Configuring AlertmanagerConfig inhibition rules for Gardener Shoot clusters
0 reputation · 10 Sept 2023, 07:01 UTC
Configuring AlertmanagerConfig inhibition rules for Gardener Shoot clusters
The goal is to reduce notification noise by suppressing alerts labeled with severity=info or debug through an inhibition rule in the Shoot's AlertmanagerConfig.
Gardener’s AlertmanagerConfig CRD lets administrators define receivers, routing trees, and inhibition rules, but the controller does not ship a default rule for info/debug severity and does not validate that the user applying the configuration has permission to create silencing entries in the underlying Alertmanager.
Because the AlertmanagerConfig is continuously reconciled, any silencing entries created directly via the Alertmanager UI or API may be overwritten, leaving it unclear whether operators should rely solely on inhibition rules or also manage silencing through Alertmanager while ensuring the rule persists across Gardener updates.
- What is the recommended approach to ensure a custom inhibition rule for severity=info/debug remains effective after each Gardener reconciliation cycle?
- Does the AlertmanagerConfig controller check the applier’s RBAC permissions for creating silencing entries, or must operators enforce this externally?
- Should operators combine inhibition rules with Alertmanager‑level silencing, and if so, how can they prevent conflicts during reconciliation?