openshift / cluster-monitoring-operator

Manage the OpenShift monitoring stack
Apache License 2.0
247 stars 363 forks source link

MON-3748: Enable audit logs by default for metrics-server #2280

Closed slashpai closed 7 months ago

slashpai commented 7 months ago

Enabling audit logs helps troubleshoot issues in Metrics Server. The details of the audit level can be tweaked by selecting an audit profile which corresponds to audit Log Level. See: https://kubernetes.io/docs/tasks/debug-application-cluster/audit/#audit-policy

The following profiles are provided:

User can pick any of the profile by modifying the CMO configmap as follows

apiVersion: v1
kind: ConfigMap
metadata:
  name: cluster-monitoring-config
  namespace: openshift-monitoring
data:
  config.yaml: |
    metricsServer:
      audit:
        profile: Request

Adapted the change as in Prometheus Adapter

openshift-ci-robot commented 7 months ago

@slashpai: This pull request references MON-3748 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "4.16.0" version, but no target version was set.

In response to [this](https://github.com/openshift/cluster-monitoring-operator/pull/2280): >Enabling audit logs helps troubleshoot issues in Metrics Server. The details of the audit level can be tweaked by selecting an audit profile which corresponds to audit Log Level. >See: https://kubernetes.io/docs/tasks/debug-application-cluster/audit/#audit-policy > >The following profiles are provided: > - Metadata: The default audit profile > - None > - Request > - RequestResponse > >User can pick any of the profile by modifying the CMO configmap as follows > >``` >apiVersion: v1 >kind: ConfigMap >metadata: > name: cluster-monitoring-config > namespace: openshift-monitoring >data: > config.yaml: | > metricsServer: > audit: > profile: Request >``` > > > > >**Adapted the change as in Prometheus Adapter** > >* [ ] I added CHANGELOG entry for this change. >* [ ] No user facing changes, so no entry in CHANGELOG was needed. > Instructions for interacting with me using PR comments are available [here](https://prow.ci.openshift.org/command-help?repo=openshift%2Fcluster-monitoring-operator). If you have questions or suggestions related to my behavior, please file an issue against the [openshift-eng/jira-lifecycle-plugin](https://github.com/openshift-eng/jira-lifecycle-plugin/issues/new) repository.
openshift-ci[bot] commented 7 months ago

@slashpai: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/e2e-aws-ovn-single-node 4ec40f89acae0555422d23d605e359798c14e12b link false /test e2e-aws-ovn-single-node
ci/prow/versions 4ec40f89acae0555422d23d605e359798c14e12b link false /test versions

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available [here](https://git.k8s.io/community/contributors/guide/pull-requests.md). If you have questions or suggestions related to my behavior, please file an issue against the [kubernetes/test-infra](https://github.com/kubernetes/test-infra/issues/new?title=Prow%20issue:) repository. I understand the commands that are listed [here](https://go.k8s.io/bot-commands).
machine424 commented 7 months ago

(I'd wait until we're sure those audit logs are useful (helped during a debug or sth) before allowing to enable them (maybe debug logs are sufficient), but your call, as this was already accepted in the enhancement proposal :))

openshift-ci[bot] commented 7 months ago

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: machine424, slashpai

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files: - ~~[OWNERS](https://github.com/openshift/cluster-monitoring-operator/blob/master/OWNERS)~~ [machine424,slashpai] Approvers can indicate their approval by writing `/approve` in a comment Approvers can cancel approval by writing `/approve cancel` in a comment
openshift-bot commented 7 months ago

[ART PR BUILD NOTIFIER]

This PR has been included in build cluster-monitoring-operator-container-v4.16.0-202403141746.p0.g255482d.assembly.stream.el9 for distgit cluster-monitoring-operator. All builds following this will include this PR.