Archive relocate-brouter-to-dedicated-host
Final step (task 9.4) of the BRouter relocation. The change is moved to openspec/changes/archive/2026-04-24-relocate-brouter-to-dedicated-host/ and the four delta specs (brouter-integration, infrastructure, observability, security-hardening) are merged into the main specs: + 6 added requirements ~ 4 modified requirements The two intentionally-unchecked tasks are 2.2 (obsoleted, see crossed-out note) and 9.4 itself (this archive). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
2e5606458d
commit
66fb5d3044
12 changed files with 121 additions and 27 deletions
|
|
@ -1,9 +1,7 @@
|
|||
## Purpose
|
||||
|
||||
Health endpoints, Prometheus metrics, structured logging, Grafana dashboards, and alerting for both apps and the flagship instance.
|
||||
|
||||
## Requirements
|
||||
|
||||
### Requirement: Health endpoints
|
||||
Both apps SHALL expose a `/health` endpoint returning service and database status.
|
||||
|
||||
|
|
@ -73,3 +71,30 @@ Loki SHALL collect and index logs from all Docker containers.
|
|||
#### Scenario: Search logs
|
||||
- **WHEN** an operator searches logs in Grafana
|
||||
- **THEN** they can filter by container name, log level, and time range
|
||||
|
||||
### Requirement: Remote BRouter metrics
|
||||
Prometheus on the flagship host SHALL scrape BRouter-specific metrics from the dedicated BRouter host over the vSwitch. Scraping SHALL be scoped to BRouter containers only and SHALL NOT collect host-level metrics from the dedicated host's other (non-trails.cool) workloads.
|
||||
|
||||
#### Scenario: BRouter container metrics collected
|
||||
- **WHEN** Prometheus scrapes the dedicated BRouter host
|
||||
- **THEN** metrics from the BRouter container (and, if enabled, the Caddy sidecar) are collected via cAdvisor filtered by container label, or via a BRouter/JMX metrics endpoint exposed on the vSwitch
|
||||
|
||||
#### Scenario: No shared-host noise
|
||||
- **WHEN** Prometheus is configured with the remote BRouter scrape target
|
||||
- **THEN** no configuration scrapes the dedicated host's `node_exporter` or metrics from containers other than BRouter and its sidecar
|
||||
|
||||
#### Scenario: BRouter scrape failure alert
|
||||
- **WHEN** the BRouter scrape target returns `up == 0` for more than 2 minutes
|
||||
- **THEN** Grafana fires an alert distinct from flagship-side alerts
|
||||
|
||||
### Requirement: Remote BRouter log shipping
|
||||
Loki on the flagship host SHALL receive BRouter container logs from the dedicated BRouter host via a Promtail or Alloy agent running on that host as the `trails` user. Log shipping SHALL be scoped to BRouter-related containers only.
|
||||
|
||||
#### Scenario: BRouter logs visible in Grafana
|
||||
- **WHEN** the BRouter container writes to stdout or stderr
|
||||
- **THEN** the log line is available in Grafana Explore via Loki with container and host labels identifying it as coming from the dedicated BRouter host
|
||||
|
||||
#### Scenario: Non-BRouter logs not shipped
|
||||
- **WHEN** a non-BRouter container on the dedicated host writes logs
|
||||
- **THEN** those logs are not ingested by the flagship Loki instance
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue