Supported telemetry types
The integration supports these telemetry types:Prerequisites
The integration has the following prerequisites:- Create a PostgreSQL role that can authenticate with a password and connect to the
postgresdatabase and every non-template database on each target. - To collect
ANALYZEprogress metrics (postgresql.analyze.*, PostgreSQL 13 and later) for operations run by other roles, grant the monitoring role the predefinedpg_monitorrole. Grantpg_monitoronly when you need that metric family; it can read privileged server statistics. - Make each PostgreSQL endpoint reachable from the CXDOT Collector.
Configure
The integration is enabled by default. To configure the integration, follow these steps:- For discovered PostgreSQL targets, provide the endpoint and credentials for each instance through autodiscovery annotations. Metrics from discovered pods arrive with that pod’s Kubernetes metadata attached. For more information, see autodiscovery and enrichment.
-
Optional: Configure static targets instead of discovered targets, such as PostgreSQL
servers outside your Kubernetes cluster, and provide the password through your
deployment’s secret management. For example, add the following to the
values.yamlfor your Helm chart:When you configure static targets, this integration instance collects from exactly those targets instead of discovered targets. -
Optional: Disable the integration. For example, add the following to the
values.yamlfor your Helm chart:
Validate
To validate the integration, follow these steps:-
In the Live Telemetry Analyzer,
filter for
__name__=cxdot.integration.target.healthandcxdot.integration.name=postgres. Confirm that each reachable target reports1forcxdot.integration.target.health, identified by itsserver.addressandserver.portattributes. -
In Metrics Explorer,
run the following query while clients are connected to the
PostgreSQL servers:
Confirm that the query returns the expected time series for each target.
Configuration reference
Configure one PostgreSQL integration instance with the following settings. In Helm values, place these settings underconfig.integrations.postgres. In a Collector configuration file, place
them under cxdot.integrations.postgres.
Optional settings
-
enabledType:boolean. Optional. Default:true. Whether to enable this PostgreSQL integration instance. If true, the Collector collects PostgreSQL metrics. If false, the Collector doesn’t run this integration instance. -
usernameType:string. Optional. Default:postgres. PostgreSQL user for connections to every statically configured instance. -
passwordType:string. Optional. PostgreSQL password for connections to every statically configured instance. The Collector requires it to start collecting frominstancesentries, and masks the value in diagnostic output, logs, and errors. -
collection_intervalType:duration. Optional. Default:10s. How often the integration collects metrics from each PostgreSQL instance. -
timeoutType:duration. Optional. Default:10s. Maximum time allowed to collect metrics from a PostgreSQL instance during one interval. A value of0sdisables the timeout. -
instancesType:array of object. Optional. Default:[]. PostgreSQL instances to monitor. Eachendpointuseshost:portformat, such aspostgres.default.svc:5432. When this list contains an instance, the integration monitors only the listed instances and disables discovery through annotations for this integration instance. When the list is empty, the integration monitors targets supplied through PostgreSQL annotations. Each discovered target uses the credentials and TLS settings in its annotation. -
instances[].endpointType:string. Required. Network address of the PostgreSQL instance inhost:portformat. -
tlsType:object. Optional. Transport Layer Security (TLS) settings for connections to statically configured instances. By default, the integration uses TLS and verifies the server certificate. Setinsecure_skip_verifytotrueto use TLS without verifying the certificate. Setinsecuretotrueto connect without TLS. Targets discovered through annotations use the TLS settings in their annotations instead. -
tls.insecureType:boolean. Optional. In gRPC and HTTP when set to true, this is used to disable the client transport security. See https://godoc.org/google.golang.org/grpc#WithInsecure for gRPC. Please refer to https://godoc.org/crypto/tls#Config for more information. (optional, default false) -
tls.insecure_skip_verifyType:boolean. Optional. InsecureSkipVerify will enable TLS but not verify the certificate.