From 78da9ea3a8cbe976346d185408b03170ef3bc55d Mon Sep 17 00:00:00 2001 From: mamoutou-diarra Date: Sun, 5 Apr 2026 23:48:44 +0000 Subject: [PATCH 1/4] move otlp collector, homepage, authentik, kyverno to metal-01 --- fleet/authentik/fleet.yaml | 57 ++++++++++++++++++---------- fleet/homepage/deployment.yaml | 9 ++++- fleet/kyverno-reporter-ui/fleet.yaml | 9 ++++- fleet/kyverno/fleet.yaml | 36 ++++++++++++++---- fleet/otlp-collector/fleet.yaml | 18 +++++++++ 5 files changed, 96 insertions(+), 33 deletions(-) diff --git a/fleet/authentik/fleet.yaml b/fleet/authentik/fleet.yaml index 0dd222b..c07901f 100644 --- a/fleet/authentik/fleet.yaml +++ b/fleet/authentik/fleet.yaml @@ -55,13 +55,18 @@ helm: - weight: 100 preference: matchExpressions: - - key: node-role.kubernetes.io/control-plane - operator: Exists - # tolerations: - # - key: "dedicated" - # operator: "Equal" - # value: "monitoring" - # effect: "PreferNoSchedule" + - key: kubernetes.io/hostname + operator: In + values: + - metal-01.he-eu-hel1.misc.vacdst + tolerations: + - key: "dedicated" + operator: "Equal" + value: "monitoring" + effect: "PreferNoSchedule" + - key: "node-role.kubernetes.io/control-plane" + operator: "Exists" + effect: "NoSchedule" redis: enabled: true @@ -167,13 +172,18 @@ helm: - weight: 100 preference: matchExpressions: - - key: node-role.kubernetes.io/control-plane - operator: Exists - # tolerations: - # - key: "dedicated" - # operator: "Equal" - # value: "monitoring" - # effect: "PreferNoSchedule" + - key: kubernetes.io/hostname + operator: In + values: + - metal-01.he-eu-hel1.misc.vacdst + tolerations: + - key: "dedicated" + operator: "Equal" + value: "monitoring" + effect: "PreferNoSchedule" + - key: "node-role.kubernetes.io/control-plane" + operator: "Exists" + effect: "NoSchedule" resources: requests: cpu: "4" @@ -200,13 +210,18 @@ helm: - weight: 100 preference: matchExpressions: - - key: node-role.kubernetes.io/control-plane - operator: Exists - # tolerations: - # - key: "dedicated" - # operator: "Equal" - # value: "monitoring" - # effect: "PreferNoSchedule" + - key: kubernetes.io/hostname + operator: In + values: + - metal-01.he-eu-hel1.misc.vacdst + tolerations: + - key: "dedicated" + operator: "Equal" + value: "monitoring" + effect: "PreferNoSchedule" + - key: "node-role.kubernetes.io/control-plane" + operator: "Exists" + effect: "NoSchedule" resources: requests: cpu: "2" diff --git a/fleet/homepage/deployment.yaml b/fleet/homepage/deployment.yaml index e1127ea..2d683d7 100644 --- a/fleet/homepage/deployment.yaml +++ b/fleet/homepage/deployment.yaml @@ -28,13 +28,18 @@ spec: - weight: 100 preference: matchExpressions: - - key: node-role.kubernetes.io/control-plane - operator: Exists + - key: kubernetes.io/hostname + operator: In + values: + - metal-01.he-eu-hel1.misc.vacdst tolerations: - key: "dedicated" operator: "Equal" value: "monitoring" effect: "PreferNoSchedule" + - key: "node-role.kubernetes.io/control-plane" + operator: "Exists" + effect: "NoSchedule" securityContext: runAsNonRoot: true runAsUser: 1000 diff --git a/fleet/kyverno-reporter-ui/fleet.yaml b/fleet/kyverno-reporter-ui/fleet.yaml index 2e31928..853de24 100644 --- a/fleet/kyverno-reporter-ui/fleet.yaml +++ b/fleet/kyverno-reporter-ui/fleet.yaml @@ -17,13 +17,18 @@ helm: - weight: 100 preference: matchExpressions: - - key: node-role.kubernetes.io/control-plane - operator: Exists + - key: kubernetes.io/hostname + operator: In + values: + - metal-01.he-eu-hel1.misc.vacdst tolerations: - key: "dedicated" operator: "Equal" value: "monitoring" effect: "PreferNoSchedule" + - key: "node-role.kubernetes.io/control-plane" + operator: "Exists" + effect: "NoSchedule" ingress: enabled: true className: "traefik" diff --git a/fleet/kyverno/fleet.yaml b/fleet/kyverno/fleet.yaml index c7b1809..3a9f075 100644 --- a/fleet/kyverno/fleet.yaml +++ b/fleet/kyverno/fleet.yaml @@ -15,13 +15,18 @@ helm: - weight: 100 preference: matchExpressions: - - key: node-role.kubernetes.io/control-plane - operator: Exists + - key: kubernetes.io/hostname + operator: In + values: + - metal-01.he-eu-hel1.misc.vacdst tolerations: - key: "dedicated" operator: "Equal" value: "monitoring" effect: "PreferNoSchedule" + - key: "node-role.kubernetes.io/control-plane" + operator: "Exists" + effect: "NoSchedule" backgroundController: replicas: 2 affinity: @@ -30,13 +35,18 @@ helm: - weight: 100 preference: matchExpressions: - - key: node-role.kubernetes.io/control-plane - operator: Exists + - key: kubernetes.io/hostname + operator: In + values: + - metal-01.he-eu-hel1.misc.vacdst tolerations: - key: "dedicated" operator: "Equal" value: "monitoring" effect: "PreferNoSchedule" + - key: "node-role.kubernetes.io/control-plane" + operator: "Exists" + effect: "NoSchedule" cleanupController: replicas: 2 affinity: @@ -45,13 +55,18 @@ helm: - weight: 100 preference: matchExpressions: - - key: node-role.kubernetes.io/control-plane - operator: Exists + - key: kubernetes.io/hostname + operator: In + values: + - metal-01.he-eu-hel1.misc.vacdst tolerations: - key: "dedicated" operator: "Equal" value: "monitoring" effect: "PreferNoSchedule" + - key: "node-role.kubernetes.io/control-plane" + operator: "Exists" + effect: "NoSchedule" reportsController: replicas: 2 affinity: @@ -60,13 +75,18 @@ helm: - weight: 100 preference: matchExpressions: - - key: node-role.kubernetes.io/control-plane - operator: Exists + - key: kubernetes.io/hostname + operator: In + values: + - metal-01.he-eu-hel1.misc.vacdst tolerations: - key: "dedicated" operator: "Equal" value: "monitoring" effect: "PreferNoSchedule" + - key: "node-role.kubernetes.io/control-plane" + operator: "Exists" + effect: "NoSchedule" # Exclude Kyverno report resources from Fleet management diff --git a/fleet/otlp-collector/fleet.yaml b/fleet/otlp-collector/fleet.yaml index 33e7d0b..60812bd 100644 --- a/fleet/otlp-collector/fleet.yaml +++ b/fleet/otlp-collector/fleet.yaml @@ -12,6 +12,24 @@ helm: mode: deployment image: repository: "otel/opentelemetry-collector-contrib" + affinity: + nodeAffinity: + preferredDuringSchedulingIgnoredDuringExecution: + - weight: 100 + preference: + matchExpressions: + - key: kubernetes.io/hostname + operator: In + values: + - metal-01.he-eu-hel1.misc.vacdst + tolerations: + - key: "dedicated" + operator: "Equal" + value: "monitoring" + effect: "PreferNoSchedule" + - key: "node-role.kubernetes.io/control-plane" + operator: "Exists" + effect: "NoSchedule" presets: clusterMetrics: enabled: true From bcbdb720678d495edefd09e55ebb42161ea51fd1 