sam 0c91cad55f docs: add router-integration guide + router-blueprints/ fragments
The stack side is portable; the router side had no reference material -- a
new operator standing up OBMP has no guide for what to configure on their
devices to feed it. Adds two artifacts, both vendor-neutral in intent,
IOS-XR-specific in syntax:

  docs/router-integration.md
    Multi-path tour of the four ingest paths (BMP, BGP-LS, gNMI,
    NETCONF) with a bring-up checklist and cross-references. The BMP
    section is deliberately thin -- it hands off to docs/router-bmp-config.md
    for the address-selection, port-choice, and RR-scope activation
    detail already covered there.

  router-blueprints/iosxr/*.cfg
    Copy-paste config fragments, one per ingest path plus a
    role-route-reflector overlay. All values are <PLACEHOLDER>
    substitutions -- no hardcoded IPs, no lab-gear names. Fragments
    align to the ROUTER_FACING_IP / ROUTER_FACING_PORT convention
    introduced in docs/router-bmp-config.md.

  router-blueprints/README.md
    Substitution legend + layout, cross-links to PORTABILITY-FINDINGS.md
    finding 4 (why routers can't target HOST_IP on WSL).

Also appends the multi-path guide link to the Greenfield deploy section
in README.md so router-side integration is discoverable from the top.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-20 16:31:06 -07:00

47 lines
2.0 KiB
INI

! ============================================================================
! 03-gnmi.cfg -- gNMI dial-in for the Telegraf telemetry sink
! ============================================================================
! Enables the Telemetry-3001 dashboards (interface counters + state, and
! anything else Telegraf's cisco_telemetry_gnmi input is set to subscribe
! to). This is dial-IN telemetry: Telegraf initiates the gRPC connection
! and asks the router to stream openconfig paths on an interval.
!
! IOS-XR note: `no-tls` is only appropriate on a trusted management
! network. For any deployment reachable from an untrusted path, provision
! a server certificate and drop `no-tls` -- Telegraf's gNMI input supports
! TLS with cert verification.
! ============================================================================
! --- gRPC server for gNMI dial-in ------------------------------------------
grpc
port 57400
no-tls
!
! --- User for Telegraf to authenticate as ----------------------------------
! Whatever user you pick, populate GNMI_USERNAME / GNMI_PASSWORD in the
! stack's .env to match. A read-only account is sufficient.
!
! username <GNMI_USER>
! group root-lr
! secret <PLAINTEXT_OR_HASHED_PASSWORD>
! !
! --- Paths Telegraf subscribes to ------------------------------------------
! These are configured in telegraf/telegraf.conf, NOT on the router --
! openconfig paths are model-native, not sensor-groups. Reference only:
!
! openconfig-interfaces:/interfaces/interface/state/counters (10s)
! openconfig-interfaces:/interfaces/interface/state (30s)
!
! If you want additional sensors (LSDB size, CPU/mem), add the subscription
! block in telegraf/telegraf.conf and rebuild the telegraf container.
! --- Verify -----------------------------------------------------------------
! show grpc status
! show running-config grpc
!
! On the stack side:
! docker logs obmp-telegraf 2>&1 | grep -i "connected"
! Grafana -> OBMP-Telemetry -> Interface Utilization