From c7e83cd7c421b7c58d06eb39d84117d230b5bd14 Mon Sep 17 00:00:00 2001 From: Vincent Stuyck Date: Fri, 31 Jul 2026 16:09:54 +0000 Subject: [PATCH] add ssl to otel-collector --- .gitignore | 2 ++ config/otel-collector.yaml | 21 +++++++++++---------- docker-compose.yaml | 10 +++++++++- generate-certificates.sh | 14 ++++++++++++++ 4 files changed, 36 insertions(+), 11 deletions(-) create mode 100755 generate-certificates.sh diff --git a/.gitignore b/.gitignore index 4c49bd7..e206c85 100644 --- a/.gitignore +++ b/.gitignore @@ -1 +1,3 @@ .env +ssl +/ diff --git a/config/otel-collector.yaml b/config/otel-collector.yaml index 12257af..4051560 100644 --- a/config/otel-collector.yaml +++ b/config/otel-collector.yaml @@ -6,8 +6,16 @@ receivers: protocols: grpc: endpoint: 0.0.0.0:4317 + tls: + ca_file: /etc/otelcol-contrib/ca.crt + cert_file: /etc/otelcol-contrib/otel.crt + key_file: /etc/otelcol-contrib/otel.key http: endpoint: 0.0.0.0:4318 + tls: + ca_file: /etc/otelcol-contrib/ca.crt + cert_file: /etc/otelcol-contrib/otel.crt + key_file: /etc/otelcol-contrib/otel.key processors: # Batch processor for efficient data transfer @@ -15,13 +23,6 @@ processors: timeout: 5s send_batch_size: 512 - # Add resource attributes for better correlation - resource: - attributes: - - key: environment - value: local-dev - action: upsert - exporters: # Send traces to Tempo via OTLP otlp/tempo: @@ -47,13 +48,13 @@ service: pipelines: traces: receivers: [otlp] - processors: [resource, batch] + processors: [batch] exporters: [otlp/tempo, debug] metrics: receivers: [otlp] - processors: [resource, batch] + processors: [batch] exporters: [prometheusremotewrite/mimir, debug] logs: receivers: [otlp] - processors: [resource, batch] + processors: [batch] exporters: [otlphttp/loki, debug] diff --git a/docker-compose.yaml b/docker-compose.yaml index fc1a6ac..6765c15 100644 --- a/docker-compose.yaml +++ b/docker-compose.yaml @@ -10,12 +10,16 @@ services: # OpenTelemetry Collector - receives and routes all telemetry otel-collector: image: otel/opentelemetry-collector-contrib - container_name: otel-collector + container_name: otel-collector-lgtm + restart: unless-stopped ports: - 4317:4317 # gprc - 4318:4318 # http volumes: - ./config/otel-collector.yaml:/etc/otelcol-contrib/config.yaml + - ./ssl/ca.crt:/etc/otelcol-contrib/ca.crt + - ./ssl/server.crt:/etc/otelcol-contrib/otel.crt + - ./ssl/server.key:/etc/otelcol-contrib/otel.key depends_on: - tempo - mimir @@ -25,6 +29,7 @@ services: tempo: image: grafana/tempo:latest container_name: tempo + restart: unless-stopped volumes: - ./config/tempo.yaml:/etc/tempo/config.yaml - tempo-data:/var/tempo @@ -36,6 +41,7 @@ services: mimir: image: grafana/mimir:latest container_name: mimir + restart: unless-stopped volumes: - ./config/mimir.yaml:/etc/mimir/config.yaml - mimir-data:/data @@ -47,6 +53,7 @@ services: loki: image: grafana/loki:latest container_name: loki + restart: unless-stopped volumes: - ./config/loki.yaml:/etc/loki/config.yaml - loki-data:/loki @@ -58,6 +65,7 @@ services: grafana: image: grafana/grafana:latest container_name: grafana + restart: unless-stopped environment: - GF_AUTH_ANONYMOUS_ENABLED=true - GF_AUTH_ANONYMOUS_ORG_ROLE=Admin diff --git a/generate-certificates.sh b/generate-certificates.sh new file mode 100755 index 0000000..ad9cb36 --- /dev/null +++ b/generate-certificates.sh @@ -0,0 +1,14 @@ + +[ -d ssl ] || mkdir ssl +cd ssl + +# create root ca +openssl req -x509 -newkey rsa:8192 -keyout ca.key -out ca.crt -days 36500 -nodes -subj "/CN=LGTM CA" + +openssl req -new -newkey rsa:2048 -nodes -keyout server.key -out server.csr -subj "/CN=$(hostname).stuyckv.local" +openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key -CAcreateserial -out server.crt -days 365 + +sudo chown 10001:10001 ./server.key ./server.crt ./ca.crt + +rm server.csr +cd ..