Mon Sep 17 00:00:00 2001 From: mamoutou-diarra Date: Sun, 5 Apr 2026 23:53:45 +0000 Subject: [PATCH 2/4] add cpu and ram panels to Hardware health dashboard --- .../health-hardware-dashboard.yaml | 195 +++++++++++++++++- 1 file changed, 193 insertions(+), 2 deletions(-) diff --git a/fleet/grafana-dashboards/health-hardware-dashboard.yaml b/fleet/grafana-dashboards/health-hardware-dashboard.yaml index 4b6710a..16847a5 100644 --- a/fleet/grafana-dashboards/health-hardware-dashboard.yaml +++ b/fleet/grafana-dashboards/health-hardware-dashboard.yaml @@ -29,7 +29,7 @@ data: "editable": true, "fiscalYearStartMonth": 0, "graphTooltip": 0, - "id": 192, + "id": 195, "links": [], "panels": [ { @@ -414,6 +414,197 @@ data: "panels": [], "title": "CPU/RAM", "type": "row" + }, + { + "datasource": { + "type": "prometheus", + "uid": "P4169E866C3094E38" + }, + "description": "Overall CPU busy percentage (averaged across all cores)", + "fieldConfig": { + "defaults": { + "color": { + "mode": "thresholds" + }, + "decimals": 1, + "mappings": [ + { + "options": { + "match": "null", + "result": { + "text": "N/A" + } + }, + "type": "special" + } + ], + "max": 100, + "min": 0, + "thresholds": { + "mode": "absolute", + "steps": [ + { + "color": "rgba(50, 172, 45, 0.97)", + "value": 0 + }, + { + "color": "rgba(237, 129, 40, 0.89)", + "value": 85 + }, + { + "color": "rgba(245, 54, 54, 0.9)", + "value": 95 + } + ] + }, + "unit": "percent" + }, + "overrides": [] + }, + "gridPos": { + "h": 6, + "w": 24, + "x": 0, + "y": 21 + }, + "id": 51, + "options": { + "minVizHeight": 75, + "minVizWidth": 75, + "orientation": "auto", + "reduceOptions": { + "calcs": [ + "lastNotNull" + ], + "fields": "", + "values": false + }, + "showThresholdLabels": false, + "showThresholdMarkers": true, + "sizing": "auto" + }, + "pluginVersion": "12.3.0", + "targets": [ + { + "editorMode": "code", + "exemplar": false, + "expr": "max by (nodename, cluster) (\n (\n 100 * (\n 1 - avg by (instance, cluster) (\n rate(\n node_cpu_seconds_total{\n mode=\"idle\",\n job=\"node-exporter\"\n }[$__rate_interval]\n )\n )\n )\n )\n * on(instance) group_left(nodename)\n node_uname_info{\n nodename=~\"$host\",\n job=\"node-exporter\"\n }\n)", + "instant": true, + "legendFormat": "{{nodename}}", + "range": false, + "refId": "A", + "step": 240 + } + ], + "title": "CPU Busy", + "transformations": [ + { + "id": "renameByRegex", + "options": { + "regex": "(node-[0-9]*)(.*)", + "renamePattern": "$1" + } + }, + { + "id": "renameByRegex", + "options": { + "regex": "(metal-[0-9]*)(.*)", + "renamePattern": "$1" + } + } + ], + "type": "gauge" + }, + { + "datasource": { + "type": "prometheus", + "uid": "P4169E866C3094E38" + }, + "description": "Real RAM usage excluding cache and reclaimable memory", + "fieldConfig": { + "defaults": { + "color": { + "mode": "thresholds" + }, + "decimals": 1, + "mappings": [], + "max": 100, + "min": 0, + "thresholds": { + "mode": "absolute", + "steps": [ + { + "color": "rgba(50, 172, 45, 0.97)", + "value": 0 + }, + { + "color": "rgba(237, 129, 40, 0.89)", + "value": 80 + }, + { + "color": "rgba(245, 54, 54, 0.9)", + "value": 90 + } + ] + }, + "unit": "percent" + }, + "overrides": [] + }, + "gridPos": { + "h": 5, + "w": 24, + "x": 0, + "y": 27 + }, + "id": 