当前位置: 首页 > news >正文

纳尼?自建K8s集群日志收集还能通过JMQ保存到JES

一、背景

基于K8s集群的私有化交付方案中,日志收集采用了ilogtail+logstash+kafka+es方案,其中ilogtail负责日志收集,logstash负责对数据转换,kafka负责对日志传递中的消峰进而减少es的写入压力,es用来保存日志数据。在私有化交付中本方案中涉及的中间件一般需要单独部署,但是在京东内网环境的部署考虑到kafka和es的高可用,则不推荐采用单独部署的方案。

二、新方案实践

1.新方案简介

在京东内网环境部署K8S收集日志, kafka+es的替代方案考虑使用JMQ+JES,由于JMQ的底层是基于kafaka、JES的底层基于ES,所以该替换方案理论上是可行的

2.主要架构

数据流向大致如下
应用日志 -> ilogtail -> JMQ -> logstash -> JES

3.如何使用

核心改造点汇总

  1. ilogtail nameservers配置
    增加解析JMQ域名的nameserver(京东云主机上无法直接解析.local域名)

spec:spec:dnsPolicy: "None"dnsConfig:nameservers:- x.x.x.x # 可以解析jmq域名的nameserver
  1. ilogtail flushers配置
    调整发送到JMQ到配置

apiVersion: v1
kind: ConfigMap
metadata:name: ilogtail-user-cmnamespace: elastic-system
data:app_stdout.yaml: |flushers:- Type: flusher_stdoutOnlyStdout: true- Type: flusher_kafka_v2Brokers:- nameserver.jmq.jd.local:80 # jmq元数据地址Topic: ai-middle-k8s-log-prod # jmq topic ClientID: ai4middle4log # Kafka的用户ID(识别客户端并设置其唯一性),对应jmq的Group名称,重要‼️ (https://ilogtail.gitbook.io/ilogtail-docs/plugins/input/service-kafka#cai-ji-pei-zhi-v2)   
  1. logstash kafka&es配置

apiVersion: v1
kind: ConfigMap
metadata:name: logstash-confignamespace: elastic-systemlabels:elastic-app: logstash
data:logstash.conf: |-input {kafka {bootstrap_servers => ["nameserver.jmq.jd.local:80"] #jmq的元数据地址group_id => "ai4middle4log" # jmq的Group的名称client_id => "ai4middle4log" # jmq的Group的名称,即jmq的省略了kafka中的client_id概念,用Group名称代替consumer_threads => 2decorate_events => truetopics => ["ai-middle-k8s-log-prod"] # jmp的topicauto_offset_reset => "latest"codec => json { charset => "UTF-8" }}}output {elasticsearch {hosts => ["http://x.x.x.x:40000","http://x.x.x.x:40000","http://x.x.x.x:40000"] # es地址index =>  "%{[@metadata][kafka][topic]}-%{+YYYY-MM-dd}" # 索引规则user => "XXXXXX" #jes的用户名password => "xxxxx" #jes的密码ssl => "false"ssl_certificate_verification => "false"}}

