Skip to content

Commit edb91a5

Browse files
committed
docs(ha-k8s): document ServiceMonitor scheme and tlsConfig for direct scraping
Covers memgraph/helm-charts#286, which adds prometheus.serviceMonitor.scheme and prometheus.serviceMonitor.tlsConfig so Prometheus can scrape Memgraph's OpenMetrics endpoint over HTTPS when Bolt TLS is enabled.
1 parent 3aba0c9 commit edb91a5

1 file changed

Lines changed: 43 additions & 0 deletions

File tree

‎pages/clustering/high-availability/setup-ha-cluster-k8s.mdx‎

Lines changed: 43 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1502,6 +1502,47 @@ exposes their monitoring ports automatically. The metric names differ from the l
15021502
JSON exporter, so use the bundled **Memgraph OpenMetrics** dashboard.
15031503
</Callout>
15041504

1505+
#### ServiceMonitor TLS for direct scraping
1506+
1507+
When an instance has `tls.bolt.enabled: true`, Memgraph serves its HTTP monitoring
1508+
endpoint over HTTPS as well, so Prometheus must scrape it with `https`. Set
1509+
`prometheus.serviceMonitor.scheme` and, if needed, a Prometheus Operator
1510+
[`TLSConfig`](https://prometheus-operator.dev/docs/api-reference/api/#monitoring.coreos.com/v1.TLSConfig)
1511+
through `prometheus.serviceMonitor.tlsConfig`:
1512+
1513+
```yaml
1514+
scrapeMemgraphDirectly: true
1515+
1516+
prometheus:
1517+
enabled: false
1518+
serviceMonitor:
1519+
enabled: true
1520+
scheme: https
1521+
tlsConfig:
1522+
insecureSkipVerify: true
1523+
```
1524+
1525+
The `scheme` applies to every instance selected by the `ServiceMonitor`, so all
1526+
coordinators and data instances must expose their metrics endpoint using the same
1527+
protocol. `insecureSkipVerify: true` is convenient for self-signed certificates but
1528+
not suitable for production; prefer `caFile`/`ca` together with `serverName` instead:
1529+
1530+
```yaml
1531+
prometheus:
1532+
serviceMonitor:
1533+
enabled: true
1534+
scheme: https
1535+
tlsConfig:
1536+
ca:
1537+
secret:
1538+
name: bolt-ca-bundle
1539+
key: ca.crt
1540+
serverName: memgraph.example.com
1541+
```
1542+
1543+
`tlsConfig` is rendered verbatim into the `ServiceMonitor` endpoint, so any field
1544+
supported by your Prometheus Operator version can be used.
1545+
15051546
#### Grafana dashboard for direct scraping
15061547

15071548
Set `prometheus.grafanaDashboard.enabled: true` to ship the bundled "Memgraph
@@ -1861,6 +1902,8 @@ and their default values.
18611902
| `prometheus.serviceMonitor.enabled` | If enabled, a `ServiceMonitor` object will be deployed. | `false` |
18621903
| `prometheus.serviceMonitor.kubePrometheusStackReleaseName` | The release name under which `kube-prometheus-stack` chart is installed. | `kube-prometheus-stack` |
18631904
| `prometheus.serviceMonitor.interval` | How often will Prometheus pull data from Memgraph's Prometheus exporter. | `15s` |
1905+
| `prometheus.serviceMonitor.scheme` | Protocol Prometheus uses when scraping Memgraph directly (`http` or `https`). Applies to every instance selected by the `ServiceMonitor`. | `http` |
1906+
| `prometheus.serviceMonitor.tlsConfig` | Prometheus Operator `TLSConfig` for direct HTTPS scraping (e.g. `insecureSkipVerify: true`, or `ca`/`serverName` for production). | `{}` |
18641907
| `prometheus.grafanaDashboard.enabled` | Ship the bundled "Memgraph OpenMetrics" Grafana dashboard as a `ConfigMap` for a Grafana sidecar to auto-load. | `false` |
18651908
| `prometheus.grafanaDashboard.namespace` | Namespace for the dashboard `ConfigMap`; must be one the Grafana sidecar watches. Defaults to `prometheus.namespace`, else release namespace. | `""` |
18661909
| `prometheus.grafanaDashboard.label` | Label the Grafana sidecar selects dashboards by. | `grafana_dashboard` |

0 commit comments

Comments
 (0)