50, + "options": { + "minVizHeight": 75, + "minVizWidth": 75, + "orientation": "auto", + "reduceOptions": { + "calcs": [ + "lastNotNull" + ], + "fields": "", + "values": false + }, + "showThresholdLabels": false, + "showThresholdMarkers": true, + "sizing": "auto" + }, + "pluginVersion": "12.3.0", + "targets": [ + { + "editorMode": "code", + "exemplar": false, + "expr": "clamp_min(\n (\n 1 -\n (\n node_memory_MemAvailable_bytes{\n job=\"node-exporter\"\n }\n /\n node_memory_MemTotal_bytes{\n job=\"node-exporter\"\n }\n )\n ) * 100,\n 0\n)\n* on(instance) group_left(nodename)\n node_uname_info{\n nodename=~\"$host\",\n job=\"node-exporter\"\n }", + "format": "time_series", + "instant": true, + "legendFormat": "{{nodename}}", + "range": false, + "refId": "B", + "step": 240 + } + ], + "title": "RAM Used", + "transformations": [ + { + "id": "renameByRegex", + "options": { + "regex": "(node-[0-9]*)(.*)", + "renamePattern": "$1" + } + }, + { + "id": "renameByRegex", + "options": { + "regex": "(metal-[0-9]*)(.*)", + "renamePattern": "$1" + } + } + ], + "type": "gauge" } ], "preload": false, @@ -455,5 +646,5 @@ data: "timezone": "browser", "title": "Node Hardware", "uid": "ds5hszf", - "version": 3 + "version": 2 } \ No newline at end of file From ce80627a3e6c6c7d8e0ba361074a5e0daf6b5175 Mon Sep 17 00:00:00 2001 From: mamoutou-diarra Date: Mon, 6 Apr 2026 00:03:22 +0000 Subject: [PATCH 3/4] move authentik to control plane --- fleet/authentik/fleet.yaml | 18 ++++++------------ 1 file changed, 6 insertions(+), 12 deletions(-) diff --git a/fleet/authentik/fleet.yaml b/fleet/authentik/fleet.yaml index c07901f..17c9d0e 100644 --- a/fleet/authentik/fleet.yaml +++ b/fleet/authentik/fleet.yaml @@ -55,10 +55,8 @@ helm: - weight: 100 preference: matchExpressions: - - key: kubernetes.io/hostname - operator: In - values: - - metal-01.he-eu-hel1.misc.vacdst + - key: node-role.kubernetes.io/control-plane + operator: Exists tolerations: - key: "dedicated" operator: "Equal" @@ -172,10 +170,8 @@ helm: - weight: 100 preference: matchExpressions: - - key: kubernetes.io/hostname - operator: In - values: - - metal-01.he-eu-hel1.misc.vacdst + - key: node-role.kubernetes.io/control-plane + operator: Exists tolerations: - key: "dedicated" operator: "Equal" @@ -210,10 +206,8 @@ helm: - weight: 100 preference: matchExpressions: - - key: kubernetes.io/hostname - operator: In - values: - - metal-01.he-eu-hel1.misc.vacdst + - key: node-role.kubernetes.io/control-plane + operator: Exists tolerations: - key: "dedicated" operator: "Equal" From aa3df56b005b8eb5d1d88c4268d90bea86fa0d9f Mon Sep 17 00:00:00 2001 From: mamoutou-diarra Date: Mon, 6 Apr 2026 00:16:03 +0000 Subject: [PATCH 4/4] move homepage to controlplane --- fleet/homepage/deployment.yaml | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/fleet/homepage/deployment.yaml b/fleet/homepage/deployment.yaml index 2d683d7..e06d213 100644 --- a/fleet/homepage/deployment.yaml +++ b/fleet/homepage/deployment.yaml @@ -28,10 +28,8 @@ spec: - weight: 100 preference: matchExpressions: - - key: kubernetes.io/hostname - operator: In - values: - - metal-01.he-eu-hel1.misc.vacdst + - key: node-role.kubernetes.io/control-plane + operator: Exists tolerations: - key: "dedicated" operator: "Equal"