Skip to content

OpenStack collector settings ​

tally-openstack-collector takes every setting from the environment, and every variable Tally defines carries the prefix TALLY_. Section 8 of roadmap/00-conventions.md states that rule.

A secret is given inline or as a path to a file. The File-backed column names the companion variable: the companion is the variable's name plus the suffix _FILE, and a companion that holds a path makes that file's content the value. One trailing newline is trimmed, which is what Kubernetes writes into a Secret volume. An empty file is refused, and so is setting a variable and its _FILE companion at the same time. The collector applies the rule from a private copy, resolveFileSecret in internal/providers/openstack/config.go, rather than from the shared internal/core/envsecret the Reporting API and the engine use. Both spell the convention the same way.

TALLY_LOG_LEVEL takes DEBUG, INFO, WARN or ERROR. The match is exact, so a lower-case info is refused.

Settings ​

VariableTypeDefaultFile-backedGoverns
TALLY_LOG_LEVELstringINFOnoLogLevel is the slog threshold, one of DEBUG, INFO, WARN, or ERROR.
TALLY_METRICS_ENABLEDbooleantruenoMetricsEnabled exposes the instrumentation: false makes GET /metrics answer 404. The variable has no OSC infix because roadmap section 8 lists it among the common variables every service reads.
TALLY_OSC_HTTP_PORTinteger8080noHTTPPort is the port the probe and metrics endpoints listen on. The collector serves no API of its own.
TALLY_OSC_AMQP_URLstringnoneyes (TALLY_OSC_AMQP_URL_FILE)AMQPURL is the broker the notifications are consumed from. It carries the broker password, so it supports the *_FILE convention.
TALLY_OSC_EXCHANGESlist, comma-separatednova,neutron,openstack,glancenoExchanges are the service exchanges the collector binds its queue to. The default covers nova, neutron, cinder and glance: cinder sets no control_exchange of its own and publishes on oslo's default, openstack. A deployment that renamed an exchange through control_exchange lists its own. An exchange the broker does not carry is skipped with a warning and bound once it appears, which is what a fresh cloud needs: glance declares its exchange with its first notification. Octavia publishes on the exchange octavia, and the default leaves it out, because a deployment that runs none would report it missing for as long as the collector runs. A deployment with octavia lists nova,neutron,openstack,glance,octavia.
TALLY_OSC_TOPICSlist, comma-separatednotifications.infonoTopics are the notification topics bound on each exchange, matching the notification_topics of the services being collected.
TALLY_OSC_REQUIRE_EXCHANGESbooleanfalsenoRequireExchanges makes a missing exchange fail the AMQP session instead of being skipped: the collector then consumes nothing until the broker carries every exchange it lists. It is for a deployment that would rather stop than collect from a part of the cloud, and for the simulator stack, whose wait for the collector reads a consumer on the queue as a queue that is bound.
TALLY_OSC_QUEUE_TYPEstringquorumnoQueueType is the type the queue tally-notifications is declared with, quorum or classic. quorum is the default: it declares a replicated queue with the delivery limit disabled, and needs RabbitMQ 4.0 or newer. classic sends no queue type and leaves the choice to the broker: a classic queue on one node, unless the virtual host's default_queue_type is quorum, which creates a quorum queue with the broker's own delivery limit. classic is the setting for a broker older than RabbitMQ 4.0 and for a queue that stays on one node. An existing queue keeps its type, so declaring it with the other one means deleting the queue first.
TALLY_OSC_CLOUDstringnonenoCloud is the cloud name every emitted event is attributed to. It has no default because a guessed cloud silently books usage to the wrong one.
TALLY_OSC_REPORTING_URLstringnonenoReportingURL is the base URL of the Reporting API the sender posts to. It must be an absolute https URL, because the ingest token travels on it; ReportingInsecure is what allows a plaintext one.
TALLY_OSC_REPORTING_INSECUREbooleanfalsenoReportingInsecure allows an http Reporting API. It exists for a collector and an API on the same trusted network, and for development; anywhere else it puts the ingest token on the wire in cleartext.
TALLY_OSC_TOKENstringnoneyes (TALLY_OSC_TOKEN_FILE)Token authenticates the sender against the Reporting API. Supports the *_FILE convention.
TALLY_OSC_BUFFER_PATHstringnonenoBufferPath is the SQLite file backing the outbox. It belongs on a volume that outlives the container: everything consumed but not yet delivered lives there and nowhere else.
TALLY_OSC_BATCH_MAXinteger500noBatchMax is how many buffered events one POST carries, bounded by what the ingest API accepts.
TALLY_OSC_FLUSH_INTERVAL_Sinteger5noFlushIntervalSeconds is how long the sender waits before posting a batch that has not filled up.
TALLY_OSC_BUFFER_MAX_EVENTSinteger1000000noBufferMaxEvents is the outbox depth at which the collector stops consuming. The events then wait on the bus instead of being dropped, which is what keeps an unreachable Reporting API from costing usage data.
TALLY_OSC_PREFETCHinteger100noPrefetch is the AMQP QoS bound: how many unacknowledged messages the broker hands out. Acks follow the outbox insert, so this bounds how much work a crash replays.
TALLY_OSC_UNHEALTHY_THRESHOLD_Sinteger600noUnhealthyThresholdSeconds is how long readiness may keep failing before liveness fails too and the orchestrator restarts the pod.
TALLY_OSC_SUMMARY_INTERVAL_Sinteger60noSummaryIntervalSeconds is how often the collector logs its summary line: the notifications consumed, skipped and unparseable and the events delivered since the previous line, with the state of the session and of the outbox. The line is logged whether or not anything happened, so a collector at rest still reports itself. It cannot be turned off; TALLY_LOG_LEVEL=WARN hides it.

