一键摆设k8s之EFK日记网络系统

[复制链接]
发表于 2025-9-22 07:29:33 来自手机 | 显示全部楼层 |阅读模式
一、摆设es

1.下载安装
  1. #下载安装
  2. https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-8.13.2-linux-x86_64.tar.gz
  3. #解压
  4. [root@es software]# tar xf  elasticsearch-8.13.2-linux-x86_64.tar.gz
  5. #创建运行elasticsearch服务用户并修改权限
  6. [root@es software]# useradd liux
  7. [root@es software]# chown liux:liux /data/software/elasticsearch-8.13.2 -R
复制代码
2.修改文件形貌符

 最大及进程数目打开上限 (不修改启动会报错)
  1.  [root@es ~]# cat > /etc/security/limits.d/es.conf <<EOF
  2. *   soft  nofile 65535
  3. *  hard  nofile 131070
  4. *  hard  nproc 8192
  5. EOF
复制代码
3.修改内核参数
  1. [root@es elasticsearch-8.13.2]$ sysctl -q vm.max_map_count
  2. vm.max_map_count = 65530
  3. [root@es elasticsearch-8.13.2]# cat > /etc/sysctl.d/es.conf <<EOF
  4. vm.max_map_count=262144
  5. EOF
  6. [root@es elasticsearch-8.13.2]# sysctl -f /etc/sysctl.d/es.conf
  7. vm.max_map_count = 262144
复制代码
4.修改设置文件
  1. [liux@es elasticsearch-8.13.2]$ egrep -v "^#|^$" config/elasticsearch.yml
  2. network.host: 0.0.0.0
  3. discovery.seed_hosts: ["192.168.91.30"]
  4. cluster.initial_master_nodes: ["192.168.91.30"]
  5. xpack.security.enabled: false
复制代码
5.设置启动文件
  1. [liux@es elasticsearch-8.13.2]$ cat > startES.sh <<EOF
  2. #!/bin/bash                                                                           
  3. # 设置Elasticsearch的安装目录                                                            ES_HOME="/data/software/elasticsearch-8.13.2"         
  4. pid=`ps -ef | grep elasticsearch-8.13.2 | grep -v grep | grep '/data/software/elasticsearch-8.13.2/jdk/bin/ja
  5. va' | awk '{print $2}'`                                                                              
  6. # 检查Elasticsearch是否已经在运行
  7. if ps -ef | grep elasticsearch | grep -v grep > /dev/null; then                           echo "Elasticsearch is running. Stopping..."
  8.     kill $pid;                                                                             echo "Elasticsearch stopped."
  9. fi                                                                                                        
  10. sleep 5s                                                                                                      
  11. # 使用nohup重新启动Elasticsearch
  12. nohup "$ES_HOME/bin/elasticsearch" -d > "$ES_HOME/es.log" 2>&1 &
  13. echo "Elasticsearch is starting in the background..."
  14. EOF
  15. [liux@es elasticsearch-8.13.2]$ sh startES.sh
复制代码
6.如下所示代表安装乐成
  1. [liux@es elasticsearch-8.13.2]$ curl http://192.168.91.30:9200
  2. {
  3.   "name" : "es",
  4.   "cluster_name" : "elasticsearch",
  5.   "cluster_uuid" : "f337MT9oRvmL16xom5muBQ",
  6.   "version" : {
  7.     "number" : "8.13.2",
  8.     "build_flavor" : "default",
  9.     "build_type" : "tar",
  10.     "build_hash" : "16cc90cd2d08a3147ce02b07e50894bc060a4cbf",
  11.     "build_date" : "2024-04-05T14:45:26.420424304Z",
  12.     "build_snapshot" : false,
  13.     "lucene_version" : "9.10.0",
  14.     "minimum_wire_compatibility_version" : "7.17.0",
  15.     "minimum_index_compatibility_version" : "7.0.0"
  16.   },
  17.   "tagline" : "You Know, for Search"
  18. }
复制代码
7.Elasticsearch天生 TLS 证书
  1. #生成 CA 证书
  2. [root@es elasticsearch-8.13.2]# bin/elasticsearch-certutil ca --pem --out config/certs/ca.zip