ilogtail 的配置如下

# ilogtail-daemonset.yaml
apiVersion: apps/v1
kind: DaemonSet
metadata:name: ilogtail-dsnamespace: elastic-systemlabels:k8s-app: logtail-ds
spec:selector:matchLabels:k8s-app: logtail-dstemplate:metadata:labels:k8s-app: logtail-dsspec:dnsPolicy: "None"dnsConfig:nameservers:- x.x.x.x # (京东云主机上)可以解析jmq域名的nameservertolerations:- operator: Exists                    # deploy on all nodescontainers:- name: logtailenv:- name: ALIYUN_LOG_ENV_TAGS       # add log tags from envvalue: _node_name_|_node_ip_- name: _node_name_valueFrom:fieldRef:apiVersion: v1fieldPath: spec.nodeName- name: _node_ip_valueFrom:fieldRef:apiVersion: v1fieldPath: status.hostIP- name: cpu_usage_limit           # iLogtail's self monitor cpu limitvalue: "1"- name: mem_usage_limit           # iLogtail's self monitor mem limitvalue: "512"image: dockerhub.ai.jd.local/ai-middleware/ilogtail-community-edition/ilogtail:1.3.1imagePullPolicy: IfNotPresentresources:limits:cpu: 1000mmemory: 1Girequests:cpu: 400mmemory: 384MivolumeMounts:- mountPath: /var/run                       # for container runtime socketname: run- mountPath: /logtail_host                  # for log access on the nodemountPropagation: HostToContainername: rootreadOnly: true- mountPath: /usr/local/ilogtail/checkpoint # for checkpoint between container restartname: checkpoint- mountPath: /usr/local/ilogtail/user_yaml_config.d # mount config dirname: user-configreadOnly: true- mountPath: /usr/local/ilogtail/apsara_log_conf.jsonname: apsara-log-configreadOnly: truesubPath: apsara_log_conf.jsondnsPolicy: ClusterFirsthostNetwork: truevolumes:- hostPath:path: /var/runtype: Directoryname: run- hostPath:path: /type: Directoryname: root- hostPath:path: /etc/ilogtail-ilogtail-ds/checkpointtype: DirectoryOrCreatename: checkpoint- configMap:defaultMode: 420name: ilogtail-user-cmname: user-config- configMap:defaultMode: 420name: ilogtail-apsara-log-config-cmname: apsara-log-config
# ilogtail-user-configmap.yaml
apiVersion: v1
kind: ConfigMap
metadata:name: ilogtail-user-cmnamespace: elastic-system
data:app_stdout.yaml: |enable: trueinputs:- Type: service_docker_stdoutStderr: trueStdout: trueK8sNamespaceRegex: ai-trainExternalK8sLabelTag:platform/resource-name: k8s_label_resource-nameplatform/task-identify: k8s_label_task-identifytask-id: k8s_label_task-idrun-id: k8s_label_run-idrequest-id: k8s_label_request-idprocessors:- Type: processor_renameSourceKeys:- k8s_label_resource-name- k8s_label_task-identify- k8s_label_task-id- k8s_label_run-id- k8s_label_request-id- _namespace_- _image_name_- _pod_uid_- _pod_name_- _container_name_- _container_ip_- __path__- _source_DestKeys:- resource_name- task_identify- task_id- run_id- request_id- namespace- image_name- pod_uid- pod_name- container_name- container_ip- path- sourceflushers:- Type: flusher_stdoutOnlyStdout: true- Type: flusher_kafka_v2Brokers:- nameserver.jmq.jd.local:80 # jmq元数据地址Topic: ai-middle-k8s-log-prod # jmq topic ClientID: ai4middle4log # Kafka的用户ID(识别客户端并设置其唯一性),对应jmq的Group名称,重要‼️ (https://ilogtail.gitbook.io/ilogtail-docs/plugins/input/service-kafka#cai-ji-pei-zhi-v2)app_file_log.yaml: |enable: trueinputs:- Type: file_logLogPath: /export/Logs/ai-dt-algorithm-toolsFilePattern: "*.log"ContainerInfo:K8sNamespaceRegex: ai-trainExternalK8sLabelTag:platform/resource-name: k8s_label_resource-nameplatform/task-identify: k8s_label_task-identifytask-id: k8s_label_task-idrun-id: k8s_label_run-idrequest-id: k8s_label_request-idprocessors:- Type: processor_add_fieldsFields:source: file- Type: processor_renameSourceKeys:- __tag__:k8s_label_resource-name- __tag__:k8s_label_task-identify- __tag__:k8s_label_task-id- __tag__:k8s_label_run-id- __tag__:k8s_label_request-id- __tag__:_namespace_- __tag__:_image_name_- __tag__:_pod_uid_- __tag__:_pod_name_- __tag__:_container_name_- __tag__:_container_ip_- __tag__:__path__DestKeys:- resource_name- task_identify- task_id- run_id- request_id- namespace- image_name- pod_uid- pod_name- container_name- container_ip- pathflushers:- Type: flusher_stdoutOnlyStdout: true- Type: flusher_kafka_v2Brokers:- nameserver.jmq.jd.local:80Topic: ai-middle-k8s-log-prodClientID: ai4middle4log

