refactor(opentelemetry): enhance RBAC and logging configuration for OpenTelemetry integration

This commit is contained in:
Nicolas 2025-09-24 11:20:24 +08:00
parent 6cd47723bc
commit 38b154547c
2 changed files with 124 additions and 88 deletions

View File

@ -1,40 +1,40 @@
{{- if .Values.logIngest.enabled }}
---
apiVersion: v1 apiVersion: v1
kind: ServiceAccount kind: ServiceAccount
metadata: metadata:
name: {{ .Release.Name }}-otel-collector name: {{ .Release.Name }}-otel-collector
namespace: {{ .Release.Namespace }} namespace: {{ .Release.Namespace }}
labels:
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
app.kubernetes.io/name: "{{ .Release.Name }}-otel-collector"
app.kubernetes.io/managed-by: {{ .Release.Service }}
app.kubernetes.io/instance: {{ .Release.Name }}
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole kind: ClusterRole
metadata: metadata:
name: {{ .Release.Name }}-otel-collector name: {{ .Release.Name }}-otel-collector
labels:
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
app.kubernetes.io/name: "{{ .Release.Name }}-otel-collector"
app.kubernetes.io/managed-by: {{ .Release.Service }}
app.kubernetes.io/instance: {{ .Release.Name }}
rules: rules:
- apiGroups: [""] - apiGroups: [""]
resources: ["pods", "nodes", "namespaces"] resources:
verbs: ["get", "list", "watch"] - pods
- namespaces
- nodes
verbs:
- get
- watch
- list
- apiGroups: ["apps"] - apiGroups: ["apps"]
resources: ["deployments", "replicasets"] resources:
verbs: ["get", "list", "watch"] - replicasets
- deployments
- statefulsets
- daemonsets
verbs:
- get
- watch
- list
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
metadata: metadata:
name: {{ .Release.Name }}-otel-collector name: {{ .Release.Name }}-otel-collector
labels:
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
app.kubernetes.io/name: "{{ .Release.Name }}-otel-collector"
app.kubernetes.io/managed-by: {{ .Release.Service }}
app.kubernetes.io/instance: {{ .Release.Name }}
roleRef: roleRef:
apiGroup: rbac.authorization.k8s.io apiGroup: rbac.authorization.k8s.io
kind: ClusterRole kind: ClusterRole
@ -43,3 +43,4 @@ subjects:
- kind: ServiceAccount - kind: ServiceAccount
name: {{ .Release.Name }}-otel-collector name: {{ .Release.Name }}-otel-collector
namespace: {{ .Release.Namespace }} namespace: {{ .Release.Namespace }}
{{- end }}

View File

@ -8,19 +8,51 @@ spec:
mode: sidecar mode: sidecar
image: ghcr.io/open-telemetry/opentelemetry-collector-releases/opentelemetry-collector-contrib:latest image: ghcr.io/open-telemetry/opentelemetry-collector-releases/opentelemetry-collector-contrib:latest
serviceAccount: "{{ .Release.Name }}-otel-collector" serviceAccount: "{{ .Release.Name }}-otel-collector"
config: | volumeMounts:
- name: app-logs
mountPath: {{ .Values.logIngest.logPath }}
securityContext:
allowPrivilegeEscalation: true
privileged: true
runAsUser: 0
runAsGroup: 0
env:
- name: KUBE_META_POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: KUBE_META_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- name: KUBE_META_NODE_NAME
valueFrom:
fieldRef:
fieldPath: spec.nodeName
- name: KUBE_META_POD_IP
valueFrom:
fieldRef:
fieldPath: status.podIP
- name: KUBE_META_POD_UID
valueFrom:
fieldRef:
fieldPath: metadata.uid
- name: KUBE_META_OBJECT_NAME
valueFrom:
fieldRef:
fieldPath: metadata.labels['app.kubernetes.io/instance']
config: config:
receivers: receivers:
filelog: filelog:
include: include:
- {{ .Values.logIngest.logPathPattern }} - {{ .Values.logIngest.logPathPattern }}
start_at: beginning start_at: end
include_file_path: false include_file_path: false
include_file_name: false include_file_name: false
operators: [] operators:
k8s_cluster: - type: json_parser
auth_type: serviceAccount parse_from: body
namespaces: [{{ .Release.Namespace }}] parse_to: attributes
processors: processors:
resource: resource:
attributes: attributes:
@ -46,8 +78,13 @@ spec:
log_statements: log_statements:
- context: log - context: log
statements: statements:
- set(resource.attributes["application"], "devops") - set(resource.attributes["application"], log.attributes["context"]["app"])
- set(resource.attributes["environment"], "{{ .Values.global.environment | default .Release.Namespace }}") - set(resource.attributes["environment"], log.attributes["context"]["env"])
- set(resource.attributes["kubernetes_node_name"], resource.attributes["k8s.node.name"])
- set(resource.attributes["kubernetes_pod_name"], resource.attributes["k8s.pod.name"])
- set(resource.attributes["kubernetes_pod_ip"], resource.attributes["k8s.pod.ip"])
- set(resource.attributes["kubernetes_deployment_name"], resource.attributes["k8s.deployment.name"])
- set(resource.attributes["kubernetes_namespace"], resource.attributes["k8s.namespace.name"])
- set(resource.attributes["body_json"], ParseJSON(log.body)) - set(resource.attributes["body_json"], ParseJSON(log.body))
- set(resource.attributes["body_json"]["kubernetes"]["pod"], resource.attributes["k8s.pod.name"]) - set(resource.attributes["body_json"]["kubernetes"]["pod"], resource.attributes["k8s.pod.name"])
- set(resource.attributes["body_json"]["kubernetes"]["namespace"], resource.attributes["k8s.namespace.name"]) - set(resource.attributes["body_json"]["kubernetes"]["namespace"], resource.attributes["k8s.namespace.name"])
@ -59,22 +96,20 @@ spec:
- set(log.body, resource.attributes["body_json"]) - set(log.body, resource.attributes["body_json"])
- delete_key(resource.attributes, "body_json") - delete_key(resource.attributes, "body_json")
batch: batch:
send_batch_size: 1 send_batch_size: 5
timeout: 1s timeout: 10s
exporters: exporters:
otlphttp/logs: otlphttp/logs:
endpoint: {{ .Values.logIngest.lokiEndpoint }}/otlp endpoint: {{ .Values.logIngest.lokiEndpoint }}/otlp
tls: tls:
insecure: true insecure: true
headers:
X-Scope-OrgID: "devops"
service: service:
telemetry: telemetry:
logs: logs:
level: info level: info
pipelines: pipelines:
logs: logs:
receivers: [filelog, k8s_cluster] receivers: [filelog]
processors: [resource, transform, batch] processors: [resource, transform, batch]
exporters: [otlphttp/logs] exporters: [otlphttp/logs]
{{- end }} {{- end }}