Deployment Overview of Percona Monitoring on Server¶
Prerequisites and Basic Requirements¶
The application requires a server running the Ubuntu operating system. The following requirements must be met for a successful deployment:
-
Privileges: Root or sudo access is required to perform package updates and manage Docker containers.
-
Package Manager:
aptmust be available for updating system packages. -
Docker Engine: Docker must be installed on the host system to run the application and the proxy service.
-
Ports:
-
Port
443(HTTPS) is required for external access via the Nginx proxy. -
Port
8080is used internally for communication between the proxy and the PMM server.
FQDN of the final panel on the hostkey.in domain¶
The application is accessible via a specific subdomain template based on the unique Server ID.
| Parameter | Value |
|---|---|
| Prefix | percona |
| Domain | hostkey.in |
| Full template | percona{Server_ID}.hostkey.in |
File and Directory Structure¶
The following directories are used for configuration, certificates, and data persistence:
-
/root/nginx/: Contains the Nginx Docker Compose configuration file (compose.yml). -
/data/nginx/user_conf.d/: Stores custom Nginx user configurations. -
/data/nginx/nginx-certbot.env: Environment file for Certbot settings. -
pmm-data(Docker Volume): Persistent storage for Percona Monitoring and Alerting data.
Application installation process¶
The installation is performed through a series of system updates and container deployments:
-
System Update: The package manager is updated, and all existing packages are upgraded to their latest versions via
apt. -
Docker Installation: Docker engine is installed on the host system.
-
Proxy Setup: A Certbot-enabled Nginx proxy is configured using a dedicated containerized setup.
-
Data Volume Creation: A Docker volume named
pmm-datais created to ensure data persistence for the monitoring server. -
PMM Server Deployment: The Percona Monitoring and Alerting (PMM) version 3 image is pulled from Docker Hub and executed as a standalone container.
Access Rights and Security¶
-
Firewall: Only necessary ports should be open; the Nginx proxy handles secure HTTPS traffic on port
443. -
Internal Communication: The PMM server is bound to
127.0.0.1:8080to prevent direct external access, ensuring all traffic must pass through the Nginx proxy. -
Container Security: The PMM container is configured with specific ulimits (
nofile=1000000) to handle high numbers of open files required for monitoring tasks.
Databases¶
The application uses an internal database system (ClickHouse) managed within the PMM server container. Data is stored in a persistent Docker volume named pmm-data located at /srv inside the container.
Docker Containers and Their Deployment¶
Nginx Proxy Container¶
This container manages SSL certificates via Certbot and handles incoming web traffic.
-
Image:
jonasal/nginx-certbot:latest -
Network Mode:
host -
Volumes:
-
nginx_secrets:/etc/letsencrypt(External volume for SSL certificates) -
/data/nginx/user_conf.d:/etc/nginx/user_conf.d(Custom Nginx configurations) -
Environment Variables:
-
CERTBOT_EMAIL: The email address used for Let's Encrypt notifications.
PMM Server Container¶
The core monitoring application.
-
Image:
percona/pmm-server:3 -
Container Name:
pmm-server -
Ports:
127.0.0.1:8080:8080 -
Volumes:
pmm-data:/srv -
Restart Policy:
unless-stopped -
Environment Variables:
-
PMM_CLICKHOUSE_CONFIG=low-memory -
PMM_ENABLE_UPDATES=0 -
PMM_ENABLE_TELEMETRY=0
Application Update Instructions¶
To update the main application, perform the following steps:
-
Pull the latest image:
-
Restart the container: If using Docker Compose for the proxy or if manual updates are required, use:
Location of configuration files and data¶
| Component | Path / Resource |
|---|---|
| Nginx Compose File | /root/nginx/compose.yml |
| PMM Data Volume | pmm-data |
| Custom Nginx Configs | /data/nginx/user_conf.d |
Available ports for connection¶
-
HTTPS (External):
443 -
PMM Web UI (Internal):
8080
Starting and Stopping the application¶
The following commands are used to manage the PMM server service:
-
Start the container:
-
Stop the container: