Compare commits

...

3 Commits

5 changed files with 622 additions and 16 deletions
+77 -1
View File
@@ -81,6 +81,57 @@ blackbox-exporter поддерживает ICMP-пробы (prober: icmp). Ме
алертом UptimeKuma. Это реальная авария, а не ошибка конфига: blackbox
корректно видит недоступность шлюза.
### 23. Read-only пользователь Grafana: provisioning НЕ работает (OSS), только UI (2026-09-08)
Задача: дать сотруднику IT Винограда read-only доступ к дашбордам
(`it@vinogorod.ru`, роль Viewer). Попытки автоматизировать — провалились:
- **Файловое provisioning пользователей** (`grafana/provisioning/access-control/users.yml`)
в Grafana 11 OSS **не обрабатывается**: в логах старта только
dashboards/datasources/alerting/plugins; access-control — фича
Enterprise/Cloud (`security.provisioning`). Файл молча игнорируется, даже с
валидным YAML.
- **API create**: `POST /api/users` → 404 (в OSS недоступно). `POST /api/login`
(JSON) → 401 даже при верном пароле; а **Basic auth работает**
(`curl -u estorozhenko:пароль /api/user` → 200).
- Итог: пользователя можно создать **только в UI** (Administration → Users →
New user, роль Viewer). Пароль задаётся при создании.
Проверка после создания:
```bash
curl -s -u 'it@vinogorod.ru:1qazXSW2' http://127.0.0.1:3001/api/user # → 200
curl -s -u 'estorozhenko:ПАРОЛЬ' http://127.0.0.1:3001/api/orgs/1/users # role=Viewer
curl -s -u 'it@vinogorod.ru:1qazXSW2' http://127.0.0.1:3001/api/users # → 403 (read-only)
```
### 24. Ошибка "Datasource __grafana__ was not found" при открытии дашборда (2026-09-08)
Симптом: на `https://grafana.nixg.ru/d/vinograd-wan/vinograd-wan` выскакивало
окно "Failed to retrieve datasource / Datasource __grafana__ was not found".
Панели при этом в порядке (Prometheus uid есть), а **секция `annotations`**
в JSON дашборда ссылалась на встроенный датасорс:
```json
"annotations": { "list": [ { "builtIn": 1,
"datasource": {"type": "grafana", "uid": "__grafana__"}, ... } ] }
```
- `__grafana__` — встроенный datasource Grafana (аннотации/алерты). В нашей
БД `data_source` его НЕТ (только Prometheus и Loki) → Grafana 11 OSS не
может его найти и показывает ошибку. Панели не используют аннотации —
секция добавляется в JSON автоматически при создании (шаблон),
но в файле она бесполезна.
- **Фикс:** очистить `annotations.list` в файле дашборда:
```bash
jq '.annotations.list = []' grafana/dashboards/vinograd-wan.json > /tmp/vw.json \
&& mv /tmp/vw.json grafana/dashboards/vinograd-wan.json
```
Провайдер дашбордов перечитывает файл **каждые 30с** (рестарт не нужен),
в БД появляется version 2 с `"list": []` — ошибка исчезает.
- Эталон: рабочий `garage-cluster.json` всегда имеет `"annotations": {"list": []}`.
- Проверка из БД: `docker cp grafana:/var/lib/grafana/grafana.db /tmp/gf.db` →
`SELECT data FROM dashboard WHERE uid='vinograd-wan'` → `__grafana__` отсутствует.
## Ключевые находки / грабли
### 1. Admin API Garage v2.1 слушает ОТДЕЛЬНЫЙ порт (`[admin] api_bind_addr`)
@@ -390,10 +441,35 @@ curl -G "http://127.0.0.1:3100/loki/api/v1/query_range" \
--data-urlencode 'query={container="garage"}' --data-urlencode 'limit=3'
```
### 25. vps03 подключён к WireGuard + node-exporter (2026-09-08)
Задача: мониторинг vps03 (77.67.89.154, Debian 13) системных метрик
(диски/память/сеть/доступность) в Grafana, не светя порт наружу.
- **Топология WG** (была): hub = vps01 (10.8.0.1, pubkey ZAvz4xCE…), пиры
bigbox (10.8.0.2), vps02 (10.8.0.4). Все слушают 51820.
- **Новая нода**: vps03 = **10.8.0.3**, ключ `HBTzrS86SZ+…`. vps03 инициирует
туннель к hub (Endpoint 5.129.217.146:51820, AllowedIPs 10.8.0.0/24).
