自建Kubernetes集群部署Elastic Fleet Server及Agent接入疑问
解决自建K8s集群中用YAML部署Elastic Agent对接自建Fleet Server的问题
你目前已经完成了Fleet Server的部署,但要通过YAML在K8s中部署Elastic Agent,遗漏了以下关键步骤:
1. 生成/获取Agent专属的注册令牌
自建Fleet Server后,不能直接用Fleet Server自身的注册令牌,需要创建Agent enrollment token:
- 登录Kibana,进入
Fleet > Settings > Agent enrollment tokens - 创建一个新令牌(或使用默认的
Default令牌),复制该令牌值,后续要写入Agent的YAML配置中。
2. 确保Fleet Server在K8s集群内可访问
Kibana显示的Fleet Server Hosts可能是Pod IP或内部临时地址,需要为Fleet Server创建稳定的Service:
- 为Fleet Server的Agent CR关联一个ClusterIP Service(如果仅集群内Agent访问),或NodePort/LoadBalancer(如果外部Agent需要接入)
- 确认Agent Pod所在节点能访问该Service的地址+端口(默认Fleet Server端口是8220)
3. 编写Elastic Agent的K8s部署YAML(以DaemonSet为例)
需要包含RBAC权限、必要挂载、环境变量配置:
第一步:创建RBAC资源
apiVersion: v1 kind: ServiceAccount metadata: name: elastic-agent namespace: kube-system --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: elastic-agent rules: - apiGroups: [""] resources: - nodes - nodes/proxy - services - endpoints - pods verbs: ["get", "list", "watch"] - apiGroups: ["extensions"] resources: - replicasets verbs: ["get", "list", "watch"] - apiGroups: ["apps"] resources: - statefulsets - deployments - replicasets verbs: ["get", "list", "watch"] - nonResourceURLs: ["/metrics"] verbs: ["get"] --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: elastic-agent subjects: - kind: ServiceAccount name: elastic-agent namespace: kube-system roleRef: kind: ClusterRole name: elastic-agent apiGroup: rbac.authorization.k8s.io
第二步:编写DaemonSet配置
apiVersion: apps/v1 kind: DaemonSet metadata: name: elastic-agent namespace: kube-system labels: k8s-app: elastic-agent spec: selector: matchLabels: k8s-app: elastic-agent template: metadata: labels: k8s-app: elastic-agent spec: serviceAccountName: elastic-agent hostNetwork: true dnsPolicy: ClusterFirstWithHostNet containers: - name: elastic-agent image: docker.elastic.co/beats/elastic-agent:8.11.3 # 替换为你的Elastic栈版本 env: - name: FLEET_URL value: "https://fleet-server-service.kube-system.svc.cluster.local:8220" # 替换为你的Fleet Server Service地址 - name: FLEET_ENROLLMENT_TOKEN value: "你的Agent注册令牌" - name: FLEET_INSECURE value: "true" # 仅测试用,生产需配置证书 - name: KIBANA_URL value: "https://your-kibana-address:5601" # 可选,部分场景需要 securityContext: privileged: true runAsUser: 0 volumeMounts: - name: varlog mountPath: /var/log - name: varlibdockercontainers mountPath: /var/lib/docker/containers readOnly: true - name: sysfs mountPath: /sys/fs/cgroup readOnly: true - name: dockersock mountPath: /var/run/docker.sock volumes: - name: varlog hostPath: path: /var/log - name: varlibdockercontainers hostPath: path: /var/lib/docker/containers - name: sysfs hostPath: path: /sys/fs/cgroup - name: dockersock hostPath: path: /var/run/docker.sock
4. 确认Fleet Server的输出配置
在Kibana的Fleet > Settings > Outputs中,确保默认输出已正确指向你的Elasticsearch实例(自建或托管),否则Agent的数据无法最终写入ES。
5. 验证部署结果
- 部署后查看Agent Pod状态:
kubectl get pods -n kube-system -l k8s-app=elastic-agent - 查看Pod日志确认注册状态:
kubectl logs -n kube-system <elastic-agent-pod-name> - 登录Kibana的
Fleet > Agents页面,确认Agent已成功上线并关联Fleet Server
内容的提问来源于stack exchange,提问作者Ojas Kale
相关产品推荐
相关产品推荐

