TelemetryDestination Custom Resource
This document applies to the Modelplane main branch and not to the latest release v0.4.
Where the fleet’s telemetry goes. Modelplane composes no collectors until a TelemetryDestination exists: neither tier stores anything, so collecting with nowhere to export would spend GPU-cluster memory on samples nobody reads. Creating one turns collection on everywhere at once. There is no per-deployment opt-out. A ModelDeployment’s author owns neither the destination nor its bill.
Concept guide: Monitor the Fleet →
#Metadata
#Spec
Where the fleet’s telemetry goes. Modelplane composes no collectors until a TelemetryDestination exists: neither tier stores anything, so collecting with nowhere to export would spend GPU-cluster memory on samples nobody reads. Creating one turns collection on everywhere at once. There is no per-deployment opt-out. A ModelDeployment’s author owns neither the destination nor its bill.
The collector’s extensions block, passed through unread, for the authenticator a sink references. Bearer token, basic auth, OIDC and SigV4 all work, because none of them is modelled here.
How to authenticate, for the schemes Modelplane composes. The collector takes no credential inline: it authenticates through an extension an exporter names, so setting this composes that extension and wires the reference. A scheme that isn’t here is still reachable. Define the extension yourself under spec.extensions and name it from this sink’s config, which is what Modelplane does on your behalf.
The key in this sink’s Secret holding the bearer token. Modelplane mounts it as a file and points the authenticator at it, so a rotated token is picked up without restarting the collector.
Anything else that exporter takes, passed through unread: TLS, retry, queueing, compression, headers. Modelplane does not model an exporter’s configuration, because the schema is OpenTelemetry’s and versioned separately. Typing it would mean a Modelplane release for each setting the collector gains, and would drop the ones this has never heard of. What is typed above is what belongs to Modelplane: which sinks exist, what each is called, where it writes, and which Secret it reads.
Where this sink writes. Typed rather than left to the configuration below because it is the setting every destination has to get right, and the one worth catching here rather than in a collector that won’t start. Optional, because not every exporter addresses its destination this way: Kafka takes brokers, the file exporter a path, and the debug exporter nothing at all. Those go in the configuration below, under the names that exporter gives them.
This sink’s name, unique within the destination. It names the collector’s exporter instance, the authenticator Modelplane composes for it, and the directory its credential mounts at, so renaming one restarts the collector.
A Secret holding this sink’s credential. Its keys reach the collector as files under /etc/modelplane/telemetry/
Name of the Secret, in Modelplane’s namespace.
The collector exporter to send with, by the name OpenTelemetry gives it: otlphttp, otlp, prometheusremotewrite, kafka, and every other one the collector provides. Not an enum, because enumerating them here would mean a Modelplane release for each exporter the collector gains, and the collector already refuses to start on a name it doesn’t have.