  3. [root@es elasticsearch-8.13.2]# unzip config/certs/ca.zip -d config/certs/
  4. # 生成节点证书(包含 SAN)
  5. [root@es elasticsearch-8.13.2]# bin/elasticsearch-certutil cert --pem \
  6.   --ca-cert config/certs/ca/ca.crt \
  7.   --ca-key config/certs/ca/ca.key \
  8.   --name "es" \
  9.   --dns localhost,es,127.0.0.1 \
  10.   --ip 192.168.91.30 \
  11.   --out config/certs/es-node.zip  
  12. [root@es elasticsearch-8.13.2]# unzip config/certs/es-node.zip -d config/certs/
复制代码
8.修改elasticsearch设置文件
  1. [root@es elasticsearch-8.13.2]# cat config/elasticsearch.yml
  2. # 集群和节点名称
  3. cluster.name: my-es
  4. node.name: es-node
  5. # 网络绑定
  6. network.host: 0.0.0.0
  7. http.port: 9200
  8. # 安全配置
  9. xpack.security.enabled: true
  10. #配置 HTTP 层 TLS(HTTPS)
  11. xpack.security.http.ssl:
  12.   enabled: true
  13.   key: certs/es/es.key
  14.   certificate: certs/es/es.crt
  15.   certificate_authorities: certs/ca/ca.crt
  16.   verification_mode: full
  17. #配置 Transport 层 TLS(节点间通信)
  18. xpack.security.transport.ssl:
  19.   enabled: true
  20.   key: certs/es/es.key
  21.   certificate: certs/es/es.crt
  22.   certificate_authorities: certs/ca/ca.crt
  23.   verification_mode: full
  24. # 初始主节点
  25. cluster.initial_master_nodes: ["192.168.91.30"]
复制代码
9.设置文件权限
  1. [root@es elasticsearch-8.13.2]# chown -R liux:liux /data/software/elasticsearch-8.13.2
  2. [root@es elasticsearch-8.13.2]# chmod 600 /data/software/elasticsearch-8.13.2/config/certs/**/*.key
  3. [root@es elasticsearch-8.13.2]# chmod 644 /data/software/elasticsearch-8.13.2/config/certs/**/*.crt
复制代码
10.启动(以非root账号)
  1. [liux@es elasticsearch-8.13.2]$ ./startES.sh
复制代码
11.为内用用户设置暗码
  1. [root@es elasticsearch-8.13.2]# ./bin/elasticsearch-reset-password -u elastic
  2. This tool will reset the password of the [elastic] user to an autogenerated value.
  3. The password will be printed in the console.
  4. Please confirm that you would like to continue [y/N]y
  5. Password for the [elastic] user successfully reset.
  6. New value: CxL+02hUBIERrlwaXefD
复制代码
12.验证 HTTPS 访问

利用 curl 或浏览器验证 HTTPS 是否收效
  1. [liux@es elasticsearch-8.13.2]$ curl -k -u elastic:qgXT6yy*Vmj8FQhO2ein https://192.168.91.30:9200
  2. {
  3.   "name" : "es",
  4.   "cluster_name" : "es8",
  5.   "cluster_uuid" : "f337MT9oRvmL16xom5muBQ",
  6.   "version" : {
  7.     "number" : "8.13.2",
  8.     "build_flavor" : "default",
  9.     "build_type" : "tar",
  10.     "build_hash" : "16cc90cd2d08a3147ce02b07e50894bc060a4cbf",
  11.     "build_date" : "2024-04-05T14:45:26.420424304Z",
  12.     "build_snapshot" : false,
  13.     "lucene_version" : "9.10.0",
  14.     "minimum_wire_compatibility_version" : "7.17.0",
  15.     "minimum_index_compatibility_version" : "7.0.0"
  16.   },
  17.   "tagline" : "You Know, for Search"
  18. }
复制代码


13.注意事项

验证模式
   verification_mode: certificate:仅验证证书有用性(开发环境适用)。
   verification_mode: full:严酷验证证书和主机名(生产环境必须)。
防火墙和网络
   确保防火墙开放端口 9200(HTTPS)和 9300(节点间通讯)。
集群设置
   多节点集群需确保全部节点利用相同的 CA 证书,并在设置中指定 discovery.seed_hosts。
二、摆设kibana

1.下载安装
  1. https://artifacts.elastic.co/downloads/kibana/kibana-8.13.2-x86_64.rpm
  2. [root@es software]# rpm -ivh kibana-8.13.2-x86_64.rpm
复制代码
2.设置kibana用户暗码
  1. [root@es elasticsearch-8.13.2]# ./bin/elasticsearch-reset-password -u kibana_system