- **Главный грабль:** hub видит vps03, но bigbox/vps02 НЕ могут ответить в
10.8.0.3: WireGuard дропает пакеты, чей src-адрес не в AllowedIPs пира.
Пришлось на bigbox и vps02 **расширить AllowedIPs пира vps01** до
`10.8.0.1/32, 10.8.0.3/32` — тогда трафик к vps03 идёт через hub, а ответы
возвращаются самому vps03. (vps03 → hub работает сразу, т.к. у vps03
AllowedIPs = 10.8.0.0/24; но в обратную сторону — нет.)
- **node-exporter на vps03**: apt install, слушает `10.8.0.3:9100` (в
/etc/default/prometheus-node-exporter: `ARGS="--web.listen-address=10.8.0.3:9100"`).
Публичный IP 77.67.89.154:9100 → connection refused (наружу не светит).
- **prometheus.yml**: job `node` получает 4-й таргет `10.8.0.3:9100` (host=vps03,
instance=vps03:9100) + relabel.
- **Дашборд**: `grafana/dashboards/nodes.json` (uid `nodes`, title "Nodes") —
6 панелей: availability (up{job="node"}, stat), disk free GB, memory available
GB, network RX/TX B/s, load1. Provisioner импортирует автоматически.
- Проверка: `curl http://127.0.0.1:9090/api/v1/targets` → node ×4 все up.
## Что осталось сделать / TODO
- [x] Развернуть стек (docker compose up -d) в /opt/monitoring
- [x] Node-exporter на всех 3 хостах (10.8.0.x:9100)
- [x] Node-exporter на всех 4 хостах (10.8.0.x:9100; vps03 = 10.8.0.3)
- [x] Дашборд Garage в Grafana (provisioning + JSON)
- [x] `up{job="garage"}` в Prometheus, Grafana :3001
- [x] Логи garage через promtail → Loki → Grafana
+3
View File
@@ -52,6 +52,9 @@ grafana.nixg.ru → 87.242.100.206 (vps02) → caddy → reverse_proxy 10.8.0.2:
`docker exec caddy caddy reload --config /etc/caddy/Caddyfile`
- Сертификат Let's Encrypt выпускается автоматически.
- Логин: **estorozhenko** (сменён с admin через UI), пароль — задан пользователем.
- Read-only доступ: **it@vinogorod.ru** (роль **Viewer**, создан вручную в UI,
пароль `1qazXSW2`). Только просмотр дашбордов, без правки. Учётка в
`grafana-data` (переживает пересоздание контейнера).
## Garage admin API (метрики)
+531
View File
@@ -0,0 +1,531 @@
{
"annotations": {
"list": []
},
"editable": true,
"fiscalYearStartMonth": 0,
"graphTooltip": 1,
"id": null,
"links": [],
"panels": [
{
"datasource": {
"type": "prometheus",
"uid": "Prometheus"
},
"fieldConfig": {
"defaults": {
"color": {
"mode": "thresholds"
},
"mappings": [
{
"options": {
"0": {
"color": "red",
"text": "DOWN"
},
"1": {
"color": "green",
"text": "UP"
}
},
"type": "value"
}
],
"thresholds": {
"mode": "absolute",
"steps": [
{
"color": "red",
"value": null
},
{
"color": "green",
"value": 1
}
]
}
},
"overrides": []
},
"gridPos": {
"h": 8,
"w": 6,
"x": 0,
"y": 0
},
"id": 1,
"options": {
"colorMode": "background",
"graphMode": "none",
"justifyMode": "auto",
"orientation": "auto",
"reduceOptions": {
"calcs": [
"lastNotNull"
],
"fields": "",
"values": false
},
"textMode": "auto"
},
"pluginVersion": "11.1.0",
"targets": [
{
"datasource": {
"type": "prometheus",
"uid": "Prometheus"
},
"expr": "up{job=\"node\"}",
"legendFormat": "{{ host }}",
"refId": "A"
}
],
"title": "Nodes availability",
"type": "stat"
},
{
"datasource": {
"type": "prometheus",
"uid": "Prometheus"
},
"fieldConfig": {
"defaults": {
"color": {
"mode": "palette-classic"
},
"custom": {
"axisCenteredZero": false,
"axisColorMode": "text",
"axisLabel": "",
"axisPlacement": "auto",
"drawStyle": "line",
"fillOpacity": 10,
