From 86381d705974f8145711d81e46e11f8041d9ca38 Mon Sep 17 00:00:00 2001 From: Niek Otten Date: Mon, 28 Sep 2026 14:31:48 +0200 Subject: [PATCH] feat(k8s): make the OTLP trace endpoint a chart value (refs #186) otelEndpoint defaults to the chart's own tempo; deploy overrides it from the OTEL_ENDPOINT repo variable, so the labs cluster can ship traces to the monitoring stack's Tempo instead of failing every export. Co-Authored-By: Claude Opus 5.5 (1M context) --- .gitea/workflows/deploy.yaml | 5 ++++- infra/helm/big-reference/values.yaml | 13 ++++++++++--- 2 files changed, 14 insertions(+), 4 deletions(-) diff --git a/.gitea/workflows/deploy.yaml b/.gitea/workflows/deploy.yaml index 5c53711..6db3231 100644 --- a/.gitea/workflows/deploy.yaml +++ b/.gitea/workflows/deploy.yaml @@ -34,6 +34,9 @@ jobs: # `true` fills in the medewerker OTP step for the public demo (chart value # demo.otpAutofill). The fixture secret is committed: demo only. OTP_AUTOFILL: ${{ vars.OTP_AUTOFILL }} + # Tempo for the services' traces, e.g. http://tempo.monitoring.svc:4317 (the + # cluster monitoring stack, Infra repo). Empty = the chart default. + OTEL_ENDPOINT: ${{ vars.OTEL_ENDPOINT }} steps: - uses: https://github.com/actions/checkout@v4 @@ -100,7 +103,7 @@ jobs: make k8s-reseed \ TALOS_HOST=${TALOS_HOST:-localhost} \ K8S_REGISTRY=${TALOS_VM_IP:-192.168.122.173}:30500 \ - K8S_SET="${KEYCLOAK_URL:+--set keycloakUrl=$KEYCLOAK_URL} --set demo.otpAutofill=${OTP_AUTOFILL:-false}" + K8S_SET="${KEYCLOAK_URL:+--set keycloakUrl=$KEYCLOAK_URL} --set demo.otpAutofill=${OTP_AUTOFILL:-false}${OTEL_ENDPOINT:+ --set otelEndpoint=$OTEL_ENDPOINT}" # `dev` is a mutable tag and helm sees an unchanged pod template, so the # new images only land on a restart (pullPolicy is already Always). diff --git a/infra/helm/big-reference/values.yaml b/infra/helm/big-reference/values.yaml index 2ef6cda..a3b057b 100644 --- a/infra/helm/big-reference/values.yaml +++ b/infra/helm/big-reference/values.yaml @@ -30,6 +30,12 @@ host: 192.168.122.100 # portals' authority (runbook, "Publishing through the labs Caddy"). keycloakUrl: "" +# Where the .NET services send traces (OTLP gRPC). The default is the chart's own +# `tempo` workload (off by default, like compose). Point it at a Tempo outside the +# release, e.g. the cluster monitoring stack's http://tempo.monitoring.svc:4317 — +# with no Tempo at all, every export fails and is counted as a .NET exception. +otelEndpoint: http://tempo:4317 + demo: # Fill in and submit the medewerker OTP step from the fixture secret, so a public # demo shows MFA enforced without an authenticator: makes the big-demo theme @@ -160,10 +166,11 @@ envGroups: NOTIFICATIONS_DISABLED: "false" RUN_SETUP_CONFIG: "true" - # Traces for the .NET services. Always set, like compose: the exporter fails - # harmlessly when Tempo is absent (services/*/Program.cs). + # Traces for the .NET services. Always set, like compose. With no Tempo behind + # `otelEndpoint` the exporter fails quietly but throws on every batch, which + # shows up as HttpRequestException/SocketException in dotnet_exceptions_total. otel: - OTEL_EXPORTER_OTLP_ENDPOINT: http://tempo:4317 + OTEL_EXPORTER_OTLP_ENDPOINT: '{{ .Values.otelEndpoint }}' OTEL_EXPORTER_OTLP_PROTOCOL: grpc # ── Workloads ────────────────────────────────────────────────────────────────── -- 2.54.0