  2. This tool will reset the password of the [kibana_system] user to an autogenerated value.
  3. The password will be printed in the console.
  4. Please confirm that you would like to continue [y/N]y
  5. Password for the [kibana_system] user successfully reset.
  6. New value: qqjW5tkngBhbWuEydDGW
复制代码
3.修改kibana设置文件
  1. [root@es kibana]# cat kibana.yml
  2. server.port: 5601
  3. server.host: "192.168.91.30"
  4. server.publicBaseUrl: "http://192.168.91.30:5601"
  5. # Elasticsearch 安全连接
  6. elasticsearch.hosts: ["https://192.168.91.30:9200"]
  7. elasticsearch.ssl.certificateAuthorities: ["/data/software/elasticsearch-8.13.2/config/certs/ca/ca.crt"]
  8. elasticsearch.ssl.verificationMode: full  
  9. elasticsearch.username: "kibana_system"
  10. elasticsearch.password: "*q-Bc0=m5d*Ev-AcGShm"
  11. # 启用 Kibana 安全
  12. #用于加密和解密敏感数据的密钥
  13. xpack.encryptedSavedObjects.encryptionKey: "1f57078d76aa5c992171a342d7a64d33e56f3a1b832967160bcc568ae43dcf8d"
  14. # 如果二进制安装可用  ./bin/kibana-encryption-keys generate生成上面32位的随机字符串
  15. # 也可以用openssl rand -hex 32 生成
复制代码
4.设置文件权限
  1. [root@es kibana]# chown -R kibana:kibana /etc/kibana
  2. # 确保 Kibana 可读 CA 证书
  3. [root@es kibana]# chmod 644 /data/software/elasticsearch-8.13.2/config/certs/ca/ca.crt
复制代码
5.启动
  1. [root@es software]# systemctl enable --now kibana
  2. [root@es software]# systemctl status kibana
  3. [root@es kibana]# cat /usr/lib/systemd/system/kibana.service
  4. [Unit]
  5. Description=Kibana
  6. Documentation=https://www.elastic.co
  7. Wants=network-online.target
  8. After=network-online.target
  9. [Service]
  10. Type=simple
  11. User=kibana
  12. Group=kibana
  13. PrivateTmp=true
  14. Environment=KBN_HOME=/usr/share/kibana
  15. Environment=KBN_PATH_CONF=/etc/kibana
  16. EnvironmentFile=-/etc/default/kibana
  17. EnvironmentFile=-/etc/sysconfig/kibana
  18. ExecStart=/usr/share/kibana/bin/kibana
  19. Restart=on-failure
  20. RestartSec=3
  21. StartLimitBurst=3
  22. StartLimitInterval=60
  23. WorkingDirectory=/usr/share/kibana
  24. StandardOutput=journal
  25. StandardError=inherit
  26. [Install]
  27. WantedBy=multi-user.target
  28. #页面访问
  29. http://192.168.91.30:5601
复制代码
三、摆设filebeat

1.下载filebeat镜像
  1.  [root@node-1 ~]# docker pull docker.elastic.co/beats/filebeat:8.13.2
复制代码
2.编写RBAC文件
  1. [root@master-1 logs]# vim filebeat-sa.yaml
  2. #创建filebeat-sa的服务账号
  3. apiVersion: v1
  4. kind: ServiceAccount
  5. metadata:
  6.   name: filebeat-sa
  7.   namespace: kube-system
  8.   labels:
  9.     k8s-app: filebeat
  10. ---
  11. #集群级权限(ClusterRole)
  12. apiVersion: rbac.authorization.k8s.io/v1
  13. kind: ClusterRole
  14. metadata:
  15.   name: filebeat
  16.   labels:
  17.     k8s-app: filebeat
  18. rules:
  19. - apiGroups: [""] # "" indicates the core API group
  20.   resources: ["namespaces","pods","nodes"]  #用于自动发现容器
  21.   verbs: ["get","watch","list"]
  22. - apiGroups: ["apps"]  #用于关联 Pod 与 ReplicaSet
  23.   resources:
  24.     - replicasets
  25.   verbs: ["get", "list", "watch"]
  26.   