"gradientMode": "none",
"hideFrom": {
"legend": false,
"tooltip": false,
"viz": false
},
"lineInterpolation": "linear",
"lineWidth": 1,
"pointSize": 5,
"scaleDistribution": {
"type": "linear"
},
"showPoints": "never",
"spanNulls": false,
"stacking": {
"group": "A",
"mode": "none"
},
"thresholdsStyle": {
"mode": "off"
}
},
"mappings": [],
"thresholds": {
"mode": "absolute",
"steps": [
{
"color": "green",
"value": null
}
]
}
},
"overrides": []
},
"gridPos": {
"h": 8,
"w": 12,
"x": 12,
"y": 0
},
"id": 2,
"options": {
"legend": {
"calcs": [],
"displayMode": "list",
"placement": "bottom",
"showLegend": true
},
"tooltip": {
"mode": "multi",
"sort": "none"
}
},
"targets": [
{
"datasource": {
"type": "prometheus",
"uid": "Prometheus"
},
"expr": "node_filesystem_avail_bytes{fstype!~\"tmpfs|overlay|squashfs\"} / 1024 / 1024 / 1024",
"legendFormat": "{{ host }} {{ mountpoint }}",
"refId": "A"
}
],
"title": "Node disk free (GB)",
"type": "timeseries"
},
{
"datasource": {
"type": "prometheus",
"uid": "Prometheus"
},
"fieldConfig": {
"defaults": {
"color": {
"mode": "palette-classic"
},
"custom": {
"axisCenteredZero": false,
"axisColorMode": "text",
"axisLabel": "",
"axisPlacement": "auto",
"drawStyle": "line",
"fillOpacity": 10,
"gradientMode": "none",
"hideFrom": {
"legend": false,
"tooltip": false,
"viz": false
},
"lineInterpolation": "linear",
"lineWidth": 1,
"pointSize": 5,
"scaleDistribution": {
"type": "linear"
},
"showPoints": "never",
"spanNulls": false,
"stacking": {
"group": "A",
"mode": "none"
},
"thresholdsStyle": {
"mode": "off"
}
},
"mappings": [],
"thresholds": {
"mode": "absolute",
"steps": [
{
"color": "green",
"value": null
}
]
}
},
"overrides": []
},
"gridPos": {
"h": 8,
"w": 12,
"x": 0,
"y": 8
},
"id": 3,
"options": {
"legend": {
"calcs": [],
"displayMode": "list",
"placement": "bottom",
"showLegend": true
},
"tooltip": {
"mode": "multi",
"sort": "none"
}
},
"targets": [
{
"datasource": {
"type": "prometheus",
"uid": "Prometheus"
},
"expr": "node_memory_MemAvailable_bytes / 1024 / 1024 / 1024",
"legendFormat": "{{ host }}",
"refId": "A"
}
],
"title": "Memory available (GB)",
"type": "timeseries"
},
{
"datasource": {
"type": "prometheus",
"uid": "Prometheus"
},
"fieldConfig": {
"defaults": {
"color": {
"mode": "palette-classic"
},
"custom": {
"axisCenteredZero": false,
"axisColorMode": "text",
"axisLabel": "",
"axisPlacement": "auto",
"drawStyle": "line",
"fillOpacity": 10,
"gradientMode": "none",
"hideFrom": {
"legend": false,
"tooltip": false,
"viz": false
},
"lineInterpolation": "linear",
"lineWidth": 1,
"pointSize": 5,
"scaleDistribution": {
"type": "linear"
},
"showPoints": "never",
"spanNulls": false,
"stacking": {
"group": "A",
"mode": "none"
},
"thresholdsStyle": {
"mode": "off"
}
},
"mappings": [],
"thresholds": {
"mode": "absolute",
"steps": [
{
"color": "green",
"value": null
}
]
}
},
"overrides": []
},
"gridPos": {
"h": 8,
"w": 12,
"x": 0,
"y": 16
},
"id": 4,
"options": {
"legend": {
"calcs": [],
"displayMode": "list",
"placement": "bottom",
"showLegend": true
},
"tooltip": {
"mode": "multi",
"sort": "none"
}
},
"targets": [
{
"datasource": {
"type": "prometheus",
"uid": "Prometheus"
},
"expr": "rate(node_net_bytes_rx_total[5m])",
"legendFormat": "{{ host }} RX",
"refId": "A"
}
],
"title": "Network RX bytes/s",
"type": "timeseries"
},
{
