Update OTEL collector config and docker setup

- Use ssl/ certificates for gRPC and HTTP TLS
- Add Prometheus scrape configs for local and gitea targets
  Keep matrix and caddy scrape targets commented for future use
- Switch exporters to OTLP gRPC and enable TLS certs
- Remove Tempo, Mimir, Loki exporters
- Use batch + resource_detection/docker in all pipelines
- Enable telemetry metrics
- Remove top-level volumes from docker-compose
- Mount docker socket and add docker group
- Drop unused depends_on entries
- Fix cert script to chown ssl dir with sudo -R
This commit is contained in:
2026-08-01 11:11:26 +00:00
parent 07ff12f3dc
commit c8118ee474
3 changed files with 50 additions and 35 deletions
+46 -28
View File
@@ -7,15 +7,36 @@ receivers:
grpc:
endpoint: 0.0.0.0:4317
tls:
ca_file: /etc/otelcol-contrib/ca.crt
cert_file: /etc/otelcol-contrib/otel.crt
key_file: /etc/otelcol-contrib/otel.key
ca_file: /etc/otelcol-contrib/ssl/ca.crt
cert_file: /etc/otelcol-contrib/ssl/server.crt
key_file: /etc/otelcol-contrib/ssl/server.key
http:
endpoint: 0.0.0.0:4318
tls:
ca_file: /etc/otelcol-contrib/ca.crt
cert_file: /etc/otelcol-contrib/otel.crt
key_file: /etc/otelcol-contrib/otel.key
ca_file: /etc/otelcol-contrib/ssl/ca.crt
cert_file: /etc/otelcol-contrib/ssl/server.crt
key_file: /etc/otelcol-contrib/ssl/server.key
prometheus:
config:
scrape_configs:
- job_name: 'otel-collector'
scrape_interval: 5s
static_configs:
- targets: ['127.0.0.1:8888']
- job_name: 'gitea'
scrape_interval: 5s
static_configs:
- targets: ['gitea_server:3000']
# - job_name: 'matrix'
# scrape_interval: 5s
# static_configs:
# - targets: ['matrix-synapse:8888']
# - job_name: 'caddy'
# scrape_interval: 5s
# static_configs:
# - targets: ['caddy-proxy:8888']
processors:
# Batch processor for efficient data transfer
@@ -23,24 +44,18 @@ processors:
timeout: 5s
send_batch_size: 512
resource_detection/docker:
detectors: [env, docker]
timeout: 2s
override: false
exporters:
# Send traces to Tempo via OTLP
otlp/tempo:
endpoint: tempo:4317
otlp_grpc:
endpoint: shion.stuyckv.local:4317
tls:
insecure: true
# Send metrics to Mimir via Prometheus remote write
prometheusremotewrite/mimir:
endpoint: http://mimir:9009/api/v1/push
tls:
insecure: true
# Send logs to Loki via its native OTLP HTTP endpoint
otlphttp/loki:
endpoint: http://loki:3100/otlp
# Keep debug output for development visibility
ca_file: /etc/otelcol-contrib/ssl/ca.crt
cert_file: /etc/otelcol-contrib/ssl/client.crt
key_file: /etc/otelcol-contrib/ssl/client.key
debug:
verbosity: basic
@@ -48,13 +63,16 @@ service:
pipelines:
traces:
receivers: [otlp]
processors: [batch]
exporters: [otlp/tempo, debug]
processors: [batch, resource_detection/docker]
exporters: [otlp_grpc]
metrics:
receivers: [otlp]
processors: [batch]
exporters: [prometheusremotewrite/mimir, debug]
processors: [batch, resource_detection/docker]
exporters: [otlp_grpc, debug]
logs:
receivers: [otlp]
processors: [batch]
exporters: [otlphttp/loki, debug]
processors: [batch, resource_detection/docker]
exporters: [otlp_grpc]
telemetry:
metrics:
+3 -6
View File
@@ -1,6 +1,4 @@
volumes:
services:
# OpenTelemetry Collector - receives and routes all telemetry
@@ -8,13 +6,12 @@ services:
image: otel/opentelemetry-collector-contrib
container_name: otel-collector
restart: unless-stopped
group_add:
- 987 # docker group
ports:
- 4317:4317 # gprc
- 4318:4318 # http
volumes:
- ./config/otel-collector.yaml:/etc/otelcol-contrib/config.yaml
- ./ssl:/etc/otelcol-contrib/ssl
depends_on:
- tempo
- mimir
- loki
- /var/run/docker.sock:/var/run/docker.sock
+1 -1
View File
@@ -25,4 +25,4 @@ request-certificate server
cd ..
# sudo chown -R 10001:10001 ./ssl
sudo chown -R 10001:10001 ./ssl