Skip to content


Add gateway component to tempo-distributed
Browse files Browse the repository at this point in the history
Signed-off-by: Daria Zubairova <>
  • Loading branch information
daryamorgan committed Sep 27, 2021
1 parent 1b00908 commit 21f7aa2
Show file tree
Hide file tree
Showing 16 changed files with 540 additions and 7 deletions.
2 changes: 1 addition & 1 deletion charts/tempo-distributed/Chart.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ apiVersion: v2
name: tempo-distributed
description: Grafana Tempo in MicroService mode
type: application
version: 0.9.14
version: 0.9.15
appVersion: 1.1.0
engine: gotpl
Expand Down
50 changes: 48 additions & 2 deletions charts/tempo-distributed/
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# tempo-distributed

![Version: 0.9.14]( ![Type: application]( ![AppVersion: 1.1.0](
![Version: 0.9.15]( ![Type: application]( ![AppVersion: 1.1.0](

Grafana Tempo in MicroService mode

Expand Down Expand Up @@ -102,6 +102,51 @@ The memcached default args are removed and should be provided manually. The sett
| distributor.service.type | string | `"ClusterIP"` | Type of service for the distributor |
| distributor.terminationGracePeriodSeconds | int | `30` | Grace period to allow the distributor to shutdown before it is killed |
| distributor.tolerations | list | `[]` | Tolerations for distributor pods |
| gateway.affinity | string | Hard node and soft zone anti-affinity | Affinity for gateway pods. Passed through `tpl` and, thus, to be configured as string |
| gateway.basicAuth.enabled | bool | `false` | Enables basic authentication for the gateway |
| gateway.basicAuth.existingSecret | string | `nil` | Existing basic auth secret to use. Must contain '.htpasswd' |
| gateway.basicAuth.htpasswd | string | `"{{ htpasswd (required \"'gateway.basicAuth.username' is required\" .Values.gateway.basicAuth.username) (required \"'gateway.basicAuth.password' is required\" .Values.gateway.basicAuth.password) }}"` | Uses the specified username and password to compute a htpasswd using Sprig's `htpasswd` function. The value is templated using `tpl`. Override this to use a custom htpasswd, e.g. in case the default causes high CPU load. |
| gateway.basicAuth.password | string | `nil` | The basic auth password for the gateway |
| gateway.basicAuth.username | string | `nil` | The basic auth username for the gateway |
| gateway.enabled | bool | `false` | Specifies whether the gateway should be enabled |
| gateway.extraArgs | list | `[]` | Additional CLI args for the gateway |
| gateway.extraEnv | list | `[]` | Environment variables to add to the gateway pods |
| gateway.extraEnvFrom | list | `[]` | Environment variables from secrets or configmaps to add to the gateway pods |
| gateway.extraVolumeMounts | list | `[]` | Volume mounts to add to the gateway pods |
| gateway.extraVolumes | list | `[]` | Volumes to add to the gateway pods |
| gateway.image.pullPolicy | string | `"IfNotPresent"` | The gateway image pull policy |
| gateway.image.registry | string | `""` | The Docker registry for the gateway image |
| gateway.image.repository | string | `"nginxinc/nginx-unprivileged"` | The gateway image repository |
| gateway.image.tag | string | `"1.19-alpine"` | The gateway image tag |
| gateway.ingress.annotations | object | `{}` | Ingress Class Name. MAY be required for Kubernetes versions >= 1.18 ingressClassName: nginx -- Annotations for the gateway ingress |
| gateway.ingress.enabled | bool | `false` | Specifies whether an ingress for the gateway should be created |
| gateway.ingress.hosts | list | `[{"host":"","paths":[{"path":"/"}]}]` | Hosts configuration for the gateway ingress |
| gateway.ingress.tls | list | `[{"hosts":[""],"secretName":"tempo-gateway-tls"}]` | TLS configuration for the gateway ingress |
| gateway.nginxConfig.file | string | See values.yaml | Config file contents for Nginx. Passed through the `tpl` function to allow templating |
| gateway.nginxConfig.httpSnippet | string | `""` | Allows appending custom configuration to the http block |
| gateway.nginxConfig.logFormat | string | `"main '$remote_addr - $remote_user [$time_local] $status '\n '\"$request\" $body_bytes_sent \"$http_referer\" '\n '\"$http_user_agent\" \"$http_x_forwarded_for\"';"` | NGINX log format |
| gateway.nginxConfig.serverSnippet | string | `""` | Allows appending custom configuration to the server block |