  27. ---
  28. #集群级权限(ClusterRoleBinding)
  29. #将角色与服务账号绑定
  30. apiVersion: rbac.authorization.k8s.io/v1
  31. kind: ClusterRoleBinding
  32. metadata:
  33.   name: filebeat
  34. subjects:
  35. - kind: ServiceAccount
  36.   name: filebeat-sa
  37.   namespace: kube-system
  38. roleRef:
  39.   kind: ClusterRole
  40.   name: filebeat
  41.   apiGroup: rbac.authorization.k8s.io
  42.   
  43. ---
  44. #访问 kubeadm-config 的权限(Role + RoleBinding)
  45. #读取 kube-system 命名空间中名为 kubeadm-config 的 ConfigMap(用于获取集群配置信息)
  46. #如需要获取data.kubernetes.container.name
  47. apiVersion: rbac.authorization.k8s.io/v1
  48. kind: Role
  49. metadata:
  50.   name: filebeat-kubeadm-config
  51.   namespace: kube-system
  52.   labels:
  53.     k8s-app: filebeat
  54. rules:
  55.   - apiGroups: [""]
  56.     resources:
  57.       - configmaps
  58.     resourceNames:
  59.       - kubeadm-config
  60.     verbs: ["get"]
  61. ---
  62. apiVersion: rbac.authorization.k8s.io/v1
  63. kind: RoleBinding
  64. metadata:
  65.   name: filebeat-kubeadm-config
  66.   namespace: kube-system
  67. subjects:
  68.   - kind: ServiceAccount
  69.     name: filebeat-sa
  70.     namespace: kube-system
  71. roleRef:
  72.   kind: Role
  73.   name: filebeat-kubeadm-config
  74.   apiGroup: rbac.authorization.k8s.io
  75. [root@master-1 logs]# kubectl apply -f filebeat-sa.yaml
复制代码
3.编写filebeat-config资源
  1. [root@master-1 logs]# vim filebeat-config.yaml
  2. apiVersion: v1
  3. kind: ConfigMap
  4. metadata:
  5.   name: filebeat-config
  6.   namespace: kube-system
  7.   labels:
  8.     k8s-app: filebeat
  9. data:
  10.   filebeat.yml: |-
  11.     # To enable hints based autodiscover, remove `filebeat.inputs` configuration and uncomment this:
  12.     filebeat.autodiscover:
  13.       providers:
  14.         - type: kubernetes
  15.           node: ${NODE_NAME}
  16.           hints.enabled: true
  17.           conditions:
  18.             equals:
  19.               data.kubernetes.container.name: "nginx" # 关键条件字段,只收集容器为nginx日志日志
  20.           hints.default_config:
  21.             type: container
  22.             paths:
  23.               - /var/log/containers/*${data.kubernetes.container.id}.log
  24.             symlinks: true
  25.     processors:
  26.       - add_host_metadata:
  27.     output.elasticsearch:
  28.       hosts: ['${ELASTICSEARCH_HOST:elasticsearch}:${ELASTICSEARCH_PORT:9200}']
  29.       username: ${ELASTICSEARCH_USERNAME}
  30.       password: ${ELASTICSEARCH_PASSWORD}
  31.       # 定义索引名称格式:nginx-logs-当前日期
  32.       index: "nginx-logs-%{+yyyy.MM.dd}"
  33.     setup.ilm.enabled: false  # 禁用索引生命周期管理
  34.     setup.template.enabled: false  # 禁用默认索引模板,开启该选项日志日志默认会收集到以filebeat+版本号的 数据流模板中
  35.     cloud.id: ""   # 清空云ID配置
  36.     cloud.auth: ""
  37. [root@master-1 logs]# kubectl apply -f filebeat-config.yaml
复制代码
4.编写filebeat的DaemonSet资源
  1. [root@master-1 logs]# vim filebeat-ds.yaml
  2. apiVersion: apps/v1
  3. kind: DaemonSet
  4. metadata:
  5.   name: filebeat
  6.   namespace: kube-system
  7.   labels:
  8.     k8s-app: filebeat
  9. spec:
  10.   selector:
  11.     matchLabels:
  12.       k8s-app: filebeat
