This repository has been archived by the owner on Jan 12, 2022. It is now read-only.
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
controller: When a given credential or exporter config is created/upd…
…ated/deleted in GraphQL, the controller will automatically apply that change to Kubernetes. Credentials are converted to Kubernetes `Secret`s, while exporters are converted to Kubernetes `Deployment`s (which may link to the `Secret`s referenced by the exporter config). The synchronization itself works against the existing Kubernetes reconciliation loop in the Controller. The main addition is that the reconciliation state now includes entries originating from GraphQL, but the reconciliation flow itself remains the same structurally and ends up being pretty straightforward. This structure would potentially be extendable to other state retrieved from GraphQL in the future. Summary: - Add GraphQL queries for dumping a "snapshot" of credentials and exporters when starting the sync, in addition to the existing subscription queries. - Add subscription client to controller, largely copied from app. - Implement `informers` for fetching and subscribing to the GraphQL credentials and exporters, and applying this data to the Redux state object. - Implement `resources` for converting the Redux state to Kubernetes objects, with type-specific logic for how to deploy each credential and exporter type. I've so far tested this by hand by creating credentials/exporters via `curl` against the go graphql `config` service (which is due to get moved/renamed), and was able to verify that actual metrics successfully appeared in prometheus/cortex from each of the current two types of exporters. As such this should complete issue #312 and epic #310 . There remains some doc work via #358 which in turn depends on the graphql config API naming that's being updated via #379 . Signed-off-by: Nick Parker <nick@opstrace.com>
- Loading branch information
Nick Parker
committed
Feb 23, 2021
1 parent
a0f2818
commit 98f2e77
Showing
24 changed files
with
1,154 additions
and
16 deletions.
There are no files selected for viewing
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
13 changes: 13 additions & 0 deletions
13
packages/app/src/state/credential/queries/getCredentialsDump.gql
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,13 @@ | ||
// Returns credentials, INCLUDING SECRET VALUES, across all tenants. | ||
// Used for initial sync of credential secrets to Kubernetes. | ||
// TODO: ability to restrict access to this API to just the controller? | ||
query GetCredentialsDump { | ||
credential { | ||
tenant | ||
name | ||
type | ||
value | ||
created_at | ||
updated_at | ||
} | ||
} |
5 changes: 5 additions & 0 deletions
5
packages/app/src/state/credential/queries/subscribeToCredentialList.gql
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,8 +1,13 @@ | ||
// Subscribes to credential updates, INCLUDING SECRET VALUES, across all tenants. | ||
// Used for syncing credential secrets to Kubernetes. | ||
// TODO: ability to restrict access to this API to just the controller? | ||
subscription SubscribeToCredentialList { | ||
credential { | ||
name | ||
tenant | ||
type | ||
value | ||
created_at | ||
updated_at | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
13 changes: 13 additions & 0 deletions
13
packages/app/src/state/exporter/queries/getExportersDump.gql
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,13 @@ | ||
// Returns exporter configurations across all tenants at once. | ||
// Used for initial sync of exporter deployments to Kubernetes. | ||
query GetExportersDump { | ||
exporter { | ||
tenant | ||
name | ||
type | ||
credential | ||
config | ||
created_at | ||
updated_at | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.