import * as pulumi from "@pulumi/pulumi"; import * as inputs from "../types/input"; import * as outputs from "../types/output"; /** * > **Note:** If you change a Scraper's source (EKS cluster or VPC configuration), Terraform * will delete the current Scraper and create a new one. * * Provides an Amazon Managed Service for Prometheus fully managed collector * (scraper). * * Read more in the [Amazon Managed Service for Prometheus user guide](https://docs.aws.amazon.com/prometheus/latest/userguide/AMP-collector.html). * * ## Example Usage * * ### Basic Usage * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.amp.Scraper("example", { * source: { * eks: { * clusterArn: exampleAwsEksCluster.arn, * subnetIds: exampleAwsEksCluster.vpcConfig[0].subnetIds, * }, * }, * destination: { * amp: { * workspaceArn: exampleAwsPrometheusWorkspace.arn, * }, * }, * scrapeConfiguration: `global: * scrape_interval: 30s * scrape_configs: * # pod metrics * - job_name: pod_exporter * kubernetes_sd_configs: * - role: pod * # container metrics * - job_name: cadvisor * scheme: https * authorization: * credentials_file: /var/run/secrets/kubernetes.io/serviceaccount/token * kubernetes_sd_configs: * - role: node * relabel_configs: * - action: labelmap * regex: __meta_kubernetes_node_label_(.+) * - replacement: kubernetes.default.svc:443 * target_label: __address__ * - source_labels: [__meta_kubernetes_node_name] * regex: (.+) * target_label: __metrics_path__ * replacement: /api/v1/nodes/1/proxy/metrics/cadvisor * # apiserver metrics * - bearer_token_file: /var/run/secrets/kubernetes.io/serviceaccount/token * job_name: kubernetes-apiservers * kubernetes_sd_configs: * - role: endpoints * relabel_configs: * - action: keep * regex: default;kubernetes;https * source_labels: * - __meta_kubernetes_namespace * - __meta_kubernetes_service_name * - __meta_kubernetes_endpoint_port_name * scheme: https * # kube proxy metrics * - job_name: kube-proxy * honor_labels: true * kubernetes_sd_configs: * - role: pod * relabel_configs: * - action: keep * source_labels: * - __meta_kubernetes_namespace * - __meta_kubernetes_pod_name * separator: '/' * regex: 'kube-system/kube-proxy.+' * - source_labels: * - __address__ * action: replace * target_label: __address__ * regex: (.+?)(\\\\\\\\:\\\\\\\\d+)? * replacement: 1:10249 * `, * }); * ``` * * ### CloudWatch Destination * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.amp.Scraper("example", { * source: { * eks: { * clusterArn: exampleAwsEksCluster.arn, * subnetIds: exampleAwsEksCluster.vpcConfig[0].subnetIds, * }, * }, * destination: { * cloudwatch: { * datasetArn: "arn:aws:cloudwatch:us-west-2:123456789012:dataset/default", * }, * }, * scrapeConfiguration: `global: * scrape_interval: 30s * scrape_configs: * - job_name: pod_exporter * kubernetes_sd_configs: * - role: pod * `, * }); * ``` * * ### VPC Configuration * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.amp.Scraper("example", { * source: { * vpc: { * securityGroupIds: [exampleAwsSecurityGroup.id], * subnetIds: [ * example1.id, * example2.id, * ], * }, * }, * destination: { * amp: { * workspaceArn: exampleAwsPrometheusWorkspace.arn, * }, * }, * scrapeConfiguration: `global: * scrape_interval: 30s * scrape_configs: * - job_name: 'my-service' * dns_sd_configs: * - names: ['my-service.my-namespace'] * type: A * port: 8080 * metrics_path: '/metrics' * relabel_configs: * - target_label: service_name * replacement: 'my-service' * - target_label: discovery_method * replacement: 'cloudmap-dns' * `, * }); * ``` * * ### OpenSearch Exporter * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.amp.Scraper("example", { * source: { * vpc: { * securityGroupIds: [exampleAwsSecurityGroup.id], * subnetIds: [ * example1.id, * example2.id, * ], * }, * }, * destination: { * amp: { * workspaceArn: exampleAwsPrometheusWorkspace.arn, * }, * }, * exporter: { * opensearch: { * domainArn: exampleAwsOpensearchDomain.arn, * }, * }, * scrapeConfiguration: `global: * scrape_interval: 30s * scrape_configs: * - job_name: 'my-service' * dns_sd_configs: * - names: ['my-service.my-namespace'] * type: A * port: 8080 * metrics_path: '/metrics' * `, * }); * ``` * * ### Use