  13.   template:
  14.     metadata:
  15.       labels:
  16.         k8s-app: filebeat
  17.     spec:
  18.       serviceAccountName: filebeat-sa   #指定 Pod 使用的服务账户
  19.       terminationGracePeriodSeconds: 30
  20.       hostNetwork: true   #使用主机网络
  21.       dnsPolicy: ClusterFirstWithHostNet  #DNS 解析策略(优先集群 DNS,兼容宿主机网络)
  22.       containers:
  23.       - name: filebeat
  24.         image: docker.elastic.co/beats/filebeat:8.13.2
  25.         args: [
  26.           "-c", "/etc/filebeat.yml",
  27.           "-e","--path.data", "/usr/share/filebeat/data/pod-$(HOSTNAME)"
  28.         ]
  29.         env:
  30.         - name: HOSTNAME
  31.           valueFrom:
  32.             fieldRef:
  33.               fieldPath: metadata.name  # 注入Pod名称作为唯一标识
  34.         - name: ELASTICSEARCH_HOST
  35.           value: 192.168.91.30
  36.         - name: ELASTICSEARCH_PORT
  37.           value: "9200"
  38.         - name: ELASTICSEARCH_USERNAME
  39.           value: elastic
  40.         - name: ELASTICSEARCH_PASSWORD
  41.           value: "CxL+02hUBIERrlwaXefD"
  42.         - name: ELASTIC_CLOUD_ID
  43.           value:
  44.         - name: ELASTIC_CLOUD_AUTH
  45.           value:
  46.         - name: NODE_NAME
  47.           valueFrom:
  48.             fieldRef:
  49.               fieldPath: spec.nodeName
  50.         #安全上下文
  51.         securityContext:
  52.           runAsUser: 0  # 以 root 用户运行(需访问宿主机日志日志文件,但存在安全风险)
  53.           # If using Red Hat OpenShift uncomment this:
  54.           #privileged: true  # 在 OpenShift 中可能需要开启特权模式
  55.         #资源限制
  56.         resources:
  57.           limits:
  58.             memory: 200Mi  # 内存上限为 200MiB
  59.           requests:
  60.             cpu: 100m
  61.             memory: 100Mi
  62.         #容器内挂载路径
  63.         volumeMounts:
  64.         - name: config
  65.           mountPath: /etc/filebeat.yml
  66.           readOnly: true
  67.           subPath: filebeat.yml
  68.         - name: data
  69.           mountPath: /usr/share/filebeat/data
  70.         - name: varlogcontainers
  71.           mountPath: /var/log/containers
  72.           readOnly: true
  73.         - name: varlogpods
  74.           mountPath: /var/log/pods
  75.           readOnly: true
  76.         - name: varlibdockercontainers
  77.           mountPath: /var/lib/docker/containers
  78.           readOnly: true
  79.       #定义存储卷来源
  80.       volumes:
  81.       - name: config
  82.         configMap:
  83.           defaultMode: 0640
  84.           name: filebeat-config
  85.       - name: varlogcontainers
  86.         hostPath:
  87.           path: /var/log/containers
  88.       - name: varlogpods
  89.         hostPath:
  90.           path: /var/log/pods
  91.       - name: varlibdockercontainers
  92.         hostPath:
  93.           path: /var/lib/docker/containers
  94.       # data folder stores a registry of read status for all files, so we don't send everything again on a Filebeat pod restart
  95.       - name: data
  96.         hostPath:
  97.           # When filebeat runs as non-root user, this directory needs to be writable by group (g+w).