What is checked ​

Load runs in both modes. It resolves the two file-backed secrets, trims a trailing slash off TALLY_OSC_REPORTING_URL, and then checks:

  • TALLY_LOG_LEVEL is one of the four levels above.
  • TALLY_OSC_QUEUE_TYPE is classic or quorum.
  • TALLY_OSC_BATCH_MAX is between 1 and 1000. The upper bound is maxBatchItems in internal/providers/openstack/config.go, and it is the longest array POST /api/v1/events accepts.
  • TALLY_OSC_FLUSH_INTERVAL_S is positive.
  • TALLY_OSC_BUFFER_MAX_EVENTS is positive.
  • TALLY_OSC_PREFETCH is positive.
  • TALLY_OSC_UNHEALTHY_THRESHOLD_S is positive.
  • TALLY_OSC_SUMMARY_INTERVAL_S is positive.

ValidateServe is the collecting mode's startup gate. It adds:

  • TALLY_OSC_AMQP_URL, TALLY_OSC_CLOUD, TALLY_OSC_REPORTING_URL, TALLY_OSC_TOKEN and TALLY_OSC_BUFFER_PATH are set.
  • TALLY_OSC_REPORTING_URL is an absolute http or https URL with a host and with no query and no fragment. The ingest path is appended to the value, and appending to a query or a fragment puts that path inside it.
  • TALLY_OSC_REPORTING_URL uses https, unless TALLY_OSC_REPORTING_INSECURE is true. The ingest token travels on every flush.

ValidateDump is the gate of --dump. It asks for TALLY_OSC_AMQP_URL and nothing else: the mode maps nothing and posts nothing.

Example ​

cmd/tally-openstack-collector/.env.example lists every variable with its default and a comment.

The Debian package installs the same list as /etc/default/tally-openstack-collector, which the systemd unit reads. There the two secrets are left to their _FILE companions, which name /etc/tally/amqp-url and /etc/tally/ingest-token; install the collector from the Debian package has the steps.