Skip to main content
Installation

Data sources

Preparing Prometheus, Alertmanager, Grafana and snmp_exporter: read-only accounts, label conventions, vendor recognition, the inventory scrape job and rule write-back.

The gateway connects to your existing Prometheus and Alertmanager; Grafana is optional. Enter the addresses and credentials during install, or after signing in under Settings > Data sources, where Test connection must pass before you can save.

Prometheus

  • The gateway calls the HTTP API read-only: /api/v1/query, query_range, series, labels, metadata, targets, rules and status/*. If a reverse proxy in front of Prometheus requires authentication, give the gateway a read-only account (Basic or Bearer).
  • Private CA: put the CA certificate in ./certs in the install directory and set RST_PROMETHEUS_CA_CERT=/certs/ca.pem in .env. Do not turn certificate checks off.

Label conventions

The bundled network content pack (metric dictionary, alert rule pack and runbooks) assumes:

  • The job of SNMP scrape jobs starts with snmp.
  • Blackbox probes and SNMP scrapes of the same device use the same instance.
  • site, role and vendor target labels are optional. When present they are carried into recording rules and alerts, and triage uses them to rank.

Vendor recognition

Vendors are recognised by the enterprise prefix of sysObjectID. Huawei, H3C, Cisco, Ruijie, Juniper, Fortinet, Sangfor and others use their private MIBs; anything unrecognised falls back to IF-MIB, ENTITY-MIB, ENTITY-SENSOR-MIB and HOST-RESOURCES-MIB.

Inventory scrape job

The network rule pack relies on three rst_* metrics exported from the device inventory: per-interface alert policy, firewall session capacity and HA flags. The gateway exposes them at /metrics/inventory. Add a scrape job to your Prometheus's prometheus.yml, with the gateway's address; if RST_METRICS_TOKEN is set, add authorization:

- job_name: rst-inventory
  honor_labels: true
  metrics_path: /metrics/inventory
  scrape_interval: 60s
  scheme: https
  # authorization:
  #   credentials: <RST_METRICS_TOKEN>
  static_configs:
    - targets: ["copilot.example.com:443"]

Without this job, interface-down alerts only follow the default policy (interfaces with a non-empty ifAlias), firewalls do not report approaching their session limit, and HA problems are not reported.

Alert rule write-back (optional)

After an alert rule is approved, the gateway writes it into its own rule directory, RST_PROM_RULES_DIR. Prometheus has to load that directory (rule_files: [<dir>/*.yml]) and run with --web.enable-lifecycle so the gateway can hot-reload it. Without it, rules can be generated and approved but not written back.

snmp_exporter

Metric names and labels in the network content pack follow deploy/snmp_exporter/snmp.yml in the bundle, whose modules were generated by the official generator from public MIBs. Use this configuration for your snmp_exporter, put community strings or SNMPv3 credentials in a separate auths.yml, and pick modules by device type. To add vendor MIBs, regenerate it in your environment.

Sangfor AF has no public MIB; the bundled Sangfor module is an unverified placeholder that you regenerate after exporting the MIB from the AF. See deploy/snmp_exporter/README.md in the bundle.

Alertmanager

  • The gateway reads /api/v2/alerts and /api/v2/status, and reads and writes /api/v2/silences (creating and expiring silences, all audited).
  • Alert routing does not change: grouping, inhibition and paging stay in Alertmanager's own route and receivers. The gateway's notifications deliver only AI output, so nobody gets an alert twice.

Grafana (optional)

Set GRAFANA_URL to the address the browser uses and GRAFANA_DATASOURCE_UID to the UID of the Prometheus data source in Grafana. Alerts and query results then offer Open in Grafana. The gateway never calls the Grafana API; the link uses the operator's own Grafana session.

On this page