  98.           path: /var/lib/filebeat-data
  99.           type: DirectoryOrCreate
  100. [root@master-1 logs]# kubectl apply -f filebeat-ds.yaml
复制代码
5.设置 Filebeat 利用 TLS 连接es

注:es如果没有开启tls认证,该步骤可以忽略
  1. #1. 通过secret存储es证书
  2. [root@master-1 logs]# kubectl create secret generic es-ca-cert -n kube-system --from-file=ca.crt=/root/ca.crt
  3. #2.在Filebeat 的 Deployment/DaemonSet 中挂载证书filebeat-ds.yaml
  4. volumeMounts:
  5. - name: es-ca-cert
  6.   mountPath: /etc/filebeat/certs
  7.   readOnly: true
  8. volumes:
  9. - name: es-ca-cert
  10.   secret:
  11.     secretName: es-ca-cert
  12. #3.配置 Filebeat 的 filebeat-config.yml
  13. #修改 Filebeat 的 Elasticsearch 输出配置,启用 TLS 并指定 CA 证书路径
  14.       #hosts需要改为https
  15.       hosts: ['${ELASTICSEARCH_HOST:elasticsearch}:${ELASTICSEARCH_PORT:9200}']
  16.       username: ${ELASTICSEARCH_USERNAME}
  17.       password: ${ELASTICSEARCH_PASSWORD}
  18.       # 禁用默认数据流,使用自定义索引
  19.       #data_stream.enabled: false
  20.       # 定义索引名称格式:nginx-logs-当前日期
  21.       index: "nginx-logs-%{+yyyy.MM.dd}"
  22.       ssl:
  23.         enabled: true
  24.         certificate_authorities: ["/etc/filebeat/certs/ca.crt"]  # 挂载的 CA 证书路径
  25.         verification_mode: "full"            # 严格验证证书(生产环境推荐)
复制代码
6.利用Secret 存储es用户暗码(更安全)
  1. #1. 使用kubectl命令创建secret
  2. [root@master-1 logs]# kubectl create secret generic es-credentials -n kube-system \
  3.   --from-literal=username=elastic \
  4.   --from-literal=password=CxL+02hUBIERrlwaXefD
  5. #也可通过yaml方式创建
  6. [root@master-1 logs]# kubectl apply -f es-credentials.yaml
  7. apiVersion: v1
  8. kind: Secret
  9. metadata:
  10.   name: es-credentials
  11.   namespace: kube-system
  12. type: Opaque
  13. data:
  14.   password: Q3hMKzAyaFVCSUVScmx3YVhlZkQ=   # echo -n "CxL+02hUBIERrlwaXefD" | base64
  15.   username: ZWxhc3RpYw==                   # echo -n "elastic" | base64
  16. #2.将secret通过环境变量注入pod中
  17. # 示例:Filebeat DaemonSet 配置片段
  18. spec:
  19.   template:
  20.     spec:
  21.       containers:
  22.         - name: filebeat
  23.           env:
  24.             - name: ELASTICSEARCH_USERNAME
  25.               valueFrom:
  26.                 secretKeyRef:
  27.                   name: es-credentials
  28.                   key: username
  29.             - name: ELASTICSEARCH_PASSWORD
  30.               valueFrom:
  31.                 secretKeyRef:
  32.                   name: es-credentials
  33.                   key: password
  34. #3.filebeat-config从环境变量中获取
  35. output.elasticsearch:
  36.   hosts: ["https://es:9200"]
  37.   protocol: "https"
  38.   username: ${ELASTICSEARCH_USERNAME}  # 从环境变量读取
  39.   password: ${ELASTICSEARCH_PASSWORD}  # 从环境变量读取
复制代码
7.汇总版本(tls+secret)
  1. #kubectl apply -f filebeat-config.yaml
  2. apiVersion: v1
  3. kind: ConfigMap
  4. metadata:
  5.   name: filebeat-config
  6.   namespace: kube-system
  7.   labels:
  8.     k8s-app: filebeat
  9. data:
  10.   filebeat.yml: |-
  11.     # To enable hints based autodiscover, remove `filebeat.inputs` configuration and uncomment this:
  12.     filebeat.autodiscover:
  13.       providers:
  14.         - type: kubernetes
  15.           node: ${NODE_NAME}
  16.           hints.enabled: true
  17.           conditions:
  18.             equals:
  19.               data.kubernetes.container.name: "nginx"  # 关键条件字段
  20.           hints.default_config:
  21.             type: container
  22.             paths:
  23.               - /var/log/containers/*${data.kubernetes.container.id}.log
  24.             symlinks: true
  25.     processors:
  26.       - add_host_metadata:
  27.     output.elasticsearch:
  28.       hosts: ['${ELASTICSEARCH_HOST:elasticsearch}:${ELASTICSEARCH_PORT:9200}']
  29.       username: ${ELASTICSEARCH_USERNAME}
  30.       password: ${ELASTICSEARCH_PASSWORD}
  31.       # 禁用默认数据流,使用自定义索引
  32.       #data_stream.enabled: false
  33.       # 定义索引名称格式:nginx-logs-当前日期
  34.       index: "nginx-logs-%{+yyyy.MM.dd}"
  35.       ssl:
  36.         enabled: true
  37.         certificate_authorities: ["/etc/filebeat/certs/ca.crt"]  # 挂载的 CA 证书路径