default EKS scraper configuration * * You can use the data source `aws.amp.getDefaultScraperConfiguration` to use a * service managed scrape configuration. * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = aws.amp.getDefaultScraperConfiguration({}); * const exampleScraper = new aws.amp.Scraper("example", { * destination: { * amp: { * workspaceArn: exampleAwsPrometheusWorkspace.arn, * }, * }, * source: { * eks: { * clusterArn: exampleAwsEksCluster.arn, * subnetIds: exampleAwsEksCluster.vpcConfig[0].subnetIds, * }, * }, * scrapeConfiguration: example.then(example => example.configuration), * }); * ``` * * ### Ignoring changes to Prometheus Workspace destination * * A managed scraper will add a `AMPAgentlessScraper` tag to its Prometheus workspace * destination. To avoid Terraform state forcing removing the tag from the workspace, * you can add this tag to the destination workspace (preferred) or ignore tags * changes with `lifecycle`. See example below. * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const _this = aws.eks.getCluster({ * name: "example", * }); * const example = new aws.amp.Workspace("example", {tags: { * AMPAgentlessScraper: "", * }}); * const exampleScraper = new aws.amp.Scraper("example", { * source: { * eks: { * clusterArn: exampleAwsEksCluster.arn, * subnetIds: exampleAwsEksCluster.vpcConfig[0].subnetIds, * }, * }, * destination: { * amp: { * workspaceArn: example.arn, * }, * }, * scrapeConfiguration: "...", * }); * ``` * * ### Configure aws-auth * * Your source Amazon EKS cluster must be configured to allow the scraper to access * metrics. Follow the [user guide](https://docs.aws.amazon.com/prometheus/latest/userguide/AMP-collector-how-to.html#AMP-collector-eks-setup) * to setup the appropriate Kubernetes permissions. * * ### Cross-Account Configuration * * This setup allows the scraper, running in a source account, to remote write its collected metrics to a workspace in a target account. Note that: * * - The target Role and target Workspace must be in the same account * - The source Scraper and target Workspace must be in the same Region * * Follow [the AWS Best Practices guide](https://aws-observability.github.io/observability-best-practices/patterns/ampxa) to learn about the IAM roles configuration and overall setup. * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.amp.Scraper("example", { * source: { * eks: { * clusterArn: exampleAwsEksCluster.arn, * subnetIds: exampleAwsEksCluster.vpcConfig[0].subnetIds, * }, * }, * destination: { * amp: { * workspaceArn: "", * }, * }, * roleConfiguration: { * sourceRoleArn: source.arn, * targetRoleArn: "arn:aws:iam::ACCOUNT-ID:role/target-role-name", * }, * scrapeConfiguration: "...", * }); * ``` * * ## Import * * ### Identity Schema * * #### Required * * * `id` (String) ID of the scraper. * * #### Optional * * * `accountId` (String) AWS Account where this resource is managed. * * `region` (String) Region where this resource is managed. * * Using `pulumi import`, import scrapers using `id`. * For example: * * ```sh * $ pulumi import aws:amp/scraper:Scraper example s-b6f487db-4761-4930-9215-e9d588a7efe2 * ``` */ export declare class Scraper extends pulumi.CustomResource { /** * Get an existing Scraper resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, state?: ScraperState, opts?: pulumi.CustomResourceOptions): Scraper; /** * Returns true if the given object is an instance of Scraper. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is Scraper; /** * Name to associate with the managed scraper. This is for your use, and does not need to be unique. */ readonly alias: pulumi.Output; /** * ARN of the scraper. */ readonly arn: pulumi.Output; /** * Configuration block for the managed scraper to send metrics to. See `destination` Block for details. */ readonly destination: pulumi.Output; /** * Configuration block for additional exporters. See `exporter` Block for details. */ readonly exporter: pulumi.Output; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ readonly region: pulumi.Output; /** * ARN of the IAM role that provides permissions for the scraper to discover, collect, and produce metrics */ readonly roleArn: pulumi.Output; /** * Configuration block to enable writing to an Amazon Managed Service for Prometheus workspace in a different account. See `roleConfiguration` Block for details. */ readonly roleConfiguration: pulumi.Output; /** * Configuration file to use in the new scraper. For more information, see [Scraper configuration](https://docs.aws.amazon.com/prometheus/latest/userguide/AMP-collector-how-to.html#AMP-collector-configuration). */ readonly scrapeConfiguration: pulumi.Output; /** * Configuration block to specify where the managed scraper will collect metrics from. See `source` Block for details. * * The following arguments are optional: */ readonly source: pulumi.Output; /** * Map of tags to assign to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ readonly tags: pulumi.Output<{ [key: string]: string; } | undefined>; /** * Map of tags assigned to the resource, including those inherited from the provider `defaultTags` configuration block. */ readonly tagsAll: pulumi.Output<{ [key: string]: string; }>; readonly timeouts: pulumi.Output; /** * Create a Scraper resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: ScraperArgs, opts?: pulumi.CustomResourceOptions); } /** * Input properties used for looking up and filtering Scraper resources. */ export interface ScraperState { /** * Name to associate with the managed scraper. This is for your use, and does not need to be unique. */ alias?: pulumi.Input; /** * ARN of the scraper. */ arn?: pulumi.Input; /** * Configuration block for the managed scraper to send metrics to. See `destination` Block for details. */ destination?: pulumi.Input; /** * Configuration block for additional exporters. See `exporter` Block for details. */ exporter?: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * ARN of the IAM role that provides permissions for the scraper to discover, collect, and produce metrics */ roleArn?: pulumi.Input; /** * Configuration block to enable writing to an Amazon Managed Service for Prometheus workspace in a different account. See `roleConfiguration` Block for details. */ roleConfiguration?: pulumi.Input; /** * Configuration file to use in the new scraper. For more information, see [Scraper configuration](https://docs.aws.amazon.com/prometheus/latest/userguide/AMP-collector-how-to.html#AMP-collector-configuration). */ scrapeConfiguration?: pulumi.Input; /** * Configuration block to specify where the managed scraper will collect metrics from. See `source` Block for details. * * The following arguments are optional: */ source?: pulumi.Input; /** * Map of tags to assign to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; /** * Map of tags assigned to the resource, including those inherited from the provider `defaultTags` configuration block. */ tagsAll?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; timeouts?: pulumi.Input; } /** * The set of arguments for constructing a Scraper resource. */ export interface ScraperArgs { /** * Name to associate with the managed scraper. This is for your use, and does not need to be unique. */ alias?: pulumi.Input; /** * Configuration block for the managed scraper to send metrics to. See `destination` Block for details. */ destination: pulumi.Input; /** * Configuration block for additional exporters. See `exporter` Block for details. */ exporter?: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * Configuration block to enable writing to an Amazon Managed Service for Prometheus workspace in a different account. See `roleConfiguration` Block for details. */ roleConfiguration?: pulumi.Input; /** * Configuration file to use in the new scraper. For more information, see [Scraper configuration](https://docs.aws.amazon.com/prometheus/latest/userguide/AMP-collector-how-to.html#AMP-collector-configuration). */ scrapeConfiguration: pulumi.Input; /** * Configuration block to specify where the managed scraper will collect metrics from. See `source` Block for details. * * The following arguments are optional: */ source?: pulumi.Input; /** * Map of tags to assign to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; timeouts?: pulumi.Input; } //# sourceMappingURL=scraper.d.ts.map