RUM Instructions
Real User Monitoring (RUM) captures performance metrics and user interactions from your web applications in production. Enabling it changes cluster-wide configuration in custom-values.yaml, so make these changes as part of a normal Helm upgrade.
| Session replay storage is optional and configured separately — see RUM Session Replay Storage: AWS S3, RUM Session Replay Storage: Azure Blob, or RUM Session Replay Storage: Google GCS. The steps below are required regardless of whether you enable session replay. |
Configure the custom-values.yaml File
-
In the Kloudfuse UI, create your RUM application and note its application ID. You use this ID when you initialize the frontend SDK. See RUM Applications.
-
Add a
global.rumsection to thecustom-values.yamlfile:global: rum: enabled: trueyamlTo add session replay storage, merge a
sessionReplayStorageblock into this sameglobal.rumsection — see RUM Session Replay Storage: AWS S3, RUM Session Replay Storage: Azure Blob, or RUM Session Replay Storage: Google GCS for the storage-specific fields. -
List RUM-specific Kafka topics in the
custom-values.yamlfile.Use the configuration for the events stream as a reference for the number of replicas and partitions.
- name: kf_rum_session_replay_topic partitions: 3 replicationFactor: 2 - name: kf_rum_views_topic partitions: 3 replicationFactor: 2 - name: kf_rum_actions_topic partitions: 3 replicationFactor: 2 - name: kf_rum_resources_topic partitions: 3 replicationFactor: 2 - name: kf_rum_longtasks_topic partitions: 3 replicationFactor: 2 - name: kf_rum_errors_topic partitions: 3 replicationFactor: 2yaml -
Specify the TLS configuration in the
tlssection of thecustom-values.yamlfile, and ensure you use a publichost.tls: enabled: true (1) host: playground.kloudfuse.io (2) email: admin@kloudfuse.com clusterIssuer: playground-letsencrypt-prodyaml1 enabled: true: Enable TLS.2 host: playground.kloudfuse.io: This host is public. -
Specify the Ingress configuration in the
ingresssection of thecustom-values.yamlfile.RUM must have a public ingest endpoint where the frontend browser posts data.
ingress: controller: service: external: enabled: true (1) externalTrafficPolicy: Local (2)yaml1 Enable external ingress policy 2 Enable and specify external traffic policy. -
Enable RUM in the
ingestersection of thecustom-values.yamlfile:ingester: config: rum: enabled: true # you can ignore the datadog section below from the PR since # this is the default datadog: proxyToDatadogEnabled: falseyaml -
To ingest frontend logs into Kloudfuse, add parsing rules in the
log-parsersection of thecustom-values.yamlfile.Include these rules verbatim, along with existing rules.
- remap: args: kf_additional_tags: - "$.origin" - "$.application_id" - "$.session_id" - "$.view.id" - "$.view.url" - "$.view.referrer" - "$.error.handling" - "$.error.kind" - "$.error.stack" - "$.error.message" - "$.http.method" - "$.http.status_code" - "$.http.url" conditions: - matcher: "__kf_agent" value: "datadog" op: "==" - transform: args: - action: "replace" - sourceLabels: "#ddsource" - targetLabel: "source" conditions: - matcher: "#__kf_ddrum" value: "true" op: "==" - moveLabelToFacet: args: - name: "error.kind" - facetName: "error_kind" - agentFacet: true conditions: - matcher: "#__kf_ddrum" value: "true" op: "==" - moveLabelToFacet: args: - name: "error.stack" - facetName: "error_stack" - agentFacet: true conditions: - matcher: "#__kf_ddrum" value: "true" op: "==" - moveLabelToFacet: args: - name: "error.message" - facetName: "error_message" - agentFacet: true conditions: - matcher: "#__kf_ddrum" value: "true" op: "==" - moveLabelToFacet: args: - name: "http.method" - facetName: "@http_method" - agentFacet: true conditions: - matcher: "#__kf_ddrum" value: "true" op: "==" - moveLabelToFacet: args: - name: "http.status_code" - facetName: "http_status_code" - agentFacet: true conditions: - matcher: "#__kf_ddrum" value: "true" op: "==" - moveLabelToFacet: args: - name: "http.url" - facetName: "http_url" - agentFacet: true conditions: - matcher: "#__kf_ddrum" value: "true" op: "==" - moveLabelToFacet: args: - name: "session_id" - facetName: "sessionid" - agentFacet: true conditions: - matcher: "#__kf_ddrum" value: "true" op: "==" - moveLabelToFacet: args: - name: "application_id" - facetName: "applicationid" - agentFacet: true conditions: - matcher: "#__kf_ddrum" value: "true" op: "==" - moveLabelToFacet: args: - name: "view.url" - facetName: "view_url" - agentFacet: true conditions: - matcher: "#__kf_ddrum" value: "true" op: "==" - moveLabelToFacet: args: - name: "view.referrer" - facetName: "view_referrer" - agentFacet: true conditions: - matcher: "#__kf_ddrum" value: "true" op: "==" - moveLabelToFacet: args: - name: "view.id" - facetName: "view_id" - agentFacet: true conditions: - matcher: "#__kf_ddrum" value: "true" op: "==" - moveLabelToFacet: args: - name: "error.handling" - facetName: "@error_handling" - agentFacet: true conditions: - matcher: "#__kf_ddrum" value: "true" op: "==" - moveLabelToFacet: args: - name: "origin" - facetName: "event_origin" - agentFacet: true conditions: - matcher: "#__kf_ddrum" value: "true" op: "=="yaml -
Enable RUM under
global.uiConfigin thecustom-values.yamlfile:global: uiConfig: rum: enabled: trueyaml -
Upgrade the cluster using these changes, and ensure that all pods are active.