  38.         verification_mode: "full"            # 严格验证证书(生产环境推荐)
  39.     setup.ilm.enabled: false  # 禁用索引生命周期管理
  40.     setup.template.enabled: false  # 禁用默认索引模板
  41.     cloud.id: ""   # 清空云ID配置
  42.     cloud.auth: ""
  43. ---
  44. #kubectl apply -f filebeat-ds.yaml
  45. apiVersion: apps/v1
  46. kind: DaemonSet
  47. metadata:
  48.   name: filebeat
  49.   namespace: kube-system
  50.   labels:
  51.     k8s-app: filebeat
  52. spec:
  53.   selector:
  54.     matchLabels:
  55.       k8s-app: filebeat
  56.   template:
  57.     metadata:
  58.       labels:
  59.         k8s-app: filebeat
  60.     spec:
  61.       serviceAccountName: filebeat-sa
  62.       terminationGracePeriodSeconds: 30
  63.       hostNetwork: true
  64.       dnsPolicy: ClusterFirstWithHostNet
  65.       containers:
  66.       - name: filebeat
  67.         image: docker.elastic.co/beats/filebeat:8.13.2
  68.         args: [
  69.           "-c", "/etc/filebeat.yml",
  70.           "-e","--path.data", "/usr/share/filebeat/data/pod-$(HOSTNAME)"
  71.         ]
  72.         env:
  73.         - name: HOSTNAME
  74.           valueFrom:
  75.             fieldRef:
  76.               fieldPath: metadata.name  # 注入Pod名称作为唯一标识
  77.         - name: ELASTICSEARCH_USERNAME
  78.           valueFrom:
  79.             secretKeyRef:
  80.               name: es-credentials
  81.               key: username
  82.         - name: ELASTICSEARCH_PASSWORD
  83.           valueFrom:
  84.             secretKeyRef:
  85.               name: es-credentials
  86.               key: password
  87.         - name: ELASTICSEARCH_HOST
  88.           value: "https://192.168.91.30"
  89.         - name: ELASTICSEARCH_PORT
  90.           value: "9200"
  91.        # - name: ELASTICSEARCH_USERNAME
  92.        #   value: elastic
  93.        # - name: ELASTICSEARCH_PASSWORD
  94.        #   value: "CxL+02hUBIERrlwaXefD"
  95.         - name: ELASTIC_CLOUD_ID
  96.           value:
  97.         - name: ELASTIC_CLOUD_AUTH
  98.           value:
  99.         - name: NODE_NAME
  100.           valueFrom:
  101.             fieldRef:
  102.               fieldPath: spec.nodeName
  103.         securityContext:
  104.           runAsUser: 0
  105.           # If using Red Hat OpenShift uncomment this:
  106.           #privileged: true
  107.         resources:
  108.           limits:
  109.             memory: 200Mi
  110.           requests:
  111.             cpu: 100m
  112.             memory: 100Mi
  113.         volumeMounts:
  114.         - name: config
  115.           mountPath: /etc/filebeat.yml
  116.           readOnly: true
  117.           subPath: filebeat.yml
  118.         - name: data
  119.           mountPath: /usr/share/filebeat/data
  120.         - name: varlogcontainers
  121.           mountPath: /var/log/containers
  122.           readOnly: true
  123.         - name: varlogpods
  124.           mountPath: /var/log/pods
  125.           readOnly: true
  126.         - name: varlibdockercontainers
  127.           mountPath: /var/lib/docker/containers
  128.           readOnly: true
  129.         - name: es-ca-cert
  130.           mountPath: /etc/filebeat/certs
  131.           readOnly: true
  132.       volumes:
  133.       - name: config
  134.         configMap:
  135.           defaultMode: 0640
  136.           name: filebeat-config
  137.       - name: varlogcontainers
  138.         hostPath:
  139.           path: /var/log/containers
  140.       - name: varlogpods
  141.         hostPath:
  142.           path: /var/log/pods
  143.       - name: varlibdockercontainers
  144.         hostPath:
  145.           path: /var/lib/docker/containers
  146.       - name: es-ca-cert
  147.         secret:
  148.           secretName: es-ca-cert
  149.       # data folder stores a registry of read status for all files, so we don't send everything again on a Filebeat pod restart
  150.       - name: data
  151.         hostPath:
  152.           # When filebeat runs as non-root user, this directory needs to be writable by group (g+w).
