swarm-otel: ship the whole host journal, drop user sessions after it
The swarm collector's journald receiver read only the units listed in `services.hyperhive.swarm.otel.journaldUnits`. A unit nobody listed never reached the store, and a misspelt entry shipped nothing without an error. The list existed to keep an operator's desktop session out of a store every swarm operator can read, but the receiver can only match positively, so the only way to express "not user sessions" was to name every service instead. The receiver now reads the whole host journal, and a new `filter/exclude-user-sessions` processor in the `logs/<swarm>` pipeline drops records whose `_SYSTEMD_SLICE` is `user-<uid>.slice` (session scopes and `user@<uid>.service`). The per-hive `logs/<hive>` pipelines carry agent-container journals only and get no filter. `journaldUnits` is removed with `mkRemovedOptionModule`, together with its non-empty assertion and the entry each host module added. The four module-eval membership checks go with it, replaced by one structural case in swarm-otel-core. Closes #3646
This commit is contained in:
parent
710f5b7b8c
commit
6b1e825c0a
25 changed files with 72 additions and 324 deletions
|
|
@ -2233,32 +2233,6 @@ in
|
|||
# granter step, on the host where that step runs.
|
||||
environment.etc."hyperhive/bao-bootstrap-policy.hcl".source = ./bao-bootstrap-policy.hcl;
|
||||
|
||||
# The in-container unit plus the host-side ones this module defines.
|
||||
# `swarm-bao-pki` and `swarm-bao-matrix-token` are declared by the glue
|
||||
# modules that create them, per the option's own rule — and a name
|
||||
# nothing defines is silently ignored, so naming them from here would
|
||||
# read as coverage on hives that have neither.
|
||||
services.hyperhive.swarm.otel.journaldUnits = [
|
||||
"openbao"
|
||||
"swarm-bao-certs"
|
||||
"swarm-bao-token"
|
||||
"swarm-bao-forwarder-oidc"
|
||||
"swarm-bao-granter-role"
|
||||
"swarm-bao-controller-policy"
|
||||
"swarm-bao-secret-publisher-policy"
|
||||
"swarm-bao-matrix-ctl-policy"
|
||||
"swarm-bao-matrix-token-policy"
|
||||
"swarm-bao-queue-agent-policy"
|
||||
"swarm-bao-grafana-oidc-policy"
|
||||
"swarm-bao-otel-oidc-policy"
|
||||
"swarm-bao-forwarder-oidc-policy"
|
||||
"swarm-bao-services-issuer-policy"
|
||||
"swarm-bao-nats-tls-policy"
|
||||
"swarm-bao-agent-pki"
|
||||
"swarm-bao-nats-auth-policy"
|
||||
"swarm-bao-operator-viewer-policy"
|
||||
];
|
||||
|
||||
# 🚫 No `swarm.otel.scrapeTargets.bao` entry any more, and its absence is
|
||||
# the deliverable rather than a tidy-up. That option is read only by the
|
||||
# SWARM collector, over loopback, so declaring the store there meant its
|
||||
|
|
@ -2266,14 +2240,6 @@ in
|
|||
# nowhere else — silently, since a store with no entry looks identical to
|
||||
# one nothing scrapes. The scrape moved into this container's own
|
||||
# collector (see `receivers.prometheus` below), which travels with the
|
||||
# store.
|
||||
#
|
||||
# Logs are a different story from that move: `journaldUnits` above still
|
||||
# names this store's units, but bao's journal now lives only inside the
|
||||
# container (see the forwarder's own comment below) — nothing links it
|
||||
# into the host tree any more, so the shared collector can never see
|
||||
# these units. The list stays untouched for the sibling containers that
|
||||
# still ride it; bao's own entries come out once delivery through the
|
||||
# container's own collector is confirmed.
|
||||
|
||||
# ⚠️ The one nginx exception to this file's header, and it is one because
|
||||
|
|
@ -3701,18 +3667,14 @@ in
|
|||
# is supposed to ship its own logs to the next hop rather than
|
||||
# leave a *different* container's collector to find them.
|
||||
#
|
||||
# The journal lives inside this container now, the same shape as
|
||||
# every agent container: nothing links it into the host's
|
||||
# /var/log/journal tree, so `swarm.otel.journaldUnits` near the
|
||||
# top of this file can no longer reach any of bao's units through
|
||||
# the shared collector — see the comment there.
|
||||
# The journal lives inside this container, the same shape as every
|
||||
# agent container: nothing links it into the host's
|
||||
# /var/log/journal tree, so the shared collector's journal
|
||||
# receiver never sees any of bao's units.
|
||||
#
|
||||
# ⚠️ NO `units` allowlist here, and that is the point rather than a
|
||||
# simplification. A shared collector needs one because the journal
|
||||
# it reads holds six containers' units plus the host's own; this
|
||||
# one reads only openbao, the UI's nginx and the two oneshots, so
|
||||
# there is nothing foreign to separate out — and a list of unit names
|
||||
# is a thing to get wrong, which ships nothing while looking healthy.
|
||||
# ⚠️ NO `units` allowlist here: this journal holds only openbao,
|
||||
# the UI's nginx and the two oneshots, and a list of unit names is
|
||||
# a thing to get wrong, which ships nothing while looking healthy.
|
||||
assertions = [
|
||||
{
|
||||
# Sibling of the agent forwarder's identical assertion, and it
|
||||
|
|
|
|||
Loading…
Reference in a new issue