Anticipating problems and resource shortages on a slice can be more valuable than fixing them after they've happened. A monitoring tool like munin lets you watch your slice's resource use over time. The graphs will highlight issues before they cause downtime or bandwidth quota overages.
What you'll need
Munin's output is in html, so you will want to have a web server running to make reports available through a web browser. You can use any web server, such as apache or nginx, but for convenience the examples in this article series will assume you are running apache. It's best if you go through a tutorial series for installing apache or nginx so you understand what's being installed, but there are also barebones instructions for a default apache install in our repository if you're an experienced user and just want the web server for the purposes of accessing munin's reports.
If you want munin to send you email alerts you'll need to have a mail server running on your munin master slice that is configured to send outgoing mail messages. Slicehost has several articles that go into detail on setting up a mail server, and as with the web server, it's best if you go through a tutorial series so you get a good explanation of how to set up the mail server. If you want a quick, minimal mail server install, however, there are barebones install articles available there as well.
Munin can monitor just a single slice or it can be used to monitor several slices from one "master" slice. If you are planning on monitoring additional slices later, be sure to perform this installation on the slice you want to use as munin's master. If you are monitoring only one slice you don't have to make that decision, of course — just follow the directions in this series and don't worry about the subsequent article on installing additional nodes.
All commands assume you're running as a non-root user with sudo access.
On CentOS and Red Hat Enterprise Linux munin is not in the default repository. The easiest way to get munin is to add a repository to your installation that includes it. One such repository is the EPEL repository maintained by the Fedora Core team that contains munin and some other useful enterprise software. Once that repository is added you can install munin from there and include it in future system-wide updates.
To add the EPEL repository to your yum list, run:
sudo rpm -Uvh http://dl.fedoraproject.org/pub/epel/5/x86_64/epel-release-5-4.noarch.rpm
With the repository in place, you should be able to install munin with:
sudo yum install munin munin-node
After checking for dependencies yum will ask if you would like to import the GPG key from the EPEL repository. Say yes so yum can verify the authenticity of RPMs retrieved from that site in the future.
The munin master and node should now be installed to your slice, and your system configured to run munin. The changes made to your slice include a "munin" user to own munin's files, directories for munin's data archive and web pages, a cron.d entry to have munin generate graphs every five minutes, and an init script for munin-node.
With that, most of the basic work is done for you. Now you need to customize a couple settings and make one adjustment to improve security.
The munin.conf file
Open the file /etc/munin/munin.conf so you can change a couple important settings. This file will be covered in more depth in a later article on customizing munin.
Email notification (optional)
It's possible for munin to use the local mail command to send some basic email alerts if you have a mail server installed on the master server. The munin.conf file provides an example that sends an email whenever a plugin changes status (from OK to WARNING, for example, or when a warning situation is resolved):
# Drop email@example.com and firstname.lastname@example.org an email everytime # something changes (OK -> WARNING, CRITICAL -> OK, etc) #contact.someuser.command mail -s "Munin notification" email@example.com #contact.anotheruser.command mail -s "Munin notification" firstname.lastname@example.org
You can use that example as a template to add your own email notifications. For instance, you could add the following lines to the munin.conf file:
contact.john.command mail -s "Munin notification" email@example.com contact.marcia.command mail -s "Munin notification" firstname.lastname@example.org
The host tree
The "host tree" section of munin.conf describes the organization of any monitored nodes on munin's overview page. This guide only covers setting up one node on the same server as the munin master, so you can leave the default address of 127.0.0.1 alone. You might want to change the host tree name to something more descriptive, however. Find the following in the munin.conf file:
# a simple host tree [localhost] address 127.0.0.1 use_node_name yes
You can change the "localhost" entry to reflect your slice name, especially if you will be adding other nodes to your munin reports later. Don't use any spaces in the name, that confuses some of munin's graphing scripts. So you might change the host tree to look like:
[slicename] address 127.0.0.1 use_node_name yes
That should do it for munin.conf.
The munin-node.conf file
The security of the default configuration can be improved by making the node (the part that actually compiles statistics) completely local so it can't accept any outside connections. There's already a directive in this file telling the munin node to reject connections from outside addresses, but it's more secure to ensure the node can't be reached by external connections to begin with. Open the /etc/munin/munin-node.conf file and look for an entry with "host *", similar to:
# Which address to bind to; host *
To restrict the node to listen to localhost only, you should change the host entry to:
# Which address to bind to; host 127.0.0.1
The munin-node service
The munin node wasn't started by the installer, so now that we're done binding it to localhost let's start that up:
sudo /etc/init.d/munin-node start
To make sure the munin-node service starts when your slice reboots, you'll also want to make the service active:
sudo /sbin/chkconfig munin-node on
In this article you set up munin as a master and a node on your slice and configured it to display some default reports via a web server.
The next article in this series will cover determining the URL you will use to access the munin reports and checking that the reports are being updated properly.
- -- Jered