add ssl to otel-collector

This commit is contained in:
2026-07-31 16:09:54 +00:00
parent 7d82b3b289
commit c7e83cd7c4
4 changed files with 36 additions and 11 deletions
+2
View File
@@ -1 +1,3 @@
.env
ssl
/
+11 -10
View File
@@ -6,8 +6,16 @@ receivers:
protocols:
grpc:
endpoint: 0.0.0.0:4317
tls:
ca_file: /etc/otelcol-contrib/ca.crt
cert_file: /etc/otelcol-contrib/otel.crt
key_file: /etc/otelcol-contrib/otel.key
http:
endpoint: 0.0.0.0:4318
tls:
ca_file: /etc/otelcol-contrib/ca.crt
cert_file: /etc/otelcol-contrib/otel.crt
key_file: /etc/otelcol-contrib/otel.key
processors:
# Batch processor for efficient data transfer
@@ -15,13 +23,6 @@ processors:
timeout: 5s
send_batch_size: 512
# Add resource attributes for better correlation
resource:
attributes:
- key: environment
value: local-dev
action: upsert
exporters:
# Send traces to Tempo via OTLP
otlp/tempo:
@@ -47,13 +48,13 @@ service:
pipelines:
traces:
receivers: [otlp]
processors: [resource, batch]
processors: [batch]
exporters: [otlp/tempo, debug]
metrics:
receivers: [otlp]
processors: [resource, batch]
processors: [batch]
exporters: [prometheusremotewrite/mimir, debug]
logs:
receivers: [otlp]
processors: [resource, batch]
processors: [batch]
exporters: [otlphttp/loki, debug]
+9 -1
View File
@@ -10,12 +10,16 @@ services:
# OpenTelemetry Collector - receives and routes all telemetry
otel-collector:
image: otel/opentelemetry-collector-contrib
container_name: otel-collector
container_name: otel-collector-lgtm
restart: unless-stopped
ports:
- 4317:4317 # gprc
- 4318:4318 # http
volumes:
- ./config/otel-collector.yaml:/etc/otelcol-contrib/config.yaml
- ./ssl/ca.crt:/etc/otelcol-contrib/ca.crt
- ./ssl/server.crt:/etc/otelcol-contrib/otel.crt
- ./ssl/server.key:/etc/otelcol-contrib/otel.key
depends_on:
- tempo
- mimir
@@ -25,6 +29,7 @@ services:
tempo:
image: grafana/tempo:latest
container_name: tempo
restart: unless-stopped
volumes:
- ./config/tempo.yaml:/etc/tempo/config.yaml
- tempo-data:/var/tempo
@@ -36,6 +41,7 @@ services:
mimir:
image: grafana/mimir:latest
container_name: mimir
restart: unless-stopped
volumes:
- ./config/mimir.yaml:/etc/mimir/config.yaml
- mimir-data:/data
@@ -47,6 +53,7 @@ services:
loki:
image: grafana/loki:latest
container_name: loki
restart: unless-stopped
volumes:
- ./config/loki.yaml:/etc/loki/config.yaml
- loki-data:/loki
@@ -58,6 +65,7 @@ services:
grafana:
image: grafana/grafana:latest
container_name: grafana
restart: unless-stopped
environment:
- GF_AUTH_ANONYMOUS_ENABLED=true
- GF_AUTH_ANONYMOUS_ORG_ROLE=Admin
+14
View File
@@ -0,0 +1,14 @@
[ -d ssl ] || mkdir ssl
cd ssl
# create root ca
openssl req -x509 -newkey rsa:8192 -keyout ca.key -out ca.crt -days 36500 -nodes -subj "/CN=LGTM CA"
openssl req -new -newkey rsa:2048 -nodes -keyout server.key -out server.csr -subj "/CN=$(hostname).stuyckv.local"
openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key -CAcreateserial -out server.crt -days 365
sudo chown 10001:10001 ./server.key ./server.crt ./ca.crt
rm server.csr
cd ..