Monitoring the External Secrets Operator for Red Hat OpenShift
By default, the External Secrets Operator for Red Hat OpenShift exposes metrics for the Operator and the operands. You can configure OpenShift Monitoring to collect these metrics by using the Prometheus Operator format.
Enable user workload monitoring
By default, the OpenShift Container Platform monitoring stack does not scrape metrics from user-installed applications like the External Secrets Operator.
Enabling user workload monitoring is necessary to collect critical operational data, such as synchronization status, API error rates, and controller performance. This helps you to configure custom alerts for secret sync failures and create dashboards to monitor the overall health of your secret management system. You can enable monitoring for user-defined projects by configuring user workload monitoring in the cluster. For more information, see "Setting up metrics collection for user-defined projects".
Prerequisites
- You have access to the cluster as a user with the
cluster-adminrole.
Procedure
- Create the
cluster-monitoring-config.yamlYAML file:apiVersion: v1kind: ConfigMapmetadata:name: cluster-monitoring-confignamespace: openshift-monitoringdata:config.yaml: |enableUserWorkload: true - Apply the
ConfigMapby running the following command:$ oc apply -f cluster-monitoring-config.yaml
Verification
-
Verify that the monitoring components for user workloads are running in the
openshift-user-workload-monitoringnamespace by running the following command:$ oc -n openshift-user-workload-monitoring get podExample outputNAME READY STATUS RESTARTS AGEprometheus-operator-5f79cff9c9-67pjb 2/2 Running 0 25hprometheus-user-workload-0 6/6 Running 0 25hthanos-ruler-user-workload-0 4/4 Running 0 25hThe status of the pods such as
prometheus-operator,prometheus-user-workload, andthanos-ruler-user-workloadmust beRunning.
Additional resources
Configure metrics collection for External Secrets Operator for Red Hat OpenShift by using a ServiceMonitor
The External Secrets Operator for Red Hat OpenShift exposes metrics by default on port 8443 at the /metrics service endpoint.
You can configure metrics collection for the Operator by creating a ServiceMonitor custom resource (CR) that enables the Prometheus Operator to collect custom metrics. For more information, see "Configuring user workload monitoring".
Prerequisites
- You have access to the cluster as a user with the
cluster-adminrole. - You have installed the External Secrets Operator for Red Hat OpenShift.
- You have enabled the user workload monitoring.
Procedure
- Configure the Operator to use
HTTPfor the metrics server.HTTPSis enabled by default.-
Update the subscription object for External Secrets Operator for Red Hat OpenShift to configure the
HTTPprotocol by running the following command:$ oc -n external-secrets-operator patch subscription openshift-external-secrets-operator --type='merge' -p '{"spec":{"config":{"env":[{"name":"METRICS_BIND_ADDRESS","value":":8080"}, {"name": "METRICS_SECURE", "value": "false"}]}}}' -
To verify that the External Secrets Operator pod is redeployed and that the configured values for
METRICS_BIND_ADDRESSandMETRICS_SECUREare updated, run the following command:$ oc set env --list deployment/external-secrets-operator-controller-manager -n external-secrets-operator | grep -e METRICS_BIND_ADDRESS -e METRICS_SECURE -e containerThe following example shows that the
METRICS_BIND_ADDRESSandMETRICS_SECUREhave been updated:# deployments/external-secrets-operator-controller-manager, container managerMETRICS_BIND_ADDRESS=:8080METRICS_SECURE=false
-
- Create the
Secretresource with thekubernetes.io/service-account.nameannotation to inject the token required for authenticating with the metrics server.- Create the
secret-external-secrets-operator.yamlYAML file:apiVersion: v1kind: Secretmetadata:labels:app: external-secrets-operatorname: external-secrets-operator-metrics-authnamespace: external-secrets-operatorannotations:kubernetes.io/service-account.name: external-secrets-operator-controller-managertype: kubernetes.io/service-account-token - Create the
