AKS中独立部署的OpenTelemetry Collector Contrib对接Azure Monitor失败求助
适用于AKS的OpenTelemetry Collector Contrib完整部署配置(导出至Azure Monitor)
以下是一套可直接用于AKS的OpenTelemetry Collector Contrib部署配置,包含权限配置、核心Collector配置及Deployment,确保能正常收集集群日志并导出至Azure Monitor:
1. 完整部署清单
1.1 创建命名空间
apiVersion: v1 kind: Namespace metadata: name: otelcollector
1.2 权限配置(收集K8s日志必需)
apiVersion: v1 kind: ServiceAccount metadata: name: otel-collector-sa namespace: otelcollector --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: otel-collector-role rules: - apiGroups: [""] resources: ["pods", "nodes", "namespaces"] verbs: ["get", "list", "watch"] - apiGroups: ["apps"] resources: ["deployments", "replicasets"] verbs: ["get", "list", "watch"] --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: otel-collector-binding subjects: - kind: ServiceAccount name: otel-collector-sa namespace: otelcollector roleRef: kind: ClusterRole name: otel-collector-role apiGroup: rbac.authorization.k8s.io
1.3 Collector核心配置(ConfigMap)
apiVersion: v1 kind: ConfigMap metadata: name: otel-collector-config namespace: otelcollector data: config.yaml: | receivers: # 收集Kubernetes集群内容器日志 kuberneteslogs: auth_type: "serviceAccount" exclude_container_names: - "otel-collector" # 接收OTLP HTTP格式的日志(兼容自定义应用上报) otlp: protocols: http: endpoint: "0.0.0.0:4318" processors: batch: timeout: 10s send_batch_size: 1024 memory_limiter: check_interval: 1s limit_percentage: 75 spike_limit_percentage: 15 exporters: # 导出至Azure Monitor azuremonitor: # 替换为你的Azure Monitor工作区连接字符串(建议用Secret存储) # 或使用AKS托管身份(需提前配置身份绑定) connection_string: "<你的Azure Monitor连接字符串>" service: pipelines: logs: receivers: [kuberneteslogs, otlp] processors: [memory_limiter, batch] exporters: [azuremonitor] telemetry: logs: level: info
1.4 Collector Deployment(修正后的版本)
apiVersion: apps/v1 kind: Deployment metadata: name: otel-collector namespace: otelcollector labels: app: otelcollector component: otel-collector spec: selector: matchLabels: app: otelcollector component: otel-collector minReadySeconds: 5 replicas: 1 template: metadata: namespace: otelcollector labels: app: otelcollector component: otel-collector spec: serviceAccountName: otel-collector-sa containers: - name: otel-collector command: - "/otelcol-contrib" - "--config=/etc/otelcol-contrib/config.yaml" image: otel/opentelemetry-collector-contrib:latest resources: limits: cpu: "1" memory: 2Gi requests: cpu: 200m memory: 400Mi ports: - containerPort: 4318 # OTLP HTTP端口 - containerPort: 55679 # ZPages监控端口 - containerPort: 13133 # 健康检查端口 volumeMounts: - mountPath: /etc/otelcol-contrib/config.yaml name: data subPath: config.yaml readOnly: true livenessProbe: httpGet: path: / port: 13133 initialDelaySeconds: 5 periodSeconds: 10 readinessProbe: httpGet: path: / port: 13133 initialDelaySeconds: 5 periodSeconds: 10 volumes: - name: data configMap: name: otel-collector-config
2. 关键配置说明
- 权限配置:Collector需要获取K8s资源元数据来丰富日志内容,因此必须配置ClusterRole和ServiceAccount绑定。
- 日志接收器:同时启用
kuberneteslogs(自动收集容器日志)和otlp(接收自定义应用上报的日志),覆盖两种日志来源场景。 - 批处理处理器:
batch处理器减少向Azure Monitor的请求次数,提升性能;memory_limiter防止Collector内存溢出。 - Azure Monitor导出器:优先使用连接字符串或托管身份,避免在配置中明文存储敏感信息。若使用托管身份,需提前在AKS中绑定对应Azure Monitor的权限。
3. 部署验证
- 应用所有配置文件:
kubectl apply -f <配置文件路径> - 检查Collector Pod状态:
kubectl get pods -n otelcollector - 查看Collector日志排查问题:
kubectl logs -n otelcollector <pod-name>
内容的提问来源于stack exchange,提问作者satish
相关产品推荐
相关产品推荐

