/
opencensus_exporter.go
111 lines (100 loc) · 3.83 KB
/
opencensus_exporter.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
/*
Copyright 2020 The Knative Authors
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/
package metrics
import (
"context"
"crypto/tls"
"fmt"
"path"
"contrib.go.opencensus.io/exporter/ocagent"
"go.opencensus.io/resource"
"go.opencensus.io/stats/view"
"go.uber.org/zap"
"google.golang.org/grpc/credentials"
corev1 "k8s.io/api/core/v1"
"k8s.io/apimachinery/pkg/api/errors"
)
func newOpenCensusExporter(config *metricsConfig, logger *zap.SugaredLogger) (view.Exporter, ResourceExporterFactory, error) {
opts := []ocagent.ExporterOption{ocagent.WithServiceName(config.component)}
if config.collectorAddress != "" {
opts = append(opts, ocagent.WithAddress(config.collectorAddress))
}
metrixPrefix := path.Join(config.domain, config.component)
if metrixPrefix != "" {
opts = append(opts, ocagent.WithMetricNamePrefix(metrixPrefix))
}
if config.requireSecure {
opts = append(opts, ocagent.WithTLSCredentials(getCredentials(config.component, config.secret, logger)))
} else {
opts = append(opts, ocagent.WithInsecure())
}
if TestOverrideBundleCount > 0 {
opts = append(opts, ocagent.WithDataBundlerOptions(0, TestOverrideBundleCount))
}
e, err := ocagent.NewExporter(opts...)
if err != nil {
logger.Errorw("Failed to create the OpenCensus exporter.", zap.Error(err))
return nil, nil, err
}
logger.Infow("Created OpenCensus exporter with config:", zap.Any("config", *config))
view.RegisterExporter(e)
return e, getFactory(e, opts), nil
}
func getFactory(defaultExporter view.Exporter, stored []ocagent.ExporterOption) ResourceExporterFactory {
return func(r *resource.Resource) (view.Exporter, error) {
if r == nil || (r.Type == "" && len(r.Labels) == 0) {
// Don't create duplicate exporters for the default exporter.
return defaultExporter, nil
}
opts := append(stored, ocagent.WithResourceDetector(
func(context.Context) (*resource.Resource, error) {
return r, nil
}))
return ocagent.NewExporter(opts...)
}
}
// getOpenCensusSecret attempts to locate a secret containing TLS credentials
// for communicating with the OpenCensus Agent. To do this, it first looks
// for a secret named "<component>-opencensus", then for a generic
// "opencensus" secret.
func getOpenCensusSecret(component string, lister SecretFetcher) (*corev1.Secret, error) {
if lister == nil {
return nil, fmt.Errorf("no secret lister provided for component %q; cannot use requireSecure=true", component)
}
secret, err := lister(component + "-opencensus")
if errors.IsNotFound(err) {
secret, err = lister("opencensus")
}
if err != nil {
return nil, fmt.Errorf("unable to fetch opencensus secret for %q, cannot use requireSecure=true: %w", component, err)
}
return secret, nil
}
// getCredentials attempts to create a certificate containing TLS credentials
// for communicating with the OpenCensus Agent.
func getCredentials(component string, secret *corev1.Secret, logger *zap.SugaredLogger) credentials.TransportCredentials {
if secret == nil {
logger.Errorf("No secret provided for component %q; cannot use requireSecure=true", component)
return nil
}
return credentials.NewTLS(&tls.Config{
MinVersion: tls.VersionTLS12,
GetClientCertificate: func(*tls.CertificateRequestInfo) (*tls.Certificate, error) {
cert, err := tls.X509KeyPair(secret.Data["client-cert.pem"], secret.Data["client-key.pem"])
if err != nil {
return nil, err
}
return &cert, nil
},
})
}