- Replace unpoller-credentials plain Secret with ExternalSecret pulling from Bitwarden item 15bfc957-5de5-49b2-ab6c-b41800e71564 via bitwarden-login ClusterSecretStore (username + password) - Pull UP_UNIFI_DEFAULT_USER from secret as well (was hardcoded) - Add OpenWRT access point (10.42.0.3) to genesis DNS hosts file as ap.thehellings.lan (discovered during network scan) - Add blackbox exporter to genesis (port 9115, ICMP module) for probing non-NixOS infrastructure that has no node_exporter: OpenWRT AP, Joel, pve1, chronicles, nas1, odoo, mattermost, homeassistant, USW-Pro-HD-24 UniFi switch - Add infra_ping scrape job to Prometheus using blackbox prober targeting all non-NixOS LAN hosts via genesis blackbox exporter
This commit is contained in:
@@ -1,5 +1,6 @@
|
|||||||
# Local hosts
|
# Local hosts
|
||||||
10.42.0.1 switch switch.thehellings.lan # Core switch for the network
|
10.42.0.1 switch switch.thehellings.lan # Core switch for the network
|
||||||
|
10.42.0.3 ap ap.thehellings.lan # OpenWRT access point (static IP)
|
||||||
10.42.0.4 joel.thehellings.lan # Proxmox
|
10.42.0.4 joel.thehellings.lan # Proxmox
|
||||||
10.42.0.5 sanswitch.thehellings.lan # Core switch for the SAN
|
10.42.0.5 sanswitch.thehellings.lan # Core switch for the SAN
|
||||||
|
|
||||||
|
|||||||
@@ -112,6 +112,18 @@ in
|
|||||||
|
|
||||||
prometheus.exporters = {
|
prometheus.exporters = {
|
||||||
dnsmasq.enable = true;
|
dnsmasq.enable = true;
|
||||||
|
blackbox = {
|
||||||
|
enable = true;
|
||||||
|
openFirewall = true;
|
||||||
|
configFile = pkgs.writeText "blackbox.yml" ''
|
||||||
|
modules:
|
||||||
|
icmp:
|
||||||
|
prober: icmp
|
||||||
|
timeout: 5s
|
||||||
|
icmp:
|
||||||
|
preferred_ip_protocol: ip4
|
||||||
|
'';
|
||||||
|
};
|
||||||
};
|
};
|
||||||
}; # End of services configuration
|
}; # End of services configuration
|
||||||
|
|
||||||
|
|||||||
@@ -43,6 +43,29 @@ data:
|
|||||||
- "hosea.shire-zebra.ts.net:9427"
|
- "hosea.shire-zebra.ts.net:9427"
|
||||||
- "exodus.shire-zebra.ts.net:9427"
|
- "exodus.shire-zebra.ts.net:9427"
|
||||||
- "linode.shire-zebra.ts.net:9427"
|
- "linode.shire-zebra.ts.net:9427"
|
||||||
|
# ICMP ping reachability for non-NixOS infrastructure
|
||||||
|
- job_name: infra_ping
|
||||||
|
metrics_path: /probe
|
||||||
|
params:
|
||||||
|
module: [icmp]
|
||||||
|
static_configs:
|
||||||
|
- targets:
|
||||||
|
- "10.42.0.3" # OpenWRT access point
|
||||||
|
- "10.42.0.4" # Joel (Proxmox)
|
||||||
|
- "10.42.1.1" # pve1 (Proxmox)
|
||||||
|
- "10.42.1.4" # chronicles (Synology NAS)
|
||||||
|
- "10.42.1.14" # nas1 (TrueNAS)
|
||||||
|
- "10.42.2.57" # odoo
|
||||||
|
- "10.42.2.89" # mattermost
|
||||||
|
- "10.42.2.155" # homeassistant
|
||||||
|
- "10.42.3.58" # USW-Pro-HD-24 (UniFi switch)
|
||||||
|
relabel_configs:
|
||||||
|
- source_labels: [__address__]
|
||||||
|
target_label: __param_target
|
||||||
|
- source_labels: [__param_target]
|
||||||
|
target_label: instance
|
||||||
|
- target_label: __address__
|
||||||
|
replacement: "genesis.shire-zebra.ts.net:9115"
|
||||||
- job_name: kea
|
- job_name: kea
|
||||||
static_configs:
|
static_configs:
|
||||||
- targets:
|
- targets:
|
||||||
|
|||||||
@@ -1,13 +1,29 @@
|
|||||||
---
|
---
|
||||||
apiVersion: v1
|
apiVersion: external-secrets.io/v1
|
||||||
kind: Secret
|
kind: ExternalSecret
|
||||||
metadata:
|
metadata:
|
||||||
name: unpoller-credentials
|
name: unpoller-credentials
|
||||||
namespace: monitoring
|
spec:
|
||||||
type: Opaque
|
target:
|
||||||
stringData:
|
name: unpoller-credentials
|
||||||
# Replace with actual UniFi controller password for the 'unpoller' read-only user
|
deletionPolicy: Delete
|
||||||
password: "CHANGEME"
|
template:
|
||||||
|
type: Opaque
|
||||||
|
data:
|
||||||
|
username: "{{ .username }}"
|
||||||
|
password: "{{ .password }}"
|
||||||
|
secretStoreRef:
|
||||||
|
name: bitwarden-login
|
||||||
|
kind: ClusterSecretStore
|
||||||
|
data:
|
||||||
|
- secretKey: username
|
||||||
|
remoteRef:
|
||||||
|
key: "15bfc957-5de5-49b2-ab6c-b41800e71564"
|
||||||
|
property: username
|
||||||
|
- secretKey: password
|
||||||
|
remoteRef:
|
||||||
|
key: "15bfc957-5de5-49b2-ab6c-b41800e71564"
|
||||||
|
property: password
|
||||||
---
|
---
|
||||||
apiVersion: apps/v1
|
apiVersion: apps/v1
|
||||||
kind: Deployment
|
kind: Deployment
|
||||||
@@ -38,7 +54,10 @@ spec:
|
|||||||
- name: UP_UNIFI_DEFAULT_VERIFY_SSL
|
- name: UP_UNIFI_DEFAULT_VERIFY_SSL
|
||||||
value: "false"
|
value: "false"
|
||||||
- name: UP_UNIFI_DEFAULT_USER
|
- name: UP_UNIFI_DEFAULT_USER
|
||||||
value: "unpoller"
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: unpoller-credentials
|
||||||
|
key: username
|
||||||
- name: UP_UNIFI_DEFAULT_PASS
|
- name: UP_UNIFI_DEFAULT_PASS
|
||||||
valueFrom:
|
valueFrom:
|
||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
|
|||||||
Reference in New Issue
Block a user