"datasource": {
"type": "prometheus",
"uid": "Prometheus"
},
"fieldConfig": {
"defaults": {
"color": {
"mode": "palette-classic"
},
"custom": {
"axisCenteredZero": false,
"axisColorMode": "text",
"axisLabel": "",
"axisPlacement": "auto",
"drawStyle": "line",
"fillOpacity": 10,
"gradientMode": "none",
"hideFrom": {
"legend": false,
"tooltip": false,
"viz": false
},
"lineInterpolation": "linear",
"lineWidth": 1,
"pointSize": 5,
"scaleDistribution": {
"type": "linear"
},
"showPoints": "never",
"spanNulls": false,
"stacking": {
"group": "A",
"mode": "none"
},
"thresholdsStyle": {
"mode": "off"
}
},
"mappings": [],
"thresholds": {
"mode": "absolute",
"steps": [
{
"color": "green",
"value": null
}
]
}
},
"overrides": []
},
"gridPos": {
"h": 8,
"w": 12,
"x": 12,
"y": 16
},
"id": 5,
"options": {
"legend": {
"calcs": [],
"displayMode": "list",
"placement": "bottom",
"showLegend": true
},
"tooltip": {
"mode": "multi",
"sort": "none"
}
},
"targets": [
{
"datasource": {
"type": "prometheus",
"uid": "Prometheus"
},
"expr": "rate(node_net_bytes_tx_total[5m])",
"legendFormat": "{{ host }} TX",
"refId": "A"
}
],
"title": "Network TX bytes/s",
"type": "timeseries"
},
{
"datasource": {
"type": "prometheus",
"uid": "Prometheus"
},
"fieldConfig": {
"defaults": {
"color": {
"mode": "palette-classic"
},
"custom": {
"axisCenteredZero": false,
"axisColorMode": "text",
"axisLabel": "",
"axisPlacement": "auto",
"drawStyle": "line",
"fillOpacity": 10,
"gradientMode": "none",
"hideFrom": {
"legend": false,
"tooltip": false,
"viz": false
},
"lineInterpolation": "linear",
"lineWidth": 1,
"pointSize": 5,
"scaleDistribution": {
"type": "linear"
},
"showPoints": "never",
"spanNulls": false,
"stacking": {
"group": "A",
"mode": "none"
},
"thresholdsStyle": {
"mode": "off"
}
},
"mappings": [],
"thresholds": {
"mode": "absolute",
"steps": [
{
"color": "green",
"value": null
}
]
}
},
"overrides": []
},
"gridPos": {
"h": 8,
"w": 12,
"x": 0,
"y": 24
},
"id": 6,
"options": {
"legend": {
"calcs": [],
"displayMode": "list",
"placement": "bottom",
"showLegend": true
},
"tooltip": {
"mode": "multi",
"sort": "none"
}
},
"targets": [
{
"datasource": {
"type": "prometheus",
"uid": "Prometheus"
},
"expr": "node_load1",
"legendFormat": "{{ host }}",
"refId": "A"
}
],
"title": "Load (1m)",
"type": "timeseries"
}
],
"refresh": "15s",
"schemaVersion": 1,
"tags": [
"nodes"
],
"time": {
"from": "now-6h",
"to": "now"
},
"timepicker": [
{
"refresh": "15s"
}
],
"title": "Nodes",
"uid": "nodes",
"version": 1
}
+2 -15
View File
@@ -1,19 +1,6 @@
{
"annotations": {
"list": [
{
"builtIn": 1,
"datasource": {
"type": "grafana",
"uid": "__grafana__"
},
"enable": true,
"hide": true,
"iconColor": "rgba(0, 211, 255, 1)",
"name": "Annotations & Alerts",
"type": "style"
}
]
"list": []
},
"editable": true,
"fiscalYearStartMonth": 0,
@@ -212,4 +199,4 @@
"uid": "vinograd-wan",
"version": 1,
"weekStart": ""
}
}
+9
View File
@@ -76,6 +76,10 @@ scrape_configs:
- 10.8.0.4:9100
labels:
host: vps02
- targets:
- 10.8.0.3:9100
labels:
host: vps03
relabel_configs:
- source_labels:
- __address__
@@ -92,6 +96,11 @@ scrape_configs:
regex: 10.8.0.4:9100
target_label: instance
replacement: vps02:9100
- source_labels:
- __address__
regex: 10.8.0.3:9100
target_label: instance
replacement: vps03:9100
- job_name: prometheus
static_configs:
- targets: