You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AKS中独立部署的OpenTelemetry Collector Contrib对接Azure Monitor失败求助

适用于AKS的OpenTelemetry Collector Contrib完整部署配置(导出至Azure Monitor)

以下是一套可直接用于AKS的OpenTelemetry Collector Contrib部署配置,包含权限配置、核心Collector配置及Deployment,确保能正常收集集群日志并导出至Azure Monitor:

1. 完整部署清单

1.1 创建命名空间

apiVersion: v1
kind: Namespace
metadata:
  name: otelcollector

1.2 权限配置(收集K8s日志必需)

apiVersion: v1
kind: ServiceAccount
metadata:
  name: otel-collector-sa
  namespace: otelcollector
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: otel-collector-role
rules:
  - apiGroups: [""]
    resources: ["pods", "nodes", "namespaces"]
    verbs: ["get", "list", "watch"]
  - apiGroups: ["apps"]
    resources: ["deployments", "replicasets"]
    verbs: ["get", "list", "watch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: otel-collector-binding
subjects:
  - kind: ServiceAccount
    name: otel-collector-sa
    namespace: otelcollector
roleRef:
  kind: ClusterRole
  name: otel-collector-role
  apiGroup: rbac.authorization.k8s.io

1.3 Collector核心配置(ConfigMap)

apiVersion: v1
kind: ConfigMap
metadata:
  name: otel-collector-config
  namespace: otelcollector
data:
  config.yaml: |
    receivers:
      # 收集Kubernetes集群内容器日志
      kuberneteslogs:
        auth_type: "serviceAccount"
        exclude_container_names:
          - "otel-collector"
      # 接收OTLP HTTP格式的日志(兼容自定义应用上报)
      otlp:
        protocols:
          http:
            endpoint: "0.0.0.0:4318"

    processors:
      batch:
        timeout: 10s
        send_batch_size: 1024
      memory_limiter:
        check_interval: 1s
        limit_percentage: 75
        spike_limit_percentage: 15

    exporters:
      # 导出至Azure Monitor
      azuremonitor:
        # 替换为你的Azure Monitor工作区连接字符串(建议用Secret存储)
        # 或使用AKS托管身份(需提前配置身份绑定)
        connection_string: "<你的Azure Monitor连接字符串>"

    service:
      pipelines:
        logs:
          receivers: [kuberneteslogs, otlp]
          processors: [memory_limiter, batch]
          exporters: [azuremonitor]
      telemetry:
        logs:
          level: info

1.4 Collector Deployment(修正后的版本)

apiVersion: apps/v1
kind: Deployment
metadata:
  name: otel-collector
  namespace: otelcollector
  labels:
    app: otelcollector
    component: otel-collector
spec:
  selector:
    matchLabels:
      app: otelcollector
      component: otel-collector
  minReadySeconds: 5
  replicas: 1
  template:
    metadata:
      namespace: otelcollector
      labels:
        app: otelcollector
        component: otel-collector
    spec:
      serviceAccountName: otel-collector-sa
      containers:
        - name: otel-collector
          command:
            - "/otelcol-contrib"
            - "--config=/etc/otelcol-contrib/config.yaml"
          image: otel/opentelemetry-collector-contrib:latest
          resources:
            limits:
              cpu: "1"
              memory: 2Gi
            requests:
              cpu: 200m
              memory: 400Mi
          ports:
            - containerPort: 4318  # OTLP HTTP端口
            - containerPort: 55679  # ZPages监控端口
            - containerPort: 13133  # 健康检查端口
          volumeMounts:
            - mountPath: /etc/otelcol-contrib/config.yaml
              name: data
              subPath: config.yaml
              readOnly: true
          livenessProbe:
            httpGet:
              path: /
              port: 13133
            initialDelaySeconds: 5
            periodSeconds: 10
          readinessProbe:
            httpGet:
              path: /
              port: 13133
            initialDelaySeconds: 5
            periodSeconds: 10
      volumes:
        - name: data
          configMap:
            name: otel-collector-config

2. 关键配置说明

  • 权限配置:Collector需要获取K8s资源元数据来丰富日志内容,因此必须配置ClusterRole和ServiceAccount绑定。
  • 日志接收器:同时启用kuberneteslogs(自动收集容器日志)和otlp(接收自定义应用上报的日志),覆盖两种日志来源场景。
  • 批处理处理器:batch处理器减少向Azure Monitor的请求次数,提升性能;memory_limiter防止Collector内存溢出。
  • Azure Monitor导出器:优先使用连接字符串或托管身份,避免在配置中明文存储敏感信息。若使用托管身份,需提前在AKS中绑定对应Azure Monitor的权限。

3. 部署验证

  1. 应用所有配置文件:kubectl apply -f <配置文件路径>
  2. 检查Collector Pod状态:kubectl get pods -n otelcollector
  3. 查看Collector日志排查问题:kubectl logs -n otelcollector <pod-name>

内容的提问来源于stack exchange,提问作者satish

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 16:08:23