| gateway.nodeSelector | object | `{}` | Node selector for gateway pods |
| gateway.podAnnotations | object | `{}` | Annotations for gateway pods |
| gateway.priorityClassName | string | `nil` | The name of the PriorityClass for gateway pods |
| gateway.readinessProbe.httpGet.path | string | `"/"` | |
| gateway.readinessProbe.httpGet.port | string | `"http"` | |
| gateway.readinessProbe.initialDelaySeconds | int | `15` | |
| gateway.readinessProbe.timeoutSeconds | int | `1` | |
| gateway.replicas | int | `1` | Number of replicas for the gateway |
| gateway.resources | object | `{}` | Resource requests and limits for the gateway |
| gateway.service.annotations | object | `{}` | Annotations for the gateway service |
| gateway.service.clusterIP | string | `nil` | ClusterIP of the gateway service |
| gateway.service.labels | object | `{}` | Labels for gateway service |
| gateway.service.loadBalancerIP | string | `nil` | Load balancer IPO address if service type is LoadBalancer |
| gateway.service.nodePort | string | `nil` | Node port if service type is NodePort |
| gateway.service.port | int | `80` | Port of the gateway service |
| gateway.service.type | string | `"ClusterIP"` | Type of the gateway service |
| gateway.terminationGracePeriodSeconds | int | `30` | Grace period to allow the gateway to shutdown before it is killed |
| gateway.tolerations | list | `[]` | Tolerations for gateway pods |
| global.clusterDomain | string | `"cluster.local"` | configures cluster domain ("cluster.local" by default) |
| global.dnsNamespace | string | `"kube-system"` | configures DNS service namespace |
| global.dnsService | string | `"kube-dns"` | configures DNS service name |
| global.image.registry | string | `nil` | Overrides the Docker registry globally for all images |
| global.priorityClassName | string | `nil` | Overrides the priorityClassName for all pods |
| ingester.affinity | string | Hard node and soft zone anti-affinity | Affinity for ingester pods. Passed through `tpl` and, thus, to be configured as string |
Expand Down Expand Up @@ -200,7 +245,7 @@ The memcached default args are removed and should be provided manually. The sett
| serviceMonitor.scrapeTimeout | string | `nil` | ServiceMonitor scrape timeout in Go duration format (e.g. 15s) |
| serviceMonitor.tlsConfig | string | `nil` | ServiceMonitor will use these tlsConfig settings to make the health check requests |
| storage.trace.backend | string | `"local"` | |
| tempo | object | `{"image":{"pullPolicy":"IfNotPresent","registry":"","repository":"grafana/tempo","tag":null},"readinessProbe":{"httpGet":{"path":"/ready","port":"http"},"initialDelaySeconds":30,"timeoutSeconds":1}}` | Overrides the chart's computed fullname fullnameOverride: tempo -- Overrides the chart's computed fullname |
| tempo | object | `{"image":{"pullPolicy":"IfNotPresent","registry":"","repository":"grafana/tempo","tag":null},"readinessProbe":{"httpGet":{"path":"/ready","port":"http"},"initialDelaySeconds":30,"timeoutSeconds":1}}` | Overrides the chart's computed fullname fullnameOverride: tempo |
| tempo.image.registry | string | `""` | The Docker registry |
| tempo.image.repository | string | `"grafana/tempo"` | Docker image repository |
| tempo.image.tag | string | `nil` | Overrides the image tag whose default is the chart's appVersion |
Expand All @@ -227,6 +272,7 @@ The other components are optional and must be explicitly enabled.
| query-frontend | no |
| compactor | no |
| memcached | yes |
| gateway | yes |

## (Configuration)[]

Expand Down
1 change: 1 addition & 0 deletions charts/tempo-distributed/
Original file line number Diff line number Diff line change
Expand Up @@ -79,6 +79,7 @@ The other components are optional and must be explicitly enabled.
| query-frontend | no |
| compactor | no |
| memcached | yes |
| gateway | yes |

## (Configuration)[]
Expand Down
3 changes: 3 additions & 0 deletions charts/tempo-distributed/templates/NOTES.txt
Original file line number Diff line number Diff line change
Expand Up @@ -15,3 +15,6 @@ Installed components:
{{- if .Values.memcached.enabled }}
* memcached
{{- end }}
{{- if .Values.gateway.enabled }}
* gateway
{{- end }}
34 changes: 34 additions & 0 deletions charts/tempo-distributed/templates/_helpers.tpl
Original file line number Diff line number Diff line change
Expand Up @@ -86,3 +86,37 @@ Gossip ring Selector labels
{{- define "tempo.gossipRing.selectorLabels" -}}
tempo-gossip-member: "true"
{{- end -}}