Instrument the Frontend Application
To set up the Frontend SDK for RUM, see instructions in RUM Setup.
Here is guide to the parameters to configure for SDK initialization:
- applicationId
-
applicationId: '<APPLICATION_ID>'Must match the ID of the RUM application you created in the Kloudfuse UI. See RUM Applications.
- clientToken
-
clientToken: '<CLIENT_TOKEN>'Use the string dummy as a value if the Kloudfuse installation does not have authenticated ingest enabled. If authenticated ingestion is enabled please follow the additional instructions noted on Step 5: Enable authenticated ingest below.
- site
-
site: '<SITE>'Use empty string.
- proxy
-
proxy: '<KFUSE_RUM_ENDPOINT>'Must be of the form
https://<customers-kfuse-hostname>/ddrumproxy.Example: Kloudfuse Playground cluster has the value of
https://playground.kloudfuse.io/ddrumproxy. - service
-
service: '<APPLICATION_NAME>'Must match the application name, and cannot contain any white space.
Example: kf-frontend
- env
-
env: 'production'This value depends on the type of deployment:
test,production,staging, and so on. - version
-
version: '1.0.0'If the frontend application has an identifier, use a string value that represents the version.
Otherwise, use the default value of
1.0.0. - sessionSampleRate
-
sessionSampleRate: 100We recommend a small number if the site has many users.
- enableSessionRecording
-
enableSessionRecording: trueWe recommend a value of
trueto use the session capture and replay feature. - enableLogCollection
-
enableLogCollection: trueWe recommend a value of
trueto get frontend logs into their Kloudfuse cluster.
Enable Authenticated Ingestion
(Optional)
By default, this feature is disabled.
When you enable authenticated ingestion on the Kloudfuse platform, you must enable it globally, and add authentication tokens.
Follow these steps:
-
To enable ingestion authentication, set
global authConfigtotruein thecustom-values.yamlfile:Enable Ingestion Authenticationglobal: authConfig: enabled: true (1)yaml1 authConfig: enable -
Generate a new authentication token:
Generate tokenuuidgen | tr -d '-' | tr 'A-Z' 'a-z' | sed 's/^/pub/' -
Configure one or more client tokens in the
ingester config rumsection of thecustom-values.yamlfile:Configure tokensingester: config: rum: enabled: true (1) clientTokens: (2) - rumauthkey1: <unique authtoken value> - rumauthkey2: <unique authtoken value>yaml1 enabled: Enable RUM ingestion2 clientTokensrumauthkey1andrumauthkey2: Unique authentication tokens for RUM, generated in Generate token. -
Match the generated auth tokens to the
clientTokenvalue in the frontend RUM SDK configuration:kfuseRumSDK.init({ config: { applicationId: '<application id>', (1) clientToken: '<unique authtoken value>', (2) ... } })javascript1 applicationId: The identifier of the service that provides the RUM stream.2 clientToken: Unique authentication token for RUM, generated in Generate token, matching the declarations in Configure tokens.
Add or update RUM labels used for RBAC policies
(Optional)
By default the chart uses the following RUM RBAC labels: application.id, service, env, geo.country_iso_code.
To add or update the labels used by RUM RBAC policies, edit the rumRBACLabels array in your custom-values.yaml under the global section.
Example:
global:
rumRBACLabels: ["application.id", "service", "env", "geo.country_iso_code", "<<new_label>>"]