From 9018c091fad49def751fbd5a3b880873722220b2 Mon Sep 17 00:00:00 2001 From: mr-forust Date: Sat, 3 Oct 2026 22:39:24 +0200 Subject: [PATCH] feat(uptime-kuma): add ServiceMonitor, alerts and secrets example --- uptime-kuma/k8s/alerts.yaml | 40 ++++++++++++++++++++++++++++ uptime-kuma/k8s/secrets.yaml.example | 9 +++++++ uptime-kuma/k8s/servicemonitor.yaml | 23 ++++++++++++++++ 3 files changed, 72 insertions(+) create mode 100644 uptime-kuma/k8s/alerts.yaml create mode 100644 uptime-kuma/k8s/secrets.yaml.example create mode 100644 uptime-kuma/k8s/servicemonitor.yaml diff --git a/uptime-kuma/k8s/alerts.yaml b/uptime-kuma/k8s/alerts.yaml new file mode 100644 index 0000000..e44a7f2 --- /dev/null +++ b/uptime-kuma/k8s/alerts.yaml @@ -0,0 +1,40 @@ +apiVersion: monitoring.coreos.com/v1 +kind: PrometheusRule +metadata: + name: uptime-kuma + namespace: uptime-kuma + labels: + release: prometheus-stack +spec: + groups: + - name: uptime_kuma.monitors + rules: + - alert: KumaMonitorDown + expr: | + monitor_status{monitor_type!="group"} == 0 + for: 5m + labels: + severity: critical + annotations: + summary: "Uptime Kuma monitor down: {{ $labels.monitor_name }}" + description: "Uptime Kuma monitor {{ $labels.monitor_name }} ({{ $labels.monitor_url }}) is down for 5m. Check Uptime Kuma (https://uptime.forust.xyz) and the target service." + + - alert: KumaScrapeDown + expr: | + absent(monitor_status) == 1 + for: 10m + labels: + severity: critical + annotations: + summary: "Uptime Kuma metrics missing" + description: "uptime-kuma: no monitor_status series for 10m. Pod may be down, the uk1_ API key may have been rotated without updating uptime-kuma-secrets, or ServiceMonitor/Service broken. All Kuma monitors are unobserved." + + - alert: KumaCertExpiring + expr: | + monitor_cert_days_remaining < 14 + for: 1h + labels: + severity: warning + annotations: + summary: "TLS cert expiring: {{ $labels.monitor_name }} ({{ $value }}d left)" + description: "Uptime Kuma monitor {{ $labels.monitor_name }} ({{ $labels.monitor_url }}) reports a TLS certificate with {{ $value }} days remaining. Check cert-manager Certificate for this host." diff --git a/uptime-kuma/k8s/secrets.yaml.example b/uptime-kuma/k8s/secrets.yaml.example new file mode 100644 index 0000000..74a1ea3 --- /dev/null +++ b/uptime-kuma/k8s/secrets.yaml.example @@ -0,0 +1,9 @@ +apiVersion: v1 +kind: Secret +metadata: + name: uptime-kuma-secrets + namespace: uptime-kuma +type: Opaque +stringData: + metrics-username: "uptime-kuma" + metrics-password: "REPLACE_ME" diff --git a/uptime-kuma/k8s/servicemonitor.yaml b/uptime-kuma/k8s/servicemonitor.yaml new file mode 100644 index 0000000..5e8ccd9 --- /dev/null +++ b/uptime-kuma/k8s/servicemonitor.yaml @@ -0,0 +1,23 @@ +apiVersion: monitoring.coreos.com/v1 +kind: ServiceMonitor +metadata: + name: uptime-kuma + namespace: uptime-kuma + labels: + release: prometheus-stack +spec: + selector: + matchLabels: + app: uptime-kuma + endpoints: + - port: http + path: /metrics + interval: 60s + scrapeTimeout: 15s + basicAuth: + username: + name: uptime-kuma-secrets + key: metrics-username + password: + name: uptime-kuma-secrets + key: metrics-password