treefmt / nix fmt (pull_request) Successful in 5s
pytest / pytest (pull_request) Successful in 30s
test ebook search / test-ebook-search (pull_request) Successful in 34s
build_systems / build-brain (pull_request) Successful in 49s
build_systems / build-bob (pull_request) Successful in 50s
build_systems / build-rhapsody-in-green (pull_request) Successful in 1m2s
build_systems / build-jeeves (pull_request) Successful in 2m14s
- scrape Portal-1 node metrics over Tailscale - add a hardened Vultr billing and bandwidth exporter - provision host health and infrastructure cost dashboards
Monitoring
Vultr API metrics
The vultr-exporter service reads its API token from:
/zfs/storage/secrets/services/vultr-exporter
Create the file on Jeeves as root with the following contents:
API_KEY=<Vultr API token>
The token needs read access to the Vultr Account and Billing APIs. Unrelated resource collectors are disabled in the packaged exporter.
Restrict the file to root and ensure the public egress IP used by Jeeves is allowed for the token in the Vultr API settings:
sudo chown root:root /zfs/storage/secrets/services/vultr-exporter
sudo chmod 600 /zfs/storage/secrets/services/vultr-exporter
The exporter listens on 127.0.0.1:9188; it is scraped by the local
prometheus-main service every five minutes and is not exposed through the
host firewall.
Portal-1 exposes its node exporter only through tailscale0 on port 9100.
Jeeves reaches it using the Portal-1 Tailscale hostname.