You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
docs(ha-k8s): document ServiceMonitor scheme and tlsConfig for direct scraping
Covers memgraph/helm-charts#286, which adds prometheus.serviceMonitor.scheme
and prometheus.serviceMonitor.tlsConfig so Prometheus can scrape Memgraph's
OpenMetrics endpoint over HTTPS when Bolt TLS is enabled.
The `scheme` applies to every instance selected by the `ServiceMonitor`, so all
1526
+
coordinators and data instances must expose their metrics endpoint using the same
1527
+
protocol. `insecureSkipVerify: true` is convenient for self-signed certificates but
1528
+
not suitable for production; prefer `caFile`/`ca` together with `serverName` instead:
1529
+
1530
+
```yaml
1531
+
prometheus:
1532
+
serviceMonitor:
1533
+
enabled: true
1534
+
scheme: https
1535
+
tlsConfig:
1536
+
ca:
1537
+
secret:
1538
+
name: bolt-ca-bundle
1539
+
key: ca.crt
1540
+
serverName: memgraph.example.com
1541
+
```
1542
+
1543
+
`tlsConfig`is rendered verbatim into the `ServiceMonitor` endpoint, so any field
1544
+
supported by your Prometheus Operator version can be used.
1545
+
1505
1546
#### Grafana dashboard for direct scraping
1506
1547
1507
1548
Set `prometheus.grafanaDashboard.enabled: true` to ship the bundled "Memgraph
@@ -1861,6 +1902,8 @@ and their default values.
1861
1902
| `prometheus.serviceMonitor.enabled` | If enabled, a `ServiceMonitor` object will be deployed. | `false` |
1862
1903
| `prometheus.serviceMonitor.kubePrometheusStackReleaseName` | The release name under which `kube-prometheus-stack` chart is installed. | `kube-prometheus-stack` |
1863
1904
| `prometheus.serviceMonitor.interval` | How often will Prometheus pull data from Memgraph's Prometheus exporter. | `15s` |
1905
+
| `prometheus.serviceMonitor.scheme` | Protocol Prometheus uses when scraping Memgraph directly (`http` or `https`). Applies to every instance selected by the `ServiceMonitor`. | `http` |
1906
+
| `prometheus.serviceMonitor.tlsConfig` | Prometheus Operator `TLSConfig` for direct HTTPS scraping (e.g. `insecureSkipVerify: true`, or `ca`/`serverName` for production). | `{}` |
1864
1907
| `prometheus.grafanaDashboard.enabled` | Ship the bundled "Memgraph OpenMetrics" Grafana dashboard as a `ConfigMap` for a Grafana sidecar to auto-load. | `false` |
1865
1908
| `prometheus.grafanaDashboard.namespace` | Namespace for the dashboard `ConfigMap`; must be one the Grafana sidecar watches. Defaults to `prometheus.namespace`, else release namespace. | `""` |
0 commit comments