misc: addressed comments

This commit is contained in:
Sheen Capadngan
2025-11-01 03:55:31 +08:00
parent 83da0dd3d9
commit 78b8ff17da
+137 -126
View File
@@ -47,43 +47,53 @@ OTEL_EXPORT_TYPE=prometheus
### Configuration ### Configuration
1. **Enable Prometheus export in Infisical**: <Steps>
<Step title="Enable Prometheus export in Infisical">
```bash
OTEL_TELEMETRY_COLLECTION_ENABLED=true
OTEL_EXPORT_TYPE=prometheus
```
</Step>
```bash <Step title="Expose the metrics port">
OTEL_TELEMETRY_COLLECTION_ENABLED=true Expose the metrics port in your Infisical backend:
OTEL_EXPORT_TYPE=prometheus
```
2. **Expose the metrics port** in your Infisical backend: - **Docker**: Expose port 9464
- **Kubernetes**: Create a service exposing port 9464
- **Other**: Ensure port 9464 is accessible to your monitoring stack
</Step>
- **Docker**: Expose port 9464 <Step title="Create Prometheus configuration">
- **Kubernetes**: Create a service exposing port 9464 Create `prometheus.yml`:
- **Other**: Ensure port 9464 is accessible to your monitoring stack
3. **Create Prometheus configuration** (`prometheus.yml`): ```yaml
global:
scrape_interval: 30s
evaluation_interval: 30s
```yaml scrape_configs:
global: - job_name: "infisical"
scrape_interval: 30s scrape_interval: 30s
evaluation_interval: 30s static_configs:
- targets: ["infisical-backend:9464"] # Adjust hostname/port based on your deployment
metrics_path: "/metrics"
```
scrape_configs: <Note>
- job_name: "infisical" Replace `infisical-backend:9464` with the actual hostname and port where your Infisical backend is running. This could be:
scrape_interval: 30s
static_configs:
- targets: ["infisical-backend:9464"] # Adjust hostname/port based on your deployment
metrics_path: "/metrics"
```
**Note**: Replace `infisical-backend:9464` with the actual hostname and port where your Infisical backend is running. This could be: - **Docker Compose**: `infisical-backend:9464` (service name)
- **Kubernetes**: `infisical-backend.default.svc.cluster.local:9464` (service name)
- **Docker Compose**: `infisical-backend:9464` (service name) - **Bare Metal**: `192.168.1.100:9464` (actual IP address)
- **Kubernetes**: `infisical-backend.default.svc.cluster.local:9464` (service name) - **Cloud**: `your-infisical.example.com:9464` (domain name)
- **Bare Metal**: `192.168.1.100:9464` (actual IP address) </Note>
- **Cloud**: `your-infisical.example.com:9464` (domain name) </Step>
</Steps>
### Deployment Options ### Deployment Options
Once you've configured Infisical to expose metrics, you'll need to deploy Prometheus to scrape and store them. Below are examples for different deployment environments. Choose the option that matches your infrastructure.
<Tabs> <Tabs>
<Tab title="Docker Compose"> <Tab title="Docker Compose">
```yaml ```yaml
@@ -168,94 +178,106 @@ OTEL_EXPORT_TYPE=prometheus
### Configuration ### Configuration
1. **Enable OTLP export in Infisical**: <Steps>
<Step title="Enable OTLP export in Infisical">
```bash
OTEL_TELEMETRY_COLLECTION_ENABLED=true
OTEL_EXPORT_TYPE=otlp
OTEL_EXPORT_OTLP_ENDPOINT=http://otel-collector:4318/v1/metrics
OTEL_COLLECTOR_BASIC_AUTH_USERNAME=infisical
OTEL_COLLECTOR_BASIC_AUTH_PASSWORD=infisical
OTEL_OTLP_PUSH_INTERVAL=30000
```
</Step>
```bash <Step title="Create OpenTelemetry Collector configuration">
OTEL_TELEMETRY_COLLECTION_ENABLED=true Create `otel-collector-config.yaml`:
OTEL_EXPORT_TYPE=otlp
OTEL_EXPORT_OTLP_ENDPOINT=http://otel-collector:4318/v1/metrics
OTEL_COLLECTOR_BASIC_AUTH_USERNAME=infisical
OTEL_COLLECTOR_BASIC_AUTH_PASSWORD=infisical
OTEL_OTLP_PUSH_INTERVAL=30000
```
2. **Create OpenTelemetry Collector configuration** (`otel-collector-config.yaml`): ```yaml
extensions:
health_check:
pprof:
zpages:
basicauth/server:
htpasswd:
inline: |
your_username:your_password
```yaml receivers:
extensions: otlp:
health_check: protocols:
pprof: http:
zpages: endpoint: 0.0.0.0:4318
basicauth/server: auth:
htpasswd: authenticator: basicauth/server
inline: |
your_username:your_password
receivers: prometheus:
otlp: config:
protocols: scrape_configs:
http: - job_name: otel-collector
endpoint: 0.0.0.0:4318 scrape_interval: 30s
auth: static_configs:
authenticator: basicauth/server - targets: [infisical-backend:9464]
metric_relabel_configs:
- action: labeldrop
regex: "service_instance_id|service_name"
prometheus: processors:
config: batch:
scrape_configs:
- job_name: otel-collector
scrape_interval: 30s
static_configs:
- targets: [infisical-backend:9464]
metric_relabel_configs:
- action: labeldrop
regex: "service_instance_id|service_name"
processors: exporters:
batch: prometheus:
endpoint: "0.0.0.0:8889"
auth:
authenticator: basicauth/server
resource_to_telemetry_conversion:
enabled: true
exporters: service:
prometheus: extensions: [basicauth/server, health_check, pprof, zpages]
endpoint: "0.0.0.0:8889" pipelines:
auth: metrics:
authenticator: basicauth/server receivers: [otlp]
resource_to_telemetry_conversion: processors: [batch]
enabled: true exporters: [prometheus]
```
service: <Warning>
extensions: [basicauth/server, health_check, pprof, zpages] Replace `your_username:your_password` with your chosen credentials. These must match the values you set in Infisical's `OTEL_COLLECTOR_BASIC_AUTH_USERNAME` and `OTEL_COLLECTOR_BASIC_AUTH_PASSWORD` environment variables.