Return the appropriate apiVersion for ingress.
{{- define "tempo.ingress.apiVersion" -}}
{{- if and (.Capabilities.APIVersions.Has "") (semverCompare ">= 1.19-0" .Capabilities.KubeVersion.Version) -}}
{{- print "" -}}
{{- else if .Capabilities.APIVersions.Has "" -}}
{{- print "" -}}
{{- else -}}
{{- print "extensions/v1beta1" -}}
{{- end -}}
{{- end -}}

Return if ingress is stable.
{{- define "tempo.ingress.isStable" -}}
{{- eq (include "tempo.ingress.apiVersion" .) "" -}}
{{- end -}}

Return if ingress supports ingressClassName.
{{- define "tempo.ingress.supportsIngressClassName" -}}
{{- or (eq (include "tempo.ingress.isStable" .) "true") (and (eq (include "tempo.ingress.apiVersion" .) "") (semverCompare ">= 1.18-0" .Capabilities.KubeVersion.Version)) -}}
{{- end -}}

Return if ingress supports pathType.
{{- define "tempo.ingress.supportsPathType" -}}
{{- or (eq (include "tempo.ingress.isStable" .) "true") (and (eq (include "tempo.ingress.apiVersion" .) "") (semverCompare ">= 1.18-0" .Capabilities.KubeVersion.Version)) -}}
{{- end -}}
Original file line number Diff line number Diff line change
@@ -1,3 +1,10 @@
distributor fullname
{{- define "tempo.distributorFullname" -}}
{{ include "tempo.fullname" . }}-distributor
{{- end }}

distributor common labels
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
apiVersion: apps/v1
kind: Deployment
name: {{ template "tempo.fullname" . }}-distributor
name: {{ include "tempo.distributorFullname" . }}
namespace: {{ .Release.Namespace }}
{{- include "tempo.distributorLabels" . | nindent 4 }}
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
apiVersion: v1
kind: Service
name: {{ template "tempo.fullname" . }}-distributor
name: {{ include "tempo.distributorFullname" . }}
namespace: {{ .Release.Namespace }}
{{- include "tempo.distributorLabels" . | nindent 4 }}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
kind: ServiceMonitor
name: {{ template "tempo.fullname" $ }}-distributor
name: {{ include "tempo.distributorFullname" $ }}
{{- with .namespace }}
namespace: {{ . }}
{{- end }}
Expand Down
30 changes: 30 additions & 0 deletions charts/tempo-distributed/templates/gateway/_helpers-gateway.tpl
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
gateway fullname
{{- define "tempo.gatewayFullname" -}}
{{ include "tempo.fullname" . }}-gateway
{{- end }}

gateway common labels
{{- define "tempo.gatewayLabels" -}}
{{ include "tempo.labels" . }} gateway
{{- end }}

gateway selector labels
{{- define "tempo.gatewaySelectorLabels" -}}
{{ include "tempo.selectorLabels" . }} gateway
{{- end }}