  153.           path: /var/lib/filebeat-data
  154.           type: DirectoryOrCreate
  155. ---
  156. #filebeat-sa.yaml
  157. apiVersion: rbac.authorization.k8s.io/v1
  158. kind: ClusterRoleBinding
  159. metadata:
  160.   name: filebeat
  161. subjects:
  162. - kind: ServiceAccount
  163.   name: filebeat-sa
  164.   namespace: kube-system
  165. roleRef:
  166.   kind: ClusterRole
  167.   name: filebeat
  168.   apiGroup: rbac.authorization.k8s.io
  169. ---
  170. apiVersion: rbac.authorization.k8s.io/v1
  171. kind: RoleBinding
  172. metadata:
  173.   name: filebeat-kubeadm-config
  174.   namespace: kube-system
  175. subjects:
  176.   - kind: ServiceAccount
  177.     name: filebeat-sa
  178.     namespace: kube-system
  179. roleRef:
  180.   kind: Role
  181.   name: filebeat-kubeadm-config
  182.   apiGroup: rbac.authorization.k8s.io
  183. ---
  184. apiVersion: rbac.authorization.k8s.io/v1
  185. kind: ClusterRole
  186. metadata:
  187.   name: filebeat
  188.   labels:
  189.     k8s-app: filebeat
  190. rules:
  191. - apiGroups: [""] # "" indicates the core API group
  192.   resources:
  193.   - namespaces
  194.   - pods
  195.   - nodes
  196.   verbs:
  197.   - get
  198.   - watch
  199.   - list
  200. - apiGroups: ["apps"]
  201.   resources:
  202.     - replicasets
  203.   verbs: ["get", "list", "watch"]
  204. ---
  205. apiVersion: rbac.authorization.k8s.io/v1
  206. kind: Role
  207. metadata:
  208.   name: filebeat-kubeadm-config
  209.   namespace: kube-system
  210.   labels:
  211.     k8s-app: filebeat
  212. rules:
  213.   - apiGroups: [""]
  214.     resources:
  215.       - configmaps
  216.     resourceNames:
  217.       - kubeadm-config
  218.     verbs: ["get"]
  219. ---
  220. apiVersion: v1
  221. kind: ServiceAccount
  222. metadata:
  223.   name: filebeat-sa
  224.   namespace: kube-system
  225.   labels:
  226.     k8s-app: filebeat
复制代码
8.测试效果以及排查题目
  1. [root@master-1 logs]# kubectl apply -f filebeat-sa.yaml
  2. [root@master-1 logs]# kubectl apply -f filebeat-config.yaml
  3. [root@master-1 logs]# kubectl apply -f filebeat-ds.yaml
  4. #以下表示部署成功
  5. [root@master-1 logs]# kubectl get pods -A -o wide
  6. NAMESPACE     NAME     READY   STATUS    RESTARTS        AGE     IP              NODE     NOMINATED NODE   READINESS GATES
  7. kube-system   filebeat-49g94                            1/1     Running   0               16m     192.168.91.22   node-2   <none>           <none>
  8. kube-system   filebeat-rgf4f                            1/1     Running   0               16m     192.168.91.21   node-1   <none>           <none>
  9. #kibana中查看索引Stack Management-->Index Management
  10. nginx-logs
  11. #查看filebeat日志
  12. [root@master-1 logs]# kubectl logs -f filebeat-49g94  -n kube-system
  13. #调试 Filebeat,输出更详细的日志,帮助排查问题
  14. [root@master-1 logs]# kubectl exec -it filebeat-49g94  -n kube-system -- filebeat -e -d "*" -c /etc/filebeat.yml
  15. # 遇到被锁的情况 进入Filebeat Pod手动删除锁文件
  16. [root@master-1 logs]# kubectl exec -it filebeat-49g94  -n kube-system  -- rm -f /usr/share/filebeat/data/filebeat.lock
  17. #查看es连通性
  18. [root@master-1 logs]# kubectl exec -it filebeat-49g94 -n kube-system -- curl -u elastic:CxL+02hUBIERrlwaXefD http://192.168.91.30:9200       
复制代码
EFK 日记系统为 Kubernetes 提供了从日记网络、存储到分析的全链路本领,生产环境中需重点关注 长期化存储、资源配额 和 安全设置(如 TLS 加密、RBAC 权限)。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有账号?立即注册

×
回复

使用道具 举报

登录后关闭弹窗

登录参与点评抽奖  加入IT实名职场社区
去登录
快速回复 返回顶部 返回列表