Secretresource by running the following command:$ oc apply -f secret-external-secrets-operator.yaml
- Create the
- Create the
ClusterRoleBindingresource required for granting permissions to access metrics:-
Create the
clusterrolebinding-external-secrets.yamlYAML file: The following example shows aclusterrolebinding-external-secrets.yamlfile.apiVersion: rbac.authorization.k8s.io/v1kind: ClusterRoleBindingmetadata:labels:app: external-secrets-operatorname: external-secrets-allow-metrics-accessroleRef:apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: external-secrets-operator-metrics-readersubjects:- kind: ServiceAccountname: external-secrets-operator-controller-managernamespace: external-secrets-operator -
Create the
ClusterRoldeBindingcustom resource by running the following command:$ oc apply -f clusterrolebinding-external-secrets.yaml
-
- Create the
ServiceMonitorCR if using the defaultHTTPS:- Create the
servicemonitor-external-secrets-operator-https.yamlYAML file:apiVersion: monitoring.coreos.com/v1kind: ServiceMonitormetadata:labels:app: external-secrets-operatorname: external-secrets-operator-metrics-monitornamespace: external-secrets-operatorspec:endpoints:- authorization:credentials:name: external-secrets-operator-metrics-authkey: tokentype: Bearerinterval: 60spath: /metricsport: metrics-httpsscheme: httpsscrapeTimeout: 30stlsConfig:ca:configMap:name: openshift-service-ca.crtkey: service-ca.crtserverName: external-secrets-operator-controller-manager-metrics-service.external-secrets-operator.svc.cluster.localnamespaceSelector:matchNames:- external-secrets-operatorselector:matchLabels:app: external-secrets-operatorsvc: external-secrets-operator-controller-manager-metrics-service - Create the
ServiceMonitorCR by running the following command:$ oc apply -f servicemonitor-external-secrets-operator-https.yaml
- Create the
- Create the
ServiceMonitorCR if configured to useHTTP:-
Create the
servicemonitor-external-secrets-operator-http.yamlYAML file:apiVersion: monitoring.coreos.com/v1kind: ServiceMonitormetadata:labels:app: external-secrets-operatorname: external-secrets-operator-metrics-monitornamespace: external-secrets-operatorspec:endpoints:- authorization:credentials:name: external-secrets-operator-metrics-authkey: tokentype: Bearerinterval: 60spath: /metricsport: metrics-httpscheme: httpscrapeTimeout: 30snamespaceSelector:matchNames:- external-secrets-operatorselector:matchLabels:app: external-secrets-operatorsvc: external-secrets-operator-controller-manager-metrics-service -
Create the
ServiceMonitorCR by running the following command:$ oc apply -f servicemonitor-external-secrets-operator-http.yamlAfter the
ServiceMonitorCR is created, the user workload Prometheus instance begins metrics collection from the Operator. The collected metrics are labeled withjob="external-secrets-operator-controller-manager-metrics-service".
-
Verification
- In the OpenShift Container Platform web console, navigate to Observe → Targets.
- In the Label filter field, enter the following labels to filter the metrics targets for each operand:
$ service=external-secrets-operator-controller-manager-metrics-service
- Confirm that the Status column shows
Upfor theexternal-secrets-operator.
Additional resources
Query metrics for the External Secrets Operator for Red Hat OpenShift
As a cluster administrator, or as a user with view access to all namespaces, you can query the Operator metrics by using the OpenShift Container Platform web console or the command-line interface (CLI). For more information, see "Accessing metrics".
Prerequisites
- You have access to the cluster as a user with the
cluster-adminrole. - You have installed the External Secrets Operator for Red Hat OpenShift.
- You have enabled monitoring and metrics collection by creating a
ServiceMonitorobject.
Procedure
- In the OpenShift Container Platform web console, navigate to Observe → Metrics.