gateway image
{{- define "tempo.gatewayImage" -}}
{{- $dict := dict "tempo" .Values.tempo.image "service" .Values.gateway.image "global" "defaultVersion" .Chart.AppVersion -}}
{{- include "tempo.tempoImage" $dict -}}
{{- end }}
11 changes: 11 additions & 0 deletions charts/tempo-distributed/templates/gateway/configmap-gateway.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
{{- if .Values.gateway.enabled }}
apiVersion: v1
kind: ConfigMap
name: {{ include "tempo.gatewayFullname" . }}
{{- include "tempo.gatewayLabels" . | nindent 4 }}
nginx.conf: |
{{- tpl .Values.gateway.nginxConfig.file . | nindent 4 }}
{{- end }}
89 changes: 89 additions & 0 deletions charts/tempo-distributed/templates/gateway/deployment-gateway.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,89 @@
{{- if .Values.gateway.enabled }}
apiVersion: apps/v1
kind: Deployment
name: {{ include "tempo.gatewayFullname" . }}
{{- include "tempo.gatewayLabels" . | nindent 4 }}
minReadySeconds: 10
replicas: {{ .Values.gateway.replicas }}
revisionHistoryLimit: 10
{{- include "tempo.gatewaySelectorLabels" . | nindent 6 }}
checksum/config: {{ include (print .Template.BasePath "/gateway/configmap-gateway.yaml") . | sha256sum }}
{{- with .Values.gateway.podAnnotations }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- include "tempo.gatewaySelectorLabels" . | nindent 8 }}
serviceAccountName: {{ include "tempo.serviceAccountName" . }}
terminationGracePeriodSeconds: {{ .Values.gateway.terminationGracePeriodSeconds }}
- name: nginx
image: {{ include "tempo.gatewayImage" . }}
imagePullPolicy: {{ .Values.gateway.image.pullPolicy }}
- name: http
containerPort: 8080
protocol: TCP
{{- with .Values.gateway.extraEnv }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.gateway.extraEnvFrom }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- toYaml .Values.gateway.readinessProbe | nindent 12 }}
- name: config
mountPath: /etc/nginx
{{- if .Values.gateway.basicAuth.enabled }}
- name: auth
mountPath: /etc/nginx/secrets
{{- end }}
- name: tmp
mountPath: /tmp
- name: docker-entrypoint-d-override
mountPath: /docker-entrypoint.d
{{- if .Values.gateway.extraVolumeMounts }}
{{- toYaml .Values.gateway.extraVolumeMounts | nindent 12 }}
{{- end }}
{{- toYaml .Values.gateway.resources | nindent 12 }}
{{- with .Values.gateway.affinity }}
{{- tpl . $ | nindent 8 }}
{{- end }}
{{- with .Values.gateway.nodeSelector }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.gateway.tolerations }}
{{- toYaml . | nindent 8 }}
{{- end }}
- name: config
name: {{ include "tempo.gatewayFullname" . }}
{{- if .Values.gateway.basicAuth.enabled }}
- name: auth
secretName: {{ include "tempo.gatewayAuthSecret" . }}
{{- end }}
- name: tmp
emptyDir: {}
- name: docker-entrypoint-d-override
emptyDir: {}
{{- if .Values.gateway.extraVolumes }}
{{- toYaml .Values.gateway.extraVolumes | nindent 8 }}
{{- end }}
{{- end }}
55 changes: 55 additions & 0 deletions charts/tempo-distributed/templates/gateway/ingress-gateway.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
{{- if .Values.gateway.enabled -}}
{{- if .Values.gateway.ingress.enabled -}}
{{- $ingressApiIsStable := eq (include "tempo.ingress.isStable" .) "true" -}}
{{- $ingressSupportsIngressClassName := eq (include "tempo.ingress.supportsIngressClassName" .) "true" -}}
{{- $ingressSupportsPathType := eq (include "tempo.ingress.supportsPathType" .) "true" -}}
apiVersion: {{ include "tempo.ingress.apiVersion" . }}
kind: Ingress
name: {{ include "tempo.gatewayFullname" . }}
{{- include "tempo.gatewayLabels" . | nindent 4 }}
{{- with .Values.gateway.ingress.annotations }}
{{- toYaml . | nindent 4 }}
{{- end }}
{{- if and $ingressSupportsIngressClassName .Values.gateway.ingress.ingressClassName }}
ingressClassName: {{ .Values.gateway.ingress.ingressClassName }}
{{- end -}}
{{- if .Values.gateway.ingress.tls }}
{{- range .Values.gateway.ingress.tls }}
- hosts:
{{- range .hosts }}
- {{ . | quote }}
{{- end }}
{{- with .secretName }}
secretName: {{ . }}
{{- end }}
{{- end }}
{{- end }}
{{- range .Values.gateway.ingress.hosts }}
- host: {{ .host | quote }}
{{- range .paths }}
- path: {{ .path }}
{{- if $ingressSupportsPathType }}
pathType: {{ .pathType }}
{{- end }}
{{- if $ingressApiIsStable }}
name: {{ include "tempo.gatewayFullname" $ }}
number: {{ $.Values.gateway.service.port }}
{{- else }}
serviceName: {{ include "tempo.gatewayFullname" $ }}
servicePort: {{ $.Values.gateway.service.port }}
{{- end }}
{{- end }}
{{- end }}
{{- end }}
{{- end }}
13 changes: 13 additions & 0 deletions charts/tempo-distributed/templates/gateway/secret-gateway.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
{{- with .Values.gateway }}
{{- if and .enabled .basicAuth.enabled (not .basicAuth.existingSecret) }}
apiVersion: v1
kind: Secret
name: {{ include "tempo.gatewayFullname" $ }}
{{- include "tempo.gatewayLabels" $ | nindent 4 }}
.htpasswd: |
{{- tpl .basicAuth.htpasswd $ | nindent 4 }}
{{- end }}
{{- end }}

0 comments on commit 21f7aa2

Please sign in to comment.