k8s operator to sync LFGW (metrics filter) ACLs from different Namespaces to common ConfigMap
334
LFGW - is a simple reverse proxy designed for filtering PromQL / MetricsQL metrics based on OIDC roles. It utilizes VictoriaMetrics/metricsql to manipulate label filters in metric expressions according to an Access Control List (ACL) before forwarding a request to Prometheus/VictoriaMetrics.
To configure metric filtering, you need to describe a configuration file, for example: acl.yaml
admin: .*
wallet-stage-ro: wallet-stage
wallet-stage-rw: wallet-stage
LFGW will read this file and apply filtering according to the user roles received from the OIDC provider.
lfgw-config-operator allows you not to describe all ACL rules in a single ConfigMap, but to deploy them in different namespaces as CustorResource
apiVersion: controls.lfgw.io/v1alpha1
kind: ACL
metadata:
name: example-acl
namespace: test
spec:
rules:
- roleName: "admin"
namespaceFilter: ".*"
- roleName: "bots-dev-ro"
namespaceFilter: "bots-dev"
The operator monitors CustomResource ACLs and adds ACL-rules to the target ConfigMap, which is mounted to LFGW. This allows us to manage LFGW configuration more flexibly.
Content type
Image
Digest
sha256:cf34a7412…
Size
31 MB
Last updated
over 2 years ago
docker pull ksxack/lfgw-config-operator:1.0.0