- In the query field, enter the following PromQL expressions to query the External Secrets Operator for Red Hat OpenShift metric:
{job="external-secrets-operator-controller-manager-metrics-service"}
Additional resources
Configure metrics collection for External Secrets Operator for Red Hat OpenShift operands by using a ServiceMonitor
The External Secrets Operator for Red Hat OpenShift operands exposes metrics by default on port 8080 at the /metrics service endpoint for all three components (external-secrets, external-secrets-cert-controll, and external-secrets-webhook).
You can configure metrics collection for the external-secrets operands by creating a ServiceMonitor custom resource (CR) that enables the Prometheus Operator to collect custom metrics. For more information, see "Configuring user workload monitoring".
Prerequisites
- You have access to the cluster as a user with the
cluster-adminrole. - You have installed the External Secrets Operator for Red Hat OpenShift.
- You have enabled the user workload monitoring.
Procedure
- Create the
ClusterRoleBindingresource required for granting permissions to access metrics:-
Create the
clusterrolebinding-external-secrets.yamlYAML file: The following example shows aclusterrolebinding-external-secrets.yamlfile.apiVersion: rbac.authorization.k8s.io/v1kind: ClusterRoleBindingmetadata:labels:app: external-secretsname: external-secrets-allow-metrics-accessroleRef:apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: external-secrets-operator-metrics-readersubjects:- kind: ServiceAccountname: external-secretsnamespace: external-secrets- kind: ServiceAccountname: external-secrets-cert-controllernamespace: external-secrets- kind: ServiceAccountname: external-secrets-webhooknamespace: external-secrets -
Create the
ClusterRoldeBindingcustom resource by running the following command:$ oc apply -f clusterrolebinding-external-secrets.yaml
-
- Create the
ServiceMonitorCR:-
Create the
servicemonitor-external-secrets.yamlYAML file:apiVersion: monitoring.coreos.com/v1kind: ServiceMonitormetadata:labels:app: external-secretsname: external-secrets-metrics-monitornamespace: external-secretsspec:endpoints:- interval: 60spath: /metricsport: metricsscheme: httpscrapeTimeout: 30snamespaceSelector:matchNames:- external-secretsselector:matchExpressions:- key: app.kubernetes.io/nameoperator: Invalues:- external-secrets- external-secrets-cert-controller- external-secrets-webhook- key: app.kubernetes.io/instanceoperator: Invalues:- external-secrets- key: app.kubernetes.io/managed-byoperator: Invalues:- external-secrets-operator -
Create the
ServiceMonitorCR by running the following command:$ oc apply -f servicemonitor-external-secrets.yamlAfter the
ServiceMonitorCR is created, the user workload Prometheus instance begins metrics collection from the External Secrets Operator for Red Hat OpenShift operands. The collected metrics are labeled withjob="external-secrets",job="external-secrets-cainjector", andjob="external-secrets-webhook".
-
Verification
-
In the OpenShift Container Platform web console, navigate to Observe → Targets.
-
In the Label filter field, enter the following labels to filter the metrics targets for each operand:
$ service=external-secrets$ service=external-secrets-cert-controller-metrics$ service=external-secrets-webhook -
Confirm that the Status column shows
Upfor theexternal-secrets,external-secrets-cert-controllerandexternal-secrets-webhook.
Additional resources
Query metrics for the external-secrets operand
As a cluster administrator, or as a user with view access to all namespaces, you can query external-secrets operand metrics by using the OpenShift Container Platform web console or the command-line interface (CLI). For more information, see "Accessing metrics".
Prerequisites
- You have access to the cluster as a user with the
cluster-adminrole. - You have installed the External Secrets Operator for Red Hat OpenShift.
- You have enabled monitoring and metrics collection by creating a
ServiceMonitorobject.
Procedure
-
In the OpenShift Container Platform web console, navigate to Observe → Metrics.
-
In the query field, enter the following PromQL expressions to query the External Secrets Operator for Red Hat OpenShift operands metric for each operand:
{job="external-secrets"}{job="external-secrets-webhook"}{job="external-secrets-cert-controller-metrics"}
Additional resources