
<%= label_name %>: '<%= label_value %>'
<% end -%>
<% end -%>
<% end -%>
<% if config['scrape_interval'] -%>
scrape_interval: <%= config['scrape_interval'] %>
<% end -%>
<% if config['metrics_path'] -%>
metrics_path: <%= config['metrics_path'] %>
<% end -%>
<% if config['scheme'] -%>
scheme: <%= config['scheme'] %>
<% end -%>
<% end -%>
<% end -%>