logstash 的配置如下

# logstash-configmap.yaml
---
apiVersion: v1
kind: ConfigMap
metadata:name: logstash-confignamespace: elastic-systemlabels:elastic-app: logstash
data:logstash.conf: |-input {kafka {bootstrap_servers => ["nameserver.jmq.jd.local:80"] #jmq的元数据地址#group_id => "services"group_id => "ai4middle4log" # jmq的Group的名称client_id => "ai4middle4log" # jmq的Group的名称,即jmq的省略了kafka中的client_id概念,用Group名称代替consumer_threads => 2decorate_events => true#topics_pattern => ".*"topics => ["ai-middle-k8s-log-prod"] # jmp的topicauto_offset_reset => "latest"codec => json { charset => "UTF-8" }}}filter {ruby {code => "event.set('index_date', event.get('@timestamp').time.localtime + 8*60*60)"}ruby {code => "event.set('message',event.get('contents'))"}#ruby {#    code => "event.set('@timestamp',event.get('time').time.localtime)"#}mutate {remove_field => ["contents"]convert => ["index_date", "string"]#convert => ["@timestamp", "string"]gsub => ["index_date", "T.*Z",""]#gsub => ["@timestamp", "T.*Z",""]}}output {elasticsearch {#hosts => ["https://ai-middle-cluster-es-http:9200"]hosts => ["http://x.x.x.x:40000","http://x.x.x.x:40000","http://x.x.x.x:40000"] # es地址index =>  "%{[@metadata][kafka][topic]}-%{+YYYY-MM-dd}" # 索引规则user => "XXXXXX" #jes的用户名password => "xxxxx" #jes的密码ssl => "false"ssl_certificate_verification => "false"#cacert => "/usr/share/logstash/cert/ca_logstash.cer"}stdout {codec => rubydebug}}

4.核心价值

在私有化部署的基础上通过简单改造实现了与京东内部中间件的完美融合,使得系统在高可用性上适应性更强、可用范围更广。

http://www.jsqmd.com/news/30235/

相关文章:

  • 2025 年艺术漆品牌最新推荐榜,综合实力与核心竞争力全面剖析,兼具品质与服务的优质之选艺术漆一线品牌公司推荐
  • 20232313 2025-2026-1 《网络与系统攻防技术》实验四实验报告 - 20232313
  • 企业热线电话系统的多渠道支持与服务拓展策略!
  • 2025 年关节电机厂家最新推荐排行榜权威发布:揭秘行业优质品牌实力、口碑及选购要点无刷直流 / 力矩 / 机械臂 / 机械手关节电机公司推荐
  • 由于 CSP 烂完了于是加训
  • DockerDeskTop安装常用的中间件
  • 2025 年卷板机源头厂家最新推荐排行榜:涵盖不锈钢 / 大型 / 锥形 / 数控等多类型设备,助力企业精准采购优质产品
  • 2025 年济南画室品牌口碑排行榜权威发布,小班教学与全封闭管理机构最新推荐济南画室高考/济南画室暑假班/济南画室素描课品牌推荐
  • Go语言学习路线图完整指南:从零基础到架构师的进阶之路
  • 2025年水泥构件直销厂家权威推荐榜单:排水槽/步道砖/水泥预购件源头厂家精选
  • Ubuntu服务器禁用NVIDIA自动更新驱动脚本
  • LongNet: Scaling Transformers to 1,000,000,000 Tokens
  • 2025高性价比Facebook广告品牌企业TOP5推荐:精准引流与高效转化的权威测评指南
  • 如何优化机器人拨打电话软件的通话效率?实用技巧!
  • Android Studio: Plugin with id com.android.library not found
  • 2025年度资深房地产模型企业推荐,专业房地产模型工作室与服务商全解析
  • 2025 年工业商城小程序最新推荐排行榜:涵盖多领域设备,解析实力企业核心优势与选择要点节能环保/车间工具/智能制造/数控转台工业商城推荐
  • JYU-ACM算法协会周赛题解 (每周刷新)
  • SAP 字段名+RANGE表
  • 2025口碑好的污水提升器源头厂家TOP5推荐:甄选不锈钢污水提升器服务商,破解排放难题
  • 2025年杭州婚姻家事律师推荐:孙旭权律师免费咨询
  • 2025 年自润滑轴承厂家最新推荐排行榜:聚焦高承载技术、全球客户口碑及协会权威测评的优质品牌榜单无油向心/复合向心/耐磨向心关节轴承公司推荐
  • 2025年5吨龙门吊供货厂家权威推荐榜单:二手5吨龙门吊/10吨龙门吊/MG门式龙门吊设备源头厂家精选
  • 系统关键信息收集
  • ROS2之仿真
  • 高速轴承和普通轴承怎么区分?
  • 20232409 2025-2026-1 《网络与系统攻防技术》实验六实验报告
  • vue3+ts+pinia项目实现数据持久化配置
  • 2025年金属线材加工设备企业排名:江苏优轧机械有限公司
  • 手把手搭建Python+Pytest+Selenium自动化环境,从零开始一点都不难!