pipelines: </Warning>
metrics: </Step>
receivers: [otlp]
processors: [batch]
exporters: [prometheus]
```
**Important**: Replace `your_username:your_password` with your chosen credentials. These must match the values you set in Infisical's `OTEL_COLLECTOR_BASIC_AUTH_USERNAME` and `OTEL_COLLECTOR_BASIC_AUTH_PASSWORD` environment variables. <Step title="Create Prometheus configuration">
Create Prometheus configuration for the collector:
3. **Create Prometheus configuration** for the collector: ```yaml
global:
scrape_interval: 30s
evaluation_interval: 30s
```yaml scrape_configs:
global: - job_name: "otel-collector"
scrape_interval: 30s scrape_interval: 30s
evaluation_interval: 30s static_configs:
- targets: ["otel-collector:8889"] # Adjust hostname/port based on your deployment
metrics_path: "/metrics"
```
scrape_configs: <Note>
- job_name: "otel-collector" Replace `otel-collector:8889` with the actual hostname and port where your OpenTelemetry Collector is running. This could be:
scrape_interval: 30s
static_configs:
- targets: ["otel-collector:8889"] # Adjust hostname/port based on your deployment
metrics_path: "/metrics"
```
**Note**: Replace `otel-collector:8889` with the actual hostname and port where your OpenTelemetry Collector is running. This could be: - **Docker Compose**: `otel-collector:8889` (service name)
- **Kubernetes**: `otel-collector.default.svc.cluster.local:8889` (service name)
- **Docker Compose**: `otel-collector:8889` (service name) - **Bare Metal**: `192.168.1.100:8889` (actual IP address)
- **Kubernetes**: `otel-collector.default.svc.cluster.local:8889` (service name) - **Cloud**: `your-collector.example.com:8889` (domain name)
- **Bare Metal**: `192.168.1.100:8889` (actual IP address) </Note>
- **Cloud**: `your-collector.example.com:8889` (domain name) </Step>
</Steps>
### Deployment Options ### Deployment Options
After configuring Infisical and the OpenTelemetry Collector, you'll need to deploy the collector to receive metrics from Infisical. Below are examples for different deployment environments. Choose the option that matches your infrastructure.
<Tabs> <Tabs>
<Tab title="Docker Compose"> <Tab title="Docker Compose">
```yaml ```yaml
@@ -463,24 +485,6 @@ These metrics track authentication attempts and outcomes, enabling you to monito
</Accordion> </Accordion>
</AccordionGroup> </AccordionGroup>
### Legacy Metrics
These metrics are from the previous instrumentation and may be deprecated in future versions. Consider migrating to the new Core API Metrics for more comprehensive observability.
<AccordionGroup>
<Accordion title="API_latency">
API request latency histogram in milliseconds
- **Labels**: `route`, `method`, `statusCode`
</Accordion>
<Accordion title="API_errors">
API error count histogram
- **Labels**: `route`, `method`, `type`, `name`
</Accordion>
</AccordionGroup>
### Integration & Secret Sync Metrics ### Integration & Secret Sync Metrics
These metrics monitor secret synchronization operations between Infisical and external systems, helping you track sync health, identify integration failures, and troubleshoot connectivity issues. These metrics monitor secret synchronization operations between Infisical and external systems, helping you track sync health, identify integration failures, and troubleshoot connectivity issues.
@@ -531,15 +535,22 @@ These low-level HTTP metrics are automatically collected by OpenTelemetry's inst
## Troubleshooting ## Troubleshooting
### Common Issues <Accordion title="Metrics not appearing">
If your metrics are not showing up in Prometheus or your monitoring system, check the following:
1. **Metrics not appearing**: - Verify `OTEL_TELEMETRY_COLLECTION_ENABLED=true` is set in your Infisical environment variables
- Ensure the correct `OTEL_EXPORT_TYPE` is set (`prometheus` or `otlp`)
- Check network connectivity between Infisical and your monitoring services (Prometheus or OTLP collector)
- For pull-based monitoring: Verify port 9464 is exposed and accessible
- For push-based monitoring: Verify the OTLP endpoint URL is correct and reachable
- Check Infisical backend logs for any errors related to metrics export
</Accordion>
- Check if `OTEL_TELEMETRY_COLLECTION_ENABLED=true` <Accordion title="Authentication errors">
- Verify the correct `OTEL_EXPORT_TYPE` is set If you're experiencing authentication errors with the OpenTelemetry Collector:
- Check network connectivity between services
2. **Authentication errors**: - Verify basic auth credentials in your OTLP configuration match between Infisical and the collector
- Check that `OTEL_COLLECTOR_BASIC_AUTH_USERNAME` and `OTEL_COLLECTOR_BASIC_AUTH_PASSWORD` match the credentials in your `otel-collector-config.yaml`
- Verify basic auth credentials in OTLP configuration - Ensure the htpasswd format in the collector configuration is correct
- Check if credentials match between Infisical and collector - Test the collector endpoint manually using curl with the same credentials to verify they work
</Accordion>